Recently i got a new internet given buy a guy in the shop.He said it is his software.I had in my pendrive and avast deleted it before it was opened.So once again i went to the shop and asked him.He said i have to disable antivirus while installing.When i did that…after sometime… Avast continously showing poups of Win32:Ramnit-G on multiple files… Next day i removed them using malwarebytes.But still 3 softwares are not working properly.
Now in malwarebyte scans there is no virus. I don’t know if it can still hide somewhere or not. I have attached the log of that scan.
now the shop guy has cheated u…U are infected with ramnit malware…
The software that the shop guy gave u is infected with ramnit…he has cheated u…Why did u disable your AV?? Always trust your AV…avast was protecting your PC by deleting the ramnit infection when it was active and USB was plugged in…
Ramnit is nasty malware and sometimes there is a need of format and re-install…but lets see if u have luck on it…I feel like ramnit wasnt active when softare got installed…and luckily avast may have deleted the malicious files before it could execute…
follow this guide: http://forum.avast.com/index.php?topic=53253.0
attach all logs here…A malware expert will help u…
If i would have been in your place i would have first knocked of the shopkeeper’s head and not disabling avast!
I can’t think like that guy cheated me because i know about him.He is a good guy and he don’t know about these software things.He just sells things.One of the people he knows sent it to him.I asked about this and he said that.Anyway… Malwarebytes log is already above. Here i have attached the logs of OTL and aswMBR.
Hi there I must tell you upfront that this may not work and you may need to reformat and reinstall windows
Never turn the AV off when you insert a USB or install a programme.
Warning This fix is only relevant for this system and no other, using on another computer may cause problems
Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot
Run OTL
[*]Under the Custom Scans/Fixes box at the bottom, paste in the following
https://dl.dropbox.com/u/73555776/OTL_Fix.GIF
:OTL O33 - MountPoints2\{7f45fd1e-927c-11e1-9d3b-001d92f8dd05}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL \RECYCLER\S-5-2-67-2170110708-7323808834-340243546-6474\OMedIyid.exe O33 - MountPoints2\{7f45fd1e-927c-11e1-9d3b-001d92f8dd05}\Shell\explore\command - "" = \RECYCLER\S-5-2-67-2170110708-7323808834-340243546-6474\OMedIyid.exe O33 - MountPoints2\{7f45fd1e-927c-11e1-9d3b-001d92f8dd05}\Shell\Open\command - "" = \RECYCLER\S-5-2-67-2170110708-7323808834-340243546-6474\OMedIyid.exe:Files
ipconfig /flushdns /c:Commands
[purity]
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]
[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
THEN
Please download the following programmes to your desktop:
Install IMGBurn
[]Double click Dr Web
[]IMGBurn will open
[*]Burn the ISO to a cd
[]Reboot the infected computer with the CD in the drive
[]Ensure that the first boot device is CD - If you are not sure about that then see this page for instructions
[*]As loading starts, a dialogue window will prompt you to choose between the standard and safe modes.
http://i1224.photobucket.com/albums/ee362/Essexboy3/Dr%20Web%20shots/livecdbootscreen.gif
[*]Use arrow keys to select DrWeb-LiveCD (Default)
[*]When the system is loaded, check the disks or folders you want to scan, and click on “Start”.
http://i1224.photobucket.com/albums/ee362/Essexboy3/Dr%20Web%20shots/livecdDriveselection.gif
[]The programme will now scan for and cure/delete any malware that it finds. Allow it to do so
[]Once completed reboot to normal windows
[*]No log is produced so once in normal windows run a fresh OTL scan and let me know if the problems persist
Will i lose any old or new files in pc if i do these ?
It depends…ramnit is a file infector…if it did infect some of your files when u disabled avast then u may or may not lose some files…
Dr.web and combofix do good in curing infected files…u shouldnt have disabled avast in first place…next time dont turn off your av under any case…its better to stay safe than to be sorry…