Folder AVG Forums » Other topics » Virus Removal, Tools for Removing » AVG 9.0 Resident Shield And Win32/Cryptor Virus
May 26, 2010 01:14 AVG 9.0 Resident Shield And Win32/Cryptor Virus #89503
Reply with Quote | Quick Reply | Top
Safezone

Avatar

Novice
Join Date: 23.5.2010
Posts: 2
Resident Shield Cryptor 32 Detection

The other day I received a notification via Resident Shield that the win32/Cryptor virus was detected. The only option presented in the dialog box was Ignore.

I looked in the manual for AVG under Resident Shield and it states the following:

7.6.1. Resident Shield Principles
The Resident Shield component gives your computer continuous protection. It scans
every single file that is being opened, saved, or copied, and guards the system areas
of the computer. When Resident Shield discovers a virus in a file that is accessed, it
stops the operation currently being performed and does not allow the virus to activate
itself. Normally, you do not even notice the process, as it runs "in the background",
and you only get notified when threats are found; at the same time, Resident Shield
blocks activation of the threat and removes it. Resident Shield is being loaded in the
memory of your computer during system startup.

After I received the message I have run a full virus scan using the software listed below. None of the programs detect any virus. I have not noticed any unusual behavior with any program. Does this mean that Resident Shield has blocked the virus? Is there any other program I should check with?

Windows XP Media Center 2005 Edition, Service Pack 3 installed
AVG 9.0.819 installed, Virus DB 271.1.1/2896
Spybot Search and Destroy 1.6.2.0 (systems settings protector 1.6.6.32)
AVG Rescue CD
Advanced SystemCare V.3.5.1
Threatfire HijackThis
ZoneAlarm Firewall ZoneAlarm version:8.0.298.000
TrueVector version:8.0.298.000
Driver version:8.0.298.000

Resident Shield detection
"Infection";"Object";"Result";"Detection time";"Object Type";"Process"
"Virus found Win32/Cryptor";"C:\WINDOWS\system32\msfeedsbs.dll";"Object is white-listed (critical/system file that should not be removed)";"5/18/2010, 8:34:36 PM";"file";"C:\WINDOWS\system32\svchost.exe"

Thanks in advance for your input.
May 26, 2010 08:22 Re: AVG 9.0 Resident Shield And Win32/Cryptor Virus #89537
Reply with Quote | Quick Reply | Top
BIG AL 43

Avatar

Moderator
Join Date: 18.6.2009
Posts: 23779
"Object is white-listed (critical/system file that should not be removed)"

You have a critical Windows system file that got infected... removing it without taking the proper steps would make your system unbootable. In short you need to do it manually. This is why that file is whitelisted.

Using your Windows CD... type SFC /SCANNOW on the run line to see if Windows will correct the issue for you or not. If not you will have to make the replacement from the Recovery Console that you can get to after booting from the CD.


AVG Free Volunteer ModeratorAVG Free Forum member since - Nov. 27, 2004My total posts on the Old AVG Free Forum - 27,063
Alan
May 26, 2010 08:42 Re: AVG 9.0 Resident Shield And Win32/Cryptor Virus #89547
Reply with Quote | Quick Reply | Top
jirka82

Avatar

Administrator
Join Date: 19.6.2009
Posts: 3892
Hi,

Also you can check this How-To article if you would like to find out more about replacing system files.

Thanks.

***************AVG Team