Jump to content

Slithereen Guard

Members
  • Posts

    19
  • Joined

  • Last visited

Posts posted by Slithereen Guard

  1. my config : windows 10 pro version 1607 x64

     

    i have done settings to protect files in D: drive from being accessed by applications running in the computer.

     

     

    you can see the detail of HIPS rule here

    post-7526-0-20223000-1471057929_thumb.jpg

     

    post-7526-0-85985100-1471057930_thumb.jpg

     

    post-7526-0-45598400-1471057932_thumb.jpg

     

    post-7526-0-88991600-1471057936_thumb.jpg

     

    Still Aimp audio player is able to access audio file in D: drive.

    as you can see in pics below that there is no HIPS rule for Aimp.exe

     

    post-7526-0-54744700-1471057942_thumb.jpg

     

    So Aimp is basically bypassing ESET HIPS rule.

    It means ESET HIPS does not know that Aimp is accessing file in D: drive

     

    I am aware that this type of file access exists. what i understand about it is Aimp.exe don't directly access files in hard disk. It actually asks windows OS to access files for it. From what i have noticed is that ntoskrnl.exe (NT Kernel & System ) access the files for Aimp.

     

     

    Similarly many other applications also accesses files in hard disk in this way and are potentially bypassing HIPS rule 

     

    Interestingly ntoskrnl.exe is also not in the HIPS rule. Then why is allowed to access D: drive without asking the user.

  2. i have done settings in parental control to block "not categorized" websites.

     

    some application do try to connect to "not categorized" websites, and get blocked by ESET.

     

    i have added those websites to parental control exception list.

     

    i also want to submit these website to ESET so that they get categorised.

    What is the procedure for doing it?

     

     

     

  3. firstly HIPS is set in Smart mode.

    additionally i created rules for HIPS to ask for permission if any application want to access files in D: drive. But it did not gets implemented until computer is restarted.

     

    I think ESET hips is blocking the upload of image file which is stored in D: drive. Check the pics

     

    hxxp://p1.pichost.me/i/79/2038530.jpg

     

     

    When i try to disbale HIPS, ESET asks for password. When i enter the password it takes me to HIPS setting instead of disabling the HIPS.

     

     

    In HIPS rule setting there should also be "File Read" operation which could be helpful in protecting files from being read by spyware. Check the pics

    hxxp://p1.pichost.me/i/79/2038529.jpg

  4. ekrn.exe does connect to  137.135.12.16:https

    but data length is zero

     

    also https scanner is not working properly in ESET 9 beta. Even if i disable the Https scanner, some https websites are not working properly

     

    since ESET activation is making https connection to 137.135.12.16  . It may be getting disrupted by ESET itself. may be something to do with certificates

    post-7526-0-16446600-1433144350_thumb.jpg

  5. Https scanner is not working properly.

     

    in windows 8.1 64 bit https scanner does not work . It is not able to install eset certificate properly.

     

    In windows 10 64 bit it causes internet connection failure for https websites. cyberfox web broswer unable to connect to https web server. microsoft spartan web browser is unable to start.

     

     

×
×
  • Create New...