Space_Munkey Posted May 6, 2025 Posted May 6, 2025 Good Morning All, Another week and another weird problem to solve! Our netsupport started being a bit flakey last week, a small numbers of devices weren't showing, then we were informed a whole room hasn't been showing for a week. I've looked at the installed files and running services and can see that Client32.exe is not running and no longer exists on the problem machines. I've read a legacy thread about MS Defender flagging and deleting it (due to nefarious use of netsupport software), however we use Trellix and have defender deactivated in our domain. Anybody able to help me brainstorm how this could have happened? - As far as I am aware, GPO's remain unchanged and trellix doesn't show any alerts... Cheers
MW_NetSupport Posted May 7, 2025 Posted May 7, 2025 @Space_Munkey, what you have described does sound like the Client32.exe has been removed / quarantined by Trellix, although it seems odd that there are no records of this happening. Have you got an exception setup for the NetSupport School folder within Trellix? If you haven't done so already, do reach out to our Support Team or DM me your details and I can arrange for someone to get in-touch to take a look at this for you. Matt 1
PotNoodleTech Posted May 7, 2025 Posted May 7, 2025 (edited) It does sound like antivirus to be honest, there must be something in a log somewhere! Can you add that folder to exclusions just in case? Edited May 7, 2025 by PotNoodleTech 1
NewFormz Posted May 7, 2025 Posted May 7, 2025 We've been having the same issue at our sites. We thought it might be related to Defender, so we have added an exception, but I know the problem is still ongoing. My team are working with Netsupport to resolve it. We have had to redeploy Netsupport to several machines to get them working again. 1
Matt_NetSupport Posted May 7, 2025 Posted May 7, 2025 @Dos_Box looks like @MW_NetSupport has responded but let me find out more.... (thanks for the tag) 1
mbl Posted May 7, 2025 Posted May 7, 2025 (edited) For me, the issue was that BitDefender removed it. I discovered this after deploying BitDefender in an IT suite where NetSupport was already installed. I just added a exclusion and this resolved the issue. Edited May 7, 2025 by mason2 1
Matt_NetSupport Posted May 7, 2025 Posted May 7, 2025 @Space_Munkey - it sounds like @MW_NetSupport and others have provided what seems to be the most likely resolution. Our support team are more than happy to assist you with resolving this (it does not look like you have raised this with them) Expect a message shortly. 1
NetSupportTechSupport Posted May 7, 2025 Posted May 7, 2025 Good Morning @Space_Munkey, It does appear that your AV is the root cause. If you can DM me your details (name, contact email), I will be happy to assist in resolving this with you. Alternatively, please feel free to reach out to [email protected] or join our chat system on www.netsupportsoftware.com/chat and we will be happy to assist. 1
colly72 Posted May 7, 2025 Posted May 7, 2025 We had a similar thing with Sophos. We ended up excluding it and all was good 1
Space_Munkey Posted May 7, 2025 Author Posted May 7, 2025 Crikey! Thanks for all the replies everyone. I've since redeployed it to the entire site and it seems to be working once again. I will look at adding an exception to our Trellix policies this afternoon - It's just so odd that it's suddenly happening as we've had it working without issue for years! I appreciate the netsupport boys for commenting and apologise for not giving you a shout in the first instance - we do pay for maintance / support, but I'm a try-to-fix-it-first type of person and only use it when I get really stuck 😛
Koldov Posted May 7, 2025 Posted May 7, 2025 I'm guessing this is because Trellix detected NetSupport hooking into some Windows processes? iirc Sophos & Malwarebytes have been responsible for a couple of our programs going sideways... they were also fine for a long time and then one day something in the definitions must have changed and BAM! Maybe worth getting in contact with Trellix so they can tell you where to look to be 100% certain, there must be some sort of log or alert. I also seem to remember one of the programs that had files deleted, the vendors spoke to Sophos as there can be times where false positive detections can be coded into (or rather out of) the definition files, rather than using exclusions/workarounds.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now