Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > Other ESET Home Products
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 8th, 2007, 06:43 AM
GSteer GSteer is offline
Infrequent Poster
 
Join Date: Aug 2006
Posts: 18
Default XMON - Launching and not detecting infections?

Hi,

We have a customer running EE with XMON and there server is scheduled to reboot every wednesday early morning.

Until the server is logged onto at the start of the day they appear to be having various infected files get past XMON and be picked up by EMON on the local desktops, is this standard behaviour?

Does NOD require that the server be logged into once before kicking in properly?

Regards

Greg.

Last edited by GSteer : August 10th, 2007 at 04:43 AM.
  #2  
Old August 8th, 2007, 08:36 PM
sparx sparx is offline
Regular Poster
 
Join Date: Jan 2007
Posts: 60
Default Re: XMON - Does it launch before logon?

Yes, you have to log in after the system boots in order for the program to start running. However, once you log in, if you log out again, it will continue to run. But, yes, it's like any other program. Windows needs to load completely to get it goin'.
  #3  
Old August 8th, 2007, 09:04 PM
YeOldeStonecat's Avatar
YeOldeStonecat YeOldeStonecat is offline
Very Frequent Poster
 
Join Date: Apr 2005
Location: Along the Shorelines somewhere in New England
Posts: 2,343
Default Re: XMON - Does it launch before logon?

Quote:
Originally Posted by sparx
But, yes, it's like any other program. Windows needs to load completely to get it goin'.

Many programs designed to run on servers, will start as a "service"...regardless if the server has been logged in or not.
Exchange itself starts as a server, you don't need to log onto the server
Remote access programs such as PcAnywhere, or various VNC flavors..can run host mode as a service.
SQL server..
Exchange itself...
IIS
I could fill the capacity of this forums hard drive space with a list.....
__________________
Guinness for Strength!
  #4  
Old August 9th, 2007, 03:52 AM
GSteer GSteer is offline
Infrequent Poster
 
Join Date: Aug 2006
Posts: 18
Default Re: XMON - Does it launch before logon?

Quote:
Originally Posted by YeOldeStonecat
Many programs designed to run on servers, will start as a "service"...regardless if the server has been logged in or not.
Exchange itself starts as a server, you don't need to log onto the server
Remote access programs such as PcAnywhere, or various VNC flavors..can run host mode as a service.
SQL server..
Exchange itself...
IIS
I could fill the capacity of this forums hard drive space with a list.....


Thats where my thoughts were coming from YeOldeStoneCat.

Lets home version 3 sets xmon as a service (if it still exists in this form).

I'm going to have to look at some sort of temporary auto logon script for rebooting some of remote servers now, anyone got any immediate pointers?

I can't really leave any server "unprotected" by not logging it in even if its a scheduled reboot at some godforsaken hour in the morning.
  #5  
Old August 9th, 2007, 04:22 AM
Megachip Megachip is offline
Frequent Poster
 
Join Date: Dec 2006
Posts: 243
Default Re: XMON - Does it launch before logon?

Hmm...

Amon also starts before login, why xmon doesn't??

Is it possible to run xmon as service?
  #6  
Old August 9th, 2007, 09:59 AM
NOD32 user's Avatar
NOD32 user NOD32 user is offline
Very Frequent Poster
 
Join Date: Jan 2005
Location: Australia
Posts: 1,766
Lightbulb Re: XMON - Does it launch before logon?

Quote:
Originally Posted by GSteer
Thats where my thoughts were coming from YeOldeStoneCat.

Lets home version 3 sets xmon as a service (if it still exists in this form).

I'm going to have to look at some sort of temporary auto logon script for rebooting some of remote servers now, anyone got any immediate pointers?

I can't really leave any server "unprotected" by not logging it in even if its a scheduled reboot at some godforsaken hour in the morning.
I'm quite sure you will find the auto login feature of Microsoft PowerToys 'Tweak UI' works even if that's the only feature you make use of.
Quote:
Originally Posted by www.microsoft.com
Tweak UI

This PowerToy gives you access to system settings that are not exposed in the Windows XP default user interface, including mouse settings, Explorer settings, taskbar settings, and more.
Version 2.10 requires Windows XP Service Pack 1 or Windows Server 2003
Download it from the list on the right: http://www.microsoft.com/windowsxp/d...powertoys.mspx

Cheers
__________________
1. What is right is always The Truth.
2. Every Truth is supported in agreement by every Truth.
3. If the facts would persuade you otherwise, see 1.

ESET Reseller (Australia)
  #7  
Old August 9th, 2007, 05:02 PM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,193
Default Re: XMON - Does it launch before logon?

Quote:
Originally Posted by GSteer
Does NOD require that the server be logged into once before kicking in properly?

No, the communication between NOD32 and MS Exchange is as follows:

MS Exchange <=VSAPI=> XMON <===> NOD32 Kernel

As soon as the kernel is loaded XMON is ready to communicate with MS Exchange.
  #8  
Old August 10th, 2007, 04:39 AM
GSteer GSteer is offline
Infrequent Poster
 
Join Date: Aug 2006
Posts: 18
Default Re: XMON - Does it launch before logon?

Quote:
Originally Posted by Marcos
No, the communication between NOD32 and MS Exchange is as follows:

MS Exchange <=VSAPI=> XMON <===> NOD32 Kernel

As soon as the kernel is loaded XMON is ready to communicate with MS Exchange.

In that case - any ideas why these infected files are getting through?

I've grabbed these screenies this morning as it really doesn't appear right

XMON - No Infected Files:
http://www.fundamentalchaos.org.uk/k...es-nodxmon.gif

AMON - Picking up Infected NOD Temp file from the exchange store?
http://www.fundamentalchaos.org.uk/k...es-nodamon.gif

Any ideas as it seems that XMON really isn't working!
  #9  
Old August 10th, 2007, 07:51 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,193
Default Re: XMON - Does it launch before logon?

Please PM me a threat log from one of the workstations where EMON detected such a threat.
  #10  
Old August 10th, 2007, 12:07 PM
GSteer GSteer is offline
Infrequent Poster
 
Join Date: Aug 2006
Posts: 18
Default Re: XMON - Does it launch before logon?

Quote:
Originally Posted by Marcos
Please PM me a threat log from one of the workstations where EMON detected such a threat.

Hi Marcos - have been in touch with Dan at UK eset support - we've upgraded XMON to 2.71.9 to see if it resolves the issue.
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > Other ESET Home Products « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 11:32 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums