Jump to content

Recommended Posts

Posted

ESET Blocking Chrome Metamask Extension Download

Today, my Metamask extension randomly corrupted on Chrome.

I tried to reinstall the extension, but now ESET is repeatedly blocking it for being a "suspicious file." It does the same when trying to add it to Brave.

I ran multiple scans & nothing has come up. I also additionally am able to use Metamask just fine on Firefox. 

I know I can simply un-quarantine the file on ESET, but I am concerned as to why this warning is coming up. I also had my boyfriend, who is on the same network and ESET license, try to download the extension, and it worked with no issue for him.

  • Administrators
Posted

I was unable to reproduce it with Chrome. Was a threat detected after you've added the extension?

image.png

Posted

Yes - every time I remove the extension and then re-add it, the threat comes back up. 

image.thumb.png.de9080c17a28968fcb39a9ea0543b98a.png

 

 

Posted

Clear your Chrome browser cache. Then install legit Metamask extension from Chrome store.

My best guess is Chrome is loading a bogus Metamask extension from its cache.

Posted
Just now, itman said:

Clear your Chrome browser cache. Then install legit Metamask extension from Chrome store.

My best guess is Chrome is loading a bogus Metamask extension from its cache.

I've cleared my cache and confirmed it's the legit link - still not working. I also cannot add the extension to any other browser (i.e. Brave).

Posted
4 minutes ago, itman said:

Clear your Chrome browser cache. Then install legit Metamask extension from Chrome store.

My best guess is Chrome is loading a bogus Metamask extension from its cache.

I also forgot to note that I even tried this on a completely fresh Chrome profile - no cache, no previous browsing history, etc. - still the same issue.

Posted
1 minute ago, itman said:

The next possibility is malware somehow is trying to load a bogus Metamask extension from a prior downloaded file on your disk: https://www.gtricks.com/chrome/how-to-manually-download-and-install-chrome-extensions/ . Since Brave is based on Chrome, I assume it also allows extensions to be manually loaded.

I've ran several scans with both ESET and Malwarebytes and both are returning nothing. How could I potentially find this file?

Posted (edited)
4 minutes ago, Stina said:

I've ran several scans with both ESET and Malwarebytes and both are returning nothing. How could I potentially find this file?

If the file is packed, encrypted, etc.., the code won't manifest until loaded into memory at which time is when Eset detects it.

Edited by itman
Posted
9 minutes ago, itman said:

If the file is packed, encrypted, etc.., the code won't manifest until loaded into memory at which time is when Eset detects it.

So at this point I just wait?

Posted

I've had this from two separate machines tonight.. Can anyone test Brave with Metamask and ESET and see if this is a false positive perhaps?

Posted

This is the same thing I am seeing. I did a quick screen capture. No it's not synched up I couldn't figure out how to record to separate windows at the same time. So I recorded the chrome extension window and the ESET window separately and cut them together.

 

Posted

This definitely appears to be an ESET issue btw - I whitelisted the file and re-downloaded it with no issues and no threats.

Posted

Appears I am not the only one!

 

 

  • Administrators
Posted
9 hours ago, Stina said:

Yes - every time I remove the extension and then re-add it, the threat comes back up.

Please provide logs collected with ESET Log Collector.

Posted

Hello,

I am in the same situation as. Since yesterday morning, eset has detected the metamask extension as a suspicious object

  • Administrators
Posted
4 hours ago, Daarky0 said:

I am in the same situation as. Since yesterday morning, eset has detected the metamask extension as a suspicious object

Please do as requested in my post above and provide ELC logs.

Posted
15 hours ago, Stina said:

Yes - every time I remove the extension and then re-add it, the threat comes back up. 

image.thumb.png.de9080c17a28968fcb39a9ea0543b98a.png

 

 

I provided logs here. I already resolved the issue by just adding the file to list of exceptions because frankly I knew it was a bug

  • Administrators
Posted
35 minutes ago, Stina said:

I provided logs here. I already resolved the issue by just adding the file to list of exceptions because frankly I knew it was a bug

I see only screenshots you've posted, not logs collected with ESET Log Collector which are needed since I'm unable to reproduce the detection by adding the said browser extension.

Posted
1 hour ago, Marcos said:

Please do as requested in my post above and provide ESET Log Collector logs.

I can't create a support ticket with logs because the max upload is 21 mb, my zip have 51 mb 

  • Administrators
Posted

The limit for uploaded files here in the forum is 100MB. If the generated archive is bigger upload it to a file sharing service, such as OneDrive, Dropbox, etc. and drop me a private message with a download link.

Posted

I figured out how to do display capture in OBS. So you see the true effect of the situation. I hesitate to use the "fix" of ignore the file. I understand that will work, but not knowing why this is occuring makes me wonder if there is indeed an issue.

On another note, For some unknown reason the "primary" display appears kind of shaded in OBS compared to the secondary other one.

Posted

Same problem here since 8 hours ago: Eset is treating Metamask files as  suspicious.
No workaround here, sadly 

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...