Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

TROJ_GEN.F47V0723 Is it a false positive?


  • Please log in to reply
5 replies to this topic

#1 Darktune

Darktune

    Very Purple


  • Members
  • 1,139 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Wales
  • Local time:10:20 PM

Posted 31 July 2013 - 05:44 PM

Hey guys.

 

I ran Rkill and didn't find any malicious services running but it did terminate 'ezSharedsvchost.exe' which to my understanding is an Easybits service. I did previously have pre-installed programs that were by Easybits these were kids games and such but I uninstalled them. I'm assuming the ezSharedsvchost.exe is a left over from the install. I decided to scan it with "Virustotal' and it came up at 1/46 AV's found it to be malicious. 

 

Here are the details of that;

 

TrendMicro-HouseCall TROJ_GEN.F47V0723
 

All of the other AV's found the ezSharedsvchost.exe to be safe. Is this a false positive? 

 

Thank you

 

Craig

 

EDIT;

 

Also the Easybits software that I removed was called 'Magic Desktop - by Easybits' just encase it's relevant. 


Edited by Darktune, 31 July 2013 - 06:16 PM.

It's very hard to imagine all the crazy things that things really are like. 

Electrons act like waves.. no they don't exactly, they act like particles.. no they don't exactly.

Words and ideas can change the world.


BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,530 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:04:20 PM

Posted 31 July 2013 - 07:24 PM

Yes at that rate it would be considered safe.
If it is in the path.... %WINDIR%\System32


In the start menu, type services.msc into the search bar and click on services.

Look for 'ezSharedsvchost.exe', if there disable it.


How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 Darktune

Darktune

    Very Purple

  • Topic Starter

  • Members
  • 1,139 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Wales
  • Local time:10:20 PM

Posted 31 July 2013 - 07:57 PM

The path is actually 

 

Windows\SysWOW64 but I've read on other websites that it's the correct place for ezSharedsvchost.exe

 

I have done what you just said and disabled it.

 

Thanks :D

 

Craig


It's very hard to imagine all the crazy things that things really are like. 

Electrons act like waves.. no they don't exactly, they act like particles.. no they don't exactly.

Words and ideas can change the world.


#4 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,530 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:04:20 PM

Posted 31 July 2013 - 08:03 PM

If all still runs well after a couple days or a week then you can delete it or just leave it.

You're welcome.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#5 Darktune

Darktune

    Very Purple

  • Topic Starter

  • Members
  • 1,139 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Wales
  • Local time:10:20 PM

Posted 01 August 2013 - 02:20 AM

Okay thank you Boopme,

 

Also thank you for the quick reply to my topic.

 

Craig


It's very hard to imagine all the crazy things that things really are like. 

Electrons act like waves.. no they don't exactly, they act like particles.. no they don't exactly.

Words and ideas can change the world.


#6 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,530 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:04:20 PM

Posted 01 August 2013 - 01:35 PM

My pleasure Craig!
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users