View Full Version : testing v4
ugly
December 21st, 2008, 11:04 AM
If , during install, I choose to perform program component update I get nothing in the next window.
204955
If I use advanced heuristics for real-time protection but without AH on execution when I try to run an application I get 100% CPU for a long time and an frozen PC.
204958
204957
With AH disabled for real-time protection everything is OK.
I did not get this with v3 even if I had enabled AH in real-time.
Marcos
December 21st, 2008, 03:10 PM
-{ Quote: "With AH disabled for real-time protection everything is OK.
I did not get this with v3 even if I had enabled AH in real-time." }-
Maybe the application copies some files which are then scanned by AH. You could check this using Process monitor.
ugly
December 22nd, 2008, 10:55 AM
All I wanted to point is that I don't have the same behavior with v3 cofigured like here (http://www.wilderssecurity.com/showpost.php?p=1162111&postcount=50) when starting different applications. So , if nothing changed much in v4 , something is wrong.
ESS3
December 22nd, 2008, 12:54 PM
It, likely, a file or a virus processed: Protector, Crypter, packed.
=>Statistics=>antivirus and antisryware protection: we look often appearing, a file.
We delete a file, if it not the good.
I processed a file :
Protector, Crypter, packed, for concealment maiware, and is very frequent on such files, terrible brakes, but mine CPU to load and on 50 % it will not turn out :P
Excuse, I use the automatic translator. It can be not clear.
I from Moscow.:)
ugly
January 8th, 2009, 03:11 PM
Is ESET aware that it has problemes with AH in real-time and launching some aplications ( not only with wmp11- yes...a windows element...very important -resolved in another thread) ?
funkydude
January 8th, 2009, 06:58 PM
It's with the way specific files are packed, the best thing is to find the files and report the problem to ESET. That improves things for everyone. Remember for all it's worth advanced heuristics is really a "beta" module, being off by default. I was patient enough to find out the file causing my problem, they fixed it and I've never had problems since. It's also nice knowing you've fixed the problem for potentially thousands of other users. Unfortunately some people don't have the time/experience to find the file causing the problem.
ugly
January 9th, 2009, 09:49 AM
-{ Quote: "If I use advanced heuristics for real-time protection but without AH on execution when I try to run an application I get 100% CPU for a long time and an frozen PC.
204958
204957
With AH disabled for real-time protection everything is OK.
I did not get this with v3 even if I had enabled AH in real-time." }-
All this happened trying to lunch Advanced Uninstaller Pro 9.1 on XP Pro. SP3 with real-time AH enabled.
Can't say the scanner stops on a certain file for a long time. Just a frozen PC for a while ......
funkydude
January 9th, 2009, 10:35 AM
Without AH on execution doesn't fix anything if it's on in real time. Advice has been given on how to try solve the problem. It's something only you can do.
ugly
January 9th, 2009, 01:37 PM
-{ Quote: " It's something only you can do." }-
I don't think so.
I've installed on my machine and reported something wrong.
ESET should do anything they have to and resolve their product bug.
funkydude
January 9th, 2009, 02:45 PM
They can't resolve a product bug if you don't help them. Sorry, but so far you have provided 0 useful information.
Marcos
January 10th, 2009, 01:57 AM
We're not aware of any bug re. advanced heuristics. Of course, enabling it on access may cause delays when running certain applications, that's why a warning is displayed when the user attempts to activate this feature. In the case of widely used and popular applications, we can whitelist them directly in the engine, otherwise you can exclude such application from scanning or disable AH on file access/execution.
ugly
January 10th, 2009, 12:49 PM
-{ Quote: "We're not aware of any bug re. advanced heuristics. Of course, enabling it on access may cause delays when running certain applications, that's why a warning is displayed when the user attempts to activate this feature. In the case of widely used and popular applications, we can whitelist them directly in the engine, otherwise you can exclude such application from scanning or disable AH on file access/execution." }-
Thank you for your answer.
I'll put that on exclusion.
ugly
January 17th, 2009, 09:50 AM
When web antivirus founds something nasty you get not 1 warning pop up but 5.
IMO this is very annoying. This behavior is present both in V3 and V4.(if I remember well , when beta-testing v3 ,Marco's answer was the browser is trying to download that multiple times so you will get multiple warnings)
But......with any other product I've used (kas.,avira,norton..) will have just one warning and ,of course, a terminated connection. I think this the right way to do it.
Maybe something like in NOD32 when IMON gives you a nice red warning in the page and that was all.
funkydude
January 17th, 2009, 10:53 AM
Could you provide screenshots? I've only ever had 1 warning (the small non-intrusive window at the corner of the screen that appears for a few sec)
wrathchild
January 17th, 2009, 11:26 AM
-{ Quote: "When web antivirus founds something nasty you get not 1 warning pop up but 5." }-
Same here...exactly 5 popups (tried with eicar test file) :thumbd:
-{ Quote: "Could you provide screenshots?" }-
maybe movie clip but screenshot hardly ;)
Marcos
January 17th, 2009, 11:49 AM
-{ Quote: "with any other product I've used (kas.,avira,norton..) will have just one warning and ,of course, a terminated connection. I think this the right way to do it.
Maybe something like in NOD32 when IMON gives you a nice red warning in the page and that was all." }-
This should happen if you switch the browser to active mode. In such case, the browser doesn't receive individual packets, but the whole file at once. If the last packet is blocked, the browser tries to download it again several times.
wrathchild
January 17th, 2009, 12:01 PM
-{ Quote: "This should happen if you switch the browser to active mode." }-
No active mode.
Marcos
January 17th, 2009, 12:29 PM
I've just tried to download eicar with Opera. With Opera set to active mode, an alert html page was displayed and an alert bubble appeared only once. When set to passive mode, I got several warnings as Opera was trying to download the last missing packet several times.
ugly
January 17th, 2009, 04:39 PM
-{ Quote: "I've just tried to download eicar with Opera. With Opera set to active mode, an alert html page was displayed and an alert bubble appeared only once. When set to passive mode, I got several warnings as Opera was trying to download the last missing packet several times." }-
You are right. If the browser is in active mode you get one alert bubble and a warning red page. But the active mode do impact the browsing speed.
For me the ideal it seems to be one warning in passive mode but that ,I presume, it is not possible.
Thank you again!
funkydude
January 17th, 2009, 07:36 PM
So this is limited to Opera?
Marcos
January 18th, 2009, 02:05 AM
-{ Quote: "So this is limited to Opera?" }-
The same holds true for any browser that attempts several times to complete download if the last packet is blocked by Eset's products.
wrathchild
January 18th, 2009, 07:29 AM
@Marcos
Is there a possibility for implementing some sort of anti flood for pop-up messages?
funkydude
January 18th, 2009, 07:48 AM
-{ Quote: "The same holds true for any browser that attempts several times to complete download if the last packet is blocked by Eset's products.
" }-
So what's the plan now?
ugly
January 20th, 2009, 02:13 AM
After uninstall "ESET Antispam" folder remain in Outlook Express and I have to manually delete it.
205618
ugly
January 22nd, 2009, 02:25 PM
After reinstall ekrn.exe gives me a 100% CPU with no obvious reason.
Restarting solved the problem.
ugly
February 19th, 2009, 01:40 AM
-{ Quote: "If , during install, I choose to perform program component update I get nothing in the next window.
204955
" }-
Solved in RC ! ;D
If I choose that I get "Automatic". :thumb:
ugly
February 19th, 2009, 01:54 AM
-{ Quote: "After uninstall "ESET Antispam" folder remain in Outlook Express and I have to manually delete it.
205618" }-
Still there in RC. :'(
But the uninstall process is much faster then before .
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums