W32/Ramnit Infection

Discussion in 'Malware Help (A Specialist Will Reply)' started by ChiDan, Apr 20, 2011.

  1. ChiDan

    ChiDan Private E-2

    I've been infected with the W32/Ramnit virus. I'm currently running the eSet online scan for a second time; will do a third one after like mentioned around the forum.

    After finishing the scans, is there anything else which I need to do?

    The attachment is the result log of first scan.
     

    Attached Files:

  2. ChiDan

    ChiDan Private E-2

    Finished the eSet logs, they all came out like the first one uploaded in the first post. I then did a avast boot-time scan, which I think cleared most of them up.

    I then did the avenger & MgLogs. After doing them I did one more eSet scan.
    I uploaded all the logs in this post.

    Will wait for reply for next step.

    Thanks.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Based on what I see in your logs, you are still infected with Ramnit and it will start spreading all over again if it has not already done so. I suggest that you power off your PC, wait a couple minutes, and then turn it back on. Then run another full scan with ESET and see if Ramnit is starting to be detected again in any quantity.

    Also read the below note/warning we give to people about Ramnit expecially when it has spread like it had on your PC.


     
  4. ChiDan

    ChiDan Private E-2

    I did another ESET scan and no infected files were found. Does this mean my laptop is now clean of 'ramnit' now?
    Also, if it is clean now is there a possibility of the back doors you talked about still being abused if they were open in the first place? Also, on that matter is there anyway to find out if these back doors have been open?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not necessarily. At least not based on a couple things I saw in your last MGlogs.zip file. So let's see if those items were fixed already.

    Yes there is still a possibility.

    Not really. That is what a format and reinstall is the only real safe option. You should however contact all financial institutions you deal with over then next few months ( that is keep checking periodically ) for any illegal activities. Sometimes stolen info is not used immediately. Also use another known clean PC to change ALL passwords for everything. Also change the passwords used on your infected PC.

    No let's get down to fixing what I still see as a problem.

    You have multiple antivirus programs installed. You must uninstall either Avira or Avast immediately.

    Is your copy of Spyware Doctor a free trial or paid subscriptions? If free, uninstall it.


    Uninstall the below old versions of software:
    Java(TM) 6 Update 21

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,,userinit.exe
    O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - D:\Spyware Doctor\BDT\PCTBrowserDefender.dll (file missing)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O4 - S-1-5-18 Startup: caqyxvsg.exe (User 'SYSTEM')
    O4 - .DEFAULT Startup: caqyxvsg.exe (User 'Default user')
    O23 - Service: Zwangie Service - Unknown owner - C:\Documents and Settings\All Users\Application Data\Zwangie\zwangie159.exe (file missing)

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now install the current version of Sun Java from: Sun Java Runtime Environment


    Now download and run Malwarebytes as instructed in the below link:
    Using Malwarebytes Anti-Malware

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\avenger.txt
    • the log from Malwarebytes
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. ChiDan

    ChiDan Private E-2

    Done what you asked. Logs in reply.
    Laptop is running fine, anti-virus not picking up anything; unlike before when it was constantly finding ramnits and other malware.

    Thanks for the help.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that remove a few more files infected with Ramnit that your scans were not picking up that could have respread the infection. Also we removed some other junk.

    I still see a bunch of stuff from Spyware Doctor in your logs. Not sure but maybe some of it is due to Browser Defender being installed from PCTools. It would be a good idea to clean all of this up since some of these left overs also may be broken. So lets uninstall Browser Defender ( you can always reinstall it later after the cleanup if you want this ). So uninstall it now and then run the below. Some items in this fix may not show anymore, but just continue.



    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - D:\Spyware Doctor\BDT\PCTBrowserDefender.dll (file missing)
    O23 - Service: Browser Defender Update Service - Unknown owner - D:\Spyware Doctor\BDT\BDTUpdateService.exe (file missing)
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - Unknown owner - D:\Spyware Doctor\pctsAuxs.exe (file missing)
    O23 - Service: PC Tools Security Service (sdCoreService) - Unknown owner - D:\Spyware Doctor\pctsSvc.exe (file missing)

    After clicking Fix, exit HJT.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
     
  8. ChiDan

    ChiDan Private E-2

    Removed 'Browser Defender' like asked and attached the MG log below.
    Thanks for help once again, appreciate you giving up your time to help me.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    A couple of services from Spyware Doctor still did not get removed. Let's remove them manually.

    Open a command prompt window by clicking Start, Run, and enter cmd and click OK. If the window opens type each of the below commands in. Follow each by the enter key. Note there are spaces after the sc and after the delete.

    sc delete sdAuxService
    sc delete sdCoreService


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
     
  10. ChiDan

    ChiDan Private E-2

    Thanks, log in post.
     

    Attached Files:

  11. ChiDan

    ChiDan Private E-2

    Also, I noticed on autorun that ISTray ("D:\Spyware Doctor\pctsTray.exe") is starting when my laptop turns on. As you've been instructing me to remove anything associated with 'Spyware Doctor', I was wondering if I should delete it?

    So basically should I delete the following:

    ISTray - "D:\Spyware Doctor\pctsTray.exe"

    Located in Registry Editor
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you can do the below to remove this registry entry.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [ISTray] "D:\Spyware Doctor\pctsTray.exe"

    After clicking Fix, exit HJT.


    Is everything running okay now?
     
  13. ChiDan

    ChiDan Private E-2

    Will do. As for my laptop, yes everything is running fine now. Thanks again for all the help, much appreciated.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds