Can't remove Win32/Cryptor
Results 1 to 5 of 5

Thread: Can't remove Win32/Cryptor

  1. #1
    Registered User
    Join Date
    Nov 2004
    Posts
    73

    Can't remove Win32/Cryptor

    I recently been hit by the Win32/Cryptor virus. Every time I start up my computer AVG 9.0 says virus infected Win32/Cryptor C:\WINDOWS\system32\anuehcy.dll It shows me this one every time I start up my computer. AVG want let me delete it just keeps coming back. I tried every program to get rid of it spybot search and destroy, ad-aware 6.0, SUPERAntiSpyware Professional, AVP 2009, Spyhunter, and Spyware doctor. None of them got ride of the virus. Then I did a scan with Malwarebytes' Anti-Malware and it found the same file as AVG 9.0 c:\WINDOWS\system32\anuehcy.dll. I deleted it then restarted my computer but AVG 9.0 still says i am infected with the virus Win32/Cryptor C:\WINDOWS\system32\anuehcy.dll I also have the problem when I go to search something on google it takes me to a totally different site. I was wondering if it had anything to do with the Win32/Cryptor virus that I have. I tried everything I know to do I don't know nothing else to do. I hope someone can help me get rid of this virus. Here is the log from Malwarebytes' Anti-Malware
    Malwarebytes' Anti-Malware 1.43
    Database version: 3458
    Windows 5.1.2600 Service Pack 3
    Internet Explorer 6.0.2900.5512

    01/11/2010 8:00:11 AM
    mbam-log-2010-01-11 (08-00-11).txt

    Scan type: Quick Scan
    Objects scanned: 138233
    Time elapsed: 1 hour(s), 47 minute(s), 49 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 3
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 1

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\{a6022701-b95d-48cb-a9e8-85f2a3086c61} (Trojan.Vundo.H) -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wpxilubt (Trojan.Vundo.H) -> Delete on reboot.
    HKEY_CLASSES_ROOT\CLSID\{a6022701-b95d-48cb-a9e8-85f2a3086c61} (Trojan.Vundo.H) -> Delete on reboot.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    c:\WINDOWS\system32\anuehcy.dll (Trojan.Vundo.H) -> Delete on reboot.

  2. #2
    Registered User CeeBee's Avatar
    Join Date
    Nov 2002
    Location
    USA
    Posts
    2,494
    Protected by Glock. Don't mess with me!

  3. #3
    Registered User
    Join Date
    Nov 2004
    Posts
    73
    CeeBee that didn't help i still have that Win32/Cryptor virus on my computer. Can anyone please help me i tried everything and have no idea how to get ride of the virus. Any help would be wonderful thanks.

  4. #4
    Registered User Ferrit's Avatar
    Join Date
    Apr 2001
    Location
    Vancouver Island The Real Canada
    Posts
    4,952
    Read your other post and try not to post twice its just confusing
    Gigabyte 990FXA-UD3
    AMD FX 8350 4ghz OCTO-Core
    Windows 8.1 PRO 64
    Adata 256 gig SSD
    Kingston HyperX 1600 16 Gigs
    Sapphire R9 280 2gig
    Enermax Liberty Modular 620
    www.northernaurora.net
    http://www.northernaurora.net/page/chat.html

  5. #5
    Registered User maced's Avatar
    Join Date
    Aug 2008
    Location
    Universal City, TX
    Posts
    16

    Win32/Cryptor

    Jon, try ADS Spy (http://www.softpedia.com/get/System/.../ADS-Spy.shtml).

    This program looks for files hidden by programs utilizing a feature of Windows called Alternate Data Streams (ADS). Run this program and you will probably see a long list of files utilizing ADS but look specifically for the dll file you mention in your post. If you see it, remove it and reboot your system. Don't forget that the virus may have created a Restore Point so you may want to avoid "going back" using one as you will re-infect yourself. If you are successful in removing the virus, delete your restore points and create a new one once your system is clean.

    Kokdiak, Ferrit, slgrieb, please chime in if you think a different approach may be better.

Similar Threads

  1. Util to remove Nero
    By Garfield99 in forum Tech Tips
    Replies: 0
    Last Post: October 25th, 2006, 08:24 AM
  2. DOWNLOAD: Remove Toolbar Buddy 4.0
    By TechZ in forum Other Software Applications
    Replies: 0
    Last Post: December 4th, 2004, 12:36 AM
  3. trying to remove bios chip's socket
    By vapd in forum BIOS/Motherboard Drivers
    Replies: 3
    Last Post: May 8th, 2002, 02:46 PM
  4. Cannot remove devices in device manager....
    By littlerumper in forum Tech-To-Tech
    Replies: 6
    Last Post: August 17th, 2001, 04:15 PM
  5. Manually remove printer
    By jasonwebb in forum Windows 95/98/98SE/ME
    Replies: 1
    Last Post: April 19th, 2001, 03:58 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •