Jump to content

Marcos

Administrators
  • Posts

    36,515
  • Joined

  • Last visited

  • Days Won

    1,453

Posts posted by Marcos

  1. By default ESET security products check for new version of modules in 1 hour interval plus we also employ streamed updates and LiveGrid check for maximum protection.

    If you mean program updates, currently you need to create and send a software install task on clients when you want to upgrade a security product to a newer version. However, we now have so-called micro program component updates ready which will allow for automatic update to the latest version if you configure program updates to be installed automatically.

  2. Ok, so this is most likely what happened:
    - the support agent received encrypted files from a customer
    - upon saving the encrypted files on a disk, Ransomware shield detected a suspicious behavior and triggered a detection which was not logged locally in the Detection log due to a bug but it was reported to EEI

    What I would suggest:
    - Excluding the ESET folder in which files from customers are saved to
    - Editing ACL and denying the permission to read & execute files in the folder to prevent the support agent from executing malicious files that might be saved there.

  3. 0b36728a48fbff17a45be400c628052e6dca95fc - NSIS/CoinMiner.T trojan
    NsCpuCNMiner32.exe - a variant of Win32/CoinMiner.DQ potentially unwanted application
    NsCpuCNMiner64.exe - a variant of Win64/CoinMiner.CZ potentially unwanted application

    The first one is a NSIS archive, the detection was added in April 2018. The other 2 executables (PUAs) are inside the NSIS archive, the detection was added in July 2017.

  4. 4 hours ago, Amr Elsisi said:

    When i close eset service from task manger (ekrn.exe) it opens again automatically but the application closes

    What OS do you use? Do you have self-defense enabled? Killing ekrn is not possible with SD on. Even if turned off for whatever reason (e.g. the user forgot to re-enable it after some tests), ekrn should be restarted automatically and keep your computer protected.

     

    image.png

  5. 1, ESET like any other application on Android is considerably limited by the design of the operating system and permissions granted by the system / user. I've searched bug reports and tickets from users related to S10 issues and there was basically just one related to fingerprint authentication. That said, I assume that EMS works alright on S10. In case of issues, customer care should be contacted and logs should be submitted from the application for perusal.

    2, Without further investigation and logs it's impossible to tell what happened. Users are expected to contact customer care if there's an issue and a resolution or explanation should be provided relatively quickly.

  6. Since this is an English forum, we kindly ask you to post in English. If you don't speak English well, you can use a machine translator.

    As for your question, the files were most likely encrypted by Filecoder.STOP. Decryption for this variant is not currently possible. Do you have a license for an ESET product? If so, which one and what version have you had installed?

     

  7. We are said to hear that you are moving away from state-of-the-art security products that ESET develops. We would highly appreciate if you could elaborate more on the reasons that made you make such decision.

    And to answer your question, simply uninstall ESET (e.g. from the ESMC console if you have it installed on many computers) and that's it.

×
×
  • Create New...