Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Netshield on Win2k

Status
Not open for further replies.

Mikecl

MIS
Oct 7, 1999
51
GB
We have 3 w2k servers sp2 with 4.5 sp1 netsheild installed the system scan disables itself eventually. If i copy files from a cd to the server it comes up with the same error. I have tried increasing the scan timeout with no sucess.

===========================================================

Event Type: Warning
Event Source: AlertManager
Event Category: None
Event ID: 257
Date: 10/28/2002
Time: 8:42:18 PM
User: N/A
Computer: CIV-DC02
Description:
Alert Manager Event Log Alert:

The scan of F:\WINNT\Driver Cache\i386\SP2.CAB\ntkrnlpa.exe has taken too long to complete and is being canceled. Scan engine version used is 4.1.60 DAT version 4.0.4230.(from CIV-DC02 IP x.x.x.x user CORP-TEST\veritas running NetShield 2000 4.5 OAS)
 
Hi

I suggest that you first add the HotFix Rollup. You can download it from the McAfeeb2b site.

From the McAfee KB:

Under the 'Advanced' tab in NetShield, increase the number value present in the Compressed Files section. This will allow more time for scans to complete.

There are two timeout settings, one for archive files (.ZIP files) and a general purpose one that applies to any scan operation. You will only be able to set the increase the compressed file timeout number to one second lower than the general timeout value. See NAI18383: Resolving a standard file timeout in McShield for information on increasing the general timeout value.



Cheers
AVDude
 
Hi Avdude

I have patched everything and editied the registry however I am still getting timeouts, what is confusing is that it is trying to scan F:\WINNT drive files but I dont have an F drive the CD is E but has nothing in it.

Any Ideas
 
What's the scan options set on VirusScan? Does it scan for all local drives or network drives? Might be trying to scan a network drive that's slow? AVChap
... take my advice, I don't use it anyway!
 
The Scan options are for local drives, I have tried excluding the F: drive even though I dont have one. It seems the Alert Manager Log is reporting scanning the F: drive but by the Backup exec account, the backup job is not set to virus scan. The NAI service on the server is using local system account.

The scan of F:\WINNT\ServicePackFiles\i386\wms4.cab\NetShow.chm has taken too long to complete and is being canceled. Scan engine version used is 4.1.60 DAT version 4.0.4230.(from CIV-DC02 IP x.x.x.x user CORP-TEST\veritas running NetShield 2000 4.5 OAS)
 
Apparently, NetShield is trying to scan the file being backed up by Veritas. I suggest you turn off the on-access scanning before the backup and restart it once it finishes to avoid this conflict. Veritas, IIRC, has options to run programs before and after a backup. Just run these commands to stop and start NetShield:

NET STOP AVSYNMGR
NET START AVSYNMGR

HTH, AVChap
... take my advice, I don't use it anyway!
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top