Variants in the Virut family (also known as Virtob) are polymorphic, memory-resident, appending file infectors that have Entry Point Obscuring (EPO) capabilities.
Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.
More information on the scanning and removal options available in your F-Secure product can be found in the Help Center.
You may also refer to the Knowledge Base on the F-Secure Community site for further assistance.
For general instructions on disinfecting a local network infection, please see Eliminating A Local Network Outbreak.
Viruses belonging to this family infect files with .EXE and .SCR extensions. All viruses belonging to the Virut family also contain an IRC-based backdoor that provides unauthorized access to infected computers.
Some Virut variants contain the following text strings:
Virut is a polymorphic appending file infector with EPO (Entry Point Obscuring) capabilities. The virus uses several infection methods:
The virus checks whether or not it is already active. If it is, then depending on the infection method used, the virus does one of the following:
If the virus is not yet active, the second decryptor decrypts the rest of the virus body and initiates installation cycle. During the installation cycle, the virus injects its code into a system process, hooks a few low-level Windows API calls and stays resident in memory. When a file with .EXE or .SCR extension is opened or run, the virus tries to infect it with one of its four methods.
The virus contains an IRC-based backdoor. The backdoor connects to the pre-defined IRC server (ircd.zief.pl in the latest variants) and joins the "virtu" channel. The author of the virus can give commands to all or to specific bots created by the virus in the channel. The bot is quite primitive - it allows a hacker to download and run files from Internet.
Description Created: 2007-10-04 17:47:27.0
Description Last Modified: 2010-07-05 05:32:52.0