Home Malware Programs Viruses Virus:Win32/Virut.gen!AO

Virus:Win32/Virut.gen!AO

Posted: May 14, 2013

Threat Metric

Ranking: 7,296
Threat Level: 8/10
Infected PCs: 3,682
First Seen: May 14, 2013
Last Seen: October 13, 2023
OS(es) Affected: Windows

Virus:Win32/Virut.gen!AO is a virus, which allows attackers to gain access to a vulnerable computer. Virus:Win32/Virut.gen!AO downloads and runs potentially malicious files and blocks an affected PC user from visiting security-related websites. Virus:Win32/Virut.gen!AO circulates through affected networks and removable drives such as USB sticks, floppy disks or flash card readers. Virus:Win32/Virut.gen!AO searches for all the removable drives on the affected computer system from drive D:\ to Z:\. When a removable drive is found, Virus:Win32/Virut.gen!AO installs a copy of itself with a randomly generated filename. Virus:Win32/Virut.gen!AO can harm some affected files with no possibility to repair them. Virus:Win32/Virut.gen!AO blocks applications from functioning properly or makes them crash when run. Virus:Win32/Virut.gen!AO is a polymorphic file infector, which inserts malicious code into every .EXE and .SCR file that it finds on the infected computer. When run, Virus:Win32/Virut.gen!AO inserts a malicious code into the 'WINLOGON.exe' process. Virus:Win32/Virut.gen!AO creates the registry entry so that the virus is added on the firewall's authorized applications list.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



AjsCEJmF.exe File name: AjsCEJmF.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
HDWXPx64.exe File name: HDWXPx64.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
VPyKrBDo.exe File name: VPyKrBDo.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
XjKBISPV.exe File name: XjKBISPV.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List "\??\[malware file and folder name]" "\??\[malware file and folder name]:*:enabled:@shell32.dll,-1"
Loading...