-
January 12th, 2010, 11:23 PM
#1
Win32/Cryptor virus need help how to delete it for good
I recently been hit by the Win32/Cryptor virus. Every time I start up my computer AVG 9.0 says virus infected Win32/Cryptor C:\WINDOWS\system32\anuehcy.dll It shows me this one every time I start up my computer. AVG want let me delete it just keeps coming back. I tried every program to get rid of it spybot search and destroy, ad-aware 6.0, SUPERAntiSpyware Professional, AVP 2009, Spyhunter, and Spyware doctor. None of them got ride of the virus. Then I did a scan with Malwarebytes' Anti-Malware and it found the same file as AVG 9.0 c:\WINDOWS\system32\anuehcy.dll. I deleted it then restarted my computer but AVG 9.0 still says i am infected with the virus Win32/Cryptor C:\WINDOWS\system32\anuehcy.dll I also have the problem when I go to search something on google it takes me to a totally different site. I was wondering if it had anything to do with the Win32/Cryptor virus that I have. I tried everything I know to do I don't know nothing else to do. I hope someone can help me get rid of this virus. Here is the log from Malwarebytes' Anti-Malware
Malwarebytes' Anti-Malware 1.43
Database version: 3458
Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512
01/11/2010 8:00:11 AM
mbam-log-2010-01-11 (08-00-11).txt
Scan type: Quick Scan
Objects scanned: 138233
Time elapsed: 1 hour(s), 47 minute(s), 49 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\{a6022701-b95d-48cb-a9e8-85f2a3086c61} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wpxilubt (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{a6022701-b95d-48cb-a9e8-85f2a3086c61} (Trojan.Vundo.H) -> Delete on reboot.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\WINDOWS\system32\anuehcy.dll (Trojan.Vundo.H) -> Delete on reboot
Similar Threads
-
By Twigs in forum Windows 95/98/98SE/ME
Replies: 8
Last Post: May 27th, 2005, 12:58 PM
-
By willie_eckaslike in forum Windows XP
Replies: 3
Last Post: May 11th, 2005, 05:52 PM
-
By skirabbit in forum Windows XP
Replies: 3
Last Post: November 26th, 2004, 04:00 PM
-
By carbine9 in forum Spyware & Antivirus - Security
Replies: 21
Last Post: June 11th, 2004, 06:26 AM
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|
Bookmarks