PDA

View Full Version : Threat:Probably a variant of Win32/Rootkit.Pdnuha.IR trojan


cellanjie
February 7th, 2009, 10:37 PM
After my computer boots and everything loads, 2 NOD32 message windows pop up with

File:
~ link to possible malware removed ~

Threat:
probably a variant of Win32/Rootkit.Podnuha.IR trojan

Upon clicking both quarantine and terminate, the window pops right back up again, ad infinitum.

I've gone through my hijackthis log and can't find anything amiss.

Any help would be much appreciated.

Thanks!

funkydude
February 8th, 2009, 03:44 PM
Try doing a full scan in safe mode. If that fails, download ESET SysInspector, create a log, and send it to samples("at")eset[dot]com with this threads URL in the subject and as much info as possible in the text.

cellanjie
February 8th, 2009, 08:41 PM
Thanks so much, will do.

cellanjie
February 8th, 2009, 11:27 PM
NOD32 didn't find anything. I decided to do a system restore and be done with it. The nag disappeared.

Thanks.