Jump to content

cmit

Members
  • Posts

    92
  • Joined

  • Last visited

Everything posted by cmit

  1. "always quarantined"? or does that depend on if the Cleaning Level is 'Strict cleaning' or 'Normal cleaning'? Or does it depend on if the threat is "affected"? I was using Eicar (testing virus) and the ESET deleted the files (not quarantine). Which setting did I not configure properly?
  2. Could you please simplify your answer? I just need to know: Does the current ERA v6 have a solution for this? My scheduled scan is Smart Scan (not In-Depth), which I believe should take too long to complete all computers. If there are some computers (i.e. laptops) offline during the scan, the scheduled scan should just skip the offline computers and if found any threat(s) on scanned online computers, it will combine all threats notifications into one email.
  3. Is there a way for scheduled scan to quarantine any types of threats (including potentially unsafe/unwanted files) during a scheduled scan? Thanks.
  4. I have a scheduled scan setup in one of my policies in ERA to scan all computer computers at nights. Is there a way in ERA to setup an email notification that every time the scheduled scan is complete, ERA would send me just one email that details all the threats the scan finds? I checked this thread (https://support.eset.com/kb3629/) but it seems to only have an option to setup: - Number of Ticks to Aggregate - Triggered every no. of occurrences But no option to group all "ticks" of the scheduled scan to just one report . Right now, we are receiving one email per threat (including potentially threat). And it becomes too many emails if the scheduled scan found 20+ 30+ threats per day. Any suggestions? Thanks.
  5. In the case of my scheduled scan, did you mean I would need to disable the 'scan with cleaning' in the 'Task Detail' of my 2nd screenshot, and that's it?
  6. I have scheduled in-depth scan running on all computers nightly. I want to make sure that if found 'potentially unsafe application' during the scan, the scan should not popup any warning asking to 'Clean', 'Delete', or 'No Action', and should "ignore" the found threat and continue finishing the scan. I don't want end-users to see any warning nor any popup cause they would get scared. And I want if the scan found possible threat, ESET ERA should email me then i will check the logs later. I have already disabled the 'Display alerts' and disabled the 'Display notifications on desktop' these two features. But, the warning of 'potentially unsafe application' still pops up and just pause there without continuing scanning. How do I make sure the scan automatically takes 'No Action' and continue the scan until complete? Attached screenshots of my setting. Did I miss something?
  7. Will this EEI have something that shows visualization (not just list of tables) of how a virus/malware/ransomware comes through? i.e. ComputerName -> explorer.exe -> iexplorer.exe -> cryptowall_xxx.exe -> explorer.exe https://www.carbonblack.com/products/cb-defense/
  8. Currently using ESET and got chance to see demo from Carbon Black. Can ERA also have a feature to visualize the attack kill chain so can always know root cause and the scope of the attack? Not just blocking all types of attacks but also provide full visibility into the source and nature of each attach. Thanks.
  9. When our ESET ERA was in v5, the database name was called 'ESET' in our SQLEXPRESS instance (in SQL Server11.0.2100). This instance has other databases running. After our ERA was upgraded to v6, the new database was created 'era_db' in another SQL Server instance call ERASQL (in SQL Server 12.0.2000). This instance only has only one database running (era_db). So we have two SQL Server instances running in the same server, which takes up unnecessary CPU. Questions: 1. Is the ESET database in my SQLEXPRESS still in use or can I take it ofline? (the last eventlog date was the date i upgraded my ERA from v5 to v6) 2. Is there a proper way to move the era_db database from the ERASQL instance to the SQLEXPRESS instance? From this help link (https://help.eset.com/era_install/65/en-US/index.html?db_migration_sql.htm), if I understood correctly, this is not doable because the era_db cannot be moved to another instance that's lower version? If not doable, that means I would probably need to move all other databases from the SQLEXPRESS instance (v11.0.2100) to the newer instance (ERASQL, v12.0.2000) in order to let my server only need to run one instance? Thanks.
  10. Thanks for the recommendation. May I know?: "proper exclusion rules" - Do you have example? "disable parts of the application" - Which application? the ERA Server? Did you mean for example using policy to disable something like HIPS, anti-phishing protection, etc one at a time?
  11. Our resources monitor / performance tool for SQL Server indicating ESET ERA taking too much cpu on our live SQL Server. Is there a proper way to investigate this? or any right solution we can do something about it? Our ESET ERA and its database (SQL Server) are on the same server.
  12. Again, doesn't matter what the issues are. This is only talking about If it's been concluded that the only solution left is to run the uninstaller in Safe Mode before reinstalling, it is necessary to create a solution to build an uninstaller that doesn't require to be run in Safe Mode.
  13. By 'uninstall the client' do you mean have to restart to 'Safe Mode with Networking' -> then run the uninstaller? Again, ESET developers have to come up with a right solution to create an uninstaller that doesn't require to run it in Safe Mode.
  14. I understand it's necessary to restart computer after the upgrade. Regarding the ESET uninstallation and reinstallation, it is ESET developers' responsibility to come up with a right solution to remove the need of having to restart computer to 'Safe Mode with Networking'. Restarting to Safe Mode properly can only be done manually for domain computers. With many business workstations (especially remote computers) to manage, the need to manually restart to Safe Mode is unacceptable. If there's no solution for this, it may be time to look for another antivirus alternative before wasting more time.
  15. Is there a way to automatically upgrade the EndPoint whenever there's a newer/latest version comes out? (like the way to set to automatically update Windows then restart the computer, or install the Windows update first then decide when to manually restart the computer) For businesses with many workstations, having to manually select which group of workstations to schedule the push of install task of newer EndPoint version doesn't quite make sense.
  16. so the simplest solution that would guarantee 100% resolving this troublesome issue is to restart the Windows to Safe Mode with Networking, run the uninstaller to uninstall the ESET product (not the Agent), restart the Windows to normal mode, then install the ESET again. Is that correct?
  17. ESET Support, Could you create a solution that can uninstall or upgrade ESET WITHOUT having to RESTART the computer? If the upgrade failed or a re-installation is necessary, having to restart to safe mode then run the uninstallation tool is simply not an option for many ESET customers.
×
×
  • Create New...