Hi essexboy,
Here some manual removal recommendations, see attached virut manual removal.txt below
together with the DrWebCureIt removal routine with the settings for file-infector and restart to replace and quarantine:
Virus.Win32.Virut Symptoms:
* Block bandwidth and internet accessibility
* Virus.Win32.Virut sets the registry to resume itself automatically at start up
* Can radically slow down the computer and cause system performance problems, data loss and "blue screen of death"
* Can't change your desktop wallpaper
* Unusual windows task manager system processes
* Disables pop-up blockers
* Pornographic, casino and other adult related ads
Virus.Win32.Virut Actions:
* Connects to IRC servers, infects computer via security holes through e-mail attachments, freeware and messenger programs
* Win32.Virut logs active security application, disable anti-virus and firewall
* Records and sends surfing history and registry information to remote servers
* Watches system activity
Virut is a file-infector, that is rather serious
1. Download Dr.Web CureIt to your Desktop: cureit.exe from
ftp://ftp.drweb.com/pub/drweb/cureit/cureit.exe(Preferably from a pendrive/ usb-stick onto mentioned PC, after this has been downloaded using a non-infected PC)
2. Doubleclick cureit.exe and then click Start in order to start a Quick Scan.
This will first scan all those files that have been loaded into momentary memory and when something has been found up
have CureIt repair this.
- Then there appears a window with an offer to buy the software with 50% off, click to disappear through clicking X.
Now the main menu will be visable.
- Choose the language to use at the top if you want to use another language as English.
- Then choose Actions and set for the following options:
Adware: Replace
Dialers: Replace
Jokes: Report
Riskware: Report
Hacktools: Replace
Then take away the tag at Prompt at action.
Then click OK.
- Choose options - Change Settings and remove tag at Heuristic analysis.
- Then click OK.
3. Back in the main window you can select the drives that you want to be scanned.
- Select all drives here. Then a red ball will appear for the drives selected for scanning.
- Then click the green arrow to start the scan.
This will replace the infected files to the following folder %userprofile%\DoctorWeb\Quarantine\
whenever disinfection fails.
- If the scan has run then choose for File - save Report list. Save this log onto your desktop.
- Close Dr.Web Cureit.
4. Now restart your computer!! This is an important stage, because it may well be that DrWebCureIT like to replace/remove files during a restart.
After restart, copy and paste the contents of the log and attach to your next posting.
But sometimes there is no other option left as a reformat, alas,
polonus