PDA

View Full Version : Amon Exlusion Fix


PosiXX
September 8th, 2003, 01:42 PM
After upgrading to v2006 components my exclusions for AMON didn't work either. However:
After adding the directories with DOS-format it works for me!

for instance, i'm using XWall on my exchange server, directory C:\Program Files\XWall

I have added to my exclusions list:

C:\Program Files\XWall type directory, permanent and include subdirs
C:\Progra~1\XWall type directory, permanent and include subdirs

And now the directory is excluded from AMON! 8)

Maybe you guys with the same problem can try this..

optigrab
September 8th, 2003, 11:46 PM
I'll be darned! ;D (How'd you think of that?)

It worked here - exclude of Boclean working fine now!

Thanks PosiXX !

marti
September 9th, 2003, 12:21 AM
-{ Quote: " quoting: PosiXX link=board=39;threadid=13274;start=0#msg86120 date=1063042926]After adding the directories with DOS-format it works for me!" }-

Yeah!!!!!!!!!!!!!!!

It works for me also. Thank you for sharing this.

Edit: In testing it doesn't hang anymore when using Trojan Hunter Live update, but AMON is still scanning the files. I had the AMON interface up on the desktop and moved it so I could see it scan with I opened TH Live update.

martindijk
September 9th, 2003, 10:25 AM
Hi PosiXX,

How do i set this up for files in other directories, like:

D:\ZFILES\MCAFEEFIREWALL\OUTPOST\OUTPOST FIREWALL\OP_VIEWER.EXE

thanks,
Martin

optigrab
September 9th, 2003, 05:44 PM
Martin,

All CAPS (I think - worked for me), remove spaces, any names more than 8 characters must be truncated to 6 and followed by "~1" (or possibly a ~2, or ~3). For a better reference, refer to the following link (I hope it's okay to post).

http://www.delanet.com/~pparish/filename.htm


I think your example would read like this...

D:\ZFILES\MCAFEE~1\OUTPOST\OUTPOS~1\OP_VIE~1.EXE

As noted in the link, please be mindful that the truncate rule raises the possibility of duplicate file and/or folder names. Check the alphabetized listing in each directory in the path.

Regards
Optigrab :)

PosiXX
September 9th, 2003, 07:36 PM
Hello Martin,

Caps isn't mandatory, just the 6 + '~1' for directorynames longer than 8 characters will do fine.

DiGi
September 10th, 2003, 02:58 AM
just use dir /X ;)

I think that all this about exclusions a BOclean is in way what BOclean is executed.

If you have in AMon full (long) windows path and file is executed by shorten path then AMon can't handle exclusion. So you must use path as is used in Run key / Startup / etc...

I'm using exclusions (for some exe files and one folder) with no problem since 2.000.4 (my first NOD)

martindijk
September 10th, 2003, 12:21 PM
Hi all,

Thanks for the input, think i have got it now :)

rgds,
Martin

spy1
September 30th, 2003, 10:11 AM
Did they already include this fix into the program? Or do you still have to do it manually? (I don't "exclude" anything, so I really don't know). Pete

marti
September 30th, 2003, 12:06 PM
-{ Quote: " quoting: spy1 link=board=39;threadid=13536;start=0#msg90932 date=1064931069]
Did they already include this fix into the program? Or do you still have to do it manually? (I don't "exclude" anything, so I really don't know). Pete
" }-
Pete,

You have to determine the DOS file name on your own and carefully input it.

spy1
September 30th, 2003, 12:19 PM
Thank you, Marti. Pete

WilliamP
September 30th, 2003, 07:00 PM
Ok, now that you guys have it all figured out, how about telling me what I have to type into Exclusions to get NOD to exclude SpyBot S&D please.

rumpstah
October 1st, 2003, 12:43 AM
Typically to exclude directories using the DOS 8.3 format you can try the following:

C:\program files\Spybot - Search & Destroy
C:\progra~1\spybot~1

The first six characters are used for 8.3 format.
~1 is used for the first directory with the first 6 letters.

Drop us a note if this helps.

SaracenBlade
October 1st, 2003, 12:46 AM
I haven't tried this with NOD32, but if you enclose long filenames and paths in quotes, like "c:\Program Files\Blowfish Email Encryptor\mysig.enc" they are fully recognized by XP's command prompt.

FanJ
October 1st, 2003, 01:14 AM
In case you would like to get the short-file-name of a file, there is a free tool to get it.

Look at this thread:
Right-click-context-menu in Windows Explorer

http://www.wilderssecurity.com/showthread.php?t=13098

There are several programs mentioned there, but the one you need is:
Ninotech Path Copy 4

Have a look at that thread and you will see a screenshot of it, several examples, a description of it, and the download-link.

Cheers, Jan.

fingers
October 1st, 2003, 04:58 AM
re Ninotech Path Copy 4
love it thanx makes doing dos batch files/scripts easy

dave

FanJ
October 1st, 2003, 05:02 AM
:D

Hi Dave,

You're welcome !

Cheers, Jan.

tosbsas
October 1st, 2003, 07:47 AM
-{ Quote: " quoting: SaracenBlade link=board=39;threadid=13536;start=0#msg91092 date=1064983602]
I haven't tried this with NOD32, but if you enclose long filenames and paths in quotes, like "c:\Program Files\Blowfish Email Encryptor\mysig.enc" they are fully recognized by XP's command prompt.
" }-

Anybody tried that oone??

Ruben

WilliamP
October 1st, 2003, 05:45 PM
Jan , I downloaded the Ninotech Path Copy 4 and whe I right click I can choose to copy short or long path. But when I click on either the window closes and I don't see anything. If it is being copied how can I find it. Help please.

anders
October 1st, 2003, 06:20 PM
My guess is that it's located in the clipboard? Go somewhere and try to paste it.

Best regards,
Anders

WilliamP
October 1st, 2003, 07:20 PM
I'm a little slow and computer ignorant. I have it figured out now. I went to AMON excludes, right clicked and pasted. Guess what it copied the paths. I copied the long and the short. I appreciate the help.

WilliamP
October 1st, 2003, 07:39 PM
Ok gang , I copied and pasted the SpySpot path, folder. I tried long and short. It will still hang when AMON is not disabled.

martindijk
October 3rd, 2003, 11:17 AM
Hi all,

Gave it a try also, but still the files and folders i have entered are not being excluded

rgds,
Martin