Author Topic: WIN32 VITRO HELP PLEASE  (Read 4757 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
WIN32 VITRO HELP PLEASE
« on: August 01, 2014, 11:14:07 PM »
Hi Everyone! I'm new to the forum and I admit I just reached this place today when my PC got infected by the win32 vitro thing.. Maybe because all is well in my PC until about 9 hours ago..

I downloaded a game for a private server and Google Chrome already detected the file as something that has malicious content or something but I ignored because I got used to it on that game (that game had so many private servers).

Then came the WIN32 VITRO..

I'm a newbie in being infected cause I highly consider taking all precautions with viruses but I think I made the wrong decision of taing the risk of still using the file I downloaded so what I did was, and I am sure everbody will say I did it wrong was to activate the boot scan of AVAST and decided to choose delete on the action. I thought I only got one or two files infected 'coz I did that scan after 10mins from downloading bbut when the boots scan was finished, it deleted 99 files, most of them in win32 folder, and there was one instance when it said one file was not deleted so I tried the rest of the choices (like repair, move to chest, etc) and ended up with "ignore".

Everyone I really need your help. Can't afford to lose some important files.

I read in some threads that we got some great experts here so I highly appreciate all your help. Please let me know step by step what I need to do.

I'm using windows 7 32-bit and just a free Avast anti-virus. I don't know if this information will help you guys figure out what's the best thing to suggest.

And please, only in layman's term.. Not so techie here.

Thank you so very much :)

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: WIN32 VITRO HELP PLEASE
« Reply #1 on: August 01, 2014, 11:20:41 PM »
Well bad news, if detection is correct and you have a Vitro/Virut file infector then this may end with a format and reinstall

Malware expert is notified...

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: WIN32 VITRO HELP PLEASE
« Reply #2 on: August 01, 2014, 11:25:46 PM »
Quote
  Can't afford to lose some important files. 
If so .... then i guess you have been smart and have a backup!

REDACTED

  • Guest
Re: WIN32 VITRO HELP PLEASE
« Reply #3 on: August 01, 2014, 11:28:26 PM »
Thanks Pondus for the quick reply.. That's what I'm thinking of as well but still wanna ask you guys' help to see if this machine can still be salvaged.. Even my notepad.exe was deleted lol..

As I was reading other threads, I noticed that you guys may need the scan logs.. where do I find that?

And oh, I'm still searching the internet for a notepad installer if there is..

And yeah, I'm checking if I activated the backup thing 'coz I remember I disabled that before due to huge disk space it consumed..

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: WIN32 VITRO HELP PLEASE
« Reply #4 on: August 01, 2014, 11:34:03 PM »
Quote
As I was reading other threads, I noticed that you guys may need the scan logs.. where do I find that?   
Instructions    https://forum.avast.com/index.php?topic=53253.0

REDACTED

  • Guest
Re: WIN32 VITRO HELP PLEASE
« Reply #5 on: August 01, 2014, 11:42:22 PM »
thanks.. working on it..

REDACTED

  • Guest
Re: WIN32 VITRO HELP PLEASE
« Reply #6 on: August 01, 2014, 11:55:01 PM »
I now have the Malwarebytes Anti-Malware scanning my machine. So far, it got 52 threats detected (again, after most of my files have been deleted by avast boot scan) and I think this may take a while so I'm gonna have a nap and be back here in 15 minutes, that's 22:15 GMT

Thanks everyone! :)

REDACTED

  • Guest
Re: WIN32 VITRO HELP PLEASE
« Reply #7 on: August 02, 2014, 12:32:09 AM »
Hello everyone! Here're the three logs that we all need..


Thanks again!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: WIN32 VITRO HELP PLEASE
« Reply #8 on: August 02, 2014, 12:59:49 AM »
Removal team is in bed now, check back tomorrow ......

Obs: and FRST tool should produse two logs, you only attached one....


« Last Edit: August 02, 2014, 01:01:39 AM by Pondus »

REDACTED

  • Guest
Re: WIN32 VITRO HELP PLEASE
« Reply #9 on: August 02, 2014, 01:47:01 AM »
Hi,


I thought there's only 3 tools in there? What's OBS? Sorry

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: WIN32 VITRO HELP PLEASE
« Reply #10 on: August 02, 2014, 01:54:36 AM »
3 tools yes .... and FRST will produce two logs frst.txt and additional.txt

Night night....



REDACTED

  • Guest
Re: WIN32 VITRO HELP PLEASE
« Reply #11 on: August 02, 2014, 01:59:49 AM »
Oh.. thanks Pondus..


OK, re-posting all three of them.. Thanks for the help and night-night too.. I'll be back here from time to time to check

REDACTED

  • Guest
Re: WIN32 VITRO HELP PLEASE
« Reply #12 on: August 02, 2014, 02:18:26 AM »
Hi.

I don't have good news. Virtu is a shortage of Virtumonde, another alias of Virut - which is a death sentence for a system.
Your confirmation is that legitimate apps/executable files have been quarantined by avast. If so, we can really do nothing here.

The only one advice for you is to reformat/reinstall not only of your system drive, but all disks/partitions. Virus doesn't care, it infects every file that he's able to spot.

If you want to backup your personal data, do it only for music, videos, documents, photos.. Do not backup any exe, dll, scr, htm, zip and rar files. Any games/apps shouldn't be backed-up also. All needs to go down.

REDACTED

  • Guest
Re: WIN32 VITRO HELP PLEASE
« Reply #13 on: August 02, 2014, 02:23:28 AM »
This is a very unfortunate thing then.. Thanks Naathim..

And thanks for letting me know that can be backed up and what not.. Will start working on it now..


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34060
  • malware fighter
Re: WIN32 VITRO HELP PLEASE
« Reply #14 on: August 02, 2014, 02:34:54 AM »
Hi Mark Anthony,

Very sad to hear about your predicament, always very unfortunate to lose a computer to a vicious file-infection like Virut, designed just simply to ruin operational systems in an unpredictable way and to an unpredictable extent. To avoid such an infection in the future while your computer is been helped to a total re-install to exist a-new, read the following 22 steps http://www.wikihow.com/Avoid-Getting-a-Computer-Virus-or-Worm

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!