![]() |
|
#1
|
|||
|
|||
|
Hi,
We have a customer running EE with XMON and there server is scheduled to reboot every wednesday early morning. Until the server is logged onto at the start of the day they appear to be having various infected files get past XMON and be picked up by EMON on the local desktops, is this standard behaviour? Does NOD require that the server be logged into once before kicking in properly? Regards Greg. Last edited by GSteer : August 10th, 2007 at 04:43 AM. |
|
#2
|
|||
|
|||
|
Yes, you have to log in after the system boots in order for the program to start running. However, once you log in, if you log out again, it will continue to run. But, yes, it's like any other program. Windows needs to load completely to get it goin'.
![]() |
|
#3
|
||||
|
||||
|
Quote:
Many programs designed to run on servers, will start as a "service"...regardless if the server has been logged in or not. Exchange itself starts as a server, you don't need to log onto the server Remote access programs such as PcAnywhere, or various VNC flavors..can run host mode as a service. SQL server.. Exchange itself... IIS I could fill the capacity of this forums hard drive space with a list.....
__________________
Guinness for Strength! |
|
#4
|
|||
|
|||
|
Quote:
Thats where my thoughts were coming from YeOldeStoneCat. Lets home version 3 sets xmon as a service (if it still exists in this form). I'm going to have to look at some sort of temporary auto logon script for rebooting some of remote servers now, anyone got any immediate pointers? I can't really leave any server "unprotected" by not logging it in even if its a scheduled reboot at some godforsaken hour in the morning. |
|
#5
|
|||
|
|||
|
Hmm...
Amon also starts before login, why xmon doesn't?? Is it possible to run xmon as service? |
|
#6
|
||||
|
||||
|
Quote:
Quote:
Cheers ![]()
__________________
1. What is right is always The Truth. 2. Every Truth is supported in agreement by every Truth. 3. If the facts would persuade you otherwise, see 1. ESET Reseller (Australia) |
|
#7
|
|||
|
|||
|
Quote:
No, the communication between NOD32 and MS Exchange is as follows: MS Exchange <=VSAPI=> XMON <===> NOD32 Kernel As soon as the kernel is loaded XMON is ready to communicate with MS Exchange. |
|
#8
|
|||
|
|||
|
Quote:
In that case - any ideas why these infected files are getting through? I've grabbed these screenies this morning as it really doesn't appear right XMON - No Infected Files: http://www.fundamentalchaos.org.uk/k...es-nodxmon.gif AMON - Picking up Infected NOD Temp file from the exchange store? http://www.fundamentalchaos.org.uk/k...es-nodamon.gif Any ideas as it seems that XMON really isn't working! |
|
#9
|
|||
|
|||
|
Please PM me a threat log from one of the workstations where EMON detected such a threat.
|
|
#10
|
|||
|
|||
|
Quote:
Hi Marcos - have been in touch with Dan at UK eset support - we've upgraded XMON to 2.71.9 to see if it resolves the issue. |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|