Jump to content

Marcos

Administrators
  • Posts

    36,312
  • Joined

  • Last visited

  • Days Won

    1,444

Posts posted by Marcos

  1. Please contact your local customer care so that the case is tracked properly. A complete memory dump will be needed as well as a registry dump and other logs gathered by ESET Log Collector. A customer care representative should be able to assist you with this and prepare the stuff for analysis by developers.

  2. Do you use VA or ERA is installed on Windows or Linux using either AiO installer or stand-alone installers? The error "Incorrect string value: '\xC5\x86\xC5\xA1' for column '_license_owner_name'" indicates that the db is likely using a latin1 encoding while ERA supports only UTF8 encoding. At any rate, please create a regular support ticket as well so that the case is properly tracked.

  3. 1, Kryptik is a generic detection.
    2, Until the suspicious files has been analyzed, it's too early to make any conclusions. It could be both FP or an undetected variant.
    3, There is no security solution that would protect you from 100% of malware.

    Please submit the file detected as Win64/Kryptik to samples[at]eset.com for analysis.

  4. 43 minutes ago, Sp Ebil said:

    Even though the rtf file is not detected, the payload is detected either as: u.b - Suspicious Object or u.b - Win32/GenKryptik.CDTU, depending on what version of the ESET product you use (v11.1 / EPv7 or older) and the time you scan it. In ~3 hours from now all versions will detect it as Win32/GenKryptik.CDTU and the rtf dropper will be detected as well.

     

     

×
×
  • Create New...