Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Trojan Horse Cryptic.GQ - Access Denied - Unable to delete folders - Can't get rid of malware.


  • Please log in to reply
1 reply to this topic

#1 Spacetrucker

Spacetrucker

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:10:12 AM

Posted 28 April 2010 - 11:04 PM

Windows XP Pro SP3, AVG Free 9.0.814 Virus DB: 2711.1/2839

AVG Virus Vault has a Trojan Horse named Cryptic.GQ in it. The path is C:\Documents and Settings\username\local settings\temp\wxSI.exe. I have some folders that I can't delete in this path.
C:\Documents and Settings\username\local settings\temp\IswTmp\Shared\SxS\. There's two folder underneath SxS that have really long names like 6adf1ed and aac18a, can't delete these either.

Their attributes are set to read only. I've booted up in safe mode to a command prompt, logged in as the admin, navigated to C:\Documents and Settings\username\local settings\temp\IswTmp\, ran attrib -R -S -H /S /D Shared. Access is still denied.

I've updated AVG, and ran a couple of full scans, they come back clean. But when I run the scan directly against the folders, the scan doesn't complete, it just keeps running. Installed Spyware Doctor, it finds something but won't clean it until you buy. Installed SpyBot, ran it until it came back clean. Installed combofix and ran it, the log file has a paragraph about scanning hidden processes, hidden autostart entries, hidden files, says the scan completed successfully and hidden files: 0

I suspect that those folders contain some type of malware because I can't seem to change the attributes, or delete them. I'm asking for suggestions on how to go about cleaning this up? Let me know if you need additional info.

Thanks in advance...

Edited by Budapest, 28 April 2010 - 11:07 PM.
Moved from XP ~BP


BC AdBot (Login to Remove)

 


#2 Spacetrucker

Spacetrucker
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:10:12 AM

Posted 29 April 2010 - 10:25 PM

My apologies for not having followed the rules, running gmer, dds, posting logs, etc. I'll get that done and add them to my post. I've been reading some other posts, and have ran ccleaner, and malwarebytes. Ccleaner is running cleanly after running it three times, I did ensure it cleaned out the recycler, I did have what I suspect to be malware stuck in there. I ran ccleaner first, until it ran clean. Then I installed Malwarbytes, a quick scan came back clean, I'm now running a full scan.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users