Jump to content

itman

Most Valued Members
  • Posts

    12,231
  • Joined

  • Last visited

  • Days Won

    322

Kudos

  1. Upvote
    itman received kudos from camelia in What is wrong with maxsecureantivirus?   
    Probably the same company since Eset also blocks this URL.
  2. Upvote
    itman received kudos from jetspeedz in FW or HIPS window Alert closes too fast, how to make it stay up longer or find log of alert?   
    Eset kernel and firewall processes for ver. 12.1.34 use approx. 90K of memory on my Win 10 x(64) 1809 build as shown in the below screen shot. Assumed is memory usage will vary depending on Win OS ver. used.

  3. Upvote
    itman received kudos from camelia in Select Scan Target   
    Appears  /private/var/vm is used as some type of virtual memory swap disk on MacIntosh's:
    https://www.bleepingcomputer.com/forums/t/682395/what-is-the-purpose-of-this-vm-folder/
    Remember that Google search is "your best friend" on questions like this.
  4. Upvote
    itman received kudos from camelia in What is wrong with maxsecureantivirus?   
    Eset's detection is correct.
    Did initial scan at URLVoid.com. That yielded Dr. Web detecting it as malicious. Viewed Quttera's analysis there and it showed a possible malicious status. So scanned the site at Quttera's web site which yielded the following:

    https://quttera.com/detailed_report/maxsecureantivirus.com
  5. Upvote
    itman received kudos from asdasdasd in Reddit Site Block   
    No problem here using IE11 as shown by the below screenshot. Appears to me Eset might be having an issue perhaps with Adblock's connection? Temporarily disable AdBlock and see if the Eset alert still appears.

  6. Upvote
    itman received kudos from jadinolf in ESET version 12.1.34.0 have been released.... ?   
    Just checked. It wasn't offered to me. So count yourself one of the "lucky ones."
  7. Upvote
    itman received kudos from rklumpp in Incorrect Ethernet Packet   
    Think I found a temporary solution until Eset has a fix for this.
    Create an IDS "Unexpected Network Protocol" exception with no IP address specified and everything else set to "No." Note: "Direction" in the rule must be set to "Both." 
    Initial test was to connect to Win Store and no Network log entries were generated. Although security-wise this is not an ideal solution, it is far better than totally disabling IDS protection.
  8. Upvote
    itman received kudos from Joliet_tech in Incorrect Ethernet Packet   
    I finally got "Incorrect Ethernet Packet" IDS exception to work. I had to set the Direction in the rule to "Both" and presently doing it by detected IP address; after verifying the IP address is associated with a Win Store connection.
    Sure hope Eset figures out what the problem here is proto. 
    -EDIT- Forget any exceptions. When I set direction to Both I started seeing blocked Google server connections appearing whose IP addresses were never seen before.
    Appears to me something serious is borked in IDS detection.
  9. Upvote
    itman received kudos from Joliet_tech in Incorrect Ethernet Packet   
    I am also starting to lean toward Port 0 usage by Microsoft as the possible culprit.
    This would not be the first instance I had in that regard using Eset. I believe in ver. 11, Eset changed something in this regard. My ISP for reasons beyond me does ICMPv6 pinging against my router; probably for connectivity purposes. My Win firewall event log was expanding a phenomenal rate  from block activity related to this. That plus Eset's firewall wizard showed the same  phenomenal counts. I resolved this one by just creating firewall rules to allow the activity for the IPv6 IP addresses involved.
  10. Upvote
    itman received kudos from AGH1965 in The Logic of your user interface (y/n)   
    Perhaps a bit of historical review will get things into proper perspective.
    Eset prior to ver. 9 had a "dated" but well-liked user interface. Starting with ver. 9, Eset adopted the current Metro style GUI. I assume that was for compatibility for all devices on which Win 10 could be installed on. There were a lot of complaints initially about the Metro style GUI; especially with changes made in regards to HIPS rule creation and editing. I am also one who did not like the changes made to the HIPS in regards to the Metro GUI adoption. Over time, I have adapted to the changes to the Eset GUI due to the Metro style changes.
    The point here is Eset laid out the GUI as best as it could in light of restrictions employed by use of the Metro style. Although it may be possible to perform limited changes to the Eset existing GUI, I really wouldn't expect to much in this regard.
  11. Upvote
    itman received kudos from camelia in EIS How do I disable a reminder?   
    As far as I am aware of, you can't. There is not separate user alert setting controlling the popup status alert. You can just close the popup alert by clicking on the "x" associated with it.
  12. Upvote
    itman received kudos from persian-boy in Python Question   
    Can Eset actually detect a Python script pre-execution if its packed and encrypted? Note that Win 10 AMSI does not scan Python scripts. -EDIT- also Python scripts "are famous" for running "sleeper" code designed to "wait out" heuristic scanning methods.
  13. Upvote
    itman received kudos from persian-boy in Python Question   
    Does Eset detect an executable created via PyBuilder in which the Python engine along with a script is bundled as a PUA? If not, it should.
  14. Upvote
    itman received kudos from TomFace in Error code 0x847695d7 when opening Firefox for banking   
    Although this article notes error code, 0x847695d0, I suspect it still applies in this case: https://support.eset.com/kb6408/?locale=en_US&viewlocale=en_US
  15. Upvote
    itman received kudos from confusedbloke in 1st part of site is fine, 2nd part apparently has HTML/ScrInject.B trojan?   
    It appears to me Eset is detecting something on the captcha web page and blocking it. My experience with such an occurrence is there might be other malware attempting to be served up from such a web page. So proceeding to enter data, etc. on that web page is done at your own peril.
    What you can try is suspending uBlock for that web page and observing what Eset detects on the web page.
  16. Upvote
    itman gave kudos to AGH1965 in Idle Time Scanning Question?   
    According to ESET Online Help it will. Logging off can be used as a trigger for idle-state scanning.
  17. Upvote
    itman received kudos from Nightowl in Win64.Vools.L Can not be cleaned   
    Appears to me, the clients got nailed by a true 0-day malware. Also, it appears Eset created a new signature for this bugger, Win64/Vools.P.
    It is encouraging that Eset was still able to detect it via AMS using a prior variant DNA signature.
    BTW - what was the source of the svchost.exe injection?
  18. Upvote
    itman received kudos from Clark T in Has There Been A Change To Banking & Payment Protection?   
    Thanks for the feedback. Would suggest Eset post an announcement when a change to GUI related components are made. Especially in regards to B&PP since many are sensitive to any changes in that area possibly due to the malware.
  19. Upvote
    itman received kudos from persian-boy in Has There Been A Change To Banking & Payment Protection?   
    The content isn't showing.
     
  20. Upvote
    itman received kudos from persian-boy in Installed poweriso and eset is blocking websites   
    My question is why is this type of software attempting to connect to the Internet with the activity you posted? It is basically just software to create a .iso file for the most part. At most, the only outbound connection it would need is to the vendor's server for software updates.
  21. Upvote
    itman received kudos from Hijin25 in EIS blocks toolslib.net   
    I just scanned toolslib.net using QUALS SSL Server check and they gave the site an A+ rating: https://www.ssllabs.com/ssltest/analyze.html?d=toolslib.net&s=51.15.229.92&latest . All certs. look OK except they are using a self-signed Let's Encrypt cert.. Only thing QUALS noted was:
    OCSP STAPLING ERROR: OCSP response expired on Tue Mar 05 18:00:00 UTC 2019   
  22. Upvote
    itman received kudos from Hijin25 in EIS blocks toolslib.net   
    You will have to be patient and let @Marcos get back to you with whatever issue Eset is detecting with the web site. If you immediately have to download AdwCleaner for some reason, you can do so via the bleepingcomputer.com link I posted previously.
  23. Upvote
    itman received kudos from Hijin25 in EIS blocks toolslib.net   
    Appears the issue has been resolved. I can download AdwCleaner from the Malwarebytes site w/o issue.
  24. Upvote
    itman received kudos from Debner in The Credentials used to access ESET LiveGrid servers are not correct.   
    Did you enter the new license key into the currently installed expired Eset version?
    I suspect any registration info. on Eset servers got wiped/hosed after the currently installed Eset version expired.
    Suggest you perform the following:
    1. If you made any custom changes to NOD32, export your current settings.
    2. Uninstall your current Eset version using Windows Control Panel -> Programs -> Uninstall a program.
    3. Reboot your PC; Eset should instruct you to do so - if it doesn't, reboot anyway.
    4. Download current version of NOD32 here: https://support.eset.com/kb2885/?locale=en_US&viewlocale=en_US .
    5. Reinstall Eset and enter your new license key. Reboot your PC if Eset instructs you to do so to complete the installation.
    6. Import your old Eset settings if you previously exported them.
  25. Upvote
    itman received kudos from persian-boy in EFI/ COMPUTRACE   
    Do all the devices have UEFI? Older PCs don't and just have a BIOS.
×
×
  • Create New...