MSAS alerts and HOSTS file issue

J

Jbob

Noticed some issues using MSAS .614 on a new build of XP Pro. I just
loaded a
new hard drive with XP Pro/sp2. Fully patched. After I installed Office XP
and patched it I then installed all my AV/Anti-Spyware apps. Spybot S & D,
Ad-Aware, MSAS and got them fully updated. For now MSAS and NAV are my only
resident scanners. Not using Teatimer or Spybots immunize feature.

I then began installing many of my other apps. I never got any warnings from
MSAS of any installation changes to my system. After a few hours of
installing and tweaking I finally put in the MVPS Host file. Still nothing.
A few minutes later during a reboot all of a sudden MSAS popped a bunch of
warnings. Some of the warnings were for installations that had already
occured. I selected all the appropriate blocks to clear the warnings. Funny
I was able to fully add a new HOST file without a peep from MSAS.

I am able to duplicate this on another system but doesn't work that way on
all systems. Some I get an instant dialog alert some not.

After further checking I can safely say that MSAS should not be depended
upon for HOSTS file monitoring, at this level of development.

In tests on a machine that it is working, i.e. MSAS will alert me
immediately,
one single entry will generate a MSAS notification. If I enter more than 2
entries,
MSAS will only pop up one entry(the bottom/last one), which MSAS gives me
the option to allow or block, however it does not give the option for action
of
the other entries. After entering two new addtions to the HOSTS file, if I
tell
MSAS to block it it does, however the other entry is allowed.

I noticed this bahavior when adding a new HOSTS file to windows. If I use
either hpgugu's or the mvps version MSAS does notify of a HOSTS file change
but only the last entry is shown.

I suppose any notification is better than none though. One should always
check anytime MSAS notifies of a HOSTS file change.

Still doesn't answer WHY in my case on certain machines I get NO
notification. In this specific case it is more than a HOSTS file issue.
 
S

Steve Dodson [MSFT]

If the real-time agents are installed, you should get a warning as soon as
we look for changes. You can see a delay (it should not be too long) when a
host file is updated. The longest I ever saw was about a minute, but I have
not looked in the code to determine what the maxtime could be. We are doing
a lot of re-work for beta 2, and hopefully your experience will be better
then.

--
-steve

Steve Dodson [MSFT]
MCSE, CISSP
PSS Security
http://blogs.technet.com/stevedod
--

This posting is provided "AS IS" with no warranties, and confers no rights.
Use of included script samples are subject to the terms specified at
http://www.microsoft.com/info/cpyright.htm

Note: For the benefit of the community-at-large, all responses to this
message are best directed to the newsgroup/thread from which they
originated.
 
J

Jbob

Steve Dodson said:
If the real-time agents are installed, you should get a warning as soon as
we look for changes. You can see a delay (it should not be too long) when
a host file is updated. The longest I ever saw was about a minute, but I
have not looked in the code to determine what the maxtime could be. We are
doing a lot of re-work for beta 2, and hopefully your experience will be
better then.

--
-steve

Steve Dodson [MSFT]
MCSE, CISSP
PSS Security
http://blogs.technet.com/stevedod
--

Thanks! At least some one from developlment is watching these newsgroups.

Hopefully I was clear in my post but I am seeing 2 issues with MSAS. One is
the delayed notification issues. I am not sure but it appears to related to
a conflict with other apps installed. As I tried to say I have duplicated
this on one other computer but it doesn't happen on all.

I have one hard drive loaded with WinXP Pro only. Fully patched. No other
apps installed. I use this load for testing of MSAS. I can get an instant
alert on this computer. I used this computer to test the alerting issue.
Since it is harder for me to make any changes I just used the HOSTS file to
test MSASs alerting function. This is how I noticed the HOSTS file issue as
well. Hopefully I was clear enough on that one.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top