PDA

View Full Version : NOD32 and svchost.exe


TechieSooner
09-07-2008, 10:14 AM
http://farm4.static.flickr.com/3175/2836361620_96654e75d0.jpg

That's my issue. If I attempt to either clean or delete the thing, it brings up a dialog box saying it could not do so, probably because it's svchost.exe

What the heck to do with this? I'm going to submit ticket with Eset but that'll take them awhile.

xxEIEIOxx
09-07-2008, 05:05 PM
I would submit a ticket and not worry about it too much. I have had 3 false positives from them in the last week on known good programs. I would dump them, but I'm at a loss to find something I like better. Your's is probably a false positive as well, unless you know for a fact that it isn't.

swatbat
09-07-2008, 05:49 PM
I would submit a ticket and not worry about it too much. I have had 3 false positives from them in the last week on known good programs. I would dump them, but I'm at a loss to find something I like better. Your's is probably a false positive as well, unless you know for a fact that it isn't.

False positives are something every av program gets from time to time. Personally kaspersky is the only thing I know of that is around the level of eset and it can't find that antivirus 2008 shit that a bunch of people have been getting. To be fair most programs can't remove it but it still pisses me off.

swatbat
09-07-2008, 07:41 PM
I've pulled it off a bunch of systems as of late. Eset and spyware doctor both will kill it. Friend who works at a local computer shop said he was removing it multiple times a day.

TechieSooner
09-07-2008, 07:48 PM
I booted into safe mode and ran the Eset command-line utility scanner- no idea if it did anything but it hasn't popped back up yet.

Still submitted a ticket.

Checking the logs (most of them are blank- which is odd) the only thing for today flagged a darn MP3 file... Odd.

False positives are something every av program gets from time to time. Personally kaspersky is the only thing I know of that is around the level of eset and it can't find that antivirus 2008 shit that a bunch of people have been getting. To be fair most programs can't remove it but it still pisses me off.
It ain't that they get that Antivirus 2008- they pay for the darn thing. Some friends of mine (to be fair- they thought they were doing good) paid $120 or something for this software... Hated to break it to them it's crap- but eventually got it all off.

swatbat
09-07-2008, 09:02 PM
Kaspersky causes my internet connection to drop. Have to reboot. Repeatedly. Too bad I have a 3 user license with 11 months left. :rolleyes:

My gripe with false positives on NOD32 is that it has a tendency to just quarantine the files regardless of the fact that I want it to exclude them. Then I have to go into quarantine and move them back. It just starts giving popups and deleting things. :mad:

I have the business version on a few hundred machines and haven't seen that problem. Have the home version on 20 or 30 machines and haven't heard of it either. Start killing some of the web av parts of it and see what happens.

xxEIEIOxx
09-07-2008, 09:03 PM
False positives are something every av program gets from time to time. Personally kaspersky is the only thing I know of that is around the level of eset and it can't find that antivirus 2008 shit that a bunch of people have been getting. To be fair most programs can't remove it but it still pisses me off.

Kaspersky causes my internet connection to drop. Have to reboot. Repeatedly. Too bad I have a 3 user license with 11 months left. :rolleyes:

My gripe with false positives on NOD32 is that it has a tendency to just quarantine the files regardless of the fact that I want it to exclude them. Then I have to go into quarantine and move them back. It just starts giving popups and deleting things. :mad:

Cyrilix
09-07-2008, 09:49 PM
I have the business version on a few hundred machines and haven't seen that problem. Have the home version on 20 or 30 machines and haven't heard of it either. Start killing some of the web av parts of it and see what happens.

Did you just quote someone from the future? :D

Uberbob102000
09-07-2008, 10:03 PM
The forum has been doing that today, I saw someone reply to someone from the future earlier.

Still cool.

swatbat
09-07-2008, 10:36 PM
Did you just quote someone from the future? :D

What can I say? I'm just that damn good. :D

Yea they have been having issues with that today.

xxEIEIOxx
09-08-2008, 08:06 AM
I have the business version on a few hundred machines and haven't seen that problem. Have the home version on 20 or 30 machines and haven't heard of it either. Start killing some of the web av parts of it and see what happens.

If we're talking about Kaspersky, I think it's their NDIS filter. It is problematic for some, not all. I also noticed the network comes into play. If I take my laptop to work, it doesn't give many problems. At home it drops a lot more. I have seen similar complaints that people on FIOS have been having problems.

My problems with NOD32 have been mostly Steam games, and Driver Cleaner.Net. But I have seen that they are having a lot of Steam problems lately.

Congratulations on your psychic abilities. ;)

EVIL-SCOTSMAN
09-08-2008, 08:42 AM
I got the same shit as the OP from eset yesterday, such n such a trojan was detected during an attempt to open said file ( which I may add differs from the OP's ) by the application C:\Windows\System32\svchost.exe

But I was able to delete the piece of shit, but the thing is, I had scanned my rig just a couple of days ago due to not having a scan for ages, although realtime is always running, so I thought on thursday/friday i think it was that I would do a deep scan on all drives. Nothing was found after a few hours of scanning, roll forward to sunday, I turn pc on, nod updates, I then go downstairs to play metal gear on the pee ess free and 4 maybe 5 hours later I come back to the pc to find virus warning.

I think it was a false positive as that app had been scanned loads of times in the past as it has been on said drive for a good1-2 years and nod and avast never picked up anything before until the update to nod on sunday.

Whatever it was has now been pwnd due to deleting the whole app, but I will go fetch another copy of it when i can be arsed.

YeOldeStonecat
09-08-2008, 08:58 AM
Scan in safe mode
Use Esets SysInspector utility to look into more details....it's a very useful tool they have...much like HijackThis and Autoruns combined on super steroids.

TechieSooner
09-08-2008, 02:23 PM
Well, Eset wasn't too bright.
Their solution was to ensure I had the latest program version, and then run an in-depth scan :rolleyes:

Still nothing has come up since that warning I got when I posted it- probably a false positive.

xxEIEIOxx
09-08-2008, 02:35 PM
I pretty much guarantee it is a false positive. That's the reason I mentioned having had some some recently. They seem to come in groups with NOD32. I had the firewall (Eset Smart Security) block the same file originally mentioned (svchost) earlier today. Took a while to find the rule it created. Couldn't connect to the DHCP server. I go months with no false positives, then get several. I hope they get these sorted out soon.