Home Malware Programs Worms Virus.Win32.Virut.av

Virus.Win32.Virut.av

Posted: March 9, 2011

Threat Metric

Ranking: 2,779
Threat Level: 9/10
Infected PCs: 53,910
First Seen: July 24, 2009
Last Seen: October 15, 2023
OS(es) Affected: Windows

The detection of Virus.Win32.Virut.av indicates the presence of a highly infectious Trojan virus and worm that can infect executable file and spread across networks. Virus.Win32.Virut.av is known to pave the way for remote attackers and specifically enables DDoS attacks as well as causing various security risks. In some cases, Virus.Win32.Virut.av may corrupt running processes, block programs drop other kinds of malware or create pop-up advertisements. Virus.Win32.Virut.av should never be tolerated on any PC; total deletion of Virus.Win32.Virut.av is required to have any semblance of safety, privacy or security on your computer.

Hopping from Computer to Computer Faster than You'd Think

Virus.Win32.Virut.av is one of the most potentially infectious kinds of malware it's possible to get and is particularly dangerous for any computers networked with other machines. Virus.Win32.Virut.av responds to the presence of a network by actively attempting to infect other linked systems, and will automatically infect various .exe files on the first PC, as well.

Your system may not show symptoms of Virus.Win32.Virut.av infection, since this malware will corrupt the Windows Registry and run as an unseen background process. Other major attacks associated with Virus.Win32.Virut.av are as follows:

  • Remote access-based control, such as recruitment into botnets for Denial-of-service attacks. Virus.Win32.Virut.av is often a detection for various backdoor Trojans that disrupt security for the specific purpose of allowing remote attackers to gain access to the machine. Remote attackers can also cause other problems such as downloading other malware, spying on information present in files or controlling input
  • Blocked access to important security and Windows maintenance applications. Virus.Win32.Virut.av is reported to block the Registry Editor and the Microsoft System Configuration Utility (or MSconfig). Blocked program events may create fake infection messages or simply stop the programs with no other signs.
  • The infection of running security processes. Virus.Win32.Virut.av can inject corrupt code into processes running in memory, particularly security-related ones, to cripple their functionality or aid in Virus.Win32.Virut.av's own survival. Insuring that a memory process-infecting malware like Virus.Win32.Virut.av isn't running is a difficult task even for automated security software, let alone human computer users.
  • Virus.Win32.Virut.av opens up communication with remote IRC servers. Typically, this is used to allow Virus.Win32.Virut.av's host computer to participate in DDoS attacks. It can also be used to transmit commands and information (a la spyware).
  • Many versions of Virus.Win32.Virut.av are Trojans and can download and install files without your permission. Such files will usually be malicious and may be able to search for and steal passwords and other critical data, or damage your computer.
  • As the finishing touch, Virus.Win32.Virut.av is also known for creating various unwanted advertisement pop-ups. Any unwanted pop-up advertisement should be considered a potential sign of a high-level threat like Virus.Win32.Virut.av. These pop-ups will often contain links to hostile websites and shouldn't be intentionally clicked.
Virus.Win32.Virut.av is a Worm (or Virus, or Trojan) By Any Other Name

Because Virus.Win32.Virut.av has multiple harmful functions and several ways of infecting new PCs, Virus.Win32.Virut.av is a very high threat to any system and should be removed through judicious application of the appropriate anti-malware programs. Regardless of how difficult Virus.Win32.Virut.av is to remove, waiting makes the problem worse – it gives Virus.Win32.Virut.av more time to drop other malware and spread to other computers.

Since Virus.Win32.Virut.av can corrupt running processes, the lack of obviously alien processes in memory doesn't indicate that this infection isn't active, which makes manual removal an improbable solution unless undertaken by an extremely skilled professional. Always use known brands of anti-malware tools to remove sophisticated threats like Virus.Win32.Virut.av, and always run these applications in Safe Mode. Anything less may turn deleting Virus.Win32.Virut.av into wasted effort!

Aliases

Trj/Passtealer.FZ [Panda]Worm/Delf.GOD [AVG]W32/AutoRun.LW!worm [Fortinet]Win-Trojan/Autorun.59392.B [AhnLab-V3]W32/SillyFDC-BP [Sophos]TR/Agent.AGBR [AntiVir]Win32.HLLW.Autoruner.1773 [DrWeb]Worm.Win32.AutoRun.EY [Comodo]Trojan.Agent.AGBR [BitDefender]Worm.Win32.AutoRun.lw [Kaspersky]Trojan.Autorun-220 [ClamAV]Win32:AutoRun-QM [Wrm] [Avast]W32/Worm.AXFI [F-Prot]Win32/AutoRun.EY [NOD32]W32/Autorun.worm.r [McAfee]
More aliases (2804)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\Users\<username>\documents\database.mdb File name: database.mdb
Size: 8.43 KB (8432 bytes)
MD5: 0a456ffff1d3fd522457c187ebcf41e4
Detection count: 6,277
Mime Type: unknown/mdb
Path: %SYSTEMDRIVE%\Users\<username>\documents
Group: Malware file
Last Updated: October 8, 2023
naked.exe File name: naked.exe
Size: 73.73 KB (73732 bytes)
MD5: da4371bc7347d3633c0eea308c9cb444
Detection count: 90
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%ALLUSERSPROFILE%\Adobe .scr File name: Adobe .scr
Size: 200.7 KB (200704 bytes)
MD5: 4798cecc36d9952ba73633c54f3468b6
Detection count: 77
Mime Type: unknown/scr
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: October 5, 2017
%SYSTEMDRIVE%\Users\<username>\appdata\roaming\musallat.exe File name: musallat.exe
Size: 190.46 KB (190464 bytes)
MD5: e1de5e4408e7db707f4a366137f40510
Detection count: 75
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\appdata\roaming
Group: Malware file
Last Updated: July 10, 2019
%ALLUSERSPROFILE%\Application Data .scr File name: Application Data .scr
Size: 1.23 MB (1232896 bytes)
MD5: 3c59bd20783744e16f749127055b52de
Detection count: 74
Mime Type: unknown/scr
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: October 5, 2017
gip3.exe File name: gip3.exe
Size: 82.84 KB (82848 bytes)
MD5: 644814aa418a3ae1716daa7fb484a539
Detection count: 73
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 10, 2022
gip1.exe File name: gip1.exe
Size: 45.05 KB (45056 bytes)
MD5: dbea1cc228c9353851e06599788a5a5e
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%SYSTEMDRIVE%\Users\<username>\appdata\roaming\musallat.exe File name: musallat.exe
Size: 203.26 KB (203264 bytes)
MD5: ef0d84b6c1066a09a657e4043070730d
Detection count: 63
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\appdata\roaming
Group: Malware file
Last Updated: July 10, 2019
%SYSTEMDRIVE%\Users\<username>\appdata\roaming\musallat.exe File name: musallat.exe
Size: 210.88 KB (210887 bytes)
MD5: 607970f9d752fc6bb5715be35704936d
Detection count: 45
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\appdata\roaming
Group: Malware file
Last Updated: July 10, 2019
K:\kop .scr File name: kop .scr
Size: 40.96 KB (40960 bytes)
MD5: 7a0b5674ec20b6455559ca1d70dc2c55
Detection count: 44
Mime Type: unknown/scr
Path: K:
Group: Malware file
Last Updated: October 5, 2017
E:\Folder 02\VirusShare_15c2f7ece2c6647c5e45608e39b08e34 File name: VirusShare_15c2f7ece2c6647c5e45608e39b08e34
Size: 40.96 KB (40960 bytes)
MD5: 15c2f7ece2c6647c5e45608e39b08e34
Detection count: 41
Path: E:\Folder 02\VirusShare_15c2f7ece2c6647c5e45608e39b08e34
Group: Malware file
Last Updated: January 10, 2022
%SYSTEMDRIVE%\Users\<username>\appdata\roaming\musallat.exe File name: musallat.exe
Size: 132.6 KB (132608 bytes)
MD5: 081dd2267978379f9a1864192402837e
Detection count: 36
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\appdata\roaming
Group: Malware file
Last Updated: July 10, 2019
paukor.exe File name: paukor.exe
Size: 416.25 KB (416256 bytes)
MD5: 7e20359dfc0b2291487f1a45c4471988
Detection count: 34
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 10, 2022
fintas.exe File name: fintas.exe
Size: 36.86 KB (36864 bytes)
MD5: 42b1eb959ce76f9013e8e9922305ca29
Detection count: 32
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 10, 2022
C:\Users\<username>\Desktop\The-MALWARE-Repo-master\Email-Worm\Prolin.exe File name: Prolin.exe
Size: 36.86 KB (36864 bytes)
MD5: 65eeb8a0fce412d7f236f8348357d1c0
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Desktop\The-MALWARE-Repo-master\Email-Worm\Prolin.exe
Group: Malware file
Last Updated: October 3, 2023
C:\Projects\Dr.Web\Virii\!!!vir\MAR\W32NAKED\NAKEDWIF.EXE File name: NAKEDWIF.EXE
Size: 73.72 KB (73728 bytes)
MD5: da9dba70de70dc43d6535f2975cec68d
Detection count: 16
File type: Executable File
Mime Type: unknown/EXE
Path: C:\Projects\Dr.Web\Virii\!!!vir\MAR\W32NAKED\NAKEDWIF.EXE
Group: Malware file
Last Updated: July 11, 2023
%SYSTEMDRIVE%\Users\<username>\appdata\roaming\musallat.exe File name: musallat.exe
Size: 226.05 KB (226051 bytes)
MD5: 5176a58244391519e1adb48221377b58
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\appdata\roaming
Group: Malware file
Last Updated: July 10, 2019
e:\ \musallat.exe File name: musallat.exe
Size: 244.6 KB (244606 bytes)
MD5: 6af25dee63ba49ddd86058eb253352cd
Detection count: 15
File type: Executable File
Mime Type: unknown/exe
Path: e:\ 
Group: Malware file
Last Updated: July 10, 2019
toil.exe File name: toil.exe
Size: 8.19 KB (8192 bytes)
MD5: ec8a1659c7d67a3859d515130bae3c4c
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 11, 2020
%SYSTEMDRIVE%\Users\<username>\appdata\roaming\musallat.exe File name: musallat.exe
Size: 189.44 KB (189440 bytes)
MD5: bba1a6d47a23806963911a46129fd920
Detection count: 6
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\appdata\roaming
Group: Malware file
Last Updated: July 10, 2019
E:\New folder\VirusShare_2ca27551e11bf054f7c5cb98eac11408 File name: VirusShare_2ca27551e11bf054f7c5cb98eac11408
Size: 36.86 KB (36864 bytes)
MD5: 2ca27551e11bf054f7c5cb98eac11408
Detection count: 5
Path: E:\New folder\VirusShare_2ca27551e11bf054f7c5cb98eac11408
Group: Malware file
Last Updated: January 20, 2022
magistr.exe File name: magistr.exe
Size: 77.82 KB (77824 bytes)
MD5: a8cfcfa06303168b5f94e0696882a3c8
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 24, 2021
E:\Folder 02\VirusShare_0eb3cca824da735aa040caa012450748 File name: VirusShare_0eb3cca824da735aa040caa012450748
Size: 76.8 KB (76800 bytes)
MD5: 0eb3cca824da735aa040caa012450748
Detection count: 5
Path: E:\Folder 02\VirusShare_0eb3cca824da735aa040caa012450748
Group: Malware file
Last Updated: January 20, 2022

More files

Registry Modifications

The following newly produced Registry Values are:

File name without path! My Picutre.SCR!new.scrimages.scrNew Folder.exeThumbs .dbwindows vista setup .scrRegexp file mask%ALLUSERSPROFILE%\Adobe .scr%APPDATA%\Microsoft\winlog.exe%APPDATA%\MusaLLaT.exe%APPDATA%\readere_lm.com%SystemRoot%\System32\XP-[RANDOM CHARACTERS].exe%WINDIR%\dc.exe

Additional Information

The following directories were created:
%PROGRAMFILES%\windows common files%PROGRAMFILES(x86)%\windows common files%TEMP%\E_4%TEMP%\E_N4
Loading...