• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Win32:Vitro

Joined
May 30, 2007
Messages
9,019 (1.46/day)
System Name Black Panther
Processor i9 9900k
Motherboard Gigabyte Z390 AORUS PRO Wifi 1.0
Cooling NZXT Kraken X72 360mm
Memory 2 x 8GB Corsair Vengeance RGB Pro DDR4 3600Mhz
Video Card(s) Palit RTX2080 Ti Dual 11GB DDR6
Storage Samsung EVO 970 500GB SSD M.2 & 2TB Seagate Barracuda 7200rpm
Display(s) 32'' Gigabyte G32QC 2560x1440 165Hz
Case NZXT H710i Black
Audio Device(s) Razer Electra V2 & Z5500 Speakers
Power Supply Seasonic Focus GX-850 Gold 80+
Mouse Some Corsair lost the box forgot the model
Keyboard Motospeed
Software Windows 10
My dad's XP is looping... login/logoff loop.

I suspect a virus...

However first I wanted to copy userinit.exe into his system32 folder...

Now this is a laptop, so I can't just take the HDD out and stick it in another pc.

Would inserting his laptop's XP recovery diskette give me access to C:/ and to the userinit file on USB thumb-drive? :confused:
 

newtekie1

Semi-Retired Folder
Joined
Nov 22, 2005
Messages
28,472 (4.23/day)
Location
Indiana, USA
Processor Intel Core i7 10850K@5.2GHz
Motherboard AsRock Z470 Taichi
Cooling Corsair H115i Pro w/ Noctua NF-A14 Fans
Memory 32GB DDR4-3600
Video Card(s) RTX 2070 Super
Storage 500GB SX8200 Pro + 8TB with 1TB SSD Cache
Display(s) Acer Nitro VG280K 4K 28"
Case Fractal Design Define S
Audio Device(s) Onboard is good enough for me
Power Supply eVGA SuperNOVA 1000w G3
Software Windows 10 Pro x64
You can try booting to the XP CD, and selecting repair, that should load the recovery console to a C: Prompt. However, the functions are very limitted.

I would boot to some kind of Live CD(Linix or BartPE) and use that to copy the file over.
 
Joined
Aug 22, 2008
Messages
2,304 (0.40/day)
Location
Edmonton, Alberta
System Name AMD | Intel | Chumpy
Processor PHII 955BE Stock | i7 920 D0 4.01 GHz | i7 920 D0 4.01 GHz
Motherboard MSI 790FX-GD70 | EX58 - UD5 | E760 4 Way SLI
Cooling Zalman 9700 CNPS | Water Loop | Water Loop
Memory 4 GB XMS3 1600 MHz | 6 GB Dominators 1600 MHz | 6 GB Dominators 1866 MHz
Video Card(s) 3 x 9600GSO, GTX260 216 | 2 x GTX 260 216 | GTX 260 216, 9600 GSO
Storage WD 640GB | Couple o' 5400RPMs | WD 1TB
Case Cosmos S | Lancool K62 Dragonlord | Lian Li PC-P80 Armor
Power Supply TX850 | HX 1000 | HX 1000
Software Win 7 Home Premium | Win 7 Ultimate | Vista Home Premium
Has it asked if you want to start up in Safe Mode at all? That alone should work. As the computer is booting, tap F8 to bring up the advanced options menu. Select boot in safe mode.

You might be able to do a recovery from the XP recovery diskette, but honestly I've never had one of these so I don't know what it all covers.

Lastly, if its a Sata HDD you can use it in any computer as the connectors are still the same. If it is IDE, this product is all you'd need. I picked one up at a local shop for less than that, and I'll keep it around until the day Sata is everything. Newegg won't work for you, but you should be able to find it in a local shop like I did.
 
Joined
May 30, 2007
Messages
9,019 (1.46/day)
System Name Black Panther
Processor i9 9900k
Motherboard Gigabyte Z390 AORUS PRO Wifi 1.0
Cooling NZXT Kraken X72 360mm
Memory 2 x 8GB Corsair Vengeance RGB Pro DDR4 3600Mhz
Video Card(s) Palit RTX2080 Ti Dual 11GB DDR6
Storage Samsung EVO 970 500GB SSD M.2 & 2TB Seagate Barracuda 7200rpm
Display(s) 32'' Gigabyte G32QC 2560x1440 165Hz
Case NZXT H710i Black
Audio Device(s) Razer Electra V2 & Z5500 Speakers
Power Supply Seasonic Focus GX-850 Gold 80+
Mouse Some Corsair lost the box forgot the model
Keyboard Motospeed
Software Windows 10
Safe mode doesn't work either.

That connector needs me to remove the laptop's hdd out I guess huh? :(

Even in 'normal' mode (not safe mode) his XP logon screen is funny... I haven't seen it yet, he's bringing it here later - anyway he said his XP logon screen is black and not blue...

Then he inputs his user password, his desktop wallpaper shows for a couple of seconds, then once again a black screen giving him the choice to either restart, shut down, or log off.

I wonder which virus it is this time...:rolleyes:

He left the laptop on overnight and in the morning he said there was the avast warning. He selected delete (probably deleting the userinit too?) and shut it down.

Which would be the best OS to run off a thumb drive?
Right now I got only a couple 8GB dvds left which I don't want to waste...
 
Joined
Aug 22, 2008
Messages
2,304 (0.40/day)
Location
Edmonton, Alberta
System Name AMD | Intel | Chumpy
Processor PHII 955BE Stock | i7 920 D0 4.01 GHz | i7 920 D0 4.01 GHz
Motherboard MSI 790FX-GD70 | EX58 - UD5 | E760 4 Way SLI
Cooling Zalman 9700 CNPS | Water Loop | Water Loop
Memory 4 GB XMS3 1600 MHz | 6 GB Dominators 1600 MHz | 6 GB Dominators 1866 MHz
Video Card(s) 3 x 9600GSO, GTX260 216 | 2 x GTX 260 216 | GTX 260 216, 9600 GSO
Storage WD 640GB | Couple o' 5400RPMs | WD 1TB
Case Cosmos S | Lancool K62 Dragonlord | Lian Li PC-P80 Armor
Power Supply TX850 | HX 1000 | HX 1000
Software Win 7 Home Premium | Win 7 Ultimate | Vista Home Premium
Sorry, as for the best OS to run off flash drive, I'm not real adept in that area so I'm not certain.

Yes, that connector requires the HDD to come out of the laptop, and then it connects to your PC via regular IDE cable and 4 pin molex. I'd use that as a last resort though.

Strange that Safe Mode doesn't work though.
 

intel igent

New Member
Joined
Jun 5, 2005
Messages
4,640 (0.67/day)
Location
Toronto, Canada
System Name old school / new school
Processor 3.0e C0 @ 3.6 / e5200
Motherboard p4p800e-dlx / p5q-DLX
Cooling custom water see sig / air
Memory 2x1g oczPC4000EbPl / 2x2g ocz2rpr1066
Video Card(s) 3850AGP / 4890vaporX
Storage 36g raptor+120g wd / wd 1001fals 1tb
Display(s) BenQ / sharpAQUOS LC-37D64U
Case modded antec plusview / generic
Audio Device(s) audigy 2zs / ASUS Xonar HDAV1.3
Power Supply fan/cable modded powerstream 520 / OCZ 700mxsp
Software Xp pro SP2 / VISTA ultimate OEM
i had a case where i was defragmenting my HDD's and then got the smart idea to surf while it was doing so! needless to say it buggered up windoze :banghead: it was acting similar to what you are describing BP all i did was insert the Xp disc and reboot and it worked :wtf: i guess it grabbed the missing/corrupt file's while it was loading/rebooting? hope it help's?

:toast:
 
Joined
Apr 21, 2008
Messages
5,250 (0.90/day)
Location
IRAQ-Baghdad
System Name MASTER
Processor Core i7 3930k run at 4.4ghz
Motherboard Asus Rampage IV extreme
Cooling Corsair H100i
Memory 4x4G kingston hyperx beast 2400mhz
Video Card(s) 2X EVGA GTX680
Storage 2X Crusial M4 256g raid0, 1TbWD g, 2x500 WD B
Display(s) Samsung 27' 1080P LED 3D monitior 2ms
Case CoolerMaster Chosmos II
Audio Device(s) Creative sound blaster X-FI Titanum champion,Creative speakers 7.1 T7900
Power Supply Corsair 1200i, Logitch G500 Mouse, headset Corsair vengeance 1500
Software Win7 64bit Ultimate
Benchmark Scores 3d mark 2011: testing
you can use the an adapter with USB output (like hard rack or something) and put it in any pc
 
Joined
May 30, 2007
Messages
9,019 (1.46/day)
System Name Black Panther
Processor i9 9900k
Motherboard Gigabyte Z390 AORUS PRO Wifi 1.0
Cooling NZXT Kraken X72 360mm
Memory 2 x 8GB Corsair Vengeance RGB Pro DDR4 3600Mhz
Video Card(s) Palit RTX2080 Ti Dual 11GB DDR6
Storage Samsung EVO 970 500GB SSD M.2 & 2TB Seagate Barracuda 7200rpm
Display(s) 32'' Gigabyte G32QC 2560x1440 165Hz
Case NZXT H710i Black
Audio Device(s) Razer Electra V2 & Z5500 Speakers
Power Supply Seasonic Focus GX-850 Gold 80+
Mouse Some Corsair lost the box forgot the model
Keyboard Motospeed
Software Windows 10
I just got the laptop here.

Tried safe mode... there is no task bar, no icons...

The only thing which functions was ctrl-alt-del to bring up the task manager.

So I was able to browse system32 -- the userinit file is there though I don't know whether it's corrupted.

Then I started up Avast through adding a new application through same task manager.
Immediately it found a virus in the memory in system32\clipsrv.exe called Win32:Vitro

Got a boot-time scan scheduled, rebooted laptop... found other virus in Documents and Settings.... Win32:JunkPoly :ohwell:

Edit: From what I googled about the Vitro virus... things don't look bright at all. It infects windows executables and doesn't allow them to get repaired, making the OS not work... :(

Now I'll let the boot-scan finish........ and see what happens.... :rolleyes:
 
Last edited:
Joined
May 30, 2007
Messages
9,019 (1.46/day)
System Name Black Panther
Processor i9 9900k
Motherboard Gigabyte Z390 AORUS PRO Wifi 1.0
Cooling NZXT Kraken X72 360mm
Memory 2 x 8GB Corsair Vengeance RGB Pro DDR4 3600Mhz
Video Card(s) Palit RTX2080 Ti Dual 11GB DDR6
Storage Samsung EVO 970 500GB SSD M.2 & 2TB Seagate Barracuda 7200rpm
Display(s) 32'' Gigabyte G32QC 2560x1440 165Hz
Case NZXT H710i Black
Audio Device(s) Razer Electra V2 & Z5500 Speakers
Power Supply Seasonic Focus GX-850 Gold 80+
Mouse Some Corsair lost the box forgot the model
Keyboard Motospeed
Software Windows 10
Decided to reinstall XP...

Infected files included---

clipsrv.exe
cmd.exe
dllhost.exe
mnmsrvc.exe
progman.exe
sc.exe
ups.exe
userinit.exe (so I guessed one... :))
 
Joined
May 30, 2007
Messages
9,019 (1.46/day)
System Name Black Panther
Processor i9 9900k
Motherboard Gigabyte Z390 AORUS PRO Wifi 1.0
Cooling NZXT Kraken X72 360mm
Memory 2 x 8GB Corsair Vengeance RGB Pro DDR4 3600Mhz
Video Card(s) Palit RTX2080 Ti Dual 11GB DDR6
Storage Samsung EVO 970 500GB SSD M.2 & 2TB Seagate Barracuda 7200rpm
Display(s) 32'' Gigabyte G32QC 2560x1440 165Hz
Case NZXT H710i Black
Audio Device(s) Razer Electra V2 & Z5500 Speakers
Power Supply Seasonic Focus GX-850 Gold 80+
Mouse Some Corsair lost the box forgot the model
Keyboard Motospeed
Software Windows 10
Virus survived the XP reinstall.

It even got in my thumbdrive... I thought the pc was clean and used my thumbdrive to install drivers....

I managed to get in Safe Mode, and am currently backing up some 13GB of stuff on my pendrive (probably re-infecting it again...)

Then I'll do a format and clean xp install...

then re-scan my pendrive and clean it up...

then scan his 1.5TB worth of external HDD's full of downloads... only the devil knows what I'll find there

... sigh...
 

pepsi71ocean

New Member
Joined
Nov 7, 2007
Messages
1,471 (0.24/day)
Location
The Peoples Republic of New South Jersey
System Name The Grand Phoenix Clusterflop
Processor AMD Phenom II X4 965 Black Edition Deneb @3.4GHz
Motherboard ASRock 870 EXTREME3
Cooling Xigmatec S1284 (Lapped)1x200mm, 4x120mm
Memory Muskin Silverline 4GB DDR3 1333 (PC3 10666) 9-9-9-24
Video Card(s) eVGA GTX 470 SC Edition 1280mb RAM (C/S/M)(640/1280/1705)
Storage 2x500GB Seagate, 32MB Cache 1xWD 40GB UMD IDE Hdd.
Display(s) SAMSUNG 22" LCDTV HD Monitor and Samsung 24"
Case COOLER MASTER RC-690
Audio Device(s) USB 2.0 Sound (USB out to my Stero System)
Power Supply Thermaltake XT TPX-775M 775W
Software Windows XP Home SP3
should have done a linux swap to see about the files



and before you reinstall write 000000000's to the drive. Use any of the disk cleaners on the UBCD. I always do 3-5 passes between formats, since using the windows disk seems to only wipe the MTF and the MBR for some reason?
 
Joined
May 30, 2007
Messages
9,019 (1.46/day)
System Name Black Panther
Processor i9 9900k
Motherboard Gigabyte Z390 AORUS PRO Wifi 1.0
Cooling NZXT Kraken X72 360mm
Memory 2 x 8GB Corsair Vengeance RGB Pro DDR4 3600Mhz
Video Card(s) Palit RTX2080 Ti Dual 11GB DDR6
Storage Samsung EVO 970 500GB SSD M.2 & 2TB Seagate Barracuda 7200rpm
Display(s) 32'' Gigabyte G32QC 2560x1440 165Hz
Case NZXT H710i Black
Audio Device(s) Razer Electra V2 & Z5500 Speakers
Power Supply Seasonic Focus GX-850 Gold 80+
Mouse Some Corsair lost the box forgot the model
Keyboard Motospeed
Software Windows 10
Thanks everyone - much appreciation!

Please don't bother posting anymore advice on how to access laptop's hard drive :) ...

That part of the complex problem I have with Dad's laptop has been solved.
It's complex because I discovered the culprit being a Win32:Vitro virus infection.

I just read an entire 17-page thread on this specific virus on Avast!WebForum... finding out that not only is this virus missed by many popular AV programs but also that those which detect it are unable to repair the infected files.

Before reading above link, I (thought I had) cleaned up the Win32:Vitro. At least what I had done now enables me to enter safe mode for backing up documents etc.

(I requested this thread to be renamed to Win32:Vitro and moved to the Networking Forum - so if some mod happens to be reading this... ;))

____________________________________________________________________________​

For who might be interested about this Win32:Vitro, here's what I've learnt so far:



1) At present to-date it is unrepairable.
Few AV programs detect it - and those which do are only able to move infected files to chest or delete them.

2) It infects exe and htm or html files which are smaller than 100K.
However, the few av programs which detect Vitro detect only the exe files, ignoring infected htm and html files totally!

3) Disconnect infected computer if it's on a shared network.

4) First thing to do is to enter Safe Mode immediately and backup any important files you don't want to lose, and afterwards format the HDD and make a clean fresh OS install.
Things won't get worse since in Safe Mode (per online rumours...) Vitro lies inactive.

--------As weird as this might sound - If you need make any backups - DO NOT scan or follow any suggestions your AV program comes up with.

Doing so will move or delete (never repair!) essential Windows System32 executables like mnmsrvc.exe, progman.exe, userinit.exe etc and on reboot you get either an OS which doesn't load at all or an infinite logon/logoff loop.

Keeping in mind that at the end you'd be getting no choice other than reformatting and fresh OS install (or binning pc!), it's definitely counterproductive to attempt any form of repair before backing up what you need to back up.

--------For same above reasons DO not reboot infected pc at all no testing unless you're sure you got nothing to lose. Enter Safe Mode at the first Win32:Vitro warning you get. Period.
Every reboot spreads Vitro to more files, your OS will get worse, giving you logon/logoff loops or just a black screen - and it'd be even more difficult to make your precious backups!

This was what happened to my Dad's laptop. He had left it running overnight, waking up to the Avast 'radio-active spinning fan' virus alert.
Now Dad's no techie - he wouldn't imagine the consequences for following Avast's suggestion and move or delete userinit.exe so he moved/deleted every file Avast brought up and shut down the laptop.
Later same day, he persisted in scanning and rebooting "hoping it'll go away", finally phoning me when "XP wasn't allowing him in anymore" and for him all hope was lost! :laugh:
When he brought me his laptop, there was no way to log in at all not even in Safe Mode (hence me starting this thread!)

Ultimately, I entered Safe Mode "half-way" having just mouse pointer and black screen, no taskbar, no icons.
Just for lack of anything else I pressed Ctrl-Alt-Del and luck had it that the Task Manager popped up! :rockout:

At the time I didn't even know there was a virus, let alone its name..

I started Avast using 'New Task' in Task Manager getting a warning immediately on starting the memory scan. I scheduled a boot scan and rebooted.
I deleted all virus threats in bootscan, thinking laptop would be clean and just needing to run Windows Repair to replace the deleted system files.

What I got in reality was a bootable OS (with a different login screen than the usual XP one) which rang bells when I found myself unable to update windows, turn on firewall or update Avast...:rolleyes:

5) Treat any storage media you connected to the infected pc as infected as well.

Before restoring your backed up data, scan it with AV and delete ALL htm and html files.

I wouldn't suggest trying to repair or clean up the infection without formatting, unless you are very bored and have loads of patience and spare time!

It's been described as one of the worst viruses ever, using polymorphism to disguise itself.
It's a virut strain and is capable of even infecting other malware (think a virus getting infected with another virus?) :wtf:

Polonus (malware fighter) said:
W32/Vitro injects code in running processes and hooks the following functions in ntdll.dll which transfers control to the virus every time any of these function calls are made.

* NtCreateFile
* NtCreateProcess
* NtCreateProcessEx
* NtOpenFile
* NtQueryInformationProcess

It disables Windows System File Protection (SFP) by injecting code into WINLOGON.EXE. This injected code patches sfc_os.dll in memory which in turn allows the virus to infect files protected by SFP.

We haven't a clue what the purpose of this corrupting file infector is, while leaving a computer beyond repair. You cannot use it as a zombie in a botnet, you cannot use it for launching spyware. However, this malware is so advanced in nature that it cannot have been developed but by very apt malcreants.
But why it is pure negative, then? It has a random encrypted file infecting routine making it very hard to recover from.

Ruins files in a random way, partially or entirely, circumventing the Windows File Protecting scheme and ruining every executable from memory it finds reappearing and going on infecting even if only a small trace of the infector is left (copies, archives). Its actions are astonishingly fast, we have to throw in the towel - it's a virus developed just to ruin an operational system as best it can, it cannot be beaten, there is no cure against it.

This virus was "just created to junk your computer and make as much damage as possible", in this sense it is an anti-MS virus a la carte.

I just lost a computer to this virus. Going with scorched earth. Also, it jumped to my USB drive (autorun?) and almost got my laptop. Avast is catching this, when Norton and McAfee did NOT.

In the thread linked above, it's rumoured that Vista and Windows 7 users are immune to Win32:Vitro.
Uhh, if someone would be willing to test... I got plenty of Vitro-infected files available to share :D Myself, I've been checking my 2 Vista x64 rigs in system specs the entire afternoon (good reason enough since I regularly exchange pendrives/emails/downloads with dad - 2 days ago I even let him access my NAS remotely :eek:) Thankfully I got no Vitro - dunno if it's due to be being careful or just because my OS is Vista and not XP.
 
Last edited:
D

Deleted member 24505

Guest
If its a sata laptop hard drive,you can connect it to a desktop like any onther sata hdd.,same connectors.
 

ohyeah

New Member
Joined
Jun 29, 2009
Messages
1 (0.00/day)
Vista is NOT immune. My Vista Home x32 has several variations of the Vitro malware on thousands of exe files. As soon as I get the CD will be deleting the partition, reformating, and reinstalling.
 

brickhouse

New Member
Joined
Aug 25, 2009
Messages
1 (0.00/day)
gahhh

Can anyone give me some suggestions?

Recently my acer aspire one (netbook) got infected with vitro, i managed to get about 5 files off on a usb that i desperately needed.

I took the hdd out (in an aspire one its increidbly confusing to do!) therefore i was wondering if it was safe to put it in an enclosure and connect it via usb to my desktop, or will the virus just go yay!

I was hoping if i could connect it via the enclosure i could get the rest of the stuff off that i needed and re-format it.

Any suggestions?
 
Joined
May 30, 2007
Messages
9,019 (1.46/day)
System Name Black Panther
Processor i9 9900k
Motherboard Gigabyte Z390 AORUS PRO Wifi 1.0
Cooling NZXT Kraken X72 360mm
Memory 2 x 8GB Corsair Vengeance RGB Pro DDR4 3600Mhz
Video Card(s) Palit RTX2080 Ti Dual 11GB DDR6
Storage Samsung EVO 970 500GB SSD M.2 & 2TB Seagate Barracuda 7200rpm
Display(s) 32'' Gigabyte G32QC 2560x1440 165Hz
Case NZXT H710i Black
Audio Device(s) Razer Electra V2 & Z5500 Speakers
Power Supply Seasonic Focus GX-850 Gold 80+
Mouse Some Corsair lost the box forgot the model
Keyboard Motospeed
Software Windows 10
Just don't touch any htm & html files, and any exe files smaller than 100Kb.
 

From_Nowhere

New Member
Joined
Jun 13, 2008
Messages
661 (0.11/day)
I do believe this is the virus that killed my old MSI laptop last year. Thankfully I have all of my needed files on an external hard drive (that was only hooked up to that MSI when I first got it new).

My MSI laptop was running Windows Vista Ultimate x64 so those thinking Vista isn't immune...


The MSI laptop is now powered down on a shelf in my closet. I'm saving up for a SSD, and Win 7 to put on it.
 
Top