Ramnit Blocking your sites

Discussion in 'Malware Help (A Specialist Will Reply)' started by rfin16, Oct 12, 2010.

  1. rfin16

    rfin16 Private E-2

    The authors of this worm may have gotten wind of your support - I can no longer reach any of the download sites listed in the read and try me first postings. Looks like they are being diverted to file not found messages on bit.ly etc. Advice would be appreciated.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The first thing to try is the online eSet scan:
    eSet Online Scan.

    But if you are at this point, you may be too far gone to be able to safely clean you. :(
     
  3. rfin16

    rfin16 Private E-2

    I am working my way through the read me and run me file now as I got versions of the programs to work from CNET sites. Meanwhile I have some important work deadlines. Is it safe to email myself word and ppt files for sue on other clean systems? Are video and picture files and pdf files safe as well? Thanks again for your help.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Those files should be safe, but you will need to scan them to be sure. I would need to see the log from running eSet to see what all is being infected. The problem with this virus is that the longer you have it, the more files it infects.
     
  5. rfin16

    rfin16 Private E-2

    Also does it matter if McAfee VS is also running at the same time as SAS etc as I cannot seem to disable it from running and cleaning files constantly. Thanks again
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Usually I would say no, but this is so insideous that it will take a lot to find and defeat this. If you can run the online eSet scan, save the log, reboot and run it again. I would like to see the first 3 logs from it.
     
  7. rfin16

    rfin16 Private E-2

    right now I am running SAS step then Malwarebytes on the read me run me list. Should I continue that path and send logs accordingly or switch to the eSet approach first?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Finish the SAS and MBAM scans and then start running back to back eSet scans.
     
  9. rfin16

    rfin16 Private E-2

    The SAS scan has been going on for 5 hours. DO I need to run the Malwarebytes immediately after this one? I may ned to be in bed for work before the SAS is completed at this rate.

    Thanks again
     
  10. rfin16

    rfin16 Private E-2

    SAS finished and provided a log (pasted below). Malwarebytes appeared to install correctly but will not open in regular or safe mode. Please advise if I continue to try malwarebytes or move to eSet now. Thanks again for your help.

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 10/12/2010 at 11:05 PM

    Application Version : 4.44.1000

    Core Rules Database Version : 5610
    Trace Rules Database Version: 3422

    Scan type : Complete Scan
    Total Scan Time : 07:00:20

    Memory items scanned : 661
    Memory threats detected : 1
    Registry items scanned : 7924
    Registry threats detected : 7
    File items scanned : 37307
    File threats detected : 2

    Trojan.Agent/Gen-QTPlugin
    C:\WINDOWS\SYSTEM32\QTPLUGIN.EXE
    C:\WINDOWS\SYSTEM32\QTPLUGIN.EXE
    [RegistryMonitor1] C:\WINDOWS\SYSTEM32\QTPLUGIN.EXE

    Trojan.DNS-Changer (Hi-Jacked DNS)
    HKLM\SYSTEM\CONTROLSET001\SERVICES\TCPIP\PARAMETERS\INTERFACES\{880310EA-1163-4710-857B-534692BDFC57}#NAMESERVER
    HKLM\SYSTEM\CONTROLSET004\SERVICES\TCPIP\PARAMETERS\INTERFACES\{880310EA-1163-4710-857B-534692BDFC57}#NAMESERVER
    HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\INTERFACES\{880310EA-1163-4710-857B-534692BDFC57}#NAMESERVER
    HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS#NAMESERVER
    HKLM\SYSTEM\CONTROLSET001\SERVICES\TCPIP\PARAMETERS#NAMESERVER
    HKLM\SYSTEM\CONTROLSET004\SERVICES\TCPIP\PARAMETERS#NAMESERVER

    Adware.CouponBar
    C:\WINDOWS\SYSTEM32\CPNPRT2.CID
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to start doing the eSet online scans. Run it back to back three times and attach each log to your next reply.
     
  12. rfin16

    rfin16 Private E-2

    Finished 2 eset scans and my text files re too large to attach. What do you dvise me to do at this stage? Thank you for your help.
     
  13. rfin16

    rfin16 Private E-2

    Running the third eset scan now; noticed that IE temp files are still on the system despite running cc cleaner as recommended.

    Do files need to be deleted as eset ends or are these effectively quarantined? I am hoping to at least print if not preserve many of the htm files before having these removed from this system or my backup drives which seem also infected.

    Best regards
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can zip them and then attach them.
     
  15. rfin16

    rfin16 Private E-2

    I attach a zipped folder with the three Eset logs. Please let me know if you get them OK and also what you think I need to do to preserve as many files as possible.

    Thanks again for your help.
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I got the files just fine. You are massively infected and it doesn't appear as though eSet will be able to fix it all.

    You need to delete everything in this folder:
    C:\Documents and Settings\Gregory\Local Settings\Temporary Internet Files\Content.IE5

    Then uninstall these:
    C:\Program Files\Adobe
    C:\Program Files\Common Files\Adobe
    C:\Program Files\Common Files\Microsoft Shared\Stationery

    Now please do three more scans with eSet and attach them.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds