Virus.Win32.Virut.q
Virus.Win32.Virut.q is a generic detection for the W32/Virut family of polymorphic, entry point obscuring (EPO) file infectors with IRC bot functionality.Aliases as virus.win32.virut.q (Kaspersky) W32.Virut.U (Symantec)
is a generic detection for the W32/Virut family of polymorphic, entry point obscuring (EPO) file infectors with IRC bot functionality.
It appends to the end of the last section of executable (PE) files an encrypted copy of its code. The decryptor is polymorphic and can be located either:
- Immediately before the encrypted code at the end of the last section
- At the end of the code section of the infected host in ’slack-space’ (assuming there is any)
- At the original entry point of the host (overwriting the original host code)
The decryptor will either receive control directly or an API call within the host code body will be overwritten to point to it (EPO technique). In all cases where host code is overwritten by the virus the original bytes are stored within the encrypted virus body, and are restored before transfering control back to the host.
Need help? Post you problem on Free Malware Remove Help forum
Virus.Win32.Virut.q Summary
1.Temporarily Disable System Restore;2.Reboot computer in SafeMode;3.delte Virus.Win32.Virut.q virus files and kill Virus.Win32.Virut.q file task process(if have);4.Delete/Modify any values added to the registry by Virus.Win32.Virut.q ;5.delete IE temp files,restart the computer and run a whole scan with Kaspersky. Virus.Win32.Virut.q virus files as following: