It's not looking good whenever Virut is on a PC. It's possible that reformat is the most likely solution but first we will confirm that it is Virut and this tool has had some success on other systems.
Please do the following:
Download Dr Web from here
. Fill in the small form and download
It will download as an 8 digit file save it to your desktop
Restart in safe mode and run
Accept the enhanced version
Then run the quick scan
About halfway through you will be prompted to buy - just X the box closed
Once finished it will generate a log please attach that
If you are unable to run the above then we'll try DrWeb as a bootable CD and run it outside of Windows.
It will be better to burn this on a uninfected PC
Download Dr.Web Live CD
- Insert blank CD into CD burner
- Start FreeISOBurner
- Click Open button and load Dr.Web LiveCD ISO file
- Select burn speed 16x or less
- Press Burn button
- Having made the bootable CD set your system to boot from CD (Instructions)
- Insert the CD and reboot your PC
- Once Dr.Web starts select Dr.Web LiveCD (Default)
- Press Scanner button on the top
- Press Custom scan on the left side
- Check all disks on the right side
- Now press Begin the scan button to start scanner
- After the scan select all infected files and press Cure button
- Select Tools then Journal
- Click Export button and save report as drweb.txt to hda1 folder
Restart your system and post C:\drweb.txt
log here for me.
If that is succesful then delete the ComboFix on the desktop and download a fresh copy:
from one of the following locations:Link 1 Link 2 VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop
- Disable your AntiVirus and AntiSpyware applications
, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
- Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console
is installed. With malware infections being as they are today, it's strongly recommended
to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
- Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
- Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Please make sure you include the combo fix log in your next reply as well as describe how your computer is running nowHomburg