Jump to content

Peter Randziak

ESET Moderators
  • Posts

    3,511
  • Joined

  • Last visited

  • Days Won

    207

Posts posted by Peter Randziak

  1. Hello Mark,

     

    "Log all blocked operations" should be enabled only during troubleshooting issues.

    I highly recommend to disable it in order to prevent HIPS from rapid growth.

     

    Self-defense is used to protect crucial parts of the AV so I don't think that any process should be trying to delete anything protected by it.

     

    Could you please paste here appropriate lines from the log?

  2. Hello,

     

    According to Dev team after applying this fix there shouldn't be any crashes, but we are not able to replicate the issue in-house so we need your help to verify it.

     

    1. Backup the original files ( esets_pfw and esets_proxy) 

    esets_pfw with this command sudo cp /Applications/.esets/Contents/kext/10.6/esets_pfw.kext/Contents/MacOS/esets_pfw /Applications/.esets/Contents/kext/10.6/esets_pfw.kext/Contents/MacOS/esets_pfw.bkp

    esets_proxy with this command sudo  cp /Applications/.esets/Contents/MacOS/esets_proxy /Applications/.esets/Contents/MacOS/esets_proxy.bkp

    2. Download the archive, and unpack (password is "clean")

    copy (via command line) esets_pfw to /Applications/.esets/Contents/kext/10.6/esets_pfw.kext/Contents/MacOS/esets_pfw

    copy (via command line) esets_proxy to /Applications/.esets/Contents/MacOS/esets_proxy

    3. Execute commands:

    sudo chown root:wheel /Applications/.esets/Contents/kext/10.6/esets_pfw.kext/Contents/MacOS/esets_pfw

    sudo chmod 755 /Applications/.esets/Contents/kext/10.6/esets_pfw.kext/Contents/MacOS/esets_pfw

    4. Restart the Mac

     

    The crashes shouldn't appear anymore.Please keep us informed.

     

    Thank you.

    esets_proxy_and_esets_pfw.zip

  3.  

    Hello,

     

    could you please try to reproduce the issue with enclosed esets_proxy binary and provide us with the crash log?

    Archive is encrypted with password "clean"

    Replace the binary in the application folder, but keep the original one.

     

    @Alex - PM sent.

     

    To be clear, are we to turn on the pre-release updates first, or drop in the esets_proxy file first, or do both before testing again? 

     

    Thanks. 

     

     

    Hello,

     

    you could enable pre-release before changing the esets_proxy.

  4. Hello Suporte.protagon,

     

    please run the tool with parameter /d

     
    "C:\>EOlmarikTdl4Cleaner.exe /d
    ESET Windows OlmarikTdl4/Olmasco Remover v1.6.0.8 (Jun 10 2013 12:48:50)
    Copyright © ESET, spol. s r.o. 1992-2013. All rights reserved.
     
    Full dump mode"
     
    and provide us with an archive located in EOlmarikTdl4Cleaner folder, which will be created in the same location as Olmarik cleaner was run from.
×
×
  • Create New...