WIN32/CRYPTOR

View previous topic View next topic Go down

WIN32/CRYPTOR

Post by london1988 on 3rd September 2009, 7:00 pm

I seemed to have unwittingly installed a virus/trojan identified by AVG 8.5 as a win32/cryptor virus.
I can't seem to get rid of it and now my AVG has informed me that I have 6 win32/cryptor files that cannot be quarantined and/or removed.
I'm new to geekpolice and it seems like a great site so I hope that I can get some help with this.

The main problem that I am facing with posting here is that when I run HijackThis the scan stops and I don't receive any log file, in fact, no NotePad file opens.
In light of this, can anyone help me either get HijackThis to work or, more importantly get rid of this malicious virus that is seriously getting me feeling low.

Many thanks!

london1988
Beginner
Beginner

Posts Posts : 1
Joined Joined : 2009-09-03
OS OS : XP
Points Points : 26563
# Likes # Likes : 0

View user profile

Back to top Go down

Re: WIN32/CRYPTOR

Post by Belahzur on 3rd September 2009, 10:31 pm

Hello.

  • Download combofix from here
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]

    1. If you are using Firefox, make sure that your download settings are as follows:

    * Tools->Options->Main tab
    * Set to "Always ask me where to Save the files".

    2. During the download, rename Combofix to Combo-Fix as follows:





    3. It is important you rename Combofix during the download, but not after.
    4. Please do not rename Combofix to other names, but only to the one indicated.
    5. Close any open browsers.
    6. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • We need to disable your local AV (Anti-virus) before running Combofix.
  • See [You must be registered and logged in to see this link.] for how to disable your AV.
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan.


  • The Recovery Console provides a recovery/repair mode should a problem occur during a Combofix run.



  • Allow ComboFix to download the Recovery Console.
  • Accept the End-User License Agreement.
  • The Recovery Console will be installed.
  • You will then get this next prompt that asks if you want to continue the malware scan, select yes



  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245121
# Likes # Likes : 1

View user profile

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum