Threat Database Viruses Virus.Win32.Virut.q

Virus.Win32.Virut.q

By GoldSparrow in Viruses

Win32.Virut.q is a highly dangerous computer virus that attacks the computers running the Windows operating system. Win32.Virut.q is able to infect all the executable files (.exe) and screen saver files (.scr) on the computer system. The problem is that the Win32.Virut.q has numerous bugs in its code and it may misinfect a proportion of executable files; therefore, the files are infected beyond remedy. Once the Virus.Win32.Virut.q opens a backdoor, it will try to download additional malware infections and send personal details to remote servers. Win32.Virut.q attempts to connect to an IRC server located at ircd.zief.pl and then joins the channel named "Virut". The only way to clean the Win32.Virut.q is a clean reformat, and it is the only way to return the PC to its usual operating condition.

File System Details

Virus.Win32.Virut.q may create the following file(s):
# File Name Detections
1. %AppData%\inetinfo.exe
2. %AppData%\smss.exe
3. %Windir%\Temp\s8w485dpq.exe
4. %AppData%\csrss.exe
5. %AppData%\services.exe
6. %Windir%\Temp\qtfcyyp.exe
7. %Templates%\DIA 54TR10.com
8. %AppData%\Isass.exe
9. %AppData%\winlogon.exe
10. %Windir%\Temp\ydky9kv.exe
11. %System%\%UserName%'s Picture.scr
12. %AppData%\ListHost5.txt
13. %Programs%\Startup\Speed.pif

Registry Details

Virus.Win32.Virut.q may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MouseDriver\Security
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MouseDriver
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] pn13 = "%Windir%\TEMP\ydky9kv.exe"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MouseDriver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] New Anti Virus = ""%Windir \Security\System.exe"" UserFaultCheck = "%System%\dumprep 0 -u"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MouseDriver\Security
60xu9 = "%Windir%\TEMP\qtfcyyp.exe"

Trending

Most Viewed

Loading...