PDA

View Full Version : IMON prevents download, nod32krn eats cpu


stephankn
October 29th, 2006, 07:12 AM
Hi,

can someone confirm this please.

i discovered the trying to download the following file:
http://download.windowsupdate.com/microsoftupdate/v6/wsusscan/wsusscan.cab

the download will not complete. It get's stuck at 99% download.
I observe nod32krn.exe eating my CPU and consuming RAM. I killed the process as it reached around 180M mem usage.

Disabling imond solves the problem.
Program run with "higher compatibility". It does not matter which program i use to download. Tried with wget and firefox.

NOD32 antivirus system information
Virus signature database version: 1.1842 (20061027)
Dated: Freitag, 27. Oktober 2006
Virus signature database build: 8313

Information on other scanner support parts
Advanced heuristics module version: 1.040 (20061027)
Advanced heuristics module build: 1126
Internet filter version: 1.002 (20040708)
Internet filter build: 1013
Archive support module version: 1.050 (20060926)
Archive support module build version: 1176

Information about installed components
NOD32 for Windows NT/2000/XP/2003/x64 - Base
Version: 2.51.26
NOD32 for Windows NT/2000/XP/2003/x64 - Internet support
Version: 2.51.26
NOD32 for Windows NT/2000/XP/2003/x64 - Standard component
Version: 2.51.26

Operating system information
Platform: Windows XP
Version: 5.1.2600 Service Pack 2
Version of common control components: 5.82.2900
RAM: 2048 MB
Processor: Intel(R) Pentium(R) 4 CPU 2.80GHz (2798 MHz)


Stephan

ctrlaltdelete
October 29th, 2006, 07:42 AM
I tried to download the same file.

184567

ctrlaltdelete
October 29th, 2006, 07:43 AM
DMON was scanning the file

184568

ctrlaltdelete
October 29th, 2006, 07:46 AM
After scanning more then 58000 files inside the *.cab

184569

ctrlaltdelete
October 29th, 2006, 07:50 AM
I'm not sure if IMON also scanned the file after DMON did, but i had to wait a few minutes before the download was complete.
Didnt check the time exactly, maybe 2 or 3 minutes before it was complete.

stephankn
October 29th, 2006, 07:52 AM
Hi,

small addition: the option "scan archives" causes the problem. It looks like the scan takes very long. a on-demand scan took nearly two minutes.
So letting it run longer it was able to finish. Also reducing effective data rate from 680kB/s down to 48kB/s.

For me the solution is to disable scanning of archives in imon. Malware inside should get detected by amon anyway.

Stephan

alglove
October 30th, 2006, 07:34 PM
You are not alone. This has been known to happen with some large archives filled with runtime packers. Here are a couple of other threads with similar problems:

http://www.wilderssecurity.com/showthread.php?t=150973
http://www.wilderssecurity.com/showthread.php?t=149650