This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] hard drive locked to scandisk and updater not functional

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My son fell prey to the "Windows Security Center" ransom ware about 3 weeks ago. we were able to clear the program and unlock the system by running MalwareBytes antimalware. Since then he has had problems with system stability and eventually would not boot. I finally got it to boot. I have run Windows Defender and Iolo antivirus and cleaned numerous incidences of viruses from the system and made some other repairs. The system now starts normally and seems relatively stable. Major problem remaining is that Windows update will not function properly. Updates will download but most fail to install after numerous attempts. The error code which I was getting was "800736CC". Indicating a probable corrupt download. I followed the instructions from windows troubleshooter of disabling updater, deleting the files from C:\WINDOWS\SoftwareDistribution\Download and \DataStore then doing a scan disk to correct any disk write problems. Scandisk was set to run at reboot. upon reboot I get an error message which states that "scandisk cannot open volume for direct access" and will not run. After several hours on the phone with HP support and numerous checks of HD integrity and other files, he aggreed there may still be a lingering "virus" locking the hard drive. So I'm hoping for some help. System Info: Compaq Presario CQ60 Athlon X2 processor Windows Vista Home Premium Reports follow: ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/11/25 19:19 Program Version: Version 1.3.5.0 Windows Version: Windows Vista SP1 ================================================== Drivers ——————- Name: dump_atapi.sys Image Path: C:\Windows\System32\Drivers\dump_atapi.sys Address: 0x8E8F7000 Size: 32768 File Visible: No Signed: - Status: - Name: dump_dumpata.sys Image Path: C:\Windows\System32\Drivers\dump_dumpata.sys Address: 0x8E8EC000 Size: 45056 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\Windows\system32\drivers\rootrepeal.sys Address: 0x9A3EF000 Size: 49152 File Visible: No Signed: - Status: - Name: sppv.sys Image Path: C:\Windows\System32\Drivers\sppv.sys Address: 0x80605000 Size: 1052672 File Visible: No Signed: - Status: - Name: sptd Image Path: \Driver\sptd Address: 0x00000000 Size: 0 File Visible: No Signed: - Status: - Name: tcpsr.sys Image Path: C:\Windows\System32\drivers\tcpsr.sys Address: 0x9AA08000 Size: 6016 File Visible: No Signed: - Status: - Name: zeeobbmw1.sys Image Path: C:\Windows\system32\drivers\zeeobbmw1.sys Address: 0x8E6F2000 Size: 64000 File Visible: No Signed: - Status: - Processes ——————- Path: System PID: 4 Status: Locked to the Windows API! Path: C:\Windows\System32\audiodg.exe PID: 1312 Status: Locked to the Windows API! Hidden Services ——————- Service Name: zeeobbmw1 Image Path: system32\drivers\zeeobbmw1.sys ==EOF== *********************************************************************** DDS (Ver_09-11-24.02) - NTFSx86 Run by [removed] at 21:02:15.51 on Wed 11/25/2009 Internet Explorer: 7.0.6001.18000 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1790.847 [GMT -6:00] AV: Windows System Defender *On-access scanning enabled* (Updated) {D21115D8-6C6B-4A0E-A7A5-CC3D08C17CDB} AV: iolo AntiVirus® *On-access scanning disabled* (Updated) {2565CEEE-6BDB-4A6D-AD6D-F682F2695014} SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} FW: Windows System Defender *enabled* {43A214DB-FDE5-46AC-B527-D09EE3E28515} FW: iolo Personal Firewall® *disabled* {38254411-9AEC-4967-913E-F892C2A4DF89} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\rundll32.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\WLANExt.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\iolo\common\lib\ioloServiceManager.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\SMINST\BLService.exe C:\Program Files\CyberLink\Shared files\RichVideo.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\HP\QuickPlay\QPService.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe C:\Windows\System32\reader_s.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe C:\Program Files\Pure Networks\Network Magic\nmapp.exe C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE C:\Program Files\iolo\System Mechanic Professional\Personal Firewall\ioloFW.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe svchost.exe C:\Windows\TEMP\VRTB856.tmp C:\Windows\system32\config\systemprofile\reader_s.exe C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\TEMP\BNF7F4.tmp C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.vista.exe C:\Windows\system32\notepad.exe C:\Windows\system32\NOTEPAD.EXE C:\Windows\system32\rundll32.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Users\Office Depot\Downloads\dds(2).scr C:\Windows\system32\ssBranded.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.ask.com?gcht=HC&o=101676&l=dis uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Presario&pf=cnnb uSearch Bar = hxxp://www.starbarsearch.com/?useie5=1&q= mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Presario&pf=cnnb mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Presario&pf=cnnb mSearch Bar = hxxp://www.starbarsearch.com/?useie5=1&q= BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Microsoft Live Search Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.0541.0\msneshellx.dll TB: Microsoft Live Search Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.0541.0\msneshellx.dll TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll TB: {A82F10B6-A8D4-4ED0-AEF6-CA27A0DE5A36} - No File TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File EB: DA Bar: {59c40940-073e-11de-8c30-0800200c9a66} - %SystemRoot%\system32\shdocvw.dll uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden uRun: [AlcoholAutomount] "c:\program files\alcohol soft\alcohol 52\axcmd.exe" /automount uRun: [reader_s] c:\users\office depot\reader_s.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe" mRun: [UpdateLBPShortCut] "c:\program files\cyberlink\labelprint\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\labelprint" updatewithcreateonce "software\cyberlink\labelprint\2.5" mRun: [UpdatePSTShortCut] "c:\program files\cyberlink\dvd suite\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\dvd suite" updatewithcreateonce "software\cyberlink\PowerStarter" mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start mRun: [UpdateP2GoShortCut] "c:\program files\cyberlink\power2go\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0" mRun: [UpdatePDIRShortCut] "c:\program files\cyberlink\powerdirector\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\powerdirector" updatewithcreateonce "software\cyberlink\powerdirector\7.0" mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe mRun: [iolo Startup] "c:\program files\iolo\common\lib\ioloLManager.exe" mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRun: [reader_s] c:\windows\system32\reader_s.exe mRun: [nmctxth] "c:\program files\common files\pure networks shared\platform\nmctxth.exe" mRun: [nmapp] "c:\program files\pure networks\network magic\nmapp.exe" -autorun -nosplash mRun: [userini] c:\windows\explorer.exe:userini.exe dRun: [reader_s] c:\windows\system32\config\systemprofile\reader_s.exe dRun: [userini] c:\windows\explorer.exe:userini.exe mExplorerRun: [userini] c:\windows\explorer.exe:userini.exe dExplorerRun: [userini] c:\windows\explorer.exe:userini.exe StartupFolder: c:\users\office~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0) mPolicies-system: ConsentPromptBehaviorUser = 0 (0x0) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000 IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\progra~1\java\jre16~1.0_0\bin\ssv.dll LSP: c:\windows\system32\iavlsp.dll LSP: c:\program files\iolo\common\firewall\iFW_Xfilter.dll DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} - hxxps://h20364.www2.hp.com/CSMWeb/Customer/cabs/HPISDataManager.CAB DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - c:\program files\common files\pure networks shared\platform\puresp4.dll mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe" IFEO: image file execution options - svchost.exe IFEO: brastk.exe - svchost.exe ================= FIREFOX =================== FF - ProfilePath - c:\users\office~1\appdata\roaming\mozilla\firefox\profiles\jfu0f1pe.default\ FF - prefs.js: browser.search.selectedEngine - search FF - prefs.js: browser.startup.homepage - hxxp://www.ask.com?gcht=HC&o=101676&l=dis FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101664&gct=&gc=1&q= FF - component: c:\users\office depot\appdata\roaming\mozilla\firefox\profiles\jfu0f1pe.default\extensions\{39124730-0779-11de-8c30-0800200c9a66}\components\daff.dll —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); ============= SERVICES / DRIVERS =============== R0 XPacket;iolo Personal Firewall Driver;c:\windows\system32\xpacket.sys [2009-4-19 39424] R1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\elrawdsk.sys [2009-4-19 20392] R2 ioloFileInfoList;iolo FileInfoList Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2009-4-19 659376] R2 ioloSystemService;iolo System Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2009-4-19 659376] R2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\sminst\BLService.exe [2008-10-25 365952] R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2009-6-9 1153368] R3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2008-10-25 193840] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-5-9 43040] S3 rcmirror;rcmirror;c:\windows\system32\drivers\rcmirror.sys [2008-10-8 3328] ============== File Associations =============== JSEFile=NOTEPAD.EXE %1 scrfile=NOTEPAD.EXE %1 VBEFile=NOTEPAD.EXE %1 VBSFile=NOTEPAD.EXE %1 =============== Created Last 30 ================ 2009-11-26 00:54:21 44 —-a-w- c:\windows\system32\D20D.tmp 2009-11-25 23:56:28 0 d—–w- c:\program files\Trend Micro 2009-11-25 23:47:16 44 —-a-w- c:\windows\system32\E10B.tmp 2009-11-25 23:31:47 0 —-a-w- c:\windows\system32\file.ext 2009-11-25 23:26:36 51200 —-a-w- c:\windows\system32\6680.tmp 2009-11-25 23:26:30 44 —-a-w- c:\windows\system32\4BFD.tmp 2009-11-25 18:44:01 0 —hatw- c:\windows\wusa.lock 2009-11-25 18:09:10 44 —-a-w- c:\windows\system32\754E.tmp 2009-11-25 17:09:34 44 —-a-w- c:\windows\system32\C83D.tmp 2009-11-25 13:47:58 44 —-a-w- c:\windows\system32\F749.tmp 2009-11-25 06:10:12 44 —-a-w- c:\windows\system32\7148.tmp 2009-11-25 06:05:13 44 —-a-w- c:\windows\system32\F6AD.tmp 2009-11-25 05:20:40 293376 —-a-w- c:\windows\system32\wlanmsm.dll 2009-11-25 05:20:40 2501921 —-a-w- c:\windows\system32\wlan.tmf 2009-11-25 05:20:40 127488 —-a-w- c:\windows\system32\L2SecHC.dll 2009-11-25 05:20:39 513024 —-a-w- c:\windows\system32\wlansvc.dll 2009-11-25 05:20:39 302592 —-a-w- c:\windows\system32\wlansec.dll 2009-11-25 05:20:35 1399296 —-a-w- c:\windows\system32\msxml6.dll 2009-11-25 05:20:34 1257472 —-a-w- c:\windows\system32\msxml3.dll 2009-11-25 05:20:30 72704 —-a-w- c:\windows\system32\fontsub.dll 2009-11-25 05:20:30 289792 —-a-w- c:\windows\system32\atmfd.dll 2009-11-25 05:20:30 156672 —-a-w- c:\windows\system32\t2embed.dll 2009-11-25 05:20:30 10240 —-a-w- c:\windows\system32\dciman32.dll 2009-11-25 05:19:16 71680 —-a-w- c:\windows\system32\atl.dll 2009-11-25 05:19:13 3599960 —-a-w- c:\windows\system32\ntkrnlpa.exe 2009-11-25 05:19:12 3547736 —-a-w- c:\windows\system32\ntoskrnl.exe 2009-11-25 05:19:08 160256 —-a-w- c:\windows\system32\wkssvc.dll 2009-11-25 05:19:02 2066432 —-a-w- c:\windows\system32\mstscax.dll 2009-11-25 05:18:57 714240 —-a-w- c:\windows\system32\timedate.cpl 2009-11-25 05:18:15 91136 —-a-w- c:\windows\system32\avifil32.dll 2009-11-25 05:18:10 636928 —-a-w- c:\windows\system32\localspl.dll 2009-11-25 05:18:07 2035712 —-a-w- c:\windows\system32\win32k.sys 2009-11-25 05:17:45 28672 —-a-w- c:\windows\system32\Apphlpdm.dll 2009-11-25 05:17:42 4240384 —-a-w- c:\windows\system32\GameUXLegacyGDFs.dll 2009-11-25 05:17:30 61440 —-a-w- c:\windows\system32\msasn1.dll 2009-11-25 05:17:25 784896 —-a-w- c:\windows\system32\rpcrt4.dll 2009-11-25 05:17:21 144896 —-a-w- c:\windows\system32\drivers\srv2.sys 2009-11-25 05:17:18 351232 —-a-w- c:\windows\system32\WSDApi.dll 2009-11-25 05:17:14 604672 —-a-w- c:\windows\system32\WMSPDMOD.DLL 2009-11-25 04:56:59 44 —-a-w- c:\windows\system32\8767.tmp 2009-11-25 04:24:42 0 d—–w- C:\092f9e63391dd6bcaab2 2009-11-25 04:22:35 44 —-a-w- c:\windows\system32\B01C.tmp 2009-11-25 03:52:27 0 d—–w- c:\windows\CheckSur 2009-11-25 03:14:04 0 d—–w- c:\windows\system32\EventProviders 2009-11-25 03:14:02 0 d—–w- C:\1dc74608824404e87b48b83ba79d 2009-11-25 03:01:42 44 —-a-w- c:\windows\system32\89E7.tmp 2009-11-24 03:49:16 0 —-a-w- c:\windows\system32\94FE.tmp 2009-11-24 03:35:46 0 —-a-w- c:\windows\system32\F8DF.tmp 2009-11-24 03:35:45 84 —-a-w- c:\windows\system32\F4AA.tmp 2009-11-24 03:25:29 51200 —-a-w- c:\windows\system32\EB69.tmp 2009-11-24 03:25:08 0 —-a-w- c:\windows\system32\9C6E.tmp 2009-11-24 03:25:07 84 —-a-w- c:\windows\system32\9684.tmp 2009-11-24 03:25:07 0 —-a-w- c:\windows\system32\98E5.tmp 2009-11-24 03:24:45 0 —-a-w- c:\windows\system32\40E7.tmp 2009-11-24 03:24:44 84 —-a-w- c:\windows\system32\3E18.tmp 2009-11-24 03:24:23 84 —-a-w- c:\windows\system32\EB28.tmp 2009-11-24 03:24:22 51200 —-a-w- c:\windows\system32\E8CA.tmp 2009-11-24 03:24:01 84 —-a-w- c:\windows\system32\9349.tmp 2009-11-24 03:24:01 0 —-a-w- c:\windows\system32\9618.tmp 2009-11-24 03:23:48 0 —-a-w- c:\windows\system32\61EF.tmp 2009-11-24 03:23:44 0 —-a-w- c:\windows\system32\52F0.tmp 2009-11-24 03:23:43 0 —-a-w- c:\windows\system32\4EDB.tmp 2009-11-24 03:23:40 0 —-a-w- c:\windows\system32\4347.tmp 2009-11-24 03:23:39 84 —-a-w- c:\windows\system32\4079.tmp 2009-11-24 03:23:18 84 —-a-w- c:\windows\system32\EBE4.tmp 2009-11-24 03:22:15 84 —-a-w- c:\windows\system32\F546.tmp 2009-11-24 03:22:15 0 —-a-w- c:\windows\system32\F815.tmp 2009-11-24 03:21:54 84 —-a-w- c:\windows\system32\A331.tmp 2009-11-24 03:21:35 0 —-a-w- c:\windows\system32\59F2.tmp 2009-11-24 03:21:34 84 —-a-w- c:\windows\system32\5733.tmp 2009-11-24 03:21:11 0 —-a-w- c:\windows\system32\FCE4.tmp 2009-11-24 03:20:48 0 —-a-w- c:\windows\system32\A42A.tmp 2009-11-24 03:20:24 0 —-a-w- c:\windows\system32\4569.tmp 2009-11-24 03:20:23 84 —-a-w- c:\windows\system32\425C.tmp 2009-11-24 03:20:03 0 —-a-w- c:\windows\system32\F279.tmp 2009-11-24 03:20:02 84 —-a-w- c:\windows\system32\EF9B.tmp 2009-11-24 03:19:42 0 —-a-w- c:\windows\system32\A13E.tmp 2009-11-24 03:19:41 84 —-a-w- c:\windows\system32\9E60.tmp 2009-11-24 03:19:21 0 —-a-w- c:\windows\system32\4FE4.tmp 2009-11-24 03:19:20 84 —-a-w- c:\windows\system32\4CE7.tmp 2009-11-24 03:18:56 0 —-a-w- c:\windows\system32\ECAF.tmp 2009-11-24 03:18:55 84 —-a-w- c:\windows\system32\E964.tmp 2009-11-24 03:18:30 0 —-a-w- c:\windows\system32\892C.tmp 2009-11-24 03:18:29 84 —-a-w- c:\windows\system32\8555.tmp 2009-11-24 03:17:49 0 —-a-w- c:\windows\system32\E83C.tmp 2009-11-24 03:17:48 84 —-a-w- c:\windows\system32\E417.tmp 2009-11-24 03:08:54 0 —-a-w- c:\windows\system32\ECEE.tmp 2009-11-24 03:08:53 84 —-a-w- c:\windows\system32\E983.tmp 2009-11-24 02:51:17 0 —-a-w- c:\windows\system32\9637.tmp 2009-11-24 02:51:16 84 —-a-w- c:\windows\system32\9211.tmp 2009-11-24 02:47:17 0 —-a-w- c:\windows\system32\EADB.tmp 2009-11-24 02:47:16 84 —-a-w- c:\windows\system32\E7AF.tmp 2009-11-24 01:40:48 0 —-a-w- c:\windows\system32\2AD7.tmp 2009-11-24 01:40:47 84 —-a-w- c:\windows\system32\27CA.tmp 2009-11-23 20:22:22 45568 —-a-w- c:\windows\system32\DEAB.tmp 2009-11-23 05:39:34 0 d—–w- c:\programdata\LightScribe 2009-11-23 04:23:31 93096 —-a-w- c:\windows\system32\IncContxMenu.dll 2009-11-23 04:17:04 0 d—–w- c:\program files\Pure Networks 2009-11-23 04:14:51 24888 —-a-w- c:\windows\system32\drivers\pnarp.sys 2009-11-23 04:14:37 26424 —-a-w- c:\windows\system32\drivers\purendis.sys 2009-11-23 04:14:18 0 d—–w- c:\program files\common files\Pure Networks Shared 2009-11-03 01:56:39 1 —-a-w- c:\users\office depot\oashdihasidhasuidhiasdhiashdiuasdhasd 2009-11-03 01:55:29 4 —-a-w- c:\users\office depot\proxy_port 2009-10-30 17:18:31 71168 —-a-w- c:\windows\system32\reader_s.exe 2009-10-30 02:00:49 0 d-sh–w- c:\programdata\8e5558b ==================== Find3M ==================== 2009-11-25 23:47:13 42712 —-a-w- c:\programdata\nvModes.dat 2009-11-25 23:32:25 86016 —-a-w- c:\windows\inf\infstrng.dat 2009-11-25 23:32:25 51200 —-a-w- c:\windows\inf\infpub.dat 2009-11-25 23:32:24 86016 —-a-w- c:\windows\inf\infstor.dat 2009-11-23 20:22:31 2927104 —-a-w- c:\windows\explorer.exe 2009-11-23 08:56:14 26624 —-a-w- c:\windows\system32\CertEnrollCtrl.exe 2009-11-23 08:56:02 97792 —-a-w- c:\windows\system32\wbem\WinMgmt.exe 2009-11-23 08:55:56 54272 —-a-w- c:\windows\system32\wlrmdr.exe 2009-11-23 08:55:56 34304 —-a-w- c:\windows\system32\mpnotify.exe 2009-11-23 08:55:22 402944 —-a-w- c:\windows\system32\vds.exe 2009-11-23 08:55:22 39936 —-a-w- c:\windows\system32\vdsldr.exe 2009-11-23 08:55:09 42496 —-a-w- c:\windows\system32\netiougc.exe 2009-11-23 08:54:34 338432 —-a-w- c:\windows\system32\rstrui.exe 2009-11-23 08:54:04 55808 —-a-w- c:\windows\system32\UI0Detect.exe 2009-11-23 08:53:16 212992 —-a-w- c:\windows\system32\recdisc.exe 2009-11-23 08:53:11 36864 —-a-w- c:\windows\system32\rasautou.exe 2009-11-23 08:52:57 60416 —-a-w- c:\windows\system32\lodctr.exe 2009-11-23 08:52:57 53760 —-a-w- c:\windows\system32\unlodctr.exe 2009-11-23 08:52:49 80384 —-a-w- c:\windows\system32\printui.exe 2009-11-23 08:52:27 66048 —-a-w- c:\windows\system32\csrstub.exe 2009-11-23 08:52:27 540672 —-a-w- c:\windows\system32\ntvdm.exe 2009-11-23 08:52:21 94720 —-a-w- c:\windows\system32\newdev.exe 2009-11-23 08:52:18 35328 —-a-w- c:\windows\system32\bridgeunattend.exe 2009-11-23 08:52:14 41472 —-a-w- c:\windows\system32\netbtugc.exe 2009-11-23 08:51:41 61440 —-a-w- c:\windows\system32\auditpol.exe 2009-11-23 08:50:53 101888 —-a-w- c:\windows\system32\consent.exe 2009-11-23 08:50:49 100352 —-a-w- c:\windows\system32\hdwwiz.exe 2009-11-23 08:50:43 87552 ——w- c:\windows\system32\MuiUnattend.exe 2009-11-23 08:50:07 164352 —-a-w- c:\windows\system32\iscsicli.exe 2009-11-23 08:49:52 34816 —-a-w- c:\windows\hh.exe 2009-11-23 08:48:47 76288 —-a-w- c:\windows\system32\wermgr.exe 2009-11-23 08:48:28 45056 —-a-w- c:\windows\system32\dnscacheugc.exe 2009-11-23 08:48:02 121856 —-a-w- c:\windows\system32\drvinst.exe 2009-11-23 08:47:31 72704 —-a-w- c:\windows\system32\expand.exe 2009-11-23 08:47:11 40960 —-a-w- c:\windows\system32\sdbinst.exe 2009-11-03 02:42:06 195456 ——w- c:\windows\system32\MpSigStub.exe 2009-10-23 21:16:54 2115496 —-a-w- c:\windows\system32\Incinerator.dll 2009-10-23 18:57:47 2198 —-a-w- C:\JDwJK.bat 2008-10-25 23:12:46 665600 —-a-w- c:\windows\inf\drvindex.dat 2008-01-21 02:43:21 174 –sha-w- c:\program files\desktop.ini 2006-11-02 12:42:02 30674 —-a-w- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 12:42:02 30674 —-a-w- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 12:42:02 287440 —-a-w- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 12:42:02 287440 —-a-w- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfc.dat 2008-10-25 23:12:45 8192 –sha-w- c:\windows\users\default\NTUSER.DAT ============= FINISH: 21:03:00.58 ===============

Attachments:

Hi,

Please do the following:


  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:


    c:\windows\system32\userinit.exe

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.

Please do the same for the following files:
c:\windows\explorer.exe
c:\windows\system32\ctfmon.exe
C:\Windows\System32\reader_s.exe

Hi CB,

Thanks for the help.

VirSCAN.org Scanned Report :
Scanned time : 2009/11/26 20:11:36 (CST)
Scanner results: 68% Scanner(s) (25/37) found malware!
File Name : userinit.exe
File Size : 45056 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : dad51f54c067421f788c54ac1b444efb
SHA1 : 2fd829a409f268b788313127db9c8a4a17012f16
Online report : http://virscan.org/report/a57fa6850dad5954…b85444a5e8.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20091127013202 2009-11-27 6.25 -
AhnLab V3 2009.11.27.00 2009.11.27 2009-11-27 1.82 Win32/Virut.F
AntiVir 8.2.1.78 7.10.1.111 2009-11-26 0.39 W32/Virut.Gen
Antiy 2.0.18 20091126.3315741 2009-11-26 0.12 -
Arcavir 2009 200911261756 2009-11-26 0.04 -
Authentium 5.1.1 200911261932 2009-11-26 1.25 W32/Virut.AI!Generic (Heuristic)
AVAST! 4.7.4 091126-1 2009-11-26 0.01 Win32:Vitro
AVG 8.5.288 270.14.83/2529 2009-11-27 0.45 Win32/Virut
BitDefender 7.81008.4634482 7.29156 2009-11-27 4.04 Win32.Virtob.Gen.12
CA (VET) 35.1.0 7143 2009-11-25 14.06 Win32/Virut.17408 virus.
ClamAV 0.95.2 10085 2009-11-27 0.02 -
Comodo 3.12 3049 2009-11-26 0.88 -
CP Secure 1.3.0.5 2009.11.26 2009-11-26 0.13 -
Dr.Web 4.44.0.9170 2009.11.26 2009-11-26 7.16 Win32.Virut.56
F-Prot 4.4.4.56 20091126 2009-11-26 1.22 Possible W32/Virut.AI!Generic
F-Secure 7.02.73807 2009.11.26.07 2009-11-26 5.75 Virus.Win32.Virut.ce [AVP]
Fortinet 11.98- 11.98 2009-11-26 0.14 -
GData 19.9019/19.587 20091127 2009-11-27 11.53 Virus.Win32.Virut.ce [Engine:A]
ViRobot 20091126 2009.11.26 2009-11-26 0.79 -
Ikarus T3.1.01.74 2009.11.27.74602 2009-11-27 4.77 -
JiangMin 11.0.800 2009.11.25 2009-11-25 7.21 -
Kaspersky 5.5.10 2009.11.27 2009-11-27 0.09 Virus.Win32.Virut.ce
KingSoft 2009.2.5.15 2009.11.26.19 2009-11-26 0.65 Win32.Virut.cr.61440
McAfee 5.3.00 5814 2009-11-26 3.65 W32/Virut.n.gen
Microsoft 1.5302 2009.11.26 2009-11-26 7.22 Virus:Win32/Virut.gen!O
Norman 6.01.09 6.01.00 2009-11-25 2.02 W32/Virut.DY
Panda 9.05.01 2009.11.26 2009-11-26 5.54 W32/Sality.AO
Trend Micro 9.000-1003 6.654.07 2009-11-27 0.04 PE_VIRUX.J
Quick Heal 10.00 2009.11.26 2009-11-26 1.82 W32.Virut.G
Rising 20.0 22.23.04.01 2009-11-27 1.67 Win32.Virut.cs
Sophos 3.01.0 4.47 2009-11-27 3.11 W32/Virut-AA
Sunbelt 5518 5518 2009-11-18 4.66 Virus.Win32.Virut.ce (v)
Symantec 1.3.0.24 20091126.016 2009-11-26 0.42 W32.Virut.CF
nProtect 20091125.01 6330100 2009-11-25 5.76 -
The Hacker 6.5.0.2 v00079 2009-11-26 1.52 -
VBA32 3.12.12.0 20091125.2123 2009-11-25 2.15 Virus.Win32.Virut.X7
VirusBuster 4.5.11.10 10.113.30/2005475 2009-11-26 2.96 Win32.Virut.AB.Gen

**********************************************************
VirSCAN.org Scanned Report :
Scanned time : 2009/11/26 20:23:30 (CST)
Scanner results: 65% Scanner(s) (24/37) found malware!
File Name : ctfmon.exe
File Size : 28672 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 990815a040003ac3acb2e96f0b220e8c
SHA1 : 808197ed08246b783eb7bdbd59ef186489dcc904
Online report : http://virscan.org/report/e2f977e7f679d1ff…271166b67a.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20091127013202 2009-11-27 11.09 -
AhnLab V3 2009.11.27.00 2009.11.27 2009-11-27 1.23 -
AntiVir 8.2.1.78 7.10.1.111 2009-11-26 0.27 W32/Virut.Gen
Antiy 2.0.18 20091126.3315741 2009-11-26 0.12 -
Arcavir 2009 200911261756 2009-11-26 0.04 -
Authentium 5.1.1 200911261932 2009-11-26 1.25 W32/Virut.AI!Generic (Heuristic)
AVAST! 4.7.4 091126-1 2009-11-26 0.01 Win32:Vitro
AVG 8.5.288 270.14.83/2529 2009-11-27 0.42 Win32/Virut
BitDefender 7.81008.4634482 7.29156 2009-11-27 4.02 Win32.Virtob.Gen.12
CA (VET) 35.1.0 7143 2009-11-25 32.89 Win32/Virut.17408 virus.
ClamAV 0.95.2 10085 2009-11-27 0.01 -
Comodo 3.12 3049 2009-11-26 2.23 -
CP Secure 1.3.0.5 2009.11.26 2009-11-26 0.05 -
Dr.Web 4.44.0.9170 2009.11.26 2009-11-26 7.21 Win32.Virut.56
F-Prot 4.4.4.56 20091126 2009-11-26 1.25 Possible W32/Virut.AI!Generic
F-Secure 7.02.73807 2009.11.26.07 2009-11-26 9.30 Virus.Win32.Virut.ce [AVP]
Fortinet 11.98- 11.98 2009-11-26 0.16 -
GData 19.9019/19.587 20091127 2009-11-27 7.54 Virus.Win32.Virut.ce [Engine:A]
ViRobot 20091126 2009.11.26 2009-11-26 0.70 -
Ikarus T3.1.01.74 2009.11.27.74602 2009-11-27 4.21 -
JiangMin 11.0.800 2009.11.25 2009-11-25 14.02 -
Kaspersky 5.5.10 2009.11.27 2009-11-27 0.07 Virus.Win32.Virut.ce
KingSoft 2009.2.5.15 2009.11.27.7 2009-11-27 0.55 Win32.Virut.cr.61440
McAfee 5.3.00 5814 2009-11-26 3.52 W32/Virut.n.gen
Microsoft 1.5302 2009.11.26 2009-11-26 8.34 Virus:Win32/Virut.gen!O
Norman 6.01.09 6.01.00 2009-11-25 2.01 W32/Virut.DY
Panda 9.05.01 2009.11.26 2009-11-26 2.26 W32/Sality.AO
Trend Micro 9.000-1003 6.654.07 2009-11-27 0.04 PE_VIRUX.J
Quick Heal 10.00 2009.11.26 2009-11-26 2.04 W32.Virut.G
Rising 20.0 22.23.04.01 2009-11-27 1.63 Win32.Virut.cs
Sophos 3.01.0 4.47 2009-11-27 3.09 W32/Virut-AA
Sunbelt 5518 5518 2009-11-18 2.86 Virus.Win32.Virut.ce (v)
Symantec 1.3.0.24 20091126.016 2009-11-26 0.05 W32.Virut.CF
nProtect 20091125.01 6330100 2009-11-25 4.21 -
The Hacker 6.5.0.2 v00079 2009-11-26 1.09 -
VBA32 3.12.12.0 20091125.2123 2009-11-25 2.15 Virus.Win32.Virut.X7
VirusBuster 4.5.11.10 10.113.30/2005475 2009-11-26 2.88 Win32.Virut.AB.Gen

************************************************************
VirSCAN.org Scanned Report :
Scanned time : 2009/11/26 20:27:46 (CST)
Scanner results: 76% Scanner(s) (28/37) found malware!
File Name : reader_s.exe
File Size : 71168 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 2ee67b46e1d338c641cc73726531b404
SHA1 : 99dec232742bfed1cf6679c800a20edbd53de89e
Online report : http://virscan.org/report/867c005b07d274ab…6d0a7bd2c4.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20091127013202 2009-11-27 4.00 Trojan-Downloader.Win32.Small!IK
AhnLab V3 2009.11.27.01 2009.11.27 2009-11-27 0.93 Win32/Virut.F
AntiVir 8.2.1.78 7.10.1.111 2009-11-26 0.13 W32/Virut.Gen
Antiy 2.0.18 20091126.3315741 2009-11-26 0.12 -
Arcavir 2009 200911261756 2009-11-26 0.05 -
Authentium 5.1.1 200911261932 2009-11-26 1.21 W32/Backdoor2.GCUD (Exact)
AVAST! 4.7.4 091126-1 2009-11-26 0.01 Win32:Vitro
AVG 8.5.288 270.14.83/2529 2009-11-27 0.58 Win32/Virut
BitDefender 7.81008.4634482 7.29156 2009-11-27 3.92 Win32.Virtob.Gen.12
CA (VET) 35.1.0 7143 2009-11-25 8.04 Win32/Virut.17408 virus.
ClamAV 0.95.2 10085 2009-11-27 0.02 -
Comodo 3.12 3049 2009-11-26 0.84 -
CP Secure 1.3.0.5 2009.11.26 2009-11-26 0.07 -
Dr.Web 4.44.0.9170 2009.11.26 2009-11-26 7.31 Win32.Virut.56
F-Prot 4.4.4.56 20091126 2009-11-26 1.20 W32/Backdoor2.GCUD (exact)
F-Secure 7.02.73807 2009.11.26.07 2009-11-26 0.12 Backdoor.Win32.Small.zv [AVP]
Fortinet 11.98- 11.98 2009-11-26 0.14 -
GData 19.9020/19.587 20091127 2009-11-27 5.78 Backdoor.Win32.Small.zv [Engine:A]
ViRobot 20091126 2009.11.26 2009-11-26 0.44 Backdoor.Win32.Small.51712.C
Ikarus T3.1.01.74 2009.11.27.74602 2009-11-27 4.13 Trojan-Downloader.Win32.Small
JiangMin 11.0.800 2009.11.25 2009-11-25 4.98 -
Kaspersky 5.5.10 2009.11.27 2009-11-27 0.06 Backdoor.Win32.Small.zv
KingSoft 2009.2.5.15 2009.11.27.7 2009-11-27 0.68 Win32.Virut.cr.61440
McAfee 5.3.00 5814 2009-11-26 3.38 Cutwail.gen.l
Microsoft 1.5302 2009.11.26 2009-11-26 7.56 Virus:Win32/Virut.gen!O
Norman 6.01.09 6.01.00 2009-11-25 4.01 W32/Virut.DY
Panda 9.05.01 2009.11.26 2009-11-26 2.73 W32/Sality.AO
Trend Micro 9.000-1003 6.654.07 2009-11-27 0.04 PE_VIRUX.J
Quick Heal 10.00 2009.11.26 2009-11-26 1.56 W32.Virut.G
Rising 20.0 22.23.04.01 2009-11-27 1.35 Win32.Virut.cs
Sophos 3.01.0 4.47 2009-11-27 3.05 W32/Virut-AA
Sunbelt 5518 5518 2009-11-18 2.80 Virus.Win32.Virut.ce (v)
Symantec 1.3.0.24 20091126.016 2009-11-26 0.05 W32.Virut.CF
nProtect 20091125.01 6330100 2009-11-25 4.48 -
The Hacker 6.5.0.2 v00079 2009-11-26 0.80 -
VBA32 3.12.12.0 20091125.2123 2009-11-25 2.16 Virus.Win32.Virut.X7
VirusBuster 4.5.11.10 10.113.30/2005475 2009-11-26 3.29 Win32.Virut.AB.Gen

*******************************************************

VirSCAN.org Scanned Report :
Scanned time : 2009/11/26 20:40:27 (CST)
Scanner results: Scanners did not find malware!
File Name : explorer.exe
File Size : 2927104 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 4f554999d7d5f05daaebba7b5ba1089d
SHA1 : e509a42554cc0e5888ac8bf494d3c02223238609
Online report : http://virscan.org/report/0c23d50383e23e6a…6c8d8c1960.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20091127013202 2009-11-27 4.86 -
AhnLab V3 2009.11.27.01 2009.11.27 2009-11-27 1.31 -
AntiVir 8.2.1.78 7.10.1.111 2009-11-26 0.07 -
Antiy 2.0.18 20091126.3315741 2009-11-26 0.12 -
Arcavir 2009 200911261756 2009-11-26 0.09 -
Authentium 5.1.1 200911261932 2009-11-26 2.42 -
AVAST! 4.7.4 091126-1 2009-11-26 0.11 -
AVG 8.5.288 270.14.83/2529 2009-11-27 0.34 -
BitDefender 7.81008.4634482 7.29156 2009-11-27 3.96 -
CA (VET) 35.1.0 7143 2009-11-25 10.34 -
ClamAV 0.95.2 10085 2009-11-27 0.34 -
Comodo 3.12 3049 2009-11-26 1.30 -
CP Secure 1.3.0.5 2009.11.26 2009-11-26 0.47 -
Dr.Web 4.44.0.9170 2009.11.26 2009-11-26 7.31 -
F-Prot 4.4.4.56 20091126 2009-11-26 2.29 -
F-Secure 7.02.73807 2009.11.26.07 2009-11-26 0.14 -
Fortinet 11.98- 11.98 2009-11-26 0.28 -
GData 19.9020/19.587 20091127 2009-11-27 10.52 -
ViRobot 20091126 2009.11.26 2009-11-26 0.99 -
Ikarus T3.1.01.74 2009.11.27.74602 2009-11-27 4.15 -
JiangMin 11.0.800 2009.11.25 2009-11-25 11.23 -
Kaspersky 5.5.10 2009.11.27 2009-11-27 0.07 -
KingSoft 2009.2.5.15 2009.11.27.7 2009-11-27 1.31 -
McAfee 5.3.00 5814 2009-11-26 3.43 -
Microsoft 1.5302 2009.11.26 2009-11-26 7.74 -
Norman 6.01.09 6.01.00 2009-11-25 4.01 -
Panda 9.05.01 2009.11.26 2009-11-26 1.97 -
Trend Micro 9.000-1003 6.654.07 2009-11-27 0.04 -
Quick Heal 10.00 2009.11.26 2009-11-26 2.19 -
Rising 20.0 22.23.04.01 2009-11-27 1.08 -
Sophos 3.01.0 4.47 2009-11-27 3.09 -
Sunbelt 5518 5518 2009-11-18 1.86 -
Symantec 1.3.0.24 20091126.016 2009-11-26 0.16 -
nProtect 20091125.01 6330100 2009-11-25 3.63 -
The Hacker 6.5.0.2 v00079 2009-11-26 0.85 -
VBA32 3.12.12.0 20091125.2123 2009-11-25 2.48 -
VirusBuster 4.5.11.10 10.113.30/2005475 2009-11-26 3.05 -
Unfortunately, you are infected with VIRUT

We would be grateful if you could assist us in our research into this infection by providing us with some samples and information from your machine. This will only take a minute or two to complete, and is very simple. If you wish to help us, please do the following:
  • Download VAPrep.bat and save it to your Desktop.
  • Double-click VAPrep.bat to run it. It will only take a moment to complete.
  • When done, please right-click the VAPrep folder which should now be on your Desktop. Select Send To >> Compressed (zipped) Folder.
  • Next, please go to this webpage.
  • Browse to the VAPrep.zip zipped folder you just created.
  • Click Send File.
Once done, you can delete the VAPrep folder and .zip file from you Desktop. Thanks for helping us out.



VIRUT
is a polymorphic file infector with some additional features. It spreads all around the drive and infects even files infected by another virus previously.

Unfortunately, the cleaning of this virus is not possible.

The only thing we recommend is to do a full reformat and install.

We have an excellent tutorial on how to reformat here

and for a Vista reformat re-install HERE

We do not recommend trying to save any files from this machine as they could all be infected and will simply re-infect your system again, there is no way of being certain what this infection can do.

It used to be certain documents, pictures etc. could be saved, but not any more. Virut is now known to infect all file formats.

Read more about the VIRUT FILE INFECTOR HERE

If you don't have a Windows Installation Disk (if this came with Windows pre-installed), you may have a Manufacturer restore disk to restore the computer to its original state - this depends on the Manufacturer though. Otherwise, give the Manufacturer a call and ask them to send you a restore disk or Windows installation CD.

Should you have any questions, please feel free to ask.

I am sorry there is nothing more that we can do.


More information:

http://free.avg.com/66558
There are bugs in the viral code. When the virus produces infected files, it also creates non-functional files that also contain the virus.

http://home.mcafee.com/VirusInfo/VirusProf…aspx?key=143034
W32/Virut.h is a polymorphic, entry point obscuring (EPO) file infector with IRC bot functionality. It can accept commands to download other malware on the compromised machine.
It appends to the end of the last section of executable (PE) files an encrypted copy of its code. The decryptor is polymorphic and can be located either:
Immediately before the encrypted code at the end of the last section
At the end of the code section of the infected host in 'slack-space' (assuming there is any)
At the original entry point of the host (overwriting the original host code)



Miekiemoes
, a highly regarded expert in malware removal, and an MS-MVP,
has an extremely informative blog post about Virut. - she only ever recommends a total reformat.

At least this way, you have the best chance of having a clean machine once more.

For future protection read this very well written article Think Prevention.
CatByte, Thanks for your assistance. Yea, wish it could have been better news, but………. I'll start a reformat and reinstall in the morning. I have forwarded the info you reqested.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI