Author Topic: Win32: Vitro advice..  (Read 12445 times)

0 Members and 1 Guest are viewing this topic.

wussup

  • Guest
Win32: Vitro advice..
« on: February 20, 2012, 11:08:41 PM »
So I'm attempting to fix my neighbors computer( actually just taking a look at it, I'm really not that good with these things). Avast's webshield popped up blocking Win32: Vitro. I ran some scans for him with MalwareBytes(didn't find anything) and Avast(which found two). Moved them to the virus chest where they currently reside. Since then I've run more scans and have found not threats. Is he in the clear? Also should I just delete the files in the Virus chest?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: Win32: Vitro advice..
« Reply #1 on: February 20, 2012, 11:14:50 PM »
if the vitro/virut detection is correct...then he may be in deep s**t   :-\
this is a nasty file infector and Malwarebytes does not clean file infectors....the pro version will block the installer...if detected

if lucky avast have stopped it from spreading....... Essexboy is notified


Virut and other File infectors - Throwing in the Towel? (Miekiemoes - Assistant Director of Research @ Malwarebytes)
http://miekiemoes.blogspot.com/2009_02_01_archive.html
« Last Edit: February 20, 2012, 11:16:55 PM by Pondus »

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: Win32: Vitro advice..
« Reply #2 on: February 20, 2012, 11:24:04 PM »
Vitro aka  Virut can be really tricky.It depends on the time it's on the computer.If it's active for more than 1 week,then format would be the solution i guess.
Before you do anything,kaspersky has released a really nice tool for this infection.Follow the instructions here :
http://support.kaspersky.com/faq/?qid=208280756
Review of Virut.ce can be found here http://www.securelist.com/en/analysis/204792122/Review_of_the_Virus_Win32_Virut_ce_Malware_Sample .
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus

wussup

  • Guest
Re: Win32: Vitro advice..
« Reply #3 on: February 21, 2012, 12:08:50 AM »
^ I don't think it's was on his computer for very long, he told about it happened this morning. At this moment I've updated his windows and I'm currently trying The Kapersky tool you recommended. I've downloaded the logging programs recommended here. I will try running scans after current reboot, and if you guys deem necessary will post logs.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: Win32: Vitro advice..
« Reply #4 on: February 21, 2012, 12:38:18 AM »
yes, you should attach the logs from this guide
http://forum.avast.com/index.php?topic=53253.0

then essexboy will have a look tomorrow

wussup

  • Guest
Re: Win32: Vitro advice..
« Reply #5 on: February 21, 2012, 02:31:12 AM »
Should I run these in Safe mode?
« Last Edit: February 21, 2012, 03:20:40 AM by wussup »

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: Win32: Vitro advice..
« Reply #6 on: February 21, 2012, 09:26:36 AM »
Should I run these in Safe mode?
There is no need to do so....
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus

akama1

  • Guest
Re: Win32: Vitro advice..
« Reply #7 on: February 21, 2012, 10:19:29 AM »
Should I run these in Safe mode?
There is no need to do so....
if your trying to remove the virut with any tool used to remove it then it's best to do in safe mode

just correcting im not gonna involved in any of these before getting a warning again.... :/

true indian

  • Guest
Re: Win32: Vitro advice..
« Reply #8 on: February 21, 2012, 01:49:23 PM »
Why not give Dr.Web a try.

Download and burn the iso to CD from a clean machine:
http://www.freedrweb.com/livecd/?lng=en

Then boot via Dr.Web Live CD try and cure all malware found.

Then once the scan is finished boot back to normal windows and scan with malwarebytes.

Note:No 100% assurance that The computer will be perfectly clean even after Dr.web and MBAM scanned and cured the files.Best option is to format and reinstall windows.

Further info on how to deal with this nasty infection will be given by essexboy.
« Last Edit: February 21, 2012, 01:51:06 PM by true indian »

akama1

  • Guest
Re: Win32: Vitro advice..
« Reply #9 on: February 21, 2012, 02:48:27 PM »
Why not give Dr.Web a try.

Download and burn the iso to CD from a clean machine:
http://www.freedrweb.com/livecd/?lng=en

Then boot via Dr.Web Live CD try and cure all malware found.

Then once the scan is finished boot back to normal windows and scan with malwarebytes.

Note:No 100% assurance that The computer will be perfectly clean even after Dr.web and MBAM scanned and cured the files.Best option is to format and reinstall windows.

Further info on how to deal with this nasty infection will be given by essexboy.
what about combofix?

wussup

  • Guest
Re: Win32: Vitro advice..
« Reply #10 on: February 21, 2012, 05:12:49 PM »
OTL isn't producing the extras.txt file only OTL. Gonna try the suggestions so far with the cd. I'll check this from work.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32: Vitro advice..
« Reply #11 on: February 21, 2012, 08:50:12 PM »
MD5's look good for the main system files - are the alerts appearing any more ?

You could have struck lucky - a few ADS to remove

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

If you have Malwarebytes 1.6 or better installed please disable it for the duration of this run

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    Quote
    :OTL
    @Alternate Data Stream - 1360 bytes -> C:\ProgramData\Microsoft:p0hlN7TI8gW6nFYkkhPODj6ab
    @Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:8CE646EE
    @Alternate Data Stream - 1117 bytes -> C:\ProgramData\Microsoft:YfsOyVlgDHNr34ZJoMbRkDE

    :Files
    ipconfig /flushdns /c

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [CREATERESTOREPOINT]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

wussup

  • Guest
Re: Win32: Vitro advice..
« Reply #12 on: February 22, 2012, 07:55:56 AM »
^I haven't had any hits from further scans with avast since the initial detection, which still is in the virus chest.

- Right after the reboot OTL ran automatically. After that I ran a quick scan using the suggested OTL custom scan in the log assist post. Here are the logs.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32: Vitro advice..
« Reply #13 on: February 22, 2012, 08:31:01 PM »
That looks good - you may have struck lucky

If all is well tomorrow let me know and I will tidy up