Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 6th, 2010, 07:13 PM
skrag skrag is offline
Infrequent Poster
 
Join Date: Jul 2010
Posts: 2
Default Post title modified

I have NOD32 Antivirus, 4.2.40.0, fully updated.

The assault started today - every time I connect to the internet, NOD32 blocks an attack every few seconds, coming up with this message:


-------------------------------------------------------------------

Object: ~Link removed~

Threat: a variant of Win32/Peerfrag.FU worm

Information: connection terminated - quarantined

-------------------------------------------------------------------


I did a full system scan using NOD32, it came up with nothing.

Has anyone here seen this before? Is there a way of stopping these attacks completely? I know I can stop the error messages from appearing, but these attacks seem to be slowing my internet speed to a crawl.

Any help would be appreciated.

Last edited by ronjor : July 6th, 2010 at 07:25 PM. Reason: Link to possible malware removed
  #2  
Old July 6th, 2010, 07:26 PM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,214
Default Re: Post title modified

See this KB article on how to submit files to ESET. http://kb.eset.com/esetkb/index?page=content&id=SOLN141 Don't post links to potential malware here.
  #3  
Old July 6th, 2010, 07:31 PM
vtol's Avatar
vtol vtol is offline
Frequent Poster
 
Join Date: Apr 2010
Location: just around the next corner
Posts: 774
Default Re: Post title modified

depends when it happens

on outbound your machine would be compromised and NOD should not only detect the malicious connection but also the culprit

on inbound the address your machine trying to connect to would perhaps be compromised with malicious code, that would be the same address again and again - any indication of that?

you may also try prevx, does not give real time protection in trial mode, but you can run a full scan see if it comes up with something. if you machine got infested already recommend to use the download link 'Download NowMalware infecting you now?
Download a randomized filename' from here http://info.prevx.com/downloadcsi.asp

Last edited by vtol : July 6th, 2010 at 07:41 PM.
  #4  
Old July 6th, 2010, 07:37 PM
vtol's Avatar
vtol vtol is offline
Frequent Poster
 
Join Date: Apr 2010
Location: just around the next corner
Posts: 774
Default Re: Post title modified

Quote:
Originally Posted by ronjor
See this KB article on how to submit files to ESET. http://kb.eset.com/esetkb/index?page=content&id=SOLN141 Don't post links to potential malware here.
it does not sound like that the culprit is known to the user, a bit difficult to submit something in that case
  #5  
Old July 6th, 2010, 07:50 PM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,214
Default Re: Post title modified

Eset has access to the information.
  #6  
Old July 6th, 2010, 10:36 PM
siljaline's Avatar
siljaline siljaline is offline
Security Expert
 
Join Date: Jun 2003
Location: Montréal, Canada
Posts: 4,142
Post Re: Post title modified

Details of the worm Here, The inherent risks of file sharing, What to do if you are infected
  #7  
Old July 6th, 2010, 10:50 PM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,214
Default Re: Post title modified

Good info Randy.
  #8  
Old July 6th, 2010, 10:59 PM
siljaline's Avatar
siljaline siljaline is offline
Security Expert
 
Join Date: Jun 2003
Location: Montréal, Canada
Posts: 4,142
Post Re: Post title modified

Thanks, Ron Always willing to help, where I can.
  #9  
Old July 7th, 2010, 06:25 AM
skrag skrag is offline
Infrequent Poster
 
Join Date: Jul 2010
Posts: 2
Default Re: Post title modified

Quote:
Originally Posted by siljaline
Details of the worm Here, The inherent risks of file sharing, What to do if you are infected

Ah, filesharing huh...

Anyway, thanks for the info. I fixed the problem by running Malwarebytes' Anti-Malware program.
  #10  
Old July 7th, 2010, 12:17 PM
siljaline's Avatar
siljaline siljaline is offline
Security Expert
 
Join Date: Jun 2003
Location: Montréal, Canada
Posts: 4,142
Post Re: Post title modified

To the best that I can determine, file sharing aka file sharing was, is the delivery method for this particular worm.

You should also consider the additional options for infected machines although MBAM has given you a green light.

Quote:
Originally Posted by skrag
Ah, filesharing huh...

Anyway, thanks for the info. I fixed the problem by running Malwarebytes' Anti-Malware program.
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:00 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums