Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: w32.virut.u virus ...! How to remove?  (Read 10383 times)

0 Members and 1 Guest are viewing this topic.

sanjaybijapur

    Topic Starter


    Beginner

    w32.virut.u virus ...! How to remove?
    « on: September 30, 2008, 03:18:45 AM »
    hai,

    in my laptop virus w32.virut.u is affected, I have symantec 10.1.4 corporation edition AV.  up dating regularly,

      How can I delete the virus without formatting the HDD?..

    pl help me

    OS :windows XP service pack2

    Ivy

    • Guest
    Re: w32.virut.u virus ...! How to remove?
    « Reply #1 on: September 30, 2008, 03:20:25 AM »
    Please read this first.

    Click here

    cpnkirk59



      Rookie

      Re: w32.virut.u virus ...! How to remove?
      « Reply #2 on: October 06, 2009, 11:39:18 AM »
      I have followed all the steps, posted on:

      http://www.computerhope.com/forum/index.php/topic,46313.0.html

      , to include using the ComputerHope HJT process tool (three times now). I have done this in safe and normal modes (I use SAS, MBAM, my subscription Norton Anti-virus, then HJT). I have deleted  the quarantined files, followed the instructions from the HJT process tool and felt I was safe; until I reboot in normal mode. At this point, I get a norton AV pop-up that says I have W32.virut.cf, that it can't remove (this has happened three times - I'm going through all the steps again for the fourth time, as I type).
      Additionally, I found "Virut Removal Tool" on the Symantec website, and it can't find anything (I've run it in Safe mode, per the instructions). After the Norton msg, I run a full Norton scan in normal mode (and find nothing); before, I go back to safe mode and run all the steps listed in the first thread (previously, I hadn't turned off my Norton. As my SAS is scanning presently, I disabled the Norton AV/Antispyware).
      I will post my logs; but, as I mentioned I felt very comfortable after running the process tool on my HJT log. Everything your tool said to fix, coincided with what my untutored brain could pick up from the HJT log.

      Thanks,
      RP

      P.S. I have an HP Pavillion dv1000, Windows XP w/SP2, current Norton AV/AS, SAS/MBAM/HJT.

      evilfantasy

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Calm like a bomb
      • Thanked: 493
      • Experience: Experienced
      • OS: Windows 11
      Re: w32.virut.u virus ...! How to remove?
      « Reply #3 on: October 06, 2009, 01:43:14 PM »
      Unfortunately the only reliable cure for Virut is a complete reformat and reinstall. See here for more information. Virut and other File infectors - Throwing in the Towel?

      Many of the major antivirus vendors have Virut removal tools but many times Virut is not repairable. The only reliable way to remove Virut is removing the system files it has infected and in turn crippling the system and calling for a reformat/reinstall anyway. Remember it is always spreading so trying to contain it is impossible. See this article on why it is so destructive. Under the Hood: Virut

      If you do try to repair this without reformatting then your best chance is using the Avira AntiVir Rescue CD. (free) And/or the Dr Web LiveCD. (also free)

      Backing up files before formatting

      If you backup any files they should be scanned from a clean properly protected PC before restoring. Also be careful what scanner is used as some are very poor at detecting and even worse at protecting from this infection. In fact due to the nature of these new infections there are probably no tools that will properly protect you from the infection. Be very selective and only backup files you can not replace like text documents and personal photos.

      Do not back up to another machine! It will likely become infected by Virut. Burn to DVD/CD, a flash drive or to an external drive which has nothing else on it and which you can format should it become infected from the backups.

      I suggest running at least 3 of the below scanners on the backup files. Run the first scan then reboot before running the second then reboot after the second before running the third.
       
      -) Dr.Web CureIt!
      -) AVG Win32/Virut Removal Tool
      -) Symantwc W32.Virut Removal Tool
      -) McAfee Avert Stinger
      -) Microsoft Windows Malicious Software Removal Tool

      If you do not know how to perform a fresh install, use this website -> http://www.windowsreinstall.com/

      Very important, do the following immediately or as soon as possible!

      If you have done any online transactions, call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts and/or change all of your account numbers.
       
      From a clean computer change all of your online passwords including for email, banks, financial accounts, PayPal, eBay, online credit card companies and any online forums or groups you belong to etc.

      DO NOT change passwords or do any transactions while using the infected computer. The attacker will get the new passwords and transaction information.

      cpnkirk59



        Rookie

        Re: w32.virut.u virus ...! How to remove?
        « Reply #4 on: October 07, 2009, 12:29:01 AM »
        As usual, I appreciate the help! You guys do a great service.

        RP

        cpnkirk59



          Rookie

          Re: w32.virut.u virus ...! How to remove?
          « Reply #5 on: October 11, 2009, 11:14:41 PM »
          EvilFantasy,
               Ran both Avira and DrWeb rescue/live cds about four times. Avira wouldn't cure anything in normal, and couldn't find the Virut.cf. DrWeb only found two virus. Ran Avira again with the file rename option. Below are the listed affected files (I hand typed on this computer and didn't copy the malware names). Didn't try to delete them yet and none were warned to have Virut.cf. I am still getting a Norton warning of Virut.cf when I boot in normal mode (the computer seems to boot normally, even after Avira renamed the affected files).

          Programfiles/i386/win9xmig/awdvstub.exe
          Programfiles/serials 2000 7.1 plus/revcrt.dll
          /media/devices/hda1/sdfix/apps/restartit!.exe
          Various Norton files and
          Spybot archives
          documents and settings/randy/local sttings/temporary internet files/content.IE5/swflash[1].cab
          /media/devices/hda1/windows/system32/napstat.exe
          /media/devices/hda1/windows/nircmd.exe
          /meida/devices/hda1/windows/system32/IME/pintlgnt/imscinst.exe
          /media/devices/had/windows/system32/dllcache/imscinst.exe
          /media/devices/hda1/windows/installer/{91120409-6000-11D3-8CFE-0150048383C9}/mspicons
          /media/deices/had/WINDOWS/Installer/{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}/ICONCDDCBBF13.exe
          /media/deices/had/WINDOWS/Installer/{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}/ICONCDDCBBF15.exe
          /media/deviceshda1/WINDOWS/Installer/{350C97BO-3D7C-4EE8-BAA9-00BCB3D54227}/places.exe
          /media/Devices/hda1/Windows/ServicePackFiles/i386/napstat.exe
          /media/Devices/hda1/WINDOWS/ServicePackFiles/i386/stub_fpsrvadm.exe
          /media/Devices/HAD/Windows/ServicePackFiles/i386/lang/imscinst.exe
          Media/Devices/hda1/WINDOWS/SoftwareDistribution/Download/dd9ab5193501484cf5e6884fa1d22f9e/napstat.exe
          Media/Devices/hda1/WINDOWS/SoftwareDistribution/Download/dd9ab5193501484cf5e6884fa1d22f9e/spnpinst.exe
          Media/Devices/hda1/WINDOWS/SoftwareDistribution/Download/dd9ab5193501484cf5e6884fa1d22f9e/stub_fpsrvadm.exe
          Media/Devices/hda1/WINDOWS/SoftwareDistribution/Download/dd9ab5193501484cf5e6884fa1d22f9e/imscinst.exe
          Media/devices/hda1/windows/$NTServicePackUninstall$/userinit.exe


           I haven't turned on my wireless on the affected computer; because of the Norton warning. Do I need to select the third option on Avira and "delete" while it is scanning to git rid of this virus? Based on the files above; can you tell me what devices/OS/software is affected (i.e. that I've lost) and is there anywhere I can download the lost files and replace the infected ones.

          Thanks.

          P.S. I know I have to uninstall Norton and SpyBot. Haven't done it yet, as it is the only Anti-virus that has indicated I have the Virut.cf.