Jump to content

Hapkido

Members
  • Posts

    26
  • Joined

  • Last visited

Posts posted by Hapkido

  1. Marcos,

    I replaced the 3 files you found that you believe were infected and that resulted in no further alerts from ESET. I did ask my Host provider to compare the 3 alleged infected files with the replacement files to identify the injected script. They did that and reported that 16 other files have that same code. I copied the actual code in a new text file and then did a manual scan of it and ESET said it was clean. Sooooo, before I replace all 16 files, can you positively identify this code is malicious?

    forum infected files & locations.txt

  2. About 2 days ago, ESET Internet Security (14.1.20.0) has flagged my personal forum due to it intercepting the "JS/Agent.OZD" trojan. I've had this forum for 20 years and never had a problem with security issues. I suspect that this item was recently added to the ESET list?? The problem has been reported to my Host Provider tech team and their scans didn't detect anything. The practical issue is that some of the features of the forum are disabled, e.g., the text box for starting new discussions or replying to one is missing. Other related features are using the "Quote" feature, and a few others. Disabling ESET resolves those problems. I suspect that this is a false positive. I think javascript items are being flagged. What can I do to resolve this issue without creating a real risk?

    TIA

  3. Version 11.1.54.0

    When I go to my bank's website I can get login fine, but when the next page tries to load where you enter your password, the page is blank. This happens with both Opera and IE 9. Yes, the "Banking and Payment Protection" option is enabled. If I temporarily disable this feature, the problem is gone and I can successfully login and navigate all aspects of the website. Is there something I need to do, aside from disabling this feature entirely, to be able to access the bank's website?

  4. I have one resistant e-mail address that ESET Spam filter doesn't remove from the Inbox despite the address being in my Blacklist. When I click on the "Spam Address" button I get the following error message:

     

     

    The following events occurred while processing addresses:

    xxxx@domain.net - not added (already exists in user's Blacklist)

     

    So, how can I get this particular address (actual address) to be recognized as spam and moved into the Junk E-Mail folder (Outlook 2007)?

  5. See attached pics of my Outlook settings.

    1. I do not have the "ESET Outlook Add-in" for 'Com Add-ins'.

     

    2. I do not have anything for ESET in the 'Trusted Publishers'

     

    3. I do have "ESET Outlook Plugin" in the "Trust Center > Add-ins > Exchange Client Extensions" section.

     

    So, my guess is ESET Anti-spam isn't properly installed/integrated into Outlook. OR, Outook 2007 is different from the version of Outlook you are using. Methinks some progress has been made at least in discovering the cause of the problem, but assuming that ESET Anti-spam isn't installed correctly, the obvious questions are Why? and Can it be fixed?

     

    Thanks for spending time with me on this issue.

  6. Hi again,

     

    IT may be ! , try creating a seperate folder called "ESET Spam", and also look in trust center of outlook and make sure you can see the ESET plugin installed.

    iF there is a way to turn off outlook spam prot or rules, i would do it.

    I looked in the "Trust Center" and I cannot see Eset nor anything related to it in any of the sections. I would have expected it (if it is supposed to be there) in the "Addins" section. Where exactly should I be looking in the Trust Center? And, what am I looking for, i.e., what should the Eset antispam be worded as if not something obvious?

  7. Hello,

     

    First off, what email client are you using ?

    Second, do you have a folder setup that is dedicated for spam, what did you name it ?

     

    My last question would have to be more of a statement, if you classify a message as Spam by ESET, and it never catches it on the second time it comes through, something must be setup wrong or the conclusion should be, not that its disappointing, but why isn't it working. It's not working at all. :lol:

    Let's see if we can determine your issue ! ;)

     

    Thanks

    1. E-mail Client: Outlook 2007

     

    2. Spam Folder: Default Outlook 'Junk E-mail', which is also the folder designated in the SS Anti-Spam setup configuration.

     

    3. Not catching repetitive spam messages: Agreed and that's why I asked the question. ;)

     

    4. Just grasping at straws now, but is it possible that Outlook's anti-spam is causing a conflict with SS's Anti-Spam?

  8. I really don't like using a negative subject line to introduce a new thread, but it is unfortunately necessary in this case. Overall, I am extremely happy with SS. In my estimation it is the best of its kind available. However, the Anti-spam module is less than satisfactory in my experience. Rarely does the Anti-spam recognize spam messages in my inbox. Many are foreign language e-mails which I have to manually mark as spam. I also get a few spam messages from the same source/address, and even after designating them as spam, SS never catches them. Is there any way to increase the effectiveness of the Anti-Spam feature?

  9. I'm having the same problem with "Outbound Traffic" dialog box appearing. It isn't restricted to one application either; random appearance. The easy way to close it however, is to right click on the Taskbar (assuming you have one), click on "Task Manager" and when it opens, click on the "Applications" tab. You will see the "Outbound Traffic" item in the list. Select (click) the item and then click on the "End Task" button located on the lower right corner. It's definitely a 'bug' which the developers will most likely fix, assuming they are aware of the problem.
     

  10. @ Marcos... Updated to version 7 with the latest definitions. All went fine. Thanks for that update information.

     

    @ Arakasi... Regardless whether Sirefer and wowlik are related, the ESETSirefefCleaner found 1 instance of Wow64 and it was removed. Good call. I then ran a Smart Scan and it found 31 items. However, the first three items were false positives as they were 14+ yr. old jokes (.exe) which are harmless. The other items were all part of Vista Codecs, which I had uninstalled over a year ago, but I chose to delete them anyway.

     

    Result:

    Good - The download function is now working in IE.

    Bad - It removed a legitimate macro in Outlook 2007 which I can easily recreate. The icons on my Quick Launch Bar were all rearranged, but that's NP either.

     

    UNLESS something else pops up that is related to this issue, let's call this one resolved. :)

     

    Thanks for the quick help. Nice to have this place on its own with new forum software, etc.

  11. Sounds like Sirefef.

     

    hxxp://kb.eset.com/esetkb/index?page=content&id=SOLN2895

     

    Please report back after scanning with the stand alone scanner for Sirefef.

     

     

    **Edit : I do have a high belief that you may have other types of malware in addition to Sirefef.

    Are you able to update the virus definitions with Eset, and what does a Smart Scan reveal after you checked for Sirefef ?

    I just downloaded the ESETSirefefCleaner file (using IDM) and will run through the process and report back.

     

    Yes, I have no trouble with the ESET auto updates.

     

    I'll run another smart scan after I finish with the Sirefef Cleaner.... back in a bit.

×
×
  • Create New...