<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ducktoes Computer Repair and Spyware Blog &#187; Virut</title>
	<atom:link href="http://ducktoes.com/blog/index.php/tag/virut/feed/" rel="self" type="application/rss+xml" />
	<link>http://ducktoes.com/blog</link>
	<description>Ms. Ducktoes is on her way!  Saving computers everyday!</description>
	<lastBuildDate>Thu, 26 Jan 2012 15:40:34 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>How to Get Rid of Virut without Reformatting</title>
		<link>http://ducktoes.com/blog/computer-repair-tools/how-to-get-rid-of-virut-without-reformatting/</link>
		<comments>http://ducktoes.com/blog/computer-repair-tools/how-to-get-rid-of-virut-without-reformatting/#comments</comments>
		<pubDate>Wed, 04 Nov 2009 14:18:13 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[Computer Repair Tools]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Virut]]></category>
		<category><![CDATA[Fix Virut]]></category>
		<category><![CDATA[How to Fix Virut]]></category>
		<category><![CDATA[How to Fix Virut without Reformatting]]></category>
		<category><![CDATA[How to Remove Virut]]></category>
		<category><![CDATA[Remove Virut]]></category>
		<category><![CDATA[Virut Virus]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1353</guid>
		<description><![CDATA[Ms. Ducktoes did it! I beat the dreaded Virut without reformatting. This is how I did it. The Dr. Web Cureit Live CD I spoke of in the last post didn&#8217;t work. At the beginning of the scan, it stopped everytime. So instead: I created an Ultimate Boot CD for Windows. I downloaded the image [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Ms. Ducktoes did it!  I beat the dreaded Virut without reformatting. This is how I did it.</p>
<ol>
<li> The Dr. Web Cureit Live CD I spoke of in the last post didn&#8217;t work.  At the beginning of the scan, it stopped everytime. So instead:</li>
<li>I created an <a href="http://www.ubcd4win.com/">Ultimate Boot CD for Windows</a>.  I downloaded the image from the UBCD website and burned it to cd.  There are detailed instructions on the site on how to do this.</li>
<li> I booted off the cd and went on the Internet through the UBCD interface.  I downloaded <a href="http://download.cnet.com/Dr-Web-CureIt/3000-2239_4-128071.html?tag=mncol">Dr. Web Cureit</a> to the Ram drive.</li>
<li>Then from the &#8220;Run&#8221; option off the start menu I browsed to the B: Ram drive and opened  cureit.exe.</li>
<li>Dr. Web Cureit started.  I had to stop the Express scan and run the Custom scan and select the C drive or the C and D drives since I had more than one hard drive. Otherwise Dr. Web Cureit just scanned the CD.</li>
<li>I cured the files instead of deleting them.  The Virut virus changes the system files and your computer system needs them.</li>
<li>I scanned a three times this way.</li>
<li>I rebooted but the computer wouldn&#8217;t start. So I did a &#8220;repair install&#8221; with my Windows Xp cd.</li>
<li>After the Repair Install, it booted, but after the logon, the logon kept returning.  I couldn&#8217;t get past it.</li>
<li>So I booted off the UBCD and replaced the Userinit.exe file in the System32/dllcache folder.  I found another copy of it in the 1386 folder and copied and pasted.  You can search using the Windows Explorer on the UBCD disk.</li>
<li>Then I ran regedit (still off UBCD) and searched for userinit.  I found the registry keys related to userinit.  One of them was set for the logon to repeat over and over, so I changed it from &#8220;1&#8243; to &#8220;0&#8243;.</li>
<li>Then I rebooted and the computer started and the logon didn&#8217;t repeat!!</li>
<li>Immediately I went into Safe Mode and started running virus scans like crazy.  I ran Malwarebytes, AVG, SuperAntiSpyware and Dr. Web Cureit again.  And found more trojans and viruses.</li>
<li>After all the scans ran clean.  I rebooted.</li>
<li>The Virut was removed!!!  And I didn&#8217;t reformat.</li>
</ol>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><map name='google_ad_map_1353_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1353?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1353_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1353&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Fcomputer-repair-tools%2Fhow-to-get-rid-of-virut-without-reformatting%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/computer-repair-tools/how-to-get-rid-of-virut-without-reformatting/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Virus Alert:  P2Ps Spreading Dangerous Virus called Virut</title>
		<link>http://ducktoes.com/blog/alerts/virus-alert-p2ps-spreading-virut/</link>
		<comments>http://ducktoes.com/blog/alerts/virus-alert-p2ps-spreading-virut/#comments</comments>
		<pubDate>Thu, 29 Oct 2009 14:55:53 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Peer-to-Peers]]></category>
		<category><![CDATA[Specific Spyware]]></category>
		<category><![CDATA[Dangerous virus Virut]]></category>
		<category><![CDATA[Virut]]></category>
		<category><![CDATA[Warning about Virut]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1336</guid>
		<description><![CDATA[The worst virus I&#8217;ve ever seen is now making its way through Bit Torrent and Limewire and other file sharing programs. It&#8217;s called Virut. And once you have it it&#8217;s pretty much game over and time for a clean install. You&#8217;re done. At least you&#8217;re operating system is kaput. So if I were you I&#8217;d [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>The worst virus I&#8217;ve ever seen is now making its way through Bit Torrent and Limewire and other file sharing programs.  It&#8217;s called Virut.  And once you have it it&#8217;s pretty much game over and time for a clean install.  You&#8217;re done.  At least you&#8217;re operating system is kaput.  So if I were you I&#8217;d make sure your anti-virus is working and updating regularly.  And stay away from P2Ps until this settles down.  Lots of people are losing everything on their computers.  What makes Virut so nasty is that it patches itself to every executable, so everything time you run an anti-virus, it &#8220;patches itself&#8221; onto the anti-virus.  Also it changes system files, so if you &#8220;delete&#8221; instead of &#8220;cure&#8221; or &#8220;heal&#8221; them, you&#8217;ll be facing at least a Repair install.  </p>
<p>Some fixes for Virut run in Safe Mode, but on my client&#8217;s computer,  Safe Mode isn&#8217;t working.  I&#8217;m right now trying a method I saw on the Internet that uses <a href="http://www.youtube.com/watch?v=FGDl-IMOt1g">Dr. Web. Cure-it.</a></p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>    </p>
<p><map name='google_ad_map_1336_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1336?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1336_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1336&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Falerts%2Fvirus-alert-p2ps-spreading-virut%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/alerts/virus-alert-p2ps-spreading-virut/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 1.470 seconds -->

