Windows, Operating System, Security, Networking, Malware, Support, Forum, Help Site Check Our Facebook Page!


Register your FREE account to unlock additional features at
LinkBack Thread Tools
Old 27th November 2009   #1
Senior Member
Join Date: Jun 2009
Posts: 60
Computer Experience:
Pops Reputation Level

My System

[Incurable] Virut Virus?

I am stuck! First of all, I am posting from a clean computer, not the computer with the problem. A somewhat brief history: The system with the problem came to me from my son-in-law already infected. I have jumoed through MANY different hoops trying to clean it, using various tools.

Right now I have two immediate problems. First, the system will not boot into safe mode. When I attempt to do that, it jsut returns to the menu of boot choices. Second, when attempting to boot up normally I get an error message "Mpnotify.exe application error. The memory could not be written". When I click on OK, I then get a empty blue screen , no desktop at all. If I continue to reboot, generally after about 12 attemts it will boot up. However, the system is highly compromised. Google is some version from the Netherlands so doing searchnes is next to impossible. If I use a different search engine to try and download a tool, I am forced off to a different website.

I did download from a clean computer a Kaspersky Recovery CD and booted with it and ran the scan. It showed a multitude of viruses, but one of them was the Viryt virus. It said it cleaned it, but I don't think it truly did. Much of the research I have done online strongly suggest I am still dealing with remnants of the Virut, especially the inability to boot into Safe Mode.

There are any number of other signs and symptoms but I thought I would start here and see if anyone has ideas for me. I need to avoid a reformat as my son-in-law has no backup (a future lesson n safe computing is coming his way) and he absolutely needs the data files on the system.

I am stuck folks and have on this issue for 5 days now. I would appreciate any and all help anyone could offer me!

Pops is offline  
Old 27th November 2009   #2
Lifetime Subscription
Geri's Avatar
Join Date: Mar 2003
Location: Washington State
Posts: 4,580
Computer Experience:
Often it's like Taz
Geri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation Level

My System
Virut, a polymorphic file infector with IRCBot functionality which infects .exe, .scr files, downloads more malicious files to your system, and opens a back door that compromises your computer.

With this particular infection, the safest solution and only sure way to remove it effectively is to reformat and reinstall the OS.

Some variants can infect the HOSTS file and block access to security related web sites. Other variants of virut can even penetrate and infect .exe files within compressed files (.zip, .cab, rar). The Virux and Win32/Virut.17408 variants are an even more complex file infectors which can embed an iframe into the body of web-related files and infect script files (.php, .asp, .htm, .html, .xml). When Virut creates infected files, it also creates non-functional files that are corrupted beyond repair and in some instances can disable Windows File Protection. In many cases the infected files cannot be disinfected properly by your anti-virus. When disinfection is attempted, the files become corrupted and the system may become irreparable. The longer virut remains on a computer, the more critical system files will become infected and corrupt so the degree of infection can vary.

The virus disables Windows File Protection by injecting code into the "winlogon.exe" process that patches system code in memory.
CA Virus detail of W32/Virut

The virus has a number of bugs in its code, and as a result it may misinfect a proportion of executable files....some W32/Virut.h infections are corrupted beyond repair.
McAfee Risk Assessment and Overview of W32/Virut

There are bugs in the viral code. When the virus produces infected files, it also creates non-functional files that also contain the virus...Due to the damaged caused to files by virut it's possible to find repaired but corrupted files. They became corrupted by the incorrect writing of the viral code during the process of infection. undetected, corrupted files (possibly still containing part of the viral code) can also be found. this is caused by incorrectly written and non-function viral code present in these files.
AVG Overview of W32/VirutThis kind of infection is often contracted and spread by visiting remote, crack and keygen sites. These type of sites are infested with a smörgåsbord of malware and a major source of system infection.

...warez and crack web pages are being used by cybercriminals as download sites for malware related to VIRUT and VIRUX. Searches for serial numbers, cracks, and even antivirus products like Trend Micro yield malcodes that come in the form of executables or self-extracting files...quick links in these sites also lead to malicious files. Ads and banners are also infection vectors...
Keygen and Crack Sites Distribute VIRUX and FakeAV

However, the CA Security Advisor Research Blog have found MySpace user pages carrying the malicious Virut URL. Either way you can end up with a computer system so badly damaged that recovery is not possible and it cannot be repaired. When that happens there is nothing you can do besides reformatting and reinstalling the OS.

If your computer was used for online banking, has credit card information or other sensitive data on it, you should disconnect from the Internet until your system is cleaned. All passwords should be changed immediately to include those used for banking, email, eBay, paypal and online forums. You should consider them to be compromised. You should change each password using a clean computer and not the infected one. If not, an attacker may get the new passwords and transaction information. If using a router, you need to reset it with a strong logon/password so the malware cannot gain control before connect again. Banking and credit card institutions should be notified of the possible security breach. Because your computer was compromised please read:Since virut is not effectively disinfectable, your best option is to perform a full reformat as there is no guarantee this infection can be completely removed. In most instances it may have caused so much damage to your system files that it cannot be completely cleaned or repaired. In many cases the infected files cannot be deleted and anti-malware scanners cannot disinfect them properly. Many experts in the security community believe that once infected with this type of malware, the best course of action is to reformat and reinstall the OS. Reinstalling Windows without first wiping the entire hard drive with a repartition and/or format will not remove the infection. The reinstall will only overwrite the Windows files. Any malware on the system will still be there afterwards. Please read:

Geri is offline  



Are you having the same problem? Please post a new thread, but first you'll have to join us by Registering (FREE).

Discussion Forums
Operating Systems
Windows 10 Windows 10
Windows 8 Windows 8
Windows 7 Windows 7
Windows Vista Windows Vista
Windows XP Windows XP
Windows Server System Windows Server System
Legacy Windows OS Legacy Windows OS
Internet & Networking
Networking (Hardware & Software) Networking
Internet Explorer Internet Explorer
Microsoft Mail Microsoft Mail
Firefox, Thunderbird & SeaMonkey Firefox, Thunderbird
      & SeaMonkey

Web Applications & Cloud Web Applications & Cloud
General Internet
Malware and Virus Removal Malware and Virus

Security and Privacy Security and Privacy

Other PC Software Other PC Software
Test Posts Test Posts
PC Hardware PC Hardware
Mobile Devices Mobile Devices
Introductions Introductions
General Discussions General Discussions
Site Comments & Suggestions Site Comments
      & Suggestions

News News @ WindowsBBS

Thread Tools

Find us on Facebook   Web Of Trust Rating

All times are GMT. The time now is 19:02.

Recent Discussions
Scroll bar (10)
Windows will not recogniz.. (0)
Oh, the Clarity of Window.. (0)
Switches are not working .. (2)
Problem With File Explore.. (3)
Removing Cloud Services i.. (4)
Is there no way to really.. (10)
[Restore Outlook personal.. (1)
iPhone Monitoring (2)
Mouse or keyboard won't w.. (8)
Microsoft yanks latest Wi.. (22)
New Updates (1)
How to open a file always.. (6)
Reasons for Holiday Weeke.. (7)
How Do I Get a Faster Int.. (5)
Win 10 - Start screen is .. (11)
Error opening file for wr.. (1)
Does Edge Work Better tha.. (18)
I just don't like certain.. (12)
Recovery Flash drive, sho.. (4)

Support Windows BBS!

Powered by vBulletin® Copyright ©2000 - 2015, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO
Copyright © 2002 - 2015 All rights reserved.
Terms of Use, Legal Information & Privacy Policy
Page generated in 0.10708 seconds with 7 queries