My laptop died last week.
I get something to do with win32 (I think, but can't remember) and system and something else and file missing or corrupt.
My friend says reinstalling Windows 2000 might work but it's quite possible it won't help at all. Obviously I don't have a Windows 2000 disc and even when I do get one, if it doesn't fix my computer, I may have to take computer to Ireland.
ok what i'm guessing you had is what i got last week and it's a fucker....
win32virut.ce dropped on 6 February and has been killing off machines left right and centre ever since it has a number of different names and details but basically nukes your machine and is very difficult to remove.
it infects your exe files and your sys files and does so very quickely indeed it lives on as remenant files and also in memory between reboots.
there is no one fix to sort this out or repair the problem, and there is no anti virus protection from it at present although most AV programs will detect and remove it they do so by removign the entire infected exe or sys which prevents the computer from working correctly....
It's a viccious bugger and can infect over networks.
It is in essence a root kit virus but an excpetionally potent one which opens up a back door IRC channel and a spam mailer as well.
Good news is that you can clean it off your machine, bad news is that it mgiht have already wreaked sufficent havok on your machine to make a full flatten and re install the only way to resolve it.
in some cases it might be possible to do a repair install however you are likely to spend significantly longer doing this than flattening and rebuilding. so it's only really adviseable if you really need certain files you've not backed up.
on the other side if you have a bit of knowledge about using programs you can run the following which will clean your system.
run this first.
Kaspersky
online scanner
which detects the win32 varient.
then run this from command prompt
AVG Win32/Virut removal tool
save the file to your destop then follow these instructions.
to do this go start > run > type cmd then hit enter (Vista start > search > cmd > enter)
then type
CD desktop
hit enter
then type rmvirut.exe c:\ and hit enter this will launch the program from the command prompt which you've saved on your desktop....
it may at some point say these files are loaded in to memory and it will need to reboot do so and the virus cleaner will run at restart before windows loads to stop the virus loading back into memory.
This is a cleaner as well as a removal tool and should clean up your entire c drive (to add further infected drives append c:\ with the other drive letters such as d:\ e:\ etc)
once this is run re run the kaspersky to see if it's really gone...
then not done yet i'm afriad you need to run another tool...
btw when you machine reboots you need to do this by shutting down completely as in turn off turn on and leave around min 30 seconds in between this which purges the memory of the machine...
Ok still with me...
http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/FixVirut.com
download this...
and follow the instructions...
http://www.symantec.com/security_response/writeup.jsp?docid=2009-022016-4444-99
this is one of th emost complex viruses out there at the moment and it appears that none of the top people are on it in terms of a onesize fits all infection dependant on what it has done to your machine it doens't appear to effect much on the machine but it seems to infest it.
feel free to pm me and i'll take a look if you're london based and you desperately need the data of the machine otherwise it's new install time for you and keeping your fingers crossed that someone either knows of a way to prevent it or the AV companies sort it the fuck out...
It's also know as :
- Submission details:
- Submission received: 7 April 2009, 15:18:25
- Processing time: 6 min 20 sec
- Submitted sample:
- File MD5: 0x9B41FB94090BCE645D83372DF98026B2
- File SHA-1: 0x74D6A44E7D7A1D790D23D76E19AD73410669B183
- Filesize: 211,968 bytes
- Alias:
http://www.threatexpert.com/report.aspx?md5=9b41fb94090bce645d83372df98026b2