Solved

W32/NGVCK.a cleaning

Posted on 2004-09-27
6
1,068 Views
Last Modified: 2013-12-04
A friend has McAfee Virus Online.  A scan shows 534 files infected, mostly by NGVCK.a virus.

After running the scan, it says it can't clean the files, and gives me the opportunity to quarantine them.  However, some of them are system files and it seems like a quarantine would make the system inoperable.  

I am getting a Windows File Protection asking to replace some of the affected files if I've got the CD  (Home Edition).

What's the best way to clean this?
0
Comment
Question by:kellysmith120
  • 4
  • 2
6 Comments
 
LVL 38

Expert Comment

by:Rich Rumble
Comment Utility
McAfee Stinger...
http://vil.nai.com/vil/stinger/
-rich
0
 

Author Comment

by:kellysmith120
Comment Utility
Thanks, rich.  I saw the stinger from McAfee, but it doesn't specifically list the virus in question.  Also, the Online version I'm running detects the virus fine, but says they can't be fixed.
0
 
LVL 38

Accepted Solution

by:
Rich Rumble earned 50 total points
Comment Utility
Did you try stinger anyway?
I don't see any standalone remover's for this- but it's rumored that this tool could do it
http://securityresponse.symantec.com/avcenter/venc/data/w32.klez.removal.tool.html but not guarnteed

http://support.f-secure.com/enu/home/ols.shtml might be able to help...

This virus may be too much for a standalone tool to remove- if you have a friend with an updated AV product, perhaps you can bring your HD over to them, and install it in thier pc as a slave drive, and they can scan you HD and remove the files (like unblaster.exe)
TDS3 may also help you http://tds.diamondcs.com.au/index.php?page=download GL
-rich
0
IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

 

Author Comment

by:kellysmith120
Comment Utility
I've downloaded the stinger for her, but it seems pretty precise about the viruses it detects.

I have a full version of McAfee on line running, so I'm not sure why it wouldn't take care of it.  The only thing I can come up with is disabling the System Restore.  Most of the files aren't don't appear to be system restore locked, so that might not work either.

I'll try both solutions (System Restore and the removal tools).  If the System Restore doesn't fix it, and the tools do, I'll award the points.

Otherwise, to clarify and repeat the question - My virus software found infections with the NGVCK.a on system files (C:\winnt , etc.), and says it can't clean them, and I'm assuming that I can't just 'delete' them.  How do I remove the virus (using McAfee Online) from my system?
0
 

Author Comment

by:kellysmith120
Comment Utility
FYI - I will be out of town for a couple of days, but will check back  before I leave and again when I return.
0
 

Author Comment

by:kellysmith120
Comment Utility
Stinger didn't remove it.  She's given up and going to reformat it.  

The answer didn't help me, but I'll award them for maybe helping someone else who reads it and is unaware of Stinger.
0

Featured Post

What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

As I write this article, I am finishing cleanup from the Qakbot virus variant found in the wild on April 18, 2011.  It was a messy beast that had varying levels of infection, speculated as being dependent on how long it resided on the infected syste…
Many people tend to confuse the function of a virus with the one of adware, this misunderstanding of the basic of what each software is and how it operates causes users and organizations to take the wrong security measures that would protect them ag…
This tutorial demonstrates a quick way of adding group price to multiple Magento products.
This video demonstrates how to create an example email signature rule for a department in a company using CodeTwo Exchange Rules. The signature will be inserted beneath users' latest emails in conversations and will be displayed in users' Sent Items…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now