PDA

View Full Version : "Virut" Memory-Resident Virus


scottcarson
10-02-2009, 03:14 AM
Hello,

Storm recently encountered a ferocious memory-resident virus called "virut". Being memory-resident, even if you delete the file(s) and/or registry entries that are causing the problem, you won't be able to remove the virus and upon reboot it will return. The reason is because it stays in memory and waits for you to reboot. In the case of this virus, it goes one step further and infects many .exe files on your computer. While the remedy is extremely time-intensive, there is a solution.

First, you MUST have a virus scanner (Storm recommends Rising Antivirus (http://www.freerav.com/)) actively running. Without this, the virus will run wild. Assuming Rising is running, it will detect many, if not all, of the files. However, they may not be deleted from memory. In order to do that, you will need Dr. Web Anti-Virus (http://www.freedrweb.com/cureit/) which is designed to scan deep into the system's memory and forcefully remove the problematic files if necessary.

We recommend multiple scans with the anti-virus software. Again, even an experienced user with significant knowledge of manual virus removal may find this process long and frustrating. In some cases, a full system rebuild may be necessary where all .exe files are deleted prior to rebuild.

-Scott.