Win32/Virut.NBP virus... Can anyone help?

Discussion in 'Malware Help (A Specialist Will Reply)' started by defdex, Aug 10, 2009.

  1. defdex

    defdex Private E-2

    Hello all,

    Okay, so this is my first post to the forum... I've just noticed that you seem to be the ppl to talk to when it comes to removing malware n the like.

    The basics: I'm running XP SP3, Eset Nod32 Antivirus & Firewall. I keep getting popups saying that certain files are infected with Win32/Virut.NBP... Eset has managed to clean and quarantine a few, but most are being left untouched by it.

    The infection's been going a few days now, and I've tried a few ways to remove it myself, but had no luck and thought I'd find some real help before I messed it up even more.

    I've just found the 'Read and Run First' post, so I'm gonna work through that and make notes here as I do... I hope that's okay.

    Step 1 - Basic maintainance:
    Run CCleaner - Done

    Step 2 - Remove all but one AV and FW software.
    Done.

    Step 3 -
    • Remove Viewpoint stuff
    - No viewpoint progs in Add Remove Programs
    • Remove all Sun Java
    - Done
    • Empty quarantine folder
    - Done
    • Empty recycle bin
    - Done
    • Run CCleaner
    - Done

    Step 4
    • Enable viewing of hidden/system/file ext's
    - Done
    • Enable MSConfig for Normal Startup
    !!! - >Start >Run >Msconfig.exe spits up an Application error !!!
    !!! The instruction at "0xf72a0517" referenced memory at "0xf72a0517". The memory could not be "written".

    • Uninstall malware and unwanted via add/remove progs.
    - Done (got rid of Messenger Plus Live)

    Step 5
    • Super Anti Spyware
    - Run, and log attached
    • MB-Anti Malware
    - !!! Installed, but when I try and run it, I get 'Run Time Error (0)' and 'Run Time Error (440)'
    • Combofix
    - !!! Attempted to run it, but it said the file had been compromised with 'Virut'
    • RootRepeal
    - Ran okay
    • MGtools
    - All seemed to run okay, found c:\MGlogs.zip, will attach.


    MASSIVE THANKS in advance!!

    Luke.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing anything in you logs....but you did not allow MGTools to run to completion and you also did not make the license agreement to run HJT> please run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator) and make the HJT agreement and allow it to run until it tells you it is finished. Then attach the new MGLogs.zip.
     
  3. defdex

    defdex Private E-2

    Hey TimW,

    Thanks for putting me right, I got a bit lost at points, but I think I've done it right now. In the process, the following files have spat up an 'application failed to intialize properly' dialog: MSinfo.exe, PROCESSDLL.EXE

    Also, I can't find the licence agreement for HJT, tho I do remember clicking something to do with HJT just after I sent the last post. So maybe that was it, anyhows, thanks for your patience, I think this should be the correct stuff now.

    Cheers,
    Luke.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you still unable to run either MBAM or Combo?
     
  5. defdex

    defdex Private E-2

    I've just downloaded a new version of MBAM, renamed the file to mb2.exe and attempted to run it. The install looked as if it was gonna go fine, it asked where to install to etc, then started extracting files. At about 60% it stopped and popped up a dialog box about runtime error 0, then runtime error 440 (Screengrabs of the dialog boxes are in the attached word doc). I clicked okay on them, as that was the only option, then it threw up a bunch of memory errors (also in word doc). This eventually installed the icon on my desktop, but then when i try and run it i just get the '0' and '440' runtime errors.

    Combofix, I copied this to my desktop and ran it from there, a small percentage bar window popped up, then half way thru the install it gave me a memory error (dialog also in word doc), and in the time it took me to copy n paste that to the word doc, it'd removed it and popped up a message saying that Combofix had been compromised by 'virut', then promptly vanished in a puff of logic.

    I've also noticed that my apps are dying on a daily basis... I'm worried that sooner or later my browser is gonna go kaput, then I'll be proper spannered. Is there owt I can do to cover my *** on this front? Download other browsers or somethin, or am I just in panic mode?

    Anyhows, thanks for all the help so far.
     
  6. defdex

    defdex Private E-2

    Forgot to attach the dialogs.
    Now attached.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    IMPORTANT NOTE: Some if not many, of your Windows system files are infected. And many other non-Windows files could also be infected. Even if we attempt to fix these problems (which may not be easy to do unless you have an original Windows XP SP3 bootable CD), your system may be unreliable and untrustworthy.You may need to reinstall this system.

    Your logs show that your Windows Operating system files have become infected and there is no known reliable fix for this. In addition there are many many other infected files. We could spend a lot of time trying to remove this infection, but odds are that it will not work because the nature of the infection has so many executable system files infected that as soon as we fix one file, other files that are infected will almost immediately or upon the next reboot, just reinfect the files. In addition, your PC would still basically be unreliable/untrustworthy even if we manage to fix the infected files that we can see since there could be many more that we are not seeing.

    The safest thing for you to do is backup your personal data immediately since your PC could possible become unbootable at any point in time. Do not back up any executable files. This includes programs that you have downloaded since any of them could be infected.

    Once you backup, you need to perform a total reinstall of Windows and all other necessary software. DO NOT reinstall from any executable files you backed up because they are most likely infected.
     
  8. defdex

    defdex Private E-2

    Okay, thanks for that, I guess it's not great news, but it's kinda what I was expecting... and it'll probably end being way less hassle in the long run. I'll start cleaning up now.

    Thanks for your help man.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are welcome. Sorry we couldn't do more.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds