Author Topic: win32:crypto - Any advice?  (Read 4873 times)

0 Members and 1 Guest are viewing this topic.

4u1e

  • Guest
win32:crypto - Any advice?
« on: April 18, 2004, 10:56:23 AM »
Picked up the following yesterday when running a scan:

Win32:Crypto
c:\WINDOWS\Temporary Internet Files\Content.IE5\EJ2FK3EZ\netsecure[1].jpg
Win32:Crypto
c:\WINDOWS\Temporary Internet Files\Content.IE5\4Z887Q8A\panel_r5_c8[1].jpg\panel_r5_c8[1]
Win32:Crypto
C:\WINDOWS\TEMP\trz21E4.TMP

They seem to be living inside some truly enormous (~1GB) files in my temp folder.

Tried to move them to virus chest, but the operation failed (Don't have the exact words, but something like: "An error occured during this action. Unable to transfer - this option is only available in win32"). Similarly couldn't repair either.

Now I could just delete all this stuff but I've already done this once and the problem has recurred so I'd rather try and get to the bottom of it.

If this is a virus it doesn't actually seem to be doing anything much (Although my hard drive is filling up with crud >:(). Housecall has shown the disk to be clean, for what it's worth. Anyhow, my questions are:

Does this ring a bell with anyone?
Could it be a false alert, if so, how do I tell?
If it is a virus would the Avast cleaner tool be any use (It doesn't list win32:crypto as something it can fix)?
Any other ideas for tracking it down and killing it?

System: Pentium, windows 95B
Avast: Build 4.1.342, virus definitions fully up to date

Cheers
« Last Edit: April 18, 2004, 11:11:16 AM by 4u1e »

Offline raman

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1062
Re:win32:crypto - Any advice?
« Reply #1 on: April 18, 2004, 12:01:31 PM »
Please delete everything, Windows allows, inside these folders:

c:\WINDOWS\Temporary Internet Files\Content.IE5\
C:\WINDOWS\TEMP\

Probably false alarm
« Last Edit: April 18, 2004, 12:02:11 PM by raman »
MfG Ralf

4u1e

  • Guest
Re:win32:crypto - Any advice?
« Reply #2 on: April 19, 2004, 08:42:20 AM »
It is OK to delete everything from these content.IE5 files/folders is it? I'm getting warnings about deleting a desktop.ini file, but I can't see why that should be a problem. (I do, however, require reassurance ;D)

How many places does IE stick stuff!

Cheers

« Last Edit: April 19, 2004, 08:47:13 AM by 4u1e »

Offline raman

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1062
Re:win32:crypto - Any advice?
« Reply #3 on: April 19, 2004, 09:53:51 AM »
If you feel  yourself more comfortable you can leave the desktop.ini, but you do not need to. Or follow the instructions in this link: http://www.shepherd.edu/compserv/prevent/internetch.htm
« Last Edit: April 19, 2004, 09:54:36 AM by raman »
MfG Ralf

4u1e

  • Guest
Re:win32:crypto - Any advice?
« Reply #4 on: April 19, 2004, 08:40:42 PM »
Ah - I hadn't twigged the link between content.ie5 and the internet explorer cache. Clearing all that out seems to have sorted it anyway.

Guess it was just a false alarm - thanks anyway Raman.