Persistent virus, Ramnit A and C, I need help!!!

Page 1 of 3 1, 2, 3  Next

View previous topic View next topic Go down

Persistent virus, Ramnit A and C, I need help!!!

Post by natty on Sun 17 Oct 2010, 7:35 am

Hi,

I have a Ramnit Virus. Within a few second from a system load my security NOD32 finds infected files. I can not run Mozilla, IE etc

I have Windows XP SP2

Please help!

natty

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2010-10-17
Operating System : Windows XP SP2

View user profile

Back to top Go down

Re: Persistent virus, Ramnit A and C, I need help!!!

Post by DragonMaster Jay on Sun 17 Oct 2010, 7:37 am

If your computer is infected with this threat, please read the following:

Attention: Your computer is severely infected with Win32\Ramnit what is now called, a cocktail infection. This is an infection that is comprised of many different types of viruses and other malware, to damage your computer, and use it as a zombie for its backdoor network. In other words, your computer is under control of a hacker, and regaining control is now next to impossible.

The first component is a backdoor trojan, which is a type of trojan that communicates with a hacker: to transfer personal information about you, use your computer to help perform a denial-of-service attack, redirect your internet searches in order to make money off of your browsing habits, and can be a keylogger to steal personal identifiable information to help rob your identity.

The second component is a rootkit, which is a type of malware to take control over your computer at administrator access, having full permission to modify all of your device drivers, and allowing itself to hide all the malware on the system. In other words, it is a hackers way of taking control of your computer, and hiding in the dark at the same time. This is a prime initiative of hackers to help keep access to your computer, robbing all of your personal information, and using your computer to send spam across the internet.

The third component is a file infector, which is a type of virus to purposely damage as many files as possible, in order to keep control of your system, so you have as little access as possible.

Not only has your system been compromised severely, it is also highly damaged, and if you do not commit to my suggested removal method below, then your computer may not function anymore.

If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable. Do NOT change passwords or do any transactions while using the infected computer because the attacker may get the new passwords and transaction information. (If using a router, you need to reset it with a strong logon/password so the malware cannot gain control before connecting again.) Banking and credit card institutions should be notified to apprise them of your situation (possible security breach). To protect your information that may have been compromised, I recommend reading these references:
  • How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
  • What Should I Do If I've Become A Victim Of Identity Theft?
  • Identity Theft Victims Guide - What to do


Removal method:

It is recommended to do a reformat and reinstall of your operating system. The experts in the Advanced Malware Analysts security community believe that once infected with such a piece of malware, the best course of action would be a reformat and clean reinstall of the OS. This is something I don't like to recommend normally, but in most cases it is the best solution for your safety.

I recommend the following articles to read:
  • When should I re-format? How should I reinstall?
  • Help: I Got Hacked. Now What Do I Do?
  • Help: I Got Hacked. Now What Do I Do? Part II
  • Where to draw the line? When to recommend a format and reinstall?
Guides for format and reinstall:

[You must be registered and logged in to see this link.]

[You must be registered and logged in to see this link.]

However, if you do not have the resources to reinstall your computer's OS and would like me to attempt to clean it, I will be happy to do so. But please consider carefully before deciding against a reformat.
If you do make that decision, I will do my best to help you clean the computer of any infections, but you must understand that once a machine has been taken over by this type of malware, I cannot guarantee that it will be 100% secure even after disinfection or that the removal will be successful.

Please let me know what you have decided to do in your next post. Should you have any questions, please feel free to ask.


[You must be registered and logged in to see this link.] - Get $30 off Kaspersky products.

~DMJ
GeekPolice Academy Manager


Donations/Contributions

DragonMaster Jay

Manager | Tech Officer
Manager | Tech Officer

Posts : 13451
Joined : 2009-09-07
Operating System : Windows 7 Ultimate

View user profile http://www.twitter.com/jaypfoutz

Back to top Go down

Re: Persistent virus, Ramnit A and C, I need help!!!

Post by natty on Sun 17 Oct 2010, 8:17 am

I have decided against a reformat, for many reasons. Please help me to clean my computer of this virus as much as possible, I would really appreciate it! Thank you.

natty

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2010-10-17
Operating System : Windows XP SP2

View user profile

Back to top Go down

Re: Persistent virus, Ramnit A and C, I need help!!!

Post by DragonMaster Jay on Sun 17 Oct 2010, 8:20 am

Ok. This may not be easy, so please follow instructions carefully.

Please download DrWeb-CureIt and save it to your Desktop. Do NOT perform a scan yet

  • Double-click on drweb-cureit.exe to start the program.
    An Express Scan of your PC notice will appear.
  • Under Start the Express Scan Now, Click OK to start the scan.
    This is a short scan that will scan the files currently running in memory.
    If something is found, click the Yes button when it asks you if you want to cure it.
  • Once the short scan has finished, Click Options > Change settings
  • Choose the Scan tab and UNcheck Heuristic analysis
  • Back at the main window, click Custom Scan, then Select drives (a red dot will show which drives have been chosen).
  • Then click the Start/Stop Scanning button (green arrow on the right, and the scan will start.
  • When finished, a message will be displayed at the bottom advising if any viruses were found.
  • Click Yes to all if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can see the icon next to the files found.
    If so, click it, then click the next icon right below and select Move incurable.
    (This will move it to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if it can't be cured)
  • Next, in the Dr.Web CureIt menu on top, click file and choose save report list.
  • Save the DrWeb.csv report to your Desktop.
  • Exit Dr.Web Cureit when you have finished.
  • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)





Save these instructions so you can have access to them while in Safe Mode.

Please click here to download AVP Tool by Kaspersky.
  • Save it to your desktop.
  • Reboot your computer into SafeMode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.
  • Double click the setup file to run it.
  • Click Next to continue.
  • Accept the License agreement and click on next.
  • It will, by default, install it to your desktop folder. Click Next.
  • It will then open a box There will be a tab that says Automatic scan.
  • Under Automatic scan make sure these are checked.
  • Hidden Startup Objects
  • System Memory
  • Disk Boot Sectors.
  • My Computer.
  • Also any other drives (Removable that you may have)
Leave the rest of the settings as they appear as default.
  • Then click on Scan at the to right hand Corner.
  • It will automatically Neutralize any objects found.
  • If some objects are left un-neutralized then click the button that says Neutralize all
  • If it says it cannot be neutralized then choose the delete option when prompted.
  • After that is done click on the reports button at the bottom and save it to file name it Kas.
  • Save it somewhere convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.

    Note: This tool will self uninstall when you close it so please save the log before closing it.





ESET Online Scan

Please run a free online scan with the ESET Online Scanner
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic


[You must be registered and logged in to see this link.] - Get $30 off Kaspersky products.

~DMJ
GeekPolice Academy Manager


Donations/Contributions

DragonMaster Jay

Manager | Tech Officer
Manager | Tech Officer

Posts : 13451
Joined : 2009-09-07
Operating System : Windows 7 Ultimate

View user profile http://www.twitter.com/jaypfoutz

Back to top Go down

Re: Persistent virus, Ramnit A and C, I need help!!!

Post by natty on Sun 17 Oct 2010, 8:56 am

I don't see an option for the express scan, it just asks if i want to scan now... do I say yes?

natty

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2010-10-17
Operating System : Windows XP SP2

View user profile

Back to top Go down

Re: Persistent virus, Ramnit A and C, I need help!!!

Post by DragonMaster Jay on Sun 17 Oct 2010, 9:18 am

Sure.


[You must be registered and logged in to see this link.] - Get $30 off Kaspersky products.

~DMJ
GeekPolice Academy Manager


Donations/Contributions

DragonMaster Jay

Manager | Tech Officer
Manager | Tech Officer

Posts : 13451
Joined : 2009-09-07
Operating System : Windows 7 Ultimate

View user profile http://www.twitter.com/jaypfoutz

Back to top Go down

Dr.web log

Post by natty on Mon 18 Oct 2010, 2:27 am

I cannot post the contents for the message is too big, so I have joined the file in question, in notepad form.

natty

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2010-10-17
Operating System : Windows XP SP2

View user profile

Back to top Go down

Kaspersky log

Post by natty on Mon 18 Oct 2010, 7:55 am

Here is my kaspersky log...
I am trying to run the ESET online scanner but the link will not open in my Internet Explorer, and I cannot open Firefox or Safari anymore either! I have a laptop which runs fine...is there a way for me to download this software so I can then transfer it to my desktop computer?

natty

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2010-10-17
Operating System : Windows XP SP2

View user profile

Back to top Go down

Re: Persistent virus, Ramnit A and C, I need help!!!

Post by DragonMaster Jay on Mon 18 Oct 2010, 8:03 pm

As you can probably see, most of your personal files are corrupted. Don't be alarmed, as this is expected.

Also, in the Kaspersky log there, the Kaspersky AVP Tool that was used had gotten infected within minutes of starting its scan. We need to work a bit more efficient.

The tools can be transferred, but keep in mind, if you use a flash drive, the flash drive will be instantly infected once connected to the system.

Let's see...

Please visit this webpage for a tutorial on downloading and running ComboFix:

[You must be registered and logged in to see this link.]

See the area: Using ComboFix, and when done, post the log back here.


[You must be registered and logged in to see this link.] - Get $30 off Kaspersky products.

~DMJ
GeekPolice Academy Manager


Donations/Contributions

DragonMaster Jay

Manager | Tech Officer
Manager | Tech Officer

Posts : 13451
Joined : 2009-09-07
Operating System : Windows 7 Ultimate

View user profile http://www.twitter.com/jaypfoutz

Back to top Go down

ComboFix log

Post by natty on Tue 19 Oct 2010, 1:10 am

Ok I used my flash drive to dowload the tool onto my PC and used it following the instructions, so here is my log. What can I do now? Your help is so precious thank you.

natty

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2010-10-17
Operating System : Windows XP SP2

View user profile

Back to top Go down

Re: Persistent virus, Ramnit A and C, I need help!!!

Post by DragonMaster Jay on Tue 19 Oct 2010, 9:26 am

Re-running ComboFix to remove infections:

  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Open notepad and copy/paste the text in the codebox below into it:
    killall::
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
    "Userinit"="c:\windows\system32\userinit.exe,"

    File::
    c:\program files\microsoft\desktoplayer.exe

    SysRst::

    Reboot::
  • Save this as CFScript.txt, in the same location as ComboFix.exe



  • Referring to the picture above, drag CFScript into ComboFix.exe
  • When finished, it shall produce a log for you at C:\ComboFix.txt
  • Please post the contents of the log in your next reply.





Please do a scan with Kaspersky Online Scanner

Click on the Accept button and install any components it needs.

  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

Note: If the scan freezes for more than 30 minutes, stop the scan, and report back to me.


[You must be registered and logged in to see this link.] - Get $30 off Kaspersky products.

~DMJ
GeekPolice Academy Manager


Donations/Contributions

DragonMaster Jay

Manager | Tech Officer
Manager | Tech Officer

Posts : 13451
Joined : 2009-09-07
Operating System : Windows 7 Ultimate

View user profile http://www.twitter.com/jaypfoutz

Back to top Go down

Re: Persistent virus, Ramnit A and C, I need help!!!

Post by natty on Tue 19 Oct 2010, 9:41 am

My Internet browser works now, should I also run the ESET online scan?

natty

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2010-10-17
Operating System : Windows XP SP2

View user profile

Back to top Go down

ComboFix re-scan

Post by natty on Tue 19 Oct 2010, 11:48 am

Here is my ComboFix log #2.

natty

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2010-10-17
Operating System : Windows XP SP2

View user profile

Back to top Go down

Re: Persistent virus, Ramnit A and C, I need help!!!

Post by natty on Tue 19 Oct 2010, 12:05 pm

I tried 3 times to run the Kaspersky online scanner, and each time it tells me:

Launch of the Java application is interrupted! Please establish an uninterrupted Internet connection for work with this program.

What does this mean?

natty

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2010-10-17
Operating System : Windows XP SP2

View user profile

Back to top Go down

Re: Persistent virus, Ramnit A and C, I need help!!!

Post by DragonMaster Jay on Tue 19 Oct 2010, 4:13 pm

Yeah. See if the ESET scan will work.

ComboFix is running in a reduced functionality, and will not give me enough info. This is because of the infection.



[You must be registered and logged in to see this link.] - Get $30 off Kaspersky products.

~DMJ
GeekPolice Academy Manager


Donations/Contributions

DragonMaster Jay

Manager | Tech Officer
Manager | Tech Officer

Posts : 13451
Joined : 2009-09-07
Operating System : Windows 7 Ultimate

View user profile http://www.twitter.com/jaypfoutz

Back to top Go down

ESET online scan

Post by natty on Wed 20 Oct 2010, 1:53 am

Ok, it has cleaned 44 out of 48 infected files (so 4 are still left uncleaned). Here is my log.

natty

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2010-10-17
Operating System : Windows XP SP2

View user profile

Back to top Go down

Re: Persistent virus, Ramnit A and C, I need help!!!

Post by DragonMaster Jay on Wed 20 Oct 2010, 4:37 am

1. Please download The Avenger by Swandog46 to your Desktop.

  • Right click on the Avenger.zip folder and select "Extract All..."
  • Follow the prompts and extract the avenger folder to your desktop
2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):

Files to delete:
C:\Program Files\QuickTime\QTSystem\QTCF.dll
C:\Program Files\iTunes\iTunesHelperSrv.exe

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


3. Now, open the avenger folder and start The Avenger program by clicking on its icon.

  • Right click on the window under Input script here:, and select Paste.
  • You can also click on this window and press (Ctrl+V) to paste the contents of the clipboard.
  • Click on Execute
  • Answer "Yes" twice when prompted.

4. The Avenger will automatically do the following:

  • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Delete", The Avenger will actually restart your system twice.)
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please copy/paste the content of c:\avenger.txt into your next reply along with a re-run of ESET online scanner..


[You must be registered and logged in to see this link.] - Get $30 off Kaspersky products.

~DMJ
GeekPolice Academy Manager


Donations/Contributions

DragonMaster Jay

Manager | Tech Officer
Manager | Tech Officer

Posts : 13451
Joined : 2009-09-07
Operating System : Windows 7 Ultimate

View user profile http://www.twitter.com/jaypfoutz

Back to top Go down

Re: Persistent virus, Ramnit A and C, I need help!!!

Post by natty on Wed 20 Oct 2010, 12:42 pm

Logfile of The Avenger Version 2.0, (c) by Swandog46
[You must be registered and logged in to see this link.]

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!

File "C:\Program Files\QuickTime\QTSystem\QTCF.dll" deleted successfully.
File "C:\Program Files\iTunes\iTunesHelperSrv.exe" deleted successfully.

Completed script processing.

*******************

Finished! Terminate.

This is my log for the Avenger task, and attached is my updated log for the ESET scan. 34 files were found and one could not be cleaned (bottom). Is this normal? Am I doing something wrong here? I have uninstalled my antivirus (because it keeps interfering and obviously wasn't very effective in the first place)and I usually disactivate my Firewall when running a scan...should I always keep it on? Should I permanently install an antivirus/antimalware right away or just follow your step-by-step instructions first? Thank you!

natty

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2010-10-17
Operating System : Windows XP SP2

View user profile

Back to top Go down

Re: Persistent virus, Ramnit A and C, I need help!!!

Post by DragonMaster Jay on Wed 20 Oct 2010, 7:25 pm

I will give you some tips on the antivirus later, if you like.

There could still be tons more infected files. So, we must keep on going till there are no more detections.

Please download Norman Malware Cleaner and save to your desktop.
alternate download link
  • Double-click on Norman_Malware_Cleaner.exe to start the program.
  • Read the End User License Agreement and click the Accept button to open the scanning window.
  • Click Start Scan to begin.
  • In some cases Norman Malware Cleaner may require that you restart the computer to completely remove an infection. If prompted, reboot and run the tool again to ensure that all infections are removed.
  • After the scan has finished, a log file with the date (i.e. NFix_2009-06-22_07-08-56.log) will be created on your desktop with the results. Please post the results, when complete.
Note: For usb flash drives and/or other removable drives to scan, use the Add button to browse to the drives location, click on the drive to highlight and choose Ok.


[You must be registered and logged in to see this link.] - Get $30 off Kaspersky products.

~DMJ
GeekPolice Academy Manager


Donations/Contributions

DragonMaster Jay

Manager | Tech Officer
Manager | Tech Officer

Posts : 13451
Joined : 2009-09-07
Operating System : Windows 7 Ultimate

View user profile http://www.twitter.com/jaypfoutz

Back to top Go down

1st Norman log

Post by natty on Thu 21 Oct 2010, 3:04 pm

Norman Malware Cleaner
Version 1.8.2
Copyright © 1990 - 2010, Norman ASA. Built 2010/10/19 21:36:56

Norman Scanner Engine Version: 6.06.07
Nvcbin.def Version: 6.06.00, Date: 2010/10/19 21:36:56, Variants: 7835834

Scan started: 2010/10/20 09:09:58

Running pre-scan cleanup routine:
Operating System: Microsoft Windows XP Professional 5.1.2600 Service Pack 2
Logged on user: DELL_E521\Natty

Set registry value: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit = "c:\windows\system32\userinit.exe,,c:\program files\microsoft\desktoplayer.exe" -> "C:\WINDOWS\System32\userinit.exe,"
Set registry value: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLS = -> ""
Removed registry value: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System -> DisableRegistryTools = 0x00000000
Removed registry value: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer -> NoDrives = 0x00000000
Removed registry value: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer -> NoDrives = 0x00000000

Scanning kernel...

Kernel scan complete


Scanning bootsectors...

Number of sectors found: 3
Number of sectors scanned: 3
Number of sectors not scanned: 0
Number of infections found: 0
Number of infections removed: 0
Total scanning time: 0s 453ms


Scanning running processes and process memory...

Number of processes/threads found: 2912
Number of processes/threads scanned: 2912
Number of processes/threads not scanned: 0
Number of infected processes/threads terminated: 0
Total scanning time: 2m 22s


Scanning file system...

Scanning: prescan

Scanning: C:\*.*

C:\Documents and Settings\Natty\Application Data\U3\1535830CB8C14D53\PelicanBusyPage.htm (Infected with HTML/Ramnit.A)
Deleted file

C:\Documents and Settings\Natty\Application Data\Ubovo\insea.exe (Infected with W32/Ramnit.A)
Repaired file

C:\Documents and Settings\Natty\Local Settings\Temporary Internet Files\Content.IE5\VSJSHEOC\freq[1].htm (Infected with HTML/Ramnit.A)
Deleted file

C:\Program Files\Safari\PubSub.resources\Entry.html (Infected with HTML/Ramnit.A)
Deleted file

C:\Qoobox\Quarantine\C\Documents and Settings\Natty\Application Data\BA19028B9503566C3DFAE04EDF32AAFD\enemies-names.txt.vir (Infected with TXT/JunkFile.BL)
Deleted file

Scanning: D:\*.*

D:\Documents\Nathalie\DS\Movies\Star.Wars.Episode.I.The.Phantom.Menace.1999.1080p.HDTV.x264-hV.mkv.7z/Star.Wars.Episode.I.The.Phantom.Menace.1999.1080p.HDTV.x264-hV.mkv.dpg (Error whilst scanning file: I/O Error (0x00220000))

D:\Documents\Nathalie\DS\Movies\Star.Wars.Episode.II.Attack.Of.The.Clones.2002.1080p.7z/Star.Wars.Episode.II.Attack.Of.The.Clones.2002.1080p.HDTV.x264-hV.mkv.dpg (Error whilst scanning file: I/O Error (0x00220000))

D:\Documents\Nathalie\My Music\Ma musique\La Vie En Rose (soundtrack)\22 - Jil Aigrot - Les Mtmes De La Cloche.mp3 (Error opening file: Not found)

D:\LogiCiel\Audio\Winamp\Plugins\Milkdrop2\docs\milkdrop_preset_authoring.html (Infected with HTML/Ramnit.A)
Deleted file

D:\LogiCiel2\Gravure\Silent MicroBurner\MicroBurner.exe (Infected with Packed_Upack.I)
Deleted file

D:\LogiCiel2\MultiMedia\Video\GomPlayer\GNF.ax (Infected with W32/Suspicious!api.A)
Deleted file

D:\LogiCiel2\Office\EssentialPIM\EssentialPIM.exe (Infected with W32/Packed_Upack.H)
Deleted file

D:\LogiCiel3\Gravure\Silent MicroBurner\MicroBurner.exe (Infected with Packed_Upack.I)
Deleted file

D:\LogiCiel3\MultiMedia\Audio\Winamp\Plugins\Milkdrop2\docs\milkdrop_preset_authoring.html (Infected with HTML/Ramnit.A)
Deleted file

D:\LogiCiel3\MultiMedia\Video\GomPlayer\GNF.ax (Infected with W32/Suspicious!api.A)
Deleted file

D:\LogiCiel3\Office\EssentialPIM\EssentialPIM.exe (Infected with W32/Packed_Upack.H)
Deleted file

Scanning: L:\*.*

L:\$RECYCLE.BIN\S-1-5-21-2814603516-3568070594-1710464331-1001\$RP82T15\Setup.exe (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\bookmarks.html (Infected with HTML/Ramnit.A)
Deleted file

L:\Desktop Documents (backup)\Download\en_talk-msn.exe (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Nathalie\DS\Movies\Star.Wars.Episode.I.The.Phantom.Menace.1999.1080p.HDTV.x264-hV.mkv.7z/Star.Wars.Episode.I.The.Phantom.Menace.1999.1080p.HDTV.x264-hV.mkv.dpg (Error whilst scanning file: I/O Error (0x00220000))

L:\Desktop Documents (backup)\Nathalie\DS\Movies\Star.Wars.Episode.II.Attack.Of.The.Clones.2002.1080p.7z/Star.Wars.Episode.II.Attack.Of.The.Clones.2002.1080p.HDTV.x264-hV.mkv.dpg (Error whilst scanning file: I/O Error (0x00220000))

L:\Desktop Documents (backup)\Nathalie\Mozilla\Mozilla\Firefox\Profiles\oum7p34x.default\bookmarkbackups\bookmarks-2007-10-29.html (Infected with HTML/Ramnit.A)
Deleted file

L:\Desktop Documents (backup)\Nathalie\Mozilla\Mozilla\Firefox\Profiles\oum7p34x.default\bookmarkbackups\bookmarks-2007-10-30.html (Infected with HTML/Ramnit.A)
Deleted file

L:\Desktop Documents (backup)\Nathalie\Mozilla\Mozilla\Firefox\Profiles\oum7p34x.default\bookmarkbackups\bookmarks-2007-11-05.html (Infected with HTML/Ramnit.A)
Deleted file

L:\Desktop Documents (backup)\Nathalie\Mozilla\Mozilla\Firefox\Profiles\oum7p34x.default\bookmarkbackups\bookmarks-2007-11-09.html (Infected with HTML/Ramnit.A)
Deleted file

L:\Desktop Documents (backup)\Nathalie\Mozilla\Mozilla\Firefox\Profiles\oum7p34x.default\bookmarkbackups\bookmarks-2007-11-12.html (Infected with HTML/Ramnit.A)
Deleted file

L:\Desktop Documents (backup)\Nathalie\Mozilla\Mozilla\Firefox\Profiles\oum7p34x.default\bookmarks.html (Infected with HTML/Ramnit.A)
Deleted file

L:\Desktop Documents (backup)\Nathalie\Mozilla\Mozilla\Firefox\Profiles\oum7p34x.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Nathalie\Mozilla\Mozilla\Firefox\Profiles\oum7p34x.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\metrics.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Nathalie\My Music\Ma musique\Gregory Isaacs\gregory isaacs COLLECTION COMPLETE!\2004 - gregory isaacs - give it all up\ABREME- OPEN ME.html (Infected with HTML/Ramnit.A)
Deleted file

L:\Desktop Documents (backup)\Nathalie\My Music\Ma musique\La Vie En Rose (soundtrack)\22 - Jil Aigrot - Les Mtmes De La Cloche.mp3 (Error opening file: Not found)

L:\Desktop Documents (backup)\Nathalie\My Stationery\ArtDeco.htm (Infected with HTML/Ramnit.A)
Deleted file

L:\Desktop Documents (backup)\Nathalie\My Stationery\BlueTiles.htm (Infected with HTML/Ramnit.A)
Deleted file

L:\Desktop Documents (backup)\Nathalie\My Stationery\Bubbles.htm (Infected with HTML/Ramnit.A)
Deleted file

L:\Desktop Documents (backup)\Nathalie\My Stationery\Cheddar.htm (Infected with HTML/Ramnit.A)
Deleted file

L:\Desktop Documents (backup)\Nathalie\My Stationery\ColorStripe.htm (Infected with HTML/Ramnit.A)
Deleted file

L:\Desktop Documents (backup)\Nathalie\My Stationery\Dinosaur.htm (Infected with HTML/Ramnit.A)
Deleted file

L:\Desktop Documents (backup)\Nathalie\My Stationery\Garden.htm (Infected with HTML/Ramnit.A)
Deleted file

L:\Desktop Documents (backup)\Nathalie\My Stationery\HandPrints.htm (Infected with HTML/Ramnit.A)
Deleted file

L:\Desktop Documents (backup)\Nathalie\My Stationery\LED.htm (Infected with HTML/Ramnit.A)
Deleted file

L:\Desktop Documents (backup)\Nathalie\My Stationery\Money.htm (Infected with HTML/Ramnit.A)
Deleted file

L:\Desktop Documents (backup)\Nathalie\My Stationery\Mosiac1.htm (Infected with HTML/Ramnit.A)
Deleted file

L:\Desktop Documents (backup)\Nathalie\My Stationery\Mosiac2.htm (Infected with HTML/Ramnit.A)
Deleted file

L:\Desktop Documents (backup)\Nathalie\My Stationery\Music.htm (Infected with HTML/Ramnit.A)
Deleted file

L:\Desktop Documents (backup)\Nathalie\My Stationery\Snowboard.htm (Infected with HTML/Ramnit.A)
Deleted file

L:\Desktop Documents (backup)\Nathalie\My Stationery\Southwest.htm (Infected with HTML/Ramnit.A)
Deleted file

L:\Desktop Documents (backup)\Nathalie\My Stationery\YellowTiles.htm (Infected with HTML/Ramnit.A)
Deleted file

L:\Desktop Documents (backup)\Nathalie\My Videos\Mes vidéos\I POD VIDEOz AND GAMEz\IPOD 20 games\iPodWizard\iPodWizard.exe (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Nathalie\Program Install\Ahead Nero v7.0.5.4 Premium Edition\Keygen.exe (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\ATI\AtiCimUn.exe (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\ATI\BIN\aticds10.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\ATI\BIN\AtiCIM.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\ATI\BIN\atiicdxx.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\ATI\CatalystRegistration\CatalystRegistration.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\ATI\CCC\CCC.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\ATI\CheckVer.exe (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\ATI\Driver\Driver.DLL (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\ATI\Driver\XP_INF\B_53901\atiiiexx.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\ATI\SBDrv\SBDrv.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\ATI\steam\setup.exe (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\ATI\steam\steam.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\ATI\SteamShortcut\setup.exe (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\ATI\SteamShortcut\SteamShortcut.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\ATI\vc8\vc8.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\ATI\WDM_ALL\WDM_ALL.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\Canon i560 Installer\Inst2\cnmis.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\Canon i560 Installer\Inst2\Cnmvsa.exe (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\Canon i560 Installer\Inst2\devid.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\Canon i560 Installer\Inst2\helpkicker.exe (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\Son\HDAQFE\win2k_xp\us\kb835221.exe (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\Son\WDM\stacapi.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\Son\WDM\staco.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\Son\WDM\suhlp.exe (Infected with W32/Ramnit.A)
Repaired file

Scanning: K:\*.*

Scanning: M:\*.*

M:\System\Apps\f121f3ff-0c8d-4ce1-a24b-c9f8c82dc5a2\Exec\doc\editorhelp.htm (Infected with HTML/Ramnit.A)
Deleted file

M:\System\Apps\f121f3ff-0c8d-4ce1-a24b-c9f8c82dc5a2\Exec\doc\gamehelp.htm (Infected with HTML/Ramnit.A)
Deleted file

Scanning: postscan


Running post-scan cleanup routine:
Set registry value: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit = "c:\windows\system32\userinit.exe,,c:\program files\microsoft\desktoplayer.exe" -> "C:\WINDOWS\System32\userinit.exe,"

Number of files found: 321087
Number of archives unpacked: 2933
Number of files scanned: 321061
Number of files not scanned: 26
Number of files skipped due to exclude list: 0
Number of infected files found: 69
Number of infected files repaired/deleted: 69
Number of infections removed: 69
Total scanning time: 2h 20m 37s

natty

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2010-10-17
Operating System : Windows XP SP2

View user profile

Back to top Go down

Re: Persistent virus, Ramnit A and C, I need help!!!

Post by natty on Thu 21 Oct 2010, 3:06 pm

It did not prompt me to restart, but I did anyway and ran a scan just in case...here is my 2nd log:

Norman Malware Cleaner
Version 1.8.2
Copyright © 1990 - 2010, Norman ASA. Built 2010/10/19 21:36:56

Norman Scanner Engine Version: 6.06.07
Nvcbin.def Version: 6.06.00, Date: 2010/10/19 21:36:56, Variants: 7835834

Scan started: 2010/10/20 20:29:18

Running pre-scan cleanup routine:
Operating System: Microsoft Windows XP Professional 5.1.2600 Service Pack 2
Logged on user: DELL_E521\Natty

Set registry value: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit = "c:\windows\system32\userinit.exe,,c:\program files\microsoft\desktoplayer.exe" -> "C:\WINDOWS\System32\userinit.exe,"

Scanning kernel...

Kernel scan complete


Scanning bootsectors...

Number of sectors found: 3
Number of sectors scanned: 3
Number of sectors not scanned: 0
Number of infections found: 0
Number of infections removed: 0
Total scanning time: 0s 172ms


Scanning running processes and process memory...

Number of processes/threads found: 2955
Number of processes/threads scanned: 2955
Number of processes/threads not scanned: 0
Number of infected processes/threads terminated: 0
Total scanning time: 2m 25s


Scanning file system...

Scanning: prescan

Scanning: C:\*.*

C:\Documents and Settings\Natty\Application Data\Dehyox\vyne.exe (Infected with W32/Ramnit.A)
Repaired file

C:\Documents and Settings\Natty\Application Data\Ubovo\insea.exe (Infected with W32/Ramnit.A)
Repaired file

Scanning: D:\*.*

D:\Documents\Nathalie\DS\Movies\Star.Wars.Episode.I.The.Phantom.Menace.1999.1080p.HDTV.x264-hV.mkv.7z/Star.Wars.Episode.I.The.Phantom.Menace.1999.1080p.HDTV.x264-hV.mkv.dpg (Error whilst scanning file: I/O Error (0x00220000))

D:\Documents\Nathalie\DS\Movies\Star.Wars.Episode.II.Attack.Of.The.Clones.2002.1080p.7z/Star.Wars.Episode.II.Attack.Of.The.Clones.2002.1080p.HDTV.x264-hV.mkv.dpg (Error whilst scanning file: I/O Error (0x00220000))

D:\Documents\Nathalie\My Music\Ma musique\La Vie En Rose (soundtrack)\22 - Jil Aigrot - Les Mtmes De La Cloche.mp3 (Error opening file: Not found)

Scanning: L:\*.*

L:\$RECYCLE.BIN\S-1-5-21-2814603516-3568070594-1710464331-1001\$RP82T15\Setup.exe (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Download\en_talk-msn.exe (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Nathalie\DS\Movies\Star.Wars.Episode.I.The.Phantom.Menace.1999.1080p.HDTV.x264-hV.mkv.7z/Star.Wars.Episode.I.The.Phantom.Menace.1999.1080p.HDTV.x264-hV.mkv.dpg (Error whilst scanning file: I/O Error (0x00220000))

L:\Desktop Documents (backup)\Nathalie\DS\Movies\Star.Wars.Episode.II.Attack.Of.The.Clones.2002.1080p.7z/Star.Wars.Episode.II.Attack.Of.The.Clones.2002.1080p.HDTV.x264-hV.mkv.dpg (Error whilst scanning file: I/O Error (0x00220000))

L:\Desktop Documents (backup)\Nathalie\Mozilla\Mozilla\Firefox\Profiles\oum7p34x.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Nathalie\Mozilla\Mozilla\Firefox\Profiles\oum7p34x.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\metrics.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Nathalie\My Music\Ma musique\La Vie En Rose (soundtrack)\22 - Jil Aigrot - Les Mtmes De La Cloche.mp3 (Error opening file: Not found)

L:\Desktop Documents (backup)\Nathalie\My Videos\Mes vidéos\I POD VIDEOz AND GAMEz\IPOD 20 games\iPodWizard\iPodWizard.exe (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Nathalie\Program Install\Ahead Nero v7.0.5.4 Premium Edition\Keygen.exe (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\ATI\AtiCimUn.exe (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\ATI\BIN\aticds10.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\ATI\BIN\AtiCIM.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\ATI\BIN\atiicdxx.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\ATI\CatalystRegistration\CatalystRegistration.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\ATI\CCC\CCC.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\ATI\CheckVer.exe (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\ATI\Driver\Driver.DLL (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\ATI\Driver\XP_INF\B_53901\atiiiexx.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\ATI\SBDrv\SBDrv.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\ATI\steam\setup.exe (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\ATI\steam\steam.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\ATI\SteamShortcut\setup.exe (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\ATI\SteamShortcut\SteamShortcut.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\ATI\vc8\vc8.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\ATI\WDM_ALL\WDM_ALL.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\Canon i560 Installer\Inst2\cnmis.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\Canon i560 Installer\Inst2\Cnmvsa.exe (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\Canon i560 Installer\Inst2\devid.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\Canon i560 Installer\Inst2\helpkicker.exe (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\Son\HDAQFE\win2k_xp\us\kb835221.exe (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\Son\WDM\stacapi.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\Son\WDM\staco.dll (Infected with W32/Ramnit.A)
Repaired file

L:\Desktop Documents (backup)\Pilotes\Son\WDM\suhlp.exe (Infected with W32/Ramnit.A)
Repaired file

Scanning: K:\*.*

Scanning: M:\*.*

Scanning: postscan


Running post-scan cleanup routine:
Set registry value: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit = "c:\windows\system32\userinit.exe,,c:\program files\microsoft\desktoplayer.exe" -> "C:\WINDOWS\System32\userinit.exe,"

Number of files found: 324904
Number of archives unpacked: 2901
Number of files scanned: 324878
Number of files not scanned: 26
Number of files skipped due to exclude list: 0
Number of infected files found: 32
Number of infected files repaired/deleted: 32
Number of infections removed: 32
Total scanning time: 2h 44m 56s

natty

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2010-10-17
Operating System : Windows XP SP2

View user profile

Back to top Go down

Re: Persistent virus, Ramnit A and C, I need help!!!

Post by natty on Thu 21 Oct 2010, 3:11 pm

..the L: is my external hard drive, which I thought might not be infected because I hadn't plugged it in my computer for a long time, but I scanned it just in case..

natty

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2010-10-17
Operating System : Windows XP SP2

View user profile

Back to top Go down

Re: Persistent virus, Ramnit A and C, I need help!!!

Post by DragonMaster Jay on Fri 22 Oct 2010, 2:19 pm

Now, ESET online scan once more, please.


[You must be registered and logged in to see this link.] - Get $30 off Kaspersky products.

~DMJ
GeekPolice Academy Manager


Donations/Contributions

DragonMaster Jay

Manager | Tech Officer
Manager | Tech Officer

Posts : 13451
Joined : 2009-09-07
Operating System : Windows 7 Ultimate

View user profile http://www.twitter.com/jaypfoutz

Back to top Go down

ESET log 22 oct.

Post by natty on Sat 23 Oct 2010, 2:53 am

So I ran the scan again, and 62 out of 63 files were «cleaned»...

natty

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2010-10-17
Operating System : Windows XP SP2

View user profile

Back to top Go down

Re: Persistent virus, Ramnit A and C, I need help!!!

Post by DragonMaster Jay on Sat 23 Oct 2010, 8:00 am

I want to try something real quick...

Please download MBRCheck.exe by a_d_13 from one of the links provided below and save it to your desktop.
    Link 1
    Link 2
    Link 3

  • Double-click on MBRCheck.exe to run it.
  • It will open a black window...please do not fix anything (if it gives you an option).
  • When complete, you should see Done! Press ENTER to exit.... Press Enter on the keyboard.
  • A log named MBRCheck_date_time.txt (i.e. MBRCheck_07.21.10_10.22.51.txt) will appear on the desktop.
  • Please copy and paste the contents of that log in your next reply.



==============

Please download TDSSKiller from here and save it to your Desktop.
  • Doubleclick TDSSKiller.exe to run the tool
  • Click the Start Scan button
  • After the scan has finished, click the Close button
  • Click the Report button and copy/paste the contents of it into your next reply
Note:It will also create a log in the C:\ directory.


[You must be registered and logged in to see this link.] - Get $30 off Kaspersky products.

~DMJ
GeekPolice Academy Manager


Donations/Contributions

DragonMaster Jay

Manager | Tech Officer
Manager | Tech Officer

Posts : 13451
Joined : 2009-09-07
Operating System : Windows 7 Ultimate

View user profile http://www.twitter.com/jaypfoutz

Back to top Go down

Re: Persistent virus, Ramnit A and C, I need help!!!

Post by Sponsored content Today at 4:10 pm


Sponsored content


Back to top Go down

Page 1 of 3 1, 2, 3  Next

View previous topic View next topic Back to top


 
Permissions in this forum:
You cannot reply to topics in this forum