Know your enemy.
First, let me tell you what this virus is and what it does. This particular virus is part of the "virut" family. That is virus/trojan mix. A virut is basically a patching virus meaning it will infect any type of executable (*.exe, *.HTML, *.scr). The longer it is on your machine the more executables are infected. This particular virut was written to use your email to send out spam and tie up your bandwidth. It also opens up port 66550 and calls out to other malicious software. It also hides itself when it detects the system doing a virus scan. It apparently jumps around folders until the scan is finished. Even more annoying, this virus will copy itself to any usb thumb drive or external drive by adding an autorun.ini and a random *.exe. So when you insert the drive into another PC it will autorun the *.exe and infect the next computer.
Bug Hunting
I first suspected something was wrong when Road Runner contacted me telling me they noticed I have sent over 1 million emails and that I might be infected. So I started a virus scan with malwarebytes and there it was, mocking me. Most anti virus scanners find it and remove, however once you restart it comes right back and you don't know where it came from. From the research I have done, this virus will let you delete it and not show up on another scan until it detects a network connection or a device like a media card or external hard drive.
Extermination
Finally, a successful way of getting rid of the virus. I waited a full month to write this just in case it showed up again since it hides very well. After a month still no sign of it and my email server hasn't complained about me. So here are the steps...
1. First you need two FREE programs and your windows disc. Malwarebytes anti-malware, which you can get here. And AVG's rmvirut.exe which you can get here.
2. Install and update malwarebytes, but don't scan just yet. Place rmvirut.exe in your C drive. It has to be in the root drive or this will not work as well.
3. Once files are placed, unplug any network cables and restart in safe mode. This is done by continuously tapping F8 as you restart the PC.
4. Run Malwarebytes on full scan. When it finds the infected files remove them and it will want to restart. Go ahead and restart but keep pressing F8 to go into safe mode again. Rinse and repeat until you do a full scan and find no infections.
5. Once malwarebytes says you aren't infected, restart and boot into your windows disc. We aren't doing a full reinstall so don't worry your files should be safe. We are choosing "repair your computer". One of the options should say "command prompt". Once selected it should bring up a black screen like the old DOS days. First type "C:" (without quotes) then enter. It should be on your C: drive. Then Type "rmvirut" and the program should start running.
6. Go to a movie or two as this will take a long time. You can leave any usb's or external drives you feel might also be infected because rmvirut will scan all drives.
7. When it says it is finished, run again just to be safe. My first scan I found 831 infections and on the second I found 4. Third didn't find any. Remember it only takes one to start the process all over again so better do it now. Since you aren't really using your Operating system to scan, the virus doesn't realize it is being destroyed and won't try to hide as much.
8. Reconnect your network and restart. Periodically doing scans. Like I said, after this method I have been scanning for a month and no issues.
Published by SlyDog
Computers have made it easy to take my love for movies and games, and make them into my own design. View profile
How to Access Safe Mode in Windows Vista, Windows XP, Windows 98, or Win...Safe Mode, often a mystery to newer Windows users, can be quite a valuable tool. Essentially, Safe Mode is a way of starting your computer in a "bare-bones" mode. This means t...- Avoiding the Ecard.EXE VirusA malicious new virus, ecard.exe, is circulating the Internet via unsolicited bulk email (SPAM) masquerading as a greeting from a family member. A few common-sense steps can keep you- and your computer- safe.
- Anti Virus Software - Why This Is EssentialAnti-Virus is essential for trouble free online experience. Remember it has to be up to date, scan periodically and working. It along with your Firewall is the only devices protecting you from the multitude of malicio...
- Three Free Anti Virus Software Sites You Should Visit Free anti virus web sites are so needed by those who cannot afford to buy one. They are easy to use and you do need the protection. Anti virus, software is health insurance for your computer.
- Free Virus Removal for PCsIn this article, I will explain how to set up and use AVG Free Edition to rid your PC of viruses and other unwanted programs, without paying a cent!
- How Anti-Virus Software Works
- Are Internet Anti Virus Programs Create Equal?
- Understanding Safe Mode in Windows: What is it and What is it For?
- How to Start Up Windows XP Safe Mode
- What is XP's Safe Mode and When Should You Use It?
- Windows: Scanning for Viruses in Safe Mode
- Safe Mode: What is it and Why Use it?



