Cheetah 0 Posted May 22 Share Posted May 22 (edited) Hi All, Today when I booted up my PC, I got an alert from ESET about a website that was blocked : x2.c.lencr.org ( I apologize if I'm not allowed to show the URL of the website) . viewing the logs, I noticed that it is detected via svhost.exe application with the user AUTORITE NT\SERVICE RÉSEAU, this is not my username and I do not recognize it, I scanned the website via VirusTotal and it does have malware (https://www.virustotal.com/gui/domain/x2.c.lencr.org/detection) but what I don't understand is: why is my computer trying to connect to it? and who is that user? I'm currently scanning the PC just in case, if anyone has an idea about this please let me know. Thank you all and have a good day! Edited May 22 by Cheetah Link to comment Share on other sites More sharing options...
Administrators Solution Marcos 5,235 Posted May 22 Administrators Solution Share Posted May 22 Please refer to https://forum.eset.com/topic/41085-false-positive/. It was a false positive (despite actual malware detection on the domain). Link to comment Share on other sites More sharing options...
Cheetah 0 Posted May 22 Author Share Posted May 22 Hi Marcos, Thank you for the quick reply and the clarification! Link to comment Share on other sites More sharing options...
Recommended Posts