rpremuz
March 30th, 2009, 01:18 PM
Hi!
On a MS Windows Server 2003 SP2 with all Microsoft high-priority updates installed I have ESET NOD32 Antivirus 4.0.314 Business Edition (see more details about the server configuration below). The server has a few file shares that have very low traffic. Client systems (MS Windows XP Pro. SP3, fully patched, with ESET NOD32 Antivirus 4.0.314 Business Edition) can copy, save and open files on the file shares without problems with most applications (e.g. Windows Explorer, xcopy, notepad, wordpad, IE7, Firefox 3, MS Office 2003 applications, OpenOffice.org 3 applications).
But if I open a shared file on a client with my favorite text editor VIM (ver. 7.2, both command line and GUI), the file opening is delayed for about 10 seconds. The delay does not depend on file size or type -- it happens even for an empty plain text file. Once the VIM opens the file all subsequent file operations (read and write) are carried out without a delay.
The problem exists only if the files are opened over the network. If the files are opened with VIM editor locally on the server, there is no delay in opening.
The problem disappears if the real-time file system protection is disabled in NOD32 AV v4 on the server. The problem didn't exist with NOD32 AV v3 on that server (I upgraded to v4 two weeks ago).
The Event Log in Windows Server 2003 does not log any errors when the problem occurs, while the Event Log in the Windows XP Pro. SP3 client usually logs the following warning:
Event Type: Warning
Event Source: MRxSmb
Event Category: None
Event ID: 3019
Description:
The redirector failed to determine the connection type.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 00000000 004e0004 00000000 80000bcb
0010: 00000000 c0000010 00000000 00000000
0020: 00000000 00000000
The most serious thing about this problem is that it can make the server unresponsive. I tried to open many files at once with VIM (using the "Edit with multiple Vims" option in context menu in Windows Explorer) -- the server became unresponsive and after waiting for about 30 minutes I shut it down by power button. If I do the same test when the real-time file system protection is disabled in NOD32 AV v4, the server does not experience any problems.
Here follows the summary of more testing of the problem (SMB server is the system that shares files while the SMB client is the system where the shared files are opened):
|--------------------------------------------------------------------------------------------------------------|
|SMB Server ------> |WinServ 2003 SP2 |WinServ 2003 SP2 |WinXP Pro. SP3 |WinXP Pro. x64 SP2 |Ubuntu 8.04 Desk. |
|-------------------|NOD32 4.0.314 |NOD32 2.71.9 |NOD32 4.0.314 |NOD32 4.0.314 |no real-time AV |
|SMB Client ---v | | | | | |
|--------------------------------------------------------------------------------------------------------------|
|WinServ 2003 SP2 | | | | | |
|NOD32 4.0.314 | ? | OK | OK | OK | OK |
|VIM 7.2 | | | | | |
|--------------------------------------------------------------------------------------------------------------|
|WinServ 2003 SP2 | | | | | |
|NOD32 2.71.9 | PROBLEM EXIST | ? | OK | OK | OK |
|VIM 7.2 | | | | | |
|--------------------------------------------------------------------------------------------------------------|
|WinXP Pro. SP3 | | | | | |
|NOD32 4.0.314 | PROBLEM EXIST | OK | OK | OK | OK |
|VIM 7.2 | | | | | |
|--------------------------------------------------------------------------------------------------------------|
|WinXP Pro. x64 SP2 | | | | | |
|NOD32 4.0.314 | PROBLEM EXIST | OK | OK | ? | OK |
|VIM 7.2 64-bit | | | | | |
|--------------------------------------------------------------------------------------------------------------|
|Ubuntu 8.04 Desk. | | | | | |
|no real-time AV | OK | OK | OK | OK | ? |
|VIM 7.1 | | | | | |
|--------------------------------------------------------------------------------------------------------------
Hardware configuration of the server:
Supermicro X6DHE-G (Intel E7520 Chipset)
2 x Xeon 3 GHz FSB 800 MHz
4 GB 333MHz PC2700 DDR ECC Reg.
3WARE SATA RAID 9500S controller
RAID1 250 GB
LAN adapter // driver: Intel PRO/1000 MT // e1000325.sys ver. 8.9.1.0 by Intel
Software configuration of the server:
MS Windows Server 2003 SP2
Active Directory, DNS, DHCP, MS WSUS 3.0
IE7, Mozilla Firefox 3.0.8
All high-priority updates from Microsoft.
ESET software on the server:
ESET RAS 3.0.105, ESET RAC 3.0.105
ESET NOD32 Antivirus 4.0.314 Business Edition
Virus signature database: 3973 (20090329)
Update module: 1028 (20090302)
Antivirus and antispyware scanner module: 1201 (20090327)
Advanced heuristics module: 1092 (20090309)
Archive support module: 1092 (20090324)
Cleaner module: 1039 (20090320)
Anti-Stealth support module: 1010 (20090302)
System status module: 1206 (20090206)
Self-defense support module : 1005 (20081105)
The XML configuration file is in the attachment.
If hope this issue will be fixed ASAP.
-- rpr. /Robert Premuž/
On a MS Windows Server 2003 SP2 with all Microsoft high-priority updates installed I have ESET NOD32 Antivirus 4.0.314 Business Edition (see more details about the server configuration below). The server has a few file shares that have very low traffic. Client systems (MS Windows XP Pro. SP3, fully patched, with ESET NOD32 Antivirus 4.0.314 Business Edition) can copy, save and open files on the file shares without problems with most applications (e.g. Windows Explorer, xcopy, notepad, wordpad, IE7, Firefox 3, MS Office 2003 applications, OpenOffice.org 3 applications).
But if I open a shared file on a client with my favorite text editor VIM (ver. 7.2, both command line and GUI), the file opening is delayed for about 10 seconds. The delay does not depend on file size or type -- it happens even for an empty plain text file. Once the VIM opens the file all subsequent file operations (read and write) are carried out without a delay.
The problem exists only if the files are opened over the network. If the files are opened with VIM editor locally on the server, there is no delay in opening.
The problem disappears if the real-time file system protection is disabled in NOD32 AV v4 on the server. The problem didn't exist with NOD32 AV v3 on that server (I upgraded to v4 two weeks ago).
The Event Log in Windows Server 2003 does not log any errors when the problem occurs, while the Event Log in the Windows XP Pro. SP3 client usually logs the following warning:
Event Type: Warning
Event Source: MRxSmb
Event Category: None
Event ID: 3019
Description:
The redirector failed to determine the connection type.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 00000000 004e0004 00000000 80000bcb
0010: 00000000 c0000010 00000000 00000000
0020: 00000000 00000000
The most serious thing about this problem is that it can make the server unresponsive. I tried to open many files at once with VIM (using the "Edit with multiple Vims" option in context menu in Windows Explorer) -- the server became unresponsive and after waiting for about 30 minutes I shut it down by power button. If I do the same test when the real-time file system protection is disabled in NOD32 AV v4, the server does not experience any problems.
Here follows the summary of more testing of the problem (SMB server is the system that shares files while the SMB client is the system where the shared files are opened):
|--------------------------------------------------------------------------------------------------------------|
|SMB Server ------> |WinServ 2003 SP2 |WinServ 2003 SP2 |WinXP Pro. SP3 |WinXP Pro. x64 SP2 |Ubuntu 8.04 Desk. |
|-------------------|NOD32 4.0.314 |NOD32 2.71.9 |NOD32 4.0.314 |NOD32 4.0.314 |no real-time AV |
|SMB Client ---v | | | | | |
|--------------------------------------------------------------------------------------------------------------|
|WinServ 2003 SP2 | | | | | |
|NOD32 4.0.314 | ? | OK | OK | OK | OK |
|VIM 7.2 | | | | | |
|--------------------------------------------------------------------------------------------------------------|
|WinServ 2003 SP2 | | | | | |
|NOD32 2.71.9 | PROBLEM EXIST | ? | OK | OK | OK |
|VIM 7.2 | | | | | |
|--------------------------------------------------------------------------------------------------------------|
|WinXP Pro. SP3 | | | | | |
|NOD32 4.0.314 | PROBLEM EXIST | OK | OK | OK | OK |
|VIM 7.2 | | | | | |
|--------------------------------------------------------------------------------------------------------------|
|WinXP Pro. x64 SP2 | | | | | |
|NOD32 4.0.314 | PROBLEM EXIST | OK | OK | ? | OK |
|VIM 7.2 64-bit | | | | | |
|--------------------------------------------------------------------------------------------------------------|
|Ubuntu 8.04 Desk. | | | | | |
|no real-time AV | OK | OK | OK | OK | ? |
|VIM 7.1 | | | | | |
|--------------------------------------------------------------------------------------------------------------
Hardware configuration of the server:
Supermicro X6DHE-G (Intel E7520 Chipset)
2 x Xeon 3 GHz FSB 800 MHz
4 GB 333MHz PC2700 DDR ECC Reg.
3WARE SATA RAID 9500S controller
RAID1 250 GB
LAN adapter // driver: Intel PRO/1000 MT // e1000325.sys ver. 8.9.1.0 by Intel
Software configuration of the server:
MS Windows Server 2003 SP2
Active Directory, DNS, DHCP, MS WSUS 3.0
IE7, Mozilla Firefox 3.0.8
All high-priority updates from Microsoft.
ESET software on the server:
ESET RAS 3.0.105, ESET RAC 3.0.105
ESET NOD32 Antivirus 4.0.314 Business Edition
Virus signature database: 3973 (20090329)
Update module: 1028 (20090302)
Antivirus and antispyware scanner module: 1201 (20090327)
Advanced heuristics module: 1092 (20090309)
Archive support module: 1092 (20090324)
Cleaner module: 1039 (20090320)
Anti-Stealth support module: 1010 (20090302)
System status module: 1206 (20090206)
Self-defense support module : 1005 (20081105)
The XML configuration file is in the attachment.
If hope this issue will be fixed ASAP.
-- rpr. /Robert Premuž/