Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET NOD32 Antivirus Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old February 18th, 2008, 01:08 PM
Ant 1 Ant 1 is offline
Infrequent Poster
 
Join Date: Feb 2008
Posts: 9
Exclamation win 32 virut

plzz guys help me out
some win32/virut ap virus has infected all my .exe files
and nod32 is popping up every now and then asking to delete these files
1st timr it happened i deleted withouut knowing i had deleted files from system 32 .
this time i have left all the files alone
how can i get rid of this virut
is there any way to clean this mess without having to format my pc
  #2  
Old February 18th, 2008, 01:34 PM
Causes Drowsiness's Avatar
Causes Drowsiness Causes Drowsiness is offline
Infrequent Poster
 
Join Date: Nov 2006
Location: Behind you...
Posts: 12
Default Re: win 32 virut

The only thing I know to do for this is to disable System Restore (you can look that up online if you don't know how), make sure NOD is up to date and run a full scan of your system in safe mode.
  #3  
Old February 18th, 2008, 02:18 PM
THE_BAD_BOY THE_BAD_BOY is offline
Infrequent Poster
 
Join Date: Nov 2007
Posts: 40
Default Re: win 32 virut

virut its one of dangers infections on the net .. because ones has infected all your exe files its imposible to remove it

Virut is a virus that infects any executable files and screensavers that the user accesses. The parasite also opens a back door providing the attacker with unauthorized remote access to the compromised computer. The intruder can upload and run arbitrary files.

do hou have try scaning on safe mode? trsy that also download and run a system scan with SUPERAntispyware
or get support from eset moderator,s :p
__________________
Security Setup: /Nod32-AV/Comodo Pro Firewall /RegDefend/SUPERAntispyware Pro/Firefox-2/Spywareblaster/
Computer: Gateway/ Intel pentium (R) D 2.80ghz / 3 gb DDR2 RAM
ISP: RoadRunner (15 mbps/10 mbps)
Location: , Fl, USA
  #4  
Old February 18th, 2008, 02:29 PM
proactivelover's Avatar
proactivelover proactivelover is offline
Frequent Poster
 
Join Date: Apr 2006
Location: Near Wilders Forums
Posts: 786
Default Re: win 32 virut

Eset Have Added This Virus Signature Since
NOD32 - v.2834 (20080129)
Virus signature database updates:
Win32/Delf.NAM, Win32/Nuwar.Gen, Win32/Rbot, Win32/VB.GW, Win32/VB.H, Win32/VB.IH, Win32/VB.IY (2), Win32/VB.NJA, Win32/VB.NJT, Win32/VB.R, Win32/Virut.AG, Win32/Virut.AP
R U First Install EAV
Or
Update First Time
  #5  
Old February 18th, 2008, 02:34 PM
proactivelover's Avatar
proactivelover proactivelover is offline
Frequent Poster
 
Join Date: Apr 2006
Location: Near Wilders Forums
Posts: 786
Default Re: win 32 virut

Quote:
Originally Posted by THE_BAD_BOY
virut its one of dangers infections on the net .. because ones has infected all your exe files its imposible to remove it

Virut is a virus that infects any executable files and screensavers that the user accesses. The parasite also opens a back door providing the attacker with unauthorized remote access to the compromised computer. The intruder can upload and run arbitrary files.

do hou have try scaning on safe mode? trsy that also download and run a system scan with SUPERAntispyware
or get support from eset moderator,s :p
Ha Ha Ha
This Is Eset Forum Not Superantispyware
And For Your Kind Information Superantispyware Is A Antispyware Not AntiVirus They Did Not Add Viruses In There Database
  #6  
Old February 18th, 2008, 02:42 PM
ASpace's Avatar
ASpace ASpace is offline
Very Frequent Poster
 
Join Date: Apr 2006
Location: Europe/Bulgaria
Posts: 7,379
Default Re: win 32 virut

@Antichrist

Hello!

You have posted in EAV v3's subforum , you are supposed to be using v3

Restart your computer in Safe Mode and open Start -> Programs -> ESET -> ESET NOD32 Antivirus

A pop-up will ask you if you want to perform a scan . A DOS like windows will appear , this is ESET's command line scanner . It will start cleaning whatever possible. As far as I am aware Virut is a virus/file infector which completely overwrites infected files and I think a complete recovery can never be achieved . However you must try!
  #7  
Old February 18th, 2008, 03:41 PM
Marcos Marcos is online now
Eset Moderator
 
Join Date: Nov 2002
Posts: 8,613
Default Re: win 32 virut

Not all Virut variants can be cleaned, some modify files to such an extent that the original file cannot be recovered. You can zip about 10 infected files, protect the archive with the password "infected" and submit it to samples[at]eset.com with this thread's url in the subject.
  #8  
Old February 18th, 2008, 09:29 PM
THE_BAD_BOY THE_BAD_BOY is offline
Infrequent Poster
 
Join Date: Nov 2007
Posts: 40
Default Re: win 32 virut

Quote:
Originally Posted by proactivelover
Ha Ha Ha
This Is Eset Forum Not Superantispyware
And For Your Kind Information Superantispyware Is A Antispyware Not AntiVirus They Did Not Add Viruses In There Database
yeah can see you dont know nothing about nothing sas can remove alot of thinks avs av,s just can,t ....
__________________
Security Setup: /Nod32-AV/Comodo Pro Firewall /RegDefend/SUPERAntispyware Pro/Firefox-2/Spywareblaster/
Computer: Gateway/ Intel pentium (R) D 2.80ghz / 3 gb DDR2 RAM
ISP: RoadRunner (15 mbps/10 mbps)
Location: , Fl, USA
  #9  
Old February 18th, 2008, 09:33 PM
THE_BAD_BOY THE_BAD_BOY is offline
Infrequent Poster
 
Join Date: Nov 2007
Posts: 40
Default Re: win 32 virut

Quote:
Originally Posted by Marcos
Not all Virut variants can be cleaned, some modify files to such an extent that the original file cannot be recovered. You can zip about 10 infected files, protect the archive with the password "infected" and submit it to samples[at]eset.com with this thread's url in the subject.
yeao you right Marcos the best recomended way to remove Virut its Reformating ... :s Virut its really Hard to remove for every av :p
__________________
Security Setup: /Nod32-AV/Comodo Pro Firewall /RegDefend/SUPERAntispyware Pro/Firefox-2/Spywareblaster/
Computer: Gateway/ Intel pentium (R) D 2.80ghz / 3 gb DDR2 RAM
ISP: RoadRunner (15 mbps/10 mbps)
Location: , Fl, USA
  #10  
Old February 19th, 2008, 12:15 AM
Ant 1 Ant 1 is offline
Infrequent Poster
 
Join Date: Feb 2008
Posts: 9
Default Re: win 32 virut

Quote:
Originally Posted by Causes Drowsiness
The only thing I know to do for this is to disable System Restore (you can look that up online if you don't know how), make sure NOD is up to date and run a full scan of your system in safe mode.

how can disabling system restore help to get rid of viruses.
actuyally i have formatted my pc just yesterday(only the c drive)
and the first thing i did was install nod32 and update it
eav dint detect anything till updated
anyways i will try scanning in safe mode
thnks all
  #11  
Old February 19th, 2008, 12:18 AM
Ant 1 Ant 1 is offline
Infrequent Poster
 
Join Date: Feb 2008
Posts: 9
Default Re: win 32 virut

Quote:
Originally Posted by Marcos
Not all Virut variants can be cleaned, some modify files to such an extent that the original file cannot be recovered. You can zip about 10 infected files, protect the archive with the password "infected" and submit it to samples[at]eset.com with this thread's url in the subject.


how do i do that
i am new so can u plzzzzzzz tell me how its done
  #12  
Old February 19th, 2008, 01:07 AM
Ant 1 Ant 1 is offline
Infrequent Poster
 
Join Date: Feb 2008
Posts: 9
Unhappy Re: win 32 virut

Quote:
Originally Posted by THE_BAD_BOY
virut its one of dangers infections on the net .. because ones has infected all your exe files its imposible to remove it

Virut is a virus that infects any executable files and screensavers that the user accesses. The parasite also opens a back door providing the attacker with unauthorized remote access to the compromised computer. The intruder can upload and run arbitrary files.

do hou have try scaning on safe mode? trsy that also download and run a system scan with SUPERAntispyware
or get support from eset moderator,s :p



i downloaded the super antispyware professional trial
and updated it
but its just not detecting the files as virus which nod had detected as virut
  #13  
Old February 19th, 2008, 04:26 AM
ASpace's Avatar
ASpace ASpace is offline
Very Frequent Poster
 
Join Date: Apr 2006
Location: Europe/Bulgaria
Posts: 7,379
Default Re: win 32 virut

Quote:
Originally Posted by Antichrist
i downloaded the super antispyware professional trial
and updated it
but its just not detecting the files as virus which nod had detected as virut


Simply because SUPER Antispyware is anti-spyware product , not detecting viruses (file infectors)
  #14  
Old February 19th, 2008, 06:22 AM
Ant 1 Ant 1 is offline
Infrequent Poster
 
Join Date: Feb 2008
Posts: 9
Unhappy Re: win 32 virut

Quote:
Originally Posted by HiTech_boy
@Antichrist

Hello!

You have posted in EAV v3's subforum , you are supposed to be using v3

Restart your computer in Safe Mode and open Start -> Programs -> ESET -> ESET NOD32 Antivirus

A pop-up will ask you if you want to perform a scan . A DOS like windows will appear , this is ESET's command line scanner . It will start cleaning whatever possible. As far as I am aware Virut is a virus/file infector which completely overwrites infected files and I think a complete recovery can never be achieved . However you must try!



yea you were right
i scanned pc in the safe mode and nod was unable to clean tha files and also
nod wont allow me to log in after i restarted in normal mode
so i had to delete the nod files in safe mode and reinstall it
so my i turn to my last resort that is format
but there is 1 thing more i wud like to know
virut infects only exe files?
cuz i8 dont want to lose my song and pics collection
and wud want to write them on a dvd
will this f**kin virut follow into the dvd
plzz lemme know
  #15  
Old February 19th, 2008, 06:26 AM
thanatos_theos's Avatar
thanatos_theos thanatos_theos is offline
Frequent Poster
 
Join Date: Apr 2007
Posts: 423
Default Re: win 32 virut

Welcome aboard matey .

Quote:
Originally Posted by Antichrist
how do i do that
i am new so can u plzzzzzzz tell me how its done

1. Using Windows Explorer, locate the first file you want to zip.
2. Right click on the file and select "Send To" and "Compressed (zipped) Folder".
3. Right click any other files you want to compress and select "Copy".
4. Right click on the compressed folder and select "Paste". The copied files will be compressed and pasted in.
5. Right click on the file and select "Explore".
6. In "File" select "Add a Password". Enter the password and confirm the password.

Quote:
Originally Posted by Antichrist
plzz guys help me out

Let's see if the following can remove ("clean") the codes appended by the infector into your files,

http://freedrweb.com/cureit/
http://downloads2.kaspersky-labs.com/devbuilds/AVPTool/ - download latest
http://free.grisoft.com/doc/virus-re...rt/0/ndi/67762
http://www.microsoft.com/security/ma...e/default.mspx
http://www.pandasecurity.com/homeuse...ns/activescan/

Note: Scan in safe mode. Use BootSafe and choose "safe mode with networking".

If they fail, please read this (post at one forum only).

thanatos
__________________
"O miserable shadow clad in darkness! Hurting and disdaining people, a karmic soul drowning in sin... Would you try dying for once?" - Enma Ai
  #16  
Old February 19th, 2008, 06:45 AM
thanatos_theos's Avatar
thanatos_theos thanatos_theos is offline
Frequent Poster
 
Join Date: Apr 2007
Posts: 423
Default Re: win 32 virut

Quote:
Originally Posted by Antichrist
but there is 1 thing more i wud like to know
virut infects only exe files?
cuz i8 dont want to lose my song and pics collection
and wud want to write them on a dvd
will this f**kin virut follow into the dvd
plzz lemme know

AFAIK, Virut only infects *.exe and *.scr files. See this.

thanatos
__________________
"O miserable shadow clad in darkness! Hurting and disdaining people, a karmic soul drowning in sin... Would you try dying for once?" - Enma Ai

Last edited by thanatos_theos : February 19th, 2008 at 06:54 AM.
  #17  
Old February 19th, 2008, 06:54 AM
Ant 1 Ant 1 is offline
Infrequent Poster
 
Join Date: Feb 2008
Posts: 9
Unhappy Re: win 32 virut

Quote:
Originally Posted by thanatos_theos
Welcome aboard matey .



1. Using Windows Explorer, locate the first file you want to zip.
2. Right click on the file and select "Send To" and "Compressed (zipped) Folder".
3. Right click any other files you want to compress and select "Copy".
4. Right click on the compressed folder and select "Paste". The copied files will be compressed and pasted in.
5. Right click on the file and select "Explore".
6. In "File" select "Add a Password". Enter the password and confirm the password.



Let's see if the following can remove ("clean") the codes appended by the infector into your files,

http://freedrweb.com/cureit/
http://downloads2.kaspersky-labs.com/devbuilds/AVPTool/ - download latest
http://free.grisoft.com/doc/virus-re...rt/0/ndi/67762
http://www.microsoft.com/security/ma...e/default.mspx
http://www.pandasecurity.com/homeuse...ns/activescan/

Note: Scan in safe mode. Use BootSafe and choose "safe mode with networking".

If they fail, please read this (post at one forum only).

thanatos


thnks thanatos but how do i send the files
i cand send thru gmail as they saying gmail can send executables for security reasons
  #18  
Old February 19th, 2008, 07:01 AM
thanatos_theos's Avatar
thanatos_theos thanatos_theos is offline
Frequent Poster
 
Join Date: Apr 2007
Posts: 423
Default Re: win 32 virut

Quote:
Originally Posted by Antichrist
thnks thanatos but how do i send the files
i cand send thru gmail as they saying gmail can send executables for security reasons

After putting atleast 10 infected files in a password-protected zip archive, attach the zip to your gmail email. Include in the email body the zip password and the link of this thread. Email the zip to samples@eset.com.

thanatos
__________________
"O miserable shadow clad in darkness! Hurting and disdaining people, a karmic soul drowning in sin... Would you try dying for once?" - Enma Ai
  #19  
Old February 19th, 2008, 07:14 AM
Ant 1 Ant 1 is offline
Infrequent Poster
 
Join Date: Feb 2008
Posts: 9
Default Re: win 32 virut

Quote:
Originally Posted by thanatos_theos
After putting atleast 10 infected files in a password-protected zip archive, attach the zip to your gmail email. Include in the email body the zip password and the link of this thread. Email the zip to samples@eset.com.

thanatos

but gmail is not allowing to send the exe files
  #20  
Old February 19th, 2008, 07:20 AM
thanatos_theos's Avatar
thanatos_theos thanatos_theos is offline
Frequent Poster
 
Join Date: Apr 2007
Posts: 423
Default Re: win 32 virut

Quote:
Originally Posted by Antichrist
but gmail is not allowing to send the exe files

Ok. Upload the password-protected zip here. Email the download link to ESET.

If you are a registered user, use this web form to upload the zip.

thanatos
__________________
"O miserable shadow clad in darkness! Hurting and disdaining people, a karmic soul drowning in sin... Would you try dying for once?" - Enma Ai
  #21  
Old February 19th, 2008, 07:50 AM
Ant 1 Ant 1 is offline
Infrequent Poster
 
Join Date: Feb 2008
Posts: 9
Default Re: win 32 virut

Quote:
Originally Posted by thanatos_theos
Ok. Upload the password-protected zip here. Email the download link to ESET.

If you are a registered user, use this web form to upload the zip.

thanatos


thanks a lot dude
  #22  
Old February 19th, 2008, 08:15 AM
Ant 1 Ant 1 is offline
Infrequent Poster
 
Join Date: Feb 2008
Posts: 9
Question Re: win 32 virut

Quote:
Originally Posted by thanatos_theos
AFAIK, Virut only infects *.exe and *.scr files. See this.

thanatos

wht does this virut do basically
i mean does it affect the hardware
does it matter if i leave it to live in my pc?
i know this is a stupid question but still does it matter?
  #23  
Old February 19th, 2008, 08:36 AM
thanatos_theos's Avatar
thanatos_theos thanatos_theos is offline
Frequent Poster
 
Join Date: Apr 2007
Posts: 423
Default Re: win 32 virut

Quote:
Originally Posted by Antichrist
thanks a lot dude

Antichrist, you are most welcome. I'm glad that I could be of help.

Quote:
Originally Posted by Antichrist
wht does this virut do basically
i mean does it affect the hardware
does it matter if i leave it to live in my pc?
i know this is a stupid question but still does it matter?

AFAIK Virut appends codes (appendage is for IRC session) into your files (*.exe and *.scr) and contacts a list of sites. Here is the ongoing Virut saga.

thanatos
__________________
"O miserable shadow clad in darkness! Hurting and disdaining people, a karmic soul drowning in sin... Would you try dying for once?" - Enma Ai

Last edited by thanatos_theos : February 19th, 2008 at 09:06 AM.
  #24  
Old February 19th, 2008, 10:43 AM
Bubba's Avatar
Bubba Bubba is offline
Global Moderator
 
Join Date: Apr 2002
Posts: 11,266
Default Re: win 32 virut

off topic posts concerning SAS removed.

Philippe_FR22,

You are advized to confine your dislike for and trollish type SAS posts to an appropriate thread and this is not one of them.

Bubba
  #25  
Old February 19th, 2008, 11:00 AM
Philippe_FR22's Avatar
Philippe_FR22 Philippe_FR22 is offline
Frequent Poster
 
Join Date: Sep 2007
Posts: 249
Thumbs up Re: win 32 virut

Quote:
Originally Posted by Bubba
off topic posts concerning SAS removed.

Philippe_FR22,

You are advized to confine your dislike for and trollish type SAS posts to an appropriate thread and this is not one of them.

Bubba

Ok no problem... It's not a dslike pb... Sorry for posting at the wrong thread
Regards
 

Wilders Security Forums > Official ESET Support Forum > ESET NOD32 Antivirus Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 11:38 AM.


Powered by vBulletin® Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2009, Wilders Security Forums