NOD32 Alerts with no file info

Discussion in 'ESET NOD32 Antivirus' started by ttm2112, Sep 2, 2010.

Thread Status:
Not open for further replies.
  1. ttm2112

    ttm2112 Registered Member

    Joined:
    Sep 2, 2010
    Posts:
    2
    Started today, i am getting:

    09/02/2010 9:13:10 AM - Module Real-time file system protection - Threat Alert triggered on computer [PCNAME]: contains .

    on all connected NOD PC's. No file info or anything telling me the file was fixed or quarentine. Nothing in quarrentine. Any thoughts?

    Product Engine: 4.0.467
    Pattern: 5418

    UPDATE: EKRN.exe seems to be involved somehow.

    Thanks
     
    Last edited: Sep 2, 2010
  2. rcash

    rcash Registered Member

    Joined:
    Dec 5, 2007
    Posts:
    56
    I have the exact same thing on many of our computers.
     
  3. yadnom

    yadnom Registered Member

    Joined:
    Nov 16, 2009
    Posts:
    7
    We are having the same issue.

    Windows XP sp3 with 5418 update
     
  4. EmpereurZorg

    EmpereurZorg Registered Member

    Joined:
    Jan 12, 2010
    Posts:
    12
    Same here with 5418 definition, with a 2003 server DC crash (DFS & no response). Don't know if the crash is a consequence...
     
  5. stridert

    stridert Registered Member

    Joined:
    Jun 18, 2010
    Posts:
    5
    Also experiencing lockups on about 50 PCs with the 5418 update.

    4.0.437,424

    XP SP3

    02/09/2010 14:58:57 - Module Real-time file system protection - Threat Alert triggered on computer XYZ contains .
    02/09/2010 14:47:14 - Module Real-time file system protection - Threat Alert triggered on computer ABC contains is OK.
     
  6. rembert

    rembert Registered Member

    Joined:
    Oct 26, 2006
    Posts:
    8
    This seems to be related to the problems caused by update 5418. I also got these errors from some servers. I've stopped remote administrator servers to prevent the 5418 update to spread further over the network, causing more grief.
     
  7. EmpereurZorg

    EmpereurZorg Registered Member

    Joined:
    Jan 12, 2010
    Posts:
    12
    5419 is here !
     
  8. ttm2112

    ttm2112 Registered Member

    Joined:
    Sep 2, 2010
    Posts:
    2
    Latest from ESET...
    http://kb.eset.eu/esetkb/index?page=content&id=NEWS98

    ESET Virus Signature Database Update to version 5418 causing problems
    News ID: NEWS98|Last Revised: September 02, 2010 On Thursday, September 2nd, ESET released standard virus definition update 5418. Unfortunately, an error in the new engine module is causing problems with the following symptoms:

    - ekrn crashed
    - system stopped responding
    - administrators might receive threat notifications with blank threat name field

    The problem was discovered in update 5417 and manifested after an update to a newer version. To protect our users, we stopped the update as soon as the problems were reported to us.

    A newer update 5419 has just been released which fixes the problem. Note that ekrn may crash during update due to the problem present in the previous versions 5417/5418.

    SOLUTION FOR USERS:
    After the next computer restart, ekrn.exe will start and function properly.

    SOLUTION FOR SERVER SYSTEMS:
    Update to v. 5419 and run "net start ekrn" to start ekrn.exe after a crash.- failing of the ESET kernel module with error messages,
     
  9. 0verlord

    0verlord Registered Member

    Joined:
    Dec 18, 2008
    Posts:
    17
    Same issue over here!!!
     
  10. nologique

    nologique Registered Member

    Joined:
    Sep 2, 2010
    Posts:
    2
    Hi all

    We got hit hard... but now things are comming back to normal.

    How can one prevent somethings like this to happen?

    It doesn't happen often, but in our case we have 300 servers (mostly 2003) and 3000 (mostly xp) users so when we got hit, we got hit hard, thanks to the eset management console we were able to push the new definition in less 30-45 minutes and we were up.

    I think Eset should be able to send an alert of some sort, to advice their business clientele before....

    Any thoughts...

    Thanks

    Nologique
     
  11. Rmuffler

    Rmuffler Former Eset Moderator

    Joined:
    Jun 26, 2008
    Posts:
    995
    Location:
    San Diego, CA USA
Thread Status:
Not open for further replies.