Multi virus infection : w32/ramnit.c, drop.agent, tr.crypt.xpac.gen ....

Discussion in 'Malware Help (A Specialist Will Reply)' started by Lamasticot, Nov 21, 2010.

  1. Lamasticot

    Lamasticot Private E-2

    Hello,


    ok firstable english isn't my foreign language but it 's ok.


    My PC is garbage, cpu usage is more than 50% all the time. It starts 2 days ago when i got tons of messages from Antivir that say i have ramnit.c infection (tons of popup alert lol)

    I have updated antivir and malwarebyte. Then i have done a scan of D: and anitvir found some virus and put them in quarantine but the problem still happen all the time.
    Now i'm doing a malwarebyte scan of my D: aswell and after 39 min he find nothing, still working.


    My windows partion is D: (40go) but i got a C: (300go) with an old truncated windows xp on it.
    Everything is FAT32 and everything is garbage because less than 5% free space..... yes i suck.


    HELP ME i'm gonna die :cry

    ps : all scans take HOURS to be executed. i'm so bored :tired
     
  2. Lamasticot

    Lamasticot Private E-2

    Malwarebyte finished and found nothing ahahahahaha

    the rapid search took 1h10min :cry
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ramnit infections have really become quit nasty and dangerous. We could attempt to remove it, and we have had some success in the past, but recently it has become even more trouble to remove. It is really safer to just bite the bullet and do a clean reinstall.

    The problem is that the damage caused by this infection really makes a PC unreliable/untrustworthy. PE file infectors like Ramnit, Virut,.... etc can infect all executable files (DLL, EXE, SCR....and many more and also HTML). These infections can open back doors that truly may compromise your computer and your security. These backdoors could allow a remote attacker to access and instruct the infected computer to download and execute more malicious files.

    In many cases the infected files (which could number in the thousands) cannot be disinfected properly by your anti-virus or by other scanning tools. Also when disinfection is attempted, the files often become corrupted and the system may become unstable or irrepairable. The longer Ramnit remains on a computer, the more files it may infect and/or corrupt so the degree of infection can vary.

    Ramnit is commonly spread via a flash drive (usb, pen, thumb, jump) infection where it copies the Ramnit worm using a random file name. The infection is often contracted by visiting remote, crack and keygen sites. These type of sites are a major source of system infection.

    So all the above being said, and please do take serious note of the warnings, do you really wish to attempt cleaning even though the stability and security of your be cannot be guaranteed? And also note that we could spend a lot of time trying to fix it and still fail due to the number of files that have been infected. What would you like to do?
     
  4. Lamasticot

    Lamasticot Private E-2

    Considering that i was infected only 2 days ago i don't think the virus has done a big expansion. I catch it visiting a website about smartphones ^^
    after that, antivir alert me that i got tons of virus onto some crack files ... but they were here since 2 years ^^ strange that he discovering it only now.They were no problem before.
    I've noticed that mostly of HTML files are infected. (don't know if that make any sense)


    If i accept to make a reinstall, what all my files will become ? (even my windows desk and "my documents" etc..)


    I have an other hard drive - the lastest 1 To western digital black- with 850go free space on it. It's already a copy of the D: drive where windows is infected at the moment.
    I agree the multiple scans will took DAYS to execute... its too boring.

    Then can you tell me what to do please, if we don't try to clean it ?
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If we don't try to clean it, then you have to save your important data and files to a cd or external drive. Then you have to use your Windows CD to do a reformat and clean install ( Yes, you will lose every thing on your system ). It will take time to replace everything, and you will need to have your protection software updated and current to scan the CD or the external drive before you transfer the data back to the clean system.

    Running the eSet scan three times will take less time and we can then see how infected you are and advise you better at that point.

    eSet Online Scan.
     
  6. Lamasticot

    Lamasticot Private E-2

    Ok then i will run eset online scan but it wil take time because it took 15min to go from 13% to 14% ^^ (that's why i quited it)



    In fact, it's not necesarly a big deal if we reinstall the system because i already have a backup of this drive on my other drive (the western digital 1to) it's a clone copy with windows, files and programs. But the boot is still on the old drive who is currently infected (D: )


    But antivir found some virus on the C: drive aswell .... i'm infected on C: and D:
    I have a clone of D: but not C: ^^


    Well, in my GMT it's night here so i will run one eset scan this night when i'm sleeping, and tomorow we will choose if we continu cleaning or if we reinstall all .

    Thx
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, that is part of the problem as both drives may be infected. I will wait to see your eSet logs when you are ready. Either Kestrel or myself will be working with you. ;)
     
  8. Lamasticot

    Lamasticot Private E-2

    Eset online scan is at 16% and took 7h50min from 0% to 16% !!!!!!!

    He found 63 infected files, there is ramnit.A/C/H and others stuffs .... (only 16% for the moment)

    I told you, scans took DAYS to run. Seriously i want your answer to continu or not but i CAN'T wait so long. 16% only OMG

    I stop or let the scan finish ? (maybe after Christmas he hit the 100%)

    By the way, i told you i got H: drive wich is a complete other hard drive wich is the clone of D:

    Maybe we can just verify if all my files on D: are saved on H: (just to be sure) and then killed D: !!!!!!


    thanks ^^
     
  9. Lamasticot

    Lamasticot Private E-2

    here the log
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only way to fix this is to run eSet scans until they come back clean. I understand this is a long procedure, but the alternative would be to save your data and personal files and then do a reformat and clean install. You could save them to your H:\ drive but it looks like most of what is being found is on your C:\ drive. What do you have on that drive?
     
  11. Lamasticot

    Lamasticot Private E-2


    On C: i have a truncated windows xp, and 300go of films, cracks, games, programs, documents ...
    But i don't use them everyday. It's just some data i keep. ^^

    D: drive is only 37go, and i have a clone of it on H:
    About that i got a question: i hear my hard drives are scratching all the time, i got bored of it and i put off the SATA connector of my H: drive to deconnect it. Then windows tell me that the windows save program was interrupt. So obvously it's because i disconnect the drive. But what the **** Windows is copying files from D: to H: without my permission ? This is normal ? he was doing it all the ****ing time, if i let the pc run, the drives scratch all day long... lol



    Is that normal that eset scan took 8 hours for 16% ????
    Can we just kill D: and make H: bootable instead ?


    Thanks

    ps: anyway, i will try to do another eset scan this night
     
  12. Lamasticot

    Lamasticot Private E-2

    Okay he found 2766 virus on the only 37go of D: ^^



    eset can't scan C: he is bugging all the time, he stop at 23% and stay 3hours on the same file !


    What is the next step ?
     

    Attached Files:

  13. Lamasticot

    Lamasticot Private E-2

    I can't boot anymore. When i start windows it's loading but before the "welcome page" he's rebooting. Safe mode do the same thing.
    I'm writing this on an other computer.

    Now what ?
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you can't boot, then the infection has corrupted your system files. There is little you can do other than try to slave the drives to another computer that is very well protected and try to save your important data and files. Then format the drives and do a clean install.
     
  15. Lamasticot

    Lamasticot Private E-2

    ok i can boot again.

    i did a second eset scan on D: , log attached.

    he found virus on files that are normally safe, like MSN messenger applications, or asus tools ... i don't understand. Maybe they are false positives ?

    What you want me to do now ?
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to keep running the scans, back to back, until we only find items in your system restore folders.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! They are infected which is why they are being found. Ramnit can infect all executables and html files.

    I refer you to message # 3 from Kestrel13!. It is time to reinstall. There is no know safe and reliable cure for Ramnit especially when it has reach the level of infection you have.

    I don't think this will work. It can be tried but I think the infection will just continue.
     
  18. Lamasticot

    Lamasticot Private E-2

    Ok but the first scan i got 2770 (if i good remember) infected files. Now i have 1900 ...

    Maybe if i continu scanning i will get 0 ? :)

    The solution of reinstall is utopic because i will lost al my files and i don't want to loose them. Making a save of it will only move the problem to an other location, but still the files are going to be infected ...
    if i'm infected on every disks i will not delete everything i have isn't it ? ^^
     
  19. Lamasticot

    Lamasticot Private E-2

    Okay i did two others scans and the last one he found 0 threats !!!!!!

    i have a huge number of quarantined files, what to do with them ?

    i haven't the log for the last scan because when 0 threats found you can't import a text file.

    I know it's only D: not C: and not H: but am i clean now ?
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to now re-run all the other scans:
    SAS
    MBAM
    ComboFix
    C:\C:\MGtools\GetLogs.bat -- and attach the C:\MGLogs.zip.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


    Also you should reboot your PC and see if things are still clean after the reboot. If you did not scan C and H, they are likely still carrying the infection. If any single infected file remains, running this one file could start the whole infection again.

    Also note that all the infected files you deleted during the scans, may have left many applications broken or unstable. Only time will tell.
     
  22. Lamasticot

    Lamasticot Private E-2

    i did another MBAM he found 2 infected files, all clear. (no ramnit)
    i did a SAS he found some infected files( like 200+ ), now all clear. (no ramnit)
    i did a ccleaner, i cleaned pretty much everything he found.
    i did MGtools, log attached.

    i will run a ComboFix later.


    Yes i know it's little bit dangerous but i have no choice because i can't loose what i have on my hard drive, so even if the infections are still somewhere on H: or C: it will be a lower threats than to be on my OS on D: ^^ and i prefer to get broken programs than loose them all.
    And be sure i reboot the PC like 20 times per day ... so i do the best i can and i know you too and i thanks you for that :)
     

    Attached Files:

  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Had you done the eSet scans on all drives? You are still very infected. So let's do this:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    I didn't see ComboFix on your desktop. Please download it to your desktop and don't run it yet.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
     
    File::
    d:\program files\microsoft\watermark.exe
    D:\Documents and Settings\FAB\\Menu Démarrer\Programmes\Démarrage\ikowin32.exe
    D:\Documents and Settings\FAB\\Menu Démarrer\Programmes\Démarrage\sishzm32.exe
    D:\Program Files\AntivirusPro_2010\AntivirusPro_2010.exe
    D:\Program Files\PC_Antispyware2010\PC_Antispyware2010.exe
    D:\WINDOWS\system32\sys32_nov.exe
    D:\WINDOWS\system32\{cad79195-a11c-d808-f596-467197d23ab2}.dll
    Folder::
    D:\Documents and Settings\FAB\\Menu Démarrer\Programmes\Démarrage
    D:\Program Files\AntivirusPro_2010
    D:\Program Files\PC_Antispyware2010
    AtJob::
     
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Why have you not installed either SP2 or SP3?
     
    Last edited by a moderator: Nov 29, 2010

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds