Home Malware Programs Worms Virus.Win32.Virut.av

Virus.Win32.Virut.av

Posted: March 9, 2011

Threat Metric

Ranking: 3,275
Threat Level: 9/10
Infected PCs: 55,360
First Seen: July 24, 2009
Last Seen: March 8, 2025
OS(es) Affected: Windows

The detection of Virus.Win32.Virut.av indicates the presence of a highly infectious Trojan virus and worm that can infect executable file and spread across networks. Virus.Win32.Virut.av is known to pave the way for remote attackers and specifically enables DDoS attacks as well as causing various security risks. In some cases, Virus.Win32.Virut.av may corrupt running processes, block programs drop other kinds of malware or create pop-up advertisements. Virus.Win32.Virut.av should never be tolerated on any PC; total deletion of Virus.Win32.Virut.av is required to have any semblance of safety, privacy or security on your computer.

Hopping from Computer to Computer Faster than You'd Think

Virus.Win32.Virut.av is one of the most potentially infectious kinds of malware it's possible to get and is particularly dangerous for any computers networked with other machines. Virus.Win32.Virut.av responds to the presence of a network by actively attempting to infect other linked systems, and will automatically infect various .exe files on the first PC, as well.

Your system may not show symptoms of Virus.Win32.Virut.av infection, since this malware will corrupt the Windows Registry and run as an unseen background process. Other major attacks associated with Virus.Win32.Virut.av are as follows:

  • Remote access-based control, such as recruitment into botnets for Denial-of-service attacks. Virus.Win32.Virut.av is often a detection for various backdoor Trojans that disrupt security for the specific purpose of allowing remote attackers to gain access to the machine. Remote attackers can also cause other problems such as downloading other malware, spying on information present in files or controlling input
  • Blocked access to important security and Windows maintenance applications. Virus.Win32.Virut.av is reported to block the Registry Editor and the Microsoft System Configuration Utility (or MSconfig). Blocked program events may create fake infection messages or simply stop the programs with no other signs.
  • The infection of running security processes. Virus.Win32.Virut.av can inject corrupt code into processes running in memory, particularly security-related ones, to cripple their functionality or aid in Virus.Win32.Virut.av's own survival. Insuring that a memory process-infecting malware like Virus.Win32.Virut.av isn't running is a difficult task even for automated security software, let alone human computer users.
  • Virus.Win32.Virut.av opens up communication with remote IRC servers. Typically, this is used to allow Virus.Win32.Virut.av's host computer to participate in DDoS attacks. It can also be used to transmit commands and information (a la spyware).
  • Many versions of Virus.Win32.Virut.av are Trojans and can download and install files without your permission. Such files will usually be malicious and may be able to search for and steal passwords and other critical data, or damage your computer.
  • As the finishing touch, Virus.Win32.Virut.av is also known for creating various unwanted advertisement pop-ups. Any unwanted pop-up advertisement should be considered a potential sign of a high-level threat like Virus.Win32.Virut.av. These pop-ups will often contain links to hostile websites and shouldn't be intentionally clicked.
Virus.Win32.Virut.av is a Worm (or Virus, or Trojan) By Any Other Name

Because Virus.Win32.Virut.av has multiple harmful functions and several ways of infecting new PCs, Virus.Win32.Virut.av is a very high threat to any system and should be removed through judicious application of the appropriate anti-malware programs. Regardless of how difficult Virus.Win32.Virut.av is to remove, waiting makes the problem worse – it gives Virus.Win32.Virut.av more time to drop other malware and spread to other computers.

Since Virus.Win32.Virut.av can corrupt running processes, the lack of obviously alien processes in memory doesn't indicate that this infection isn't active, which makes manual removal an improbable solution unless undertaken by an extremely skilled professional. Always use known brands of anti-malware tools to remove sophisticated threats like Virus.Win32.Virut.av, and always run these applications in Safe Mode. Anything less may turn deleting Virus.Win32.Virut.av into wasted effort!

Aliases

Trj/Passtealer.FZ [Panda]Worm/Delf.GOD [AVG]W32/AutoRun.LW!worm [Fortinet]Win-Trojan/Autorun.59392.B [AhnLab-V3]W32/SillyFDC-BP [Sophos]TR/Agent.AGBR [AntiVir]Win32.HLLW.Autoruner.1773 [DrWeb]Worm.Win32.AutoRun.EY [Comodo]Trojan.Agent.AGBR [BitDefender]Worm.Win32.AutoRun.lw [Kaspersky]Trojan.Autorun-220 [ClamAV]Win32:AutoRun-QM [Wrm] [Avast]W32/Worm.AXFI [F-Prot]Win32/AutoRun.EY [NOD32]W32/Autorun.worm.r [McAfee]
More aliases (2804)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\Users\<username>\documents\database.mdb File name: database.mdb
Size: 8.43 KB (8432 bytes)
MD5: 0a456ffff1d3fd522457c187ebcf41e4
Detection count: 6,326
Mime Type: unknown/mdb
Path: %SYSTEMDRIVE%\Users\<username>\documents
Group: Malware file
Last Updated: September 1, 2024
D:\doc01 .scr File name: doc01 .scr
Size: 114.68 KB (114688 bytes)
MD5: d3dd17b567bdc7e7daa1ab36495d1bcb
Detection count: 92
Mime Type: unknown/scr
Path: D:
Group: Malware file
Last Updated: October 5, 2017
naked.exe File name: naked.exe
Size: 73.73 KB (73732 bytes)
MD5: da4371bc7347d3633c0eea308c9cb444
Detection count: 90
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%ALLUSERSPROFILE%\Adobe .scr File name: Adobe .scr
Size: 200.7 KB (200704 bytes)
MD5: 4798cecc36d9952ba73633c54f3468b6
Detection count: 77
Mime Type: unknown/scr
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: October 5, 2017
D:\LAPTOP DATA .scr File name: LAPTOP DATA .scr
Size: 47.61 KB (47612 bytes)
MD5: 349752fc724199059603073bacfa429e
Detection count: 74
Mime Type: unknown/scr
Path: D:
Group: Malware file
Last Updated: October 5, 2017
%ALLUSERSPROFILE%\Application Data .scr File name: Application Data .scr
Size: 1.23 MB (1232896 bytes)
MD5: 3c59bd20783744e16f749127055b52de
Detection count: 74
Mime Type: unknown/scr
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: October 5, 2017
gip3.exe File name: gip3.exe
Size: 82.84 KB (82848 bytes)
MD5: 644814aa418a3ae1716daa7fb484a539
Detection count: 73
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 10, 2022
gip1.exe File name: gip1.exe
Size: 45.05 KB (45056 bytes)
MD5: dbea1cc228c9353851e06599788a5a5e
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%SystemDrive%\FOUND.039 .scr File name: FOUND.039 .scr
Size: 118.78 KB (118784 bytes)
MD5: e64e104bd27c0e0c7eb7d1b528f45b06
Detection count: 56
Mime Type: unknown/scr
Path: %SystemDrive%
Group: Malware file
Last Updated: October 5, 2017
%ALLUSERSPROFILE%\InstallMate .scr File name: InstallMate .scr
Size: 204.8 KB (204800 bytes)
MD5: 9b85d177c939421dc4a4e7f3bee729a2
Detection count: 46
Mime Type: unknown/scr
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: October 5, 2017
K:\kop .scr File name: kop .scr
Size: 40.96 KB (40960 bytes)
MD5: 7a0b5674ec20b6455559ca1d70dc2c55
Detection count: 44
Mime Type: unknown/scr
Path: K:
Group: Malware file
Last Updated: October 5, 2017
E:\Folder 02\VirusShare_15c2f7ece2c6647c5e45608e39b08e34 File name: VirusShare_15c2f7ece2c6647c5e45608e39b08e34
Size: 40.96 KB (40960 bytes)
MD5: 15c2f7ece2c6647c5e45608e39b08e34
Detection count: 41
Path: E:\Folder 02\VirusShare_15c2f7ece2c6647c5e45608e39b08e34
Group: Malware file
Last Updated: January 10, 2022
C:\Users\<username>\Desktop\The-MALWARE-Repo-master\Email-Worm\Prolin.exe File name: Prolin.exe
Size: 36.86 KB (36864 bytes)
MD5: 65eeb8a0fce412d7f236f8348357d1c0
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Desktop\The-MALWARE-Repo-master\Email-Worm\Prolin.exe
Group: Malware file
Last Updated: January 27, 2025
paukor.exe File name: paukor.exe
Size: 416.25 KB (416256 bytes)
MD5: 7e20359dfc0b2291487f1a45c4471988
Detection count: 34
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 10, 2022
C:\Projects\Dr.Web\Virii\!!!vir\MAR\W32NAKED\NAKEDWIF.EXE File name: NAKEDWIF.EXE
Size: 73.72 KB (73728 bytes)
MD5: da9dba70de70dc43d6535f2975cec68d
Detection count: 33
File type: Executable File
Mime Type: unknown/EXE
Path: C:\Projects\Dr.Web\Virii\!!!vir\MAR\W32NAKED\NAKEDWIF.EXE
Group: Malware file
Last Updated: January 27, 2025
fintas.exe File name: fintas.exe
Size: 36.86 KB (36864 bytes)
MD5: 42b1eb959ce76f9013e8e9922305ca29
Detection count: 32
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 10, 2022
%USERPROFILE%\Desktop\????\عععع .scr File name: عععع .scr
Size: 76.28 KB (76284 bytes)
MD5: 7ab70d44ec07d076ea7dc7e8aff6a011
Detection count: 22
Mime Type: unknown/scr
Path: %USERPROFILE%\Desktop\????
Group: Malware file
Last Updated: October 5, 2017
toil.exe File name: toil.exe
Size: 8.19 KB (8192 bytes)
MD5: ec8a1659c7d67a3859d515130bae3c4c
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 11, 2020
%USERPROFILE%\Desktop\111\ADORER AVEC NOUS .scr File name: ADORER AVEC NOUS .scr
Size: 3.37 MB (3373568 bytes)
MD5: 5421ad3e8fbe0f8a04e617224f4abbf0
Detection count: 5
Mime Type: unknown/scr
Path: %USERPROFILE%\Desktop\111
Group: Malware file
Last Updated: October 5, 2017
E:\New folder\VirusShare_2ca27551e11bf054f7c5cb98eac11408 File name: VirusShare_2ca27551e11bf054f7c5cb98eac11408
Size: 36.86 KB (36864 bytes)
MD5: 2ca27551e11bf054f7c5cb98eac11408
Detection count: 5
Path: E:\New folder\VirusShare_2ca27551e11bf054f7c5cb98eac11408
Group: Malware file
Last Updated: January 20, 2022
magistr.exe File name: magistr.exe
Size: 77.82 KB (77824 bytes)
MD5: a8cfcfa06303168b5f94e0696882a3c8
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 24, 2021
E:\Folder 02\VirusShare_0eb3cca824da735aa040caa012450748 File name: VirusShare_0eb3cca824da735aa040caa012450748
Size: 76.8 KB (76800 bytes)
MD5: 0eb3cca824da735aa040caa012450748
Detection count: 5
Path: E:\Folder 02\VirusShare_0eb3cca824da735aa040caa012450748
Group: Malware file
Last Updated: January 20, 2022

More files

Registry Modifications

The following newly produced Registry Values are:

File name without path! My Picutre.SCR!new.scrimages.scrNew Folder.exeThumbs .dbwindows vista setup .scrRegexp file mask%ALLUSERSPROFILE%\Adobe .scr%APPDATA%\Microsoft\winlog.exe%APPDATA%\MusaLLaT.exe%APPDATA%\readere_lm.com%SystemRoot%\System32\XP-[RANDOM CHARACTERS].exe%WINDIR%\dc.exe

Additional Information

The following directories were created:
%PROGRAMFILES%\windows common files%PROGRAMFILES(x86)%\windows common files%TEMP%\E_4%TEMP%\E_N4
Loading...