Java Mailing List Archive

http://www.dba.5341.com/

Home » Home (12/2007) » oracle l »

Re: McAfee Anti-virus software causing grief to Oracle binaries (win32)

Paul Drake

2006-03-12

Replies:

On 3/12/06, Paul Drake <bdbafh@gmail.com> wrote:
If you are using McAfee antivirus software on your win32 Oracle servers - check your logs.

It attempted to remove files such as Dell OpenManage, Cygwin, perl, Sysinternals pstools suite.
Basically, anything that was in the PATH environment variable was targeted.

Not only did it attempt to remove files in the %ORACLE_HOME%\bin directory, but also in the .patch_storage folder - so as far as oracle files, this was not limited to the PATH environment variable.

This was also capable of navigating mapped drives, so if you had a file server setup as a common install location, if filesystem permissions permitted modification of such files, you'll want to refresh the installation files from the downloaded, compressed source file.

More info to follow - I haven't even made coffee yet.

Paul


Apparently, this is a known issue.
Sounds like a good time to roll out 10.1.0.5 + 10.1.0.5 patch 1  (CPUJan2006).

Paul
 


http://isc.sans.org/diary.php?storyid=1179

Handler's Diary March 11th 2006


previous - next

McAfee/NAI rolls bad pattern

Published: 2006-03-11,
Last Updated: 2006-03-11 01:29:45 UTC by Daniel Wesemann (Version: 1)

NAI/McAfee today released pattern version 4716 only hours after 4715 had come out. Pattern 4715 triggered false positive virus alerts for "W95/CTX" on a number of files that are part of quite prominent third party products.  Good for you if you have your AV configured to "quarantine" bad files and not to delete them outright, this makes restoring the chewed up files after a false positive considerably faster. Nevertheless, things like this can get messy pretty quickly if the AV scanner starts to quarantine vital components of your environment.

If you weren't affected and/or are using a different AV product, it might still be worthwhile to spend a couple of minutes on the following questions:

©2008 dba.5341.com - Jax Systems, LLC, U.S.A.