Ducktoes Computer Repair and Spyware Blog

Ms. Ducktoes is on her way! Saving computers everyday!

  • Home
  • How to Protect yourself from Spyware and Viruses

4

Nov

How to Get Rid of Virut without Reformatting

Posted by Administrator  Published in Computer Repair Tools, Virus, Virut

Ms. Ducktoes did it! I beat the dreaded Virut without reformatting. This is how I did it.

  1. The Dr. Web Cureit Live CD I spoke of in the last post didn’t work. At the beginning of the scan, it stopped everytime. So instead:
  2. I created an Ultimate Boot CD for Windows. I downloaded the image from the UBCD website and burned it to cd. There are detailed instructions on the site on how to do this.
  3. I booted off the cd and went on the Internet through the UBCD interface. I downloaded Dr. Web Cureit to the Ram drive.
  4. Then from the “Run” option off the start menu I browsed to the B: Ram drive and opened cureit.exe.
  5. Dr. Web Cureit started. I had to stop the Express scan and run the Custom scan and select the C drive or the C and D drives since I had more than one hard drive. Otherwise Dr. Web Cureit just scanned the CD.
  6. I cured the files instead of deleting them. The Virut virus changes the system files and your computer system needs them.
  7. I scanned a three times this way.
  8. I rebooted but the computer wouldn’t start. So I did a “repair install” with my Windows Xp cd.
  9. After the Repair Install, it booted, but after the logon, the logon kept returning. I couldn’t get past it.
  10. So I booted off the UBCD and replaced the Userinit.exe file in the System32/dllcache folder. I found another copy of it in the 1386 folder and copied and pasted. You can search using the Windows Explorer on the UBCD disk.
  11. Then I ran regedit (still off UBCD) and searched for userinit. I found the registry keys related to userinit. One of them was set for the logon to repeat over and over, so I changed it from “1″ to “0″.
  12. Then I rebooted and the computer started and the logon didn’t repeat!!
  13. Immediately I went into Safe Mode and started running virus scans like crazy. I ran Malwarebytes, AVG, SuperAntiSpyware and Dr. Web Cureit again. And found more trojans and viruses.
  14. After all the scans ran clean. I rebooted.
  15. The Virut was removed!!! And I didn’t reformat.

Tags: Fix Virut, How to Fix Virut, How to Fix Virut without Reformatting, How to Remove Virut, Remove Virut, Virut, Virut Virus

5 comments

Pages

  • How to Protect yourself from Spyware and Viruses

Back to Ducktoes Blog Home

  • Ducktoes Blog Home Page

Blogroll

  • Ducktoes Computer Services
  • Ducktoes Webdesign

Ducktoes Webdesign

  • Need a professional-looking web site?

Share and Save Ducktoes Blog

Share/Bookmark

Meta

  • Log in
  • Entries RSS
  • Comments RSS
  • WordPress.org
  • Add to My Yahoo!
  • Hosting by Yahoo!

Categories

  • Advanced Spyware Removal Techniques
  • Alerts
  • anti-virus
  • AVG
  • Back Up
  • Basic Computer Tips
  • Botnets
  • Computer Repair Tools
  • Definition of Spyware
  • drive by infections
  • Ducktoes heros
  • E-mail
  • Facebook
  • Free Utilities
  • Funny
  • Great Websites
  • Hallmark Card Virus
  • Hardware
  • Hints for Techies
  • How to Speed up your Computer
  • Individual Spywares
  • Keyloggers
  • Koobface
  • Learn about Computers
  • Mac Computers
  • Malware and Pornography
  • Peer-to-Peers
  • Phishing
  • Rogue Anti-spyware
  • Rootkits
  • Safestarts
  • Slow Computer
  • Software
  • Software
  • Spam
  • Specific Spyware
  • Spyware Fighting Browsers
  • Too Slow Security
  • Toobars
  • Troubleshooting
  • Uncategorized
  • Virus
  • Virut
  • w32
  • w32 Removal Tool
  • Windows XP Antivirus 2008/2009
  • WordPress

Tags

7 ways to a faster computer Ad Agent BN Add new tag Ad sense ads adultery and keyloggers adware and p2ps affairs anti-spy anti-spyware anti-virus anti-virus applications antispyware antivirus AVG battery best free anti-spyware better browser black screen white cursor blank screen bloated anti-virus boot problems Calgary computer repair Computer hardware computer humor difficult spyware fix spyware free anti-spyware free AVG Free Utilities Hallmark card fix Hallmark Card Virus How to Speed up your Computer humor Malwarebytes P2Ps without spyware Remove Hallmark card virus Remove Windows XP Antivirus 2008 Remove Windows Xp Antivirus 2009 Rogue Anti-spyware Speed up your computer spyware Spyware Doctor Virus Virut Windows XP Antivirus 2008/2009

Recent Entries

  • How to Remove Spyware and Viruses Manually with Process Explorer
  • Start Backing Up Your Files
  • Speed Up Windows 7 and Vista with this Free Tool
  • How to Stay Free with AVG
  • Be Careful when Downloading AVG from Google
  • AVG Faster Now: AVG Press Release
  • How to Fix Black Screen with White Cursor, Part 2
  • Get Perpendicular Animation from Hitachi
  • Check out this Wonderful Website: Virus.gr
  • How to Get Rid of Virut without Reformatting

Recent Comments

  • cathiedsquared in Welcome to Ducktoes Computer Repair and Spyware Bl…
  • dathWEara in How to Fix Sysguard, Win32 Patched-Kg, and Malware…
  • Administrator in How to Get Rid of Virut without Reformatting
  • Terry in How to Get Rid of Virut without Reformatting
  • Administrator in How to Get Rid of Virut without Reformatting
  • Terry in How to Get Rid of Virut without Reformatting
  • Terry in How to Get Rid of Virut without Reformatting
  • How to Fix the Black Screen with Wh… in How to Fix Black Screen with White Cursor, Part 2
  • How to Fix Black Screen with White … in How to Fix the Black Screen with White Cursor
  • How to Fix the Black Screen with Wh… in Free Anti-Spyware Programs and Tools
  • Random Selection of Posts

    • Spyware Trespasses into Your Computer
    • Win32.Renos
    • Funny YouTube Videos
    • How to Fix Rebooting Vista Machines after an Update
    • How to Remove Virus w32/ w32 Removal Tool
    • Stay away from Norton and McCaffee Internet Security
    • You Don't let Strangers into Your House
© 2008 Ducktoes Computer Repair and Spyware Blog is proudly powered by WordPress
Theme designed by Roam2Rome