Cat.DB and VirusDefs Folder
Updated: 21 May 2010 | 7 comments
This issue has been solved. See solution.
I believe it has been within the past week, but i recently noticed a new file in the VirusDefs folder of both my SAV and SEP servers. The file is "Cat.DB". Can anyone please tell me what this "new" file is for and if it should truly be in there?
The rest of the structure is:
BinHub
incoming
TextHub
"TheCurrentDefinitions" folder
"The PreviousDefinitions" folder
definfo.dat
usage.dat
Thanks,
-Mike
discussion Filed Under:
Comments
Cat.DB is being created now by Symantec as of 8-26, it appears.
Symantec just started putting this new file into that folder.
This file appears on every updated SAVCE 10.x client I check at
C:Program FilesCommon FilesSymantec SharedVirusDefs.
It began appearing today 8-26-2009 (or possibly yesterday 8-25 but I was out then).
It does not look like malware but I submitted it for analysis.
Symantec is putting it there. Tested this sequence:
Found a client that needed help updating. It had NO Cat .db file there.
Pushed a def update to it.
Lulock.dat appears.
Later The update is complete and a CAT.db file is now in the above path in the VirusDefs folder.
Thanks
umcat_01.db
Just found a client that also has another new DB file in the same folder by this name:
umcat_01.db
No virus in the sample.
Symantec Security Response Automation: Tracking #12558662
replied:
Thanks
John, Thanks for the update.
John, Thanks for the update.
Good to know!
Thanks John for the thorough research and answer. Makes me feel better. Maybe someone from Symantec can chime in and let us know the function of the Cat.DB file and the umcat_01.db (I have not seen this one yet).
Thanks again,
-Mike
Anyone having new about what
Anyone having new about what CAT.DB and UMCAT_01.DB is?.
Any news on these two files?
Any news on these two files? I have them on some of my managed clients but not others?
Thanks
--
Duct tape is like the force. It has a light side, a dark side, and it holds the universe together.
Would you like to reply?
Login or Register to post your comment.