Jump to content

cutting_edgetech

ESET Insiders
  • Posts

    336
  • Joined

  • Last visited

  • Days Won

    3

Posts posted by cutting_edgetech

  1. On 12/13/2017 at 7:34 AM, Peter Randziak said:

    Hello @cutting_edgetech

    we are currently distributing Antivirus and antispyware module version 1533.2 ) which should address the issues with too aggressive detection of LiveGrid servers not accessible.

    Can you please update and check if the issue persists?

    Regards. P.R.

    Yes, I did this already, and the pre-release updates fixed the problem. Check this thread out.

     

  2. 15 hours ago, itman said:

    It appears to be HTTP using TCP based on the connection LG established when using the Tools -> Program reputation option.

    BTW - whenever I have had LG dropped connections in the past, I used the above Tools feature to reestablish the connection which stuck for the entire boot session.

    I have already tried using the tools -> Program reputation option, and it doesn't take long before I start getting the alert again that LG is unaccessible. The pre-release updates seems to have fixed the problem so I don't have to deal with it any longer.

  3. It has been over a day now since installing the pre-release updates, and I have not experienced the problem anymore. It seems the pre-release updates may have fixed the problem. The longest I had gone without experiencing the problem before this was maybe four hours. I went about 2-4 hours without experiencing the problem each time I updated Eset application to the latest build. After the problem began to occur though it happened about every 5-10 minutes.

    Wireshark is not compatible with my Wireless Internet Adapter firmeware. The Wireshark installation package thinks I have a prior version of WinPcap installed on my machine. What ever it is detecting as a prior version of WinPcap is part of my Wireless Internet Adapter firmware. I checked my system multiple times, and WinPcap is not installed. I have to uninstall the driver for my Wireless adapter in order to install Wireshark, but then I don't have internet. I don't remember if WinPcap driver is contained in the Wireshark installation package, or if it has to download it from the internet during the instllation. If it has to download it from the internet then I will not be able to install Wireshark since I will not have internet access if I have to uninstall my firmware for my wireless adapter. I will try installing Wireshark only if the problem begins to occur again.

    What protocol does liveGrid use? HTTPS, TCP, UDP, etc..? If it uses HTTP then I can use Fiddler instead of Wireshark to see if it captures enough data to help diagnose the problem. At the moment the problem no longer exist so hopefully the pre-release updates fixed the problem. It's been over a day now so it appears it has fixed the problem.

  4. 15 hours ago, Marcos said:

    Do you get this error only shortly after starting Windows or even later when the Internet communication appears to work just fine? Could you try switching to pre-release updates and see if the error occurs less often?

    No it happens the entire time the computer is on. It happens once about every 5 minutes. I can switch to pre-release updates if you think it will not cause BSOD's, or boot failures. Unfortunately this is the only machine I have at the moment. I'm doing Mysql work for a project right now. I keep fairly recent image backups to an external drive though. I will make an image backup right now, and enable pre- release updates. If I start having boot problems, or instability then it will not be an option. I will give it a try, and report back.

  5. Sorry, for the extremely late response to this thread, but I know longer experience this problem. I upgraded to version 11, and I now have to deal with the "LiveGrid is not Accessible" problem instead. This problem has been persistent since I upgraded to version 11 back in October. I will report this in a different thread, or with someone else's thread that is experiencing the same problem. I'm currently using Eset Internet Security version 11.0.154.0 on Window 10 x64 version 1703.

     

  6. I have had the same problem ever since upgrading to version 11 back in October. I just haven't had any time to report it until now because of school. School is out for the next month so I have plenty of time to report it now. I'm currently using Eset Internet Security Version 11.0.154.0 on Windows 10 x64 version 1709, and the problem continues to persist. I have log files, but don't know where to submit them to. I've submitted many logs for beta builds, but I don't know where to send logs for stable builds to.

    Eset Live Grid.jpg

    Eset Notification 2.jpg

  7. Well, I upgraded to Eset Internet Security 10.1.235.0 from 10.1.219.0 again, and the really slow startup is still a problem. Not as slow as previously mentioned above, but pretty close to the same. Windows stays at the login screen for an unusual amount of time, and after the desktop finally appears the tray icons take forever to load. It's like Eset is holding all the other tray icons up from loading also.

    I'm extremely busy with school so I have very little time to trouble shoot anything.To top it off I am having problems with Eset's Firewall blocking content silently as reported here.

    hxxps://forum.eset.com/topic/13550-eset-internet-security-1012350-firewall-bug/

     Maybe you could look into both problems at once. How do I proceed to collect logs (where do I download the latest log collector), and where do I send the logs to?

     

    Thank You,

    Mike

    Edited 10/25/17 @ 8:16

  8. Since upgrading to Eset Internet Security 10.1.235.0 I have been unable to download pdf files using Firefox from my College Website when the Firewall is in Automatic Mode. If I switch the Firewall to Interactive Mode the pdf files download almost immediately without even prompting me. I also just upgraded to Window 10 X64 Fall Creators Update build 1709. Maybe it was a combination of Eset upgrading, and Windows upgrading that has caused problems for Eset's firewall. My browsing speed has been a little slower than usual also.  How should we proceed in diagnosing this problem?

  9. Windows startup was extremely slow after updating Eset Internet Security to 10.1.235.0. It took about 3 times as long for my desktop, and applications to load at startup. The problem did not go away so I rolled my computer back to a system image I made with Shadow Protect 2 months ago. Fall Creators update was not installed at that time. After rolling my computer back I was upgraded to the Fall Creators update which I did not have installed before.

    I'm going to create another system image before updating Eset Internet Security in case I run into the same problem. It took my slow internet connection 7 hours to download, and install the creators update so i'm not about to go through that again. During that time Microsoft update agent used 100% of my bandwidth so I could not access the internet to do anything else for 7 hours. I guess you can see my frustration, or hesitance to just upgrade Eset again. That's why I wanted to look at the changelog to see if I needed to upgrade or not. I guess I will need to upgrade now that Windows 10 updated to Fall Creators Edition,  just 2 hours ago.

    I'm keeping my fingers crossed. If I run into the same problem with Windows 10 startup being extremely slow then we will have to figure out what is going on. I'm using Windows 10 X64 Professional. I also have AppGuard, and Malwarebytes Anti-exploit installed. I've been using them with Eset for years, and the problem did not occur until after updating Eset Internet Security to the latest build.

    Thank You for your prompt response!

    Mike

  10. As long as Eset firewall is running properly, you can turn off windows firewall.

    I wonder how it came to be that Windows Firewall is even on. I suspect there is a bug in Eset Smart Security for not turning it off. I think maybe Window Firewall became enabled when I disabled Eset Firewall from the tray icon, and then reenabled Eset Firewall from the tray icon. When I turned Eset Firewall back on again I assume Eset should have turned Windows Firewall back off.

  11. I really wish Eset forum would warn the user when they are no longer logged in. Eset Forum still gives the user the option to make a post even when not logged in. Why give the user the option to make a post if it's only going to deny the post. I just lost my very lengthy post when submitting the post. It said I did not have permission to make the post, and I lost the entire post. Eset is the only forum I have ever used that does this. Please take this option away since it denies the post regardless, and the user loses their post.

     

    Well, I don't have time to retype my post. I will make a very brief one. I just used a stop watch, and it takes egui.exe 58 seconds to load after the desktop has loaded. That can not be typical behavior. I would try a reinstall, but it will take a very long time to reconfigure my firewall settings and rules. There are issues with the firewall that I reported during the beta that never was fixed, and it makes it very time consuming to deal with the firewall.

     

    Yes, i'm aware that egui.exe is only the GUI. I just wanted to confirm that the service begins to do it's job before the GUI is running. You would be surprised to see what I have discovered when testing other software. Just recently I found some software that was not protecting the user when the service was running. The developers informed me several times it was, but I proved them wrong. It turned out there was a bug in their software they were not aware of.

  12. egui.exe is taking a long time to load after the desktop loads with ESS 9. I never had this problem until shortly after upgrading from ESS 8. The Eset tray icon, and splash screen does not appear until after all my other tray icons have loaded. This is about 25-30 seconds after the desktop has loaded. I used autoruns to see where egui.exe was in the order of startup, but I don't see it listed. What can I do to make egui.exe launch more promptly? ekrn.exe service seems to be running before the desktop loads. Is Eset scanning startup items, and executions before egui.exe is running? Malware uses techniques in the wild that causes the user's computer to reboot, and then executes the malware as soon as the desktop begins to load. Some samples are able to execute even sooner.

  13.  

    It would be nice to see Eset incorporate a Behavior Blocker into their products. If something slips through then the behavior blocker can help detect the malware when it executes. They could have the feature disabled by default if they are worried about it causing false positives when being tested by independent test organizations.

     

    hxxp://www.eset.com/int/about/technology/#advanced-memory-scanner

    "Advanced Memory Scanner complements Exploit Blocker, as it is also designed to strengthen protection against modern malware. In an effort to evade detection, malware writers extensively use file obfuscation and/or encryption. This causes problems with unpacking and can pose a challenge for common anti-malware techniques, such as emulation or heuristics. To tackle this problem, the Advanced Memory Scanner monitors the behavior of malicious processes and scans them once they decloaks in the memory. This allows for effective detection of even heavily obfuscated malware. Unlike Exploit Blocker, this is a post-execution method, which means that there is a risk that some malicious activity could have been performed already. However, it steps into the protection chain when everything else fails."

     

    I assume you had something like Emsisoft's Behavior Blocker in mind when you made this request. Just wanted to mention the purpose of AMS and what it does.

     

    hxxp://static3.esetstatic.com/fileadmin/Images/INT/Docs/Other/ESET-Technology-Overview.pdf

    Edit: This PDF literally explains the ins and outs of the software itself and what happens behind the scene on the back-end systems. Every customer/user that is interested in this kind of geek information (it is very informative) should take time and read through the whole PDF.

     

    Sorry for the late reply.  I have not been on the forum in a while. I didn't think I was going to get a reply to my post. Thank you for the .pdf manual. I will have to look more at AMS, but I don't think it is the same as something like Emsisoft's BB. Marcos said AMS only triggers a memory scan here. https://forum.eset.com/topic/5283-behavior-blocker/So the question is if it only triggers a memory scan then is it only looking for already blacklisted executables.

  14. Do you have any custom firewall rules created? In automatic mode, the firewall allows all outbound communication and blocks all non-initiated inbound communication which means that submissions from your computer should not be blocked. With v9 installed, you can run the firewall troubleshooting wizard to see a list of recently blocked communications and allow those that you don't want to have blocked.

    Where is the Firewall trouble shooting wizard? I just upgraded to ESS 9, and it has the same bug as version 8. I have to get this fixed. I can't get my work done for it.

  15. eeclnt.exe (belongs to Eset Smart Security) causes UAC to prompt me every time an application request internet access. It is causing application errors, and internet access failure for my applications even if I choose allow from the UAC prompt. I rarely used UAC in the past, and I just started using Eset Firewall this year so I was not aware of this problem until now. I tried making eeclnt.exe run as an administrator under compatibility mode, but that did not work. How do I keep Eset Firewall from triggering UAC every time an application request internet access? I'm using Eset Smart Security 8.0.319.0 on Windows 7X64 Ultimate, and i'm using the firewall in interactive mode.

×
×
  • Create New...