Jump to content

Leonardo

Members
  • Posts

    97
  • Joined

  • Last visited

  • Days Won

    1

Posts posted by Leonardo

  1. 12 minutes ago, itman said:

    Eset will unblock a file after the "Maximum wait time for analysis result expires." The default value is 5 mins..

    As far as if there is a risk associated with this, theoretically the answer is yes. To exploit this however would require an attacker to perform system modifications prior to the executable/script being dropped. One example would be creating a scheduled task to run every 6 mins. or so that in turn, runs the executable/script.

    I had tweaked "30 minutes" for the maximum wait time, it is not possible to choose more time.

    I think it is really dangerous without any clear notification saying "safe" or "unsafe" the situation remains ambiguous ; the most secure for the basic user who does not be careful is to block the file till the result of LiveGuard analysis.

  2. 4 minutes ago, itman said:

    I had one that took 35 mins. .................

    Eset_LiveGuard.thumb.png.dd2999f1e180d846d5216466a8d4af32.png

    But you received an answer, not me after

     

    5 minutes ago, itman said:

    I had one that took 35 mins. .................

    Eset_LiveGuard.thumb.png.dd2999f1e180d846d5216466a8d4af32.png

    Thanks @itman

    But you received an aswwer (file safe); but I did not received any answer even after near 7 hours !

    And what do you think about the dangerosity of unblocking a file (it is ESET SSP that unblock the file !) before the end of the analysis?

  3. On 4/27/2022 at 5:14 PM, Marcos said:

    Do you have the latest version 15.1.12 installed? If not, try uninstalling the current version, download the installer from www.eset.com and install it. If you have the latest version. Try uninstalling and reinstalling it even if you have have the latest version and the issue persists after a reboot.

    Hello @Marcos

    Thanks for your solution👍

    I just uninstalled and reinstalled ESSP and now Banking Protection works fine.

  4. 1 hour ago, itman said:

    I am running Win 10 Pro x(64) 21H2 and FireFox 99.0.1 and having no issues with Eset B&PP. I also applied latest Win preview updates yesterday. Also my ESSP ver. is 15.1.12

    This issue might be related to Firefox ESR.

    Hello @itman

    No the issue isn't  related to Firefox 91.8.0esr because I tried at home on another PC with the same specs and the Banking Protection works fine.

    11.thumb.PNG.b0a6151062e654975640baa760975a56.PNG

  5. 17 minutes ago, Marcos said:

    Do you have the latest version 15.1.12 installed? If not, try uninstalling the current version, download the installer from www.eset.com and install it. If you have the latest version. Try uninstalling and reinstalling it even if you have have the latest version and the issue persists after a reboot.

    Thanks @Marcos

    Yes I have the latest version installed ; I'll try to uninstall and reinstall ESSP later because it takes too much time.

    3.PNG.8a003ada653a8a3b6ebf5f600418f742.PNG

  6. 6 hours ago, itman said:

    I'll save you some work.

    For those not familiar with this download test, it is to test Microsoft Defender "block-at-first-sight" of a file download with subsequent upload and analysis by the Microsoft cloud.

    Upon file download by Firefox, Eset LiveGuard detected it and submitted it to the Eset cloud:

    Time;Component;Event;User
    4/19/2022 9:12:55 AM;ESET Kernel;File 'Sj2-Kz7u.exe.part' was sent to ESET Virus Lab for analysis.;SYSTEM

    Time;Hash;File;Size;Category;Reason;Sent to;User
    4/19/2022 9:12:55 AM;09C513ABE0F1B48029E8EBE288EBE530DEE8E5FE;C:\Users\xxxxxx\Downloads\Sj2-Kz7u.exe.part;5716;Executable;Automatic;ESET LiveGuard;xxxxxxxxx

    Since this download was an executable, Eset blocked file access upon file creation until Eset cloud scanning was completed:

    WD_Test.thumb.png.cfb69c679badcf964d07633cd680bc09.png

    Blocked file access was further confirmed when I tried to access the file while Eset cloud analysis was underway:

    Time;Component;Event;User
    4/19/2022 9:16:14 AM;ESET Kernel;ESET LiveGuard is analyzing the file to ensure it's safe to use. We will notify you in a few minutes.Unblock the file (not recommended)Change setup;xxxxxxxxx

    Upon completion of Eset cloud scanning, a safe verdict was rendered by LiveGuard and access to the file was unlocked:

    Time;Component;Event;User
    4/19/2022 9:17:49 AM;ESET Kernel;ESET LiveGuard has analyzed a file. It is safe to use.;xxxxxxxxxx

    WD_Test-2.thumb.png.2f0f49cc2dea2767e7d294b7d394047d.png

    Pertaining to Eset log entries created in this transaction, all were Event log entries except for one Sent log entry.

    -EDIT- I forgot to mention that although 29 vendors at VirusTotal detect this file malicious, Kaspersky's detection is the most accurate, "Not-a-virus:HEUR:RiskTool.Win32.TestFile.gen."

    When the file is created by the Microsoft download site, it in turn creates a sig. for it only used by the MD cloud. In other words, this is a MD "block-at-first-sight" functionality test only. This is further confirmed by the file not being detected by Microsoft at VirusTotal.

    Thanks @itman for your help.

    But It is not normal that the event did not appear on "files sent" logs on my ESSP. Is my remark right ?

  7. 5 hours ago, itman said:

    Since I realize many are following this thread, I will post an update on LiveGuard script processing.

    After a long and arduous off-forum session with @Marcos, the following has been resolved. LiveGuard will not process suspicious scripts until actual execution of the script is performed. Again when a script is downloaded, LiveGuard will not be invoked.

    Additionally when the script is being processed by LiveGuard, script access is "locked" but this status will not be shown via Win Explorer Content Menu examination.

    @itman

    Thank you very much for your works and the explanations you give at other ESET users 👍

×
×
  • Create New...