Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Help Ramnit I/B/C Infection


  • This topic is locked This topic is locked
4 replies to this topic

#1 faisalk

faisalk

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:08:24 AM

Posted 10 February 2011 - 02:51 AM

Hi,
I have been using Microsoft Security Essentials (MSE) and a couple of days back my computer got infected by a variety of Ramnit viruses from a usb drive. Although I got MSE to clean it, and then followed up with a thorough scanning with Bitdefender Online Scanner which removed over a 1000 infections, I keep getting alerts from MSE several times a day, and though I keep asking it to clean the same, MSE history shows that Ramnit.I threat was "Allowed". Through Google search I got to know about combo fix and ran it before I saw the preparation guide at the bleeping computer. I am attaching the combo fix log. Please help me, I cannot afford to reformat my computer, I have two hard drives (160GB + 500GB) with a lot of data that has not been backed up. Thanks.

Attached Files



BC AdBot (Login to Remove)

 


#2 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:08:24 AM

Posted 12 February 2011 - 10:18 PM

Hello faisalk ,

Posted Image

Well, if it is indeed Ramnit, you should be prepared now to reformat. :( I'd like to be sure, though. I see you have MBAM.....could you please have a scan with it and post the report? Also, I'd like to see a fresh DDS log created from the directions here: http://www.bleepingcomputer.com/forums/topic34773.html

Thanks,
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#3 faisalk

faisalk
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:08:24 AM

Posted 15 February 2011 - 08:46 AM

Hi teacup61,

Thank you very much for your help. I have attached the DDS log and Malware Bytes log.
Some extra information - right after MSE alerted me about Ramnit infection I scanned and cleaned the computer. But susbsequently I kept getting alerts about similar threats and I cleaned them. Then I scanned my computer with Bitdefender Online Scanner and it identified 12 viruses and 1250 infected files which it cleaned. Next I checked MSE history and found that it had been 'allowing' Ramnit.I several times and Ramnit.B a lesser number of times. Although MSE had categorized these as serious threats, it never notified me and allowed them on its own. Several of these files were located within MSE's own Microsoft Antimalware folder. Next I manually deleted all files that had been allowed by MSE, they were present in various drives. Then I uninstalled MSE with Recuva and deleted (Shift+Del) all its folders including Microsoft Antimalware. After this I restarted the machine installed MSE, Zone Alarm Firewall (Free), Threatfire and Spyware Terminator. I have scanned my machine with all of them and have not found any threats. Although I feel the machine is taking a bit longer to shut down otherwise its running fine. But I would like to have an expert's opinion because of the dangerous reputation of Ramnit viruses. I have also created a GMER log, do let me know if you want me to post it and any other log like the Bitdefender Online Scan log. Thanks.

Attached Files



#4 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:08:24 AM

Posted 16 February 2011 - 03:54 PM

Hello,

I have also created a GMER log, do let me know if you want me to post it and any other log like the Bitdefender Online Scan log. Thanks.

Both would be good, please. :)
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#5 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:08:24 AM

Posted 20 February 2011 - 10:50 AM

Due to the lack of feedback this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users