Endpoint Protection

 View Only
  • 1.  Scans find virus in Endpoint directory

    Posted Mar 02, 2012 09:29 AM

    We are running Endpoint Protection Version 12.1. Some of our PCs are picking up virus in the C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\SRTSP\Quarantine folder usually .tmp files as shown below

    Quarantined
    Auto-Protect

    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\SRTSP\Quarantine\APQ979B.tmp

    Why and how do I correct this?



  • 2.  RE: Scans find virus in Endpoint directory
    Best Answer

    Posted Mar 02, 2012 09:51 AM

    The "xfer" and "xfer_temp" folders still store files scanned by AutoProtect transferred from migrations of legacy Symantec AntiVirus (SAV) or SEP installations".
    To be honest it seems that for some unexpected circumstances (for example a damaged file) SEP starts a loop where a file goes in quarantine (.vbn archives), then it is extract this file in a .tmp file to rescan it, it is again detected and quarantined, and so on...

     

    Try re-installing sep client and check .

    & check article below for 12.1 http://www.symantec.com/business/support/index?page=content&id=TECH102953 



  • 3.  RE: Scans find virus in Endpoint directory

    Posted Mar 02, 2012 01:25 PM

    Thanks for the reply. As far as I know, there have not been any other Symantec antivirus softwares installed on the problem computers. I'll try the work around solutions from the document you sent.



  • 4.  RE: Scans find virus in Endpoint directory

    Posted Mar 02, 2012 11:15 PM

    The above suggestion is right. You may also want to look at the below doc.

    http://www.symantec.com/business/support/index?page=content&id=TECH101323



  • 5.  RE: Scans find virus in Endpoint directory

    Posted Mar 05, 2012 06:49 AM

    Certain software like seach indexers can trigger such issues:

    http://www.symantec.com/business/support/index?page=content&id=TECH92399