Jump to content


Most Valued Members
  • Content Count

  • Joined

  • Last visited

  • Days Won


Everything posted by itman

  1. Tip: When it comes to freeware, always opt for the "portable" version. As such, no software installation is performed. If the freeware does not offer a "portable" version in the form of a zipped download, consider that "a big red flag" that something is suspicious about the software. Note that LightShot is not offered in a portable version. Now the following I find hilarious. There is a web site that supposedly offers a portable version of LightShot here: https://karanpc.com/lightshot-free-download/ . When you select the DirectLink download, you are greeted with the below screenshot. If you proceed further, you are indeed a fool.
  2. https://malwaretips.com/blogs/remove-yandex-ru-search/
  3. As far as CPU-Z goes, download the zip version from here: https://www.cpuid.com/softwares/cpu-z.html . It is in essence the portable version and installs no drivers. It will run with Eset not detecting anything.
  4. @Rami is correct. It's the installer that contains the PUA/PUP components. Refer to this article for another like example of how crud is embedded in installers and a way to remove the crud from the installer: https://superuser.com/questions/1246402/remove-adware-from-installer-exe-before-installation . I have often commented in other forums that there really is no such thing as "free" software. For many of these, you will indeed end up paying for the software via adware and the like.
  5. STOP Ransomware Decryptor Released for 148 Variants https://www.bleepingcomputer.com/news/security/stop-ransomware-decryptor-released-for-148-variants/
  6. You're clean. In this instance Eset detected a redirect to a malware web site via JavaScript HTML code associated with the web site you were viewing at the time.
  7. Just noticed that my HIPS specified logged entries are now appearing in both the Eset Event and HIPS logs. Is this by design?
  8. Post a few link references to what you used. We still have no idea what you are referring to in regards to this border issue and how it could be in any way related to the Eset software you have installed.
  9. One other important part about ecmds.exe. It only runs at system startup time via a registry run key. Its sole purpose is to start the desktop toolbar icon Eset GUI and Windows Security Center processes. If it runs at any other time, it is most likely malware related. It would be an ideal malware target since it can run hidden.
  10. I assume you have verified that ekrn.exe is indeed running and Eset is fully functional? Also did you verify that WD; i.e. MsMpEng.exe, is not running? Appears this is a "glitch" with EFS registration processing on Server 2019. Suggest you open an Eset support ticket.
  11. In my case, the ecmds.exe activity started on 10/8 and stopped on 10/10 after I discovered the malware and removed it. The activity was completely random in nature occurring once a day at random intervals with multiple attempts each interval. The activity did not occur at boot time and was not related to any Windows Security Center initialization activities. For reference on Win 10, a code integrity violation occurs when an executable is compiled with Win 10 code integrity guard protection. This ensures that only code signed with a Microsoft code signing certificate can be injected. In my case, I believe the malware was most likely attempting to inject its malicious .dll into ecmds.exe. This would allow the malware to bypass any Eset detection since ecmds.exe is a trusted process to it. -EDIT- The preceding only applies to Windows system executables compiled with CGI protection. A code integrity violation for an app such as ecmds.exe would occur when the hash value of the .exe does not match that stored in the Eset code signing certificate associated with ecmds.exe. One possibility is in my case, the initial malware set a backdoor on my Win 10 installation. Whatever the malware was, it had to be quite old. Suspect all the backdoor did was periodically ping the attacker's C&C server to let it know the backdoor was alive and well. Also believe backdoor statuses are sold on the Dark web and automation is employed to periodically check their statuses. The one on my device suddenly "came alive" and was sold to the highest bidder. This does raise the question of if ecmds.exe is monitored by Eset's self-protection mechanism? It appears it is not. Of note is CGI bypasses have been demonstrated in the past.
  12. Here's the story. It's also the reason why I haven't complained about Eset non-detection. Call this a classic example of "shooting yourself in the foot" by someone who should have known better. Recently I received my first every Win 10 blue screen during normal operation. Researching that it turned out one of the three HDD's in my tower case died. Luckily it wasn't the Win 10 boot drive but it was my largest, newest, and fastest SATA drive. Being extremely peeved over this, I rummaged around in my stack of old HDD's and found an old Western Digital SATA 3 GB drive that would be a suitable replacement. Couldn't remember when I last used the drive but its be years. Still livid, swapped out failed drive for the WD drive. Upon boot into Win 10, took a look on what was on the drive. Norton Ghost backup files. This means either it was used last on XP or the early days of Win 7. Promptly did a quick reformat of the drive, All was well after that or so I thought ........... My best guess at this point is there was some very nasty malware on the drive that activated upon install of that drive. Besides entrenching itself in the page file, it somehow found my router and reconfigured it to pass through mode to a gateway using DNS servers in Poland no less. This also explains why my IPv6 connections became borked at the same time. Now for the "shooting in the foot part." I should have used my SATA to USB converter to perform a full reformat of the drive via USB connection prior to installing it in the tower. This way at least Eset would have had a chance to scan the drive fully. Whether if Eset would have found MBR or rootkit malware is debatable, but it should be removed via a full reformat. Or better yet, using a solid disk wiper utility running from bootable DVD media.
  13. Malwaretips.com has a removal guide on it dated 8/19: https://malwaretips.com/blogs/remove-newsmode-me/ . So its is far from being a recent event. It's adware. The problem is adware can serve up malicious ones. The best way to prevent crud like this is using a good ad blocker in your browser. What I am curious about is VT shows an Eset detection as "suspicious." Is this a new detection? If not, Eset should have thrown an alert upon attempted access to this domain. Was the alert ignored?
  14. Appears to be a "quirk" of FireFox. Like warning does not appear in IE11. Believe FF will immediately try to connect to the URL specified when its opened. As posted above, the URL shown is not route-able.
  15. This appears to be normal: https://support.eset.com/kb6063/?locale=en_EN&segment=home
  16. The problem here is that WD's engine, MsMpEng.exe, shouldn't even be loading. It obviously has been loaded and additionally is detecting Eset as malware: None of the above sounds anywhere near normal Windows Security Center normal initialization processing as far as third party AV use goes. Microsoft just announced it is auto enabling WD's self-protection on all Win 10 versions. This also might apply to Win Server 2019. It also might be a factor of what is going on in regards to this very weird EFS and WD behavior. -EDIT- Another possibility is Eset's ELAM driver. If Windows detects this third party AV driver isn't loaded at boot time, it will enable both WD's and the third party AV real-time scanner running them concurrently.
  17. That is the correct URL for U.S. based B&PP. Try the steps listed here: https://help.eset.com/eis/12/en-US/how_resolve_bp_browser_error.html
  18. Again, B&PP only supports Chrome, FireFox, and IE11. If your current Win default browser is set to anything other than those noted, B&PP when accessed via desktop icon shortcut will fail. When you access a B&PP protected web site via FireFox, it will open that web site in B&PP mode within FireFox. In other words, Eset is using the current open browser as long as it's a supported browser. The purpose of the desktop B&PP icon is to allow the option to open the default browser in B&PP mode w/o predefined protected web site consideration.
  19. Being in the pagefile, its almost impossible to access. Over the years have become fairly good at spotting pagefile malware. In this case it was fairly obvious since it increased my pagefile storage allocation 50% and kept it there. I just set the registry option to clear the pagefile at system shutdown time and the bugger was gone as evidenced by pagefile returning to normal allocation size.
  20. I assumed you were running Win 10. The reference was to Win 10's Cortana feature which is the major source of Microsoft's telemetry activities most find objectionable.
  21. Appears not be an issue anymore after I found some nasty hidden pagefile malware and cleared it out of there. The Event log entry hasn't appeared since then. The question is what the malware was trying to do with ecmds.exe?
  22. Add to this the PUA test doesn't work either. Looks to me they might have been hacked.
  23. The explorer.exe outbound activity on second thought is most likely due to Win 10 Cortana activities. I never see any like activity since I am using a third party product to block most of its outbound activities. Ref.: https://support.microsoft.com/en-us/help/4028014/windows-manage-cortana-settings FYI. Win 10 settings has a Data Usage section where parameters can be set to limit bandwidth activities in case you were not aware of this. Of the 4.68 GB data usage shown in the below screen, 4.2 GB was due to FireFox. Like I stated previously, it is a real "pig" when it comes to data usage.
  • Create New...