This morning my PC was attacked by a variant of the ‘Kryptik’ Trojan some how got through NOD32 initially but was picked up later. Too late damage done, the only way I could get into my machine was via a boot CD. It corrupted the boot.ini file (Xp Prof SP3) although on initial inspection it looked OK but it wasn’t until I built a new file was I able to get past the ‘Disk Error’ message I received on boot up and get in to finish cleaning the mess. A heart stopping couple of hours.
Note:
Look at your C:\Windows\system32 folder
Look for 3 files NLx.EXE
x = B, C, D,
Delete them or if unsure move them to another ‘Junk’ folder.
Then
Look at your C:\Windows\Prefetch folder
Look for 3 files starting with NLx.EXE they will look something like NLB.EXE-1E7655f5.pf
x = B, C, D,
Delete them or if unsure move them to another ‘Junk’ folder.
After they have done their damage they get moved to your ……\Local Settings\Temp\ folder as NLD.EXE. It was on the move NOD32 detected their presence.
KEEP A COPY OF YOUR ‘boot.ini’ file on a memory stick as there are many viruses out there that attack it.







