beserver.exe keeps downloading threatcon.zip every 5 minutes

Bobtb's picture

Hello everybody,

We have several servers running Backup Exec 12.5 in our network, but 1 of them is doing something odd.
This particular server keeps downloading the URI http://securityresponse.symantec.com/avcenter/thre..., every 5 minutes.

I can't find anything in Backup Exec that would need a file like that, nor can I find any setting that controls this behaviour.
I would like to turn this off completely because it's clogging our webfilter logs with unnecessary notifications.
None of the other BE 12.5 servers are doing this, I have no idea why this server is acting the way it is.

There is no Symantec AV installed on the server, nor any other Symantec product. LiveUpdate is scheduled to run on a weekly basis so that's not it either.
Using Microsoft Network Monitor 3.3 I found out the process beserver.exe is responsible.

Can anyone please help me solve this?

Thanks.

Regards,
Bob ten Berge

BEsymc's picture

These files are getting

These files are getting created, because the machine keeps polling for securityresponse.symantec.com, every 5 minutes, and it does not have internet connectivity. Also, there is no SEP Manager installed on this machine, so threatcon integration may not work for you. So, you may want to disable this. As a workaround, you may make an entry in hosts file for securityresponse.symantec.com to 127.0.0.1.

Please mark it a solution, if this is useful.
Thanks

Bobtb's picture

Thanks for your reply, but

Thanks for your reply, but it's not really a solution.
I would rather find out why it's polling every 5 minutes, since the other backup exec servers don't show this behaviour.
The server does have an internet connection, through a firewall. It's the firewall that tipped us off about these connections (they are allowed too, so the downloads do not fail).
How do I disable this threatcon integration? And since when is this part of backup software?

BEsymc's picture

Unfortunately, with current

Unfortunately, with current release, there is no way of disabling this at this time. You may want to call tech support, for more information on the same.

Thanks