Jump to content

cyberhash

Most Valued Members
  • Posts

    728
  • Joined

  • Last visited

  • Days Won

    30

Posts posted by cyberhash

  1. The site (quttera) seems to be nothing more than some sort of auto blacklist  ??

    Never heard of the site (quttera) so ran a test on my own website and it came back as "potentially suspicious" and i have nothing more than a clean install of a cms on it.

    Sounds like you pay to get whitelisted with them.

    Like Marcos says, ESET's web access protection is very strong and it works in a totally different (legitimate) way as opposed to getting flagged as suspicious unless you pay them.

    :huh:

  2. V10 is not being "pushed down your throat". Like any software there is always new features added into it to make it more desirable (otherwise there would be no point in upgrading). Likewise the code itself has been cleaned up and polished.

    I have been running v10 for a long time now and the difference between it and v9 makes it worth the change alone. Memory usage has fallen massively, and problems with poor web browser performance has been addressed.

    You always get a free 30 day trial with any version anyway, so why not install it (on release) and see for yourself. If you don't like it then you are always free to uninstall it and go back to the previous version you were using that you were happy with.

    We don't do gambling on here, but my money would say that you would install v10 and never return to the older versions :) 

  3.  

     

    I've found HIPS settings posted by an user, it includes MBR protection (that's what his post says) https://malwaretips....48/#post-150572

    Are these settings good?

    Yes. Those settings were copied from a security configuration guide for an earlier ver. of Eset, ver. 6 I believe, that is posted also on the malwaretips.com web site. Many of the rules in the guide now exist as default HIPS rules such as the monitoring of the registry "run" keys.

     

    As I warned previously, any monitoring of drive direct access by the HIPS will cause issues with some existing Windows processes. The one most affected is shadow volume copying since it runs in the background. As such, you may not be present to respond to any alert with the result being a borked system backup occurring. So use of this type of HIPS monitoring is at the user's risk. 

     

    I also have yet to try such monitoring in Win 10. I also use Emsisoft's Antimalware and its behavior blocker does monitor for direct/low level disk access.

     

    Is it possible to add custom rules in HIPS settings to improve ransomware protection? Or maybe Smart mode is enough? I'm asking because I've seen Youtube video, where user was testing ESET 10 Beta on default settings and it didn't protect OS from zero-day ransomware sample.

     

    That youtube video wont be unique to just ESET products  ...........

    NO security product from any vendor can give 100% protection against zero day ransomware or other types of virus/malware.

    Like i said before, common sense is your best defence. Stay clear of sites offering pirated software and music and the like and always be skeptical of any attachments received in an email from anyone (including family).

    You can always add custom rules to HIPS, but you could also render your system unusable by causing problems with windows system files being denied access to the files it needs in the process.

  4. Hello, i need to download something using MS SDM, it's just file download via port 80, but it's look like ESET checks every byte, which is very annoying, how can i temporarily stop it? I dont care about cpu usage, thats fine, almost idle. But HDD is between 60-90 % and the download even crash sometime and i think it's because of that.

    Thx for reply

    It wont be checking every byte as its downloading, are you sure there is not a HDD scan running in the background ??? You can temporarily disable the protection by right clicking on the ESET icon and choose "Temporarily Disable Protection". Or a better idea would be to pause the scan IF its running.

×
×
  • Create New...