Infected with Ramnit Win/32 virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by TheNutKicker, May 16, 2012.

  1. TheNutKicker

    TheNutKicker Private E-2

    Hello guys as of yesterday i was infected with a Ramnit Win/32 virus without any 'A' Or 'B' Variants just a non variant Ramnit, now i think i got this virus from my friends flash drive as it has folders called 'Copy to Shortcut 1.2.3.4 and a folder called Recycler (which i used MBAM(it detected ramnit and trojan downlaoder) but it just came coming back). i have a dual boot system with 7 and vista, and i used MBAM(my hard drive space was 60kb so i knew something was wrong) on the windows 7 one and it detected Ramnit win32 and i removed them, but to my misfortune the virus came back for some reason and i heard i have to reformat, but i think i might have found the Source of the Ramnit virus its in UserName/Roaming/Microsoft/Microsoft/Startmenu/programs/startup/ and there is a file called 'ehskmecj' which is EXACTLY 105 Kb so i knew it was the ramnit source, but i couldn't delete it because it said the file was in use and in my msconfig startup it says to have ehskmecj to automatically start up and even after i disabled, and rebooted it still started up and i couldn't find it in my windows process.

    UPDATE: i did a scan on my Vista Partition and found over a THOUSAND Virus32 Ramnit, and i can't remove them all because some of them are game folder such as mass effect 3, battlefield, and alot of other
     
  2. TheNutKicker

    TheNutKicker Private E-2

    Requesting @Kestrel13! to help me and i have the Following Symptoms

    1.Hard Drive Space Decreasing even after i run ESET Online Scanner and Mal ware bytes (On my Windows 7 partition at least),the size of the partition goes down from 1gb to 64 kb and even it goes to 0 bytes.

    2.I Deleted a very very suspicious file found in UserName/Roaming/Microsoft/Microsoft/StartMenu/Programs/startup/ehskmecj.exe which was 105 kb and after i killed 2 extra firefox.exe processes i was able to delete the file, but the problem persists.

    3. I'm running on a Laptop via a XGA Cable which has its Screen broken so i can't go to Safe Made.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  4. TheNutKicker

    TheNutKicker Private E-2

    Actually i THINK the problem is solved now the online scanner picked up a whopping 10,747 infections and cleaned them all and it took 3 hours and 10 minutes(vista), i dled ESET Anti Virus and scanned my drive(7) and the other one(vista) and cleaned them both up and i'm not getting any low disk problems or anything but i'd like confirmation that i'm clean, and on my FLASH Drive there are the folders copy to shortcut1,2,3,4 and recycler and i would like to get rid of these files because they are 100% spreading the virus.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then you should follow the instructions that I linked to. :)
     
  6. TheNutKicker

    TheNutKicker Private E-2

    Shit i think i might have it AGAIN my hard drive space was 2.6gb then suddenly its 1.8gb then now 1.6gb and then i saw on eset nod32 that ramnit was detected in my download folder about some Stockmarket folder.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Follow my instructions please.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds