Virut.ce - Please Help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by hcarson, Jun 8, 2010.

  1. hcarson

    hcarson Private E-2

    to try and make a long story short, my son's computer is infected with the win32virut.ce From what I have been reading there is no removal of this nasty thing and the only solution would be to reinstall OS. I do not have a disk..the computer did not come with one when I purchased it new a few years ago. It is an HP computer and I am running Windows XP.

    If I am reading wrong and there is a removal of this thing someone please help me. If not, what do I do? Is there a way to clean and reinstall without a disk?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    If you really do have a Virut infection then yes you will have to reinstall.

    Let's see if we can quickly determine if you have a Virut infection. Please follow the instructions in the below link to run MGtools then attach the requested MGlogs.zip file.

    Using MGtools
     
  3. hcarson

    hcarson Private E-2

    Well I ran Vipre (spelling) and that is where it told me that I have the virut. I also tried to run Combo Fix (from a clean flashdrive I downloaded from my laptop, which is clean) and I got an error saying that the file had been corrupt, and I may have the virut..then removed the program.

    I will run the MGTools tomorrow as I just got home and am too tired to mess with it tonight. I am a little confused though, I tried to reinstall last night...the computer which is a Compaq Win XP desktop did not come with a disk when I purchased it. I remember having to do the F11 thing when I first got the machine 4+ years ago because Windows was corrupt...yet when I tried last night I was getting an error saying there were no partitions found.

    Anyway, thank you and I will post the log tomorrow night.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now the probability is even higher that you have Virut, but running MGtools and giving us the log will likely give us the info we need to determine for sure if it is Virut.

    It is pretty simple. Download it and then double click it to run it. When it finishes, you will have the C:\MGlogs zip file to attach. It will take as little as 3 minutes to as much as 15 minutes to run depending on hard disk size and number of files and folders on the PC.

    Then perhaps something done in the past erased your recovery partition.
     
  5. hcarson

    hcarson Private E-2

    I am sorry it took me so long to get back to you it has been a crazy week. Ok I just tried running the MG Tools and it is not working. The black screen comes up and then goes down again. It does not stay up long enough for me to read it, but at the end it says something like Deleting It! and I think it was referring to log files. Am I doing something wrong?

    I tried running that Symantic Virut Removal tool, it said it deleted the virut, but it didn't, because I still cannot run Combo Fix I am getting the same error. I ran Malware Bites this morning, first there were 25 infected files, the second time there were 2 that said would be deleted upon reboot of my computer.

    The two files that show that were infected were
    C:\WINDOWS\system32\Drivers\ntndis.sys (Rootkit.Agent) -> Delete on reboot

    C:\WINDOWS\system32\ipsecndis.sys (Rootkit.Agent) -> Delete on reboot

    I have not ran it a 3rd time to see if it would completely clean. I can tell you the first time I ran Malware Bites was on 5/25/10 and there were 223 infected files, 9 registry keys infected, 9 registry values infected. The majority were Backdoor.Bot and all said quarantined and successfully deleted, which was not the case because more kept coming back. The one thing I can say is that since I ran that Symantic Virut Removal Tool, I am getting messages after I am done running Malware Bites saying that the files will be deleted after reboot, I never got that message before. Also I need to mention that I have disconnected the machine from the internet.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try the below.

    Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.


    Waste of time. It cannot fix it. You must format.
     
  7. hcarson

    hcarson Private E-2

    Ok, it did change to C:\MGTools> like you said, but when I typed ShowNew I got the following error message

    'ShowNew' is not reconized as an internal or external command, operable program or batch file.

    I had the MG Tools on my flashdrive, because I had to download it from my clean laptop and then put it on the infected PC. I just tried moving the file from the flash drive to the desktop of the PC and it seemed to have started to run ok...It gets to where it says Running processdl.exe to find loaded DLL's then I get an error screen

    ProcessDLL.exe - Application Error
    The application failed to initialize properly (0xc000007b). Click on OK to terminate the application

    But it did create logs, there are several in the C:]MGlogs.zip. Which do you want posted the hijackthis.log?
     
    Last edited: Jun 12, 2010
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's do something different. From the command prompt window, type the below two commands and tell me the size of the files that is shown in bytes.

    dir C:\windows\explorer.exe
    dir C:\windows\userinit.exe


    Also which service pack level do you have installed for Win XP?
     
  9. hcarson

    hcarson Private E-2

    Please read the message before this one, but I wanted to attach all of the logs in this post..just an FYI, I am doing this with a flash drive from the infected pc to my laptop. Every time I put the flash drive in my laptop I scan it first with my AV and every file I download says it was infected with the win32/virut.17408, and it was cleaned by my AV. I had the same AV program in the pc, why didn't it detect and clean it there as well?
     

    Attached Files:

    Last edited: Jun 12, 2010
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I already did. You need to do what I requested in my last message only.
     
  11. hcarson

    hcarson Private E-2

    C:\windows\explorer.exe -
    1 File <s> 1,058,816 bytes
    0 Dir <s> 128,895,434,75 bytes free

    C:\windows\userinit.exe -
    it says, "file not found"

    Service Pack is 3
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry! That was supposed to say

    dir C:\windows\system32\userinit.exe


    However, it does not matter anymore. The one for explorer.exe already reveals that you definitely have a Virut infection. Below is a blurb we post to everyone getting this infection. Sorry to be bring you the bad news. :(


    I can see the reason for your problems. Your logs show that your Windows Operating system files have become infected by a Virut infection and there is no known reliable fix for this. In addition there are many many other infected files. We could spend a lot of time trying to remove this infection, but odds are that it will not work because the nature of the infection has so many executable system files infected that as soon as we fix one file, other files that are infected will almost immediately or upon the next reboot, just reinfect the files. In addition, your PC would still basically be unreliable/untrustworthy even if we manage to fix the infected files that we can see since there could be many more that we are not seeing.

    The safest thing for you to do is backup your personal data immediately since your PC could possibly become unbootable at any point in time. Do not back up any executable files. This includes programs that you have downloaded since any of them could be infected. Anything you may have already backed up that is an executable type file (things you downloaded to install programs....etc) are most likely infected and will cause you to be reinfected if you reuse these files.

    Once you backup, you need to format partitions and reinstall Windows and all other software especially your protection software. Then install all updates for all software. DO NOT reinstall from any executable file backups you made while this PC was infected or you will just be reinstalling the infection.
     
  13. hcarson

    hcarson Private E-2

    Well I kind of went into this knowing I had the Virut so it really isn't a surprise. Now for my next step. When I bought the PC it did not come with a recovery disk. Can I format partitions and reinstall windows without a disk? As I said before, when I first bought the pc I had to reinstall windows because it kept crashing, although when I tried following instructions online (to locate the i3xx file) I got an error saying that there were no partition files. Perhaps I was doing it wrong?

    In short, I have no clue how to do this, can you help me with instructions, or am I going to need to purchase a disk? Also I am just curious about something. As I mentioned I had to use a flash drive from the infected pc to my laptop each time, so of course I scanned the flash drive and it revealed I had the virut in any files that I took from the pc...my av deleted the infected files. My question is this, I had the same av on the pc, why didn't it pick up those files before the computer became infected? Just curious..
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is a topic for the Software Forum; however you cannot use ANYTHING that is on the hard disk to reinstall. It is all infected. You need a Windows CD or a recovery partition installed on a different partition if your PC manufacturer made this partition. Without a Recovery Partition or equivalent CDs or with out a Windows CD for this PC, you are out of luck and will have to purchase one.


    While the infection is active on a PC, the AV programs themselves will even become infected like every other executable file and thus are not trust worthy. And with the infection active and in memory, it can prevent you from being able to detect it on that PC. If you took that flash drive to another PC, you really need to check that PC or any other PC you plugged it into, for the Virut infection. If even one infected file remains, you could trash other PCs.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds