Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > Other ESET Home Products
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old December 14th, 2010, 01:52 PM
Cosmo32's Avatar
Cosmo32 Cosmo32 is offline
Regular Poster
 
Join Date: Feb 2007
Location: Rossville, Georgia USA
Posts: 179
Default SysInspector v12026

Is there a bug in SI v12026? Does SI v12026 no longer care for the action of the MVPS Host File protection I use?

I just test ran v12026. The results lit up the "Critical Files" section bright RED!
And, most of the log lists stuff shown in the Hosts File that all focus to 127.0.0.1. Yes. Confused I am...........

Yes, I still use the V2.7 BE A/V; just because it runs so well.
__________________
Best,
Duncan
-----------
ESET Endpoint AV v5.0.2214.4 (2 client) - , ESET NOD32 AV v6.0.314.0 (1 client) . ESET EFS4MWS AV v4.5.12011.0 (1 server) - , MalwareBytes v1.75.0.1300 - , MVPS Host file -
  #2  
Old December 14th, 2010, 08:37 PM
agoretsky's Avatar
agoretsky agoretsky is offline
Eset Moderator
 
Join Date: Apr 2006
Location: California
Posts: 3,917
Default Re: SysInspector v12026

Hello,

Could you provide a screenshot of the problem? Thank you.

Regards,

Aryeh Goretsky
__________________
Resources: ESET · blog · documentation · FAQs · knowledge base · news · RSS · signature updates · support · Threat Center · @ESETNA (Twitter) · YouTube: ESETKnowledgebase · VirusRadar
Fun Stuff: Facebook (global) · Facebook (US) · @ESET (Twitter) · YouTube: esetusa
  #3  
Old December 16th, 2010, 10:56 AM
Cosmo32's Avatar
Cosmo32 Cosmo32 is offline
Regular Poster
 
Join Date: Feb 2007
Location: Rossville, Georgia USA
Posts: 179
Default Re: SysInspector v12026

Aryeh,
Thank you. I am trying to provide small captures of what I see. Found/loaded FSC v5.3 and am learning to use it. As soon as I learn to cull the excess blank screen space, I will attempt to upload a pair of views using the directions from Bubba and GroverH.
I suppose my basic observation is:
SI v120210 appears to ignore the MVPS Host file.
SI v120260 appears to see the MVPS Host file and code it critical.
__________________
Best,
Duncan
-----------
ESET Endpoint AV v5.0.2214.4 (2 client) - , ESET NOD32 AV v6.0.314.0 (1 client) . ESET EFS4MWS AV v4.5.12011.0 (1 server) - , MalwareBytes v1.75.0.1300 - , MVPS Host file -
  #4  
Old December 20th, 2010, 10:46 AM
Cosmo32's Avatar
Cosmo32 Cosmo32 is offline
Regular Poster
 
Join Date: Feb 2007
Location: Rossville, Georgia USA
Posts: 179
Default Re: SysInspector v12026

Aryeh,
Here is an attempt to share two small screen shots. They show how the latest version of System Inspector 12060 is working here.....
Name:  2010-12-16_082930.jpg
Views: 153
Size:  42.4 KB

Click image for larger version

Name:	2010-12-16_083524.jpg
Views:	2
Size:	104.0 KB
ID:	224029

I hope these pix help.
__________________
Best,
Duncan
-----------
ESET Endpoint AV v5.0.2214.4 (2 client) - , ESET NOD32 AV v6.0.314.0 (1 client) . ESET EFS4MWS AV v4.5.12011.0 (1 server) - , MalwareBytes v1.75.0.1300 - , MVPS Host file -
  #5  
Old December 22nd, 2010, 02:04 PM
agoretsky's Avatar
agoretsky agoretsky is offline
Eset Moderator
 
Join Date: Apr 2006
Location: California
Posts: 3,917
Default Re: SysInspector v12026

Hello,

I spoke with one of ESET SysInspector's principals about this, and he explained that the increased Risk Level for localhost redirections in the hosts file is the result of concerns about malicious software using this method to block or redirect access to sites.

Please keep in mind that the heuristics used in ESET SysInspector are not the same as those in ESET NOD32 Antivirus and also evaluate things differently because the purpose of the programs is different, e.g., ESET SysInspector's focus is on troubleshooting installations of ESET's software as well as evaluating infected systems versus ESET NOD32 Antivirus' task of protecting your system from threats. As a result, ESET SysInspector may flag something as suspicious or risky while ESET NOD32 Antivirus does not report anything.

ESET does provide some blocking of malicious sites, however, there is nothing wrong with taking a defense-in-depth approach and providing an additional layer of protection with tools like the MVPS HOSTS File, Pyrenean's eDexter and so forth.

Since you initiated the hosts file blocking yourself, have evaluated the source of the block, provenance of its entries and so forth and understand the reasons for doing so, it is safe for you to ignore this section of the ESET SysInspector log report.

Regards,

Aryeh Goretsky
__________________
Resources: ESET · blog · documentation · FAQs · knowledge base · news · RSS · signature updates · support · Threat Center · @ESETNA (Twitter) · YouTube: ESETKnowledgebase · VirusRadar
Fun Stuff: Facebook (global) · Facebook (US) · @ESET (Twitter) · YouTube: esetusa
  #6  
Old December 24th, 2010, 10:41 AM
Cosmo32's Avatar
Cosmo32 Cosmo32 is offline
Regular Poster
 
Join Date: Feb 2007
Location: Rossville, Georgia USA
Posts: 179
Default Re: SysInspector v12026

Aryeh,
Thank you for your reply and the research. Yes, I do use the MVPS Hosts file logic as part of my layered approach to protection. I do see the distinction mentioned between ESET A/V and the System Inspector. NOD32 runs 24/7. System Inspector is used when I notice odd behavior that does not trigger NOD32.

I do now understand the increased scrutiny of SI toward local host redirection. I was unaware that malicious code was also copying this activity. I may test your suggested Pyrenean's eDexter also now.

Please share my appreciation with your "white hats!" They do an excellent job keeping the bad guys at bay!

Best of the Season!
__________________
Best,
Duncan
-----------
ESET Endpoint AV v5.0.2214.4 (2 client) - , ESET NOD32 AV v6.0.314.0 (1 client) . ESET EFS4MWS AV v4.5.12011.0 (1 server) - , MalwareBytes v1.75.0.1300 - , MVPS Host file -
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > Other ESET Home Products « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:46 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums