Jump to content

LiveGrid servers cannot be reached


Recommended Posts

Hello,

Today 1 of my computers started giving me intermittent errors about livegrid servers being available, i tested all the hostnames on the support page, they are all reachable via http or port 53535.

The first time around, it didnt detect cloudcar.exe, then after a reboot it started detecting that, even though its still giving errors about servers not being reachable. There is another computer on the same network with no such issues, so its not my network firewall.

I do have a fairly aggressive ESET firewall setup here, block all incoming and ask for all outgoing, but that never proved an issue with this before.
I also checked and there are no deny rules for any eset service.

 

Im starting to worry that its malware causing this behaviour, but i checked the running processes and they all have a fine reputation, aswell as ran sysinpector and saw nothing out of the ordinary that i couldn't explain or verify in drivers, scheduled tasks, and running processes.

 

What could be causing this?

Link to comment
Share on other sites

I also noticed with diagnostics dump, that there is some weird DNS shenanigans going on...

23.11.2021 17:04:13.456 [3504:6092] ERROR [RESOLV] <dns_resolver>: Failed to get new name server addresses (error: 7013)
23.11.2021 17:04:15.757 [3504:6092] DEBUG [RESOLV] <dns_resolver>: Obtained 1 system DNS addresses
23.11.2021 17:04:15.757 [3504:6092] DEBUG [RESOLV] <dns_resolver>: New name server '192.168.0.1' configured
23.11.2021 17:04:15.757 [3504:6092] DEBUG [RESOLV] <dns_resolver>: New name server '8.8.8.8' already configured
23.11.2021 17:04:15.757 [3504:6092] DEBUG [RESOLV] <dns_resolver>: New name server '8.8.4.4' already configured
23.11.2021 17:04:15.757 [3504:6092] INFO [RESOLV] <dns_resolver>: New name servers set (count: 3)
23.11.2021 17:04:15.782 [3504:6092] DEBUG [RESOLV] <dns_resolver>: Obtained 1 system DNS addresses
23.11.2021 17:04:15.782 [3504:6092] DEBUG [RESOLV] <dns_resolver>: New name server '192.168.0.1' already configured
23.11.2021 17:04:15.782 [3504:6092] DEBUG [RESOLV] <dns_resolver>: New name server '8.8.8.8' already configured
23.11.2021 17:04:15.782 [3504:6092] DEBUG [RESOLV] <dns_resolver>: New name server '8.8.4.4' already configured
23.11.2021 17:04:15.782 [3504:6092] INFO [RESOLV] <dns_resolver>: New name servers set (count: 3)
23.11.2021 17:04:15.866 [3504:6092] DEBUG [RESOLV] <dns_resolver>: Obtained 1 system DNS addresses
23.11.2021 17:04:15.866 [3504:6092] DEBUG [RESOLV] <dns_resolver>: New name server '192.168.0.1' already configured
23.11.2021 17:04:15.866 [3504:6092] DEBUG [RESOLV] <dns_resolver>: New name server '8.8.8.8' already configured
23.11.2021 17:04:15.866 [3504:6092] DEBUG [RESOLV] <dns_resolver>: New name server '8.8.4.4' already configured

No idea where it would be getting googles dns servers from, my system DNS is my router (192.168.0.1) and my router uses cloudflares DNS.

 

Then the other dump iris.dc.log is filled with

23.11.2021 16:32:51.315 [3504:4808] ERROR [DC] <dc_connector>: [AVCLOUD] Resolving hostname '' failed (error: 10004 INVALID_PARAM)
23.11.2021 16:32:51.315 [3504:4808] ERROR [DC] <dc_connector>: [AVCLOUD] Resolving failed; No cache available
23.11.2021 16:32:51.315 [3504:4808] ERROR [DC] <dc_client>: [type: AVCLOUD, channel: HTTP] SendAndReceive failed: no connection (error: 19)
23.11.2021 16:32:51.315 [3504:4808] ERROR [DC] AvCloud resolve failed: internal resolve failed (result: 21202)
23.11.2021 16:34:51.317 [3504:4808] ERROR [DC] <dc_client>: [type: AVCLOUD, channel: HTTP] SendAndReceive failed: offline
23.11.2021 16:34:51.317 [3504:4808] ERROR [DC] AvCloud resolve failed: internal resolve failed (result: 19061)
23.11.2021 16:36:51.325 [3504:4808] ERROR [DC] <dc_client>: [type: AVCLOUD, channel: HTTP] SendAndReceive failed: offline
23.11.2021 16:36:51.325 [3504:4808] ERROR [DC] AvCloud resolve failed: internal resolve failed (result: 19061)
23.11.2021 16:36:51.325 [3504:4808] ERROR [DC] <dc_client>: [type: AVCLOUD, channel: HTTP] SendAndReceive failed: offline
23.11.2021 16:36:51.325 [3504:4808] ERROR [DC] AvCloud resolve failed: internal resolve failed (result: 19061)
23.11.2021 16:38:51.325 [3504:4808] ERROR [DC] <dc_connector>: [AVCLOUD] Resolving hostname '' failed (error: 10004 INVALID_PARAM)
23.11.2021 16:38:51.325 [3504:4808] ERROR [DC] <dc_connector>: [AVCLOUD] Resolving failed; No cache available
23.11.2021 16:38:51.325 [3504:4808] ERROR [DC] <dc_client>: [type: AVCLOUD, channel: HTTP] SendAndReceive failed: no connection (error: 19)
23.11.2021 16:38:51.325 [3504:4808] ERROR [DC] AvCloud resolve failed: internal resolve failed (result: 21202)
23.11.2021 16:40:51.337 [3504:4808] ERROR [DC] <dc_client>: [type: AVCLOUD, channel: HTTP] SendAndReceive failed: offline
23.11.2021 16:40:51.337 [3504:4808] ERROR [DC] AvCloud resolve failed: internal resolve failed (result: 19061)
23.11.2021 16:42:51.351 [3504:4808] ERROR [DC] <dc_client>: [type: AVCLOUD, channel: HTTP] SendAndReceive failed: offline
23.11.2021 16:42:51.351 [3504:4808] ERROR [DC] AvCloud resolve failed: internal resolve failed (result: 19061)
23.11.2021 16:43:20.865 [3504:8284] ERROR [DC] <dc_client>: [type: AVCLOUD, channel: HTTP] SendAndReceive failed: offline
23.11.2021 16:43:20.865 [3504:8284] ERROR [DC] AvCloud resolve failed: internal resolve failed (result: 19061)
23.11.2021 16:43:20.865 [3504:8284] ERROR [DC] <dc_client>: [type: AVCLOUD, channel: HTTP] SendAndReceive failed: offline
23.11.2021 16:43:20.865 [3504:8284] ERROR [DC] AvCloud resolve failed: internal resolve failed (result: 19061)
23.11.2021 16:43:20.899 [3504:8284] ERROR [DC] <dc_client>: [type: AVCLOUD, channel: HTTP] SendAndReceive failed: offline
23.11.2021 16:43:20.899 [3504:8284] ERROR [DC] AvCloud resolve failed: internal resolve failed (result: 19061)
23.11.2021 16:43:20.899 [3504:8284] ERROR [DC] <dc_client>: [type: AVCLOUD, channel: HTTP] SendAndReceive failed: offline

Which to me seeems its trying to resolve an empty hostname ' ' ?
Then it just magicly starts resolving normally again, bearing in mindd that it resolves fine for me by nslookup, ping, firefox what have you.

Link to comment
Share on other sites

55 minutes ago, Marcos said:

Could you check if re-configuring the router to use Google DNS servers makes a difference?

Hi, thank you for the swift response, i will, as soon as it acts up again. However just to be clear, its been this same configuration for years now without any issues, maybe google DNS servers are acting up today?

Also, could you give me any idea as to where ESET is getting those DNS entries from? do you have googles DNS's hardcoded or is something interfering with ESET?

Thanks again!

Link to comment
Share on other sites

On 11/23/2021 at 5:28 PM, Marcos said:

Could you check if re-configuring the router to use Google DNS servers makes a difference?

I tried, it didn't make a difference. I noticed it gets fixed if i sleep and wake the PC.

Adding a bit more logs:

24.11.2021 16:58:14.461 [3688:1188] DEBUG [RESOLV] <dns_resolver>: Question [name: avcloud.e5.sk, type: A] resolving finished; record found in cache
24.11.2021 16:58:14.498 [3688:1188] DEBUG [RESOLV] <dns_resolver>: Question [name: avcloud.e5.sk, type: A] resolving finished; record found in cache
24.11.2021 16:58:14.512 [3688:1188] DEBUG [RESOLV] <dns_resolver>: Question [name: avcloud.e5.sk, type: A] resolving finished; record found in cache
24.11.2021 19:49:20.850 [3688:10304] ERROR [RESOLV] <dns_resolver>: Failed to get new name server addresses (error: 7013)
24.11.2021 19:49:20.885 [3688:10304] ERROR [RESOLV] <dns_resolver>: Failed to get new name server addresses (error: 7013)
24.11.2021 19:49:20.905 [3688:10304] ERROR [RESOLV] <dns_resolver>: Failed to get new name server addresses (error: 7013)
24.11.2021 19:49:20.917 [3688:10304] ERROR [RESOLV] <dns_resolver>: Failed to get new name server addresses (error: 7013)
24.11.2021 19:49:33.018 [3688:10304] ERROR [RESOLV] <dns_resolver>: Failed to get new name server addresses (error: 7013)
24.11.2021 19:49:33.029 [3688:10304] ERROR [RESOLV] <dns_resolver>: Failed to get new name server addresses (error: 7013)
24.11.2021 19:49:33.094 [3688:10304] ERROR [RESOLV] <dns_resolver>: Failed to get new name server addresses (error: 7013)
24.11.2021 19:49:33.159 [3688:10304] ERROR [RESOLV] <dns_resolver>: Failed to get new name server addresses (error: 7013)
24.11.2021 19:49:33.178 [3688:10304] ERROR [RESOLV] <dns_resolver>: Failed to get new name server addresses (error: 7013)
24.11.2021 19:49:33.191 [3688:10304] ERROR [RESOLV] <dns_resolver>: Failed to get new name server addresses (error: 7013)
24.11.2021 19:49:51.444 [3688:19640] DEBUG [RESOLV] <dns_resolver>: Question [name: i4.c.eset.com, type: A] record not found in cache
24.11.2021 19:49:51.444 [3688:19640] ERROR [RESOLV] <dns_nameserver>: [8.8.4.4]: Question [name: i4.c.eset.com, type: A] UDP send failed (nod error: 1)
24.11.2021 19:49:51.470 [3688:19640] DEBUG [RESOLV] <dns_resolver>: Name server '8.8.8.8' state reset
24.11.2021 19:49:51.470 [3688:19640] INFO [RESOLV] <dns_resolver>: Name server list prioritized: 8.8.8.8, 8.8.4.4, 192.168.0.1
24.11.2021 19:49:51.470 [3688:19640] INFO [RESOLV] <dns_rr_cache>: Record [name: i4.c.eset.com, type: CNAME] [=>i4.cwip.eset.com] inserted to cache [TTL: 13829]
24.11.2021 19:49:51.470 [3688:19640] INFO [RESOLV] <dns_rr_cache>: Record [name: i4.cwip.eset.com, type: A] inserted to cache [items: 2, TTL: 11]
24.11.2021 19:49:57.603 [3688:19640] DEBUG [RESOLV] <dns_resolver>: Question [name: i1.cwip.eset.com, type: A] record not found in cache
24.11.2021 19:49:57.648 [3688:19640] INFO [RESOLV] <dns_rr_cache>: Record [name: i1.cwip.eset.com, type: A] inserted to cache [items: 1, TTL: 6]
24.11.2021 19:50:15.639 [3688:11904] DEBUG [RESOLV] <dns_resolver>: Question [name: i4.cwip.eset.com, type: A] record not found in cache
24.11.2021 19:50:15.667 [3688:11904] INFO [RESOLV] <dns_rr_cache>: Record [name: i4.cwip.eset.com, type: A] inserted to cache [items: 1, TTL: 16]
24.11.2021 19:50:20.808 [3688:11904] DEBUG [RESOLV] <dns_resolver>: Question [name: i3.cwip.eset.com, type: A] record not found in cache
24.11.2021 19:50:20.834 [3688:11904] INFO [RESOLV] <dns_rr_cache>: Record [name: i3.cwip.eset.com, type: A] inserted to cache [items: 1, TTL: 10]
24.11.2021 19:56:39.541 [3688:16116] DEBUG [RESOLV] <dns_resolver>: Question [name: avcloud.e5.sk, type: A] record not found in cache
24.11.2021 19:56:39.583 [3688:16116] INFO [RESOLV] <dns_rr_cache>: Record [name: avcloud.e5.sk, type: A] inserted to cache [items: 2, TTL: 5]
24.11.2021 19:56:39.611 [3688:16116] DEBUG [RESOLV] <dns_resolver>: Question [name: avcloud.e5.sk, type: A] resolving finished; record found in cache
24.11.2021 19:56:39.638 [3688:16116] DEBUG [RESOLV] <dns_resolver>: Question [name: avcloud.e5.sk, type: A] resolving finished; record found in cache
.11.2021 16:58:14.476 [3688:1188] DEBUG [DC] AvCloud resolve succeeded (response size: 128)
24.11.2021 16:58:14.512 [3688:1188] DEBUG [DC] AvCloud resolve succeeded (response size: 126)
24.11.2021 16:58:14.526 [3688:1188] DEBUG [DC] AvCloud resolve succeeded (response size: 133)
24.11.2021 19:49:51.470 [3688:19640] INFO [DC] <dc_connector>: [AVCLOUD] Resolved '91.228.167.46' (initial, TTL: 311)
24.11.2021 19:49:51.714 [3688:19640] DEBUG [DC] AvCloud resolve succeeded (response size: 233284)
24.11.2021 19:49:57.648 [3688:19640] INFO [DC] <dc_connector>: [AVCLOUD] Resolved '38.90.226.13' (initial, TTL: 306)
24.11.2021 19:49:58.057 [3688:19640] DEBUG [DC] AvCloud resolve succeeded (response size: 573)
24.11.2021 19:50:15.667 [3688:11904] INFO [DC] <dc_connector>: [AVCLOUD] Resolved '38.90.226.13' (initial, TTL: 316)
24.11.2021 19:50:16.667 [3688:11904] DEBUG [DC] AvCloud resolve succeeded (response size: 131948)
24.11.2021 19:50:20.834 [3688:11904] INFO [DC] <dc_connector>: [AVCLOUD] Resolved '38.90.226.11' (initial, TTL: 310)
24.11.2021 19:50:21.260 [3688:11904] DEBUG [DC] AvCloud resolve succeeded (response size: 1642)
24.11.2021 19:56:39.583 [3688:16116] INFO [DC] <dc_connector>: [AVCLOUD] Resolved '91.228.167.46' (changed from '91.228.166.52', TTL: 305)
24.11.2021 19:56:39.610 [3688:16116] DEBUG [DC] AvCloud resolve succeeded (response size: 126)
24.11.2021 19:56:39.611 [3688:16116] INFO [DC] <dc_client>: [type: AVCLOUD, channel: DIRECT_UDP] Secret exchange: started...
24.11.2021 19:56:39.638 [3688:16116] INFO [DC] <dc_client>: [type: AVCLOUD, channel: DIRECT_UDP] Secret exchange: done
24.11.2021 19:56:39.666 [3688:16116] DEBUG [DC] AvCloud resolve succeeded (response size: 128)
24.11.2021 20:01:55.724 [3688:18708] ERROR [DC] <dc_connector>: [AVCLOUD] Resolving hostname '' failed (error: 10004 INVALID_PARAM)
24.11.2021 20:01:55.724 [3688:18708] ERROR [DC] <dc_connector>: [AVCLOUD] Resolving failed; No cache available
24.11.2021 20:01:55.724 [3688:18708] ERROR [DC] <dc_client>: [type: AVCLOUD, channel: HTTP] SendAndReceive failed: no connection (error: 19)
24.11.2021 20:01:55.724 [3688:18708] ERROR [DC] AvCloud resolve failed: internal resolve failed (result: 21202)
24.11.2021 20:01:55.724 [3688:18708] ERROR [DC] <dc_connector>: [AVCLOUD] Resolving hostname '' failed (error: 10004 INVALID_PARAM)
24.11.2021 20:01:55.724 [3688:18708] ERROR [DC] <dc_connector>: [AVCLOUD] Resolving failed; No cache available
24.11.2021 20:01:55.724 [3688:18708] ERROR [DC] <dc_client>: [type: AVCLOUD, channel: HTTP] SendAndReceive failed: no connection (error: 19)
24.11.2021 20:01:55.724 [3688:18708] ERROR [DC] AvCloud resolve failed: internal resolve failed (result: 21202)
24.11.2021 20:01:55.826 [3688:18708] ERROR [DC] <dc_connector>: [AVCLOUD] Resolving hostname '' failed (error: 10004 INVALID_PARAM)
24.11.2021 20:01:55.826 [3688:18708] ERROR [DC] <dc_connector>: [AVCLOUD] Resolving failed; No cache available
24.11.2021 20:01:55.826 [3688:18708] INFO [DC] Channel HTTP state changed to: offline (caused by AVCLOUD request)
24.11.2021 20:01:55.826 [3688:18708] ERROR [DC] <dc_client>: [type: AVCLOUD, channel: HTTP] SendAndReceive failed: no connection (error: 19)
24.11.2021 20:01:55.826 [3688:18708] ERROR [DC] AvCloud resolve failed: internal resolve failed (result: 21202)
24.11.2021 20:01:55.826 [3688:18708] ERROR [DC] <dc_client>: [type: AVCLOUD, channel: HTTP] SendAndReceive failed: offline
24.11.2021 20:01:55.826 [3688:18708] ERROR [DC] AvCloud resolve failed: internal resolve failed (result: 19061)
24.11.2021 20:02:22.421 [3688:18708] ERROR [DC] <dc_client>: [type: AVCLOUD, channel: HTTP] SendAndReceive failed: offline
24.11.2021 20:02:22.421 [3688:18708] ERROR [DC] AvCloud resolve failed: internal resolve failed (result: 19061)
24.11.2021 20:02:22.421 [3688:18708] ERROR [DC] <dc_client>: [type: AVCLOUD, channel: HTTP] SendAndReceive failed: offline
24.11.2021 20:02:22.421 [3688:18708] ERROR [DC] AvCloud resolve failed: internal resolve failed (result: 19061)
24.11.2021 20:02:22.464 [3688:18708] ERROR [DC] <dc_client>: [type: AVCLOUD, channel: HTTP] SendAndReceive failed: offline
24.11.2021 20:02:22.464 [3688:18708] ERROR [DC] AvCloud resolve failed: internal resolve failed (result: 19061)
24.11.2021 20:02:22.464 [3688:18708] ERROR [DC] <dc_client>: [type: AVCLOUD, channel: HTTP] SendAndReceive failed: offline
24.11.2021 20:02:22.464 [3688:18708] ERROR [DC] AvCloud resolve failed: internal resolve failed (result: 19061)
24.11.2021 20:07:36.695 [3688:1756] ERROR [DC] <dc_connector>: [AVCLOUD] Resolving hostname '' failed (error: 10004 INVALID_PARAM)
24.11.2021 20:07:36.695 [3688:1756] ERROR [DC] <dc_connector>: [AVCLOUD] Resolving failed; No cache available
24.11.2021 20:07:36.695 [3688:1756] ERROR [DC] <dc_client>: [type: AVCLOUD, channel: HTTP] SendAndReceive failed: no connection (error: 19)
24.11.2021 20:07:36.695 [3688:1756] ERROR [DC] AvCloud resolve failed: internal resolve failed (result: 21202)
24.11.2021 20:07:36.695 [3688:1756] ERROR [DC] <dc_client>: [type: AVCLOUD, channel: HTTP] SendAndReceive failed: offline
24.11.2021 20:07:36.695 [3688:1756] ERROR [DC] AvCloud resolve failed: internal resolve failed (result: 19061)
24.11.2021 20:07:36.696 [3688:1756] ERROR [DC] <dc_client>: [type: AVCLOUD, channel: HTTP] SendAndReceive failed: offline
24.11.2021 20:07:36.696 [3688:1756] ERROR [DC] AvCloud resolve failed: internal resolve failed (result: 19061)
24.11.2021 20:07:36.735 [3688:1756] ERROR [DC] <dc_client>: [type: AVCLOUD, channel: HTTP] SendAndReceive failed: offline
24.11.2021 20:07:36.735 [3688:1756] ERROR [DC] AvCloud resolve failed: internal resolve failed (result: 19061)
24.11.2021 20:07:36.735 [3688:1756] ERROR [DC] <dc_client>: [type: AVCLOUD, channel: HTTP] SendAndReceive failed: offline
24.11.2021 20:07:36.735 [3688:1756] ERROR [DC] AvCloud resolve failed: internal resolve failed (result: 19061)
24.11.2021 20:07:51.959 [3688:1756] ERROR [DC] <dc_client>: [type: AVCLOUD, channel: HTTP] SendAndReceive failed: offline
24.11.2021 20:07:51.959 [3688:1756] ERROR [DC] AvCloud resolve failed: internal resolve failed (result: 19061)
24.11.2021 20:07:51.959 [3688:1756] ERROR [DC] <dc_client>: [type: AVCLOUD, channel: HTTP] SendAndReceive failed: offline
24.11.2021 20:07:51.959 [3688:1756] ERROR [DC] AvCloud resolve failed: internal resolve failed (result: 19061)
24.11.2021 20:07:51.996 [3688:1756] ERROR [DC] <dc_client>: [type: AVCLOUD, channel: HTTP] SendAndReceive failed: offline
24.11.2021 20:07:51.996 [3688:1756] ERROR [DC] AvCloud resolve failed: internal resolve failed (result: 19061)
24.11.2021 20:07:51.996 [3688:1756] ERROR [DC] <dc_client>: [type: AVCLOUD, channel: HTTP] SendAndReceive failed: offline
24.11.2021 20:07:51.996 [3688:1756] ERROR [DC] AvCloud resolve failed: internal resolve failed (result: 19061)

As you can see, it sometimes fails to get DNS servers, and sometimes its resolving fine, but then stops randomly.

Link to comment
Share on other sites

I just noticed something. 

I downloaded the eicarcom2.zip from eicar.org

When checking the file from the context menu in explorer, the Live Grid notification disappeared.

I tried to find a pattern on some other clients.

If I downloaded the Eicar.txt which was found instantly the Live Grid notification didn't disappear.

When I tried to download the cloudcar test file from amtso.org the file was detected and the notification disappeared.

 

At this moment I am out of test clients, but I get the feeling that the message disappears when Live Grid is actually used.

 

BTW. The notification (including an Proxy Server unreachable Notification) started after updating to

ESET Management Agent 9.0.2141.0
ESET PROTECT Server

9.0.2144.0

on the Server and 

ESET Management Agent 9.0.1141.0
ESET Endpoint Security 9.0.2032.2

on my clients

 

Edited by HSN-FK
working against German autocorrect...
Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...