PDA

View Full Version : Threat detected after reboot pc


xptovv
March 24th, 2007, 11:17 PM
Hi

nod32 shows me this redbox of threat detected after i reboot or put on my pc when my internet is on :o , if my internet is off i dont have this problem (at least til now i dont have this problem with internet off) .

http://img137.imageshack.us/img137/8025/faxiaothreatdetected1zy1.jpg

my inglish isn´t very good so i will try tell my problem by steps.

-i reboot my pc.
-i dont open any program and also dont open my internet browser.
-after my pc is on , i wait 1 minut +\ - and i see the threat detected box.
-with internet on i have this problem , with internet off i dont have this problem (at least till now i dont have).
-i have my pc clean with hijackthis
-i run ccleaner to clean all from internet.
-got this problem today , so i instaled today Spybot - Search & Destroy , after run it , dont have any entry there (just told me that i have security center icon off , i have put it off long time ago)
-i use firewall and router.

note:
before i closed nod32 Threat detected box , i saw that nod32 IMON scaned this link :
daoqq.eicp.net\test.txt

i didn´t use my net browser how this link is runing on my pc :o ???

next i opened that text file with my net browser and i saw that it have that link that we can see in my picture , the virus exe.

this is wierd , 1ºtime i see this .

anyone know anything about this , thanks for the help :)

im on xp sp2

divedog
March 24th, 2007, 11:52 PM
Do you have some program running related to FAXAIO? It would appear it is trying to update via the web and NODs HTTP scanner is picking it up as a threat.

kjempen
March 25th, 2007, 12:05 AM
Seems like you got an infection. There's more than 13 AV programs labelling this as malware or suspicious/possible malware. I suggest you do a HijackThis scan (http://www.hijackthis.eu/) and clean out the bad entries.

Blackspear
March 25th, 2007, 07:29 AM
Hi xptovv, welcome to Wilders.

Wilders no longer allows posting of HijackThis Logs as per this announcement, (http://www.wilderssecurity.com/showthread.php?t=42148) unless specifically requested by a member of staff.

Cheers ;D

divedog
March 25th, 2007, 10:51 AM
Try posting a log here.
http://forum.gladiator-antivirus.com/index.php?act=idx