Plz help me with this virus!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by fAbro, Jul 10, 2009.

  1. fAbro

    fAbro Private E-2

    well my problem is that nod32 detect a "Win32/Virut.NPB" virus on my pc, this thing infect all my .exe files and .rar files, tell me a possible solution, thank you
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    If you really have a Virut infection, you will have to reinstall. Running the below will help us determine whether it is necessary to reinstall.

    Please follow the instructions in the READ & RUN ME FIRST link given futher down and attach the requested logs when you finish these instructions.
    • If you have problems where no tools seem to run, please try following the steps given in the below and then continue on no matter what you find. You only need to try the TDSSserv steps if having problems getting scans in the Read & Run Me First. If TDSSserv is not found, just continue on with the READ & RUN ME.
    READ & RUN ME FIRST. Malware Removal Guide
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:
    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. fAbro

    fAbro Private E-2

    First of all, Thanks For Your Help :)

    Well, i follow all that guides and found a few problems:

    1. I can´t install SUPERAntiSpyware, i just double click SAS.exe and immediately appears and close a window and i can´t do anything. I tried four times and get the same problem.

    2. I have a problem with ComboFix, please check "ComboFix.JPG", my english its not good, so i can´t explain it all. (Sorry)

    Executing the others programs i don´t have any problems, so i attached all logs.

    Sorry if you don´t understand something, and once again, Thanks For Your Help.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry to have to give you the bad news, but you are infected with Virut as suspected.

    Your logs show that your Windows Operating system files have become infected and there is no known reliable fix for this. In addition there are many many other infected files. We could spend a lot of time trying to remove this infection, but odds are that it will not work because the nature of the infection has so many executable system files infected that as soon as we fix one file, other files that are infected will almost immediately or upon the next reboot, just reinfect the files. In addition, your PC would still basically be unreliable/untrustworthy even if we manage to fix the infected files that we can see since there could be many more that we are not seeing.

    The safest thing for you to do is backup your personal data immediately since your PC could possibly become unbootable at any point in time. Do not back up any executable files. This includes programs that you have downloaded since any of them could be infected.

    Once you backup, you need to format partitions and reinstall Windows and all other software especially your protection software. Then install all updates for all software. DO NOT reinstall from any executable file backups you made while this PC was infected or you will just be reinstalling the infection.
     
    fAbro likes this.
  5. fAbro

    fAbro Private E-2

    Thank you very much for your help :)!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome but Wow! Almost 7 yrs for this reply. That is the longest response time I have ever seen anywhere. :confused:
     
    dr.moriarty, Kestrel13! and TimW like this.
  7. fAbro

    fAbro Private E-2

    There is always a first time for everything! Better late than never :oops:. I just wanted to express my most sincere thanks to you and all the team here in MajorGeeks. I may not log in or post anything at all, but ive been following you and your work is superb :cool:, at the point that my pc's have been clean since then. Keep going further, best of wishes, F.
     
    dr.moriarty and Kestrel13! like this.
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks and you're welcome. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds