![]() |
|
#1
|
|||
|
|||
|
I was just checking the running processes for anything unusual and came across several sites saying that nod32krn.exe is really a worm. Here's one http://www.castlecops.com/s7845-nod32krn_exe.html
Other sites say that it is just a normal nod32 process. Which is it? |
|
#2
|
||||
|
||||
|
Th
Quote:
Quote:
Cheers ![]()
__________________
1. What is right is always The Truth. 2. Every Truth is supported in agreement by every Truth. 3. If the facts would persuade you otherwise, see 1. ESET Reseller (Australia) |
|
#3
|
|||
|
|||
|
So it should NOT be listed in task manager?
|
|
#4
|
||||
|
||||
|
If you find nod32krn.exe in the Windows\system32 folder it probably is a worm.
If not, then I'm quite sure it's legit since it's part of NOD32 ![]() Quote:
__________________
AntiVir Premium ▪ FD-ISR Pro ▪ Firefox 3 ▪ Jetico 2 Firewall ASAP Member |
|
#5
|
|||
|
|||
|
I just searched my computer and the only instance of the file is in C:\Program Files\ESET
But it is listed in task manager as a running process. |
|
#6
|
||||
|
||||
|
Quote:
![]()
__________________
AntiVir Premium ▪ FD-ISR Pro ▪ Firefox 3 ▪ Jetico 2 Firewall ASAP Member |
|
#7
|
|||
|
|||
|
Is it that way on your computer? LOL, I'm paranoid.
|
|
#8
|
||||
|
||||
|
It's been like that for over a year now hehe.
nod32krn.exe and nod32kui.exe
__________________
AntiVir Premium ▪ FD-ISR Pro ▪ Firefox 3 ▪ Jetico 2 Firewall ASAP Member |
|
#9
|
|||
|
|||
|
OK. Whew!!! Thanks for clearing that up.
|
|
#10
|
||||
|
||||
|
Quote:
![]() If you have any doubts whatsoever you can test your nod32krn.exe and nod32kui.exe at VirusTotal. Your results should look something like this and this. Cheers ![]()
__________________
1. What is right is always The Truth. 2. Every Truth is supported in agreement by every Truth. 3. If the facts would persuade you otherwise, see 1. ESET Reseller (Australia) |
|
#11
|
|||
|
|||
|
I didn't scan it at VirusTotal but I did scan it at Jotti's. It came back clean.
![]() Thanks again. |
|
#12
|
||||
|
||||
|
Quote:
![]()
__________________
1. What is right is always The Truth. 2. Every Truth is supported in agreement by every Truth. 3. If the facts would persuade you otherwise, see 1. ESET Reseller (Australia) |
|
#13
|
|||
|
|||
|
It is a kind of social engeneering in action. Rbot.AAO copies itself to the Windows system32 folder as nod32krn.exe and creates entries in the registry to run itself on system startup. Just for case, check HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
for presence of "Nod32 Free antivirus" key. |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|