I have Ramnit - please help reduce risk of reinfection

Discussion in 'Malware Help (A Specialist Will Reply)' started by Cadmus, Oct 8, 2010.

  1. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't worry about it. Just finish what Tim last requested and attach the new logs from ComboFix and MGtools so we can review where you are at.

    Since Ramnit can infect hundreds if not thousands of files, some programs may need to be reinstalled when/if we ever get things cleaned up where it stops spreading. Having just one laying around can cause it to spread again. Also it may even be in our best interest to uninstall a few things to lessen what starts up and what can get infected. Minimize the use of this PC as much as possible. Everything you open/run is prone to getting infected and hence possibly broken.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Frankly, I am not sure. If it completes the report, then that isn't a problem.
     
  3. Cadmus

    Cadmus Private E-2

    I like the "if" :)

    Here are the Combo and MGTools logs.

    MBAM coming in a bit, installing AVG.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now we need to see what is still being reported by the eSet scan. After uninstalling AVG, re-run the scan and get us the new eSet log. Keep the computer off the net and I will be back tomorrow to see the progress. ( Wife beckons!! )
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Oh and a few more things to do right now. In fact, please get a new log from MGtools after doing the below.
    • Since System Restore had already been disabled, no useful restore points exists for us to use. Thus disable System Restore right now and keep it disable until we are finished with cleanup.
    • Also immediately uninstall AVG and delete all folders from it that you can see. It is only going to add to the list of things being picked up in scans as being infected and make logs longer and make it harder to cleanup.
    • Also uninstall any Adobe programs you have installed since it typically had lots of HTMLs which are all propagating the infection. Do not reinstall this either at this point in time.
     
  6. Cadmus

    Cadmus Private E-2

    My warmest regards and deepest apologies to the Mrs! :)

    Bit confused now, I was just told to uninstall it and install it again above:
    Can you both please confirm that I need to get rid of it again?
     
  7. Cadmus

    Cadmus Private E-2

    OK.

    In absence of a response I uninstalled Adobe products, AVG and disabled System Restore.

    I am attaching the MBAM log (done after the last fix and before the uninstallations) and the new MGTools logs.

    I am proceeding with the ESET scans.

    Of course, desktoplayer.exe is back, two copies sitting comfortably in the usual place...aaaaaarghhhhh!!! :cry
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that. Tim had asked me to look in here. I did not know he was still posting.

    Yes do what I requested in my last message. Disable System Restore, uninstall AVG and all Adobe. Then reboot. After reboot, run C:\MGtools\GetLogs.bat and attach a new log so I can continue with things from that point. Again take note of my warning about minimizing the use of this PC to avoid spreading the infection further.
     
  9. Cadmus

    Cadmus Private E-2

    Thanks chaslang, all done, see post above.

    I have started doing the ESET scan, as Tim requested. Should I abandon that now to minimise spreading the infection further?

    That PC is off the net and (when not attaching logs) I'm posting from a different clean PC.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Stop the Eset scan!

    Okay I see you already posted again. Try to wait in between messages a little since we have other things we are looking at too.;) Since you already uninstalled the programs, just try doing the below to try and stop desktoplayer.exe.



    Please do the below in the exact order/way written.
    • Flush the Internet Explorer Cache. To flush your Internet Explorer Cache:
      • click Tools
      • Internet Options
      • Now on the General tab and click Delete Files and select Delete all Offline content too
      • Click OK.
      • When it finishes Click OK.
    • Now right click Start and select Explore to open a Windows Explorer window.
    • Navigate to the c:\program files\microsoft folder and just click once on the folder to have it selected. Don't do anything else yet.
    • Now simultaneously press CTRL-SHIFT-ESC to bring up Task Manger
    • In Task Manager locate the desktoplayer.exe process and right click on it and kill the process. If you do not see the desktoplayer.exe process, just continue on with the below anyway.
    • Then quickly go back to your Windows Explorer window and right click on the selected Microsoft folder and choose Rename. Change the name to BAD
    • Now just wait for my next post to come as I look through your last log. Do not run anything else.
     
  11. Cadmus

    Cadmus Private E-2

    Sorry about the speedy posting.

    Quick report:


    • Flushed IE (but I don't use it, I use Firefox)
    • Was unable to find desktoplayer.exe in TM. However there are three IEXPLORE processes
    • Could not rename - system would not allow it, it's in use (surprise, surprise rolleyes)
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes because that is what desktoplayer.exe must be appearing as. Kill all 3 iexplore.exe processes and then quickly rename the Microsoft folder to BAD. It should work after the processes are killed. I will post what to do next in a couple minutes.
     
  13. Cadmus

    Cadmus Private E-2

    Yes, that's what my research from before indicated, that it appears as multiple iexplore.exe processes. Done now, Microsoft folder renamed. It has a subfolder btw called Search Enhancement Pack.

    Also, since this thing started there has been an extra IExplorer icon on my desktop. I don't use it and according to my recollection (not 100% sure) I think there was none before (on the odd ocassion that I had to use IE I would run it from the Programs list). There is one now. In addition to that, on starting Firefox I get prompted whether I want it as a default browser which means the little turd alters my default browser settings to IExplorer as well.

    Am waiting for other instructions patiently. :)
     
    Last edited: Oct 9, 2010
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe,c:\windows\system32\rundll32srv.exe,,c:\program files\microsoft\desktoplayersrv.exe
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
    O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
    O23 - Service: AVG8 E-mail Scanner (avg8emc) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgemc.exe (file missing)
    O23 - Service: AVG8 WatchDog (avg8wd) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (file missing)

    After clicking Fix, exit HJT.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!

    I'm not too sure what the outcome will be since you seem to have acquired a particularly nasty dose of this infection. I clean one of this in person recently and had no problems getting rid of desktoplayer.exe by this method. It did not come back; however the infection had not spread all the way through to all HTML files and other executables like yours had. The level to which this infections spreads, can sometimes lead to a reinstall being necessary to get a PC running properly again. Too many things could be broken. And even one remaining infected file, could allow it to spread again.
     
  15. Cadmus

    Cadmus Private E-2

    I understand that a reinstall is sometimes the only option. If you look at the opening post, I came here with a set mind to wipe my drive clean but wanted to reduce the infection before back up because I have one very important HTML file that needs to be backed up - my Firefox bookmarks. I cannot lose that, even if it meant opening it and removing the code Ramnit inserted manually!

    I will post the logs in 5 minutes.

    P.S. I noticed the kill included only desktoplayersrv.exe. There was one such file without the suffix srv in there too (two in total). Also, immediately upon reboot after Combofix I had Windows Explorer being reported as being blocked by Windows security...
     
  16. Cadmus

    Cadmus Private E-2

    Here are the logs
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not clean yet!! I want to check to see if your userinit.exe file is infected.

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1

    Download Mirror #2
    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      userinit.exe
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. You can just close this notepad window since the log is already saved on your Desktop. Be patient! It may look like it is not doing anything, but it takes awhile for this to scan thru your whole system look for matches.
    • Please attach the SystemLook.txt log found on your Desktop to next reply.
     
  18. Cadmus

    Cadmus Private E-2

    Here it is
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that looks okay.

    Please kill any iexplore.exe processes again and then rename the C:\Program Files\Microsoft folder to BAD again.

    Then also see if you can delete the C:\Program Files\system32 folder. It looks like ComboFix is not deleting this. It may be skipping this when we request it because it is thinking that it is a valid folder. However only the C:\Windows\system32 folder is valid. The one in C:\Program Files is an infection.

    Let me know what happens when you do the above.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  21. Cadmus

    Cadmus Private E-2

    Done.

    I renamed the Microsoft folder to BAD2, wouldn't accept BAD because it already exists.

    System32 in Program files also deleted and Recycle bin emptied.
     
  22. Cadmus

    Cadmus Private E-2

    Can I have some instructions for running GMER? Should follow what's posted here: http://forums.majorgeeks.com/showthread.php?t=122626&highlight=gmer ?

    I downloaded it and now my computer is extremely slow - something's wrong! I can't get Task manager up!

    EDIT TO ADD: I had to force reboot. Everything froze. The reboot caused the Microsoft folder (renamed earlier) to return...
     
    Last edited: Oct 9, 2010
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The reboot will require renaming / deleting the folders again.
    Okay now delete both the BAD2 and the BAD folders.


    Then see if you can do the below. If you need more info on how to do this, just ask.
    • Create two copies of the C:\MGtools.exe file in the C:\Program Files folder. You will do this one at a time.
    • After getting the first copy there, right click on it and rename it to Microsoft ( ignore the error message about renaming the file making it become unusable ).
    • The right click on the renamed file and select Properties. Then put checks in the boxes to make it Read-only and Hidden.
    • Then get the second copy into the C:\Program Files folder and rename it to ( you guessed it ) system32.
    • Change this copy to be Read-only and Hidden too.
    Let me know if you are able to do all of the above.
     
  24. Cadmus

    Cadmus Private E-2

    Running GMER now. I will be back in a bit.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay. You will also have to attach a new log from C:\MGtools\GetLogs.bat since the reboot may have cause changes.

    I'm only going to try one more fix and then I will suggest that the safest and most reliable thing would really be to reinstall. While we have had some luck in removing this infection, the damage caused by this infection really makes a PC unreliable/untrustworthy. PE file infectors like Ramnit, Virut,.... etc are can infect all executable files (DLL, EXE, SCR....and many more and also HTML). These infections can open back doors that truly may compromise your computer and your security. These backdoors, could allow a remote attacker to access and instruct the infected computer to download and execute more malicious files.

    In many cases the infected files (which could number in the thousands) cannot be disinfected properly by your anti-virus or by other scanning tools. Also when disinfection is attempted, the files often become corrupted and the system may become unstable or irrepairable. The longer Ramnit.A remains on a computer, the more files it infects and corrupts so the degree of infection can vary.

    Ramnit is commonly spread via a flash drive (usb, pen, thumb, jump) infection where it copies Worm:Win32/Ramnit.A with a random file name. The infection is often contracted by visiting remote, crack and keygen sites. These type of sites are a major source of system infection.
     
  26. Cadmus

    Cadmus Private E-2

    While I wait for GMER to finish...
    This is where this thread started in the first place, me coming ready for a total wipe out but just asking for help to reduce the infection in the files I was going to back up. And I'm going back to the original question again - I need my Firefox bookmarks saved and available after the potential formatting. They get exported as an HTML file.

    How do I do that?
     
    Last edited: Oct 9, 2010
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    May not be possible, but what you could try doing is exporting the bookmarks to a different file name extension ( like bookmarks.bak ). And then copy that file to a clean PC. On the clean PC, rename the file to bookmarks.html

    Do not open the file on this clean PC. First run a full ESET scan on the assumed clean PC and see if this copy from the infected PC is detected and if so is it cleaned. Run a 2nd scan if it is detected and cleaned to see if really cleaned.

    However, just be aware that putting in any usb drive into this PC, could cause a spread of the infection to other PCs. If you have an empty USB drive and only copy just the one file (bookmarks.bak) to it. It would be safer since there are no executables to infect. Even emailing it to yourself could be dangerous. Copying just the one file to a CD is another choice.


    Do you know where/how you picked this infection up?
     
  28. Cadmus

    Cadmus Private E-2

    Since I do not know how long I had this I might have put an USB drive in during that period. The other clean PC, in which I did put that USB drive too, came clean on ESET and Malwarebytes scans. What do I do with the USB drive? I cant format it, it has very important data. Run ESET on it on the formerly infected reformatted PC after autoplay has been switched off?
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Highly recommended along with running a couple other online scanners just to be safe. You can see a few other tools here: Alternative Scans

    Also run a full scan with your fully updated antivirus program on it. It the data is really important ( and also the security of your other PCs ), it is in your best interest to really check this usb drive in detail. ;)
     
  30. Cadmus

    Cadmus Private E-2

    Ok, quick report. I really gotta go to bed - very late here where I am.

    GMER did its thing but I could not open Notepad to paste the report. had to reboot. So next time, sorry.

    I did the other routine after the reboot. Killed iexplore processes, renamed Microsoft folder to BAD-whatever, deleted those folders. Put MGTools.exe in Program files folder, renamed it to Microsoft and the other one to system 32, hidden and read-only.

    I am attaching the log from MGTools too.

    When I look into my task manager now, another iexplore.exe is there...no microsoft folder in Program files though. I will shut this infected PC now so a reboot tomorrow will bring it all back.

    I'm losing all faith TimW tried to inspire in me. :) And for the record, I came with no faith. Moral of the story is - do not try to convert unbelievers. :)

    Good night, catch you tomorrow.
     

    Attached Files:

  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you still want to try cleaning it ( not recommended) then it would be best not to power down.
     
  32. Cadmus

    Cadmus Private E-2

    Nah, there's really no point is there? Just wasting everybody's time.

    OK, before I to the back-up and reformat I have a few questions:

    1) Am I really safe keeping MP3, AVI, PDF, DOC, JPEG files? They never showed up on the ESET scans as being infected.

    2) I have a PC which originally had Vista on but came with an XP downgrade and is running XP. Will I have to go all the way back to Vista or will it be sufficient to use the XP downgrade CD to reformat?

    Thank you both.
     
  33. Cadmus

    Cadmus Private E-2

    I have started the reinstall. So pls disreggard question 2 above.

    Could you please keep this thread open so I can ask further questions about protecting myself later and seek advice during moving data back?

    I would like to thank you both for the effort and optimism (well, TimW's at least :) ) and if you were close I would buy you a drink at least.
     
  34. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sigh, yes, we will keep the thread open. I am sorry that we were unable to get you clean without a reformat. I know you were originally expecting to do that, but it appears as though, even with Chaslangs assistance, you were too far gone to accomplish that. My apologies.
     
  35. Cadmus

    Cadmus Private E-2

    Please don't apologise. There is nothing to apologise for - you attempted to help and spent a considerable amount of time on it. I should apologise for keeping you busy when there was no hope to start with and I suspected it from the moment I googled "desktoplayer.exe".

    I see you are helping someone else now who reported AVG finding Win32 Heur. Just to share my experience - AVG (and I had the full version, not free) did not pick up Ramnit but Heur and Zbot. The person in that thread is reporting hundreds of Heur finds. To me, it sounds very very familiar.

    I'm posting this from the reformatted PC - all is well.

    I have decided to let ZoneAlarm go for good. So can you please recommend me a good free firewall and any software other than the standard pack (AV+MBAM+CC Cleaner)? Thanks.
     
  36. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  37. Cadmus

    Cadmus Private E-2

  38. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not familiar with that program, but I see it is something that would reside along side of your other AV and AS software.

    To quote from Chaslang a couple of years ago:
     
    Last edited: Nov 1, 2010
  39. Cadmus

    Cadmus Private E-2

    Hi,

    I followed the advice on how to protect myself and opted for the Comodo + AVG combination. However, I have to report that either these two do not seem to be compatible or there is an issue with Comodo that doesn't make it so brilliant as one would expect.

    I am pretty much constantly experiencing the problem of Windows not being able to shut down because of Comodo. The "End Program" routine has no effect and the Comodo service cannot be turned off from the Task Manager. Similarly, at times it is impossible to access Comodo through the tray icon - although the icon is there, clicking on it produces no result. The problem is discussed here.

    I might have to drop this firewall (which otherwise seems excellent) because I cannot keep shutting down Windows by pressing the external button.

    I think you can close this thread now by the way. :)
     
  40. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, that is a common occurrence when two programs seem to conflict. I suggest you post in the software forum for further advice.
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Personally, I would just use all of Comodo Security Suite and not mix it with AVG at all. I would stay away from AVG since it has been becoming more and more problematic since version 8 was released long ago. The How to protect thread even stated there are issues with AVG.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds