I think a live CD might be more helpful than other methods of removal. Download the Kaspersky Live CD from here: ftp://ftp.downloads1.kaspe
Hope it helps.
Main Topics
Browse All TopicsI have an xp pro machine infected with cryptor I believe. (AVG and malwarebytes call it cryptor anyway)
I have a full acronis backup of the drive.
I have scanned with avg updated in safe mode and removed the virus. On reboot no .exe files work. Pops up asking what to do with the file type.
Same issue when removed with malwarebytes and dr web. (incidently avg was preinstalled and able to run. I am unable to install any other virus fighting software. Malwarebytes and dr web scans were done with the drive slaved.)
I have now reloaded my backup and am looking for another avenue to attack this infection.
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
I think a live CD might be more helpful than other methods of removal. Download the Kaspersky Live CD from here: ftp://ftp.downloads1.kaspe
Hope it helps.
All those will work.. but I think, you should do this before you try anything else:
Save the following text as a .INF file:
[Version]
Signature="$Chicago$"
Provider=Symantec
[DefaultInstall]
AddReg=UnhookRegKey
[UnhookRegKey]
HKLM, Software\CLASSES\batfile\s
HKLM, Software\CLASSES\comfile\s
HKLM, Software\CLASSES\exefile\s
HKLM, Software\CLASSES\piffile\s
HKLM, Software\CLASSES\regfile\s
HKLM, Software\CLASSES\scrfile\s
HKCU, Software\Microsoft\Windows
Right-click the .INF file and click install. It does not display any notice or boxes when you run it. If you face any issues while saving the file, please download the file from here:
http://securityresponse.sy
ran this tool to get exe's working again
http://www.dougknox.com/xp
continuing scans again.
I could've sworn that I've posted here before... but obviously not.
If MalwareBytes and other tools won't help, then run Combofix too and show us the log.
Please download ComboFix by sUBs:
http://download.bleep
(If it doesn't run re-download but rename before saving to your desktop)
You must download it to and run it from your Desktop
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
If needed, here's the Combofix tutorial which includes the installation of the Recovery Console:
http://www.bleepin
Ok here's the update.
Ran any number of av tools to pull out the bulk of it. I used the kav rescue cd with update definitions. This of course hosed the exe extensions. Used the exe fix tool listed above to get that back. At that point I was able to run malwarebytes, spybot, avg and smitfraud fix after spybot picked that up.
Scanned with each in safe mode until they started coming up clean.
Now it appears my only issue is trying to run defrag says that chkdsk /f is scheduled. Once I correct that I do not believe there are any more issues.
Business Accounts
Answer for Membership
by: dragon24Posted on 2009-07-30 at 12:01:03ID: 24983287
Have you tried a scan with AVG Link Scanner, which used to be ewido? You might be able to access the online scan using safe mode with networking. /
Here is the website: http://linkscanner.avg.com