Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 14th, 2006, 11:34 PM
miller tim miller tim is offline
Infrequent Poster
 
Join Date: Aug 2006
Posts: 6
Default Is nod32krn.exe really a worm?

I was just checking the running processes for anything unusual and came across several sites saying that nod32krn.exe is really a worm. Here's one http://www.castlecops.com/s7845-nod32krn_exe.html

Other sites say that it is just a normal nod32 process. Which is it?
  #2  
Old August 14th, 2006, 11:42 PM
NOD32 user's Avatar
NOD32 user NOD32 user is offline
Very Frequent Poster
 
Join Date: Jan 2005
Location: Australia
Posts: 1,766
Lightbulb Re: Is nod32krn.exe really a worm?

Th
Quote:
Originally Posted by miller tim
I was just checking the running processes for anything unusual and came across several sites saying that nod32krn.exe is really a worm. Here's one http://www.castlecops.com/s7845-nod32krn_exe.html

Other sites say that it is just a normal nod32 process. Which is it?
What you have linked to is a reference for startup items.
Quote:
Originally Posted by CastleCops StartupList Deep Dive
!! THIS IS A STARTUP PROGRAM AND NOT A TASK MANAGER PROCESS ITEM !!
nod32krn.exe is the 'NOD32 Kernel Service' but it should not appear in your startup items since it is a system service set to start automatically.

Cheers
__________________
1. What is right is always The Truth.
2. Every Truth is supported in agreement by every Truth.
3. If the facts would persuade you otherwise, see 1.

ESET Reseller (Australia)
  #3  
Old August 14th, 2006, 11:44 PM
miller tim miller tim is offline
Infrequent Poster
 
Join Date: Aug 2006
Posts: 6
Default Re: Is nod32krn.exe really a worm?

So it should NOT be listed in task manager?
  #4  
Old August 14th, 2006, 11:44 PM
Brian N's Avatar
Brian N Brian N is offline
Very Frequent Poster
 
Join Date: Jul 2005
Location: Denmark
Posts: 2,150
Default Re: Is nod32krn.exe really a worm?

If you find nod32krn.exe in the Windows\system32 folder it probably is a worm.
If not, then I'm quite sure it's legit since it's part of NOD32

Quote:
Originally Posted by miller tim
So it should NOT be listed in task manager?
^ Only the "real" nod32krn process should be in the task manager...
__________________
AntiVir PremiumFD-ISR ProFirefox 3Jetico 2 Firewall
ASAP Member
  #5  
Old August 14th, 2006, 11:47 PM
miller tim miller tim is offline
Infrequent Poster
 
Join Date: Aug 2006
Posts: 6
Default Re: Is nod32krn.exe really a worm?

I just searched my computer and the only instance of the file is in C:\Program Files\ESET

But it is listed in task manager as a running process.
  #6  
Old August 14th, 2006, 11:48 PM
Brian N's Avatar
Brian N Brian N is offline
Very Frequent Poster
 
Join Date: Jul 2005
Location: Denmark
Posts: 2,150
Default Re: Is nod32krn.exe really a worm?

Quote:
Originally Posted by miller tim
I just searched my computer and the only instance of the file is in C:\Program Files\ESET

But it is listed in task manager as a running process.
That's how it should be
__________________
AntiVir PremiumFD-ISR ProFirefox 3Jetico 2 Firewall
ASAP Member
  #7  
Old August 14th, 2006, 11:50 PM
miller tim miller tim is offline
Infrequent Poster
 
Join Date: Aug 2006
Posts: 6
Default Re: Is nod32krn.exe really a worm?

Is it that way on your computer? LOL, I'm paranoid.
  #8  
Old August 14th, 2006, 11:51 PM
Brian N's Avatar
Brian N Brian N is offline
Very Frequent Poster
 
Join Date: Jul 2005
Location: Denmark
Posts: 2,150
Default Re: Is nod32krn.exe really a worm?

It's been like that for over a year now hehe.
nod32krn.exe and nod32kui.exe
__________________
AntiVir PremiumFD-ISR ProFirefox 3Jetico 2 Firewall
ASAP Member
  #9  
Old August 14th, 2006, 11:53 PM
miller tim miller tim is offline
Infrequent Poster
 
Join Date: Aug 2006
Posts: 6
Default Re: Is nod32krn.exe really a worm?

OK. Whew!!! Thanks for clearing that up.
  #10  
Old August 14th, 2006, 11:53 PM
NOD32 user's Avatar
NOD32 user NOD32 user is offline
Very Frequent Poster
 
Join Date: Jan 2005
Location: Australia
Posts: 1,766
Lightbulb Re: Is nod32krn.exe really a worm?

Quote:
Originally Posted by Brian N
That's how it should be
Exactly

If you have any doubts whatsoever you can test your nod32krn.exe and nod32kui.exe at VirusTotal. Your results should look something like this and this.

Cheers
__________________
1. What is right is always The Truth.
2. Every Truth is supported in agreement by every Truth.
3. If the facts would persuade you otherwise, see 1.

ESET Reseller (Australia)
  #11  
Old August 14th, 2006, 11:56 PM
miller tim miller tim is offline
Infrequent Poster
 
Join Date: Aug 2006
Posts: 6
Default Re: Is nod32krn.exe really a worm?

I didn't scan it at VirusTotal but I did scan it at Jotti's. It came back clean.

Thanks again.
  #12  
Old August 14th, 2006, 11:59 PM
NOD32 user's Avatar
NOD32 user NOD32 user is offline
Very Frequent Poster
 
Join Date: Jan 2005
Location: Australia
Posts: 1,766
Default Re: Is nod32krn.exe really a worm?

Quote:
Originally Posted by miller tim
I didn't scan it at VirusTotal but I did scan it at Jotti's. It came back clean.

Thanks again.
No worries
__________________
1. What is right is always The Truth.
2. Every Truth is supported in agreement by every Truth.
3. If the facts would persuade you otherwise, see 1.

ESET Reseller (Australia)
  #13  
Old August 15th, 2006, 05:55 AM
mrtwolman mrtwolman is offline
Eset Moderator
 
Join Date: Dec 2002
Posts: 612
Default Re: Is nod32krn.exe really a worm?

It is a kind of social engeneering in action. Rbot.AAO copies itself to the Windows system32 folder as nod32krn.exe and creates entries in the registry to run itself on system startup. Just for case, check HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
for presence of "Nod32 Free antivirus" key.
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 07:05 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums