Register for your free account! | Forgot your password?

Go Back   elitepvpers > Blogs > tschulian
You last visited: Today at 02:28

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



Rate this Entry

[Release] Remove Ramnit in 2 easy steps

Posted 05/27/2016 at 12:12 by tschulian
Updated 05/27/2016 at 12:21 by tschulian

Since the amount of "requesting clean files" Threads is growing and no1 else take care about I decided to release a "boundle" to fix infected files and to avoid re-infections.
Tested it with my good old ******** Files which I already downloaded infected. Got them clean now.

Which files might be Infected by Ramnit?
.html & .htm, .exe, .dll

Symptoms:
a.) A .exe called DesktoLayer.exe is being created in C:/Program Files/Microsoft
b.) there could be fake tasks like iExplore and FireFox in your Taskmanager. The Memory Size of those fake tasks should be way to less for actual IE and FF Versions. (between 1kb and 10kb only).
Note: Those Tasks are even present if none of those browsers are currently running!
c.) Disk-Activity may be highly increased, depends on the speed of your Disks / vDisks.
d.) starting an infected .exe like "MyProgrammX1.exe" creates a 59kb sized clone called "MyProgrammX1Srv.exe"

Possible Protection & an easy and secure way to clean infected Files.

a. ) First Merge the following Registry Key: avoidRamnit_Registry.reg
Quote:
"If the registry key HKEY_LOCAL_MACHINE\Software\WASAntidot is present
and has a value named "disable" it will skip the infection process and
pop up a messagebox: "Antidot is activate". However, it will still try
to call home and possibly download stuff."
Source:



b.) After merging the registry key, execute FxRamnit.exe

Source:



Example Log after Cleaning:


#gönnteuch

PS: Scan for "antiRamnit_boundle.zip (8,10 MB)"
Attached Files
File Type: zip antiRamnit_boundle.zip (8.10 MB, 239 views)
Posted in General
Views 1341 Comments 0 Email Blog Entry
« Prev     Main     Next »
Total Comments 0

Comments

 

All times are GMT +1. The time now is 02:29.


Powered by vBulletin®
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2025 elitepvpers All Rights Reserved.