Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Crypt.AQLW


  • This topic is locked This topic is locked
2 replies to this topic

#1 DrMikeJ

DrMikeJ

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:01:09 PM

Posted 03 May 2012 - 05:28 AM

I was using Google Images and I clicked on one, and a fraud spyware scanner popped up - I went to kill it using the Task Manager to discover it was disabled.
AVG 2012 (Free) then was going berserk giving all manner of files which were being infected with Crypt.AQLW (& variant names) every few seconds. ping.exe was one of the files infected. It reminded me of the Biblical "our name is legion for we are many)!
I ran the Malwarebytes program and it restored the Task Manager, and deleted some files.
I then ran all manner of Trojan removers (AVG remove Zero Access, Symatec, Fix Zero Access, Panda Yorkyt, and avastMBR (Always disbaling AVG First). I ran the TDSSKiller and it quarantined some files. AVG then stopped reporting the Trojan, and I replaced ping.exe from another computer and the system seemed normal. So I deleted all the various reports, thinking all was well.

I had an old copy of ComboFix (from about 4 years ago). I thought ok one last check so I ran it untutored (never read any instructions to the contrary!) and it offered to update (accepted) and after running it, it reported this;
"You are infected with Rootkit.ZeroAccess! It has inserted itself into the tcp/ip stack. This is a particularly difficult infection. If for any reason that you’re unable to connect to the internet after running ComboFix, reboot once and see if that fixes it. If it's not fixed, run ComboFix one more time". I have removed ComboFix with the uninstall command.

My question is this – is there any other Trojan remover which might to the full job – or will I have to reinstall Windows XP – and if so can I do a reinstall and keep my data and settings – or how can I remove the tcp/ip stack and force a reinstall of the chained programs which make up the stack?

BC AdBot (Login to Remove)

 


#2 Budapest

Budapest

    Bleepin' Cynic


  • Moderator
  • 23,579 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:09 AM

Posted 03 May 2012 - 05:17 PM

Hello,Please follow the instructions in ==>This Guide<== starting at step 6. If you cannot complete a step, skip it and continue.Once the proper logs are created, then post them in a reply to this topic by using the Add Reply button.If you can produce at least some of the logs, then please create the post and explain what happens when you try to create the log(s) that you couldn't get. If you cannot produce any of the logs, then still post the reply and explain that you followed the Prep. Guide, were unable to create the logs, and describe what happens when you try to create the logs.Please note that I am not a member of the Malware Removal Team and will not be assisting you in removing the infection. I'm simply helping you to post the information they need in order to assist you.If HelpBot replies to your topic, PLEASE follow Step One so it will report your topic to the team members.
The power of accurate observation is commonly called cynicism by those who haven't got it.

—George Bernard Shaw

#3 DrMikeJ

DrMikeJ
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:01:09 PM

Posted 05 May 2012 - 02:55 AM

This topic can close as I am gpoing to do a reinstall - many thanks for your assistance




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users