Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help > Resolved HJT Threads
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Resolved HJT Threads Resolved spyware and popup issues.

 
 
LinkBack Thread Tools
Old 05-17-2009, 11:15 AM   #1 (permalink)
Registered User
 
Join Date: May 2009
Posts: 4
OS: Windows XP


Can't get rid of Win32.Virut virus

Good evening. I've got a really serious problem. At least, it looks serious to me. Two weeks ago I noticed that I got Reader_S.EXE, Services.EXE, CMD.EXE, BN16.TMP and some other weird processes. Later I realized those had been viruses. Tried Malwarebytes, AVG Antivirus and Spyware Doctor. These helped, but the virus appeared again. So the only solution was to format my Windows.
Alright, I've done format twice. I've started my Windows and few minutes later I got that virus again. I couldn't believe. When I start my Windows now, it just crashes. I really doubt that it's Windows XP Service Pack 2 CD problem, it's clean. If anyone knows, what's the matter, please, let me know.
Wrinkle is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 05-17-2009, 12:33 PM   #2 (permalink)
Moderator, Analyst, Security Team ; Rangemaster, TSF Academy
 
amateur's Avatar
 
Join Date: Jun 2006
Location: USA
Posts: 7,436
OS: XP SP3


Re: Can't get rid of Win32.Virut virus

Hello and welcome to TSF.

Quote:
Can't get rid of Win32.Virut virus
Virut is a polymorphic file infector, infecting all the executable files(.exe) and screen saver files(.scr) by way of corrupting them beyond repair. . Unfortunately, the best approach is to reformat and reinstall as you have already done. However, you are possibly getting re-infected by your backed up data.

While backing up your files prior to r/r, you were to make sure that you do not backup any executables, screen savers and compressed files such as zip, rar and cab, and also the htm/html/php files as they may also contain infected files.

Backups are not be made to another machine or another internal harddrive, as they may become compromised. Best to burn to DVD/CD, or to an external drive which has nothing else on it, and which you can format should it happen to become infected from the backups.

Here's some information on this infection:

http://www.microsoft.com/security/en...=Win32%2fVirut
http://vil.nai.com/vil/content/v_143034.htm
http://www.avast.com/eng/win32-virut.html
http://www.symantec.com/security_res...558-99&tabid=1

You'll have to reformat and reinstall again, I am afraid.
__________________
My services are free. However, you can donate to TSF to help keep it running.




Member of ASAP since 2005
Member of UNITE since 2006

Last edited by amateur; 05-17-2009 at 12:36 PM.
amateur is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 05-17-2009, 01:36 PM   #3 (permalink)
Registered User
 
Join Date: May 2009
Posts: 4
OS: Windows XP


Re: Can't get rid of Win32.Virut virus

Quote:
Originally Posted by amateur View Post
Hello and welcome to TSF.



Virut is a polymorphic file infector, infecting all the executable files(.exe) and screen saver files(.scr) by way of corrupting them beyond repair. . Unfortunately, the best approach is to reformat and reinstall as you have already done. However, you are possibly getting re-infected by your backed up data.

While backing up your files prior to r/r, you were to make sure that you do not backup any executables, screen savers and compressed files such as zip, rar and cab, and also the htm/html/php files as they may also contain infected files.

Backups are not be made to another machine or another internal harddrive, as they may become compromised. Best to burn to DVD/CD, or to an external drive which has nothing else on it, and which you can format should it happen to become infected from the backups.

Here's some information on this infection:

http://www.microsoft.com/security/en...=Win32%2fVirut
http://vil.nai.com/vil/content/v_143034.htm
http://www.avast.com/eng/win32-virut.html
http://www.symantec.com/security_res...558-99&tabid=1

You'll have to reformat and reinstall again, I am afraid.
Hello. Thanks a lot for trying to help. The problem is that I've made no back ups. Didn't even try to download anything.
Wrinkle is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 05-17-2009, 03:26 PM   #4 (permalink)
Moderator, Analyst, Security Team ; Rangemaster, TSF Academy
 
amateur's Avatar
 
Join Date: Jun 2006
Location: USA
Posts: 7,436
OS: XP SP3


Re: Can't get rid of Win32.Virut virus

Hi,

Quote:
The problem is that I've made no back ups. Didn't even try to download anything.
What happened to your personal documents, pictures, music, video, etc? Did you perform a clean install or a re-install? A reformat would wipe everything on the harddisk. Here's a good guide for reformat and reinstall, i.e. clean install, for your information:

How to format the current system drive and reinstall the operating system

Quote:
Alright, I've done format twice. I've started my Windows and few minutes later I got that virus again.
How did you know it was the same virus?
__________________
My services are free. However, you can donate to TSF to help keep it running.




Member of ASAP since 2005
Member of UNITE since 2006
amateur is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 05-18-2009, 07:18 AM   #5 (permalink)
Registered User
 
Join Date: May 2009
Posts: 4
OS: Windows XP


Re: Can't get rid of Win32.Virut virus

Quote:
Originally Posted by amateur View Post
Hi,

What happened to your personal documents, pictures, music, video, etc? Did you perform a clean install or a re-install? A reformat would wipe everything on the harddisk. Here's a good guide for reformat and reinstall, i.e. clean install, for your information:

How to format the current system drive and reinstall the operating system

How did you know it was the same virus?
Good afternoon. I've done a full reformat, nothing is left on C:\, as I have only one Hard Disk. After reformat, Windows had been installed. Installation was successful, so I had started Windows. While browsing C:\, Firewall noticed me that Reader_S.EXE is trying to connect. Declined it and suddenly computer crashed. Later on, after it was restarted, I had seen Reader_S.EXE, Services.EXE, CMD.EXE, BN.TMP etc. in Processes. Even some adult web sites started to appear every 10 minutes or so. Have a good day and Thank You.
Wrinkle is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 05-18-2009, 10:02 AM   #6 (permalink)
Moderator, Analyst, Security Team ; Rangemaster, TSF Academy
 
amateur's Avatar
 
Join Date: Jun 2006
Location: USA
Posts: 7,436
OS: XP SP3


Re: Can't get rid of Win32.Virut virus

Quote:
While browsing C:\, Firewall noticed me that Reader_S.EXE is trying to connect.
This tells me that you had a third party firewall installed as Windows XP firewall does not protect against the outgoing traffic.

http://www.microsoft.com/windowsxp/u...2_wfintro.mspx

Quote:
What Windows Firewall Does and Does Not Do
It does It does not

Detect or disable computer viruses and worms if they are already on your computer. For that reason, you should also install antivirus software and keep it updated to help prevent viruses, worms, and other security threats from damaging your computer or using your computer to spread viruses to others.
I am not really sure if I understand your point but it sounds like you're saying that Virut infection survives a reformat. That cannot be unless you're installing the operating system from a questionable copy, which itself may be viruted, or installing other data/software which is/are viruted.

There's no point in discussing this any further. If you're able to provide the logs requested in our pre-posting NEW INSTRUCTIONS sticky, we'll check them out for you and advise you accordingly.
__________________
My services are free. However, you can donate to TSF to help keep it running.




Member of ASAP since 2005
Member of UNITE since 2006
amateur is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 05-18-2009, 12:51 PM   #7 (permalink)
Registered User
 
Join Date: May 2009
Posts: 4
OS: Windows XP


Re: Can't get rid of Win32.Virut virus

Quote:
Originally Posted by amateur View Post
This tells me that you had a third party firewall installed as Windows XP firewall does not protect against the outgoing traffic.

http://www.microsoft.com/windowsxp/u...2_wfintro.mspx



I am not really sure if I understand your point but it sounds like you're saying that Virut infection survives a reformat. That cannot be unless you're installing the operating system from a questionable copy, which itself may be viruted, or installing other data/software which is/are viruted.

There's no point in discussing this any further. If you're able to provide the logs requested in our pre-posting NEW INSTRUCTIONS sticky, we'll check them out for you and advise you accordingly.
Well, that's the matter. It was Windows Firewall, not Thirt Party Software. Thanks for some advices. I'll try using another copy of Windows XP. Have a good evening.
Wrinkle is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 05-18-2009, 01:17 PM   #8 (permalink)
Moderator, Analyst, Security Team ; Rangemaster, TSF Academy
 
amateur's Avatar
 
Join Date: Jun 2006
Location: USA
Posts: 7,436
OS: XP SP3


Re: Can't get rid of Win32.Virut virus

You're welcome and good luck!
__________________
My services are free. However, you can donate to TSF to help keep it running.




Member of ASAP since 2005
Member of UNITE since 2006
amateur is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 05-20-2009, 12:50 PM   #9 (permalink)
Moderator, Analyst, Security Team ; Rangemaster, TSF Academy
 
amateur's Avatar
 
Join Date: Jun 2006
Location: USA
Posts: 7,436
OS: XP SP3


Re: Can't get rid of Win32.Virut virus

Since this issue appears resolved, this topic will now be closed. If you need continued support, please begin a new thread, and provide a link to this topic. This applies only to the original topic starter. Everyone else please begin a New Topic, after following the steps outlined here:

http://www.techsupportforum.com/secu...oval-help.html

Surf Safely, and Think Prevention!
__________________
My services are free. However, you can donate to TSF to help keep it running.




Member of ASAP since 2005
Member of UNITE since 2006
amateur is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
 


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 08:34 AM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85