CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Nod32

 
Post new topic   Reply to topic       All -> FavForums -> x-Wall series [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
ggsearch

Special Response Team
Premium Member

Joined: Feb 09, 2004
Posts: 702
Location: Netherlands
Premium Team F@H

PostPosted: Mon Sep 13, 2004 8:30 am    Post subject: Nod32
Reply with quote

Can you give me the exact version of Nod32 that would work with X-wall?

I was look for v3 but i got this back after my question to Nod 32:

The very latest version of NOD32 has a slightly different classification
style. The beta is v. 2.000.11b.... the next full version will be v.
2.12.0 and the last increment will change to 1, 2, etc.


_________________
Do something back for CCSP: Donate!
Back to top
View users profile Send private message Visit posters website Yahoo Messenger MSN Messenger
x-Wall-team

Corporal
Corporal


Joined: Apr 19, 2004
Posts: 50
Location: USA

PostPosted: Mon Sep 13, 2004 12:46 pm    Post subject: compatiblity with NOD32
Reply with quote

Unfortunately, I am not a specialist in NOD version numbering.
I receive something named (nd98en3r.exe and ndnten3r.exe) about 3-4 months ago.
The bundles above include API and were tested with x-Wall. Everything was fine.
I was also promised that the API functionality would be included in regular version soon.
Special license for API access was compiled into x-Wall binaries.
Might be I confused the version numbers…..
I cannot contact them with the question now, nod32.com is down from my connection point Sad
I will certainly ask ESET about compatible version.

Back to top
View users profile Send private message Visit posters website
ggsearch

Special Response Team
Premium Member

Joined: Feb 09, 2004
Posts: 702
Location: Netherlands
Premium Team F@H

PostPosted: Tue Sep 14, 2004 5:31 pm    Post subject:
Reply with quote

The version I am currently using is:

Code:
NOD32 Antivirus System information
Virus signature database version:   1.869 (20040913)
Dated:   maandag 13 september 2004
Virus signature database build:   4836

Information on other scanner support parts
Advanced heuristics module version:   1.010 (20040902)
Advanced heuristics module build:   1061
Archive support module version:   1.003 (20030903)
Archive support module build version:   1056

Information on installed components
NOD32 For Windows NT/2000/XP - Base
Version:   2.000.6
NOD32 For Windows NT/2000/XP - Internet support
Version:   2.000.6
NOD32 for Windows NT/2000/XP - Standard component
Version:   2.000.6


Anyway, everything is working good, virusses get catched by Nod32 and S-wall does stop incomming or outgoing nasty's.. accept that this version of Nod32 is not showing up in the S-wall logfiles..


_________________
Do something back for CCSP: Donate!
Back to top
View users profile Send private message Visit posters website Yahoo Messenger MSN Messenger
x-Wall-team

Corporal
Corporal


Joined: Apr 19, 2004
Posts: 50
Location: USA

PostPosted: Wed Sep 15, 2004 7:31 am    Post subject: proper AV engine sign
Reply with quote

The main sign of correct NOD32 (or any other AV) version is check passing.
For that purpose, choose desired AV in setting tab and press test button.
There are 3 consecutive test checking AV compatibility exactly in the same way as x-Wall do in the network AV scanning.

Back to top
View users profile Send private message Visit posters website
x-Wall-team

Corporal
Corporal


Joined: Apr 19, 2004
Posts: 50
Location: USA

PostPosted: Fri Sep 17, 2004 8:59 am    Post subject: x-Wall + NOD32 2.12 = OK
Reply with quote

The problem with proper NOD32 version seems solved.
Beta 3.0.084
http://sphinx-soft.com/download/s-Wall-Setup.exe
works fine with NOD32 2.12

Don’t forget to manipulate with NOD options in NOD Control Center to avoid double (or triple) AV checking in x-Wall/quarantine path and directly in E-mail message box if AMON\DMON is used



Last edited by x-Wall-team on Mon Jul 17, 2006 7:34 am, edited 1 time in total
Back to top
View users profile Send private message Visit posters website
ggsearch

Special Response Team
Premium Member

Joined: Feb 09, 2004
Posts: 702
Location: Netherlands
Premium Team F@H

PostPosted: Fri Sep 17, 2004 12:25 pm    Post subject:
Reply with quote

I got it working Thumbs Up

Quote:
Don’t forget to manipulate with NOD options in NOD Control Center to avoid double (or triple) AV checking in x-Wall/quarantine path


In the Nod32 Control center:
AMON > setup > Exclusion > add > C:\PROGRAM FILES\X-WALL\QUARANTINE\

Quote:
and directly in E-mail message box if AMON\DMON is used

Now this part I do not understand for now...
Please explain what I should do...


_________________
Do something back for CCSP: Donate!
Back to top
View users profile Send private message Visit posters website Yahoo Messenger MSN Messenger
x-Wall-team

Corporal
Corporal


Joined: Apr 19, 2004
Posts: 50
Location: USA

PostPosted: Fri Sep 17, 2004 3:43 pm    Post subject: Possible additional AV configurations
Reply with quote

It concerns with all compatible x-Wall AVs (not only NOD32).
AV technology is very high developed. The times of simple file scanner were remained in the past. Every modern AV includes several opportunities that could interfere with x-Wall.
The interference is not dangerous and might cause only additional message boxes or slightly overload the system and nothing more.
However, it would be better to understand before than be surprised after.

Let’s examine the situation with NOD32.
There are several protecting technologies in addition to AV scanner (NOD32 itself)

- AMON – resident file monitoring.
x-Wall always temporary stores each piece of internet content in x-Wall\quarantine directory and then calls AV via API to check it for viruses. AMON (if enabled) immediately hooks the attempt to write potentially infected internet content as any other file operation. If the content (file) is infected, AMON will immediately prompt you. If you skip all possible AMON’s actions x-Wall will call NOD32 again with the same file. As the result, you will obtain double AV checking. If your action on AMON’s prompt is delete the file, x-Wall’s attempt to check the file will fail as the file has just deleted by AMON. To avoid that you could simply to disable AMON monitoring in x-Wall\quarantine at least.
Technology like AMON is certainly progressive. However, let us imagine, AMON (like any other resident monitor) will intercept each file operation. It might occur many times under the same file, each time the file is under operation. Files could be big and operations could be frequent… CPU (and possibly disk) overload is guaranteed. I know a story when AV file monitor was installed on machine with serious database. The first impression was a deadlock for unknown reason. Everything was working but inexpressible slowly….. Anyway, it is your choice. Remember, 99% of viruses arrive from the internet, but is not born on your disks.

- DMON could produce double-checking of the same data. First time the internet content is forwarded to NOD32 via API for AV conclusion, the second time, when the content become a web page or an e-mail, correspondent internet client (Internet Explorer or Outlook) might decide to check it again via DMON plug-ins. Only you could decide that you really need it.

- IMON acts similar to x-Wall, but x-Wall performs network operation at TCP-stack level (lower than socket level). Therefore, the probability of hijacking / intercepting of its operations is significantly lower. Furthermore, x-Wall does not require any port customization – all traffic detecting is automatic. As the result if you use IMON additionally to x-Wall, you will perform double-checking.

So, if you enable all of the options you will check the same up to four times in the next sequence
x-Wall – AMON – IMON – DMON.

Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> x-Wall series All times are GMT
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer