Jump to content

scottls59901

Members
  • Posts

    96
  • Joined

  • Last visited

  • Days Won

    1

Posts posted by scottls59901

  1. Appears this is the problem? Appears to be activated when anything other than the default mode of allowing all outbound traffic is selected? In any case, any updates that are signed should not be triggering an alert. I would check your settings in this area.

     

    attachicon.gifEset App Mod Detection.png

    I checked App Mod Detection, and found this-

    post-4132-0-91840400-1435612227_thumb.jpg

     

    1. Should I Remove the 3 Programs in the box, and OK..., as ESS is still Slow getting browsers... Trusted (open/close 4 times)?

     

    2. Maybe I'm not Trusting properly..., as after the next days cold startup. I have to Trust all over again...?- Especially after Win7 manual updates/Java/Adobe Flash Player/sandboxie/...!?

    Is it necessary to open Every module of updated programs (CCleaner/MS Word 2003/...?

  2. If I understand it correctly, you are using firewall in policy-based mode and have created rules for the applications you use. However, if some of these applications update, the path to the executable changes which causes the firewall to block the communication. Is that the case? Or you are using firewall in automatic mode (default), do not have any custom rules created and disabling firewall temporarily resolves the issue?

    I first tried using  Learning-mode for initial-setup (after an over-the-top upgrade to .312), then back to automatic, as firewall/program... Trust rules weren't created in Learning-mode.

    I had also tried policy-based mode in old .304, and have Never created separate profiles. 

    I do sometimes get ESS pop-ups saying rules have changed, and I Allow/always.

  3. I would like to know if there is an easier way to get complex (i.e.- CCleaner, browsers, Outlook, sandboxie, ...) Fully trusted, than what method I am currently doing?-

     

    I am now spending Huge amounts of time opening/closing Every program module on install/updates..., and then again after restart!  :unsure:

    Then the next day it is necessary again, after a cold startup (especially after Windows updates!).  :ph34r:

     

    I am spending sooo much time keeping ESS firewall trusted on my 2 computers, that I don't have time to keep up with my email...  :wacko:

     

     

    -Maybe I would be better off with regular ESET NOD32, and quit messing with pesky Internet Security firewalls (KIS 2014 was Much worse than ESS!)? 

  4. - Yesterday on cold startup (desktop) I got the Do you want to update pop-up, and I said yes as I had recently done a Macrium sys Image backup. Download only took a few seconds, and reboot...

     

    - When I started my laptop I clicked Ask Me later, as I hadn't done a sys backup for quite some time. I did my backup, but on todays cold startup no pop-up?

    I tried check for Product updates, but it said I was current with .304...

     

    How do I get it to ask me again, as online update was Much quicker than a Big download?

  5. I am having issues before/after defragging with MD (MyDefrag), (Defraggler too))?-

     

    1. I have to Open/close(trust) /reboot before defragging.

    2. I then have to reboot twice, and Trust MD again.

    3. After the next cold startup I have to reboot Trust MD again/reboot.

     

    MD doesn't connect with the internet, so Learning mode didn't help.

     

    Is there some way that I can 100% Trust... MD, so that ESS v8 will auto-Allow... everything it does, or...?

     

     

  6. Perhaps these links and screenshots will help a bit.

     

     

    Notification levels

    These levels correspond to Microsoft's ranking system for updates (low priority, common, important and critical). If you disable Windows update notifications in your ESET product, we recommend that you enable update notifications or automatic updating in your Windows operating system as these updates are available to keep your computer fully protected. Click here to learn more about automatic updates from Windows..

    • Select No updates from the drop-down menu to disable all Windows update notifications
    • Select Optional updates to be notified any time that Windows updates are available
    • Select Recommended updates to be notified when Windows updates marked as common or higher are available
    • Select Important updates to be notified when Windows updates marked as important or higher are available
    • Select Critical updates to be notified only when Windows updates marked as Critical are available, this is the default setting

     

    How do I disable Windows update notifications in ESET Smart Security or ESET NOD32 Antivirus?

    hxxp://kb.eset.com/esetkb/index?page=content&id=SOLN3192&actp=search&viewlocale=en_US&searchid=1426572107613

     

     

    How do I disable pop-up notifications about virus signature updates, scheduled scan activity, etc.?

    hxxp://kb.eset.com/esetkb/index?page=content&id=SOLN3223&actp=search&viewlocale=en_US&searchid=1426572107613

     

     

    Also, make sure that "Do not display notification about successful update" as seen in the screenshot below is unchecked.

     

    hxxp://kb.eset.com/library/ESET/KB%20Team%20Only/SOLN3415/SOLN3415Fig1-3f.png

     

     

    The "system update" verbosity levels is only connected to the Windows updates, they are not connected to the VSD updates at all so they are continuously updated as before, but the update notification bubble will not show up after successful VSD updates if the checkbox for "do not display notification" in the screenshot above is checked.

    I went to F5...- Do not Display notification was Not checked, I said OK anyway (still Not showing)?

     

    As for Optional System Updates, Not interfering with VSD updates- I suggest that you try this, and ...! 

  7. I have Smart Security 8.0.304.0 running on an XP Lenovo laptop and when I try to defrag with DiskKeeper (came with computer) there are many eset files that are fragmented and held open.  I tried phyisically disconnecting from the internet and disabling as much as I could of eset and running the defrag again. Is there a way to temporarily close Smart Security so I can defrag?  Attached is a fragmentation report listing the files.attachicon.gifVolumeC.txt

    I gave up on Diskeeper/Smart Defrag, and Puran's boot defrag (made things Much slower after awhile!)-

    I now use free MyDefrag (downloaded from authors site, with No crapware (like Cnet adds on!)), and my computer is sooo Fast!.

    On independent Performance tests MyDefrag was #1 by Far, and defrags/optimizes ESS!

     

    TIP!-  My procedure For Whatever... defrag you use (I'm a software tech)!-

    Never defrag/install/uninstall/... on a cold startup (reboot 3-times (35min ea.) First (ESS/system is Trusting..., what you did yesterday)!

    1. Open defrag (Run as Admin!) for 4min (to get it trusted by ESS (KIS2014 too)/ close/reboot (after 10min!), and then no-activity wait 35min (for Win/files... to close).

      a. Open defrag (run as Admin!), and wait 4min for ESS to Trust it again..., and 1-pass defrag/ close after 4min/ wait 20min/reboot.

    2. Wait 15min, and open defrag (Admin!) for 4min to get it re-trusted. Open ESS, and get it re-trusted (or ESS will think it's corrupted, and download All Modules!), wait 30min/reboot. Good to go (after 15min)  now.

     

    3. After the next cold startup- Trust your defrag/ESS Again/ wait 35min, and reboot. Good to go after 15min.

     

    I Strongly suggest that you get a digital kitchen timer, and Select/Print this procedure out (you will never remember All of it!)!

     

    G'luck! 

    Scott 

     

    BTW!-

    -If things seem slow...-  Trust defrag/ESS, and reboot!

    -ESS (All Security Suites) are often balky... on a cold startup!-  I have my breakfast/reboot (after 35min) Before I compute...!-

  8.  

    Solution that Stopped PMU updates-

    I opened the ESS GUI, ran the pointer over Everything to get it Trusted..., and when I touched Protection Active..., the whole page Reset...

    attachicon.gifProtectionActive.JPG

    Really? This is only a static GUI element...

    and to hover the pointer over something you don't get it trusted...

     

     

    You also don't have to worry that some of your updates stopped - it seems you just got a notification too much.

    BTW what shows the event log when this issue happens?

     

    The GUI may be static, but the whole page Reset when hovered over Protection Active...?

     

    Here is the Event log you asked for. I clicked on it, but nothing happened?-

    post-4132-0-36243900-1420664610_thumb.jpg

  9.  

    @SweX

     

     

    VDU = VSD = Virus signature database

    VDU = VSD ?? :blink:

     

    So what should "VDU" mean? "virus database u-signature"?? ;)

    Yes, when he said VDU he most likely meant VSD. 

     

    Not sure, maybe... VDU = Virus Database Update....  ;) But the term we use VSD is = Virus Signature Database.

     

    But IMO, TS does not need to worry about if he see the  "The Program Modules Have Been Updated" popup notification or not. (even if it could be interesting to know why) As the modules get updated automatically through the VSD update channel in any case. And like I said, I haven't see that popup for years on any system and the modules gets updated just fine. So no need to worry.

     

    OOPS, Sorry for the confusion! -

    I meant to say the VSD (Virus Signature Update) pop-up, was close followed by a PMU (Program Modules Update) pop-up?

     

    I got to thinking that I usually get this PMU pop-up, the next day after doing a full defrag with Smart Defrag (I Run as Admin, and I also show Hidden/Protected files to get indexes...).

    My old KIS2014 AV would also update modules much the same, after doing a Defraggler defrag (same settings...).

     

    Solution that Stopped PMU updates-

    I opened the ESS GUI, ran the pointer over Everything to get it Trusted..., and when I touched Protection Active..., the whole page Reset...

    post-4132-0-41913700-1420588394_thumb.jpg

    I would guess that is what stopped PMU updates?

  10. Every few days on my Win7 32-bit desktop- On 1st cold startup I get the VDU pop-up, then Quickly followed by "The Program Modules Have Been Updated" pop-up?

    I searched for a PMU log file, but can only find VDU (opens ESS web page...)?

     

    On my Win7 64-bit laptop- On 1st cold startup, I get the VDU pop-up, but Never get the PMU pop-up?

     

    What's up? :mellow:

     

    BTW- My ESS, and on-demand virus/rootkit scans are negative.

  11. I Was Also having intermittent dropped connection issues on my Win7 Pro laptop (Public- Desktop was OK), and this fixed it/ Reduced boot times 5sec/Great Performance Increase.

    It is Always a Good idea to save a Full system image Before making major system changes (I like Macrium Reflect as you can also Easily recover Files/Folders...(free or Paid)!-

     

    I switched 3d party defrags- From Defraggler (no replace WDD, puts Many files in MFT)), to free IObits Smart Defrag v3 (did Not download from cnet, as they add crapware...! I Use Safer Softtonic for downloads, then scan with VirusTotal-This will identify some addons that you can Opt out of.

    Opted out of addons... on install, and Disable auto-updates on 1st open (supposedly another source of crapware, and Never check for updates from GUI!?) /reboot.

    Opened/ hovered over most everything in SD to get it Trusted by ESS/reboot.

    This is what fixed internet!- Configured SD (Any Defrag- Always Run as admin!) Enabled Boot defrag configured for Everything (MFT/sys?...) /reboot.

    Removed 3,200 files from MFT, and...!- Internet problem went away!

     

    Tips!-

    Never do any defrag, until after next days cold startup (Trust by ESS Again!/reboot).

    Never defrag/ install/uninstall/... Anything on a cold startup (reboot after 40min)!

    Never use SD's  Cleanup..., as this corrupted my system! Don't install any of SD's other software!

     

    I like Quick Optimize better (Wait 2min on open!- then Always Analyze Twice (ESS will then Trust, and allow All of it's files too)), as the other defrag Options move Huge files to the end of the HD...

     

    G'luck!

    Scott (software tech)

  12. Today I set ESET 8 to auto-clean while scanning.

     

    It found and deleted three Emails from one of my accounts in Thunderbird.

     

    The Inbox for that account was now scrambled, as described earlier in this thread.

     

    I copied the entire folder from the corrupted account to a second location and then started deleting personal Emails from the original folder so that I could send it in for inspection by Marcos.

     

    After deleting a ton of personal Emails, but leaving the scrambled ones intact, I closed and restarted Thunderbird. All of the corrupted Emails were now fixed!

     

    I am assuming that Thunderbird somehow knows how to re-index the folder after those Emails were deleted by ESET 8.

     

    I never bothered to try this, to my recollection, because my computer is in Sleep mode when not in use and I rarely restart Thunderbird.

     

    The only thing different now than earlier when I started this thread is that I upgraded from ESET 7 to 8.

     

    Maybe this is a fluke, but I will try this method again if a folder gets corrupted in a subsequent scan.

    You might try a reboot, and wait 15min before doing your daily on-demand scan- This allows windows to release all files...

    This cuts several minutes off my on-demand scan times.

     

    I also do a no-activity reboot at the end of the day, and wait 45min before shutdown.

    My system comes up Much faster after cold startup, but sometimes I have to reboot after waiting 35min   before browsers... work correctly?

    This isn't just with my ESS v8, but also with my old KIS2014- I feel it may have something to do with Trusting changes...?

  13. About the main issue: Maybe it's quite simple: When installing a new ESS version over an old version normally all settings are adopted.

    Also the firewall settings.

     

    So maybe it's just that the rules you want to create are already created.

    You could have a look into the rules and zones editor to see it.

    rugk,

    Thanks for pointing me to rules, as the rules I created in old v7 did indeed carry over to v8! ;)

  14.  

    So, are you saying that e.g Zemana is opening faster by doing it like you describe above, than if you only would have used the Automatic mode is that right?

     

    Not only are apps Fully opening faster (eslecially sandboxie), but before creating the Zemana rule in Learning Mode it Never auto-notified me of updates to install (Manual check either)-

    20min after the next days Cold startup, Zemana notified me that a new version was available/Update Now?

    It turned out that I had missed Several updates!?

  15. Solved thanks. I've had a reply from Emsisoft that resolves this.

     

    "The files are created during the quarantine re-scan. You can either empty your quarantine in EAM, disable the automatic quarantine re-scan (Settings/General) or exclude a2service.exe from your existing anti-virus software. "

    Having more than 1 active AV is usually Not recommended, as they actually can cancel each other out (trying to access the file..., at the same time!)-

    I installed free on-demand Emsisoft Emergency Kit, and have no conflict issues.

  16. If you want to see firewall notifications (where you allow/deny a connection) you should set the firewall to "interactive mode".

    FYI-

    -For Initial Setup with No browsing (No active FW!)- Learning Mode is Best for me, as it allows everything to completely open 1st time creating permanent/quickly accessed rules (open Every module... for complete Trust/rules).

    -Then when I switch back to Automatic Mode, the Apps (Browsers/Sandboxie/LastPass/Zemana Anti-Logger/...), Completely Open Much Faster, and I don't have to close/open them again to get them working fully (Hotmail/Redbox/...).

     

    - I tried Slow Interactive Mode in v7 (remember rule...),and Didn't like it re-Prompting me every-time there was Any change (Especially Bad for Windows Update..., as new drivers need to load in fast order!).

    Even after switching back to Automatic Mode, I'd be re-prompted about Interactive rules changes, and I finally deleted All Interactive created rules.

     

    BTW?- After creating this Topic, and going back to opening/closing apps, v8 started creating new rules pop-ups in Learning Mode?

  17. Yesterday I downloaded the latest Offline installer/Public, and installed it over v7/reboot/Full scan/reboot/Learning Mode/reboot (I first created a Full Image backup)-

     

    I then started opening/closing everything on my Win7 Pro 32-bit computer, for Initial Setup/Trust...

     

    With my old v7/ & Win7 Pro 64-bit laptop (clean Offline installer (no rules import, Public), I would see pop-ups saying rules had been created, but No pop-ups on my 32-bit desktop?

     

    I tried switching back to Automatic FW Mode, and then to Learning Mode (No reboot), but still no pop-ups?-

    Otherwise computer is running good.

     

    BTW- Negative scans with my on-demand AV's.

     

    What Now? :huh:

     

     

  18. ESS vs Kaspersky vs Emsisoft (I've used all 3 extensively)-

    1. Kaspersky (KIS 2014)-

    -Gives Excellent 100% protection, but slows your system.

    -Updates every 2hrs, but the system is Slow for 10min... afterwards (makes it's not-so-Quick scan).

    -Fast Scans!- Remembers scanned files, and doesn't scan them again unless modified... (I don't know if this good, as new definitions may detect...?).

    -You have to Open/close your browser 3 times (for 3min...), before it gets Fast (Hotmail...), and drove me Nuts!

     

    2. Emsisoft, with firewall (bought old Online Armor FW)-

    -Good detection rate, and system is fairly fast.

    -Bombards you with alerts, that Really are hard to answer (tells you what others have answered...!?- Lemmings...?).

    -Written in old A2 non-MS language, and is Not always recognized in Security Center (warnings, and they want you to disable)!

    -Firewall is problematic!- They want you to Uninstall in Safe Mode, with every update, then reinstall frequently.

     

    3. ESS-

    -Good detection rate, and user friendly (doesn't slow my systems much).

    hxxp://threatcenter.crdf.fr/?Stats#null (rates NOD #1!?).

    -Slow to respond to new threats with infrequent updates (Consumer Reports dinged ESS on this!)!

     

    My Bottom Line- I'll stick with user friendly ESS, and do on-demand scans with free-

    old Fast MBAM v1.75 (No Pro!) hxxp://filehippo.com/download_malwarebytes_anti_malware/comments/14815/,

    Kaspersky hxxp://usa.kaspersky.com/downloads/free-anti-virus-scan,

    Emsisoft Emergency Kit hxxp://www.emsisoft.com/en/software/eek/

  19. You of course have to click on download.

    About the version numbers see this topic: Decoding version numbers

    Basically I can conclude for you: the last number says nothing about how up-to-date the product is. It only describes the language of the product.

    Thanks- It downloaded the full installer, no version# is displayed in Properties..., but I will assume it is correct?

     

    Question?- Does this version have the Memory leak fix, or do I have to do the Pre-Release...?

  20.  

    i tried again last night but like many times before after install version of antivirus is 7 instead 8 :huh:

     

    and other problem is when i connect to eset website and download latest version while i want to install it if i connect to internet give me alarm that there is new version  and you must download it please check latest version (8.0.341.1) that is on web site

     

    Try here: hxxp://www.eset.com/us/download/home/detail/family/5/#offline

     

    Pick OS and language and start the download of V8. You should not get a V7 installer from there.

     

    Upgrade via GUI e.g V7 -> V8 will be available later ESET mentions that in the release post.

     

    Problem!- When I click on this site to download 8.0.304.1, enter Win7 64-bit/English- It shows v 8.0.304.0, and nothing happens when I click Offline Installer?

    post-4132-0-25851400-1414612790_thumb.jpg

  21. Hello scottls59901,

     

    I tried to find some info on that .exe you mention, but didn't find any, I guess it's possible that this wasn't the exact name of it.

     

    Yes it's important that one knows what to allow or deny while in interactive mode for security reasons.

     

    If you would like to use automatic-mode from now on, then IMO the best would probably be to revert the firewall to the defaults and start over from zero again incase you have more allow rules for something that's not needed. 

     

    This kb article will explain how to revert the personal firewall back to the default state and how to delete the rules.

    hxxp://kb.eset.com/esetkb/index?page=content&id=SOLN3323&actp=search&viewlocale=en_US&searchid=1414363645637

    Note: Complete the instructions from both sections to configure the ESET Personal firewall to behave like a new installation.

     

    But if you just want to delete the firewall rule for that particular .exe then you will find it in the rules and zones editor.

    You can browse there from the main gui, Setup -> click on Network -> Configure rules and zones...    

    Then you have to locate it in the list of rules and delete it, if you indeed created a permanent rule for it otherwise it won't be in the list.

    Thank you for the info!-

    I found the Good rule iPuninstall.exe-  It belongs to my recently updated LastPass password manager, so I'll leave it!

    I also ran all my on-demand AV scans, and they were clean.

     

    I'm back to Automatic mode, and let ESS make the decisions...!-

    Old True saying!- You can protect the computer from malware, but you can't protect it from the user!

×
×
  • Create New...