Results 1 to 14 of 14

Thread: Win32 Ramnit gen!A infection

  1. #1
    Va Va Voom Lowe's Avatar
    Join Date
    Jul 2003
    Location
    Newcastle Under Lyme
    Posts
    6,748
    Thanks
    323
    Thanked
    359 times in 267 posts
    • Lowe's system
      • Motherboard:
      • Gigabyte Z97MX Gaming 5
      • CPU:
      • Intel i5 4690K
      • Memory:
      • 16GB Crucial Ballistix Tactical
      • Storage:
      • Crucial M550 256GB and 1TB spindle drive
      • Graphics card(s):
      • Palit Geforce GTX1080 Jetstream
      • PSU:
      • EVGA 600w
      • Case:
      • Coolermaster Silencio 352 m-ATX
      • Operating System:
      • Win 7/Mac OSX
      • Monitor(s):
      • 27" 1080p AOC, Oculus Rift CV1
      • Internet:
      • 200mb Virgin VIVID

    Win32 Ramnit gen!A infection

    Anyone got much experience with this one? MSE went nuts this morning saying my system was infected. It's running a scan now and the list of items infected is frankly quite concerning. Even worse it seems to have spread onto both my Win7 and WinXP partitions. Reading a few bits and pieces around the web it seems to suggest that the only course of action is a reinstall. Is this really the case?

    If a reinstall is a must, how can I safely copy files for backup purposes? I've never had a serious infection before, god only knows how this got in.

  2. #2
    Herr Doktor Oetker, ja!!! pollaxe's Avatar
    Join Date
    Jul 2006
    Location
    West of England
    Posts
    2,969
    Thanks
    1,013
    Thanked
    280 times in 225 posts

    Re: Win32 Ramnit gen!A infection

    IIRC that's an email-based one (it gets in via attachments, I think..)

    I've no direct experience with it but I've dealt with a number of infections on other people's PCs and have found Malwarebytes AntiMalware one of the better ones to use.

    Give that a try as a cleaner (the free version works fine). So far I've not had to blat any systems that have been infected with anything using that - fingers crossed for you.

    Edit: This looks a nasty little beast. This may be of use too if you've not already seen/tried it (this is a Google find so as ever, treat with caution).
    Last edited by pollaxe; 12-10-2010 at 10:17 AM.

  3. #3
    Va Va Voom Lowe's Avatar
    Join Date
    Jul 2003
    Location
    Newcastle Under Lyme
    Posts
    6,748
    Thanks
    323
    Thanked
    359 times in 267 posts
    • Lowe's system
      • Motherboard:
      • Gigabyte Z97MX Gaming 5
      • CPU:
      • Intel i5 4690K
      • Memory:
      • 16GB Crucial Ballistix Tactical
      • Storage:
      • Crucial M550 256GB and 1TB spindle drive
      • Graphics card(s):
      • Palit Geforce GTX1080 Jetstream
      • PSU:
      • EVGA 600w
      • Case:
      • Coolermaster Silencio 352 m-ATX
      • Operating System:
      • Win 7/Mac OSX
      • Monitor(s):
      • 27" 1080p AOC, Oculus Rift CV1
      • Internet:
      • 200mb Virgin VIVID

    Re: Win32 Ramnit gen!A infection

    Quote Originally Posted by pollaxe View Post
    IIRC that's an email-based one (it gets in via attachments, I think..)

    I've no direct experience with it but I've dealt with a number of infections on other people's PCs and have found Malwarebytes AntiMalware one of the better ones to use.

    Give that a try as a cleaner (the free version works fine). So far I've not had to blat any systems that have been infected with anything using that - fingers crossed for you.
    D'oh, only the missus checks emails on the computer... Grr...

    Will try that cleaner when I get home - ta!

  4. #4
    Registered User
    Join Date
    Jul 2003
    Location
    Cornwall/Weston-Super-Mare
    Posts
    5,337
    Thanks
    438
    Thanked
    309 times in 262 posts
    • Behemoth's system
      • Motherboard:
      • Gigabyte mATX
      • CPU:
      • Phenom 2 X2 555 BE
      • Memory:
      • 8 Gig DDR3 Corsair XMS 3 1600 MHz
      • Storage:
      • 4 TB's Storage
      • Graphics card(s):
      • Gigabyte GTX 460 OC2
      • PSU:
      • OCZ StealthStream 2 600 Watt
      • Case:
      • Silverstone TJ08-E
      • Operating System:
      • Windows 7 64 Bit
      • Monitor(s):
      • HP x23LED
      • Internet:
      • BT Broadband

    Re: Win32 Ramnit gen!A infection

    Even if malware bytes does get the worst of it off I know from experience that you'll never be totally clear of it. The best thing to do is to backup any important data and re-install the lot. You don't know where else the virus will be hiding.

    A friend of mine had it and he thought he'd gotten shot of it, only to find two weeks later it reared its ugly head again so he had no choice but to start from scratch and a reintall was needed.

  5. #5
    Va Va Voom Lowe's Avatar
    Join Date
    Jul 2003
    Location
    Newcastle Under Lyme
    Posts
    6,748
    Thanks
    323
    Thanked
    359 times in 267 posts
    • Lowe's system
      • Motherboard:
      • Gigabyte Z97MX Gaming 5
      • CPU:
      • Intel i5 4690K
      • Memory:
      • 16GB Crucial Ballistix Tactical
      • Storage:
      • Crucial M550 256GB and 1TB spindle drive
      • Graphics card(s):
      • Palit Geforce GTX1080 Jetstream
      • PSU:
      • EVGA 600w
      • Case:
      • Coolermaster Silencio 352 m-ATX
      • Operating System:
      • Win 7/Mac OSX
      • Monitor(s):
      • 27" 1080p AOC, Oculus Rift CV1
      • Internet:
      • 200mb Virgin VIVID

    Re: Win32 Ramnit gen!A infection

    Well it looks like the system is shot. All kinds of programs beginning to simply fail, system is unstable and it's killed my system backups as well.

    I'm desperately trying to save what I can to USB pen drives and my Mac laptop and I think I'm going to have to bite the bullet and reinstall. Gutted, absolutely gutted.

  6. #6
    SiM
    SiM is offline
    Senior Member
    Join Date
    Apr 2006
    Location
    London
    Posts
    7,787
    Thanks
    300
    Thanked
    633 times in 422 posts
    • SiM's system
      • Motherboard:
      • P5K Premium
      • CPU:
      • Q6600
      • Memory:
      • 8GB PC2-6400 OCZ ReaperX + Platinum
      • Storage:
      • 3 x 320gb HD322HJ single platter in Raid 0
      • Graphics card(s):
      • PNY GTX285
      • PSU:
      • Corsair TX650W
      • Case:
      • Antec 1200
      • Monitor(s):
      • 2407-HC

    Re: Win32 Ramnit gen!A infection

    Sorry mate, but the evidence is clear. Your missus has been opening penis enlargement emails

    But seriously, I hope you can recover all your important data. I would suggest loading the hard drive in a linux pc to copy everything over and prevent it spreading to other files on the PC and to other computers over the USB drives

  7. Received thanks from:

    Terbinator (12-10-2010)

  8. #7
    Senior Member
    Join Date
    Aug 2004
    Location
    W Yorkshire
    Posts
    5,691
    Thanks
    85
    Thanked
    15 times in 13 posts
    • XA04's system
      • Motherboard:
      • MSI X570-A Pro
      • CPU:
      • AMD Ryzen 5 3600
      • Memory:
      • Corsair 2x 8gb DDR 4 3200
      • Storage:
      • 1TB Serpent M.2 SSD & 4TB HDD
      • Graphics card(s):
      • Palit RTX 2060
      • PSU:
      • Antec Truepower 650W
      • Case:
      • Fractcal Meshify C
      • Operating System:
      • Windows 10
      • Monitor(s):
      • iiyama 34" Curved UWQHD
      • Internet:
      • Virgin 100mb Fibre

    Re: Win32 Ramnit gen!A infection

    Boot up in safe mode from now on. That way things should function better and you can backup that way too. If you run an online virus scan or use the above suggested tool in safe mode too it should help.

  9. #8
    Va Va Voom Lowe's Avatar
    Join Date
    Jul 2003
    Location
    Newcastle Under Lyme
    Posts
    6,748
    Thanks
    323
    Thanked
    359 times in 267 posts
    • Lowe's system
      • Motherboard:
      • Gigabyte Z97MX Gaming 5
      • CPU:
      • Intel i5 4690K
      • Memory:
      • 16GB Crucial Ballistix Tactical
      • Storage:
      • Crucial M550 256GB and 1TB spindle drive
      • Graphics card(s):
      • Palit Geforce GTX1080 Jetstream
      • PSU:
      • EVGA 600w
      • Case:
      • Coolermaster Silencio 352 m-ATX
      • Operating System:
      • Win 7/Mac OSX
      • Monitor(s):
      • 27" 1080p AOC, Oculus Rift CV1
      • Internet:
      • 200mb Virgin VIVID

    Re: Win32 Ramnit gen!A infection

    It looks like the important stuff like documents and pictures will be OK, it's just a case of copying and reinstalling by the look of it. Everything else like programs can be downloaded and replaced.
    But, it's clear that Microsoft Security Essentials simply isn't up to the job. It's currently saying that the system is 100% clear, which is odd given 5 minutes ago it was saying there was 225 infections...

  10. #9
    Registered User
    Join Date
    Jul 2003
    Location
    Cornwall/Weston-Super-Mare
    Posts
    5,337
    Thanks
    438
    Thanked
    309 times in 262 posts
    • Behemoth's system
      • Motherboard:
      • Gigabyte mATX
      • CPU:
      • Phenom 2 X2 555 BE
      • Memory:
      • 8 Gig DDR3 Corsair XMS 3 1600 MHz
      • Storage:
      • 4 TB's Storage
      • Graphics card(s):
      • Gigabyte GTX 460 OC2
      • PSU:
      • OCZ StealthStream 2 600 Watt
      • Case:
      • Silverstone TJ08-E
      • Operating System:
      • Windows 7 64 Bit
      • Monitor(s):
      • HP x23LED
      • Internet:
      • BT Broadband

    Re: Win32 Ramnit gen!A infection

    Looks like I'll have to switch over to something else as I'm also running MSE.

  11. #10
    Senior Member
    Join Date
    Jul 2003
    Posts
    12,116
    Thanks
    906
    Thanked
    583 times in 408 posts

    Re: Win32 Ramnit gen!A infection

    Do you have a spare machine you can stick the drive in to clean it?

  12. #11
    SiM
    SiM is offline
    Senior Member
    Join Date
    Apr 2006
    Location
    London
    Posts
    7,787
    Thanks
    300
    Thanked
    633 times in 422 posts
    • SiM's system
      • Motherboard:
      • P5K Premium
      • CPU:
      • Q6600
      • Memory:
      • 8GB PC2-6400 OCZ ReaperX + Platinum
      • Storage:
      • 3 x 320gb HD322HJ single platter in Raid 0
      • Graphics card(s):
      • PNY GTX285
      • PSU:
      • Corsair TX650W
      • Case:
      • Antec 1200
      • Monitor(s):
      • 2407-HC

    Re: Win32 Ramnit gen!A infection

    Quote Originally Posted by Lowe View Post
    it's clear that Microsoft Security Essentials simply isn't up to the job
    Don't think that is fair to be honest. It could be the user's fault and you won't ever see a post saying "MSE saved my PC" because people just click quarantine/delete and then get on with their lives, but people who get hit complain.

    I'm more than satisfied with MSE + general IT awareness until I see some hard evidence proving it is not effective.

  13. #12
    Splash
    Guest

    Re: Win32 Ramnit gen!A infection

    Quote Originally Posted by Lowe View Post
    But, it's clear that Microsoft Security Essentials simply isn't up to the job. It's currently saying that the system is 100% clear, which is odd given 5 minutes ago it was saying there was 225 infections...
    Have you cleared out system restore and disconnected it from the network in case another machine is re-infecting it? Cleared temporary internet files and the like?

    Possibly worth trying something like http://www.f-secure.com/en_EMEA/secu...ols/rescue-cd/ too

  14. #13
    Va Va Voom Lowe's Avatar
    Join Date
    Jul 2003
    Location
    Newcastle Under Lyme
    Posts
    6,748
    Thanks
    323
    Thanked
    359 times in 267 posts
    • Lowe's system
      • Motherboard:
      • Gigabyte Z97MX Gaming 5
      • CPU:
      • Intel i5 4690K
      • Memory:
      • 16GB Crucial Ballistix Tactical
      • Storage:
      • Crucial M550 256GB and 1TB spindle drive
      • Graphics card(s):
      • Palit Geforce GTX1080 Jetstream
      • PSU:
      • EVGA 600w
      • Case:
      • Coolermaster Silencio 352 m-ATX
      • Operating System:
      • Win 7/Mac OSX
      • Monitor(s):
      • 27" 1080p AOC, Oculus Rift CV1
      • Internet:
      • 200mb Virgin VIVID

    Re: Win32 Ramnit gen!A infection

    Quote Originally Posted by [GSV]Trig View Post
    Do you have a spare machine you can stick the drive in to clean it?
    Nope - and I've gone for a 'copy whats important and format the PC' approach. I don't want any backdoors left open.

    Quote Originally Posted by SiM View Post
    Don't think that is fair to be honest. It could be the user's fault and you won't ever see a post saying "MSE saved my PC" because people just click quarantine/delete and then get on with their lives, but people who get hit complain.

    I'm more than satisfied with MSE + general IT awareness until I see some hard evidence proving it is not effective.
    I see your point, and I was of the same opinion myself until I found myself in this situation. I don't consider myself someone who would find themselves at the mercy of a virus through lack of general IT awareness. It's possible the missus clicked on something but again pretty unlikely. I suppose it's even possible that my 3 year old clicked something without me knowing. But, even if you did open a dodgy attachment, surely an antivirus should step in and stop it from progressing? Perhaps I don't understand how antivirus systems work?


    Quote Originally Posted by Splash View Post
    Have you cleared out system restore and disconnected it from the network in case another machine is re-infecting it? Cleared temporary internet files and the like?

    Possibly worth trying something like http://www.f-secure.com/en_EMEA/secu...ols/rescue-cd/ too
    Frankly it takes 3 hours to run a full system scan. I've bitten the bullet and formatted the sod.

  15. #14
    Registered User
    Join Date
    Jul 2003
    Location
    Cornwall/Weston-Super-Mare
    Posts
    5,337
    Thanks
    438
    Thanked
    309 times in 262 posts
    • Behemoth's system
      • Motherboard:
      • Gigabyte mATX
      • CPU:
      • Phenom 2 X2 555 BE
      • Memory:
      • 8 Gig DDR3 Corsair XMS 3 1600 MHz
      • Storage:
      • 4 TB's Storage
      • Graphics card(s):
      • Gigabyte GTX 460 OC2
      • PSU:
      • OCZ StealthStream 2 600 Watt
      • Case:
      • Silverstone TJ08-E
      • Operating System:
      • Windows 7 64 Bit
      • Monitor(s):
      • HP x23LED
      • Internet:
      • BT Broadband

    Re: Win32 Ramnit gen!A infection

    Having had to do this to my own two systems just recently I know how gutting it is. I had a friend come over with his USB memory stick as there were some files on it he wanted me to burn to DVD for him as his PC isn't fast enough to make Movie DVD's.

    Just think Athlon XP 1800 with 512 megs of ram and no DVD burner kinda slow.

    He is very tight, he still uses dial up and thinks that broadband is a con, yet he pays BT for two sets of line rental. Personally I think thats a bigger con than paying one monthly amount for phone and broadband.

    Anyway he doesn't run any Windows Update, it crashes his dial (no surprise there then) he does run a very out of date version of AVG (so he hasn't got anything) and without so much as asking me to scan the memory stick first, plugs it into my PC. His memory stick has an autorun virus and several other trojans on it from his old slow PC.

    Not content with infecting my PC he does the same to my laptop. It took me 5 hours a piece to sort out and that was before I started on re-installing Windows.

    Needless to say he won't be touching my kit again, ever !

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Conficker infection on network - advice wanted on removal/protection
    By BadBoy House in forum Help! Quick Relief From Tech Headaches
    Replies: 5
    Last Post: 10-10-2010, 11:33 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •