Eset Agent

0 views
Skip to first unread message

Trine Gritz

unread,
Aug 3, 2024, 1:15:58 PM8/3/24
to gehrtheferpa

Hi Marcos, sorry for the delay.
I have only installed adobe acrobat, google documents offline, pinterest and vimeo video downloader . Also docs, sheets and slides from google. But none of them recently installed.
In Internet Explorer and Edge I believe that this behavior does not reproduce. Ah, another strange thing is that it is not constant in time.
I started with this warning yesterday in the morning, in the afternoon it was not show any more. This morning eset started showing it and in the last ours of the morning they disappeared. Now eset does not show any warning.

You can try:
1, Disabling syncing in the browser options
2, Disabling browser extensions
3, Trying another browser and see if the detection occurs with it as well
4, Uninstalling the browser including the user profile and installing it from scratch.

At this point I decide to uninstall chrome and reinstall, now, at this moment I have not warnings. Ah, the first time that I uninstalled chrome I did not delete the user profile and the warnings came out again

Desistale el google chrome y volver a instalar, funciono durante unos dias pero ha vuelto a salir el aviso de virus. He imtentado bloquear todas las paginas web sospechosas tambien la que aparece en el mensaje (ttps://a.xfreeservice.com) pero sigue saliendo.

Remove the google chrome and reinstall, it worked for a few days but the virus warning has returned. I have tried to block all suspicious web pages also the one that appears in the message (ttps: //a.xfreeservice.com) but it keeps coming out.

I started getting this notification (js / adware.agent.aw a.xfreeservice.com) in the Opera Browser. I had the Vimeo Video Downloader extension installed. I deleted it and it no longer detects anything.

In Protect Cloud I am creating installers for end-user's PCs, Laptops and Servers. Ok, I can imagine difference between PC and Server product, but installer offers me an option to create installer for Agent only or/and for Security product. I do not understand this concept - are both needed on endpoints, or just an Agent?

Agent maintains the communication between the security product and the ESET PROTECT server. You can have Endpoint installed without the agent but it won't be centrally managed and report to ESET PROTECT.

thank you. What I forgot to mention is that one of ESET technicians prepared some installer for me and he said, there is no need to check "Security Product" checkbox when creating installer, which broke my understanding of concept. Does in case when installer only has AGENT checked, but no Security Product checkbox, then after installation endpoint somehow automagically downloads and installs security product as well?

Sorry, obviously I did not explain my question well enough. I am asking about the differnece, if you prepare installer via Protect cloud WITH versus WITHOUT "Security Product". Because I can install only "Management Agent", but as far as I understand, "Agent" does not protect from viruses, malware etc. So what's the point of making installer for endpoint, which only has Agent? Furthermore, ESET technician told me I onl need to select checkbox beside "Managment Agent" and I should not select "Security Product" not "Disk Encryption", and endpoint will be fully protected.

I will try to answer on the questions above. The agent allows the communication betweeen the Server and the Endpoint Machine itself you can read more on this topic here, where a diagram will showcase the communication between these components.

In the second question the agent can be used for many different approaches and one of them is to create a templates based upon the dynamic groups. Some for example if you installa agent on a new machine and the agent reports back to the server that it doesn't have a security product it will fall into a group which you have defined and from there you can automatize the installation of the product of a specific type to this machine. For more I would recommend looking through the links I have provided above which can help you understand the whole process.

The difference between having a security product with the agent and not having it is that agent is lighter to be distributed on its own while if you add the product you increase the size of the installation package. However, on the other hand distributing the agent and having the automatization after can speed up your own process as well which can be helpful in larger networks. But I'm sure @Marcos can add some more pros and cons, as I have found these to be interesting to me.

Hi @IggyPop, thank you very much, your explanation puts some broken ends together in my mind. Of which main point is that (lightweight) installer with agent only, can upon deployment on client's computer afterwards - depending on policy - download and (silently, in the background, without user interventioin?) install (by policy) choosen security product, so there is no need to pack the cesurity product into installer itself.
This makes perfect sense to me.

Maybe just a sub-question as you mentioned Dynamic Groups:
In PROTECT CLOUD console I have COMPANIES, but under those I cannot create new company, just new Dynamic Group. Only MY OWN company is there, but if I re-sell products to another company, how and where can I add NEW COMPANY?

Thanx, I thought it is the way.... but it is a bit annoying, because installer and endpoint product in this case say, they are licensed on MY compnay, instead to END-USER's company. I am a kind of un-official sub-reseller, aka I buy from official reseller, then I have few dozens of my customer's companies which I manage.

In my case I have an MSP Account created for this purpose as I thought you might a reseller or an MSP. If this is something interesting for you surely you can read more on this topic here. But you can also create a dynamic group on top of your already existing company or you can create a new static group.

Well, I have access to my BUSINESS ACCOUNT where all licenses are stored, and from there I have access to PROTECT CLOUD. So I guess I do not have MSP Account, but my top resseller does. So he should create compaines for me? Will ask him.

i have installed eset agent software using live agent installer .sh script file on linux mint debian edition (LMDE). the installation was quick & can now see few processes with the name eraagent on the system.

finally figured out the way to uninstall. took some help from linux mint forum also.

the installation folder /opt/eset/RemoteAdministrator/Agent had a setup folder which had a uninstall.sh file and that did my job. sw removed completely.

So I've figured out how to get computers outside the network to connect back to the ERA server over the Internet successfully, but how do I configure policy to connect to the ERA server over the LAN while inside the network, and over the Internet when outside the network?

To enable connection from the Internet, I've created a new 'Remote Administrator Agent - http proxy usage' policy, adding the WAN IP address of the network in the 'Servers to connect to' list, and disable 'Use proxy server', all settings with the force flag enabled. Also with the relevant port forwarding on the firewall.

I now have a situation where I have nearly 20 notebooks that won't talk to the ERA server. I've removed this policy so now only the default policy applies, but I still can't get these clients to report back tot he server. I've tried redeploying the agent, which reports success for the task, but still no response back from the client. I've tried running an agent uninstall task, which is just sitting with status 'planned'. I set the trigger for asap but I don't know if the task is getting to the client as the agent isn't communicating.

In order to specify steps for "repairing" AGENT you will have to provide more information, but If I understood you correctly, they are not connecting only because SERVER is not available for them from outside of network. If this is the case, connecting notebooks to internal network should enable them to connect and receive task/configuration policies.

When configuring policy to enable connection from outside the network, I've specified the WAN IP address and standard port 2222 in the 'Servers to connect to' list, and disabled 'Use proxy server', and this seems to have worked fine in other deployments.

So now that the agent is installed and not reporting back to the server, what can I do? As above, I was able to create a new task to install the agent on one of the computers where the agent was already installed, and this task reported success. The ERA server can still see the computers on the internal network obviously. Surely there must be some way I can send the updated policy to the clients if they're on the same LAN?

I have other PC's and servers on the internal network that I deployed the agent to from the ERA server exactly the same as I deployed to the notebooks, only difference is they didn't have the 'inside/outside' modified 'Remote Administration Agent - HTTP Proxy Usage' policy applied, and these are reporting back to the server as expected.

You can create policy for ESET Remote Administrator Agent and in section Connection -> Servers to connect to list both internal IP and also external IP. Agents will be trying to connect to them in specified order, in case internal network connection will fail, it will try alternative.

c80f0f1006
Reply all
Reply to author
Forward
0 new messages