Hey guys, like the title says, I have an infestation of this WIn32 Virut Virus, In the last 5 days i've done for fresh reformattong the hard-drive and re-installing windows 7.
After i'm done installing my drivers, next after that i install AVG 9free, And what do you know it detects over 80 win32 virut viruses. Majority of them are in the system32 folder, And to be sure i tried NOd32 4.42 and latest update, but with nod32 its even worst, It discovers over 150 of them, And with nod32 in deletes it and the whole system would just freeze, and only way is turn it off, but when i do try log back on, i can't cause it'll just stay stuck on the log on screen with pop up messages telling me so and so system file could not be found la did dadada. Then my only choice is fresh install and format. Guys what i don't get is how does it keep coming back after i do this. I HELP FAST. I just want to tel you guys also, that i use a portable hard drive that i've backup all my driver files and programs to, And always do my reinstall from that, But 've scanned my Portable hard drive tens of times, and no detection,, to make sure i've tried scanning with AVG, NOD32, BULLGUARD, AVANT, A SQUARED, and no detection on the porable, Omly in the system itself, So if you guys can please help get rid of this once and for all it would be great thank you.
My spec is, ASUS M51Sn laptop
Intel Core2Duo T9300
3GB RAM
250GB HDD
WINDOWS 7
And i've read in some places that you can't get rid of it unless you format and install, and some say you can fix it with a little bit of work. And my stress is that i have reformatted and installed, FOUR TIME'S OVER........aaaaaAAAAAHHHHHHH help, help,help.
I use my laptop for work, so the sooner i fix this the better


MY THANKS IN ADVANCE....
Guys if you could, my email is <snip> if you could contact me thru that it'll be much appreciated, cause my wotk comp, is blocked to forum sights, So email is only option during the day.
THANKS AGAIN

Dani AI

Generated

Short expert summary tied to the thread: ’s symptoms (reinstalls followed by immediate detection of many Virut hits) match a classic polymorphic file infector that appends itself to executables and can inject hidden iframe/html payloads so it spreads via infected installers, archived files and web content rather than only via a single obvious file. That behavior explains inconsistent scanner results and why an OS reinstall alone sometimes looks like it failed to “fix” the machine. [Kaspersky Securelist analysis of Virut]. (https://securelist.com/review-of-the-virus-win32-virut-ce-malware-sample/36305/)

Why it keeps returning (gaps in earlier replies): reinfection commonly comes from an infected source put back onto the clean system — driver installers, program installers, compressed archives, an OEM recovery image or a backup partition/image, other machines on the LAN, or removable media. Offline scanners and specialized removal tools are often required because Virut variants are polymorphic and can evade simple on‑system scans; many experts therefore recommend imaging/formatting when large numbers of executables are infected. [AVG removal tool; Malwarebytes community guidance]. (https://www.avg.com/en-us/remove-win32-virut) (https://forums.malwarebytes.com/topic/11798-i-am-infected/)

Practical, ordered workflow (do these in sequence):

  1. From a known-clean PC create bootable rescue media (Kaspersky Rescue, Microsoft Defender Offline or vendor removal tool) and update its signatures.
  2. Boot the infected laptop from that rescue media and run a full offline scan of the internal disk plus any attached USB/portable drives — scan the portable drive from the rescue environment before copying anything.
  3. If scans show many infected/corrupted .exe/.scr files, remove all partitions (including any OEM/recovery partition) and securely wipe the drive (HDD: full wipe; SSD: vendor secure-erase). Reinstall Windows from freshly downloaded/verified media.
  4. Install drivers only from the hardware maker’s site (do not restore driver installers or setup .exe files from the backup), update Windows fully, then install AV and run full scans. Finally, purge old System Restore points (Disk Cleanup → More Options) and create a new clean restore point. [Kaspersky rescue / AVG removal / Microsoft guidance]. (https://support.kaspersky.com/8527) (https://www.avg.com/en-us/remove-win32-virut) (https://learn.microsoft.com/en-us/answers/questions/2447721/how-can-i-delete-all-restore-points-except-the-rec)

Notes on the portable backup and drivers: an AV scan in a running Windows session can miss polymorphic or archived infections. Treat the portable drive as suspect until scanned from rescue media on a known-clean machine; copy only documents (no .exe/.scr/.zip installers). If reinfection persists even after a full wipe and clean install, the remaining suspects are an infected recovery image, another machine on the LAN, or compromised router/DNS — those require targeted inspection or professional help.

Recommended Answers

All 2 Replies

Virut requires a reformat, as you say. Are you doing a quick format or full format? I would not be doing the quick format.
Somehow or other you are re-infecting yourself from an infected file somewhere.
Stay disconnected from the net when you do the install and then install the AV before anything else. Run a full scan and see what comes up.
What happens when you install from the W7 CD?

Some viruses can survive an FDISK & FORMAT. A better method is to use a hard drive eraser util,

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.