View Full Version : IMON question
cupez80
December 3rd, 2006, 11:41 AM
i test IMON by downloading eicar test file from nod32sse.com (i use IDM integration with firefox 2) and imon let it downloaded ??!! when i check nod32 log it said that virus detected and connection terminated. ??? ive set idm to higher efficiency. imon work well if i dont use idm.
Banger696
December 20th, 2006, 10:15 PM
Just tried the Eicar download from nod32sse and using FireFox 2.0 the file downloaded without any interaction from Nod32 2.7.23. Has FF changed in some way IE7 the d/l gets terminated but not in FF. Anyone else confirm or is it just my settings ?
cupez80
December 21st, 2006, 12:41 AM
it seems that idm cause it. i change with another download manager and work fine now.
Banger696
December 21st, 2006, 02:07 PM
{QUOTE-> it seems that idm cause it. i change with another download manager and work fine now. <-QUOTE}
I'm just using standard FF 2 with download manager tweak and no matter what settings I use it still gets past Nod32 ???
Thankful
December 21st, 2006, 02:21 PM
I am running FF 2.0.0.1 with NOD32 2.70.23. I tested the Eicar file and NOD32 caught it and reported file in Threat Log. What download manager tweak are you using?
Banger696
December 21st, 2006, 02:38 PM
I'm using 2.0.0.1 too and this extension (http://dmextension.mozdev.org/).
Cheers
Thankful
December 21st, 2006, 02:55 PM
I installed the extension and restarted FF. NOD32 still had no problem with the Eicar virus.
Banger696
December 21st, 2006, 03:01 PM
{QUOTE-> I installed the extension and restarted FF. NOD32 still had no problem with the Eicar virus. <-QUOTE}
I've double checked my settings and uninstalled the extension, NOD still lets me download the eicar test file. :o and nothing in the threat log :(
cupez80
December 21st, 2006, 08:42 PM
have you set your client compatibility setting in NOD32 http scanner(IMON) ? set to high efficiency
Banger696
December 21st, 2006, 08:47 PM
{QUOTE-> have you set your client compatibility setting in NOD32 http scanner(IMON) ? set to high efficiency <-QUOTE}
Tried that made no difference. :wacko: Also tried running FF in safe mode with all extensions disabled and re-installing both FF and Nod32 and it still bypasses nod32 and lets me download. I tried the test files from eicar.com and they were blocked - all of them, just not the test file on nod32sse.com. IE7 blocks ok just FF that doesn't.
ronjor
December 21st, 2006, 09:02 PM
This is what I get using higher compatibility settings in NOD using Firefox.
Banger696
December 21st, 2006, 09:06 PM
{QUOTE-> This is what I get using higher compatibility settings in NOD using Firefox. <-QUOTE}
Hi Ron thats what I get on the eircar site but the test file on nod32sse.com totally bypasses Nod32, I'm worried that someone will exploit this weakness.
ronjor
December 21st, 2006, 09:31 PM
Banger696,
Thanks for the link. I still get a warning using typical settings in NOD on the Eicar file at the nod32sse.com site using Firefox. It does state it is downloading a harmless file. Not sure where it went but I can't find it. (I did terminate the download) And, because NOD knows this file is "malware", it will go nowhere.
Banger696
December 21st, 2006, 09:40 PM
{QUOTE-> Banger696,
Thanks for the link. I still get a warning using typical settings in NOD on the Eicar file at the nod32sse.com site using Firefox. It does state it is downloading a harmless file. Not sure where it went but I can't find it. (I did terminate the download) And, because NOD knows this file is "malware", it will go nowhere. <-QUOTE}
Hi RonJor I don't get that warning with the nod32 site for some reason despite re-installing Nod32 using BS settings and Firefox 2. I used to get that warning before I updated to FF 2 but now I don't. I have no option to terminate the download but with IE7 I get the warning Dialog. :gack:
ronjor
December 21st, 2006, 09:49 PM
Not sure what's going on Banger696. You could try Firefox in the (Firefox) safe mode located on your start menu and see if that makes a difference. That would eliminate any extension interference.
Barring that, you could try using the default settings in NOD.
Banger696
December 21st, 2006, 10:12 PM
{QUOTE-> Not sure what's going on Banger696. You could try Firefox in the (Firefox) safe mode located on your start menu and see if that makes a difference. That would eliminate any extension interference.
Barring that, you could try using the default settings in NOD. <-QUOTE}
I think you have fixed it Ron. Safe mode in FF didn't help but resetting Imon to the default settings seems to have fixed it.
I still don't get the warning dialog but Imon seems to clean the Zip file of the infection and quarantine it now and download the empty multiple zip files. Imon says infections detected 1 and cleaned 1 thats good enough for me cheers Ron. :)
Edit: I spoke to soon. It's not repeatable it still downloads the zip file with eicar.com in tact. I think the cleaned file was from the eicar.com site that I tested before. I'm really stuck now - help!
Thankful
December 21st, 2006, 11:06 PM
A couple of things:
Is Port 80 included in the IMON->Setup->HTTP protocol?
Did you try FF with the default theme?
What other extensions do you have installed?
Banger696
December 22nd, 2006, 04:38 AM
{QUOTE-> A couple of things:
Is Port 80 included in the IMON->Setup->HTTP protocol?
Did you try FF with the default theme?
What other extensions do you have installed? <-QUOTE}
Yes port 80 is included and I tried in FF safe mode with all extensions and themes disabled - still the same behaviour. Any more ideas ?
Brian N
December 22nd, 2006, 05:38 AM
You sure IMON is set to scan archives?
Ocky
December 22nd, 2006, 06:03 AM
{QUOTE-> Banger696,
Not sure where it went but I can't find it. (I did terminate the download) And, because NOD knows this file is "malware", it will go nowhere. <-QUOTE}
Works fine with Opera, but what do you mean by 'Not sure where it went but I can't find it.' Surely when the download is terminated, as you did, that's it, no download of the malicious file(s). ???
ronjor
December 22nd, 2006, 08:10 AM
{QUOTE-> that's it, no download of the malicious file <-QUOTE} That's correct Ocky. Nothing was downloaded.
Ocky
December 22nd, 2006, 08:37 AM
Thanks ronjor, and Merry Christmas.
Banger696
December 22nd, 2006, 02:40 PM
{QUOTE-> You sure IMON is set to scan archives? <-QUOTE}
Yes, like I say if I download the file in IE7 Nod32 blocks it with a warning window offering me the option to terminate it. This is what I get with IE7. FF just happily downloads the file.
Brian N
December 22nd, 2006, 03:12 PM
Hmm.. Try these
1. http://dl.nod32sse.com/eicar.rar
2. http://dl.nod32sse.com/eicar.zip
3. http://dl.nod32sse.com/eicar.com
Banger696
December 22nd, 2006, 03:21 PM
{QUOTE-> Hmm.. Try these http://dl.nod32sse.com/eicar.rar, http://dl.nod32sse.com/eicar.zip & http://dl.nod32sse.com/eicar.com <-QUOTE}
All of those were blocked by Nod32 which popped up the red warning dialog in Firefox. Could it be how firefox gets the file ?
Brian N
December 22nd, 2006, 03:23 PM
Ok try this: http://dl.nod32sse.com/10.zip
Banger696
December 22nd, 2006, 03:31 PM
{QUOTE-> Ok try this: http://dl.nod32sse.com/10.zip <-QUOTE}
That was blocked with a red warning window and terminated.
Brian N
December 22nd, 2006, 03:48 PM
Hmm... But you can download it if you click the "AV test file" link?
This is very strange. Did you try to empty the cache too?
Banger696
December 22nd, 2006, 03:59 PM
{QUOTE-> Hmm... But you can download it if you click the "AV test file" link?
This is very strange. Did you try to empty the cache too? <-QUOTE}
Guess what clearing the cache fixed it ! Not sure why but I feel safer now !
Brian N
December 22nd, 2006, 04:08 PM
Nice :)
Banger696
December 22nd, 2006, 04:22 PM
{QUOTE-> Nice :) <-QUOTE}
Many thanks for your help with this Brian and Happy Holidays. ;D
vBulletin® Copyright ©2000-2009, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2009, Wilders Security Forums