Win32.Vitro properties:
• Changes browser settings
• Shows commercial adverts
• Hides from the user
• Stays resident in background
W32:Vitro (Virut) virus removal
How to Remove Win32: Vitro virus.
The Virut family of viruses uses polymorphism to hide from all anti-virus protection, it infects executable files. File infection makes it very hard to repair a system that has been infected. W32/Vitro injects code in running processes and hooks the following functions in ntdll.dll which transfers control to the virus every time any of these function calls are made.
* NtCreateFile
* NtCreateProcess
* NtCreateProcessEx
* NtOpenFile
* NtQueryInformationProcess
We would strongly recommend rebuilding the system from backups.
How to Remove Win32:Vitro (Removal Instructions)




