Win32/Kryptik.CME - what to do ?

Discussion in 'ESET NOD32 Antivirus' started by mihai1988, Feb 19, 2010.

Thread Status:
Not open for further replies.
  1. mihai1988

    mihai1988 Registered Member

    Joined:
    Feb 19, 2010
    Posts:
    2
    For 2 days, y have this problems, at every 5 minnutes nod 32 allert me about this trojan
    Example:
    2/20/2010 12:54:55 AM Real-time file system protection file C:\Windows\TEMP\luwu.tmp\svchost.exe a variant of Win32/Kryptik.CME trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\Windows\System32\svchost.exe.

    2/20/2010 12:49:51 AM Real-time file system protection file C:\Windows\TEMP\fiaj.tmp\svchost.exe a variant of Win32/Kryptik.CME trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\Windows\System32\svchost.exe.

    2/20/2010 12:44:47 AM Real-time file system protection file C:\Windows\TEMP\fume.tmp\svchost.exe a variant of Win32/Kryptik.CME trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\Windows\System32\svchost.exe.

    It all start whit this thing
    2/18/2010 8:40:43 PM HTTP filter file http://[I]~Link removed~[/I]/install.exe Win32/Sirefef.P trojan connection terminated - quarantined NT AUTHORITY\SYSTEM Threat was detected upon access to web by the application: C:\Windows\System32\svchost.exe.

    o_O help ?
     
    Last edited by a moderator: Feb 19, 2010
  2. stackz

    stackz Registered Member

    Joined:
    Dec 27, 2007
    Posts:
    619
    Location:
    Sydney Australia
  3. mihai1988

    mihai1988 Registered Member

    Joined:
    Feb 19, 2010
    Posts:
    2
    thanks :thumb: :thumb: :thumb:
    Results:
    12:16:54:580 1972 Memory objects infected / cured / cured on reboot: 2 / 2 / 0
    12:16:54:580 1972 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
    12:16:54:580 1972 File objects infected / cured / cured on reboot: 1 / 0 / 1
     
  4. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,374
    TDSSKiller is an eqivalent to the ESET Olmarik cleaner. The new version we're going to release shortly should be able to remove all known Olmarik variants (ie. more than most of competitive tools).
     
Thread Status:
Not open for further replies.