BleepingComputer.com: Win32/Sality. NAQ Virus

Jump to content

Forum Rules

When posting your problem, do not run and post a ComboFix log. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.


If you have not received help after three days, please post a link to your topic HERE.
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Win32/Sality. NAQ Virus Laptop infected

#1 User is offline   asterias 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 1
  • Joined: 04-April 10

Posted 05 April 2010 - 12:04 AM

Hi

I am having an infection on my laptop.

These are some of the symptoms that I see:

1. I have ESET NOD32. On startup it says "

Threat Found
C:\windows\system32\drivers\mpfqn.sys

Threat : win32/sality.NAQ virus

2. I cant open msconfig or regedit or task manager

3. Any thumb drive placed into the laptop, automatically has folders like newfolder.exe

4. Can't even open bleepingcomputer.com/forums from the infected laptop. As soon as this page opens, the browser window (google chrome) automatically closes

Please, can some one help me fix it

#2 User is offline   quietman7 

  • Bleepin' Janitor
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 25,514
  • Joined: 09-July 05
  • Gender:Male
  • Location:Virginia, USA

Posted 05 April 2010 - 07:34 AM

I'm afraid I have very bad news. Your system is infected with a nasty variant of Win32/Sality. This family of malware is a polymorphic file infector which infects .exe, .scr files, downloads more malicious files to your computer, steals sensitive system information/passwords and sends it back to the attacker.

Please see Kaspersky's Threat Encyclopaedia of Win32.Sality.NAO.

With this particular infection, the safest solution and only sure way to remove it effectively is to reformat and reinstall the OS.

Quote

As with many other malware, Sality disables antivirus software and prevents access to certain antivirus and security websites. Sality can also prevent booting into Safe Mode and may delete security-related files found on infected systems. To spread via the autorun component, Sality generally drops a .cmd, .pif, and .exe to the root of discoverable drives, along with an autorun.inf file which contains instructions to load the dropped file(s) when the drive is accessed.
About Sality Virus

If the computer was used for online banking, has credit card information or other sensitive data on it, you should disconnect from the Internet until your system is cleaned. All passwords should be changed immediately to include those used for banking, email, eBay, paypal and online forums. You should consider them to be compromised and change each password using a clean computer and not the infected one. If not, an attacker may get the new passwords and transaction information. Banking and credit card institutions should be notified immediately of the possible security breach.Because your computer was compromised please read:Since Win32.Sality is not effectively disinfectable, your best option is to perform a full reformat as there is no guarantee this infection can be completely removed. In most instances it may have caused so much damage to your system files that it cannot be completely cleaned or repaired. In many cases the infected files cannot be deleted and anti-malware scanners cannot disinfect them properly. Many experts in the security community believe that once infected with this type of malware, the best course of action is to wipe the drive clean, reformat and reinstall the OS. Reinstalling Windows without first wiping the entire hard drive with a repartition and/or format will not remove the infection. The reinstall will only overwrite the Windows files. Any malware on the system will still be there afterwards. Please read:
Microsoft MVP - Consumer Security 2007-2012 Posted Image
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

#3 User is offline   MMMM2424 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 7
  • Joined: 18-October 08

Posted 29 December 2010 - 11:35 AM

Hello, can anyone please expand on Quietman7 qoute " Reinstalling Windows without first wiping the entire hard drive with a repartition and/or format will not remove the infection."
Basically, my computer has a recovery partition, as well as 3 recovery dvd's that I created.

So if I had virut or sality, would restoring the computer using the recovery dvd's to its factory settings, NOT guarantee the removal of the virus ?

Also I used the windows 7 utility to create an image of my pc, which is stored on an external hard drive, would restoring to that image,NOT guarantee the removal of the virus ?
Thank you very much for explaing ths to me, I would appreciate it.
Do the two methods I have mentioned, actually wipe the original hard drive, or just write on top, thus leaving the infection

#4 User is offline   quietman7 

  • Bleepin' Janitor
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 25,514
  • Joined: 09-July 05
  • Gender:Male
  • Location:Virginia, USA

Posted 29 December 2010 - 05:25 PM

If you're not sure how to reformat and reinstall Windows, please review:
These links include specific step-by-step instructions with screenshots:
Vista users can refer to these instructions:
Windows 7 users can refer to these instructions:

Quote

So if I had virut or sality, would restoring the computer using the recovery dvd's to its factory settings, NOT guarantee the removal of the virus ?
Depends on whether the recovery partition itself was not infected. If so, you would need to contact the manufacturer, explain what happened and ask them to send full recovery disks to use instead. If you lost or misplaced your recover disks, again you can contact and advise the manufacturer. In many cases they will send replacements as part of their support.

If you have made a disk image with an imaging tool (i.e. Acronis True Image, Drive Image, Ghost, Macrium Reflect, etc.) before your system was infected, then using it is another option. Disk Imaging allows you to take a complete snapshot (image) of your hard disk which can be used for system recovery in case of a hard disk disaster or malware resistent to disinfection. The image is an exact, byte-by-byte copy of an entire hard drive (partition or logical disk) which can be used to restore your system at a later time to the exact same state the system was when you imaged the disk or partition. Essentially, it will restore the computer to the state it was in when the image was made. You will then have to reinstall all programs that you added afterwards. This includes all security updates and patches from Microsoft.
Microsoft MVP - Consumer Security 2007-2012 Posted Image
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

#5 User is offline   MMMM2424 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 7
  • Joined: 18-October 08

Posted 30 December 2010 - 02:12 PM

Many thanks Quietman7,I really appreciate your detailed answer and links.Very much appreciated

#6 User is offline   quietman7 

  • Bleepin' Janitor
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 25,514
  • Joined: 09-July 05
  • Gender:Male
  • Location:Virginia, USA

Posted 30 December 2010 - 04:31 PM

You're welcome.
Microsoft MVP - Consumer Security 2007-2012 Posted Image
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users