Home / Software / Computer viruses and spyware / Re: Cannot remove this virus which started with Win32:JunkPoly [Cryp]
0 Members and 1 Guest are viewing this topic. « previous next »
Pages: 1 [2]  All - (Bottom) Print
Author Topic: Re: Cannot remove this virus which started with Win32:JunkPoly [Cryp]  (Read 6915 times)
evilfantasy
Malware Removal Specialist
Moderator
Genius



Thanked: 458
Posts: 11,711

Experience: Beginner
OS: Windows 7


Calm like a bomb

evilfantasy's blog
« Reply #15 on: April 23, 2009, 11:19:07 AM »

This is why my first and only suggestion when I see virut is to reformat and reinstall. Until then you can never be sure if the computer is clean or not.

Stay away from warez. It only takes one click and it's all over...
IP logged

astrosoup
Newbie



Thanked: 1
Posts: 1


« Reply #16 on: April 23, 2009, 12:54:04 PM »

Virut adds one or more iFrame tags to any html file it finds to redirect users to an exploit site.

Edit any html file on the infected computer and you'll see something like this at the bottom:

Code: [Select]
<- iframe src="http://ZieF,pl/rc/" width=1 height=1 style="border:'<- / iframe>',0Dh,0Ah
Virut makes similar changes to other file types such as .PHP, .ASP and .HTM, and is very hard for scanners to detect. So FYI don't bring web documents over in the backup when this infection finally brings you to your knees.

The most damning property of Virut is that it is polymorphic- it changes slightly with each replication, allowing some of the files infected to elude scanners. So if you scan your system with a boot cd repeatedly and follow up with a repair install, you may get virut to low for a while, but there is likely a file somewhere on your machine that will inevitably be activated before long, starting the entire infection over again.

Trying to remove Virut is an effort in futility, which is why evilfantasy and virtually every other malware expert who has experience with this infection will tell you that your only option is to reformat and reinstall, and to be careful what you transfer from your previous installation.

But feel free to keep trying. You'll just end up learning the hard way like I did.  ;D
IP logged
evilfantasy
Malware Removal Specialist
Moderator
Genius



Thanked: 458
Posts: 11,711

Experience: Beginner
OS: Windows 7


Calm like a bomb

evilfantasy's blog
« Reply #17 on: April 23, 2009, 12:58:19 PM »

Great post astrosoup and welcome to CH.
IP logged

Helpmeh
Egghead



Thanked: 116
Posts: 3,583

Experience: Experienced
OS: Windows XP


Roar.

1
« Reply #18 on: April 23, 2009, 06:01:24 PM »

Great post astrosoup and welcome to CH.
That site is known to give you Bloodhound.Exploit.196, is blocked by google and is rated extremely poorly on WOT...(link from googling http://ZieF.pl/rc/ that link doesn't go to the site for safety reasons)

For more information go to http://www.google.com/safebrowsing/diagnostic?site=http://zief.pl/rc/&hl=en

Visiting a site that has been injected with the iframe code while currently using the NoScript addon for firefox will not affect you as NoScript blocks iframes. But going to the actual website will infect you...I wonder if viewing the page source will get me infected...
IP logged

Where's MagicSpeed?
Quote from: 'matt'
He's playing a game called IRL. Great graphics, *censored* gameplay.
evilfantasy
Malware Removal Specialist
Moderator
Genius



Thanked: 458
Posts: 11,711

Experience: Beginner
OS: Windows 7


Calm like a bomb

evilfantasy's blog
« Reply #19 on: April 23, 2009, 07:12:43 PM »

It's definitely a nasty site. Does a LOT of damage. http://www.threatexpert.com/report.aspx?md5=71eb4db6da3338655c1ec3cb48489d03
IP logged

sxkorn
Topic Starter
Greenhorn



Posts: 8




« Reply #20 on: April 24, 2009, 05:42:03 AM »

So if you scan your system with a boot cd repeatedly and follow up with a repair install, you may get virut to low for a while, but there is likely a file somewhere on your machine that will inevitably be activated before long, starting the entire infection over again.
Like I said, I did not perform a reinstall and deleted all the files from the previous system. The current system is a fresh install and I previously formated the current system partition. All I did I kept other files, which were not infected according to kaspersky tool.

Virut adds one or more iFrame tags to any html file it finds to redirect users to an exploit site.

Edit any html file on the infected computer and you'll see something like this at the bottom:

Code: [Select]
<- iframe src="http://ZieF,pl/rc/" width=1 height=1 style="border:'<- / iframe>',0Dh,0Ah
Virut makes similar changes to other file types such as .PHP, .ASP and .HTM, and is very hard for scanners to detect. So FYI don't bring web documents over in the backup when this infection finally brings you to your knees.
The iFrame problem, mentioned in an earlier post, happened on my wife's computer, while browsing. It was not a web file on the computer and avast blocked access to that page. That computer was not infected and I scanned it just in case [no sign of virut found, like I said].

But feel free to keep trying. You'll just end up learning the hard way like I did
If I get it again, from the files I have on my computer, I will let you know. But I'm not ready to throw all I have as long as I don't have a reason just yet. I would delete infected files, but not those found not to be infected. Maybe I'm wrong, maybe not. I'll see and let u know.
IP logged
Pages: 1 [2]  All - (Top) Print 
Home / Software / Computer viruses and spyware / Re: Cannot remove this virus which started with Win32:JunkPoly [Cryp] « previous next »
 


Login with username, password and session length

Old Forum Search | Forum Rules
Copyright © 2010 Computer Hope ® All rights reserved.
Powered by SMF 2.0 RC3 | SMF © 2006–2010, Simple Machines LLC
Page created in 0.087 seconds with 22 queries.