View Full Version : Polycrypt.b Problem
hkedi
May 24th, 2007, 10:47 PM
Hello everyone, I am new here.
I am a user of NOD32 anti virus and AVG anti spyware.
Recently my PC has been affected by a malware named Trojan.PolyCrypt.b.
My NOD32 has been updated however it cannot scan out this malware while my AVG can only scan this out as file under the system volume information of my c drive.
Here is the problem, since there is only one file that can be found is detected, I first tried to delete and of cuz it does not work and after reboot it comes out again. So I quarintined it and tried to use my PC normally again.
However, few days later it became another file in system volume information and my PC runs wierd again.
I tried to find out solutions from internet but seems no help at all. therefore I came here and I hoped anyone can help me to delete this malware.
Thank you!:)
ASpace
May 25th, 2007, 02:38 AM
-{ Quote: "Hello everyone, I am new here.
I am a user of NOD32 anti virus and AVG anti spyware.
Recently my PC has been affected by a malware named Trojan.PolyCrypt.b.
" }-
I would then recommend you to contact ESET Techical support (http://www.eset.eu/support/form) for further help.
Include as many details as possible , exact file names and location , link to this thread and other appropriate things.
karl.ewido
May 25th, 2007, 03:32 AM
Please send us also a copy of this detected Nod file:
http://www.ewido.net/en/support/?AID=34
hkedi
May 25th, 2007, 04:01 AM
-{ Quote: "Please send us also a copy of this detected Nod file:
http://www.ewido.net/en/support/?AID=34" }-
Sorry, maybe my english is bad.
Let me explain it 1 more time.
My NOD32 has been updated and IT CANNOT SCAN OUT ANY VIRUS OR MALWARE in my PC.
My AVG anti spyware can scan it out, it is a file inside my System Volume Information.
I tried to delete it but it appears again after I reboot my PC.
The problem is that when my internet is on it will suddenly have thousands of pop ups and my programs will open randomly.
(example, microsoft word, excel, anti virus)
And there is even one time that my NOD32 has even been once uninstalled and I did not know it.
I will send the file to Ewido soon, and thx for replying my post :)
Firecat
May 25th, 2007, 06:23 AM
-{ Quote: "Sorry, maybe my english is bad.
Let me explain it 1 more time.
My NOD32 has been updated and IT CANNOT SCAN OUT ANY VIRUS OR MALWARE in my PC.
My AVG anti spyware can scan it out, it is a file inside my System Volume Information.
I tried to delete it but it appears again after I reboot my PC.
The problem is that when my internet is on it will suddenly have thousands of pop ups and my programs will open randomly.
(example, microsoft word, excel, anti virus)
And there is even one time that my NOD32 has even been once uninstalled and I did not know it.
I will send the file to Ewido soon, and thx for replying my post :)" }-
PolyCrypt....isn't that a dependent packer detection? ???
The best way to delete this thing forever is to disable System Restore and enable it again. See below:
http://www.trendmicro.com/vinfo/secadvisories/default6.asp?VNAME=Disabling%2FEnabling+System+Restore
hkedi
May 26th, 2007, 01:19 AM
-{ Quote: "PolyCrypt....isn't that a dependent packer detection? ???
The best way to delete this thing forever is to disable System Restore and enable it again. See below:
http://www.trendmicro.com/vinfo/secadvisories/default6.asp?VNAME=Disabling%2FEnabling+System+Restore" }-
So is that mean first I disable system restore then I delete the malware and then enable it again and restore it to a day where the malware was not in my PC yet?
Firecat
May 26th, 2007, 03:29 AM
-{ Quote: "So is that mean first I disable system restore then I delete the malware and then enable it again and restore it to a day where the malware was not in my PC yet?" }-
No, since the malware was in your System volume information folder, you should just disable System Restore which will delete all restore points. Then run another scan with your AV/As and you should be clean.
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums