Threat detected after reboot pc

Discussion in 'NOD32 version 2 Forum' started by xptovv, Mar 24, 2007.

Thread Status:
Not open for further replies.
  1. xptovv

    xptovv Registered Member

    Joined:
    Mar 24, 2007
    Posts:
    1
    Hi

    nod32 shows me this redbox of threat detected after i reboot or put on my pc when my internet is on :eek: , if my internet is off i dont have this problem (at least til now i dont have this problem with internet off) .

    http://img137.imageshack.us/img137/8025/faxiaothreatdetected1zy1.jpg

    my inglish isn´t very good so i will try tell my problem by steps.

    -i reboot my pc.
    -i dont open any program and also dont open my internet browser.
    -after my pc is on , i wait 1 minut +\ - and i see the threat detected box.
    -with internet on i have this problem , with internet off i dont have this problem (at least till now i dont have).
    -i have my pc clean with hijackthis
    -i run ccleaner to clean all from internet.
    -got this problem today , so i instaled today Spybot - Search & Destroy , after run it , dont have any entry there (just told me that i have security center icon off , i have put it off long time ago)
    -i use firewall and router.

    note:
    before i closed nod32 Threat detected box , i saw that nod32 IMON scaned this link :
    daoqq.eicp.net\test.txt

    i didn´t use my net browser how this link is runing on my pc :eek: o_O

    next i opened that text file with my net browser and i saw that it have that link that we can see in my picture , the virus exe.

    this is wierd , 1ºtime i see this .

    anyone know anything about this , thanks for the help :)

    im on xp sp2
     
    Last edited: Mar 24, 2007
  2. divedog

    divedog Registered Member

    Joined:
    Jun 7, 2004
    Posts:
    265
    Location:
    Seabeck WA
    Do you have some program running related to FAXAIO? It would appear it is trying to update via the web and NODs HTTP scanner is picking it up as a threat.
     
  3. kjempen

    kjempen Registered Member

    Joined:
    May 6, 2004
    Posts:
    379
    Seems like you got an infection. There's more than 13 AV programs labelling this as malware or suspicious/possible malware. I suggest you do a HijackThis scan and clean out the bad entries.
     
  4. Blackspear

    Blackspear Global Moderator

    Joined:
    Dec 2, 2002
    Posts:
    15,115
    Location:
    Gold Coast, Queensland, Australia
    Hi xptovv, welcome to Wilders.

    Wilders no longer allows posting of HijackThis Logs as per this announcement, unless specifically requested by a member of staff.

    Cheers :D
     
  5. divedog

    divedog Registered Member

    Joined:
    Jun 7, 2004
    Posts:
    265
    Location:
    Seabeck WA
Thread Status:
Not open for further replies.