Help for Virus web32:vitro; mudrop-u; html:Iframe-inf [Trj]

Just eliminated ZAS and loaded NIS2010 when the SONAR began to delete way to many files in the System32 area including cmd and msconfig which I use on a regular basis. Along with this also received an error of 0xc0000142 and 0xc0000042 which did not allow me to do much with the computer.

Found a restore point before the delete of ZAS and all seemed to be working without issue, until again after NIS2010 all went “South”. Could not do much in the way of self help but to run various virus, Trojan, spyware, etc programs with little help.

Malwarebytes’ Anti-Malware and SuperAntiSpyware finally came up with zero with a full scan in Safe Mode.

Then loaded your home program to cover me while I was trying to figure out how to attach this issue. During the reboot, up came VITRO plus the others and now the program is in the process of deleting all the infected files on ALL setting of 2.

I am using Win7 Pro with 3 hard drives and the process continues to eliminate various files.

When this scan is finished and those files are gone, and the computer will start I will run OTL. Is there a step I can take before that?

Thank you for your program and what it has done so far!!! Nothing else has been able to give me a clue as to what the problem could have been!

Unfortunately, I did not read your “logs to assist” prior to running Avast. I did select to “delete” and not “quarantine”. Does that present a problem??

W32:Vitro (Virut) virus removal
http://support.avast.com/index.php?_m=knowledgebase&_a=viewarticle&kbarticleid=314

Dealing with the dispicable Vitro / Virut (Win32.Virut) polymorphic virus
http://technosopher.wordpress.com/2009/04/21/vitro-virut-win32/

Virut and other File infectors - Throwing in the Towel?
http://miekiemoes.blogspot.com/2009/02/virut-and-other-file-infectors-throwing.html

Pondus says it all - save what data you can and wipe the drive. It is doubtful that it will ever get clean otherwise

Thank you for the response and links.

I did download those and even though I have already used the Avast scan…I do these also.

But wait…if it can not be removed unless I save the data and re-install the programs…why should I not just remove what I need and reformat?

What about the other 2 drives that are primarily data…do I just leave these alone since the remover has done its’ job or what?

I did not see any info on why Vista or Win7 made any difference to WinXP…of if there is what is it?

Do I still do the OTL or is the only way to remove data and format the main dirve and reinstall all programs???

Yes reformat is the best and in my opinion the only option - with the other two data drives if there are no exe, zip or any other executable type files then they should be OK - This is the advice I would give on any system ranging from 95 to win 7

To bad that this is the case.

The other drives do and still have may exe and dll that were left after both Avast and Virut removal went through them. Virut did not find any new deletes but did ID many that it could not open. Is that a good sign that those drives are clean?

BTW, does the Virut or vitro have anything to do with those errors 0xc0000142 and 0xc0000042?

My next step prior to reformat of my main drive as suggested, I ran the other suggested Vi rut removal tools and there were no indications that any of these pests were still around.

Also ran Avast Home 5 in “boot scan”. This resulted in many indications of “Corrupted” files, Errors 42111 and 42060 on the none main drive. Is it correct to conclude that these files are the left overs after the original scan removed infected files?

The BIG QUESTION, based on these results, is it still necessary to reformat the C_Drive?

There are some applications that are no longer operating but those were the .exe files that were deleted during the original scan. It would be a lot easier to just reinstall those programs that do not load and also do a repair on Win7 files than to reformat and reinstall everything back to the original.

Many of my applications are downloads and may have already been alter during that original scan where I could not use them if they were the original cause of this problem. If any of those files have been indicated as corrupt, than I would try to download a fresh copy if I still can. If I can not get a fresh copy, that application will just disappear and not be reinstalled. It would seem best if the original was bad so would subsequent downloads be just as bad…best to eliminate these.

Based on the above, it would appear that it would be safer to fix or eliminate what does not work rather than reinstall programs that were infected in the first place. Does this logic make any sense?

Last question is regarding those 0xc0000142 and 0xc0000042 are these related to the Vitro issue or is this something else that may have been missed?

Based on the above, it would appear that it would be safer to fix or eliminate what does not work rather than reinstall programs that were infected in the first place. Does this logic make any sense?
Unfortunately no - as you are starting to experience file corruption on some system files and stop errors on some drivers it will only get worse, so cut your loses now and reformat. It is the only sensible option

OK, I sincerely believe that you have the knowledge and experience with matters such as this and will follow your advice, but in order for me to understand what is going on I must ask you to answer a few more questions please. Sorry to be a pest but I am one of those that would like to understand what is going on since this is my second infection problem.

After I format the C_drive, reinstall Windows 7, reinstall the programs that were there that are still available for me to install, how will that be different than were I am at this moment in time?

In other words, were are the Vi rut and its friends living on my C_Drive?

I was at one time many months ago infected by the Vi rut virus and did reformat the C_Drive. Unfortunately the virus protection I had been using may not have eliminated the infected files on my other drive which could have been the cause of this re-occurrence.

Now that there have been two boot scans with the elimination of the pests that were infected on the other drives, will I, after the reformat, be a target from the outside of my computer only and not from within?

Or can we conclude that this infection did not occur from with those drives and this was a new occurrence which will again be removed with the reformat?

Once you have reformated the virus will be gone (full reformat of the drive) Download all programmes afresh, as any on your other drives may be infected. Replace all exe files on your slave drives as they can carry the infection do not run any of them - that includes zip, rar etc.

I was at one time many months ago infected by the Vi rut virus and did reformat the C_Drive. Unfortunately the virus protection I had been using may not have eliminated the infected files on my other drive which could have been the cause of this re-occurrence.
This is probably where the reinfection came from

Thank you for the response.

Will begin the process.

Unfortunately, I need to rely on some of the downloads to put this back together again. With the aid of Avast Home, I hope that those files that will respond to the reinstall have been cleared and are not infected.

I am making the choice that what has not been modified by Avast Home boot scan is a clean file and can be use to reconstruct my newly formatted C_Drive.

Hi cyclone3211,

Everything with traces of the file-infector on it (files, drives, peripherals like USB etc. etc.) will immediately lead to reinfection as soon as one could say presto or even faster, goes like hayfire through the OS, network etc… And because of the random and buggy nature of the file-infector infecting there is no known cure for it until this day. It is a virus where the malware fighter has to throw in the towel and gloves, boxing match over, virus has won, eliminator bites the dust, the only silver bullet that works against this malcreation is a total recall - fdisk - reformat - clean re-install - take the loss of infected files, they can no longer be used, as our friend essexboy says,

polonus

Last question regarding Format

Since DOS is just about gone, and I am using a HD of 144 GB, where do I get the Format.exe to do this?

I thought that Fdisk had a limitation below what I need.

Could you direct me to where I can get what I need in a Boot Disk that would have Format for my needs?

If you are reloading from CD there is a little guide here that goes through the process of reformating http://www.geekstogo.com/forum/Reformat-Install-Windows-t173729.html

Thank you …currently in FULL FORMAT with the Win 7 disk. Thank you all!

this kind of virus is scaring ??? because they will hijack your all executable files…

Anyway Reformatting and installing a fresh O.S is the best solutions…^^