Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 19th, 2008, 10:25 PM
m00t m00t is offline
Infrequent Poster
 
Join Date: May 2008
Posts: 3
Default nvsvc32.exe

Hi There,

A pc on my network has been sending traffic to an ip 89.39.110.250 from incrementing soure ports starting around 1212 and trying 3 times on each port to send to dest port 443. I ran an eset sysinspector log and it suggests that the file nvsvc32.exe is dangerous because it has no versioning information.

To add to this the computer it was on did not have a nvidia video card in it, it was a intel based notebook.

So i submitted the file to virustotal.com and 24/35 scanners suggest that it is a trojan.

My problem is that nod32 was running on this system and it did not pick the virus up. I have submitted it to eset via the nod shell intergrated submission tool, when do you think that this will be added to the defs.

Thanks

Will
  #2  
Old August 19th, 2008, 11:14 PM
The Hammer's Avatar
The Hammer The Hammer is offline
Massive Poster
 
Join Date: May 2005
Location: Toronto Canada
Posts: 5,089
Default Re: nvsvc32.exe

Quote:
Originally Posted by m00t
Hi There,

A pc on my network has been sending traffic to an ip 89.39.110.250 from incrementing soure ports starting around 1212 and trying 3 times on each port to send to dest port 443. I ran an eset sysinspector log and it suggests that the file nvsvc32.exe is dangerous because it has no versioning information.

To add to this the computer it was on did not have a nvidia video card in it, it was a intel based notebook.

So i submitted the file to virustotal.com and 24/35 scanners suggest that it is a trojan.

My problem is that nod32 was running on this system and it did not pick the virus up. I have submitted it to eset via the nod shell intergrated submission tool, when do you think that this will be added to the defs.

Thanks

Will
When will it be added is hard to say. Eset tends to prioritize the submissions they receive although they're probably not alone in doing that.
  #3  
Old August 20th, 2008, 01:43 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,185
Default Re: nvsvc32.exe

Quote:
Originally Posted by m00t
My problem is that nod32 was running on this system and it did not pick the virus up. I have submitted it to eset via the nod shell intergrated submission tool, when do you think that this will be added to the defs.

Please compress the suspicious files with WinRAR or another common packer, protect the archive with the password "infected" and send it to samples[at]eset.com with as much information about the files as possible (e.g. the url you downloaded it from before you ran it, a link to your post dealing with that threat at Wilders's, etc.). Also enclose a log from ESET SysInspector.
  #4  
Old August 20th, 2008, 04:11 AM
m00t m00t is offline
Infrequent Poster
 
Join Date: May 2008
Posts: 3
Default Re: nvsvc32.exe

Sorry Marcos,

I have done away with the little critter, not the kind of thing that i wanted hanging around.

I hope that you can find it in amongst the submissions from the nod32 shell intergration

Regards

Will
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:01 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums