Jump to content

How to evaluate the system using Eset Sysinspector


ulzie

Recommended Posts

Hi ulzie

There are a couple KBs on submitting a log to ESET for research.

Most of their logs contain standard and common pc and windows information relating to drivers services and files etc.

The interface is quite easy to pick up once its open and the image is complete with a top toolbar and a slider to set strength of what your looking at.

It might be an informative KB if the team were to write a quick one with maybe a gui picture with a key.

I like the sysinspector.

Edited by Arakasi
Link to comment
Share on other sites

what is the filtering all about?.. what is the meaning of risky? is that software listed on risky is a risk to the system?..

Link to comment
Share on other sites

Yes ulzie

Especially if its hooked to a normal processes like explorer or taskman. Executables are easy to find.

You can find active x and all types of malware not just virus.

Im glad i could have been a little help.

Link to comment
Share on other sites

Your welcome.

When i get to the office ill try to remember to post more info.

No access at the moment.

Good day :)

Edited by Arakasi
Link to comment
Share on other sites

Here are a few pictures from one of my machines using Sysinspector.

The first picture of course is the loading form, just to make sure you know your looking at the right ESET Tool.

Second is the main graphical user interface of the app once loaded. The filter as discussed in thread can be seen across the top.

In third i moved the slider to threat level 8 of 9 to ascertain why there are red notifications on the system. As seen in the pic the reds are from Cylance which is a legitimate program created by old Mcafee project managers and devs. I inserted hash codes including md5 below.

4th picture is where i have moved the filter to risk level 5 of 9 to look at the medium threat level services running.

This is ultimately a breakdown of a quick evaluation on a system and how you can isolate threats faster and eliminating the normal windows processes etc from the equation if your not all sure of the legitimacy, ESET may have already done that for you. ;)

 

Additional: Menus are trees in the top right corner; Detail is the level of informative information that it is given back to you about your system. Full Recommended.

 

CylanceSvc.exe

MD5: 7ac02ce56c0db3d9356a2a53302b55e6
SHA1: ccff110a4d4c19354e7e50b85a0d96f8ffaab530
SHA256: 8fb025816f6a9bf8e4c0ddb1199cc33c890db724cb7b2c6aff1a93bbe95a6031

 

CylanceUI.exe

MD5: 8d69edcedbc0a2a39f72a09fda25aabd
SHA1: 3f18fe03d80d5d01d113e88d266fbd17afda5bba
SHA256: b20d6a9a73ac7c71764dd2dafaa5762fd227b64df2e76c366a16414e3f949486

 

 

 

 

Thanks for reading :D

 

post-1101-0-73514400-1383185823_thumb.jpg

post-1101-0-99616300-1383185850_thumb.jpg

post-1101-0-16912900-1383185865_thumb.jpg

post-1101-0-86152700-1383185896_thumb.jpg

Edited by Arakasi
Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...