Nasty Win32/Ramnit infection - help!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by LosingTheWill, Jun 26, 2011.

  1. LosingTheWill

    LosingTheWill Private E-2

    Hi

    You guys are my last hope before reformatting my family's PC. It became infected last Sunday night, from a website I think, with what Microsoft Security Essentials is identifying as Win32/Ramnit.AC along with a number of other nasties (Win32.TrojanDownloader.Mufanom/A, Trojan.Win32.Generic.pak!cobra, etc). MSE can't cope with the hundreads of Ramit infections reported and my PC is a dog, reporting hard disk errors, missing files, blocking websites, etc.

    I've read through the 'Read first' post and have performed all the tasks and attach my logs. Hopefully someone can help me out.

    Combofix seems to clear it, but it was back once more after rebooting.

    Huge thanks in advance - you guys offering your time like this restores my faith in humanity.

    Kind regards

    Sean
     

    Attached Files:

  2. LosingTheWill

    LosingTheWill Private E-2

    The last log...
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, you have a nasty Ramnet infection. Let's run this and see just how deep it has its hooks in.

    Using ESET's Online Scanner

    Attach the results please.
     
  4. LosingTheWill

    LosingTheWill Private E-2

    Hi, many thanks, unfortunately the malware appears to be blocking me from accessing anything on est.com on this machine, using either IE or FF I just get an "Unable to connect" message. I can access est.co.uk, but unfortunately the 'Scan Now' link refers back to est.com and won't connect.

    Is there anything I can edit, maybe in my registry, to allow access to this site?

    Kind regards

    Sean
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    While you wait for Kes to return, consider this:
    Now, we can try to clean some things up and hopefully get you to be able to do the Eset scan:

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\Documents and Settings\Pagan\Local Settings\Application Data\acqmgjka.log
    C:\Documents and Settings\Pagan\Local Settings\Application Data\hitvxgcs.log
    C:\Documents and Settings\Pagan\Local Settings\Application Data\jenskfgy.log
    C:\Documents and Settings\Pagan\Local Settings\Application Data\npdfpogw.log
    C:\Documents and Settings\Pagan\Local Settings\Application Data\shfnsnru.log
    C:\Documents and Settings\Pagan\Local Settings\Application Data\usvrentf.log
    C:\Documents and Settings\All Users\Application Data\17555236
    C:\Documents and Settings\All Users\Application Data\22601508
    C:\Documents and Settings\All Users\Application Data\~17555236
    C:\Documents and Settings\All Users\Application Data\~17555236r
    C:\Documents and Settings\All Users\Application Data\~22601508
    C:\Documents and Settings\All Users\Application Data\~22601508r
    C:\Documents and Settings\Pagan\Local Settings\temp\lwqufqnpduvfgwdj.exe
    c:\documents and settings\Pagan\Start Menu\Programs\Startup\trsadolg.exe
    C:\trsadolg.exe
    C:\Program Files\llbnsofs\trsadolg.exe
    C:\WINDOWS\Ikavuqikuwafonut.dat
    
    Folder::
    C:\Program Files\llbnsofs
    c:\documents and settings\Pagan\llbnsofs
    
    Registry:
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
    "Userinit"="C:\WINDOWS\system32\userinit.exe,"
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now see if you cant do the Eset scan.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  6. LosingTheWill

    LosingTheWill Private E-2

    Hi Tim

    I did as you asked with ComboFix but still couldn't access Eset. Here are the logs you asked for.

    I hear what you're saying about Ramnit, I hate quitting, but maybe I will have to bite the bullet on this one. My drive came pre-partitioned into c/d/e drives, is there a recommended way to reinstall windows to ensure all malware is gone? I'm not worried about keeping the drive partitioned, just want to make sure everything's clean.

    Many thanks

    Sean
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now download MSE for XP.

    Run it and attach the log when it is done.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip
    • C:\Avenger.txt

    Make sure you tell me how things are working now!
     
  8. LosingTheWill

    LosingTheWill Private E-2

    Sorry for delay, got a success message with the regedit. Avenger log attached. I already run MSE, tried running a full scan but after 12 hours it was still only one third completed when I had to stop it, had already found 1,266 infected files. MG is just getting lots of "access is denied" messages.

    Time to throw in the towel? :(
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, I am afraid so. The infection has gotten too deep into the system to salvage it. :(
     
  10. LosingTheWill

    LosingTheWill Private E-2

    Many thanks for all your help.

    Just after a bit of advice on reformatting now. My drive came pre-partitioned into c/d/e drives, is there a recommended way to reformat and reinstall windows to ensure all malware is gone? I'm not worried about keeping the drive partitioned, just want to make sure everything's clean.

    Sean
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The best way would be to use an install disc. But you may be able to use the recovery partition to return it to factory spec's. You should post in the software forum if you have questions about doing this. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds