Jump to content

Nightowl

Most Valued Members
  • Posts

    1,844
  • Joined

  • Days Won

    17

Posts posted by Nightowl

  1. 10 hours ago, Tetranitrocubane said:

    I'll put it out of my mind in that case, and thank you for the explanation! I'm surprised that ESET would label these files as malicious after nearly 10 years - but I suppose stranger things have happened.

    Thank you once again

    Most likely due to a vulnerability found in that file.

    ESET designates them as unsafe because a malicious actor can exploit them depending how vulnerable they are.

  2. It's the BIOS package or the updater which is vulnerable , updating to more recent BIOS version will make ESET go quiet

    It's just mad about the BIOS/driver whatever this is , because it's vulnerable , you  can exclude the detection so ESET can be quiet about it , or just update the BIOS/drivers(more recommended) which will fix the vulnerability and make ESET go quiet.

    But I think ESET is mad about the downloaded files of the BIOS , removing them will get rid of the detection, if the detection was from the BIOS itself , we will see another location in the message.

  3. On 4/11/2024 at 4:15 AM, Guillermo Mariel said:

    Thanks for the prompt response, something important to add is that it is a Windows Server and domain controller role.

    Better to keep it behind a Firewall protected and allow only specific IP addresses to be able to connect to the domain controller , this is more secure approach.

      

    On 4/11/2024 at 3:59 AM, Guillermo Mariel said:

    the server does not have port 135 open to the Internet, however, when executing the netstat command, it is observed that it is trying to connect to different public IPs (Several classified as malicious or malware according to Virustotal) , and the connection status is SYN_SENT.

    I am also almost sure that the port is open

     

    Otherwise the said IP won't be able to reach , or in another scenario there has to be a reverse shell for it to be open a way for bad guys to get in , but I still believe in the first scenario , port is enabled.

  4. 1 hour ago, Faizan said:

    Hello,  We are getting below error while installing AV through live installer.

    Windows version 20h2 build 19042.631

    image.thumb.png.bb68efc55b18764d0e3a281220ad0c9c.png

    I don't know exactly why the installer cannot run , an ESET staff can help more than me

    But I have a suggestion to upgrade your Windows 10 to more recent Windows 10 version because 20h2 is out of support.

     

    Quote

     

    Current status as of May 9, 2023
     
    May 9, 2023, all editions of Windows 10, version 20H2 have reached end of servicing. The May 2023 security update, released on May 9, is the last update available for this version. Devices running this version will no longer receive monthly security and preview updates containing protections from the latest security threats.

     

     

  5. I believe slow downloads are related to Blizzard(Battle.net) themselves

    It's not only you , as Battle.net is buggy when you open Download Limit , try to go for no limit

    If not limited , try to limit it to half of your internet speed or even more or even above your download connection speed. ( sounds stupid I know , but their limit is buggy or used to be buggy ).

    And it can be their servers are just feeling tired and there isn't enough speed for everyone , I don't know how are their servers located , but your location can also make an affect.

    I know because I experienced this with high speed connections , with ESET and without ESET with different locations.

  6. 4 minutes ago, kurco said:

    Hi,

    kernel 5.15 is not affected, because it's compiled with default version of ubuntu gcc. But 6.5 is compiled with gcc version, which is not by default present and therefore it needs to be installed, because it is dependency for kernel modules compilation. 

    Kurco. 

    I understand , thanks for the explanation , I installed the dependency

    I cannot get the GUI to run , I have this error in systemctl

    econnd[1774]: ESET Endpoint Antivirus Error: Invalid request: Function not implemented

    I restarted eea service

    eea[4375]: ESET Endpoint Antivirus error: Can't start GUI for user vm. Please log out and log in to start GUI for vm

    image.thumb.png.d1e9763a0aca3a6ceb34924694f6decb.png

    I logged in and out

    Should I try to reinstall again?

    I have other machines that run same endpoint and linux server but didn't have those troubles , it's weird , and I also noticed if I open the Secure boot , the protections cannot open , am I doing something wrong?

  7. 1 minute ago, kurco said:

    Hello ,

    I used kernel 5.15 and it worked fine , I don't know if this KB can solve it with 6.5 I didn't try because I already removed 6.5 kernel.

     

    Thank you.

  8. 1 hour ago, Microbe said:
    Hi,
     
    The screenshot of the notification is below, followed by the information for your points below it
    As you can see in the screenshot above, although camera is blocked in edge, every time I clear browser history I get the webcam access blocked notification visible on the lower right.
    image.thumb.png.da171b654fb3b6b130ce8bedf9bdb3e3.png

    What happens if you block the Camera Access to Edge from Privacy Settings in Windows 10/11?

  9. 7 hours ago, PassingBy said:

    Hi Nightowl,

     

    Thanks for the insights. Actually, Vantage was just updated and now the Energy/Battery section offers a lot more of data. The configuration on this Yoga does in such a way that Windows power management doesn't offer the same functions so i need to keep Vantage. I guess my next machine won't be a Lenovo.

    You are welcome

    There is a topic about it here also :

     

  10. 1 hour ago, PassingBy said:

    As per headline.

     

    I ran a scan, which is still ongoing and instantly these two files popped up.

    C:\Drivers\OneKey Optimizer\setup.exe » INSTALLSHIELD » OneKey Optimizer.msi » MSI » ISSetupFile.SetupFile42 » INNO » {app}\bin\reaper_u.dll - a variant of Win32/Lenovo.G potentially unsafe application - action selection postponed until scan completion

    C:\Drivers\OneKey Optimizer\setup.exe » INSTALLSHIELD » OneKey Optimizer.msi » MSI » ISSetupFile.SetupFile42 » INNO » {app}\bin\reaper.dll - a variant of Win32/Lenovo.G potentially unsafe application - action selection postponed until scan completion

    Sole difference between the two seems the name "dll" and "u.dll"

     

    I think they're part of Lenovo Vantage, which i only use for power management but has lots of exe tasks ongoing on my machine, including some i never liked too much but keep going.

    Any advice?

    Thanks

    E.

    egui_ldUbzSXHK0.jpg

    Try to update the Lenovo tools to a more recent version if that doesn't fix the ESET detections then you can ignore it or proceed to remove the Lenovo tools

    Unsafe detection with Lenovo probably means what has been detected is vulnerable therefore ESET doesn't like it because it can be exploited to infect the machine.

    I've googled about the OneKey Optimzer , It's related to the battery management in the Laptop, if there is no recent version with the vulnerability that ESET is mad about fixed , then I would ditch that and use Windows internal power management.

  11. 7 hours ago, Laplacian said:

    I now scanned the external IP from LTE/4G device and it didn't show no ports or even any host up. Then I also scanned my LAN again using NMAP and the device inside my network seems to have the port 53 open indeed, but it is TCPwrapped. I do not know why does show that one port. But I trust ESET so its all good thanks for the help :)

    You are welcome :)

    About port 53 , try to check that device and see the firewall rules for port 53 TCP , it shouldn't be open for DNS unless that device serves something or it's open by mistake.

  12. 1 minute ago, Laplacian said:

    I scanned the machine inside my LAN with another LAN device. As for the public IP, I will try to scan outside my LAN. I will post when I have done that thanks.

    Yes while connected from LAN , see your IP from whatismyip websites , then disconnect from your WIFI home , and then scan the WAN IP that you got from the website , it should how you the results from Outside > to your side

    I think inside the LAN , since it's trusted , ports can communicate with eachother unless it's instructed by the personal firewall on the devices (like ESET or windows firewall) to disable certain ports from communicating.

  13. Just now, Laplacian said:

    I scanned with phone where I have paid app called Net Analyzer

    I don't know this application , but try to use LTE/4G connection when attempting to scan your IP , that will show your firewall that you are outsider scanning , scanning from the LAN to WAN IP , will show wrong results if I am not mistaken.

  14. 20 minutes ago, Laplacian said:

    Hi,

    So I scanned all my machines on my network, and it showed that my computer has the port 53 DNS domain port open? Is this normal, as I think that I haven't seen that being open before if I remember correctly. And even if it is open, shouldn't ESET prevent showing that it is open?

    May I ask how did you scan? did you use Nmap for example or ESET built in scanner?

  15. 26 minutes ago, Ahmeduchiha said:

    Thank you for your reply,

    HTTP/3 QUIK protocol is disabled.

    image.png.f0fa4cf1c4d1f31e30800250175328bb.png

    I believe now ESET should be able to detect stuff , you can test it with an EICAR test file from EICAR official website

    I've read now that in a recent FortiOS firewall version 7.2+ , it's able to scan the QUIC protocol but it was never able and the solution was to block QUIC through App Control , same applies to Palo Alto firewall , but I don't know if they added the function to scan QUIC protocol or not.

    So could be security software solutions like ESET and other companies will follow the path soon.

×
×
  • Create New...