Malware and Bsod

Discussion in 'Malware Help (A Specialist Will Reply)' started by Aozora, Mar 8, 2014.

  1. Aozora

    Aozora Private E-2

    Hello user of MG ;)

    I actually got a big problem from a f*cking virus, I think it's a Ramnit.A, but maybe there is another virus or something else.

    This virus broke a lot of files (dll/exe/html), with some inject.

    I already had run Malwarebytes Anti-Malware (see log below), who had deleted a lot of infected files, but the malware is still here, I also had run, Combo Fix, TDSSkiller, and Rogue Killer.

    Hitman won't run, I don't know why, tested on Safe Mode too.

    The computer is a Win7 x64 SP1, fully updated, UAC is disabled.
    This computer had 3 HDD, C: D: K: (C is the OS, D is the first backup HDD, K is the second backup HDD)

    This pc was bought 'used' from a store, so I don't know all the software.

    The 2rd problem, is some random bsod, but I want to remove the virus first :-D.

    Thanks in advance.

    Please forgive my mistake, English is not my main language, so I can make some little error :)
     

    Attached Files:

    Last edited: Mar 8, 2014
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Sorry to send you this bad news but there is only one safe and reliable method to remove Ramnit infections and that is to delete all partitions on ALL hard disks, recreate partitions, format and then reinstall everything. DO NOT save any executable type files at all from your hard disks. Saving just one file and then reusing it, will start the problem all over again.

    Note that any USB or other writeable media that has been plugged into this computer is likely infected, and if this removeable media has been used in another computer that computer may also be infected.

    Why? The malware injects code in legitimate files similar to the Virut virus and in many cases the infected files (which could number in the thousands) cannot be disinfected properly by your anti-virus. When disinfection is attempted, the files often become corrupted and the system may become unstable or irreparable. The longer Ramnit.A remains on a computer, the more files it infects and corrupts so the degree of infection can vary.

    Ramnit is commonly spread via a flash drive (usb, pen, thumb, jump) infection where it copies Worm:Win32/Ramnit.A with a random file name. The infection is often contracted by visiting remote, crack and keygen sites. Which you have used per your logs. These type of sites are infested with a vast variety of malware and are a major source of system infection.

    Ramnit.A is not effectively disinfectable, so your best option is to perform a full reformat as there is no guarantee this infection can be completely removed. In most instances it may have caused so much damage to your system files that it cannot be completely cleaned or repaired. Further, your machine has likely been compromised by the backdoor Trojan and there is no way to be sure the computer can ever be trusted again. It is dangerous and incorrect to assume the computer is secure even if your anti-virus reports that the malware appears to have been removed.
     
  3. Aozora

    Aozora Private E-2

    Hi, thanks for your reply chaslang!

    I see, sad news for me, I have bought this computer yesterday morning and the vendor had "killed" the virus normally, but looks like it's not really the case... Need to go back tomorrow to this shop and ask for a little compensation if the shop is regular, otherwise I ask a total payback.

    Do you think it's safe to save only MY media files? (Like JPG, png, mp3, mp4, mkv, and some PDF/TXT), from google, Ramnit.A only affect exe,dll,html, so I think it's good no? I don't had a lot of files, ~ 7Go from my old computer.

    A lot of my other folder are 7zipped or on tar.gz, do you think Ramnit can alter this? Or do I need to delete these folder too. (These folder had been 7zipped / tar.gz, on my old computer who don't had got any problem.)

    2rd question, what AV/protection do you recommend? I have looked some topic on MG, and still hesitate for my future AV, Panda & Avira look good, but I don't know anything on computer, so i'm open to any proposition.

    Otherwise, it's why I had think... Need to ask a friend to do the full format, just had to wait for see if I can backup my little files.
    From this friend too, it's normally safe to:
    - Put all my files on my proper HDD (eg K: make a folder eg 765645215u put my media files + txt + pdf)
    - Delete all other informations from this HDD with a simple delete, and erase the free space of this HDD with a 3rd software, CCleaner make this normally, but I don't know if it's really good, with 3 or 7pass to erase free space?
    - Unplug K:/
    - Erase the partition C: D: and make a new partition (From the official DVD)
    - Make a Fresh install of Windows Seven
    - Update Windows at 100%
    - Install the new AV.
    - Plug K:

    I use only 7go on 3500go of these HDD, so this computer had a lot of garbage from the old owner, and I don't know any of is/her software :-o
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Most like they are okay but it would be a good idea to scan all of them after you back them up. But scan on an uninfected PC. Scan results run from the infected PC cannot really be trusted.

    These are not necessarily safe. FIle inside of them could get infected too. There are many versions of Ramnet and it can also download other infections.

    You have to be VERY careful what you save and then reuse when there is a case of PE file infection like Ramnet, Virut....etc. All it takes is one file still being infected to start the process all over again.

    If you are going to backup onto an external hard drive, you need to make sure that you have disabled autorun on any PC where you are going to use this drive. Ramnet spreads by using the autorun feature. See this tool: Autorun Eater

    Avast, Avira, Comodo are all fine.
     
  5. Aozora

    Aozora Private E-2

    Hello chaslang,

    I have finished to format my hard drive in LLC (low level format), and setup a fresh copy of windows 7.

    I also have scanned my external hard drive on a clean computer with Kaspersky, Malware Anti Malware and Hitman, and no threat found.

    24 hours since the new setup and no problem, the OS work flawless, and I don't have got any problem / popup, I currently use Avira on this computer.

    Thank you very much for your assistance and your time chaslang! :major
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Glad to hear you are back up and working clean. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds