Avast WEBforum

Consumer Products => Avast Free Antivirus / Premium Security (legacy Pro Antivirus, Internet Security, Premier) => Topic started by: studiot on October 29, 2011, 08:50:25 PM

Title: Ramnit G / H
Post by: studiot on October 29, 2011, 08:50:25 PM
Avast rescue disk reports over 4000 infected files on my other (XP) pc which suddenly froze solid.

Is this recoverable or do I have to reformat?

If I ask the rescue disk to delete all infected files how safe am I recovering remaining data files (jpg etc) before reformat?
Title: Re: Ramnit G / H
Post by: Pondus on October 29, 2011, 08:58:58 PM
There is a virus and worms section here   ;)   http://forum.avast.com/index.php?board=4.0

follow the guide here and attach the logs   http://forum.avast.com/index.php?topic=53253.0



Quote
Summary
Win32/Ramnit is a family of multi-component malware that infects Windows executable files, Microsoft Office files and HTML files. Win32/Ramnit spreads to removable drives, steals sensitive information such as saved FTP credentials and browser cookies. The malware may also open a backdoor to await instructions from a remote attacker.
seems to be a fileinfector and that is usually very bad news
Title: Re: Ramnit G / H
Post by: Pondus on October 29, 2011, 09:06:30 PM
Virut and other File infectors - Throwing in the Towel?
http://miekiemoes.blogspot.com/2009/02/virut-and-other-file-infectors-throwing.html

http://www.tech-101.com/support/index.php/topic/1354-ramnit-the-newest-file-infector/
Title: Re: Ramnit G / H
Post by: studiot on October 29, 2011, 09:39:03 PM
Thank you for the posts, Pondus.

I can't get the log file from the infected disk to post so that is not really an option.

The links you posted seem to concur with the web reports I found that no effective cure has yet been found.

I just wondered if Avast has anything to offer since they found it and named the variant G and H not A and B.
Title: Re: Ramnit G / H
Post by: Pondus on October 29, 2011, 09:42:17 PM
Quote
I just wondered if Avast has anything to offer since they found it and named the variant G and H not A and B.
what do you mean?
Title: Re: Ramnit G / H
Post by: essexboy on October 29, 2011, 11:18:03 PM
Sometimes Dr Web from a live cd has a reasonable result, so if you do not yet want to reformat it may be worth a shot

Please download the following programmes to your desktop:

Dr Web Live CD (http://www.freedrweb.com/livecd/)

ImgBurn (http://www.filehippo.com/download_imgburn/)

Install IMGBurn
(http://i1224.photobucket.com/albums/ee362/Essexboy3/Dr%20Web%20shots/livecdbootscreen.gif)

(http://i1224.photobucket.com/albums/ee362/Essexboy3/Dr%20Web%20shots/livecdDriveselection.gif)

Title: Re: Ramnit G / H
Post by: ady4um on October 30, 2011, 05:18:25 AM
I don't want to contradict any of the previous comments / suggestions. But I want to suggest a different approach.

It could be more effective (having so many files infected that could also prevent Windows from even boot again) to start the system with some Live system CD/UFD and try to backup any relevant user data, like emails, contacts, documents and so on. Alternatively, a full backup image could be useful too (and even recommended).

Only after having a backup, try to work on cleaning the system. Whatever happens with the attempt (to recover), you would still have the source to start over with a second attempt, or to try to use the backup data (not executables) on a new clean system.

Of course, if you use the backed up data in any way, you need to scan the specific files you would want to use, so to be sure you wouldn't be re-inserting the malware again in a clean system.

As mentioned, this doesn't contradict any previous suggestion.