Future Changes to EAV

Discussion in 'ESET NOD32 Antivirus' started by Blackspear, Jan 20, 2008.

  1. techie007

    techie007 Registered Member

    Joined:
    Jan 2, 2008
    Posts:
    125
    Location:
    Ontario, Canada
    Re: Future Changes to EAV 3.0

    And you're right.. LAME!

    So that'a Bug, not a feature request -- different thread. :)
     
  2. techie007

    techie007 Registered Member

    Joined:
    Jan 2, 2008
    Posts:
    125
    Location:
    Ontario, Canada
    Re: Future Changes to EAV 3.0

    OK here's a few I suggested the support guy today via phone:

    1. All Threats detected should be reported in the Threat Log (tab) of the RA regardless of which scan found it (it currently only shows threats caught by the Real-time scanning, not scheduled scans).

    2. The Scan logs should report action taken if it was handled, currently if it cleans it, it doesn't tell you that it cleaned it, or how it cleaned it (cleaned or deleted).

    3. The RA Server should email you any time there is a problem. IE: if there's an entry added to the Threat Log, Errors in the Event log, Protection Status Error levels, Lack of client check-in, etc. Currently it only emails "reports" at the server level. All real-time alerting comes from the Clients, which leads to needing multiple config files with different SMTP server settings for different offices, and is extra annoying for laptops that travel between multiple networks (and therefor usually need to use different SMTP servers on each one, some of which we don't know the configuration of).

    4. A way to view a client's Quarantine, and make a task to empty it.
     
  3. sangam

    sangam Registered Member

    Joined:
    Jan 26, 2007
    Posts:
    49
    Location:
    ahmedabad, india
    Re: Future Changes to EAV 3.0

    ability to generate a boot CD, and a boot USB disk, to clean infected system files. should be low foot print, run on minimum system resources (128mb system, older cpus), and contain essential tools for repairing the system.

    or may be sold as a separate standalone product.
     
  4. wiak

    wiak Registered Member

    Joined:
    Sep 10, 2006
    Posts:
    107
    some improvments to NOD32 when cleaning viruses

    what about giving users the message "please restart the computer and run NOD32 in safemode"

    when you cant remove trojans and virues you should run nod32 in safe mode
    and meybe a restart to safemode, am sure microsoft made a option in windows to boot into safe mode on next restart

    msconfig > boot has it

    this will make LIFE eseier for everyone that gets cannot clean/delete the item and so on :eek:
     
  5. ASpace

    ASpace Guest

    Re: some improvments to NOD32 when cleaning viruses

    Because generally both v2 and v3 can clean infiltrations immediately (especially v3 which has cleaning malware improved) . This is when it comes to processes . When the situation is a bit more difficult (e.g. infected dll) , ESS/EAV/NOD32 will tell you that upon next reboot the malware will be gone , so generally no restart to Safe Mode is needed
     
  6. Philippe_FR22

    Philippe_FR22 Registered Member

    Joined:
    Sep 6, 2007
    Posts:
    249
    Re: Future Changes to EAV 3.0

    Request for corrections and new features in EAV 3.0

    1) Rights Management
    Currently, configuration can be protected by password. Problem is each time you access the Advanced Configuration Tab, you are asked for type your password (even is main ESET windows is still opened). That is annoying.

    What I suggest is to log as ESET Admininstrator (once) during a whole session and possibility to log off. This is particularly interesting when you have a multi user PC, with 1 Admin and Serveral Users, and you are currently configuring ESET for a particular User

    Another feature, maybe, could be to apply change for current user (or selected user ) or to all users...


    2) Mail client Downloading Progress bar (as in NOD32 v2.7)

    3) Attachement management inside original mails... I noticed, using gfi.com mail testing, that dangerous threats were removed, but a strange attachement were remaining (still several bytes, impossible to save on the disk). In NOD32 v2.7, attachement were replaced by a text file explaining that attachement were removed...


    4) Mail Tags enhancements... Sometimes, on html mails, tags do not appear...

    5) Number of infected files, written on main windows, corresponds to the threats detected during current session... That is not clear... May be, adding history as : nb of threats detected since <date of last log cleanup>


    6) Some translations are quite approximatives (noticed in french release)

    7) hhtp client management and explaination are not sufficient... It is said that all application viewed as browser must be checked, the one that we don't want to be recognized as a browser, must be marked, using the cross... Well, but how to insert the cross (instead of the check mark ?)... That is not very clear in fact... Altough, the http "active" detection is not sufficiently documented...


    Regards


    Phil
     
  7. THE_BAD_BOY

    THE_BAD_BOY Registered Member

    Joined:
    Nov 15, 2007
    Posts:
    40
    Re: Future Changes to EAV 3.0

    self-defense protection just like a kaspersky :)
     
  8. RubberBandit24

    RubberBandit24 Registered Member

    Joined:
    Nov 18, 2007
    Posts:
    7
    Self-Defense

    Definitely agree. I saw a thread a while ago stating that "ekrn.exe" can be terminated by a simple batch file; I'm not sure if the self-defense has improved at all since then, but if it hasn't, I'd love to see it incorporated.
     
  9. reni

    reni Registered Member

    Joined:
    Feb 22, 2008
    Posts:
    19
    Re: Future Changes to EAV 3.0

    I would like to see a command line option to force EAV to update its virus defs.

    We got one XP base image for our 5000+ workstations, after imaging we run a script. It would be nice if we could trigger to update with it.
     
  10. wiak

    wiak Registered Member

    Joined:
    Sep 10, 2006
    Posts:
    107
    Re: Future Changes to EAV 3.0

    a option to disable Web access protection and email protection and not get the annoying red icon, useful if you have a program that isnt liking web access protection and if you use webmail, no need for email protection

    here is a bootscan picture of eset to make ;P

    http://bcheck.scanit.be/bcheck/hj-images/avast-scan.png
    i totaly agree it should have a bootscan option, meybe scan everytime pc boots option to, like if you want to scan MBR, system files and stuff
     
  11. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    Re: Future Changes to EAV 3.0

    SSL scanning support when using SSL-pop3.
     
  12. Nitrous

    Nitrous Registered Member

    Joined:
    Feb 4, 2008
    Posts:
    29
    Location:
    Russia, St.Petersburg
    Re: Future Changes to EAV 3.0

    sound signal when threat is detected
     
  13. hobbit666

    hobbit666 Registered Member

    Joined:
    Jul 18, 2006
    Posts:
    45
    Re: Future Changes to EAV 3.0

    How about a option to uninstall the software completly from within Remote Administrator Console
     
  14. wiak

    wiak Registered Member

    Joined:
    Sep 10, 2006
    Posts:
    107
    Re: Future Changes to EAV 3.0

    here is another basic future request
    what about making md5 hash of the installation files and put the hash on the downloads page?

    makes it realy easy to verify!
    the version numb3r and if its real :thumb:

    please
     
  15. curiousmicrobe

    curiousmicrobe Registered Member

    Joined:
    Feb 17, 2008
    Posts:
    32
    Re: Future Changes to EAV 3.0

    Ideas:
    - Registry checking when On Demand Scan is triggered.
    - Cookie scanning / blocking / removal.
     
    Last edited: Feb 29, 2008
  16. piranha

    piranha Registered Member

    Joined:
    Mar 21, 2005
    Posts:
    623
    Location:
    Laval, Qu?bec, Canada
    Re: Future Changes to EAV 3.0

    We can set to accept program component update but nod32 never inform us of NEW version

    I suggest a pop-up when a new version is available.
     
  17. nodyforever

    nodyforever Registered Member

    Joined:
    Oct 30, 2007
    Posts:
    549
    Location:
    PT / Lisbon
    Re: Future Changes to EAV 3.0


    +1 vote :D


    cheers :cool:
     
  18. wiak

    wiak Registered Member

    Joined:
    Sep 10, 2006
    Posts:
    107
    Re: Future Changes to EAV 3.0

    .xml based language translation?
    would be great if NOD32 / Smart Security gets support for it!

    +2
     
  19. guest

    guest Guest

    Re: Future Changes to EAV 3.0

    Do not scan on backup

    Symantec had this, it shaved 2 hours off backup times on our file server.
     
  20. An10Bill

    An10Bill Registered Member

    Joined:
    Feb 24, 2005
    Posts:
    21
    Location:
    Norway/Sweden
    Re: Future Changes to EAV 3.0

    My biggest loss from v2 is the the ability to push the configuration.xml file along with the updates from the mirror... That was one great feature!

    Earlier on V2 i freshly installed a new client, pointed it to the mirror and the client got updated and configured itself with the correct config-file. - And the best part - if i changed the config, all clients got the new config next time they did an update.

    Now in v3 i have to first intall the client, then push the config, then update the client.....and if I do changes I have to push out a new config, but this only hits the computers online - which is about 65% of my total users, and I have to redo this every once in a while hoping to catch them all while connected with VPN and give them new configs.....which takes very long time, and makes this a lot more difficult to manage.

    So my biggest wish for V3 is the ability to distribute the config from the mirror.
     
  21. nodyforever

    nodyforever Registered Member

    Joined:
    Oct 30, 2007
    Posts:
    549
    Location:
    PT / Lisbon
    Re: Future Changes to EAV 3.0

    - Progress bar v3.0 - attachment image

    - Suggestion send sample user - add sigla database


    example:


    Threat Normal- detecting AV heuristics:

    Win32/Poision


    Threat User - Send sample user from Eset - sigla USS = user send sample


    Win32/USS.Poision


    I do not know if that is possible, but it was a way to prove that we are not sending samples of virus in vain.




    That is my suggestion



    Cheers :cool:
     

    Attached Files:

  22. Atomas31

    Atomas31 Registered Member

    Joined:
    Sep 7, 2004
    Posts:
    923
    Location:
    Montreal, Quebec
    Re: Future Changes to EAV 3.0

    I also have a ssl-pop3 and I would greatly appreciate if, finally, ESS/NOD32 be able to scan ssl-pop3...
     
  23. Atomas31

    Atomas31 Registered Member

    Joined:
    Sep 7, 2004
    Posts:
    923
    Location:
    Montreal, Quebec
    Re: Future Changes to EAV 3.0


    I add my vote for this suggestion too!
     
  24. MR X

    MR X Registered Member

    Joined:
    Feb 21, 2007
    Posts:
    15
    Re: Future Changes to EAV 3.0

    mee two;)
     
  25. mps_surcouf

    mps_surcouf Registered Member

    Joined:
    Mar 5, 2008
    Posts:
    33
    Re: Future Changes to EAV 3.0

    You are right on it techie007 these are exactly the same points I would like to make.

    I will add

    5. When showing the current signature version for the network on the RA console (clients tab) give the cients a chance to update to the current version before considering it a warning situation. Currently as soon as the server has a new version everthng is red until all clients have updated. I think this is a bit over the top as you will always need to allow 15 mins for all cients to update to server version.

    Cheers

    Mike
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.