lesser-equity

Magazine
Go Back   Computer Juice > Computer Software > Virus, Spyware & Security

Register


Default Virut PE Win32.Virut.56 Polymorphic Virus on the Rise

Discovered: April 11, 2007 Latest Rapid Release version February 10, 2009 revision 024 Virut spreads through every .exe and .scr file on a computer. It's polymorphic, which means it spreads faster than any antivirus can contain it. 99.99% of the time the only solution is a reformat and reinstall. Virut ...


Closed Thread
 
Thread Tools
  #1  
Old 21st Feb 2009, 13:55
Moderator Group
 
Skill Level: Advanced
Posts: 7,136
Default Virut PE Win32.Virut.56 Polymorphic Virus on the Rise


Discovered: April 11, 2007


Latest Rapid Release version February 10, 2009 revision 024

Virut spreads through every .exe and .scr file on a computer. It's polymorphic, which means it spreads faster than any antivirus can contain it. 99.99% of the time the only solution is a reformat and reinstall. Virut is so aggressive it even infects already infected files with itself. It's a computer killer...

Viruses belonging to the Virut family also contain an IRC-based backdoor that provides unauthorized access to infected computers.

In short. There is no solution for this other than a reformat and reinstall.

Win32/Virut: Microsoft

Symptoms: The following symptoms may be indicative of a Virus:Win32/Virut infection:

* Network traffic on TCP port 65520 with connection to IRC server proxima.ircgalaxy.pl, on channel & virtu

* Increase in file size of infected files

* Infected files fail during execution and have a recent modified date property


HJT logs will have an F2 entry similar to this.

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDO WS\TEMP\init.exe,

Dr. Web CureIt will show many files like this. Notice that these aren't just some random files. Pretty much sums it up...


explorer.exe;c:\windows;Win32.Virut.56;Cured.;
imagination studio.scr;c:\windows;Win32.Virut.56;Cured.;
unregmp2.exe;c:\windows\inf;Win32.Virut.56;Cured.;
xpnetdiag.exe;c:\windows\network diagnostic;Win32.Virut.56;Cured.;
alg.exe;c:\windows\system32;Win32.Virut.56;Cured.;
cisvc.exe;c:\windows\system32;Win32.Virut.56;Cured .;
clipsrv.exe;c:\windows\system32;Win32.Virut.56;Cur ed.;
ctfmon.exe;c:\windows\system32;Win32.Virut.56;Cure d.;
dllhost.exe;c:\windows\system32;Win32.Virut.56;Cur ed.;
logon.scr;c:\windows\system32;Win32.Virut.56;Cured .;
logonui.exe;c:\windows\system32;Win32.Virut.56;Cur ed.;


It says cured but that isn't true. Virut spreads back to the newly cured files so it's a never ending process of cleaning and infecting.

It's believed to have started from a p2p web site or sites. One malware removal forum is saying they are at about 40% of their users requesting help are infected with Virut right now. Since it also spreads via IRC the longer they wait to wipe the drive the more users there are getting infected.

Waiting or trying to clean it just gives it that much longer to infect others. Enough users have it now that the IRC-based backdoor part has zombified many who haven't figured out they are infected yet. Even seemingly clean email/chat attachments from known good sources can be infected.

If you have a shared folder for your p2p then that is a gateway for the IRC to connect to you, spread itself, and zombie your computer or network.

There is NO safe cure for this. If you see one file infected with Virut immediately disconnect from the Internet and start reformatting and reinstall.

This probably won't go away any time soon but all major AV vendors have supposedly updated to block this new variation.

Good luck!
__________________

  #2  
Old 21st Feb 2009, 14:02
Administrator Group
 
Skill Level: Advanced
Posts: 9,903
Default Virut PE Win32.Virut.56 Polymorphic Virus on the Rise

Good post mate, dugg it > http://digg.com/security/Virut_PE_Wi...us_on_the_Rise
__________________

My System: Hybr!d

Processor(s):
AMD Turion 64 x2 TL-64 2.2GHz
Motherboard:
HP nForce 560
RAM Memory:
2GB DDR2 PC2-5300
Graphics Card(s):
Nvidia 7150M Onboard Integrated
Sound Card:
5.1 Onboard Integrated
Hard Drive(s):
250GB 5400RPM SATA300
Optical Drive(s):
18x CD/DVDRW-DL ATA
Case / PSU:
Stock HP
Cooling:
Stock HP
Network / Internet:
10/100 Nic / 10MB Virgin Cable
Monitor(s):
17" WXGA+ HD BrightView Widescreen
Operating System(s):
Windows 7 Ultimate 32Bit
  #3  
Old 21st Feb 2009, 14:15
Moderator Group
 
Skill Level: Advanced
Posts: 7,136
Default Virut PE Win32.Virut.56 Polymorphic Virus on the Rise

Thanks!

I haven't put that much effort into a singe post in a while

I read where a Houston, Texas City network had over 600 computers down for nearly a week due to this. Pretty nasty bugger indeed!
__________________

  #4  
Old 21st Feb 2009, 14:25
Administrator Group
 
Skill Level: Advanced
Posts: 9,903
Default Virut PE Win32.Virut.56 Polymorphic Virus on the Rise

Seems like you pretty much broke the news, not much in Google on this.
  #5  
Old 21st Feb 2009, 14:29
Moderator Group
 
Skill Level: Advanced
Posts: 7,136
Default Virut PE Win32.Virut.56 Polymorphic Virus on the Rise

For some reason it's only being discussed in passing or in private forums it seems. No need to keep it a secret. Too many techs out there who should know what's up.
__________________

  #6  
Old 22nd Feb 2009, 00:51
Malware Group
 
Skill Level: Advanced
Posts: 301
Default Virut PE Win32.Virut.56 Polymorphic Virus on the Rise

Come across a couple of infected machines myself, nasty peice of work, just one cure - Format! Most infections comming in from P2P (as stated above) so one good reason for users out there to pack up limewire and such....!
__________________
Proud member of ASAP & UNITE
__________________

My System: Steves Rig

Processor(s):
AMD Athlon 64x2 6000+
Motherboard:
ASUS M3N78 Pro
RAM Memory:
Corsair 4GB Dual Channel
Graphics Card(s):
NVIDIA GeForce 8400 GS
Sound Card:
Onboard
Hard Drive(s):
640GB Western Digital HD
Optical Drive(s):
LG Lightscribe
Case / PSU:
Cooling:
Stock HSF
Network / Internet:
20Mb Virgin Media Broadband
Monitor(s):
Hanns-G 19" Widescreen
Operating System(s):
Vista Premium 64x
  #7  
Old 22nd Feb 2009, 09:01
Administrator Group
 
Skill Level: Advanced
Posts: 9,903
Default Virut PE Win32.Virut.56 Polymorphic Virus on the Rise

No wonder I couldn't find anything, you spelt it wrong in the thread title but correct everywhere else, I changed it for you now mate.
  #8  
Old 22nd Feb 2009, 09:26
Moderator Group
 
Skill Level: Advanced
Posts: 7,136
Default Virut PE Win32.Virut.56 Polymorphic Virus on the Rise

Yes they seem to be calling this one Virut PE.

I found this blog post. Pretty technical stuff but informative. Under the Hood: Virut. I love the first line. "Virut is a weird freak amongst malware."
__________________

  #9  
Old 22nd Feb 2009, 13:03
Malware Group
 
Skill Level: Advanced
Posts: 348
Default Virut PE Win32.Virut.56 Polymorphic Virus on the Rise

Great post EF!

The only person I've seen successfully cleanse an earlier version of virut was sUBs (no surprise there!) - the user stayed online all the time sUBs was on, so instructions were being enacted almost immediately. This newer version seems to be much worse though...
__________________
Iain - Defender of the Haggis
Member of ASAP : : Member of UNITE
__________________

My System: It's all mine...

Processor(s):
C2D E6750 2.66Ghz
Motherboard:
Gigabyte P35C-DS3R
RAM Memory:
2 x 1Gb Corsair DDR2 XMS2 PC26400
Graphics Card(s):
GeForce 8600GT
Sound Card:
Creative X-Fi
Hard Drive(s):
Maxtor 320Gb
Optical Drive(s):
Pioneer DVD-RW
Case / PSU:
Antec 900 / Antec TruPower Trio 650
Cooling:
Various Antec + Zalman 92mm
Network / Internet:
ASUS Router/VirginMedia
Monitor(s):
LGL226WQ 22" Widescreen
Operating System(s):
XP Pro SP3
  #10  
Old 22nd Feb 2009, 14:57
Moderator Group
 
Skill Level: Advanced
Posts: 7,136
Default Virut PE Win32.Virut.56 Polymorphic Virus on the Rise

sUBs would be one of the people, maybe the only person, I would trust to be able to fix Virut in a forum setting.

I saw someone offer up a fix on the MBAM forums but it was pretty complex and didn't sound like it would work. Something like slaving a drive and cleaning/transferring/deleting files. To me it would just result in two infected drives instead of one and reformat/reinstall would be much easier since you still have to reinstall all third party software and so on.
__________________

Closed Thread

Donate

Register

Bookmarks

Similar Threads
Thread Thread Starter Forum Replies Last Post
Win32:Alureon-BH [RTK] Rootkit - Virus or Malware Removal Mooseknuckle Virus, Spyware & Security 13 19th Jun 2009 15:19
Xp Virus Problem - win.32.virut G Mohi212 Virus, Spyware & Security 10 16th May 2009 14:36
Hijack This for Analysation - Virut Poss? Coolyxxx Virus, Spyware & Security 4 23rd Feb 2009 22:01
New VIRUT Virus Got Me Bad. EvilFantasy Said Reformat. How Do I Do That??? actionlover Windows Operating Systems 5 23rd Feb 2009 13:48
Infected with Virus.Win32.Tenga.a; Please Help !! ruffryder2k7 Virus, Spyware & Security 17 20th May 2008 10:23
Thread Tools




Arabic Bulgarian Chinese (Simplified) Chinese (Traditional) Croatian Czech Danish Dutch English Finnish French German Greek Hebrew Hungarian Italian Japanese Korean Latvian Lithuanian Norwegian Polish Portuguese Romanian Russian Serbian Slovak Spanish Swedish Thai Turkish Ukrainian

Copyright ©2006 - 2009 Computer Juice.

Powered by vBulletin® Copyright ©2000 - 2009 Jelsoft Enterprises Ltd. SEO by vBSEO ©2009, Crawlability, Inc.