Caspian 0 Posted May 22 Share Posted May 22 Got three of these errors earlier on, a bit concerned as the NT Authrority/Network service is involved. I have absolutely no knowledge about malware and computers ect..., just want some clarification to ease my mind. Link to comment Share on other sites More sharing options...
Administrators Marcos 5,394 Posted May 22 Administrators Share Posted May 22 It was a false positive that was fixed around 10:25 PM CEST. For more informatio, please refer to https://forum.eset.com/topic/41085-false-positive. Link to comment Share on other sites More sharing options...
AlSky 4 Posted May 22 Share Posted May 22 I have exactly the same problem since this night. I hope someone of the staff may explain this because I'm concerned about it. Link to comment Share on other sites More sharing options...
Administrators Marcos 5,394 Posted May 22 Administrators Share Posted May 22 You don't need to be concerned. C.lencr.org domain is used by Let's Encrypt certification authority that provides certificate revocation lists. Link to comment Share on other sites More sharing options...
AlSky 4 Posted May 22 Share Posted May 22 6 minutes ago, Marcos said: You don't need to be concerned. C.lencr.org domain is used by Let's Encrypt certification authority that provides certificate revocation lists. Good evening. I have the same problem, but I didn't even open Firefox, I just started the computer, I opened Telegram desktop and... voilà! Two messages saying that process C :\Windows\System32\svchost.exe; and the user NT AUTHORITY\Network service were attempting to access hxxp://x2.c.lencr.org and had been blocked. I closed everything, restarted the computer, without opening any program a new warning that ESET had blocked the process C :\Windows\System32\svchost.exe; and user NT AUTHORITY\Network service attempt and the user from accessing http ://x2.c.lencr.org. I don't know whether to worry or not. Why is my computer trying to connect to that web site? Is infected by any malware? According to virustotal.com this web site is used to load StealC and Lumma Infostealers. Link to comment Share on other sites More sharing options...
Recommended Posts