Jump to content

toxinon12345

ESET Insiders
  • Posts

    165
  • Joined

  • Last visited

  • Days Won

    5

Posts posted by toxinon12345

  1. signatures and heuristics seems more difficult to deal with latest threats.

     

     

    Not heuristics, but the context in that are operating these heuristics

     

    I use v7 for testing unrecognized malware from live malicious urls and AMS catches it in most cases. I look forward to seeing results of malware tests with v7 :)

     

    I cannot wait for the results as new v7 seems to introduce what I`m call a "Just-In-Time Heuristics"  :rolleyes:

  2. It sounds like it is one of these cases when the programs tries to update/check for updates, before the internet connection is fully established. Like on first boot, or waking the computer up from sleep. Because like you say, you can update manually just fine, and it will auto update normally every hour after you have seen the error. 

     

    I even noticed Update cache is not used for already downloaded modules, specially in slow connections when Update failed after 83% progress

    All the files are downloaded again ! 

    The update cache is used only for Succesful Updates

  3.  

    HIPS-Unterstützung: 1100B (20131024)

     

    Erweiterter Spam-Schutz: 1535P (20131121)

     

    Means that particular module you obtained is in Pre-release state or Beta state

    Usually it means the latest Module Build rather than latest module version

     

    Im using the regular update channel, so my Advanced Anti-Spam module is 1535 (without P)

    I could understand the HIPS module in Beta state; as it is continually experimental

  4.  

    Does ESET still publishes module update information? I remember some time ago, we used to have module update information details, like what were packer details updated and sth like that.

     

    And little deviation to the original topic, but related to VSD. Did anyone see the size of v9061 update, it has 16k entries. So, strange, i never saw a single update having entries having more than 250 or 300 entries.. :unsure:

     

     

    Seems to be the new v7 is capturing a wave of many Kryptik samples heuristically

  5. E) So in my opinion, these two could be reduced to one single option

       - "Protocol filtering - Integrate into system", and

       - "Protocol filtering - Enable application protocol content filtering"

     

    These are different options

    The first options control data routing,,,,,, is the Installation Level of the Firewall;  

         is the same as Advanced Setup>Network>Personal Firewall>System integration>Only scan application protocols

    The second is for actually scan the routed data

  6. Isn't there any additional error code displayed?

    18/11/2013 10:47:14 Update module An error occurred while downloading update files. NT AUTHORITY\SYSTEM
    18/11/2013 10:47:14 Update module Updater: retval = 0x1204, failures: 2 NT AUTHORITY\SYSTEM
    18/11/2013 10:47:11 Update module Updater: Switch DEVEL modules retval = 0x00005007 [NOT NEED] NT AUTHORITY\SYSTEM
     
    WinXP SP3 ESS v7.0.302  DB: v9056(20131116)
  7. Motivation  : My thought with this Site Advisor or guide is, that it could supplement the parental control, and give the young user or any user, a visual notification about a link/web sites immediate reliability, as Eset see it. 

     

    You are refering to Web content filtering

    Anti-Spam parsers are proven to be also very effective when combined to URL blocking

    Recently ESET won First place thanks to the Anti-Phishing module,,,you can view it here

     

    Currently Parental Controls trust only in reactive methods as URL blocking; without using specific proactive algorithms

    If Web parsing could be added into Parental Controls, it would be great

     

    Anyway the yearning of Web reputation seems to be added long time ago

    post-973-0-79409700-1384736193_thumb.png

  8. I have just returned to ESET Smart Security 7 after a break trying other bloat ware

     

    I´m impressed too, as ESET is returning to the ages of the "Little NOD",,,

    ( New features were not an excuse for turning the package into bloatware  :)(Parental, Device Control, HIPS, Anti-Phishing, Anti-Theft)

     

    - ESET msi package is only 70 MB in size,,,, the smallest package

    - ESET continue leading the most advanced heuristics in the world

    - Now their usability is extremely high as the GUI is unified and very smart for the end-user (version 7)

  9. The file won't be submitted if it has already been submitted by somebody else.

     

    Because the software has mechanisms to avoid uploading files you already submitted or submitted by somebody else (ThreatSense,net cache) For example checksums,,,,etc

    I cannot say the same for files manually submitted through context-menu,,,, as I dont know if these are cached or not

     

    Anyway files will be submitted after update I think

  10.  

    The "Blocked object" detections come from suspicious websites. V6 updates the list of such websites every few minutes via cloud while older versions update it with every attempt to update, ie. every hour by default.

    I don't want to go into details as this forum may also be read by bad guys, you know.

     

    P.S I hope it's OK to share this here, I figure if it weren't OK to talk about it then Marcos wouldn't have told us about this feature in the first place   :)

     

    post-973-0-97867900-1384458018_thumb.png

    post-973-0-11212400-1384735528_thumb.png

  11.  

    As for Advanced memory scanner, it's not that it would detect new threats that ESET couldn't recognize before.

    It could but only by startup and on-demand scans which did not provide real-time protection to users.

     

     

    Excellent info!

    I like the way the Advanced Memory Scanner map RAM data when specific events happened only........

    because, if understand well, a continuous monitoring of processes results in performance lags..

     

    But I think there is a little room for improvement as you can see below

    Taking into account Maximum protection and Performance

     

    HIPS Support :

      + Advanced Memory Scanner :

        + Whole memory scanning

          ...triggered on subsequent AMS approvals/enabled 

            (not the first time AMS is enabled!...... as it may lag boot process on user logon)

        + Process exclusion

            (as some gaming users are reporting performance lags when running ultra-packed applications)

             see https://forum.eset.com/topic/570-games-are-not-happy-with-new-eset-smart-security/?hl=%2Bgames+%2Bhappy

        + Scheduled Tasks

          ...triggered on all AMS detections

            (yes, AMS detections doesnt trigger the Scheduler)

  12. LiveGrid file reputation is not applied on files scanned by the on-demand or on-access scanner.

    So, the LiveGrid option in ThreatSense engine parameters  is some type of background file-queue for building file reputation across all users?

    Reputation blocking should be enabled for Web-Mail protection even if data recopilation for LiveGrid is off.

  13. I agree with Marcos, and we haven't really seen what AMS (advanced memory scanner) goes for yet. But I bet ESET knows how effective it is through their internal testing  :D

    It is likely that this feature protects against worms that never make it to harddisk.

×
×
  • Create New...