Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old September 25th, 2012, 09:19 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,185
Default Beware of MS hotfixes KB2735855 and KB2750841

The recently released hotfixes KB2735855 and KB2750841 have been confirmed to cause data corruption during the download when a 3rd party driver working at Windows Filtering Platform layer intervenes in the communication. ESET has demonstrated it using a sample driver from Windows Development Kit and will contact Microsoft to address the issue with as highest priority as possible. In the mean time, we strongly recommend removing this hotfix until Microsoft comes up with a solution.

Update: Microsoft has released hotfix 2789397 addressing this issue.

Last edited by Marcos : February 20th, 2013 at 09:41 AM.
  #2  
Old September 25th, 2012, 11:59 AM
Wallaby's Avatar
Wallaby Wallaby is offline
Regular Poster
 
Join Date: Jan 2011
Posts: 138
Default Re: Beware of MS hotfix KB2735855

What is the practical symptom and the practical effects of this fact?
__________________
It is the Tale, not he who tells it (Stephen King)
  #3  
Old September 25th, 2012, 12:06 PM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,185
Default Re: Beware of MS hotfix KB2735855

So far we know about corrupted (non-executable) files downloaded via Internet Explorer but it's probably just a coincidence that the issue hasn't been reported with other browsers yet.
  #4  
Old September 25th, 2012, 10:43 PM
siljaline's Avatar
siljaline siljaline is offline
Security Expert
 
Join Date: Jun 2003
Location: Montréal, Canada
Posts: 4,123
Post Re: Beware of MS hotfix KB2735855

Many are remiss in uninstalling this patch from:
http://technet.microsoft.com/en-us/s...letin/ms12-sep. Waiting for further disposition from ESET.

Last edited by LowWaterMark : September 26th, 2012 at 01:30 PM. Reason: removed period from inside of link
  #5  
Old September 26th, 2012, 01:20 AM
johnpd johnpd is offline
Regular Poster
 
Join Date: May 2004
Posts: 80
Default Re: Beware of MS hotfix KB2735855

I attempted to uninstall the fix. It hung at the infamous "Preparing To Configure Windows, Please Do Not Turn Off Your Computer" message. When I finally decided to shutdown the computer (a laptop), it would only go into sleep mode and returned to the "Preparing" message when I powered back up. I eventually had to disconnect the AC and remove the battery in order to get it to boot from scratch. Once I got it back, it finished up and booted to Windows. Not fun.

JohnD
  #6  
Old September 26th, 2012, 02:09 AM
rcdailey rcdailey is offline
Frequent Poster
 
Join Date: Dec 2009
Posts: 233
Default Re: Beware of MS hotfix KB2735855

Quote:
Originally Posted by johnpd
I attempted to uninstall the fix. It hung at the infamous "Preparing To Configure Windows, Please Do Not Turn Off Your Computer" message. When I finally decided to shutdown the computer (a laptop), it would only go into sleep mode and returned to the "Preparing" message when I powered back up. I eventually had to disconnect the AC and remove the battery in order to get it to boot from scratch. Once I got it back, it finished up and booted to Windows. Not fun.

JohnD

I would hate to try uninstalling the fix on a laptop that needs to be running during the day. I just did another update (this time for MS Security Essentials) on a laptop running Win 7 Pro 64-bit. This laptop was never offered SP1, but seems to be fine. All the updates that have been offered were installed. The laptop required a restart, but the other systems (that have SP1) did not. Maybe many laptops are going to be difficult when it comes to uninstalling the fix, and perhaps all systems that did not get SP1.
  #7  
Old September 26th, 2012, 07:54 AM
johnpd johnpd is offline
Regular Poster
 
Join Date: May 2004
Posts: 80
Default Re: Beware of MS hotfix KB2735855

The laptop is a Lenovo Win7 Pro 64-bit. I recall something like this happening once before where it would not shutdown. I don't remember what I was doing at the time, but I again had to remove all power from it to get it to shutdown completely.

JohnD
  #8  
Old September 26th, 2012, 10:45 AM
Trooper's Avatar
Trooper Trooper is offline
Very Frequent Poster
 
Join Date: Jan 2005
Posts: 2,535
Default Re: Beware of MS hotfix KB2735855

Quote:
Originally Posted by siljaline
Many are remiss in uninstalling this patch from:
http://technet.microsoft.com/en-us/s...letin/ms12-sep. Waiting for further disposition from ESET.

I have a dead link showing here.
__________________
This space for rent.

Last edited by LowWaterMark : September 26th, 2012 at 01:33 PM. Reason: removed period from inside of link in quote
  #9  
Old September 26th, 2012, 12:28 PM
rockshox rockshox is offline
Frequent Poster
 
Join Date: Oct 2009
Posts: 261
Default Re: Beware of MS hotfix KB2735855

We rolled this hotfix out to around 200 machines a couple weeks ago. We haven't had any reports of any download issues with NOD32 4.2.76.0.

What are the steps to recreate this issue? I downloaded some non-executable files from IE that all worked correctly.
  #10  
Old September 26th, 2012, 01:12 PM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,550
Default Re: Beware of MS hotfix KB2735855

Quote:
Originally Posted by Trooper
I have a dead link showing here.
Same here with server error.
__________________
OS X 10.8.3 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
  #11  
Old September 26th, 2012, 01:31 PM
LowWaterMark LowWaterMark is offline
Administrator
 
Join Date: Aug 2002
Location: New England
Posts: 15,521
Default Re: Beware of MS hotfix KB2735855

Quote:
Originally Posted by Dark Shadow
Same here with server error.
There was an extra period inside of link. The original post with link has been edited to fix that.
  #12  
Old September 26th, 2012, 03:15 PM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,550
Default Re: Beware of MS hotfix KB2735855

working perfect now.Thanks LWM
__________________
OS X 10.8.3 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
  #13  
Old September 26th, 2012, 04:19 PM
siljaline's Avatar
siljaline siljaline is offline
Security Expert
 
Join Date: Jun 2003
Location: Montréal, Canada
Posts: 4,123
Post Re: Beware of MS hotfix KB2735855

My bad on broken link. Thanks @ LWM

http://technet.microsoft.com/en-us/s...letin/ms12-sep
  #14  
Old September 27th, 2012, 07:40 AM
pacek pacek is offline
Infrequent Poster
 
Join Date: Sep 2012
Location: Poland
Posts: 4
Default Merged in from: NOD32 locking up developers computer

I tested this issue and wrote about all workarounds in this thread:
http://answers.microsoft.com/en-us/w...c-d46e91878bc0
I sent bug report to ESET but they didn't answer me yet...
Do you know is it a ESET HTTP filter related issue or Microsoft patch issue?
  #15  
Old September 27th, 2012, 08:39 AM
hillrb hillrb is offline
Infrequent Poster
 
Join Date: Apr 2008
Posts: 44
Default Re: Beware of MS hotfix KB2735855

Quote:
Originally Posted by Wallaby
What is the practical symptom and the practical effects of this fact?

We use the Business version and rolled this out to around 100 machines last week via WSUS and I later discovered issues in Internet Explorer 8 and 9. The issues were related with searches. If you tried to search via the search bar (top right), the window that opened would say, "Internet Explorer cannot display the webpage". If you hit F5 many times, you might get the search window to finally populate, but usually wouldn't. Secondly, if you tried to search via the BING bar on MSN's homepage, it would do the same thing. I didn't notice the problem using Firefox though (not sure why). After discovering these problems from several people calling, I set WSUS to uninstall the patches from the computers and as far as I can tell, the uninstalls went successfully. Heck, I installed/uninstalled on my computer probably about 8 times with no problems. I posted to a TechNet forum yesterday about this and it finally occurred to me this morning that it might be a problem with NOD32 and sure enough I found this forum.

Kind Regards,
Brett

Last edited by hillrb : September 27th, 2012 at 08:46 AM.
  #16  
Old September 27th, 2012, 08:49 AM
rcdailey rcdailey is offline
Frequent Poster
 
Join Date: Dec 2009
Posts: 233
Default Re: Beware of MS hotfix KB2735855

Quote:
Originally Posted by siljaline
My bad on broken link. Thanks @ LWM

http://technet.microsoft.com/en-us/s...letin/ms12-sep

The only critical patch listed in the link is:

Cumulative Security Update for Internet Explorer (2744842)

I did not find the KB2735855 patch listed in the link above. Maybe MS has changed the content?

The Win 7 systems had the patch KB2735855 installed and no one has noticed a search issue in IE9, but the default browser is set to Chrome. Some are using IE9 anyway and I am sure they would have commented. NOD32 is not installed on the Win 7 systems.

Last edited by rcdailey : September 27th, 2012 at 09:06 AM.
  #17  
Old September 27th, 2012, 11:49 AM
geekpryde geekpryde is offline
Infrequent Poster
 
Join Date: Mar 2012
Location: USA
Posts: 7
Default Re: Beware of MS hotfix KB2735855

WOW! I am so happy I randomly stopped by these forums today. I have been pulling out my hair and freaking out at Fortinet (hardware firewall vendor) for all these broken downloads, busted youtube videos, busted quicktime videos, etc. Ie downloads have been particularly troublesome. Yahoo.com IE homepage has been randomly crashing just sitting there (no user activity). I was 100% sure it was the firewall and blaming Fortinet for pusing a bad IPS sig or AV sig.

So happy there are smart people here!

I am uninstalling KB2735855 now. I will report back in 24 hours and see if there are any further broken downloads at the company (around 30 users).
  #18  
Old September 27th, 2012, 03:50 PM
pacek pacek is offline
Infrequent Poster
 
Join Date: Sep 2012
Location: Poland
Posts: 4
Default Re: Beware of MS hotfix KB2735855

Quote:
Originally Posted by geekpryde
I am uninstalling KB2735855 now. I will report back in 24 hours and see if there are any further broken downloads at the company (around 30 users).

This issue occurs only on 4-core (and more) Intel and AMD CPUs. If you don't want to do mess with uninstalling this Microsoft update, you can disable HTTP filter in ESET and then everything will be OK with your transfer. It won't be a problem if you use ESET Remote Administration Console (ERAC) with ESET Remote Administration Server. You can do it via Configuration Task in ERAC, and it's done in few seconds. You must understand that disabling HTTP filter will increase risk of infection via HTTP protocol. Uninstalling KB2735855 can be done via WSUS but it'll consume you more time to propagate over the network and also it requires rebooting of the computer, which is annoying to users.
Good luck
  #19  
Old September 28th, 2012, 01:14 AM
rcdailey rcdailey is offline
Frequent Poster
 
Join Date: Dec 2009
Posts: 233
Default Re: Beware of MS hotfix KB2735855

It occurs to me that if this MS patch does not cause a problem with respect to other AV software (or other applications in general), then MS is not going to do anything about it. Eset users will have to do what you suggest or quit being Eset users. I am still unhappy about having to disable Malwarebytes Pro real-time protection in order to use Eset 5.x on my XP system. The fix for that is still pending.
  #20  
Old September 28th, 2012, 04:38 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,185
Default Re: Beware of MS hotfix KB2735855

We've received a response from MS: I have forwarded your issue to our sustained engineering folks to investigate.
  #21  
Old October 4th, 2012, 05:51 AM
SaphireX's Avatar
SaphireX SaphireX is offline
Regular Poster
 
Join Date: Jul 2004
Posts: 84
Default Re: Beware of MS hotfix KB2735855

Hi Marcos
I noticed this morning that the Internet protection module: 1047 (20121002) updated (since I have pre-release updates selected)
Is this possibly the fix to this issue?
Thanks
__________________
ASRock™Z68 Extreme7 Gen3-Intel™Core i7-2600K-Corsair™H100-16GB G.SKILL™RipjawsX DDR3 2133-(2)ASUS™ENGTX560 TI in SLi -120GB Mushkin™Chronos Deluxe SSD SATA 6.0 Gb/s-PCP&C™Silencer Mk II 950W-Win7™Ultimate 64
  #22  
Old October 4th, 2012, 06:25 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,185
Default Re: Beware of MS hotfix KB2735855

Quote:
Originally Posted by SaphireX
Hi Marcos
I noticed this morning that the Internet protection module: 1047 (20121002) updated (since I have pre-release updates selected)
Is this possibly the fix to this issue?
Thanks
The module addresses an issue with Windows Updates after recent changes in the Windows Update Agent. As for the issues caused by the hotfix 2735855, Microsoft was provided all information and files necessary to debug the issue and is currently looking into it.
  #23  
Old October 4th, 2012, 10:08 PM
siljaline's Avatar
siljaline siljaline is offline
Security Expert
 
Join Date: Jun 2003
Location: Montréal, Canada
Posts: 4,123
Post Re: Beware of MS hotfix KB2735855

Although I have not yet removed the hotfix, my system information on non pre-release. I am showing these module changes.

Quote:
Antivirus and antispyware scanner module: 1367 (20120921)
Archive support module: 1153 (20120917)
  #24  
Old October 19th, 2012, 02:04 PM
etretat etretat is offline
Infrequent Poster
 
Join Date: Oct 2012
Location: Brazil
Posts: 9
Default Re: Beware of MS hotfix KB2735855

Marcos:

Any evolution and / or solution for this problem?

Regards,

etretat.

Last edited by etretat : October 19th, 2012 at 02:39 PM.
  #25  
Old October 20th, 2012, 03:36 PM
TONPumper's Avatar
TONPumper TONPumper is offline
Regular Poster
 
Join Date: Jul 2010
Posts: 101
Default Re: Beware of MS hotfix KB2735855

Is this fix included with Windows updates, or is it something that has to be manually downloaded and installed? I'm just wondering if this could be the cause of my problem.

Last edited by TONPumper : October 20th, 2012 at 03:43 PM.
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 09:54 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums