[Resolved] hard drive locked to scandisk and updater not functional
3 min read
Please do the following:
- Make sure to use Internet Explorer for this
- Please go to VirSCAN.org FREE on-line scan service
- Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:
c:\windows\system32\userinit.exe
- Click on the Upload button
- If a pop-up appears saying the file has been scanned already, please select the ReScan button.
- Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
- Paste the contents of the Clipboard in your next reply.
Please do the same for the following files:
c:\windows\explorer.exe
c:\windows\system32\ctfmon.exe
C:\Windows\System32\reader_s.exe
Thanks for the help.
VirSCAN.org Scanned Report :
Scanned time : 2009/11/26 20:11:36 (CST)
Scanner results: 68% Scanner(s) (25/37) found malware!
File Name : userinit.exe
File Size : 45056 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : dad51f54c067421f788c54ac1b444efb
SHA1 : 2fd829a409f268b788313127db9c8a4a17012f16
Online report : http://virscan.org/report/a57fa6850dad5954…b85444a5e8.html
Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20091127013202 2009-11-27 6.25 -
AhnLab V3 2009.11.27.00 2009.11.27 2009-11-27 1.82 Win32/Virut.F
AntiVir 8.2.1.78 7.10.1.111 2009-11-26 0.39 W32/Virut.Gen
Antiy 2.0.18 20091126.3315741 2009-11-26 0.12 -
Arcavir 2009 200911261756 2009-11-26 0.04 -
Authentium 5.1.1 200911261932 2009-11-26 1.25 W32/Virut.AI!Generic (Heuristic)
AVAST! 4.7.4 091126-1 2009-11-26 0.01 Win32:Vitro
AVG 8.5.288 270.14.83/2529 2009-11-27 0.45 Win32/Virut
BitDefender 7.81008.4634482 7.29156 2009-11-27 4.04 Win32.Virtob.Gen.12
CA (VET) 35.1.0 7143 2009-11-25 14.06 Win32/Virut.17408 virus.
ClamAV 0.95.2 10085 2009-11-27 0.02 -
Comodo 3.12 3049 2009-11-26 0.88 -
CP Secure 1.3.0.5 2009.11.26 2009-11-26 0.13 -
Dr.Web 4.44.0.9170 2009.11.26 2009-11-26 7.16 Win32.Virut.56
F-Prot 4.4.4.56 20091126 2009-11-26 1.22 Possible W32/Virut.AI!Generic
F-Secure 7.02.73807 2009.11.26.07 2009-11-26 5.75 Virus.Win32.Virut.ce [AVP]
Fortinet 11.98- 11.98 2009-11-26 0.14 -
GData 19.9019/19.587 20091127 2009-11-27 11.53 Virus.Win32.Virut.ce [Engine:A]
ViRobot 20091126 2009.11.26 2009-11-26 0.79 -
Ikarus T3.1.01.74 2009.11.27.74602 2009-11-27 4.77 -
JiangMin 11.0.800 2009.11.25 2009-11-25 7.21 -
Kaspersky 5.5.10 2009.11.27 2009-11-27 0.09 Virus.Win32.Virut.ce
KingSoft 2009.2.5.15 2009.11.26.19 2009-11-26 0.65 Win32.Virut.cr.61440
McAfee 5.3.00 5814 2009-11-26 3.65 W32/Virut.n.gen
Microsoft 1.5302 2009.11.26 2009-11-26 7.22 Virus:Win32/Virut.gen!O
Norman 6.01.09 6.01.00 2009-11-25 2.02 W32/Virut.DY
Panda 9.05.01 2009.11.26 2009-11-26 5.54 W32/Sality.AO
Trend Micro 9.000-1003 6.654.07 2009-11-27 0.04 PE_VIRUX.J
Quick Heal 10.00 2009.11.26 2009-11-26 1.82 W32.Virut.G
Rising 20.0 22.23.04.01 2009-11-27 1.67 Win32.Virut.cs
Sophos 3.01.0 4.47 2009-11-27 3.11 W32/Virut-AA
Sunbelt 5518 5518 2009-11-18 4.66 Virus.Win32.Virut.ce (v)
Symantec 1.3.0.24 20091126.016 2009-11-26 0.42 W32.Virut.CF
nProtect 20091125.01 6330100 2009-11-25 5.76 -
The Hacker 6.5.0.2 v00079 2009-11-26 1.52 -
VBA32 3.12.12.0 20091125.2123 2009-11-25 2.15 Virus.Win32.Virut.X7
VirusBuster 4.5.11.10 10.113.30/2005475 2009-11-26 2.96 Win32.Virut.AB.Gen
**********************************************************
VirSCAN.org Scanned Report :
Scanned time : 2009/11/26 20:23:30 (CST)
Scanner results: 65% Scanner(s) (24/37) found malware!
File Name : ctfmon.exe
File Size : 28672 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 990815a040003ac3acb2e96f0b220e8c
SHA1 : 808197ed08246b783eb7bdbd59ef186489dcc904
Online report : http://virscan.org/report/e2f977e7f679d1ff…271166b67a.html
Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20091127013202 2009-11-27 11.09 -
AhnLab V3 2009.11.27.00 2009.11.27 2009-11-27 1.23 -
AntiVir 8.2.1.78 7.10.1.111 2009-11-26 0.27 W32/Virut.Gen
Antiy 2.0.18 20091126.3315741 2009-11-26 0.12 -
Arcavir 2009 200911261756 2009-11-26 0.04 -
Authentium 5.1.1 200911261932 2009-11-26 1.25 W32/Virut.AI!Generic (Heuristic)
AVAST! 4.7.4 091126-1 2009-11-26 0.01 Win32:Vitro
AVG 8.5.288 270.14.83/2529 2009-11-27 0.42 Win32/Virut
BitDefender 7.81008.4634482 7.29156 2009-11-27 4.02 Win32.Virtob.Gen.12
CA (VET) 35.1.0 7143 2009-11-25 32.89 Win32/Virut.17408 virus.
ClamAV 0.95.2 10085 2009-11-27 0.01 -
Comodo 3.12 3049 2009-11-26 2.23 -
CP Secure 1.3.0.5 2009.11.26 2009-11-26 0.05 -
Dr.Web 4.44.0.9170 2009.11.26 2009-11-26 7.21 Win32.Virut.56
F-Prot 4.4.4.56 20091126 2009-11-26 1.25 Possible W32/Virut.AI!Generic
F-Secure 7.02.73807 2009.11.26.07 2009-11-26 9.30 Virus.Win32.Virut.ce [AVP]
Fortinet 11.98- 11.98 2009-11-26 0.16 -
GData 19.9019/19.587 20091127 2009-11-27 7.54 Virus.Win32.Virut.ce [Engine:A]
ViRobot 20091126 2009.11.26 2009-11-26 0.70 -
Ikarus T3.1.01.74 2009.11.27.74602 2009-11-27 4.21 -
JiangMin 11.0.800 2009.11.25 2009-11-25 14.02 -
Kaspersky 5.5.10 2009.11.27 2009-11-27 0.07 Virus.Win32.Virut.ce
KingSoft 2009.2.5.15 2009.11.27.7 2009-11-27 0.55 Win32.Virut.cr.61440
McAfee 5.3.00 5814 2009-11-26 3.52 W32/Virut.n.gen
Microsoft 1.5302 2009.11.26 2009-11-26 8.34 Virus:Win32/Virut.gen!O
Norman 6.01.09 6.01.00 2009-11-25 2.01 W32/Virut.DY
Panda 9.05.01 2009.11.26 2009-11-26 2.26 W32/Sality.AO
Trend Micro 9.000-1003 6.654.07 2009-11-27 0.04 PE_VIRUX.J
Quick Heal 10.00 2009.11.26 2009-11-26 2.04 W32.Virut.G
Rising 20.0 22.23.04.01 2009-11-27 1.63 Win32.Virut.cs
Sophos 3.01.0 4.47 2009-11-27 3.09 W32/Virut-AA
Sunbelt 5518 5518 2009-11-18 2.86 Virus.Win32.Virut.ce (v)
Symantec 1.3.0.24 20091126.016 2009-11-26 0.05 W32.Virut.CF
nProtect 20091125.01 6330100 2009-11-25 4.21 -
The Hacker 6.5.0.2 v00079 2009-11-26 1.09 -
VBA32 3.12.12.0 20091125.2123 2009-11-25 2.15 Virus.Win32.Virut.X7
VirusBuster 4.5.11.10 10.113.30/2005475 2009-11-26 2.88 Win32.Virut.AB.Gen
************************************************************
VirSCAN.org Scanned Report :
Scanned time : 2009/11/26 20:27:46 (CST)
Scanner results: 76% Scanner(s) (28/37) found malware!
File Name : reader_s.exe
File Size : 71168 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 2ee67b46e1d338c641cc73726531b404
SHA1 : 99dec232742bfed1cf6679c800a20edbd53de89e
Online report : http://virscan.org/report/867c005b07d274ab…6d0a7bd2c4.html
Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20091127013202 2009-11-27 4.00 Trojan-Downloader.Win32.Small!IK
AhnLab V3 2009.11.27.01 2009.11.27 2009-11-27 0.93 Win32/Virut.F
AntiVir 8.2.1.78 7.10.1.111 2009-11-26 0.13 W32/Virut.Gen
Antiy 2.0.18 20091126.3315741 2009-11-26 0.12 -
Arcavir 2009 200911261756 2009-11-26 0.05 -
Authentium 5.1.1 200911261932 2009-11-26 1.21 W32/Backdoor2.GCUD (Exact)
AVAST! 4.7.4 091126-1 2009-11-26 0.01 Win32:Vitro
AVG 8.5.288 270.14.83/2529 2009-11-27 0.58 Win32/Virut
BitDefender 7.81008.4634482 7.29156 2009-11-27 3.92 Win32.Virtob.Gen.12
CA (VET) 35.1.0 7143 2009-11-25 8.04 Win32/Virut.17408 virus.
ClamAV 0.95.2 10085 2009-11-27 0.02 -
Comodo 3.12 3049 2009-11-26 0.84 -
CP Secure 1.3.0.5 2009.11.26 2009-11-26 0.07 -
Dr.Web 4.44.0.9170 2009.11.26 2009-11-26 7.31 Win32.Virut.56
F-Prot 4.4.4.56 20091126 2009-11-26 1.20 W32/Backdoor2.GCUD (exact)
F-Secure 7.02.73807 2009.11.26.07 2009-11-26 0.12 Backdoor.Win32.Small.zv [AVP]
Fortinet 11.98- 11.98 2009-11-26 0.14 -
GData 19.9020/19.587 20091127 2009-11-27 5.78 Backdoor.Win32.Small.zv [Engine:A]
ViRobot 20091126 2009.11.26 2009-11-26 0.44 Backdoor.Win32.Small.51712.C
Ikarus T3.1.01.74 2009.11.27.74602 2009-11-27 4.13 Trojan-Downloader.Win32.Small
JiangMin 11.0.800 2009.11.25 2009-11-25 4.98 -
Kaspersky 5.5.10 2009.11.27 2009-11-27 0.06 Backdoor.Win32.Small.zv
KingSoft 2009.2.5.15 2009.11.27.7 2009-11-27 0.68 Win32.Virut.cr.61440
McAfee 5.3.00 5814 2009-11-26 3.38 Cutwail.gen.l
Microsoft 1.5302 2009.11.26 2009-11-26 7.56 Virus:Win32/Virut.gen!O
Norman 6.01.09 6.01.00 2009-11-25 4.01 W32/Virut.DY
Panda 9.05.01 2009.11.26 2009-11-26 2.73 W32/Sality.AO
Trend Micro 9.000-1003 6.654.07 2009-11-27 0.04 PE_VIRUX.J
Quick Heal 10.00 2009.11.26 2009-11-26 1.56 W32.Virut.G
Rising 20.0 22.23.04.01 2009-11-27 1.35 Win32.Virut.cs
Sophos 3.01.0 4.47 2009-11-27 3.05 W32/Virut-AA
Sunbelt 5518 5518 2009-11-18 2.80 Virus.Win32.Virut.ce (v)
Symantec 1.3.0.24 20091126.016 2009-11-26 0.05 W32.Virut.CF
nProtect 20091125.01 6330100 2009-11-25 4.48 -
The Hacker 6.5.0.2 v00079 2009-11-26 0.80 -
VBA32 3.12.12.0 20091125.2123 2009-11-25 2.16 Virus.Win32.Virut.X7
VirusBuster 4.5.11.10 10.113.30/2005475 2009-11-26 3.29 Win32.Virut.AB.Gen
*******************************************************
VirSCAN.org Scanned Report :
Scanned time : 2009/11/26 20:40:27 (CST)
Scanner results: Scanners did not find malware!
File Name : explorer.exe
File Size : 2927104 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 4f554999d7d5f05daaebba7b5ba1089d
SHA1 : e509a42554cc0e5888ac8bf494d3c02223238609
Online report : http://virscan.org/report/0c23d50383e23e6a…6c8d8c1960.html
Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20091127013202 2009-11-27 4.86 -
AhnLab V3 2009.11.27.01 2009.11.27 2009-11-27 1.31 -
AntiVir 8.2.1.78 7.10.1.111 2009-11-26 0.07 -
Antiy 2.0.18 20091126.3315741 2009-11-26 0.12 -
Arcavir 2009 200911261756 2009-11-26 0.09 -
Authentium 5.1.1 200911261932 2009-11-26 2.42 -
AVAST! 4.7.4 091126-1 2009-11-26 0.11 -
AVG 8.5.288 270.14.83/2529 2009-11-27 0.34 -
BitDefender 7.81008.4634482 7.29156 2009-11-27 3.96 -
CA (VET) 35.1.0 7143 2009-11-25 10.34 -
ClamAV 0.95.2 10085 2009-11-27 0.34 -
Comodo 3.12 3049 2009-11-26 1.30 -
CP Secure 1.3.0.5 2009.11.26 2009-11-26 0.47 -
Dr.Web 4.44.0.9170 2009.11.26 2009-11-26 7.31 -
F-Prot 4.4.4.56 20091126 2009-11-26 2.29 -
F-Secure 7.02.73807 2009.11.26.07 2009-11-26 0.14 -
Fortinet 11.98- 11.98 2009-11-26 0.28 -
GData 19.9020/19.587 20091127 2009-11-27 10.52 -
ViRobot 20091126 2009.11.26 2009-11-26 0.99 -
Ikarus T3.1.01.74 2009.11.27.74602 2009-11-27 4.15 -
JiangMin 11.0.800 2009.11.25 2009-11-25 11.23 -
Kaspersky 5.5.10 2009.11.27 2009-11-27 0.07 -
KingSoft 2009.2.5.15 2009.11.27.7 2009-11-27 1.31 -
McAfee 5.3.00 5814 2009-11-26 3.43 -
Microsoft 1.5302 2009.11.26 2009-11-26 7.74 -
Norman 6.01.09 6.01.00 2009-11-25 4.01 -
Panda 9.05.01 2009.11.26 2009-11-26 1.97 -
Trend Micro 9.000-1003 6.654.07 2009-11-27 0.04 -
Quick Heal 10.00 2009.11.26 2009-11-26 2.19 -
Rising 20.0 22.23.04.01 2009-11-27 1.08 -
Sophos 3.01.0 4.47 2009-11-27 3.09 -
Sunbelt 5518 5518 2009-11-18 1.86 -
Symantec 1.3.0.24 20091126.016 2009-11-26 0.16 -
nProtect 20091125.01 6330100 2009-11-25 3.63 -
The Hacker 6.5.0.2 v00079 2009-11-26 0.85 -
VBA32 3.12.12.0 20091125.2123 2009-11-25 2.48 -
VirusBuster 4.5.11.10 10.113.30/2005475 2009-11-26 3.05 -
We would be grateful if you could assist us in our research into this infection by providing us with some samples and information from your machine. This will only take a minute or two to complete, and is very simple. If you wish to help us, please do the following:
- Download VAPrep.bat and save it to your Desktop.
- Double-click VAPrep.bat to run it. It will only take a moment to complete.
- When done, please right-click the VAPrep folder which should now be on your Desktop. Select Send To >> Compressed (zipped) Folder.
- Next, please go to this webpage.
- Browse to the VAPrep.zip zipped folder you just created.
- Click Send File.
VIRUT is a polymorphic file infector with some additional features. It spreads all around the drive and infects even files infected by another virus previously.
Unfortunately, the cleaning of this virus is not possible.
The only thing we recommend is to do a full reformat and install.
We have an excellent tutorial on how to reformat here
and for a Vista reformat re-install HERE
We do not recommend trying to save any files from this machine as they could all be infected and will simply re-infect your system again, there is no way of being certain what this infection can do.
It used to be certain documents, pictures etc. could be saved, but not any more. Virut is now known to infect all file formats.
Read more about the VIRUT FILE INFECTOR HERE
If you don't have a Windows Installation Disk (if this came with Windows pre-installed), you may have a Manufacturer restore disk to restore the computer to its original state - this depends on the Manufacturer though. Otherwise, give the Manufacturer a call and ask them to send you a restore disk or Windows installation CD.
Should you have any questions, please feel free to ask.
I am sorry there is nothing more that we can do.
More information:
http://free.avg.com/66558
There are bugs in the viral code. When the virus produces infected files, it also creates non-functional files that also contain the virus.
http://home.mcafee.com/VirusInfo/VirusProf…aspx?key=143034
W32/Virut.h is a polymorphic, entry point obscuring (EPO) file infector with IRC bot functionality. It can accept commands to download other malware on the compromised machine.
It appends to the end of the last section of executable (PE) files an encrypted copy of its code. The decryptor is polymorphic and can be located either:
Immediately before the encrypted code at the end of the last section
At the end of the code section of the infected host in 'slack-space' (assuming there is any)
At the original entry point of the host (overwriting the original host code)
Miekiemoes, a highly regarded expert in malware removal, and an MS-MVP,
has an extremely informative blog post about Virut. - she only ever recommends a total reformat.
At least this way, you have the best chance of having a clean machine once more.
For future protection read this very well written article Think Prevention.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI