Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 24th, 2008, 06:40 AM
nordeide's Avatar
nordeide nordeide is offline
Infrequent Poster
 
Join Date: Jul 2008
Location: Bergen, Norway
Posts: 11
Default NOD32 v2.7 Server 2003: Random hang

Hi y'all,

I have installed NOD32 v2.7 on a server running Windows Small Business Server 2003.
From time to time, which means anything from after 10 minutes to after several hours, the server freezes for about a minute. After that, all is fine until the next occurrance.

During that time, everything except the mouse pointer is stuck, meaning that some process takes 100% CPU capacity, Task Manager is not updated during that period. As a result, network traffic is halted, and users cannot access files.

I found out that disabling AMON solved the freeze problem, but that is of course a bad solution.

Any suggestions on how to optimize AMON and find out which file(s) that cause this hang?

Thanks!
  #2  
Old July 24th, 2008, 06:49 PM
BFG BFG is offline
Frequent Poster
 
Join Date: Oct 2004
Location: San Diego
Posts: 482
Default Re: NOD32 v2.7 Server 2003: Random hang

Hello,

Is AMON scanning all files or just the default file set? If all, see if it's one of the other extensions that AMON might be hanging on by just scanning the default.

Thank you,
BFG
  #3  
Old July 24th, 2008, 08:27 PM
spm spm is online now
Frequent Poster
 
Join Date: Dec 2002
Location: U.K.
Posts: 434
Default Re: NOD32 v2.7 Server 2003: Random hang

Try excluding *.log files from AMON scanning. NOD32 is poor at scanning log files which are updated regularly, as they are in SBS, especially during the hourly SBS monitoring tasks.
  #4  
Old July 27th, 2008, 03:15 PM
YeOldeStonecat's Avatar
YeOldeStonecat YeOldeStonecat is offline
Very Frequent Poster
 
Join Date: Apr 2005
Location: Along the Shorelines somewhere in New England
Posts: 2,343
Default Re: NOD32 v2.7 Server 2003: Random hang

Have you followed these exclusions?
http://www.sbsfaq.com/Lists/FAQs/DispForm.aspx?ID=137

"Listed below are the items and their default locations - your installation may be different.

Exchange Server Database = C:\Program Files\Exchsrvr\Mdbdata (see note above)
Exchange MTA files = C:\Program Files\Exchsrvr\Mtadata
Exchange Message tracking log files = C:\Program Files\Exchsrvr\server_name.log
Exchange SMTP Mailroot = C:\Program Files\Exchsrvr\Mailroot
Exchange working files = C:\Program Files\Exchsrvr\Mdbdata
Site Replication Service (not normally used in SBS but should be excluded anyway) = C:\Program Files\Exchsrvr\srsdata
C:\Program Files\Exchsrvr\Conndata

IIS related Exclusions
IIS System Files = C:\WINDOWS\system32\inetsrv
IIS Compression Folder = C:\WINDOWS\IIS Temporary Compressed Files

Domain Controller related exclusions
Active Directory database files = C:\WINDOWS\NTDS
SYSVOL C:\WINDOWS\SYSVOL
NTFRS Database Files = C:\WINDOWS\ntfrs

Windows SharePoint Services
Temporary SharePoint space = C:\windows\temp\Frontpagetempdir

Additional Exclusions
Removable Storage Database (used by SBS Backup) = C:\Windows\System32\ntmsdata
SBS POP3 connector Failed Mail = C:\Program Files\Microsoft Windows Small Business Server\Networking\POP3\Failed Mail
SBS POP3 connector Incoming Mail = C:\Program Files\Microsoft Windows Small Business Server\Networking\POP3\Incoming Mail
Windows Update Store = C:\WINDOWS\SoftwareDistribution\DataStore
DHCP Database Store = C:\WINDOWS\system32\dhcp
WINS Database Store = C:\WINDOWS\system32\wins


Desktop Folder Exclusions
These folders need to be excluded in the desktops and notebooks clients.

Windows Update Store = C:\WINDOWS\SoftwareDistribution\DataStore"
__________________
Guinness for Strength!
  #5  
Old July 30th, 2008, 08:31 AM
nordeide's Avatar
nordeide nordeide is offline
Infrequent Poster
 
Join Date: Jul 2008
Location: Bergen, Norway
Posts: 11
Default Re: NOD32 v2.7 Server 2003: Random hang

Thanks for your replies!

I start with excluding the Exchange files, and then I'll check if that's OK. If not, I'll try excluding the other areas as suggested. I think Exchange exclusions might be the answer, as that is the only significant application on the server.
  #6  
Old July 31st, 2008, 07:39 AM
YeOldeStonecat's Avatar
YeOldeStonecat YeOldeStonecat is offline
Very Frequent Poster
 
Join Date: Apr 2005
Location: Along the Shorelines somewhere in New England
Posts: 2,343
Default Re: NOD32 v2.7 Server 2003: Random hang

Quote:
Originally Posted by nordeide
Thanks for your replies!

I start with excluding the Exchange files, and then I'll check if that's OK. If not, I'll try excluding the other areas as suggested. I think Exchange exclusions might be the answer, as that is the only significant application on the server.

It would be prudent to follow all of them...they are important to keep the AV scanning engine out of. DHCP database corruption is common if it isn't excluded.
I also uncheck "Scan all files" in the file extension section
And in XMON..I uncheck background scanning.

Not having Exchange exclusions is without question VERY bad. No "think it might be the answer" about it. But the other ones are quite important also.
__________________
Guinness for Strength!
  #7  
Old August 7th, 2008, 05:48 AM
Biscuit Biscuit is offline
Frequent Poster
 
Join Date: May 2006
Location: Isle of Man
Posts: 976
Default Re: NOD32 v2.7 Server 2003: Random hang

I've found that Nod32 does not run well on W2003 since SP2. I've found that the reliable method is to disable AMON on any W2003 SP2 server.
__________________
Windows 7 32bit Ultimate SP1 | MS ISA 2004 Firewall | Malwarebytes | Firefox with NoScript | Acronis True Image
  #8  
Old August 7th, 2008, 06:52 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,193
Default Re: NOD32 v2.7 Server 2003: Random hang

It's a good idea to set AMON to scan files with default extension set. Also make sure that IMON is not loaded which is indicated by the grey IMON icon.
  #9  
Old August 8th, 2008, 07:58 AM
nordeide's Avatar
nordeide nordeide is offline
Infrequent Poster
 
Join Date: Jul 2008
Location: Bergen, Norway
Posts: 11
Thumbs up Re: NOD32 v2.7 Server 2003: Random hang

Hi again!

In this particular case, excluding the Exchange directories did the trick; the server responds normally now. But thanks for the list of exclusion recommendations, I'll apply them as well.

Thanks, everyone!
  #10  
Old August 13th, 2008, 07:18 AM
YeOldeStonecat's Avatar
YeOldeStonecat YeOldeStonecat is offline
Very Frequent Poster
 
Join Date: Apr 2005
Location: Along the Shorelines somewhere in New England
Posts: 2,343
Default Re: NOD32 v2.7 Server 2003: Random hang

Quote:
Originally Posted by Biscuit
I've found that Nod32 does not run well on W2003 since SP2. I've found that the reliable method is to disable AMON on any W2003 SP2 server.

I have many..many Server2003 boxes out there at various clients, no issues with NOD32 2.7. As long as you follow proper real time protection exclusions for your server (which holds true regardless of what brand AV you use on it). As well as turn down AMON to not scan all files.
__________________
Guinness for Strength!
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 03:05 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums