Jump to content
An upgrade will take place on June 18, 2024 during the midday hours (UTC). The Forum will not be accessible for a short period of time. ×

Marcos

Administrators
  • Posts

    36,872
  • Joined

  • Last visited

  • Days Won

    1,464

Posts posted by Marcos

  1. Please move the following files to a new folder, then reboot the machine. Those are two tasks that trigger powershell to download a resource from blocked URLs:

    c:\windows\system32\tasks\Sync
    c:\windows\system32\tasks\Winnet

    Please submit the two files to samples[at]eset.com in an archive encrypted with the password "infected".

  2. If possible, uninstall ESET and install the latest version of Endpoint v7.1. In case of problems with uninstallation, use the Uninstall tool in safe mode as per https://support.eset.com/kb2289/.

    Should the problem persist, please carry on as follows:
    1, Configure Windows to generate complete memory dumps as per https://support.eset.com/kb380/.
    2, After a reboot, reproduce BSOD.
    3, Gather logs with ESET Log Collector (e.g. after removing ESET in safe mode).

    Provide us with both the dump (in a compressed form) and ELC logs. You can upload them to a safe location and drop me a private message with download links.

     

  3. Please contact the seller from whom you purchased your license. It could be that we have a different email address on files than the one you entered in the form. The seller should be able to assist you and provide you with your license email.

  4. 3 hours ago, zamar27 said:

    What's the difference btw OBJECTS and FILES in Real-time File System Protection? Why FILES are separated to Additional Threatsense Parameters? 😉

    When referring to objects, we mean basically files, but we prefer using this general term since objects may also mean archives, processes, WMI, UEFI, streams, etc., ie. anything that can be scanned. As for the settings referring to newly created or modified files, it really concerns files only. We could use the general term "objects" as well but "files" sounds more natural to users.

  5. Novice, please stop trolling and refrain from ranting. Stop blaming ESET without any proof that we failed to stop ransomware. Without forensic analysis it is impossible to make any conclusions! How do you know that the user had ESET password protected? What if it wasn't, an attacker remoted in via RDP because the OP didn't have RDP secured, paused protection and then ran the ransomware? We don't know yet what happened so we can't make any conclusions without a proof either.

    And if you expect 100% malware protection and missing a threat as a big big fail, then show us antivirus with 100% detection that doesn't miss a single threat and we'll prove otherwise.

  6. On 5/11/2019 at 2:01 AM, pcguy said:

    I have installed Firefox release version and NOD32 still is complaining apparently every hour or so that the cert cannot be installed on some unknown browser somewhere on this computer.

    Please carry on as follows:
    - disable SSL filtering
    - reboot the machine
    - without launching any application, re-enable SSL filtering.

    Should the problem persist, start logging with Procmon and disable / re-enable SSL filtering, then stop logging and provide the generated log in a compressed form.

  7. 10 minutes ago, Navara said:

    Description: Lower priority for maintenance tasks

    Detail: Several times a day while playing game (DarkSouls 1 on Steam if it matters) game gets very laggy and drops to 1 frame per few seconds. When I explore task explorer for what's going on, it's ekrn.exe fully utilizing cpu.

    Searching trough it's logs I find out it was regular database update. No defending my computer against ongoing attack, but just regular maintenance. Those should be run on lowest priority possible to not interfere with computer operation...

    Applications running in full screen mode activate gamer mode by default in which neither updates nor scans are run. Updates have nothing to do with the log maintenance task.

  8. A quote from https://en.wikipedia.org/wiki/Firefox_Send:

    All files are encrypted before being uploaded and decrypted on the client after downloading. The encryption key is never sent to the server.

    That means ESET scans only encrypted files, ie. it's impossible to detect anything there.

     

    From the technical documentation (https://github.com/mozilla/send/blob/master/docs/encryption.md :

    The secret key is appended to the share url as a #fragment and presented to the UI

    That means the key only leaves the machine when the user transmits it manually, so there's no reliable way for us to get to it.

×
×
  • Create New...