Friday, January 06, 2017

Symantec 12 Virus Definitions not updating

Problem: Symantec Antivirus on one of the servers I run was not updating it's antivirus definitions.

I would be able to install Symantec and then it would be updating antivirus definitions for 2 weeks and it would continue to update the Network Threat Protection definitions past those 2 weeks.

I thought something could have been corrupted or some miscommunication was occurring between the antivirus and the Symantec EndPoint Protection Server, so I did a clean wipe(removing all Symantec files). I then reinstalled thinking my issues were gone.

After about 2 weeks, it started not having the antivirus updates again, so I was then looking around to see if some certificate was messed up. I would try to run the live update but it said it was downloading but then it did not install the Latest Definition.

Solution: I ended up making a support call to Symantec and a friendly support tech helped me and it was solved in about 3 minutes. He went into the C:\ProgramData\Symantec\Symantec Endpoint Protection\CurrentVersion\Data\Definitions\VirusDefs folder confirmed that the definitions were there. Then we started Task Manager, went to details and ended the ccsvchst.exe task being run by SYSTEM. We then closed this and went back into Symantec and it was updated.
ccSvcHst.exe SYSTEM user in Task Manager


Reason: Apparently, the issue was that some update was waiting for a reboot but since this was a server and it was a non-security patch it could wait, I didn't reboot. I'm not sure why the Symantec program didn't say "cannot update due to pending reboot".

No comments: