PC Review


Reply
Thread Tools Rate Thread

How can I confirm and remove Win32.Virut.A ?

 
 
Maximus the Mad
Guest
Posts: n/a
 
      2nd Nov 2007
(E-Mail Removed) after much thought,came up with this jewel in
news:(E-Mail Removed):

>
> Hi Folks,
>
> I downloaded the FREE version of PCTools AV and did a scan on

several
> large internal and external hard drives. It found, and quarantined)
> over 1,300 EXE files saying that they were infected with
> "Win32.Virut.A".
>
> Is there a way for me to manualy verify that this infection exists.
> Also, is there a tool to "disenfect these files instead of simply
> deleting them?
>
> Thank you for helping,
>
> Don
>


Submit the files in question to www.virustotal.com You could also use
David Lipman's AV tool to scan each file(it includes 4 diferent
scanners). BitDefender has a on-demand scanner that you can install
also.
Many files cannot be disinfected because they are not valid windows
files.
max
--
Virus Removal http://max.shplink.com/removal.html
Keep Clean http://max.shplink.com/keepingclean.html
Tools http://max.shplink.com/tools.html
Change nomail.afraid.org to gmail.com to reply by email.
 
Reply With Quote
 
 
 
 
jen
Guest
Posts: n/a
 
      2nd Nov 2007
"Maximus the Mad" <(E-Mail Removed)> wrote in message
news:Xns99DCB806DE586whatsinaname@207.115.33.102...
> (E-Mail Removed) after much thought,came up with this jewel in
> news:(E-Mail Removed):
>> Hi Folks,
>> I downloaded the FREE version of PCTools AV and did a scan on

> several
>> large internal and external hard drives. It found, and quarantined)
>> over 1,300 EXE files saying that they were infected with
>> "Win32.Virut.A".
>> Is there a way for me to manualy verify that this infection exists.
>> Also, is there a tool to "disenfect these files instead of simply
>> deleting them?

> Submit the files in question to www.virustotal.com You could also use


"over 1,300 EXE files"? Hope he's got a lot of time on his hands, lol


> David Lipman's AV tool to scan each file(it includes 4 diferent
> scanners). BitDefender has a on-demand scanner that you can install
> also.
> Many files cannot be disinfected because they are not valid windows
> files.


-jen


 
Reply With Quote
 
Infected@diseased.net
Guest
Posts: n/a
 
      2nd Nov 2007

Hi Folks,

I downloaded the FREE version of PCTools AV and did a scan on several
large internal and external hard drives. It found, and quarantined)
over 1,300 EXE files saying that they were infected with
"Win32.Virut.A".

Is there a way for me to manualy verify that this infection exists.
Also, is there a tool to "disenfect these files instead of simply
deleting them?

Thank you for helping,

Don
 
Reply With Quote
 
Maximus the Mad
Guest
Posts: n/a
 
      2nd Nov 2007
"jen" <(E-Mail Removed)> after much thought,came up with this jewel
in news:whNWi.48531$(E-Mail Removed):

> "over 1,300 EXE files"? Hope he's got a lot of time on his hands,
> lol
>


Perhaps he is on an extended leave of absence......
--
Virus Removal http://max.shplink.com/removal.html
Keep Clean http://max.shplink.com/keepingclean.html
Tools http://max.shplink.com/tools.html
Change nomail.afraid.org to gmail.com to reply by email.
 
Reply With Quote
 
jen
Guest
Posts: n/a
 
      2nd Nov 2007
"Maximus the Mad" <(E-Mail Removed)> wrote in message
news:Xns99DCBA3C49D57whatsinaname@207.115.33.102...
> "jen" <(E-Mail Removed)> after much thought,came up with this jewel
> in news:whNWi.48531$(E-Mail Removed):
>> "over 1,300 EXE files"? Hope he's got a lot of time on his hands,
>> lol
>>

> Perhaps he is on an extended leave of absence......


If he's not now, I'm sure he will be after this )))

-jen


 
Reply With Quote
 
jen
Guest
Posts: n/a
 
      3rd Nov 2007
<(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> Hi Folks,
> I downloaded the FREE version of PCTools AV and did a scan on several
> large internal and external hard drives. It found, and quarantined)
> over 1,300 EXE files saying that they were infected with
> "Win32.Virut.A".
> Is there a way for me to manualy verify that this infection exists.
> Also, is there a tool to "disenfect these files instead of simply
> deleting them?


Win32.Virut.A is an appending virus. This file infector infects .exe
and .scr files by attaching its encrypted code to the end of the file.

The encrypted code contains IRCBot functionality.

When Win32.Virut.A is executed it injects it's code into all running
processes.

Win32.Virut.A opens up a backdoor at port 65520 on the compromised
machine.

This virus tries to connect to IRC servers located at:

* proxima.ircgalaxy.

Symptoms -

# Modified executable files (increase of 5,120 bytes of exe files)
# DNS queries to proxima.ircgalaxy.pl and IRC related network traffic

Method of Infection -

Win32.Virut.A is a file infecting virus. Infection starts with *manual
execution* of the binary. Executables in network shares may also get
infected if accessed by the compromised machine. This virus can also be
instructed to scan for vulnerable systems and infect them.

Good luck,

-jen



 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Re: HELP! I killed my computer with the help of win32/virut.a Ray Luca Windows XP Help 3 25th Apr 2009 01:35 PM
Re: HELP! I killed my computer with the help of win32/virut.a Buffalo Windows XP Help 2 22nd Apr 2009 02:00 AM
Re: HELP! I killed my computer with the help of win32/virut.a David H. Lipman Windows XP Help 0 22nd Apr 2009 01:54 AM
Re: HELP! I killed my computer with the help of win32/virut.a db Windows XP Help 0 20th Apr 2009 04:13 PM
Defender Does nor remove Win32/Fotomoto and Win32/Virtumonde =?Utf-8?B?QUNT?= Spyware Discussion 5 14th Aug 2007 01:57 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 07:26 PM.