Extension Downloader - Information - Security Alerts from Antivirus in AIP Versions below 8.3.32

Purpose

This page provides information on Extension Downloader being reported as a security violation by anti-virus installations

For more information, refer to:

Applicable CAST Version


Release

Yes/No

8.3(tick)


Applicable RDBMS
RDBMS
Yes/No
Oracle Server N/A
Microsoft SQL Server N/A 
CSS3 N/A
CSS2 N/A
Details

Extension downloader has been reported as a security threat by antivirus programs installed on the servers, like McaFee/Kaspersky. They were detecting  ExtensionDownloader.exe as a malware.

 

It is also observed that even though Extension Downloader gets installed, once the anti-virus runs, it gets automatically blocked/deleted from the installation path as well.

Before 8.3.32, Extension Downloader was detecting if write access is present in the extension folder and if not, Extension Downloader was running as administrator to get write access permissions. This feature seems to be a new check from Antivirus companies and  is not permitted anymore.

With CAST AIP 8.3.32 versions and higher this is not detected anymore. 

Notes/comments

 Tickets # 28664