Natas-virus

  • Thread starter Thread starter TaxiBUS
  • Start date Start date
T

TaxiBUS

Hi Folks!

Can someone please help me? It seems that I have the Natas-virus in my PC...
This Natas-virus is a memory-resident virus.
I know that there is a trick with FDISK... but what was it again?
I work with ME.

Please?

TaxiBUS
 
From: "TaxiBUS" <[email protected]>

| Hi Folks!
|
| Can someone please help me? It seems that I have the Natas-virus in my PC...
| This Natas-virus is a memory-resident virus.
| I know that there is a trick with FDISK... but what was it again?
| I work with ME.
|
| Please?
|
| TaxiBUS
|

Natas ?

That's been around for more than 10 years !

Download CLEAN.EXE from the URL --
http://www.ik-cs.com/programs/virtools/clean.exe

It is a self-extracting ZIP file that contains the Kixtart Script Interpreter
{ http://kixtart.org Kixtart is CareWare } three batch files, two Kixtart scripts, two Link
(.lnk) files and a PDF instruction file.

GETFILES.BAT -- For downloading (FTP) the files needed to run the McAfee Command Line
Scanner. If you are using Windows XP, you may have to disable the Windows XP FireWall to
allow the FTP utility to download the needed files

CLEAN.BAT -- For running within Windows after running c:\mcafee\GetFiles.BAT. If you choose
to scan again at a future date, run this batch file. It will automatically check the date
of the McAfee DAT files and if it is a couple of days old, it will download (FTP) the latest
signature files and install them before performing the scan.

DOSCLEAN.BAT -- For use on a Win9x/ME PC or on a Win2K/WinXP PC that is using FAT32 after
you have booted from an Emergency Boot Disk or DOS disk and have already executed;
c:\mcafee\GetFiles.BAT from within Windows. DOS disk boot images can be obtained from;
http://www.bootdisk.com/bootdisk.htm

I need you to perform the following...

Execute; CLEAN.EXE
Choose; Unzip
Choose; Close

Execute; c:\mcafee\GetFiles.BAT
{ or Double-click on 'GetFiles Link' in c:\mcafee }

Reboot the PC using a WinME Emergency Bootdisk or a disk image from
http://www.bootdisk.com/bootdisk.htm

After you boot from the floppy,
Execute; c:\mcafee\DOSCLEAN.BAT

A final report in HTML format called C:\mcafee\ScanReport.HTML will be generated.
 
TaxiBUS said:
Can someone please help me? It seems that I have the Natas-virus in my PC...
This Natas-virus is a memory-resident virus.
I know that there is a trick with FDISK... but what was it again?
I work with ME.

Please?

What AV claims that you have Natas? Except a message from some antivirus, what
are the symptoms of the infection. Where exactly did your AV detect Natas? In
the MBR, a file, or in memory?

Note that it's highly probable that you are dealing with a false alarm!

Natas is a very old (from early nineties) multipartite. It affects 16 bit
COM/EXE files, the MBR, and is one of the few multi-partites that can affect the
boot sector of floppies (through a complex sequence that doesn't always work).
Natas also uses full stealth, in both its boot routines, and the executables.

Before you engage on a wild goose chase, and harm your drive content and files,
may I suggest that you refrain from attempting anything before getting a second
opinion from some other AV.

Follows the report from www.virustotal.com on a NATAS sample that you can choose
which AV to use as "second opinion". As you can see, all detected Natas except
ClamAV:
This is a report processed by VirusTotal on 05/13/2005 at 08:43:20 (CET) after scanning the file "natas.com" file.

Antivirus Version Update Result
AntiVir 6.30.0.12 05.12.2005 Natas.4774.Boot
AVG 718 05.12.2005 Natas.4744
Avira 6.30.0.12 05.12.2005 Natas.4774.Boot
BitDefender 7.0 05.13.2005 Natas.4744.A
ClamAV devel-20050501 05.13.2005 no virus found
DrWeb 4.32b 05.13.2005 Natas.4744
eTrust-Iris 7.1.194.0 05.12.2005 Natas.4764
eTrust-Vet 11.9.1.0 05.13.2005 Natas.4744
Fortinet 2.51 05.13.2005 Natas.mp.4744
Ikarus 2.32 05.12.2005 Natas.4744-boot
Kaspersky 4.0.2.24 05.13.2005 Virus.Boot-DOS.Natas.4744
McAfee 4490 05.12.2005 Natas.mp.4744a
NOD32v2 1.1094 05.12.2005 Natas.4744.A
Norman 5.70.10 05.12.2005 Natas.A-G.4744
Panda 8.02.00 05.12.2005 Natas.4744
Sybari 7.5.1314 05.13.2005 Natas-b
Symantec 8.0 05.12.2005 Satan Bug.Natas.4744
VBA32 3.10.3 05.12.2005 Natas.4740

Regards, Zvi
 
From: "TaxiBUS" <[email protected]>

| Hi Folks!
|
| Can someone please help me? It seems that I have the Natas-virus in my PC...
| This Natas-virus is a memory-resident virus.
| I know that there is a trick with FDISK... but what was it again?
| I work with ME.
|
| Please?
|
| TaxiBUS
|

We never did hear back from you ?

Please update the thread.
 
Back
Top