HELP: Repeated warnings from Nod32 about Kryptik

Discussion in 'Malware Help (A Specialist Will Reply)' started by HotDay, Mar 10, 2010.

  1. HotDay

    HotDay Private E-2

    Hi
    I keep getting emails with a message from NOD32 Antivirus saying it has deleted the Kryptik trojan. (See text from emails below.)

    My question is what do I need to do now? Have I got the Kryptik trojan? Or has Nod32 caught it?

    Thanks in advance.

    ===============
    MY SYSTEM
    *Windows Vista 32 bit
    *MS Office Outlook 2007 SP2
    *ESET NOD32 4.0.424

    ===============
    STEPS I HAVE DONE:
    1) Basically I followed your "READ & RUN ME FIRST. Malware Removal Guide" upto but excluding "Vista Cleaning Procedure"

    In particular I have
    2) Run Nod32 --- came up clean
    3) Run CCleaner
    4) Gone thru Uninstall Malware via Add/Remove Programs as carefully as I can --- none found.

    ===============
    COPIES OF THREE EMAILS:

    "Dear customer!

    We were not able to deliver postal package you have sent on the 21st of December in time because the addressee's address is erroneous.
    Please print out the invoice copy attached and collect the package at our office.

    United Parcel Service of America.

    __________ ESET NOD32 Antivirus warning, version of virus signature database 4910 (20100302)
    ______

    Warning, ESET NOD32 Antivirus found the following threats in the message:

    UPS_invoice_463.zip - a variant of Win32/Kryptik.CSX trojan - deleted
    UPS_invoice_463.zip > ZIP > UPS_invoice_463.exe - a variant of Win32/Kryptik.CSX trojan - was a part of the deleted object

    http://www.eset.com"

    ===============
    Three weeks ago I received a similar email saying:


    "Dear user of facebook,
    Because of the measures taken to provide safety to our clients, your password has been changed.
    You can find your new password in attached document.
    Thanks,
    Your Facebook.

    __________ ESET NOD32 Antivirus warning, version of virus signature database 4872 (20100216)

    __________

    Warning, ESET NOD32 Antivirus found the following threats in the message:

    Facebook_password _3444.zip - a variant of Win32/Kryptik.CKN trojan - deleted
    Facebook_password _3444.zip > ZIP > Facebook_password _3444.exe - a variant of

    Win32/Kryptik.CKN trojan - was a part of the deleted object

    http://www.eset.com"

    ==============
    Prvious to that I recieved an email saying
    Dear customer!

    The courier service was not able to deliver your parcel at your address.

    Cause: Mistake in address

    You may pickup the parcel at our post office personally.

    The delivery advice is attached to this e-mail.
    Print this label to get this package at our post office.

    Please do not reply to this e-mail, it is an unmonitored mailbox!

    Thank you,
    DHL Global Forwarding Services.


    __________ ESET NOD32 Antivirus warning, version of virus signature database 4815 (20100128)

    __________

    Warning, ESET NOD32 Antivirus found the following threats in the message:

    DHL_label_NR78913.zip - Win32/Oficla.CX trojan - deleted
    DHL_label_NR78913.zip > ZIP > DHL_label_NR78913.exe - Win32/Oficla.CX trojan - was a

    part of the deleted object

    http://www.eset.com
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    It does not do any good to stop there. You need to run the actual cleaning procedure and then attach the logs we request. Without them, there is nothing we can do for you.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds