Persistent W32.Ramnit problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by flywrite, Jul 24, 2010.

  1. flywrite

    flywrite Private E-2

    ]Hi, I've been having a problem with W32.Ramnit for a few days. No matter what I've tried so far, I still get Auto-Protect Results popping up when I start the computer saying it is still there (in many places).

    I've been running Malwarebytes, Super Anti-Spyware, Ad-Aware, Spybot Search & Destroy, Spyware Doctor, and Hijackthis. Spyware Doctor is the only one that seems to recognise it. I run it in Safe Mode and try to catch them all, but it takes hours and when I restart W32.Ramnit is still there.

    Since finding this forum, I've followed the steps recommended.

    I've attached the logs that I can. Please help!

    View attachment mbam-log-2010-07-24 (21-58-25).txt

    View attachment MGlogs.zip

    View attachment RGlog.txt

    View attachment SUPERAntiSpyware Scan Log - 07-14-2010 - 21-46-17.log
     

    Attached Files:

    Last edited: Jul 24, 2010
  2. flywrite

    flywrite Private E-2

    ComboFix didn't seem to work for me. It was stuck on the checking screen for hours. The 2nd time I tried it didn't even get that far


    Matt
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's start with this:

    Please Disable Spybot's TeaTimer --> Should have been done as per the R&R instructions!

    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot!

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Download TDSSKiller from Kaspersky to your directly onto your Desktop

    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  4. flywrite

    flywrite Private E-2

    TimW, many thanks for your reply and walk-throughs with this problem.

    I've followed the steps.


    All steps worked as explained. I received a success message after running the fixME.reg. However, upon rebooting the last time I still get an Auto-Protect popup with quite a few W32.Ramnit!html risks


    Attached to this post are the TDS Killer report, avenger.txt and MGlogs.zip, and a screenshot of the Auto-Protect popup (as much as i could fit).


    View attachment TDSSKiller.2.4.0.0_26.07.2010_12.47.57_log.txt

    View attachment avenger.txt

    View attachment MGlogs.zip

    autoprotectresults.jpg



    Thanks
    Matt
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That screen shot looks like all the reported items are within the Spyware Doctor folders. Is Spyware Doctor a paid for version? If not, uninstall it!!!

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...

    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message.
     
  6. flywrite

    flywrite Private E-2

    Spyware Doctor is the only one of my virus programs that I have paid for! All the others are on the free trial.

    Previously, the W32.Ramnit problem seemed to always show up in my Adobe CS3 collection's language folders. So I deleted them all. Now it shows up in Spyware Doctor's language folders.

    I ran the MBRCheck program and got the 'fine' message. I've attached the log.

    View attachment MBRCheck_07.26.10_21.02.09.txt

    Thanks
    Matt
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you keeping you disc emulation software disabled as we go through this process? Your runkeys log is still showing a problem with your MBR, so my only conclusion is that it has been re-enabled.
     
  8. flywrite

    flywrite Private E-2

    Hi,
    I have since run Defogger.exe to make sure. It didn't ask me to reboot. I've since retried all steps you asked earlier, and repost my logs below.

    I've also managed to run ComboFix.exe and posted the log from that, incase it is any help to you.

    Some questions I have - should I be doing any of this in safe mode? Also, I have not disables Symantec Antivirus at any point as I don't know how - should I have done so?

    View attachment avenger.txt

    View attachment MGlogs.zip

    View attachment ComboFix.txt

    View attachment TDSSKiller.2.4.0.0_26.07.2010_21.34.25_log.txt

    Thanks
    Matt
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you know why these files have a Srv in them:
    C:\MGtoolsSrv.exe
    c:\windows\system32\rundll32Srv.exe
    C:\cleanupSrv.exe
    c:\windows\system32\runonceSrv.exe
    c:\windows\ExplorerSrv.exe

    I am not seeing any malware in your logs, so you need to tell me what issues you are having, if any.
     
  10. flywrite

    flywrite Private E-2

    I'm not sure what the Srv issues are.

    The only problem I'm seeing now is every time I boot up, about 5 minutes after getting to the desktop, the Auto-Protect Results pop up with the W32.Ramnit!html risk 'Quarantined' in the same file.

    It doesn't appear to be affecting the computer in any way, so if you think it's harmless I'll leave it.


    Thanks for your patience and help!

    Matt
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  12. flywrite

    flywrite Private E-2

    OK, I downloaded Kaspersky Anti Virus and ran it from CD on boot. It found a LOT of items, and at the end attempted to Quarantine or Delete them.


    Now, when I boot the laptop I get a few messages about components not being able to launch because of missing DLLs.

    Now the laptop seems unable to find any wireless networks :confused


    On the flip side, I haven't seen any W32.Ramnit messages. But this may be because it's not on the internet.


    Any tips?
    Thanks
    Matt
     
  13. flywrite

    flywrite Private E-2

    I fixed the wireless problems by repairing my Intel PROSet Wireless software within Windows.

    So far so good - 20 minutes without a virus popup :-D
     
  14. flywrite

    flywrite Private E-2

    No sooner had I posted, the W32.Ramnit came back :-o

    It appeared as soon as I started browsing, and the files it was in were the newly 'fixed' Intel PROSet Wireless ones. I noticed this last night - I downloaded a some work documents, and soon after the virus appeared in them.


    I think I'm going to have to wipe the laptop and start again.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds