Friday 7 October 2011

How to corner and kill the "win32.virut" virus?

Hi, I have been infected with a new version of win32.virut


For those of you who arent sure what kind of virus this is: It is a poliphorphing virus that changes its name every time it infects your computer, and continuously infects files throughout your hard drives, flash drives, external drives, and other networked computers.


It also injects itself into various critical system files like svchost (generic host).





I have disconnected all hard drives but one, re-formated the one left, and re-installed windows on it.





I now need to establish a decent protection and removal method agiainst the virus on the other hard drives when I re-connect them.





Does anyone have suggestions on what antivirus programs would be best for prevention agiainst this virus?





Also, I%26#039;m wondering if there is a way to run the whole dis-infection process in a virtual windows or something to prevent risk of re-infecting my main OS...|||You should carry out a format and clean install of your remaining hard drive because there isn%26#039;t a tool right now that can remove Virut. I can tell that you researched alot about Virut. Have a look in this link to tell you more about Virut and see why you should carry out a full format and clean install. I wish I can say there is a tool but there isn%26#039;t one.





It is far much easier and stress free just to flatten down your operating system and start again, at least this way, you know for sure that Virut is gone. What if you did carry on with the cleaning process in a virtual windows or other method, you have no way of knowing for sure that Virut is gone, especially it can infect all executable files and the damage to your files could be so great that it is unrepairable.





Have a look in this to tell you what you can and cannot backup otherwise you will re-infect your hard drive again if you backup the wrong files





%26quot;Virut is not disinfectable. Your only option is to perform a full reformat. Do NOT attempt a repair install. It shall be a waste of time. If you do so, the infected executables remain on the machine %26amp; you shall likely trigger another bout of Virut.%26quot;





http://www.bleepingcomputer.com/forums/l鈥?/a>





EDIT: I missed out your another question. Don%26#039;t rely on security programs to protect you because that is a wrong way of looking at it. YOU are the best hope that you can give to your computer.





%26quot;This kind of infection is contracted and spread by visiting remote, crack and keygen sites. These type of sites are infested with a sm枚rg氓sbord of malware and an increasing source of system infection. However, the CA Security Advisor Research Blog says they have found MySpace user pages carrying the malicious Virut URL.%26quot;|||I guess I%26#039;m in that 1%. rmvirut did NOTHING to help me. Ran it 3 times and it was a complete waste of time.

Report Abuse


|||i am using best antivirus protection reviews for my computer and really have great experience with this security system. i suggest you to use the best antivirus software like Macrovirus-oncall.|||Hey,





Here is a specific tool for these type of viruses powered by AVG. Please download and scan,





Result is 99% effecitve.





http://free.avg.com/us-en/virus-removal.鈥?/a>|||Free McAfee Avert stinger remove some forms of win32.virut





Does anyone have suggestions on what antivirus programs would be best for prevention agiainst this virus?





No AV gives 100% protection, however if you have a 32bit PC you might want to look at running free sandboxie.|||You have to stop your system restore. Do this by starting system restore and on the left it states to start or stop. You must stop system restore. With your virus protector, do a full scan. That will take out any malware or viruses that has been injected into your restore points. Don%26#039;t for get to turn your system restore back on. You can then do a reboot.