PDA

View Full Version : IMON warning on dangerous access


Cyberslider
January 30th, 2009, 07:59 AM
:dry: I'm getting from time to time a strange warning: hxxp://incrates.com/iCashe.exe is trying to attack with a variant of win32/kryptik.FI trojan.

No options to use other than terminate it. But it keeps coming back - Can something be done?! I checked throughlly with the AV, and various Trojan removals, cashe cleaners, and temp files removers - still nothing...

Any ideas?!???

Fixer
January 30th, 2009, 08:54 AM
Download and run ESET SysInspector
http://www.eset.com/download/sysinspector.php

When the utility has collected the information, click File > Save Log
Confirm your wish. A log file, placed in a zip archive, will be created.

Send that archived file to ESET Technical Support ( support@eset.com ).
Then, they'll guide you to a way to eliminate the threat.

Cyberslider
January 30th, 2009, 10:51 AM
Thanks Fixer.

Should I indicate something aside from the file?! What sort of info should I provide to ESET besides this file, in order for them to understand what is the problem?!

Marcos
January 30th, 2009, 12:51 PM
If you're not using Windows 95/98/ME, I'd suggest installing EAV v3 that has better detection than v2 or install v4 beta which has cleaning of threats improved compared to older versions.

Cyberslider
January 30th, 2009, 03:56 PM
Nop. Actually I'm using XP SP2. Do you really think that V3 will do better for me?!

Fixer
January 30th, 2009, 05:41 PM
To your e-mail, add log file from ESET SysInspector, explain your problem and finally give a link to this topic.

Think Smart - Use protection from a new generation version 3 :)

Cyberslider
January 31st, 2009, 12:02 PM
Thanks Fixer I did that. Also I noticed something very "interesting". This attack happens exactlly every 2 hours. I checked the threat log and this happens periodically.

I sent the email to support as you suggested. Maybe some antimalware or some specific trojan remover can do the job?! As NOD32 and trojan remover fin nothing... And this attack seems to be from the web - so it seems like a trojan?!

Fixer
January 31st, 2009, 12:50 PM
-{ Quote: "Thanks Fixer I did that. Also I noticed something very "interesting". This attack happens exactlly every 2 hours. I checked the threat log and this happens periodically.

I sent the email to support as you suggested. Maybe some antimalware or some specific trojan remover can do the job?! As NOD32 and trojan remover fin nothing... And this attack seems to be from the web - so it seems like a trojan?!" }-

I think this is a Trojan Downloader. He is trying to download threats of a special address, but fortunately ESET NOD32 Antivirus detects the threat posed by Trojan Downloader is trying to download and not allow your system to be further infected. :)

Cyberslider
January 31st, 2009, 01:32 PM
Yes, so it seems. Only the trojan remover sees nothing... Maybe I need something stronger?!

Fixer
January 31st, 2009, 01:36 PM
-{ Quote: "Yes, so it seems. Only the trojan remover sees nothing... Maybe I need something stronger?!" }-

Stronger? You have - ESET NOD32 Antivirus. As you see, he was able to protect you. I'd recommend you instead Trjoan Remover - MalwareBytes' Anti-Malware. For more information visit official website:
http://www.malwarebytes.org/mbam.php

Cyberslider
January 31st, 2009, 03:31 PM
:thumb: Thanks again Fixer...

Fixer
January 31st, 2009, 03:34 PM
-{ Quote: ":thumb: Thanks again Fixer..." }-

No problem. I hope as soon as possible to clean your computer from threats. ;)