Jump to content

A variant of Trojan WIN32/GenKryptik.BSJG


Recommended Posts

Hi guys,

My customer is using ESET File Security on Window Server 2008 R2, with Real-time file system protection feature, it can be found and Cleaned by deleting this variant

1.JPG.523bbfb2a1f9af67dd0650b9fd38960e.JPG

2.JPG.a1103cbe2149ae16734018b40c36fe94.JPG

, but after cleaned, the process "explorer.exe" will be killed also, so nothing on desktop! Then must to click File -> New Task "explorer" for show up!

3.JPG.01cbb9c5822cb4d5c08d301abaeea657.JPG

4.JPG.ab0ca73394cd2fdd2251a15cbc697b50.JPG

This situation is still occurring many times, so please help us how to permanently remove the type of variant without killed the process "explorer"?

Thanks in advance!

 

Link to comment
Share on other sites

1 hour ago, Marcos said:

Please provide:
- ELC logs
- A Procmon boot log created as per the instructions at https://support.eset.com/kb6308/

Upload both archives to a safe location and drop me a message with download links and a link to this topic.

@Marcos

Please help me with logs details as link below

hxxp://fsend.vn/download/AbXuimyHyUMT0W3exh2ajV1-Lwf-jEUS 

Link to comment
Share on other sites

  • Administrators

Unfortunately, the Procmon log was not from a boot. Please refer to the section "Gather boot log files" in the above mentioned KB article. Before you start logging, enable also advanced output in the Filter menu.

Link to comment
Share on other sites

15 hours ago, Marcos said:

Unfortunately, the Procmon log was not from a boot. Please refer to the section "Gather boot log files" in the above mentioned KB article. Before you start logging, enable also advanced output in the Filter menu.

Hi @Marcos

This is new "Gather boot log files" i have just collected, please help us: hxxp://fsend.vn/download/Kjv5tb08BQTLaPawYzKIOZ-xfv1Aelfq

1.JPG.b8b163bfe7c1aad55a6799a3a9fa9b5a.JPG

Link to comment
Share on other sites

  • Administrators

The log is not from a boot.

After launching Procmon, select "Enable boot logging" in the Options menu and "Enable advanced output" in the Filter menu. Then reboot the computer, launch Procmon and save the log.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...