molojavy 0 Posted November 16 Share Posted November 16 Is my PC compromised? NT Kernel & System Multicast ping from 1.0.168.192 Hostname: node-81s.pool-1-0.dynamic.totinternet.net. Quote Link to comment Share on other sites More sharing options...
Administrators Marcos 4,935 Posted November 16 Administrators Share Posted November 16 Please provide logs with ESET Log Collector. Quote Link to comment Share on other sites More sharing options...
molojavy 0 Posted November 16 Author Share Posted November 16 29 minutes ago, Marcos said: Please provide logs with ESET Log Collector. My logs essp_logs.zip Quote Link to comment Share on other sites More sharing options...
itman 1,630 Posted November 16 Share Posted November 16 (edited) Strange that what appears to be a residential ISP provider in Thailand is pinging you; Also, your router firewall should be blocking this ping activity on the WAN-side of the router. Edited November 16 by itman Quote Link to comment Share on other sites More sharing options...
molojavy 0 Posted November 16 Author Share Posted November 16 3 hours ago, itman said: Strange that what appears to be a residential ISP provider in Thailand is pinging you; Also, your router firewall should be blocking this ping activity on the WAN-side of the router. This is really strange, thats why im asking for help or opinion. My first thought was that i have a reverse shell or something like that... But im not specialist at stuff like that... Quote Link to comment Share on other sites More sharing options...
Solution itman 1,630 Posted November 16 Solution Share Posted November 16 (edited) Since Eset is blocking inbound ping activity, I would say you're not infected. Also, ping activity from external sources is expected since hackers are always looking for targets. Again, you should check out your router firewall and make sure its configured properly. It it where you want this ping activity to be dropped at. Edited November 16 by itman Quote Link to comment Share on other sites More sharing options...
itman 1,630 Posted November 16 Share Posted November 16 (edited) You might also be the target of a Ping (ICMP) Flood attack: https://www.radware.com/security/ddos-knowledge-center/ddospedia/icmp-flood/ since you state this activity is occurring on a continuing basis. Eset IDS doesn't detect this attack as best as I can determine. Again, most router firewalls should. You can create an Eset firewall rule to block all inbound network traffic from remote IP address,1.0.168.192. However, this won't prevent your network bandwidth being saturated with these requests. Edited November 16 by itman Quote Link to comment Share on other sites More sharing options...
Administrators Marcos 4,935 Posted November 16 Administrators Share Posted November 16 By the way, you are using a license from Sri Lanka which was misused and is one of those that were seen sold to numerous users, typically for a dumping price. I'd suggest contacting the seller, asking for a refund and purchasing a regular license from an authorized ESET distributor or reseller. Quote Link to comment Share on other sites More sharing options...
molojavy 0 Posted November 16 Author Share Posted November 16 6 minutes ago, Marcos said: By the way, you are using a license from Sri Lanka which was misused and is one of those that were seen sold to numerous users, typically for a dumping price. I'd suggest contacting the seller, asking for a refund and purchasing a regular license from an authorized ESET distributor or reseller. Thanks for the information. Do i have no right to use it? Am i gonna loose my license now? Quote Link to comment Share on other sites More sharing options...
molojavy 0 Posted November 16 Author Share Posted November 16 22 minutes ago, Marcos said: By the way, you are using a license from Sri Lanka which was misused and is one of those that were seen sold to numerous users, typically for a dumping price. I'd suggest contacting the seller, asking for a refund and purchasing a regular license from an authorized ESET distributor or reseller. May I ask you to provide me a additional information about the licence issue? Because i would like to clear this situation. And any official information from ESET gonna help me. Quote Link to comment Share on other sites More sharing options...
Administrators Marcos 4,935 Posted November 16 Administrators Share Posted November 16 The license is registered to soxxxxxxxxxxxx99@hotmail.com from Sri Lanka. Quote Link to comment Share on other sites More sharing options...
molojavy 0 Posted November 16 Author Share Posted November 16 7 minutes ago, Marcos said: The license is registered to from Sri Lanka. Many thanks for your time. Just one last question, are we talking about license until 13.10.2024? One year/One PC? And im really sorry for asking so many questions. Quote Link to comment Share on other sites More sharing options...
Administrators Marcos 4,935 Posted November 16 Administrators Share Posted November 16 Yes, the public license ID: 3A9-AN4-VSH, reseller: DCS International Private Limited (shop.eset.lk), expiration date: 10/13/2024. Registered to person: Sxxxxxh Gxxxxxi Quote Link to comment Share on other sites More sharing options...
molojavy 0 Posted November 16 Author Share Posted November 16 2 minutes ago, Marcos said: Yes, the public license ID: 3A9-AN4-VSH, reseller: DCS International Private Limited (shop.eset.lk), expiration date: 10/13/2024. Many thanks, i already issued a refund. Do you need the seller information, or copy of my transaction? Quote Link to comment Share on other sites More sharing options...
Administrators Marcos 4,935 Posted November 16 Administrators Share Posted November 16 Yes, you can provide information about the seller. It's possible that their website is blocked by ESET. Quote Link to comment Share on other sites More sharing options...
molojavy 0 Posted November 16 Author Share Posted November 16 1 minute ago, Marcos said: Yes, you can provide information about the seller. It's possible that their website is blocked by ESET. Sure, i need a couple of minutes to make all screenshots and prepare some links. Quote Link to comment Share on other sites More sharing options...
molojavy 0 Posted November 16 Author Share Posted November 16 25 minutes ago, Marcos said: Yes, you can provide information about the seller. It's possible that their website is blocked by ESET. https://www.kinguin.net/category/74559/eset-smart-security-premium-key-1-year-1-pc Softgenuinkeys Quote Link to comment Share on other sites More sharing options...
itman 1,630 Posted November 16 Share Posted November 16 (edited) 30 minutes ago, Marcos said: It's possible that their website is blocked by ESET This web site, shop.eset.lk, is not blocked by Eset. What is interesting is Sir Lanka link from Eset authorized partner web site won't render in Firefox. Edited November 16 by itman Quote Link to comment Share on other sites More sharing options...
itman 1,630 Posted November 16 Share Posted November 16 7 minutes ago, molojavy said: https://www.kinguin.net/category/74559/eset-smart-security-premium-key-1-year-1-pc The "give away" on this web site is the price; way to low, and that the license is not region locked. Quote Link to comment Share on other sites More sharing options...
molojavy 0 Posted November 16 Author Share Posted November 16 3 minutes ago, itman said: The "give away" on this web site is the price; way to low, and that the license is not region locked. Yeah... This was my first and last time been so stupid and purchase on this kind of sites... Quote Link to comment Share on other sites More sharing options...
molojavy 0 Posted November 16 Author Share Posted November 16 (edited) 46 minutes ago, Marcos said: Yes, you can provide information about the seller. It's possible that their website is blocked by ESET. Sir, can I kindly ask you to provide me a trial licence as an exception until my case is clear? Because I need to delete this stolen licence from my account. Edited November 16 by molojavy Misspellings Quote Link to comment Share on other sites More sharing options...
Administrators Marcos 4,935 Posted November 17 Administrators Share Posted November 17 4 hours ago, itman said: This web site, shop.eset.lk, is not blocked by Eset. This belongs to an authorized distributor and it's the issuer of the license, not the seller. Kinguin.net is an online market where virtually everybody can sell goods. It's not a website that would sell ESET and other software directly. Quote Link to comment Share on other sites More sharing options...
Administrators Marcos 4,935 Posted November 17 Administrators Share Posted November 17 3 hours ago, molojavy said: Sir, can I kindly ask you to provide me a trial licence as an exception until my case is clear? Because I need to delete this stolen licence from my account. It is possible to activate a fully functional 30-day trial license after installation which you can use in the mean time. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.