Author Topic: Remove Virut & Sility  (Read 4138 times)

0 Members and 1 Guest are viewing this topic.

Offline Justin_22

  • Avast Evangelist
  • Poster
  • ***
  • Posts: 445
  • Free your soul and let it fly
Remove Virut & Sility
« on: February 23, 2010, 02:59:01 AM »
Im posting this outside of the evangelist corner so everyone can see it. But is this a way to remove Virut and Sality without having to rebuild the system?

http://www.youtube.com/watch?v=FGDl-IMOt1g

From the video at the end it seemed to be all clean, but even if one trace remains cant virut begin to infect .exe and .scr files all over again?

P.S grab a snack, its a pretty long video.
Avast!  2014 beta - Sandboxie - K9 Web Protection

Offline Marc57

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1944
  • KISS Rules The World!!!
    • KISS Army
Re: Remove Virut & Sility
« Reply #1 on: February 23, 2010, 07:17:22 AM »
interesting video, Thanks.
You Wanted the Best You Got the Best the Hottest Band in the World KISS!!!

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Remove Virut & Sility
« Reply #2 on: February 23, 2010, 09:02:14 PM »
Well if they have cleaned up virut so it no longer wrecks the system files I would agree.  However, it still wrecks the system files - so yes it can be removed but you will have a lot of problems with windows files refusing to work properly.  I would go for a reformat if I was hit 

Offline Justin_22

  • Avast Evangelist
  • Poster
  • ***
  • Posts: 445
  • Free your soul and let it fly
Re: Remove Virut & Sility
« Reply #3 on: February 23, 2010, 11:40:02 PM »
Thank you for that Insight essexboy I didn't know that  :-[
Avast!  2014 beta - Sandboxie - K9 Web Protection

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Remove Virut & Sility
« Reply #4 on: February 23, 2010, 11:58:22 PM »
Howdy malware fighters,

I just sat out this extremely long video and have a couple of remarks to make about the cleansing routine as it was presented there on top of what caution our good friend essexboy brought to the thread (I nearly put there to the table). Remember the man who presented this video is a professional malware analyst and I think qualified eliminator. This routine is not for the average user, who probably could make head nor tail of all the magic performed and would shy off. Some issues were not properly explained as well. The surroundings were an experimental minimal VM isolated test surrounding, completely taken offline at times and fully sandboxed.
I would not like to have virut dance in any other theatre either. Then the man also had a go at the virut file infector with ComboScript. As what I saw was taken down right well, he started to cleanse out in two strikes through a boot up from a DrWeb live CD (this is no new method to attack virut, it is propagated elsewhere).
Then he had a go at the rest and the infected processes with Comodo AV + FW (this demands a lot of pre-knowledge of what to terminate, kill and reintroduce. What was a good tip was that on further cleansing with an updated MBAM quick scan - he did the cleansing in bits after encountering a crash.
The final bit was detecting the proxy file and restoring the normal connection and the blocking of the malware sites. He did not tell about the normal theatre where one has infected backups, various additional temporal cleansing to do and other inconsistencies to be dealt with plus the enormous danger to reintroduce the infector from peripherals etc. Impressive, but do you like to know what I really think this is: "Art for the art of it!",

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: Remove Virut & Sility
« Reply #5 on: February 24, 2010, 10:37:22 AM »
Yes there is a time factor which cannot be dealt with in the frame of this video.

Given virut infection, the longer the malware has been resident in the system. the far more difficult it will be to remove. I would have thought. Although the infection did seem to be deeply bedded. There is some good practice at work.

Interesting about virut working on executables and dll files - every time they are run, virut attaches a patch.
Good reason to make use of Safe Mode, for however much is possible.
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.