Jump to content

Marcos

Administrators
  • Posts

    36,194
  • Joined

  • Last visited

  • Days Won

    1,440

Posts posted by Marcos

  1. Things like this must be tracked. You can provide a list of things that don't work as expected and we will create tickets for developers if necessary. However, it would be better if LATAM support did it based on your support ticket in their system so that you could inquire about it at a later time by a reference to your ticket.

  2. We don't need ELC logs. You'd better create a dump of ekrn through the advanced setup -> tools -> diagnostics. However, whether real-time protection starts or not does not depend on the registry value but on the state that the OS reports. The registry value just tells what state it the system is in, however, we've seen that the actual state often differs from what is in the registry.

  3. Please move the following files to a new folder, then reboot the machine. Those are two tasks that trigger powershell to download a resource from blocked URLs:

    c:\windows\system32\tasks\Sync
    c:\windows\system32\tasks\Winnet

    Please submit the two files to samples[at]eset.com in an archive encrypted with the password "infected".

  4. If possible, uninstall ESET and install the latest version of Endpoint v7.1. In case of problems with uninstallation, use the Uninstall tool in safe mode as per https://support.eset.com/kb2289/.

    Should the problem persist, please carry on as follows:
    1, Configure Windows to generate complete memory dumps as per https://support.eset.com/kb380/.
    2, After a reboot, reproduce BSOD.
    3, Gather logs with ESET Log Collector (e.g. after removing ESET in safe mode).

    Provide us with both the dump (in a compressed form) and ELC logs. You can upload them to a safe location and drop me a private message with download links.

     

×
×
  • Create New...