?
Solved

Win32/RAMNIT Virus

Posted on 2010-08-28
4
Medium Priority
?
2,020 Views
Last Modified: 2012-05-10
Hi,

I have a Ramnit Virus. Within a few second from a system load my security NOD32 finds infected files. I can not run Mozilla, IE etc

I have Windows XP SP3

Please help

Many thanks
0
Comment
Question by:Remap
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 10

Assisted Solution

by:Fayaz
Fayaz earned 1000 total points
ID: 33548604
Download Dr. Web Cureit and scan the machine in safemode. Disable system restore before scanning.
0
 
LVL 20

Accepted Solution

by:
n2fc earned 1000 total points
ID: 33548635
Ramnit is not only dangerous, but tough to remove...
I would NOT attempt removal in-place (i.e. either in Safe Mode or by malware removal) due to the way it spreads on the drive...
Rather, if at all possible, REMOVE the hard drive, attach it as a slave to a known-good computer with competent Anti-virus/anti-malware software, and do a thorough scan of the drive under the GOOD system...
Then a follow-up manual look at the known registry start-up injections should be made before attempting to reinstall in the original PC.  I would only then try a deep scan from safe mode on the original PC.
This virus destroys .exe and .htm files and causes data loss.
BE CAREFUL!
0
 
LVL 25

Expert Comment

by:madunix
ID: 33570419
0
 
LVL 25

Expert Comment

by:madunix
ID: 33570551
0

Featured Post

Ransomware-A Revenue Bonanza for Service Providers

Ransomware – malware that gets on your customers’ computers, encrypts their data, and extorts a hefty ransom for the decryption keys – is a surging new threat.  The purpose of this eBook is to educate the reader about ransomware attacks.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this blog we highlight approaches to managed security as a service.  We also look into ConnectWise’s value in aiding MSPs’ security management and indicate why critical alerting is a necessary integration.
Hey fellow admins! This time, I have a little fairy tale for you. As many tales do, it starts boring and then gets pretty gory. I hope you like it. TL;DR: It is about an important security matter, you should read it if you run or administer Windows …
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…
Suggested Courses

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question