Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus/Smart Security Beta
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 2nd, 2012, 09:21 PM
drose25 drose25 is offline
Infrequent Poster
 
Join Date: Jul 2012
Location: USA
Posts: 4
Default ESS locks, won't update, followed by Kryptik.AMQ infection

So I had something very unusual happen with Smart Security over the weekend. When I got to my PC yesterday afternoon, the ESS icon was still spinning like it was scanning the PC. I found this odd since the scan starts at 3am and it only has two SSDs to scan.

ESS opened normally, and showed the scanning screen normally, where it appeared to be stuck on a file (in a Windows Python distro for Blender, had been on PC long time already). Clicking the pause button, etc. failed to stop or restart the scan. I rebooted the PC and scanned the PC manually, nothing unusual was found.

This morning when I got to the PC, I got an alert saying ESS was not able to update its virus signatures. I tried clearing the cache, etc., but it continued to die when updating. I checked the box for the beta or pre-release signatures, and started the update again. It downloaded a lot of new stuff, but also failed to update successfully. The update would die around 7 or 8 of 10 steps, in what appeared to be a data unpacking and applying stage rather than a downloading stage.

At this point I uninstalled the ESS beta and installed ESS 5. It installed properly, updated without any trouble, and I ran a quick memory and boot sector scan with nothing found. I then set it for a full scan and went about working.

After a few minutes ESS starting popping up warnings about files in memory and the disk being infected with Kryptik.AMQ. One of the infected files was in the ESET program directory, and so was one of the files in memory. ESS was unable to delete the files or quarantine them. At this point I pulled the power and intended to boot from a rescue CD to check the system with an uncompromised source.

Unfortunately it did not boot from the CD as intended, and Windows booted to the login screen while I was out of the room. So, it's possible ESS deleted any infected files at boot. I rebooted with rescue CDs.

Running complete scans with both Avira and Kaspersky rescue CDs yielded no infections. Rebooting into Windows and scanning again with ESS 5 yields no infections.

I am concerned, however, because the ESS threat log does not show that all of the infected files were deleted. They no longer appear in the locations given, but I'm skeptical.

I've been unable to identify the vector by which the virus would have entered the system. All downloads are saved on a networked share and a scan of it yields nothing infected. The only thing I've downloaded or installed recently was a game patch for Tropico 4, and that was downloaded directly by the game. There is only one other Windows PC on the network, and it scans as clean. From Googling, it appears this Kryptik trojan is fairly old, so I'm surprised it would have been able to slip by ESS 6.

I know this information is very vague and probably not helpful, but I thought I would throw it out there in case anyone else experiences a similar problem. If so, maybe ESET can determine if there's an actual bug running loose.
  #2  
Old July 2nd, 2012, 10:12 PM
toxinon12345's Avatar
toxinon12345 toxinon12345 is offline
Very Frequent Poster
 
Join Date: Sep 2010
Location: Managua, Nicaragua
Posts: 1,134
Default Re: ESS locks, won't update, followed by Kryptik.AMQ infection

Check the On demand scans log, maybe the cleaning was performed after reboot.
__________________
Pentium M| 512 RAM
ESET NOD32 Antivirus 5
ESET Smart Security 6 RC
  #3  
Old July 2nd, 2012, 10:16 PM
toxinon12345's Avatar
toxinon12345 toxinon12345 is offline
Very Frequent Poster
 
Join Date: Sep 2010
Location: Managua, Nicaragua
Posts: 1,134
Default Re: ESS locks, won't update, followed by Kryptik.AMQ infection

How you noticed signs of active infiltrations?

Maybe you could paste the info from the "Detected threats" log here.
__________________
Pentium M| 512 RAM
ESET NOD32 Antivirus 5
ESET Smart Security 6 RC
  #4  
Old July 2nd, 2012, 11:04 PM
drose25 drose25 is offline
Infrequent Poster
 
Join Date: Jul 2012
Location: USA
Posts: 4
Default Re: ESS locks, won't update, followed by Kryptik.AMQ infection

This is from the Detected Threat Log:

7/2/2012 12:05:39 PM Startup scanner file Operating memory » C:\Windows\SysWOW64\msv1_0.DLL a variant of Win32/Kryptik.AMQ trojan error while deleting
7/2/2012 12:04:08 PM Startup scanner file Operating memory » C:\Program Files\ESET\ESET Smart Security\x86\ekrnSmon.dll a variant of Win32/Kryptik.AMQ trojan cleaned by deleting (after the next restart) - quarantined
7/2/2012 12:04:06 PM Startup scanner file C:\Windows\system32\msv1_0.dll a variant of Win32/Kryptik.AMQ trojan error while deleting

I don't see any thing called an On Demand Scan log.
  #5  
Old July 3rd, 2012, 05:20 PM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,193
Default Re: ESS locks, won't update, followed by Kryptik.AMQ infection

Please submit the 2 dlls to ESET as per the instructions here. Also enclose a link to this thread.
  #6  
Old July 3rd, 2012, 06:16 PM
drose25 drose25 is offline
Infrequent Poster
 
Join Date: Jul 2012
Location: USA
Posts: 4
Default Re: ESS locks, won't update, followed by Kryptik.AMQ infection

Thanks for reading this thread! I submitted the files from quarantine as requested.
  #7  
Old July 4th, 2012, 12:51 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,193
Default Re: ESS locks, won't update, followed by Kryptik.AMQ infection

Are you able to reproduce the detection at any time by running an on-demand memory scan? As for the update issue, if it persists enable debug logging, run a manual update and copy & paste here the appropriate records from the ESET Event log. Also try deleting the content of the system and user temporary folders.
  #8  
Old July 4th, 2012, 05:28 PM
drose25 drose25 is offline
Infrequent Poster
 
Join Date: Jul 2012
Location: USA
Posts: 4
Default Re: ESS locks, won't update, followed by Kryptik.AMQ infection

Unfortunately I cannot check -- I uninstalled the beta and re-installed v5 when the virus cropped up, so I can't try it out again now.
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus/Smart Security Beta « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:09 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums