Advertisement

Free AV to kill RAMNIT/W32 virus!

Started by May 15, 2011 08:11 AM
4 comments, last by ddn3 13 years, 4 months ago
Anybody ever deal with that virus? it creates some .lnk files on removable drive, create suspicious files in recycle bin, infecting system files(svchost.exe, iexplore.exe, etc). So far my AV could only quarantine it, but the virii didnt stop! Argh I just reinstalled the OS, still no luck T.T...
Salvage whatever you can, and format your machine.
Advertisement
I don't know what antivirus you are using, but you might try

Kaspersky - Online Scanner (EDIT: Currently unavailable)

or

ESET - Online Scanner

"I can't believe I'm defending logic to a turing machine." - Kent Woolworth [Other Space]

Learn to use search engine, and to find actual technical support oriented sites, as to get help such as removal instructions and/or diagnostics help.

See here for removal descriptions:
http://www.spywareremove.com/removeW32Ramnit.html

And here is an example of a kind of site to use for these kinds of troubles:

http://www.techspot.com/vb/topic163719.html

Best of luck, stay updated in the future and don't download piracy or porn from suspect sources.
It is I, the spectaculous Don Karnage! My bloodthirsty horde is on an intercept course with you. We will be shooting you and looting you in precisely... Ten minutes. Felicitations!
Reboot using Linux to prevent further infection.

Scan and Backup all your files.

Reformat.

Reinstall Windows.
These worms/trojans are very persistent esp the ones designed for cross infection (over removable media and network). Problem with scanning and restoring from backup after fresh install is it's possible that these worms use some sort of polymorhpic technology (they scramble their payload each infection) so they infect many files of which there is a small percentage which will pass through the scanning process un-detected and thus re-infect. If you get re-infected even after a clean install and restoring a clean scanned backup, you might have to just nuke all executable on your backups.. if that fails then consider your backups irrecoverably infected and use a different OS to access them and only then to extract select non-executable files and even then i would quarantine those files if possible.

Good Luck!

-ddn

This topic is closed to new replies.

Advertisement