![]() ![]() |
Jul 4 2009, 04:58 AM
Post
#1
|
|
|
New Member ![]() Group: New Member Posts: 4 Joined: 4-July 09 Member No.: 86,537 Operating System: XP |
Edit: topic moved to HJT removal - CB
Reason for edit: Moved to HJT removal
|
|
|
|
Jul 4 2009, 05:20 AM
Post
#2
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,924 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi,
First we need to verify that you do indeed have virut. If this is the case. There is nothing to do but reformat and re-install your operating system as virut is a polymorphic file infector and will have destroyed pretty much every file on your system. Please do the following:
Please do the same for the following files: c:\windows\system32\userinit.exe |
|
|
|
Jul 4 2009, 05:45 AM
Post
#3
|
|
|
New Member ![]() Group: New Member Posts: 4 Joined: 4-July 09 Member No.: 86,537 Operating System: XP |
I scanned all those files and did'nt find nothing , but i am running windows in safe mode because in normal mode the internet explorer wont open , does that afect the scan ?
|
|
|
|
Jul 4 2009, 05:47 AM
Post
#4
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,924 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
It shouldn't. - what program told you that you had virut.
If you have any logs from all of the scans you have performed (especially Dr.Web - please post them) |
|
|
|
Jul 4 2009, 05:58 AM
Post
#5
|
|
|
New Member ![]() Group: New Member Posts: 4 Joined: 4-July 09 Member No.: 86,537 Operating System: XP |
here's the log file , i told you , in normal mode i cannot run any program , should i reinstall my OS ? and ofcourse delete all the .exe-s that i have on the other drive ?
... i restarted the computer and it turned on in normal mode , and when i retried to restart i see and error message that says You don't have the permision to shut down the computer , when i try to open something there's also an error message that says : this program doesnt have any asociated program to open or something like that , now i can see only the wallpaper This post has been edited by zb3ngyu: Jul 4 2009, 06:21 AM
Attached File(s)
|
|
|
|
Jul 4 2009, 06:26 AM
Post
#6
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,924 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi,
Virut cannot be cleaned - regardless of what the scanner says about removing the infection. There are always traces left that will eventually respawn. You will need to do a total reformat/reinstall... I will post my usual explanation for virut: VIRUTis a polymorphic file infector with some additional features. It spreads all around the drive and infects even files infected by another virus previously. Unfortunately, the cleaning of this virus is not recommended. The only thing we recommend is to do a full reformat and install. We have an excellent tutorial on how to reformat here Things to bear in mind, only back up data files (word, excell etc.) DO NOT backup any .exe/.scr/.htm/.html/.xml/.zip/.pif/.com/.rar files... as they could all be infected and will simply re-infect your system again, there is no way of being certain what this infection can do. Read more about the VIRUT FILE INFECTOR HERE If you don't have a Windows Installation Disk (if this came with Windows pre-installed), you may have a Manufacturer restore disk to restore the computer to its original state - this depends on the Manufacturer though. Otherwise, give the Manufacturer a call and ask them to send you a restore disk or Windows installation CD. Here is a guide on backing up your data; Although you can use whatever method you prefer. Do not back up to another machine, as it may become compromised. Burn to DVD/CD, or to an external drive which has nothing else on it, and which you can format should it happen to become infected from the backups. Should you have any questions, please feel free to ask. I am sorry there is nothing more that we can do. More information: QUOTE http://free.avg.com/66558 There are bugs in the viral code. When the virus produces infected files, it also creates non-functional files that also contain the virus. http://home.mcafee.com/VirusInfo/VirusProf...aspx?key=143034 W32/Virut.h is a polymorphic, entry point obscuring (EPO) file infector with IRC bot functionality. It can accept commands to download other malware on the compromised machine. It appends to the end of the last section of executable (PE) files an encrypted copy of its code. The decryptor is polymorphic and can be located either: Immediately before the encrypted code at the end of the last section At the end of the code section of the infected host in 'slack-space' (assuming there is any) At the original entry point of the host (overwriting the original host code) Miekiemoes, a highly regarded expert in malware removal, and an MS-MVP, has an extremely informative blog post about Virut. - she only ever recommends a total reformat. At least this way, you have the best chance of having a clean machine once more. For future protection read this very well written article Think Prevention. |
|
|
|
Jul 4 2009, 06:31 AM
Post
#7
|
|
|
New Member ![]() Group: New Member Posts: 4 Joined: 4-July 09 Member No.: 86,537 Operating System: XP |
Thank you very much for your time i already started to reinstall .
|
|
|
|
Jul 4 2009, 06:32 AM
Post
#8
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,924 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Good Luck,
At least this way, you will have a clean machine again. |
|
|
|
Jul 4 2009, 07:25 PM
Post
#9
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,924 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Since this issue appears to be resolved ... this Topic has been closed. Glad we could be of assistance.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic. |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
20 | Wakenaam | 361 | Yesterday, 09:54 AM Last post by: Tomk |
|||
![]() |
16 | mesa215 | 281 | Yesterday, 12:05 AM Last post by: Raktor |
|||
![]() |
17 | stjohn | 353 | 19th November 2009 - 06:17 PM Last post by: CatByte |
|||
![]() |
57 | VanDavies | 656 | 19th November 2009 - 05:20 PM Last post by: CatByte |
|||
|
Time is now: 21st November 2009 - 05:13 AM |