• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 5531
  • Last Modified:

Corrupt Symantec Endpoint Protection (SEP) Definitions on 1 Server

Hey,

I've got all my desktops/servers protected with Symantec Endpoint Protection 11.1 and has been working fine for over 18 months.  Occasionally I'll get one client report a corrupt definition, so I usually just run the intelligent updater on them and it resolves it.

Problem is I now have 1 client (my main file server and DC) where the defs are corrupt and I can't resolve it.  I have tried,

1.

Running the intelligent updater - no effect

2.

Stopping EndPoint - Doing this - http://www.symantec.com/business/support/index?page=content&id=TECH103176&locale=en_US - Same problem, after a few mins it reports corrupt defs.

3.

Doing the same as above but running the intelligent updater afterwards - same problem
I'm a little lost now.  No other servers/clients report the same problem and they all use the same definitions.

I get event ID 40 - Symantec Endpoint Protection has determined that the virus definitions are missing on this computer. This computer will remain unprotected from viruses until virus definitions are downloaded to this computer.Application has encountered an error.

and event ID 4 - SRTSP - Error loading virus definitions.

Any suggestions?

Thanks,

Andy
0
manic_andy
Asked:
manic_andy
1 Solution
 
TymetwisterCommented:
Try uninstall/reinstall of SEP?
0
 
itsecalertCommented:
From Add/Remove Programs, Uninstall the LiveUpdate component. Then reinstall again. If you have the installation media or an installation package somewhere.
Look for LUSETUP.exe under SEPM folder of the installation media and run it after you uninstall LiveUpdate.

If possible reboot the system before re-installing. Looks corrupted to me.

Thanks

HB
0
 
andrewmccCommented:
Not sure if this is 100% similar, though we've had issues with Symantec Endpoint on some of the servers we have deployed across specific sites (they came from a small consultancy which was acquired then merged into the group).

http://www.symantec.com/connect/forums/sep-11-and-net-framework-problems

http://support.microsoft.com/kb/961293

We've had some issues which are not directly related I think to your issue, though seem similar enough for us to follow the Microsoft link and from memory, I checked with the server team before making the post, Symantec tech support suggested a .Net framework update might have had something to do with it, though afterwards we came to the conclusion that it was partially something else which was impacted by an update and then something SEP did....

Took some time before they worked out that one guy at Microsoft said he'd suggest the KB961293 article.

I think this solution was posted in part here before, though there were different scenarios.
0
 
postechgeekCommented:
There is a utility called Rx4DefsSEP, that can be used to removed corrupted definitions from SEP11 clients. You will have to call and request it from Symantec Technical Support.

RX4DefsSEP:
http://www.symantec.com/business/support/index?page=content&id=TECH93036&locale=en_US

I've used it in the past.
0
 
manic_andyAuthor Commented:
Nothing I did worked for whatever reason so I'm just going to uninstall it prior to upgrading to the latest version.
0

Featured Post

 The Evil-ution of Network Security Threats

What are the hacks that forever changed the security industry? To answer that question, we created an exciting new eBook that takes you on a trip through hacking history. It explores the top hacks from the 80s to 2010s, why they mattered, and how the security industry responded.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now