|
问题:
Symantec杀毒软件在不到2个小时内隔离了7G的有毒邮件。造成系统几乎当机。
分析:
初步反映,外网有大量的病毒邮件发到邮件服务器上。然后被symantec截获。
进一步分析:2个小时内收不了这么多的病毒邮件(上万封),否则去internet的带宽将全部占用。最后在网上找到问题所在:是symantec和ARCserver相互冲突所致。
引用文档:
Symantec AntiVirus Corporate Edition 8.1 quarantines an infected file repeatedly with ARCserve Backup installed
Situation:
You have a computer with ARCserve Backup Agent for Open Files. When Symantec AntiVirus Corporate Edition 8.x Realtime Protection detects a virus on that computer, it quarantines the virus repeatedly. This issue can occur with ARCserve 2000, ARCserve for Windows NT Version 6.5 build 620, and ARCserve 9.0.
Solution:
This issue was resolved in build 314a of Symantec AntiVirus 8.1.1 and build 460 of Symantec AntiVirus 8.01. For instructions on obtaining the latest release, read the article How to obtain an update or an upgrade for your Symantec Corporate product.
References:
This is caused by the Backup Agent for Open Files accessing the infected file while Symantec AV processes the file in the APTemp folder.
Document ID:2003080415232848
Last Modified:12/22/2004
http://service1.symantec.com/sup ... 2848?Open&src=w
解决方案:
依文档所述,升级Symantec AntiVirus 到9.0问题获解. |
|