The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    SNDVOL32.exe, Can this be infected?

    Discussion in 'Windows OS and Software' started by iOsiris, Jun 18, 2007.

  1. iOsiris

    iOsiris Notebook Evangelist

    Reputations:
    40
    Messages:
    447
    Likes Received:
    0
    Trophy Points:
    30
    I know sndvol32.exe is the actual sound volume executable and its found in the \windows\system32\, but all of a sudden it is now repeatedly trying to open up ports / use other progs that have access to ports to access the net or so my firewall tells says. Is it possible that this file is infected or somehow replaced with a different version even though I haven't installed anything (that I am aware of) ?

    I've used avast to scan it but it doesn't find anything, but I guess you can never be sure..
     
  2. Kdawgca

    Kdawgca rotaredoM repudrepuS RBN

    Reputations:
    5,855
    Messages:
    8,609
    Likes Received:
    2
    Trophy Points:
    206
  3. ttupa

    ttupa Tech Elitist NBR Reviewer

    Reputations:
    136
    Messages:
    1,150
    Likes Received:
    0
    Trophy Points:
    55
    Yeah, I would definitely scan the computer using another program. That is NOT normal behavior for that component. In fact, I basically never see that exe in the process monitor.
     
  4. Pitabred

    Pitabred Linux geek con rat flail!

    Reputations:
    3,300
    Messages:
    7,115
    Likes Received:
    3
    Trophy Points:
    206
    Any executable can contain virus code. Try McAfee FreeScan and get the opinion of another AV program. It could be that you also just have a new virus that the companies haven't seen before. I believe that most AV companies have places you can submit suspicious files for them to test. There is absolutely no reason for that file to be opening ports on your machine... is there a chance there's another program somewhere else on your hard drive with the same name?
     
  5. iOsiris

    iOsiris Notebook Evangelist

    Reputations:
    40
    Messages:
    447
    Likes Received:
    0
    Trophy Points:
    30
    I just permanently blocked it, and it still seems to do it (though I killed the notifications). Apparently though, it is not infected, odd.