Author Topic: Win32.Vitro  (Read 2339 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Win32.Vitro
« on: June 14, 2015, 03:20:41 AM »
 So I'd borrowed an USB drive from my friend and as soon as I plugged it into my desktop, Avast detected this virus (urDrive.exe) and moved to quarantine chest. I instantly quick formated USB Drive after that.
 have done  few quick scan so far and found nothing suspicious. Do I safe from it ?from what I've read Win32:Vitro is a nasty one, it isn't easy to remove it  from your PC.
I'm doing a project right now, I don't want to break my computer :(

Offline Rednose

  • Pirate Party Member
  • Avast Überevangelist
  • Massive Poster
  • *****
  • Posts: 3738
  • Bits of Freedom : https://www.bof.nl
    • Nederlandstalig Avast! forum
Re: Win32.Vitro
« Reply #1 on: June 14, 2015, 03:31:35 AM »
Hi fallengt, welcome to the forum :)

Our experts can check your system if you like :

Please follow this turtorial https://forum.avast.com/index.php?topic=53253.0 and attach the requested logs in your next reply.
Also notice the "Additional program to run and install if you have used an infected USB stick" in the tutorial, and install MCShield.
As soon as an expert is online and available he/she will help you.

Greetz, Red.
« Last Edit: June 14, 2015, 03:34:04 AM by Rednose »
OS: Win 10 / iOS 17 / Debian 12 / Tails 6
Real Time: Avast Premium Security
On Demand: Malwarebytes
VPN: NordVPN ( NordLynx ) with Threat Protection ( Lite )

REDACTED

  • Guest
Re: Win32.Vitro
« Reply #2 on: June 14, 2015, 04:52:39 AM »
Here are all the log files.

REDACTED

  • Guest
Re: Win32.Vitro
« Reply #3 on: June 14, 2015, 04:54:09 AM »
McShield.
I didn't touch anything from the infected USB. Formated it as soon as Avast'd warned me.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32.Vitro
« Reply #4 on: June 14, 2015, 11:57:02 AM »
Nothing major apparent on the system

Are you experiencing any problems ?

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
CreateRestorePoint:
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Windows\wscript.exe /boot,
2014-07-25 17:42 - 2014-07-25 17:42 - 0000000 _____ () C:\Users\truongsinh\AppData\Local\{85D475FC-3FF9-4F67-B94B-95A9968FDBDE}
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe

Run FRST and press Fix
On completion a log will be generated please post that

REDACTED

  • Guest
Re: Win32.Vitro
« Reply #5 on: June 14, 2015, 10:59:02 PM »
 There was some wscript error ( Location not found etc..) but I don't think it harmful, deleted it now. Thanks @essexboy