Dmt Posted January 20, 2008 Share Posted January 20, 2008 if theres some valid server for nod32 3.0.621 please send to me. thanks so much Link to comment Share on other sites More sharing options...
shought Posted January 20, 2008 Share Posted January 20, 2008 What the... Has this become the NOD32 server request thread? LOL :) Link to comment Share on other sites More sharing options...
Guest bmnot1 Posted January 21, 2008 Share Posted January 21, 2008 The fix by Temdono makes me increasingly suspicious.I had a look with TCPview from sysinternals.My ekrn.exe opens many connections to various sites and ip addresses:www.weissgerbers.comwww.18edu.comimpactglobalmarketing.combasic-bongo.breakout.dreamhost.com213.144.186.210...As i'm typing here more and more addresses are coming!Furthermore there are tens of connections opening/closing in localhost(127.0.0.1).I have noticed also a strange activity for ekrn.exe and svchost.exe(TermService and DcomLaunch). Looking in Process Explorer they start to have 5-10% of CPU then begin repeated connections to various addresses and ip.It's very strange. If I pause ekrn.exe connections end and all its ok. Then on ekrn.exe resume... oleee!! Again tens of connections..Anyone noticed that? Link to comment Share on other sites More sharing options...
KotaXor Posted January 21, 2008 Share Posted January 21, 2008 What the... Has this become the NOD32 server request thread? LOL :)What to do? Try to please everyone! :) To all the above members, read your PM! Link to comment Share on other sites More sharing options...
Guest bmnot1 Posted January 21, 2008 Share Posted January 21, 2008 This is from Process Explorer: Link to comment Share on other sites More sharing options...
Peymon Posted January 21, 2008 Share Posted January 21, 2008 Hello,I dont seem to be able to update using the Temdono fix... can someone please PM me some update servers?Thank you-Peymon Link to comment Share on other sites More sharing options...
DaEnigma Posted January 21, 2008 Share Posted January 21, 2008 The fix by Temdono makes me increasingly suspicious.I had a look with TCPview from sysinternals.My ekrn.exe opens many connections to various sites and ip addresses:www.weissgerbers.comwww.18edu.comimpactglobalmarketing.combasic-bongo.breakout.dreamhost.com213.144.186.210...As i'm typing here more and more addresses are coming!Furthermore there are tens of connections opening/closing in localhost(127.0.0.1).I have noticed also a strange activity for ekrn.exe and svchost.exe(TermService and DcomLaunch). Looking in Process Explorer they start to have 5-10% of CPU then begin repeated connections to various addresses and ip.It's very strange. If I pause ekrn.exe connections end and all its ok. Then on ekrn.exe resume... oleee!! Again tens of connections..Anyone noticed that?I only see connections made to http addresses when I open a browser or another internet app, then I see the active internet monitor watching background connections from that app and scanning them. Seems normal to me, but I do not see any really odd addresses, but lots of advertising/tracking addresses. When was the last time you scanned for attached toolbars and or spyware? I mean it could be that the address you are hitting from your browser is just connecting to these addresses and the monitor is filtering them, but I only checked at nsane, yahoo mail, and google using Firefox. Link to comment Share on other sites More sharing options...
jhn195 Posted January 21, 2008 Share Posted January 21, 2008 Damn my NOD32 using TemDono fix is disabled for some reason. I can no longer update my signature, it gives me a "Undocumented serious error (0x101a)" Link to comment Share on other sites More sharing options...
Klockren Posted January 21, 2008 Share Posted January 21, 2008 Kotaxor and Jofre thanx for the pm :) Link to comment Share on other sites More sharing options...
eBait Posted January 21, 2008 Share Posted January 21, 2008 The fix by Temdono makes me increasingly suspicious.I had a look with TCPview from sysinternals.My ekrn.exe opens many connections to various sites and ip addresses:www.weissgerbers.comwww.18edu.comimpactglobalmarketing.combasic-bongo.breakout.dreamhost.com213.144.186.210...As i'm typing here more and more addresses are coming!Furthermore there are tens of connections opening/closing in localhost(127.0.0.1).I have noticed also a strange activity for ekrn.exe and svchost.exe(TermService and DcomLaunch). Looking in Process Explorer they start to have 5-10% of CPU then begin repeated connections to various addresses and ip.It's very strange. If I pause ekrn.exe connections end and all its ok. Then on ekrn.exe resume... oleee!! Again tens of connections..Anyone noticed that?I only see connections made to http addresses when I open a browser or another internet app, then I see the active internet monitor watching background connections from that app and scanning them. Seems normal to me, but I do not see any really odd addresses, but lots of advertising/tracking addresses. When was the last time you scanned for attached toolbars and or spyware? I mean it could be that the address you are hitting from your browser is just connecting to these addresses and the monitor is filtering them, but I only checked at nsane, yahoo mail, and google using Firefox.This might be some spyware or you visiting bad sites, bmnot. What Eset 3.x software does is that it tunnels *all* the data you down or upload through ekrn.exe. I think this is what's happening, you should try to install an VMware box with XP+Eset 3.x+TemDono, and you will see it's all fine. Link to comment Share on other sites More sharing options...
phiggs Posted January 21, 2008 Share Posted January 21, 2008 I've tried like 10 different servers now and none are working for me :)Can somebody tell me what update servers you guys are using or PM me it? Thanks. Link to comment Share on other sites More sharing options...
Guest bmnot1 Posted January 21, 2008 Share Posted January 21, 2008 I only see connections made to http addresses when I open a browser or another internet app, then I see the active internet monitor watching background connections from that app and scanning them. Seems normal to me, but I do not see any really odd addresses, but lots of advertising/tracking addresses. When was the last time you scanned for attached toolbars and or spyware? I mean it could be that the address you are hitting from your browser is just connecting to these addresses and the monitor is filtering them, but I only checked at nsane, yahoo mail, and google using Firefox.I did many checks for toolbars and/or spyware and malware. Not found anything. I think my system is clean. In my screenshots there is firefox.exe but things happens also if it is closed. It's the same. <_< This might be some spyware or you visiting bad sites, bmnot. What Eset 3.x software does is that it tunnels *all* the data you down or upload through ekrn.exe. I think this is what's happening, you should try to install an VMware box with XP+Eset 3.x+TemDono, and you will see it's all fine.As I said, I think my system is clean. Anyway thank you DaEnigma and eBait for your hints. I'll continue to check and try to resolve. ;) Link to comment Share on other sites More sharing options...
KotaXor Posted January 21, 2008 Share Posted January 21, 2008 I've tried like 10 different servers now and none are working for me <_<Can somebody tell me what update servers you guys are using or PM me it? Thanks.Hi phiggs and Peymon, Look at your PM.I have been updating just fine, mine was updated to 2810 automatically. I have been using the same list of servers for the past one week. Link to comment Share on other sites More sharing options...
KotaXor Posted January 21, 2008 Share Posted January 21, 2008 I only see connections made to http addresses when I open a browser or another internet app, then I see the active internet monitor watching background connections from that app and scanning them. Seems normal to me, but I do not see any really odd addresses, but lots of advertising/tracking addresses. When was the last time you scanned for attached toolbars and or spyware? I mean it could be that the address you are hitting from your browser is just connecting to these addresses and the monitor is filtering them, but I only checked at nsane, yahoo mail, and google using Firefox.I did many checks for toolbars and/or spyware and malware. Not found anything. I think my system is clean. In my screenshots there is firefox.exe but things happens also if it is closed. It's the same. <_< This might be some spyware or you visiting bad sites, bmnot. What Eset 3.x software does is that it tunnels *all* the data you down or upload through ekrn.exe. I think this is what's happening, you should try to install an VMware box with XP+Eset 3.x+TemDono, and you will see it's all fine.As I said, I think my system is clean. Anyway thank you DaEnigma and eBait for your hints. I'll continue to check and try to resolve. ;)I am using firefox too, and my firewall is Agitum outpost, when I close my browser, outpost show no outgoing or incoming data. While I am writing this, ekrn.exe is totally inactive, my firewall only show firefox.exe. Link to comment Share on other sites More sharing options...
maxima2k53 Posted January 21, 2008 Share Posted January 21, 2008 I only see connections made to http addresses when I open a browser or another internet app, then I see the active internet monitor watching background connections from that app and scanning them. Seems normal to me, but I do not see any really odd addresses, but lots of advertising/tracking addresses. When was the last time you scanned for attached toolbars and or spyware? I mean it could be that the address you are hitting from your browser is just connecting to these addresses and the monitor is filtering them, but I only checked at nsane, yahoo mail, and google using Firefox.I did many checks for toolbars and/or spyware and malware. Not found anything. I think my system is clean. In my screenshots there is firefox.exe but things happens also if it is closed. It's the same. <_< This might be some spyware or you visiting bad sites, bmnot. What Eset 3.x software does is that it tunnels *all* the data you down or upload through ekrn.exe. I think this is what's happening, you should try to install an VMware box with XP+Eset 3.x+TemDono, and you will see it's all fine.As I said, I think my system is clean. Anyway thank you DaEnigma and eBait for your hints. I'll continue to check and try to resolve. ;)y dont u try and download spybot search and destroy...for me thats the best antispyware program ever Link to comment Share on other sites More sharing options...
Guest bmnot1 Posted January 21, 2008 Share Posted January 21, 2008 Thank you for replies kotaxor and maxima! <_<I tried: AVG antispyware 7 --> nothingAdAware Pro 2007 --> nothingKaspersky 7 --> nothingHijackthis --> nothingBHODemon --> nothing;)I will try SystemScan (from SuspectFile.com) and then Spybot.. Link to comment Share on other sites More sharing options...
irefay Posted January 21, 2008 Share Posted January 21, 2008 If someone is looking for a way to use nod for a very LONG time:google4life!This is the search engine I have my nod subscribed to. (lol ?) Link to comment Share on other sites More sharing options...
bearoninternet Posted January 21, 2008 Share Posted January 21, 2008 As i mentioned before, as soon as the trialperiod has ended, i just uninstall, clean my reg with jv16 and ccleaner, and reinstall with a fresh new trial.This has worked out for me about 4 times so far... The Temdono fix does seem to work, but i dont trust it as i mentioned here.Also read Toyo's reaction.DaEnigma seems to be an early victim. <_< Link to comment Share on other sites More sharing options...
xicoescuro Posted January 21, 2008 Share Posted January 21, 2008 Hello everybody!After all that was written here about TemDono fix for Nod32 v3, I have (and I'm sure that I'm the lonely one) a simple but very important question:Can anyone (one of those who knows much better than I about all this stuff - programming, and so on...)tell me is this fix is safe or not?It just fixes AV and ESS versions or it opens something that it was not supposed to?Thanks in advance!All my best! Link to comment Share on other sites More sharing options...
Jman123 Posted January 21, 2008 Share Posted January 21, 2008 I have Outpost Firewall and NOD smart security, would it be better for me to use NOD or outpost? Link to comment Share on other sites More sharing options...
shought Posted January 21, 2008 Share Posted January 21, 2008 I have Outpost Firewall and NOD smart security, would it be better for me to use NOD or outpost?That's up to you but i sure wouldn't use both! Link to comment Share on other sites More sharing options...
Jman123 Posted January 21, 2008 Share Posted January 21, 2008 Yeah I know,lol I was just wondering since I don't really know how good the firewall in smart security is. Link to comment Share on other sites More sharing options...
maxima2k53 Posted January 21, 2008 Share Posted January 21, 2008 Yeah I know,lol I was just wondering since I don't really know how good the firewall in smart security is.the firewall is very good trust me Link to comment Share on other sites More sharing options...
shought Posted January 21, 2008 Share Posted January 21, 2008 Yeah I know,lol I was just wondering since I don't really know how good the firewall in smart security is.the firewall is very good trust meI've had no problems with it, it works just fine for me. But if you're behind a router(like me) you don't have to care at all, then even windows firewall will do the job... I guess that says enough. Link to comment Share on other sites More sharing options...
DaEnigma Posted January 21, 2008 Share Posted January 21, 2008 As i mentioned before, as soon as the trialperiod has ended, i just uninstall, clean my reg with jv16 and ccleaner, and reinstall with a fresh new trial.This has worked out for me about 4 times so far... The fix does seem to work, but i dont trust it as i mentioned here.Also read Toyo's reaction.DaEnigma seems to be an early victim. <_<I do not have any trouble... I just updated to 2811 using the Temdono fix, but I am also worried it may stop working at some point. Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.