• I want to thank all the members that have upgraded your accounts. I truly appreciate your support of the site monetarily. Supporting the site keeps this site up and running as a lot of work daily goes on behind the scenes. Click to Support Signs101 ...

BAD virus out there called VIRUT

Techman

New Member
The baddest of the bad is out there running amok. It's called "Virut" and its variants are making the way around the web. Very bad one this guy is. I gotta hand it to the coder of this one. Very clever. It is just about 99% impossible to remove. Most people are forced to do a complete reinstall and reformat. No jail house expert will defeat this one. If one tries it will only get worse.

Virut is a virus that infects any executable files, html and screen savers. The maggot ware opens a back door and downloads more maggotry. And it could provide someone with unauthorized remote access to the compromised computer. It infects your system restore files so there is no going back as well.

Other variants invade additional files on your hard drive key drives and any other storage media it can find. Yes even SD cards.

It is polymorhic and invades HTML and .exe files. It is memory resident. It uses hidden files to remain on your machine. If it is in just one file it will propagate across your machine into every drive and into your network.

Years ago there was one called LOP.com that just about the worst there was in ruining your user experience. This Virut is LOP on steroids. This one makes smitfraud look like a first grader.

Virut comes in via some of those online greeting cards, warez, and compromised java, compromised files and just about any other .exe file you receive from any one. This one is so good it is rumored to be a revenge release. Why? because the sophistication of the code is not something a script kiddy would write.

Symptoms include sudden closing of your virus deflectors, and opening of your firewall. It invades the host file so you cannot goto a security site to get a fix. It slows your machine and will eventually infect your OS files and blue screen your machine. It compromises your browsers. It will invade Internet explorer and you may hear the surfing "click" when it makes a burst attack.

The usual cleaning tools do not work. Spy bot doesn't have a chance. Also, there are a few variants and not all "on the web cleaning techniques" work.

BEWARE. If you get a antivirus warning about VIRUT do not attempt a system restore. Disconnect from the web, and call your tech. It starts out slow but builds up speed as it wrights itself to more and more files. Do not attempt to stop it with malware deflectors. It will simply keep on its way.

IT damages your program files. Your program may not run or lock up. It registers itself with virus deflectors to look like it belongs there.

I have a client machine on my desk. This is my second experience with this one. The first time I saw it the client sent me the hard drive after he tried to clean a virus himself. It was too late. The OS files were compromised so much that only a reformat would work. Not even a repair install could get it back. This virus writes to the boot sectors. The machine would not boot in any circumstance.

The second machine..

Classic Virut infection. I installed a monitor software called "whats running" and watched. Suddenly a red line would appear and the virus would do a burst attack. Sit there for about 3 minutes and suddenly operate for about 5 seconds and quit. AHA! Gotcha maggotry..

I developed a cleaning solution but it was necessary to perform a repair OS install. I also found its base code file hiding some in My Documents files just waiting to reinfect the machine. All one has to do is access these files and the maggotry will be back.

Remember, It looks like a legal executable program. Your antivirus may alert to it but it will be too late. Spy bot will not stop it. Nor will Malwarebytes. If you try it will only make matters worse.

The only way out is a cleaning by a technician who knows the way around system files. Good luck my friends. And, it will take at least 4 cleaning runs to get it.

Summary.
Do not do a system restore. Do not accept any thing that has an .EXE file in it. Do not get a new hard drive and slave the old.. Do not try to stop it with standard malware deflectors. Disconnect from the internnet. Shut down the machine until you can get help. Call me if you need a hand. I can promise you that it will take some expertise to stop this one.

How good to you have to be? If you can read a hijack this log you may have the experience to stop this virut. Maybe!!!!
 

gnatt66

New Member
more reason for me to get a mac. not cause they are better, cause crap like this doesnt happen. thanks for the xmas cheer, techman..haha...

my next home desktop (aka the one that gets surfed the most) will be an apple product.
 

Techman

New Member
more reason for me to get a mac. not cause they are better, cause crap like this doesnt happen. thanks for the xmas cheer, techman..haha...

Just couldn't stand it could ya,, MAC fanboy?

Just had to gloat and act all smug. Bow down to your alter of the MAC cult and act all knowing and omnipotent. Geeeses, this crap gets old.

The very fact that a PC is wide open to any possible type of innovation makes it a better machine the tweakers and experimenters. This openness makes room for the maggots to cause mayhem. So along comes a MAC cultist and tries to use this advantage as a reason to slam a PC owner.

If you look at your MAC you will see all those new innovations were invented for usage on a PC. Yes thats right. While you gloat about having a good machine you kick sand in the very face of those who developed those PC goodies that a MAC uses.

Ya thats right.. The memory, the hard drives, the Ethernet, the USB, ( thats right USB was NOT a MAC invention like some MAC users claim) fire wire, etc. right down to the CPU.. Every thing there is PC based. It's so incestuous that if they were human they couldn't marry. They are so close in design a MAC can run windows and a PC can run MAC OS.

And all the while MAC users were forced to use proprietary vid cards PC makers wre developing the dozons of choice in VID cards. And now MAC's are using the same video technology. Whole PC users were relishing in the Ethernet MAC users were jammed into their own networks. That is until the MAC users saw the light and went to Ethernet.

And finally, tweakers learned how to run MAC OS on a PC years ago. Today no one wants to do it. Why? because there is no advantage. But,, at the same time LOTS of MAC users put XP on their machines. IF the MAC OS was so good why do they have to use a third party software and load XP??


Geeses,, It's like developing a race car. After spending years making a great race car someone comes along and copies it and sticks a different paint job on the skin and says,, LOOK WHAT I GOT.. The very best machine around.

Look under the hood and every one sees the truth. They both the same...

PC tech's know the truth and look at MAC FANboys as someone living in a fantasy land.
 

cgsigns_jamie

New Member
Techman if you had read his post you would have seen he doesn't currently own a Mac... and isn't a "FANboy"

He just commented that his NEXT computer will be an Apple product because Mac OS X isn't prone to viruses and malware.

You should listen to yourself, you sound like a Microsoft FANboy to me.

Yes the hardware is the same but the OS is the real advantage.
You must not realize that Mac OS X is built on a Unix kernel. It's just as open as Linux.

Calm down there buddy... have a Merry Christmas!
 

cgsigns_jamie

New Member
One more thought...

Apple is very Open Source friendly. They even let you view the source code for their operating system... I don't think Microsoft will ever be that brave.

Once again have a Merry Christmas from another one of those Apple "FANboys"
 

CES020

New Member
Doesn't appear to be new, it was shown as being discovered almost a year ago and listed as something picked up and stopped by having the latest DAT files downloaded for your virus scanner.

http://vil.nai.com/vil/content/v_154029.htm

Here's Microsoft's response from several months ago, which should help protect you :

http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Virus:Win32/Virut.BM

It's listed as a low risk assessment on McAfee's site, listed above.

Did the computers you worked on have the latest service patches and DAT files? Or was that what allowed them to get through? Just asking, not any hidden tone or meaning behind it, just curious.
 

gnatt66

New Member
Just couldn't stand it could ya,, MAC fanboy?

Just had to gloat and act all smug. Bow down to your alter of the MAC cult and act all knowing and omnipotent. Geeeses, this crap gets old.

The very fact that a PC is wide open to any possible type of innovation makes it a better machine the tweakers and experimenters. This openness makes room for the maggots to cause mayhem. So along comes a MAC cultist and tries to use this advantage as a reason to slam a PC owner.

If you look at your MAC you will see all those new innovations were invented for usage on a PC. Yes thats right. While you gloat about having a good machine you kick sand in the very face of those who developed those PC goodies that a MAC uses.

Ya thats right.. The memory, the hard drives, the Ethernet, the USB, ( thats right USB was NOT a MAC invention like some MAC users claim) fire wire, etc. right down to the CPU.. Every thing there is PC based. It's so incestuous that if they were human they couldn't marry. They are so close in design a MAC can run windows and a PC can run MAC OS.

And all the while MAC users were forced to use proprietary vid cards PC makers wre developing the dozons of choice in VID cards. And now MAC's are using the same video technology. Whole PC users were relishing in the Ethernet MAC users were jammed into their own networks. That is until the MAC users saw the light and went to Ethernet.

And finally, tweakers learned how to run MAC OS on a PC years ago. Today no one wants to do it. Why? because there is no advantage. But,, at the same time LOTS of MAC users put XP on their machines. IF the MAC OS was so good why do they have to use a third party software and load XP??


Geeses,, It's like developing a race car. After spending years making a great race car someone comes along and copies it and sticks a different paint job on the skin and says,, LOOK WHAT I GOT.. The very best machine around.

Look under the hood and every one sees the truth. They both the same...

PC tech's know the truth and look at MAC FANboys as someone living in a fantasy land.

just didnt read my post, eh?

i own 6 pcs. not a mac to be found....never had one...but i will.


racing analogy, huh? when we get beat at the track...we get beat. we dont whine to the tech guy that the guy stole "my setup"...we work on our stuff to make ours faster. cause what happened really doesnt matter, we are only as good as our last race.

have a great holiday.
 

PMG

New Member
just didnt read my post, eh?

i own 6 pcs. not a mac to be found....never had one...but i will.


racing analogy, huh? when we get beat at the track...we get beat. we dont whine to the tech guy that the guy stole "my setup"...we work on our stuff to make ours faster. cause what happened really doesnt matter, we are only as good as our last race.

have a great holiday.
if ya aint cheatin ya aint eatin :munchie:
 
Top