TechSpot

Infected by win32/heur

By Kikka
Oct 20, 2009
  1. Esteemed aiders,

    My computer is infected by Win32/Heur and win32/Virut virus that came through a friends USB stick when he wanted to show me an exe, which was corrupted even though I scanned it for viruses before opening.

    The current symptoms are that I can't open many programs, instead they give me an "application error" or "damaged executable" message. Also MBAM, SUPERantispyware and AVG can't run their updates.

    I performed a full scan with MBAM, SUPERantispyware, Spybot and AVG. The others found nothing, but AVG found 700 win32/heur or win32/virut viruses! It managed to remove 600 of them but it refused to remove the remaining 100 saying that they are "white listed", important system files that can cause instability if removed. During the scan, it also stated with several files that: "Locked file. Not tested." Some web pages also seem to be blocked to me (microsoft, AVG).

    What should I do?

    Appreciating your time,

    P.S. Attached is a recent hijackthis logfile.

    P.P.S. I found this http://www.scanforfree.com/06/virus.win32.virut-removal.html Will it do the trick?
     
  2. Bobbye

    Bobbye Helper on the Fringe Posts: 16,335   +36

    Virut is a polymorphic file infector with IRCBot functionality which infects .exe, .scr files, downloads more malicious files to your system, and opens a back door that compromises your computer. Some variants can infect the HOSTS file and block access to security related web sites.

    I refer you to Post #2 HERE for a more complete description. Most of us have found that it is so agressive, trying to clean it is not recommended.

    No, I don't think XOFSPY will do the trick and advise you to change all of your passwords and monitor any online financial transactions..
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...