Jump to content

Peter Randziak

ESET Moderators
  • Posts

    3,511
  • Joined

  • Last visited

  • Days Won

    207

Posts posted by Peter Randziak

  1. Hello,

     

    @Maxx2777 in case you have Endpoint 5 version lower than 5.0.2254 please upgrade it so you won't suffer from the first mentioned issue with updating i.e. premature x64 .nup update file deletion.

     

    Those, who have only 5.0.2254+ deployments, are you able to estimate how much time after a system restart does it approximately takes until the issue starts to manifest again?

     

    Regards, P.R.

  2. Hello Slarkins.

     

    there are 2 issues described:

    1. premature x64 module update files deletion (fixed in 5.0.2254.0+)

    2. issue is related to memory allocation (can be fixed by rebooting the operating system, a permanent fix will also be provided by means of an Internet protection module update (version 1256) soon.)

     

    So in case you have an Endpoint of v. 5.0.2254.0 it should be the second issue.

     

    Hopefully this clarifies it a bit, P.R.

  3. Hello,

     

    in case you are not able to upgrade to the new version (it notifies you, but nothings happen after clicking on the upgrade button) please

     

    1. take Procdump from ekrn right after the issue manifests (download Procdump tool from https://technet.microsoft.com/en-us/sysinternals/dd996900.aspxrun cmd as an administrator and run procdump -ma ekrn)

    2. collect logs by means of ESET log collector as described here: hxxp://support.eset.sk/kb3466/?viewlocale=en_US

     

    Pack these two logs, upload them to a safe location and send me a download link with reference to this forum topic, we will check it.

     

    Thank you, P.R.

  4. Hello,

     

    in case you are not able to upgrade to the new version (it notifies you, but nothings happen after clicking on the upgrade button) please

     

    1. take Procdump from ekrn right after the issue manifests (download Procdump tool from https://technet.microsoft.com/en-us/sysinternals/dd996900.aspxrun cmd as an administrator and run procdump -ma ekrn)

    2. collect logs by means of ESET log collector as described here: hxxp://support.eset.sk/kb3466/?viewlocale=en_US

     

    Pack these two logs, upload them to a safe location and send me a download link with reference to this forum topic, we will check it.

     

    Thank you, P.R.

  5. Hello,

     

    you you be able to provide us with an application crash dump?

    You need to download a Procdump tool from Microsoft site: https://technet.microsoft.com/en-us/sysinternals/dd996900.aspx

    run a scan by ESETOnlineScanner than run the Procdump from elevated command prompt with command procdump -ma -e ESETOnlineScanner 

    once ESETOnlineScanner crashes, it will dump a process memory into a file (with .dmp extension). Please pack it with output from ESET Log Collector output, upload it to a safe location and send me a private message with the download link, we will check it.

     

    Regards, P.R.

  6. Hello Slarkins,

     

    I'm sorry that we request such amount of logs, but many users are reporting it, but no-one has supplied us yet with all the logs we need to check the issue as there are more theories, what might be causing it.

    Once fixed, it should work transparently again.

     

    Probably the most important change is that we need a Procdump of ekrn from such state as well.

     

    Regards, P.R.

  7. Hello Slarkins,

     

    As the issue persists, please continue as follows:
     
    1, download and install Wireshark as well as Process Monitor.
    2, run the following command from the command line prompt started with administrator rights
    logman start updater -p {f329ae9a-556d-4934-920f-234e835d9ece} 0xffffff 10 -o C:\eset.etl -ets
    3, start logging with Wireshark and Process Monitor
    4, run update (wait until an error occurs)
    5, stop logging in Wireshark and Process Monitor and save the logs
    6, run the command "logman stop updater -ets" with administrator rights
    7, run procdump from elevated command line with -ma switch for ekrn i.e. procdump -ma ekrn
    8, collect logs using ESET Log Collector (ELC) from both the workstation and server where a mirror is created
    9, create a listing of the mirror folder (e.g. dir c:\mirror > mirror.txt) on the server
    10, compress all logs + the listing of the mirror folder, upload them to a safe location along with ELC logs and pm me the download link. 

     

    I will check it with Devs with priority.

     

    Thanks, P.R.

  8. We are happy to announce that the BETA versions of our products – brand new ESET Internet Security, providing multiple layers of security without significant impact on performance, and ESET NOD32 Antivirus, offering fast anti-malware – are both ready to download and test on https://www.eset.com/int/beta/edition2017/

     

    What's new in BETA?

    • Webcam Protection (ESET Internet Security only) – Lists all applications that have been using the webcam and allows the user to block access.
    • Home Network Protection (ESET Internet Security only) – Shows devices connected to your network and offers a router scan to check for router vulnerabilities.
    • Script-Based Attack Protection - Protects you against malicious Windows and PowerShell scripts.
    • UPDATED - Parental Control (ESET Internet Security only) – Now with updated categorization.

     

    To report issues, please fill in the built-in support form or hxxp://www.eset.com/int/beta/form .

  9. Hello,

     

    that should work, can you please answer the questions below to help us troubleshoot the issue?

     

    Are you able to start the GUI if you run it from the Start menu?

    Does it fix after the restart or not?

    Can you see egui.exe process running in the task manager?

    By a chance do haven't you set Silent GUI start mode ? (Advanced setup -> User interface -> User Interface elements -> Start mode: Silent)? 

     

    Please enable diagnostics dump creation in Advanced setup -> Tools -> Diagnostics -> set dump type to "full" and check if dumps are being created in the diagnostics folder, after few days of using?

     

     

    Regards, P.R.

×
×
  • Create New...