View Single Post
Old 03-03-2009, 08:44 AM   #4 (permalink)
amateur
Moderator, Analyst, Security Team ; Rangemaster, TSF Academy
 
amateur's Avatar
 
Join Date: Jun 2006
Location: USA
Posts: 7,450
OS: XP SP3


Re: Virut.j and Mariofev!mem Infection UPDATE! HELP!

Hi,

Quote:
But based on my logs and whatnot, is there any solution you can offer me regarding the Mariofev!mem infection? I was able to contain Virut.j and eliminate it for the most part.

I would like to know more about this virus.
Your log is riddled with infection, including backdoor trojans, Virut being the worst of all. It's polymorphic structure makes it difficult to detect and clean, because its code is constantly changing. If this were to be my system, I wouldn't even hesitate a second to reformat and reinstall. As I already explained, Virut infects every exe file. This means that you may not delete these files, but they should be disinfected. And since it's a buggy virus, the files cannot be properly disinfected. Even if we attempt to clean it, our efforts will be futile. There's no tool that can fix this infection at the moment. Some tools claim to disinfect it but they also end up corrupting the system files in the end just like the virut itself. So, I am afraid there's no other option but a reformat and reinstall.

Btw, Virut is mostly spread via crack and keygen sites. In future, I would strongly recommend that you stay away from such sites.

Here's some information on this infection:

http://www.microsoft.com/security/en...=Win32%2fVirut
http://vil.nai.com/vil/content/v_143034.htm
http://www.avast.com/eng/win32-virut.html
http://www.symantec.com/security_res...558-99&tabid=1

If you need assistance in performing a clean install, here is a good guide to walk you through the process:

http://www.windowsreinstall.com/winx...tallguides.htm

You might also like to have a look at this blog by our colleague, miekiemoes:

http://miekiemoes.blogspot.com/2009/...-throwing.html
__________________
My services are free. However, you can donate to TSF to help keep it running.




Member of ASAP since 2005
Member of UNITE since 2006

Last edited by amateur; 03-03-2009 at 08:56 AM. Reason: to add more info
amateur is offline