This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Infected by Win32:Virut ...

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

while i was browsing a week ago, suddenly NOD32 started going crazy… almost all of my .EXE files were infected by Win32:Virut , and it couldn't Heal the files, neither delete them. So i uninstalled nod32 and installed Avast Antivirus… I ran startup-scan 2 times already on my hard drive, but it only deleted files infected by Win32:JunkPoly (Cryp) … When i logged in back to windows, all of my core system files were infected by win32:Virut (pop-ups by avast…) IEXPLORE.EXE , svchost.exe , explorer.exe , taskmgr.exe and so on… the strange thing is, that avast didn't find any file during startup scan that was infected by win32:virut , and when i logged in, everything was messed up… i read in the site of ESET nod32 that if you are infected by win32:virut, the only solution is FORMAT… but the problem is, i have 400GB of files i want to save from deletion…If i just backup them to a external drive and there's a .EXE in these files, then my pc will still be infected after i restore the files to the formatted hard drive… So…i want some Help: How can i Backup all these files without infecting the external drive? I thought just Not To Transfer Any .exe on the external… Thanks :)
coreygaylas,

Your System is infected with Virut!!
Virut is a file infecting virus which is able to modify itself each and every time it runs. In addition, when it infects, sometimes it will destroy the file it tries to latch onto.
For these reasons, you really can't truly fix Virut. You will need to format/reinstall the operating system on this machine.

More information:
http://free.avg.com/66558

There are bugs in the viral code. When the virus produces infected files, it also creates non-functional files that also contain the virus.


http://home.mcafee.com/VirusInfo/VirusProf…aspx?key=143034

W32/Virut.h is a polymorphic, entry point obscuring (EPO) file infector with IRC bot functionality. It can accept commands to download other malware on the compromised machine.
It appends to the end of the last section of executable (PE) files an encrypted copy of its code. The decryptor is polymorphic and can be located either:
Immediately before the encrypted code at the end of the last section
At the end of the code section of the infected host in 'slack-space' (assuming there is any)
At the original entry point of the host (overwriting the original host code)


Miekiemoes, an expert for malware removal, and an MS-MVP, additionally has a blog post about Virut.

I suggest you to start backup all of your valuable data/documents/pictures/movies/songs/etc..
Do NOT backup any applications/installers and Do NOT backup any .exe/.scr/.htm/.html/.xml/.zip/.rar files…
This because these files may be infected as well. If you back them up and replace them afterwards, it will infect your computer again.

Read here for instructions how to format and reinstall Windows
:

http://web.mit.edu/ist/products/winxp/adva…all-format.html
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI