![]() |
|
#1
|
||||
|
||||
|
I am using 3.0.551.0 up-to-date.
I have scheduled to backup my outlook .pst file evernight to a network storage device. NOD keeps killing it stating this: 2/3/2008 11:05:49 PM Real-time file system protection file probably unknown NewHeur_PE virus unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\WINDOWS\system32\ntbackup.exe. This happens every single night. I have even gone in and added the .exe to the exclusions list. If I manually run it, it works just fine, but the scheduled task gets killed every night. Any ideas?
__________________
RememberMe .... PhoneMGR .... WatchYourIP Remote Data Backups .... SUPERAntispyware .... Diskeeper/Undelete |
|
#2
|
|||
|
|||
|
samples {at} eset {dot} sk
Report the false positive and send them the file. My computers has no such file C:\WINDOWS\system32\ntbackup.exe However , this feauture might not be installed here |
|
#3
|
|||
|
|||
|
c:\windows\system32\ntbackup.exe exists here.
NOD32 doesn't detect it as a virus. However i'm using 3.0.621.0 up-to-date....
__________________
ESET NOD32 Anti Virus 4.2.64.12 AMD 64 X2 4400+ Asus A8N-SLi Deluxe (Bios 1016) 3 Gb RAM Sony DVD-RAM AW-G170A Seagate ST3200820AS (200 Gb Main Drive) |
|
#4
|
||||
|
||||
|
please install letest build v621 and send this file to eset support
i have xpsp3 but not any warning
__________________
Malwarebytes Anti-Malware v1.70.0.1100 Eset Smart Security v6.0.308.0 SUPERAntiSpyware Professional v5.6 Window 7 Service Pack 1 x86 Eset Beta Tester |
|
#5
|
||||
|
||||
|
Updated to newest version and samplet sent. We'll see tomorrow morning if it still happens.
I knew to submit it, but I didn't know the newest build was out just yet. thanks for the heads-up ![]()
__________________
RememberMe .... PhoneMGR .... WatchYourIP Remote Data Backups .... SUPERAntispyware .... Diskeeper/Undelete |
|
#6
|
||||
|
||||
|
Quote:
For instance, I attempted to open a saved eicar file with notepad with the below results. Quote:
Here's one also where I performed a ntbackup on the eicar file.... Quote:
Excluding ntbackup or notepad is not the answer I would be looking for, it's what ever file was being accessed, either by notepad or ntbackup and in your case it's your nightly PST file. By chance is your quarantine now plus one PST file ? Also, is there possible malware in that PST file that Nod does not care for ? Bubba
__________________
Wilders - Terms of Service · Site FAQ · Searching the forum easier · The Art of Quoting in Posts |
|
#7
|
||||
|
||||
|
Good call Bubba. Didn't even think of that.
It is my business email so I dont get any viruses or malcious email. I never even get any spam (crosses fingers) lol. Quite possible it just doesn't like something in there though. I'll try to add it to the exclusion list as well and see what happens. Thanks ![]()
__________________
RememberMe .... PhoneMGR .... WatchYourIP Remote Data Backups .... SUPERAntispyware .... Diskeeper/Undelete |
|
#8
|
||||
|
||||
|
If you make sure your context menu settings are fairly tight, in particular Advanced heuristics. Then via Windows Explorer attempt to do a context menu scan against that PST file, what happens ?
__________________
Wilders - Terms of Service · Site FAQ · Searching the forum easier · The Art of Quoting in Posts |
|
#9
|
||||
|
||||
|
I essentially have the "Blackspear" settings. I did a context-menu scan of the single file and the entire folder and the only message I got at all was "Unable to open extend.dat", which isn't even a file I try to backup nightly.
As I mentioned above, if I manually use the XP Backup wizard to back up the file/folder 1 time, it works just fine. Its just when the scheduled task tries to activate is when it buggers up.
__________________
RememberMe .... PhoneMGR .... WatchYourIP Remote Data Backups .... SUPERAntispyware .... Diskeeper/Undelete |
|
#10
|
||||
|
||||
|
Quote:
Is this PST file password protected ? Will definetly watch this thread for further results but that's about the extent of my thoughts for now ![]()
__________________
Wilders - Terms of Service · Site FAQ · Searching the forum easier · The Art of Quoting in Posts |
|
#11
|
||||
|
||||
|
I tried scanning it just sitting there, I tried copying it to network server, I tried manually using the backup.exe and all of them returned 0 results.
The PST is not password protected. I can only reproduce this when it is done via the scheduler. This is why I came here to see if anybody else had run into this before, because I had not. I have exhausted everything I know to check as well and can't figure out why its being deleted upon backup. ![]() We'll just wait to see what happens.
__________________
RememberMe .... PhoneMGR .... WatchYourIP Remote Data Backups .... SUPERAntispyware .... Diskeeper/Undelete |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|