1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

[Incurable] Virut Virus?

Discussion in 'Malware and Virus Removal Archive' started by Pops, 2009/11/27.

  1. 2009/11/27
    Pops

    Pops Inactive Thread Starter

    Joined:
    2009/06/03
    Messages:
    60
    Likes Received:
    0
    I am stuck! First of all, I am posting from a clean computer, not the computer with the problem. A somewhat brief history: The system with the problem came to me from my son-in-law already infected. I have jumoed through MANY different hoops trying to clean it, using various tools.

    Right now I have two immediate problems. First, the system will not boot into safe mode. When I attempt to do that, it jsut returns to the menu of boot choices. Second, when attempting to boot up normally I get an error message "Mpnotify.exe application error. The memory could not be written ". When I click on OK, I then get a empty blue screen , no desktop at all. If I continue to reboot, generally after about 12 attemts it will boot up. However, the system is highly compromised. Google is some version from the Netherlands so doing searchnes is next to impossible. If I use a different search engine to try and download a tool, I am forced off to a different website.

    I did download from a clean computer a Kaspersky Recovery CD and booted with it and ran the scan. It showed a multitude of viruses, but one of them was the Viryt virus. It said it cleaned it, but I don't think it truly did. Much of the research I have done online strongly suggest I am still dealing with remnants of the Virut, especially the inability to boot into Safe Mode.

    There are any number of other signs and symptoms but I thought I would start here and see if anyone has ideas for me. I need to avoid a reformat as my son-in-law has no backup (a future lesson n safe computing is coming his way) and he absolutely needs the data files on the system.

    I am stuck folks and have on this issue for 5 days now. I would appreciate any and all help anyone could offer me!
     
    Pops,
    #1
  2. 2009/11/27
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Virut, a polymorphic file infector with IRCBot functionality which infects .exe, .scr files, downloads more malicious files to your system, and opens a back door that compromises your computer.

    With this particular infection, the safest solution and only sure way to remove it effectively is to reformat and reinstall the OS.

    Some variants can infect the HOSTS file and block access to security related web sites. Other variants of virut can even penetrate and infect .exe files within compressed files (.zip, .cab, rar). The Virux and Win32/Virut.17408 variants are an even more complex file infectors which can embed an iframe into the body of web-related files and infect script files (.php, .asp, .htm, .html, .xml). When Virut creates infected files, it also creates non-functional files that are corrupted beyond repair and in some instances can disable Windows File Protection. In many cases the infected files cannot be disinfected properly by your anti-virus. When disinfection is attempted, the files become corrupted and the system may become irreparable. The longer virut remains on a computer, the more critical system files will become infected and corrupt so the degree of infection can vary.

    CA Virus detail of W32/Virut

    McAfee Risk Assessment and Overview of W32/Virut

    AVG Overview of W32/VirutThis kind of infection is often contracted and spread by visiting remote, crack and keygen sites. These type of sites are infested with a smörgåsbord of malware and a major source of system infection.

    Keygen and Crack Sites Distribute VIRUX and FakeAV

    However, the CA Security Advisor Research Blog have found MySpace user pages carrying the malicious Virut URL. Either way you can end up with a computer system so badly damaged that recovery is not possible and it cannot be repaired. When that happens there is nothing you can do besides reformatting and reinstalling the OS.

    If your computer was used for online banking, has credit card information or other sensitive data on it, you should disconnect from the Internet until your system is cleaned. All passwords should be changed immediately to include those used for banking, email, eBay, paypal and online forums. You should consider them to be compromised. You should change each password using a clean computer and not the infected one. If not, an attacker may get the new passwords and transaction information. If using a router, you need to reset it with a strong logon/password so the malware cannot gain control before connect again. Banking and credit card institutions should be notified of the possible security breach. Because your computer was compromised please read:Since virut is not effectively disinfectable, your best option is to perform a full reformat as there is no guarantee this infection can be completely removed. In most instances it may have caused so much damage to your system files that it cannot be completely cleaned or repaired. In many cases the infected files cannot be deleted and anti-malware scanners cannot disinfect them properly. Many experts in the security community believe that once infected with this type of malware, the best course of action is to reformat and reinstall the OS. Reinstalling Windows without first wiping the entire hard drive with a repartition and/or format will not remove the infection. The reinstall will only overwrite the Windows files. Any malware on the system will still be there afterwards. Please read:
     
    Geri,
    #2

  3. to hide this advert.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.