Welcome to SecurityForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

How can I confirm and remove Win32.Virut.A ?

 
   Security Forums (Home) -> General Discussions RSS
Next:  Nod 32 and yearly license  
Author Message
Infected

External


Since: Nov 02, 2007
Posts: 1



(Msg. 1) Posted: Fri Nov 02, 2007 2:14 pm
Post subject: How can I confirm and remove Win32.Virut.A ?
Archived from groups: alt>comp>anti-virus (more info?)

Hi Folks,

I downloaded the FREE version of PCTools AV and did a scan on several
large internal and external hard drives. It found, and quarantined)
over 1,300 EXE files saying that they were infected with
"Win32.Virut.A".

Is there a way for me to manualy verify that this infection exists.
Also, is there a tool to "disenfect these files instead of simply
deleting them?

Thank you for helping,

Don

 >> Stay informed about: How can I confirm and remove Win32.Virut.A ? 
Back to top
Login to vote
jen

External


Since: Aug 15, 2003
Posts: 114



(Msg. 2) Posted: Fri Nov 02, 2007 6:12 pm
Post subject: Re: How can I confirm and remove Win32.Virut.A ? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Maximus the Mad" <maxwachtel.DeleteThis@nomail.afraid.org> wrote in message
news:Xns99DCB806DE586whatsinaname@207.115.33.102...
> Infected.DeleteThis@diseased.net after much thought,came up with this jewel in
> news:h98ni31u2numrke8is3m1nb2i7ls0q1ed1@4ax.com:
>> Hi Folks,
>> I downloaded the FREE version of PCTools AV and did a scan on
> several
>> large internal and external hard drives. It found, and quarantined)
>> over 1,300 EXE files saying that they were infected with
>> "Win32.Virut.A".
>> Is there a way for me to manualy verify that this infection exists.
>> Also, is there a tool to "disenfect these files instead of simply
>> deleting them?
> Submit the files in question to www.virustotal.com You could also use

"over 1,300 EXE files"? Hope he's got a lot of time on his hands, lol
Smile

> David Lipman's AV tool to scan each file(it includes 4 diferent
> scanners). BitDefender has a on-demand scanner that you can install
> also.
> Many files cannot be disinfected because they are not valid windows
> files.

-jen

 >> Stay informed about: How can I confirm and remove Win32.Virut.A ? 
Back to top
Login to vote
jen

External


Since: Aug 15, 2003
Posts: 114



(Msg. 3) Posted: Fri Nov 02, 2007 7:47 pm
Post subject: Re: How can I confirm and remove Win32.Virut.A ? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Maximus the Mad" <maxwachtel.RemoveThis@nomail.afraid.org> wrote in message
news:Xns99DCBA3C49D57whatsinaname@207.115.33.102...
> "jen" <jen.RemoveThis@example.com> after much thought,came up with this jewel
> in news:whNWi.48531$b9.34539@bignews1.bellsouth.net:
>> "over 1,300 EXE files"? Hope he's got a lot of time on his hands,
>> lol
>>Smile
> Perhaps he is on an extended leave of absence......

If he's not now, I'm sure he will be after this Smile)))

-jen
 >> Stay informed about: How can I confirm and remove Win32.Virut.A ? 
Back to top
Login to vote
jen

External


Since: Aug 15, 2003
Posts: 114



(Msg. 4) Posted: Fri Nov 02, 2007 8:01 pm
Post subject: Re: How can I confirm and remove Win32.Virut.A ? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

<Infected DeleteThis @diseased.net> wrote in message
news:h98ni31u2numrke8is3m1nb2i7ls0q1ed1@4ax.com...
> Hi Folks,
> I downloaded the FREE version of PCTools AV and did a scan on several
> large internal and external hard drives. It found, and quarantined)
> over 1,300 EXE files saying that they were infected with
> "Win32.Virut.A".
> Is there a way for me to manualy verify that this infection exists.
> Also, is there a tool to "disenfect these files instead of simply
> deleting them?

Win32.Virut.A is an appending virus. This file infector infects .exe
and .scr files by attaching its encrypted code to the end of the file.

The encrypted code contains IRCBot functionality.

When Win32.Virut.A is executed it injects it's code into all running
processes.

Win32.Virut.A opens up a backdoor at port 65520 on the compromised
machine.

This virus tries to connect to IRC servers located at:

* proxima.ircgalaxy.

Symptoms -

# Modified executable files (increase of 5,120 bytes of exe files)
# DNS queries to proxima.ircgalaxy.pl and IRC related network traffic

Method of Infection -

Win32.Virut.A is a file infecting virus. Infection starts with *manual
execution* of the binary. Executables in network shares may also get
infected if accessed by the compromised machine. This virus can also be
instructed to scan for vulnerable systems and infect them.

Good luck,

-jen
 >> Stay informed about: How can I confirm and remove Win32.Virut.A ? 
Back to top
Login to vote
Maximus the Mad

External


Since: Oct 29, 2007
Posts: 22



(Msg. 5) Posted: Fri Nov 02, 2007 10:06 pm
Post subject: Re: How can I confirm and remove Win32.Virut.A ? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Infected.TakeThisOut@diseased.net after much thought,came up with this jewel in
news:h98ni31u2numrke8is3m1nb2i7ls0q1ed1@4ax.com:

>
> Hi Folks,
>
> I downloaded the FREE version of PCTools AV and did a scan on
several
> large internal and external hard drives. It found, and quarantined)
> over 1,300 EXE files saying that they were infected with
> "Win32.Virut.A".
>
> Is there a way for me to manualy verify that this infection exists.
> Also, is there a tool to "disenfect these files instead of simply
> deleting them?
>
> Thank you for helping,
>
> Don
>

Submit the files in question to www.virustotal.com You could also use
David Lipman's AV tool to scan each file(it includes 4 diferent
scanners). BitDefender has a on-demand scanner that you can install
also.
Many files cannot be disinfected because they are not valid windows
files.
max
--
Virus Removal http://max.shplink.com/removal.html
Keep Clean http://max.shplink.com/keepingclean.html
Tools http://max.shplink.com/tools.html
Change nomail.afraid.org to gmail.com to reply by email.
 >> Stay informed about: How can I confirm and remove Win32.Virut.A ? 
Back to top
Login to vote
Maximus the Mad

External


Since: Oct 29, 2007
Posts: 22



(Msg. 6) Posted: Fri Nov 02, 2007 10:19 pm
Post subject: Re: How can I confirm and remove Win32.Virut.A ? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"jen" <jen DeleteThis @example.com> after much thought,came up with this jewel
in news:whNWi.48531$b9.34539@bignews1.bellsouth.net:

> "over 1,300 EXE files"? Hope he's got a lot of time on his hands,
> lol
>Smile

Perhaps he is on an extended leave of absence......
--
Virus Removal http://max.shplink.com/removal.html
Keep Clean http://max.shplink.com/keepingclean.html
Tools http://max.shplink.com/tools.html
Change nomail.afraid.org to gmail.com to reply by email.
 >> Stay informed about: How can I confirm and remove Win32.Virut.A ? 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Remove worm.win32.Muha.a - i used kaspersky as my antivirus.my antivirus cannot delete virus worm.win32.Muha.a. how i want to remove this virus from my computer? manje-

found TrojanDownloader.Win32.RVP.c how to remove (using Ka.. - Using Kaspersky version 4.5 I found TrojanDownloader.Win32.RVP.c But Kaspersky could not disinfect. Please help, thanks, MV

found TrojanDownloader.Win32.RVP.c how to remove (using Ka.. - Using Kaspersky version 4.5 I found TrojanDownloader.Win32.RVP.c But Kaspersky could not disinfect. Please help, thanks, MV

Need non-auto anti-virus prog with end-scan confirm - Anyone know an anti-virus program that does the following..... 1. Has an option to NOT automatically remove any viruses it finds but report first and ask you what you want to do. 2. Can scan all partitions with above option without stopping until the en...

Kaspersky Results confirm Exploit.html.mht infection - Clam AV showed exploit while AVG came up clean but Kaspersky found same exploit code. Below is read out. C:\DOCUME~1\RICHAR~1\LOCALS~1\TEMPOR~1\CONTENT.IE5\A2O8H6EG\DELIVE~2.HTM suspicion: Exploit.HTML.Mht..
   Security Forums (Home) -> General Discussions All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]