ICT_GUY Posted November 24, 2009 Posted November 24, 2009 (edited) I recently installed the latest 64bit version of Nod on our main DC, so far I have had two server hangs on two consecutive Tuesdays since installing it. It seems to be a common problem and It seems to be down to the UPHCLEAN running on the server, only post here to give people the heads up. Problems after upgrading NOD32 on File Server - Page 2 - Wilders Security Forums Edited November 24, 2009 by ICT_GUY
earlyriser Posted November 25, 2009 Posted November 25, 2009 Hi there. Which version of NOD32 (2, 3 or V4), and what OS? I have just completed a migration of our directory to Windows Server 2008/R2, and everything was fine, other than every so often, a few of the servers would just die. No events in the logs, could still ping the servers, but file shares were unresponsive and clicking anything on the desktop of the server brought the whole thing to a halt. These are brand new, HP Proliant DL380s with 32Gb RAM and Quad CPUs. I spent ages with performance monitoring and troubleshooting, switches etc. and eventually the light came on in my pea sized brain and I looked at the antivirus software. I've used NOD32 for years and had installed the latest version of NOD32 (v4, x64) without even thinking about compatibility. Searches in the Wilders Security Forums soon revealed many with exact or very similar issues. To cut a long story short, I uninstalled NOD32 V4, downloaded and installed V3 and configured as per Eset's recommendations, and the problems went away instantly. Phew...
ICT_GUY Posted November 25, 2009 Author Posted November 25, 2009 Hi there. Which version of NOD32 (2, 3 or V4), and what OS? I have just completed a migration of our directory to Windows Server 2008/R2, and everything was fine, other than every so often, a few of the servers would just die. No events in the logs, could still ping the servers, but file shares were unresponsive and clicking anything on the desktop of the server brought the whole thing to a halt. These are brand new, HP Proliant DL380s with 32Gb RAM and Quad CPUs. I spent ages with performance monitoring and troubleshooting, switches etc. and eventually the light came on in my pea sized brain and I looked at the antivirus software. I've used NOD32 for years and had installed the latest version of NOD32 (v4, x64) without even thinking about compatibility. Searches in the Wilders Security Forums soon revealed many with exact or very similar issues. To cut a long story short, I uninstalled NOD32 V4, downloaded and installed V3 and configured as per Eset's recommendations, and the problems went away instantly. Phew... I was using the latest version, version 3 also screws things up royally. So the main DC has no AV at the moment. Mine too was a Proliant server running 64 bit 2008.
cookie_monster Posted November 25, 2009 Posted November 25, 2009 (edited) I'm still avoiding V4 on servers for these reasons but I have 3.0.657 and 3.0.684 running on server 2003 SP2 and server 2008 SP2 without issue, they're both x32 though. I do have an issue with one 2008 DC freezing on login occasionaly and I'm hoping it's not NOD, I've configured a few of the recommended exclusions and it seems ok for now. Edited November 25, 2009 by cookie_monster
ICT_GUY Posted November 25, 2009 Author Posted November 25, 2009 I'm still avoiding V4 on servers for these reasons but I have 3.0.657 and 3.0.684 running on server 2003 SP2 and server 2008 SP2 without issue, they're both x32 though. I do have an issue with one 2008 DC freezing on login occasionaly and I'm hoping it's not NOD, I've configured a few of the recommended exclusions and it seems ok for now. Yes I have no problems on my 32 bit servers. I am getting flak for the two times the system has frozen (2 times in 5 years) but I dont like leaving my main dc naked.
cookie_monster Posted November 25, 2009 Posted November 25, 2009 Yes I have no problems on my 32 bit servers. I am getting flak for the two times the system has frozen (2 times in 5 years) but I dont like leaving my main dc naked. I know what you mean. At least on 2008 you can run the firewall and you won't be browsing the net so your risk is limited.
ICT_GUY Posted November 25, 2009 Author Posted November 25, 2009 I have just spoken to Eset, they have said its down to file exclusions, I did mention the fact that it works fine on my 32bit servers, so they said to install the latest build, add the file exclusions and all should be fine. Now, do I go and test this crud in a live environment since if it goes wrong I will have everyone and their wife coming in and telling me "it don't work, will it work next week, I need it for BLAH BLAH BLAH..>" BTW I am not having a good week, the chest freezer blew this morning and Christmas is coming, both equally expensive and just about as much fun shelling out for. BAH HUMBUG.
ICT_GUY Posted November 25, 2009 Author Posted November 25, 2009 Virus scanning recommendations for computers that are running Windows Server 2008 R2, Windows Server 2008, Windows Server 2003, Windows 2000, Windows XP, Windows Vista, or Windows 7 This is the typical MS article detailing which files need to be excluded. I have to wonder why this is not automatically set when you install nod onto a SBS server.
cookie_monster Posted November 25, 2009 Posted November 25, 2009 Yep as I mentioned above following the exclusions seemed to work on our servers but there is one that freezes occasionally but it's so infrequent I can't pin it down.
leco Posted November 25, 2009 Posted November 25, 2009 I have Nod V3 (can't remember which version) on x64 Server 2008, though not a Proliant. I too followed the exclusion list and so far it's working. V3 is also on the 2003 x32 Server. I agree that the exclusions should be built in to the install as if you miss one can cause all sorts of issues.
ICT_GUY Posted November 25, 2009 Author Posted November 25, 2009 (edited) I have Nod V3 (can't remember which version) on x64 Server 2008, though not a Proliant. I too followed the exclusion list and so far it's working. V3 is also on the 2003 x32 Server. I agree that the exclusions should be built in to the install as if you miss one can cause all sorts of issues. Well it might also explain some other issues I have been having with joining PCs to the network (directory service busy), possibly. I would have thought that some warning somewhere would have displayed. I am still wondering if to attempt to install the AV on the main DC knowing the amount of I will get if it falls over next week Edited March 20, 2010 by EduTech language
cookie_monster Posted November 25, 2009 Posted November 25, 2009 Well that's timing one of my x32 2008 servers just died. This one is a VM and all of the other VM's on the box carried on just fine, this is just a file server so no extra complicated services or software to interfere. Just ploughing the event logs now.
cookie_monster Posted November 25, 2009 Posted November 25, 2009 I missed an exclusion on a directory "C:\Windows\SoftwareDistribution\DataStore\Logs", on the server that crashed there's loads of log files all created today, on all of the other servers there's only a couple. I wonder if that could signify anything, I've added the exclusion so i suppose it's a waiting game now.
ICT_GUY Posted November 25, 2009 Author Posted November 25, 2009 I have excluded *.log, looking through the exclusions, MS have given best practice though I am more concerned that I do not miss any exclusions and have the DC hang again.
cookie_monster Posted November 25, 2009 Posted November 25, 2009 Once you've finished adding all of the exceptions the list is pretty long. I'm surprised they don't have profiles for different server roles as you say.
cookie_monster Posted December 2, 2009 Posted December 2, 2009 Interestingly (or not) a couple of my 2008 servers have recently suddenly ground to a halt and had to be restarted. It's happened a couple of times while I'm logged on to the server I’ll be doing something, copying a file or changing a GPO when suddenly it will pause and start behaving erratically this will continue to happen until it crashes. This morning the same thing happened and we all noticed as our desktops locked up due to our profiles being on this server, luckily I still had an RDP session open to the server so I managed to right click the NOD32 tray icon and disable active scanning. The server immediately sprang back to life. I'm currently on 3.0.684 which I recently updated this server to from 3.0.657 I'm going to go back to 3.0.657 tonight to see if that helps. Both servers are 2008 SP2 with all of the recommended AV exclusions set, one is a physical DC and the other that is affected is a VM on Xenserver, both are good upto date servers HP and Sun with upto date drivers (not really an issue with the VM). When the VM went down all other VM's on the Xenserver box were fine so I don't think it's an issue with the server hardware, SAN or switch.
earlyriser Posted December 2, 2009 Posted December 2, 2009 I wonder if this is a case of a company/product growing too big too fast? I have used and recommended NOD32 for years as an antivirus product on desktops and unthinkingly didn't hesitate to stick it on our new servers (and others). In the back of my mind I've always been a bit concerned though that there was very little information from ESET regarding configuration on servers. I remember ringing them a few years ago and getting a fairly generic "it's the same on servers as it is on workstations" response and at the time thinking that they really didn't have a clue. I rang them earlier in the year about installing on a Server Core installation and they were like "what's that then?...." At least they have some basic recommendations now, and combined with the Microsoft generic antivirus exclusions some of us seem to be able to achieve something workable, but an enterprise class product should be better than this. Come on ESET, employ someone to test your products properly on servers and save us some pain. Since back revving to version 3.0.657 on all of our 2008 R2 and 2008 servers and configuring the exclusions etc. our issues seem to have settled. However, I didn't follow the recommendations exactly. At the moment I have the whole sysvol and NTDS directories excluded as I was convinced this was the problem. Not great for security but at least we can all log on now........
ICT_GUY Posted December 3, 2009 Author Posted December 3, 2009 The problem I had with joining pcs to the network, "Directory service busy PC joined under the old name" is now history, after I added the exclusion lists to the Second DC. Slightly happier now. Though why this was not part of the install I have no idea.
cookie_monster Posted December 3, 2009 Posted December 3, 2009 (edited) Well it didn it again today but this time I received an error just before oh YAY, I might contact ESET now I have something to tell them. I've dissabled active scanning again to test. Faulting application ekrn.exe, version 3.0.657.0, time stamp 0x480f2a9e, faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code 0xc0000005, fault offset 0x0448d49b, process id 0x1460, application start time 0x01ca73ec6e8edb14. ESET have told me to go to the latest version before they'll take a look. They also pointed me to their list of exclusions as well as the MS recommendations. http://kb.eset.com/esetkb/index?page=content&id=SOLN727 I'll let you all know what happens. Edited December 3, 2009 by cookie_monster
cookie_monster Posted December 14, 2009 Posted December 14, 2009 Typical, I've updated the server to 4.0.474 this morning and added the exclusions and it's going ok so far but I've encountered an issue that was easily solvable on V3. On boot up I get an error in the event logs. The ESET Service service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly. On V3 I would simply untick the 'Allow service to interact with desktop' box and the error never returned. With V4 when I try to do this I receive an access denied error does anyone else using V4 see this error? I know that interactive should allow scanning of network drives but I have this turned off anyway. Ideas? Thanks.
ICT_GUY Posted January 20, 2010 Author Posted January 20, 2010 (edited) What the hell is is it with this ****ware? My second server (which has all the exceptions manually put in) decided today that it would not let me log onto it, either remotely or locally. After an hour of trying various fixes (resulting in 6+ reboots) I decided to uninstall nod32. Bingo its now a happy server. Anti virus software for servers needs to be bullet proof, its why these solutions typically cost 10 x as much as the consumer versions. This pile of poo has caused all of the failures on my servers over the past year, in excess of 10 server hangs which personally is 10 too many for a server level product. Yet this is what county insist we use Edited January 20, 2010 by ICT_GUY Inchoerent ranting
cookie_monster Posted January 20, 2010 Posted January 20, 2010 What the hell is is it with this ****ware? My second server (which has all the exceptions manually put in) decided today that it would not let me log onto it, either remotely or locally. After an hour of trying various fixes (resulting in 6+ reboots) I decided to uninstall nod32. Bingo its now a happy server. Anti virus software for servers needs to be bullet proof, its why these solutions typically cost 10 x as much as the consumer versions. This pile of German Shepherd of poo (trust me they poop a lot) has caused me all of the failures of my servers over the past year, in excess of 10 server hangs which personally is 10 too many for a server level product. Yet this is what county insist we use I'm thought it was originally from an eastern european company but is now based in the U.S. Anyway i've not had any issue on my servers since going to 4.0.474.0 what version are you on now? These are the exclusions I have set now. C:\ProgramData\ntuser.pol C:\Windows\NTDS\*.log C:\Windows\NTDS\edb.chk C:\Windows\NTDS\edb.log C:\Windows\NTDS\edbres00001.jrs C:\Windows\NTDS\edbres00002.jrs C:\Windows\NTDS\edbtmp.log C:\Windows\NTDS\ntds.dit C:\Windows\NTDS\Ntds.pat C:\Windows\NTDS\temp.edb C:\Windows\ntfrs\jet\log\*.log C:\Windows\ntfrs\jet\log\edbres00001.jrs C:\Windows\ntfrs\jet\log\edbres00002.jrs C:\Windows\ntfrs\jet\ntfrs.jdb C:\Windows\ntfrs\jet\sys\edb.chk C:\Windows\security\*.chk C:\Windows\security\*.edb C:\Windows\security\*.log C:\Windows\security\*.sdb C:\Windows\security\database\*.log C:\Windows\security\database\edb.chk C:\Windows\security\database\edb.log C:\Windows\security\database\edbres00001.jrs C:\Windows\security\database\edbres00002.jrs C:\Windows\security\database\security.sdb C:\Windows\security\database\Tmp.edb C:\Windows\SoftwareDistribution\DataStore\DataStore.edb C:\Windows\SoftwareDistribution\DataStore\logs\Edb*.log C:\Windows\SoftwareDistribution\DataStore\Logs\edb.chk C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log C:\Windows\SoftwareDistribution\DataStore\Logs\edbres00001.jrs C:\Windows\SoftwareDistribution\DataStore\Logs\edbres00002.jrs C:\Windows\SoftwareDistribution\DataStore\Logs\tmp.edb C:\Windows\System32\dhcp\*.* C:\Windows\System32\dns\*.* C:\Windows\System32\dns\backup\*.* C:\Windows\System32\GroupPolicy\*.* C:\Windows\System32\GroupPolicy\Machine\Registry.pol C:\Windows\SYSVOL\*.* C:\Windows\SYSVOL\domain\DO_NOT_REMOVE_NtFrs_PreInstall_Directory\*.* C:\Windows\SYSVOL\stagingareas\*.* C:\Windows\SYSVOL\staging\*.* C:\Windows\SYSVOL\sysvol\*.* 1
ICT_GUY Posted January 20, 2010 Author Posted January 20, 2010 Thanks, now do I install this again with the latest version on the off chance that it will kill my server again?
cookie_monster Posted January 20, 2010 Posted January 20, 2010 Thanks, now do I install this again with the latest version on the off chance that it will kill my server again? Thats your call I waited until after school then put it on to give me time to set the exceptions. There's alsp a few NOD tweeks like turning off email scanning and a few other features i'll post it when I find it. Why they don't have this rolled into a 'Server Install' option is beyond me. Ah here you go. http://kb.eset.com/esetkb/index?page=content&id=SOLN2144 Once i set the exclusions and followed the link above the issues went away.
ICT_GUY Posted January 20, 2010 Author Posted January 20, 2010 Thats your call I waited until after school then put it on to give me time to set the exceptions. There's alsp a few NOD tweeks like turning off email scanning and a few other features i'll post it when I find it. Why they don't have this rolled into a 'Server Install' option is beyond me. Ah here you go. ESET Knowledgebase - What are the recommended settings for ESET NOD32 Antivirus installed on a server? (4.0) Once i set the exclusions and followed the link above the issues went away. Thanks, I had done the exclusion list, and the server worked well until today. Does the evil monkey pointing at Eset. http://purpleentertainmentonline.com/Evil_Monkey_301.gif
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now