Virus

Virus.Virut removal

Malware Removal

The Virus.Virut is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus.Virut virus can do?

  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Code injection with CreateRemoteThread in a remote process
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

ilo.brenz.pl
ant.trenz.pl
mrqnes.com
cbbvnr.com
mxgjyh.com
ypezxi.com
noiwpk.com
zoerrv.com

How to determine Virus.Virut?


File Info:

crc32: 8275F576
md5: 43c4fe0c958de3f3008a4d16cc553f24
name: tregsvr.exe
sha1: a0e09b779142b2ebc50d3adba7fc1fef5497ed45
sha256: 82cfdfd7fa643c7685f9b4263800a538913c54af2634d35c16faf183c3309351
sha512: f8578ceade23819472fec3a6259732606029e97e5d32a8b7d2918fa99ca24f377a555f3dbb185e6e70ad9a6be186e4a807452883032f33b56561724fe872d262
ssdeep: 12288:faNtZbkecmymjWtR1mBmsHdmheAt/N+araNXxpt1:yN4ecmhi1mBmsHdmheAtl+arafpt
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Virus.Virut also known as:

BkavW32.Vetor.PE
MicroWorld-eScanWin32.Virtob.Gen.12
FireEyeGeneric.mg.43c4fe0c958de3f3
CAT-QuickHealW32.Virut.G
Qihoo-360Virus.Win32.Virut.M
McAfeeW32/Virut.n.gen
CylanceUnsafe
ZillyaVirus.Virut.Win32.1938
K7AntiVirusVirus ( f10002001 )
BitDefenderWin32.Virtob.Gen.12
K7GWVirus ( f10002001 )
Cybereasonmalicious.c958de
TrendMicroPE_VIRUX.R
BaiduWin32.Virus.Virut.gen
F-ProtW32/Virut.AM
SymantecW32.Virut.CF
TotalDefenseWin32/Virut.17408
APEXMalicious
AvastWin32:Vitro
GDataWin32.Virtob.Gen.12
KasperskyVirus.Win32.Virut.ce
AlibabaVirus:Win32/Virut.ff914962
NANO-AntivirusVirus.Win32.Virut.hpeg
ViRobotWin32.Virut.Gen.C
AegisLabVirus.Win32.Virut.llPw
RisingVirus.Virut!1.A08B (CLOUD)
Endgamemalicious (high confidence)
EmsisoftWin32.Virtob.Gen.12 (B)
ComodoVirus.Win32.Virut.CE@1fhkga
F-SecureMalware.W32/Virut.Gen
DrWebWin32.Virut.56
VIPREVirus.Win32.Virut.ce.5 (v)
Invinceaheuristic
McAfee-GW-EditionW32/Virut.n.gen
Trapminemalicious.high.ml.score
CMCVirus.Win32.Virut.1!O
SophosW32/Scribble-B
IkarusVirus.Win32.Virut
CyrenW32/Virut.AM
JiangminWin32/Virut.bt
AviraW32/Virut.Gen
MAXmalware (ai score=84)
Antiy-AVLVirus/Win32.Virut.ce
KingsoftWin32.Virut.dd.368640
ArcabitWin32.Virtob.Gen.12
ZoneAlarmVirus.Win32.Virut.ce
MicrosoftVirus:Win32/Virut.BN
AhnLab-V3Win32/Virut.F
VBA32BScope.TrojanPSW.Papras
TACHYONVirus/W32.Virut.Gen
Ad-AwareWin32.Virtob.Gen.12
MalwarebytesVirus.Virut
PandaW32/Sality.AO
ESET-NOD32Win32/Virut.NBP
TrendMicro-HouseCallPE_VIRUX.R
TencentVirus.Win32.Virut.Gen.200001
YandexWin32.Virut.AB.Gen
SentinelOneDFI – Malicious PE
FortinetW32/Virut.CE
BitDefenderThetaAI:FileInfector.C9457D4313
AVGWin32:Vitro
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureVirus.Virut.CE

How to remove Virus.Virut?

Virus.Virut removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment