Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET Smart Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old February 3rd, 2012, 12:38 PM
DrFix DrFix is offline
Infrequent Poster
 
Join Date: Nov 2009
Posts: 20
Default Strange NOD32 Behavior

Hi,
everyday NOD32 pops-up telling me it bocked a connection:

03/02/2012 18:25:57 HTTP filter file ~Link removed~ HTML/ScrInject.B.Gen virus connection terminated - quarantined NT AUTHORITY\NETWORK SERVICE Threat was detected upon access to web by the application: C:\Windows\SysWOW64\uniime32.exe.

Yes, thanks NOD, but I scanned the whole system and it doesn't find any HTML/ScrInject.B.Gen virus.... so I really don't know what to do.

It seems me to be the only one experiencing this sisutation... there's something opening a connection to a virus site but NOD doesn't help me finding WHHAT is opening the connection...

Last edited by ronjor : February 3rd, 2012 at 01:19 PM. Reason: Link to possibly harmful site removed
  #2  
Old February 3rd, 2012, 12:41 PM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,193
Default Re: Strange NOD32 Behavior

I'd suggest uploading C:\Windows\SysWOW64\uniime32.exe to VirusTotal as it could be malware. If it is, copy & paste here the MD5/SHA1 hash of the file.
  #3  
Old February 3rd, 2012, 12:57 PM
DrFix DrFix is offline
Infrequent Poster
 
Join Date: Nov 2009
Posts: 20
Default Re: Strange NOD32 Behavior

Yes it's malware!!! 7 / 43

Here is the sha
4f8f2f9a848d658e07fbb1fa965f2a3d446fcb430952417821cb5acd5c196bcd

What could I do now?
  #4  
Old February 3rd, 2012, 01:07 PM
future's Avatar
future future is offline
Infrequent Poster
 
Join Date: Aug 2009
Location: France
Posts: 25
Default Re: Strange NOD32 Behavior

It may be necessary to remove the link?
__________________
Sorry for my bad english...
  #5  
Old February 3rd, 2012, 01:30 PM
DrFix DrFix is offline
Infrequent Poster
 
Join Date: Nov 2009
Posts: 20
Default Re: Strange NOD32 Behavior

Ok, sorry...
I'll rename the file but I don't think thath would be enough to remove the trojan...
  #6  
Old February 3rd, 2012, 01:33 PM
future's Avatar
future future is offline
Infrequent Poster
 
Join Date: Aug 2009
Location: France
Posts: 25
Default Re: Strange NOD32 Behavior

Quote:
Originally Posted by DrFix
Ok, sorry...
I'll rename the file but I don't think thath would be enough to remove the trojan...

Thank you The reason is that some people can click on the link
__________________
Sorry for my bad english...
  #7  
Old February 5th, 2012, 05:13 PM
2570windsor 2570windsor is offline
Infrequent Poster
 
Join Date: Feb 2012
Location: United States
Posts: 2
Default Re: Strange NOD32 Behavior

So is ScrInject.b.gen a virus or not? According to microsoft.com Threat Encyclopedia it is an alias for the Trojan JS/BlacoleRef.A. Ever since I got hit with the ScrInject.B.gen (eset currently shows no infections) my machine has started acting crazy.
  #8  
Old February 6th, 2012, 12:14 AM
tipo's Avatar
tipo tipo is offline
Frequent Poster
 
Join Date: Dec 2008
Location: romania
Posts: 403
Default Re: Strange NOD32 Behavior

do a scan with malwarebytes and/or hitman pro and see what they find.
__________________
switching from one AV to another very often
Rollback RX
On demand: HitMan Pro
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET Smart Security « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 07:16 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums