Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus/Smart Security Beta
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old June 13th, 2011, 11:20 AM
ashishsingh1508's Avatar
ashishsingh1508 ashishsingh1508 is offline
Regular Poster
 
Join Date: May 2011
Location: Pune
Posts: 125
PixelPup Why not eset self protection protect these..?

Hi'
I can easily delete files in these folders or even folders by just pressing delete. I can even delete HIPS Rules. Why don't eset self protection protect these files also

"C:\Program Files\ESET\ESET NOD32 Antivirus\Drivers"
"C:\ProgramData\ESET\ESET NOD32 Antivirus"

In my opinion ESET should protect all files in the following folders

"C:\Program Files\ESET\ESET NOD32 Antivirus"
and
"C:\ProgramData\ESET\ESET NOD32 Antivirus"

I have to check registry entries for working of self protection.
I think thats why malware are able to disable ESET and remove.

Regards
Ashish Singh
  #2  
Old June 13th, 2011, 11:30 AM
toxinon12345's Avatar
toxinon12345 toxinon12345 is offline
Very Frequent Poster
 
Join Date: Sep 2010
Location: Managua, Nicaragua
Posts: 1,134
Default Re: Why not eset self protection protect these..?

Self defense is not active until the user reboot the system
__________________
Pentium M| 512 RAM
ESET NOD32 Antivirus 5
ESET Smart Security 6 RC
  #3  
Old June 13th, 2011, 11:37 AM
ESS3's Avatar
ESS3 ESS3 is offline
Regular Poster
 
Join Date: Dec 2007
Posts: 112
Default Re: Why not eset self protection protect these..?

HIPS rules can not be removed
__________________
ESET Smart Security 5 - The next generation of NOD32 Technology. ESET - Essential Security against Evolving Threats
Windows 7 x64 SP1. Moscow

Last edited by ESS3 : June 13th, 2011 at 11:47 AM.
  #4  
Old June 13th, 2011, 09:29 PM
ashishsingh1508's Avatar
ashishsingh1508 ashishsingh1508 is offline
Regular Poster
 
Join Date: May 2011
Location: Pune
Posts: 125
Default Re: Why not eset self protection protect these..?

Well I can delete all these files
Attached Thumbnails
Click image for larger version

Name:	Capture2.JPG
Views:	4
Size:	41.9 KB
ID:	227592  

  #5  
Old June 13th, 2011, 09:34 PM
funkydude's Avatar
funkydude funkydude is offline
Massive Poster
 
Join Date: Apr 2004
Posts: 5,988
Default Re: Why not eset self protection protect these..?

You can't delete anything in ProgramData without admin escalation. What exactly are you reporting?
__________________
OpenDNS with DNSCrypt

SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs
HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere
  #6  
Old June 13th, 2011, 09:35 PM
ashishsingh1508's Avatar
ashishsingh1508 ashishsingh1508 is offline
Regular Poster
 
Join Date: May 2011
Location: Pune
Posts: 125
Default Re: Why not eset self protection protect these..?

I can even delete the installer contained in it
  #7  
Old June 13th, 2011, 09:37 PM
ashishsingh1508's Avatar
ashishsingh1508 ashishsingh1508 is offline
Regular Poster
 
Join Date: May 2011
Location: Pune
Posts: 125
Default Re: Why not eset self protection protect these..?

Look I am using Outpost Firewall Pro 7.5 with nod32. Whenever I try to delete any file from outpost folder it gives me an error that it can't be done because of self protection. Why don't eset protect its files from deletion?
  #8  
Old June 13th, 2011, 09:50 PM
toxinon12345's Avatar
toxinon12345 toxinon12345 is offline
Very Frequent Poster
 
Join Date: Sep 2010
Location: Managua, Nicaragua
Posts: 1,134
Default Re: Why not eset self protection protect these..?

In my case i cannot delete those files because of self defense
__________________
Pentium M| 512 RAM
ESET NOD32 Antivirus 5
ESET Smart Security 6 RC
  #9  
Old June 14th, 2011, 11:36 AM
ashishsingh1508's Avatar
ashishsingh1508 ashishsingh1508 is offline
Regular Poster
 
Join Date: May 2011
Location: Pune
Posts: 125
Default Re: Why not eset self protection protect these..?

Today with ESET RC version installed from scratch I tried deleting this file
C:\ProgramData\ESET\ESET NOD32 Antivirus\Installer

And I could easily delete it
Also I can delete HIPS Rules .dat as well .xml file

is it normal ? Or these files are useless?
NOTE: I am using ESET Nod32 Antivirus 5 RC
  #10  
Old June 14th, 2011, 12:00 PM
toxinon12345's Avatar
toxinon12345 toxinon12345 is offline
Very Frequent Poster
 
Join Date: Sep 2010
Location: Managua, Nicaragua
Posts: 1,134
Default Re: Why not eset self protection protect these..?

I cannot reproduce that, eset denied me access to those files
__________________
Pentium M| 512 RAM
ESET NOD32 Antivirus 5
ESET Smart Security 6 RC
  #11  
Old June 14th, 2011, 02:27 PM
BoerenkoolMetWorst BoerenkoolMetWorst is offline
Very Frequent Poster
 
Join Date: Dec 2009
Location: Outer space
Posts: 2,053
Default Re: Why not eset self protection protect these..?

Quote:
Originally Posted by ashishsingh1508
Today with ESET RC version installed from scratch I tried deleting this file
C:\ProgramData\ESET\ESET NOD32 Antivirus\Installer

And I could easily delete it
Also I can delete HIPS Rules .dat as well .xml file

is it normal ? Or these files are useless?
NOTE: I am using ESET Nod32 Antivirus 5 RC
Have you restarted after installing the RC?
  #12  
Old June 14th, 2011, 10:33 PM
ashishsingh1508's Avatar
ashishsingh1508 ashishsingh1508 is offline
Regular Poster
 
Join Date: May 2011
Location: Pune
Posts: 125
Default Re: Why not eset self protection protect these..?

Yes of course. Most of the files are protected but not all...
  #13  
Old June 15th, 2011, 12:51 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,185
Default Re: Why not eset self protection protect these..?

Quote:
Originally Posted by ashishsingh1508
Yes of course. Most of the files are protected but not all...
Which aren't? Msi is merely the installer, it has no effect on security and deleting it won't make your computer vulnerable to malware attacks. As for the xml, I couldn't find any, be more specific please.
  #14  
Old June 15th, 2011, 08:31 AM
ashishsingh1508's Avatar
ashishsingh1508 ashishsingh1508 is offline
Regular Poster
 
Join Date: May 2011
Location: Pune
Posts: 125
Default Re: Why not eset self protection protect these..?

"Msi is merely the installer, it has no effect on security".

Why ?? It is needed for repair of eset.
Ok leave it I can delete all the files(only outside the folders) in the following folder
"C:\ProgramData\ESET\ESET NOD32 Antivirus"

File names are
EpfwUser.dat
HipsRules.dat
HipsRules.xml
httpblk.dat
local (database file)
__________________
ESET NOD32 Antivirus 5
Outpost Firewall Pro 7.5
Windows 7 Ultimate 32bits
  #15  
Old June 15th, 2011, 08:34 AM
ashishsingh1508's Avatar
ashishsingh1508 ashishsingh1508 is offline
Regular Poster
 
Join Date: May 2011
Location: Pune
Posts: 125
Default Re: Why not eset self protection protect these..?

Also all files in this folder

"C:\ProgramData\ESET\ESET NOD32 Antivirus\Stats"
"C:\ProgramData\ESET\ESET NOD32 Antivirus\Charon"
"C:\ProgramData\ESET\ESET NOD32 Antivirus\Logs"
"C:\ProgramData\ESET\ESET NOD32 Antivirus\Stats"

AND MOST IMPORTANT

"C:\ProgramData\ESET\ESET NOD32 Antivirus\Updfiles"

Regards
Ashish
__________________
ESET NOD32 Antivirus 5
Outpost Firewall Pro 7.5
Windows 7 Ultimate 32bits
  #16  
Old June 15th, 2011, 09:15 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,185
Default Re: Why not eset self protection protect these..?

None of the above are critical files. They are merely statistics, logs or update files that are downloaded during every update so amending them has no effect on program's functionality.
  #17  
Old June 15th, 2011, 12:23 PM
toxinon12345's Avatar
toxinon12345 toxinon12345 is offline
Very Frequent Poster
 
Join Date: Sep 2010
Location: Managua, Nicaragua
Posts: 1,134
Default Re: Why not eset self protection protect these..?

Quote:
Originally Posted by Marcos
None of the above are critical files. They are merely statistics, logs or update files that are downloaded during every update so amending them has no effect on program's functionality.
Hey Marcos, you are right, but seems files being critical in the %programdata% folder are HipsRules.???. After deleting and a restart, the manually created rules are no listed anymore in HIPS Rules Management.

This files (HipsRules.*) seems to need Self-Defense protection.
__________________
Pentium M| 512 RAM
ESET NOD32 Antivirus 5
ESET Smart Security 6 RC

Last edited by toxinon12345 : June 15th, 2011 at 12:40 PM.
  #18  
Old June 15th, 2011, 12:27 PM
mbmalone mbmalone is offline
Infrequent Poster
 
Join Date: Aug 2005
Posts: 13
Default Re: Why not eset self protection protect these..?

Quote:
Originally Posted by toxinon12345
Hey Marcos, you are right, but seems files being critical in the %programdata% folder are HipsRules.dat and HipsRules.xml. After a restart, the manually created rules are no listed anymore in HIPS Rules Management.

This files (HipsRules.dat and HipsRules.xml) seems to need Self-Defense protection.

I have never seen any HipsRules.dat
  #19  
Old June 17th, 2011, 03:09 AM
yongsua's Avatar
yongsua yongsua is offline
Frequent Poster
 
Join Date: Feb 2011
Location: Malaysia
Posts: 434
Default Re: Why not eset self protection protect these..?

Quote:
Originally Posted by mbmalone
I have never seen any HipsRules.dat

Maybe you can try to change your HIPS to interactive or learning mode?
__________________
Intel Core i5 processor 3450/ 3GB DDR3 RAM/Windows 7 Premium 64-bit/Avast Free Antivirus/Secunia PSI/Hitman Pro/Panda USB Vaccine
  #20  
Old June 17th, 2011, 06:08 AM
NodboN's Avatar
NodboN NodboN is offline
Regular Poster
 
Join Date: Nov 2007
Posts: 138
Exclamation Re: Why not eset self protection protect these..?

Quote:
Originally Posted by yongsua
Maybe you can try to change your HIPS to interactive or learning mode?
I'm on 'learning mode' and there's no HipsRules.dat - instead, there's an HipsRules.bin (can't spot the HipsRules.dat in the screenshot posted above, either.)
__________________
Never argue with fools - first, they'll try to get you down to their level and then defeat you with experience.
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus/Smart Security Beta « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:08 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums