Errors from Live Update
Dear all,
We've been having problems updating to the latest signatures over here. We're getting the following event log entry:
Event Type: Error
Event Source: LiveUpdate
Event Category: None
Event ID: 58
Date: 12/02/2008
Time: 10:31:39 AM
User: NT AUTHORITY\SYSTEM
Computer: MTPC-SANDROG
Description:
6006: LiveUpdate did not complete because the C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri512\liveupdt.grd file failed validation.
Run LiveUpdate again.
In the log file Log.LiveUpdate we get the following errors:
2/12/2008, 9:31:39 GMT -> EVENT - SERVER SELECTION SUCCESSFUL EVENT - LiveUpdate connected to server C:\PROGRAM FILES\SYMANTEC ANTIVIRUS\CONTENTCACHE\{ECCC5006-EF61-4C99-829A-417B6C6AD963} at path C:\PROGRAM%20FILES\SYMANTEC%20ANTIVIRUS\CONTENTCACHE\%7BECCC5006-EF61-4C99-829A-417B6C6AD963%7D\2007122000 via a LAN connection. The server connection connected with a return code of 200, Successfully download TRI file
2/12/2008, 9:31:39 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri512\decomposer_1.0.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri512"
2/12/2008, 9:31:39 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.grd"
2/12/2008, 9:31:39 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.sig"
2/12/2008, 9:31:39 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "updecabi.zip.dat"
2/12/2008, 9:31:39 GMT -> Progress Update: SECURITY_SIGNATURE_ERROR: HR: 0x802A003A GuardFile: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri512\liveupdt.grd" ErrorMsg: CPkcs7SignedFile::verify(): C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri512\liveupdt.SIG: invalid signature for C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri512\liveupdt.grd.
2/12/2008, 9:31:39 GMT -> HR 0x802A003A DECODE: E_SIGNATURE_NOT_VERIFIED
2/12/2008, 9:31:39 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri512\decomposer_1.0.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri512", HR: 0x802A0037
2/12/2008, 9:31:39 GMT -> HR 0x802A0037 DECODE: E_MISSING_GUARD_FILE
2/12/2008, 9:31:39 GMT -> Progress Update: SECURITY_GENERAL_ERROR: HR: 0x802A0037 ErrorMsg1: ErrorMsg2:
2/12/2008, 9:31:39 GMT -> HR 0x802A0037 DECODE: E_MISSING_GUARD_FILE
2/12/2008, 9:31:39 GMT -> Mini-TRI file C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri512\decomposer_1.0.0_symalllanguages_livetri.zip failed the authentication check. LiveUpdate will ignore this Mini-TRI file and continue other processing updates.
2/12/2008, 9:31:39 GMT -> Due to authentication failure, C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\decomposer_1.0.0_symalllanguages_livetri.zip has been removed
2/12/2008, 9:31:39 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "1"
Did anyone else come across this issue, and if so, is there a fix yet?
Kind Regards
Sandro
Comments
6006: LiveUpdate did not complete because the C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri771\liveupdt.grd file failed validation.
Run LiveUpdate again.
6001: LiveUpdate failed because the LiveUpdate package is corrupt. Internal authentication files are not present.
Please run LiveUpdate again. If the error persists, contact your network administrator or LiveUpdate provider.
Hope someone has got a fix!!
Mitigating solution to the errors - at least we stop messages in the Event Log for the time being till there is a fix.
Symantec knows about this one and they are working on it - No fix ETA yet
Mod Note: Please do not use any profanities in the the forums. For guidlines please see the Discussion Forums Terms and Conditions.
Thank you.
Message Edited by Optimus Prime on 02-15-2008 02:55 PM
6001: LiveUpdate failed because the LiveUpdate package is corrupt. Internal authentication files are not present.
Event Source: LiveUpdate
Event Category: None
Event ID: 55
Date: 2008-02-13
Time: 08:05:58
User: NT AUTHORITY\SYSTEM
Computer: SERVER02
Description:
6001: LiveUpdate failed because the LiveUpdate package is corrupt. Internal authentication files are not present.
Event Source: LiveUpdate
Event Category: None
Event ID: 58
Date: 2008-02-13
Time: 08:05:58
User: NT AUTHORITY\SYSTEM
Computer: SERVER02
Description:
6006: LiveUpdate did not complete because the C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri966\liveupdt.grd file failed validation.
I got this from Symantec, however it didn't work. Then they asked me to run a file called SymBatchSEP that they sent me which made a 130MB log file. He didn't seem aware that other users were having the same problem!
First download the latest definitions according to this KB article, do not yet copy the file to the folder mentioned in the article ;
http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007100820002048
Once its downloaded, follow thes steps;
Delete the folders:
C:\Program Files\Common Files\Symantec Shared\SymcData\sesmvirdef32
C:\Program Files\Common Files\Symantec Shared\SymcData\sesmvirdef64
Delete the contents of the LiveUpdate downloads folder.
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\
4. Copy the downloaded .jdb file to the folder mentioned in above KB article.
As mentioned in the article, the Manager will process the file and update the clients, after this you should not see the messages appear in the Event Viewer anymore.
eagerly awaiting something official from Symantec...perhaps a KB article or a solution posted on the forum
6001: LiveUpdate failed because the LiveUpdate package is corrupt. Internal authentication files are not present.
Please run LiveUpdate again. If the error persists, contact your network administrator or LiveUpdate provider.
AND
6006: LiveUpdate did not complete because the C:\ProgramData\Symantec\LiveUpdate\Downloads\Tri3\liveupdt.grd file failed validation.
Run LiveUpdate again.
====
The above is in our logs every 1- 2 minutes. PLEASE PROVIDE A FIX!!!!!!
Hey Guys,
I'm having the same issues but, I was able to free up some bandwidth until the issue is resolved.
Go to Clients--> Policies--> Communication Settings.
Change the client mode from Push to Pull and set your heartbeat interval to an hour or two.
This is not a fix! Just a way to stop the bog down of Push mode until the problem is fixed. I hope this helps you guys get through this mess. Just remember to set it back to Push mode (if that's what you used prior to this error)
crud! just realized someone mentioned this earlier in the thread. My apologies!
Message Edited by JTF on 02-13-2008 10:32 AM
Event Type: Error
Event Source: SescLU
Event Category: None
Event ID: 13
Date: 2/13/2008
Time: 7:58:15 AM
User: N/A
Computer: server1
Description:
LiveUpdate returned a non-critical error. Available content updates may have failed to install.
Event Type: Error
Event Source: LiveUpdate
Event Category: None
Event ID: 55
Date: 2/13/2008
Time: 11:19:23 AM
User: NT AUTHORITY\SYSTEM
Computer: server2
Description:
6001: LiveUpdate failed because the LiveUpdate package is corrupt. Internal authentication files are not present.
Event Type: Error
Event Source: LiveUpdate
Event Category: None
Event ID: 58
Date: 2/13/2008
Time: 11:24:31 AM
User: NT AUTHORITY\SYSTEM
Computer: server2
Description:
6006: LiveUpdate did not complete because the C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri93\liveupdt.grd file failed validation.
The above mentioned errors appear on all my workstations and servers.
Hi all,
Well, i decide to take the hard way and seems to work, or at least i see no more messages in the event viewer.... and the liveupdate from the SEPM seems to work ok again....
I follow tihs note
http://service1.symantec.com/support/ent-security....
I'm still trying to fix the problem with the report page where the virusdef informed is not the correct.
Message Edited by Steven Bright on 02-13-2008 10:46 AM
Message Edited by ADutch1 on 02-13-2008 11:11 AM
I'm having the same issue. Just looking for a reply and potential fix for this issue and to bump the thread.
Jim Waggoner Director Product Management, Symantec Endpoint Protection, Enterprise Security Group, Symantec
Jim Waggoner Director Product Management, Symantec Endpoint Protection, Enterprise Security Group, Symantec
If this helps anyone, it appeared as though the 2/13/2008 updates didn't fix the error messages initially but, I waited about 20 minutes and the error messages stopped. Keep checking the Event Viewer to verify the update didn't fix the errors because on my end, the errors have finally dissipated.
**Ignore this post. Error messages have returned from the dead**
Message Edited by JTF on 02-13-2008 05:44 PM
Event Source: LiveUpdate
Event Category: None
Event ID: 58
Date: 2/13/2008
Time: 3:03:35 PM
User: NT AUTHORITY\SYSTEM
Computer: MOSS64TEST
Description:
6006: LiveUpdate did not complete because the C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri992\liveupdt.grd file failed validation.
Jim Waggoner Director Product Management, Symantec Endpoint Protection, Enterprise Security Group, Symantec
Jim Waggoner Director Product Management, Symantec Endpoint Protection, Enterprise Security Group, Symantec
Jim Waggoner Director Product Management, Symantec Endpoint Protection, Enterprise Security Group, Symantec
Jim Waggoner Director Product Management, Symantec Endpoint Protection, Enterprise Security Group, Symantec
Message Edited by Steven Bright on 02-13-2008 08:24 PM
Guys - JimW is correct and we stopped the logs from flooding following similar advice very early on in the thread.
Check the first page of this thread...
Jim if possible keep us posted on this.
TY.
Hi,
On my side, rolling back Decomposer Definitions to 2007.12.20 doesn't fix the problem. But unckecking Updates of Decomposer Definitions successfully stops the error messages.
Confirmation that disabling Decomposer signatures has aleviated Event ID 55 & 58 client errors.
Waiting for solution from Symantec.
Bump.
Jim Waggoner Director Product Management, Symantec Endpoint Protection, Enterprise Security Group, Symantec
Good News. Hope it fixes the problem. Our Clients need a short break :smileywink:
It worked for us as well.
Can we get a post on when the new defs are released so we can download and test them asap?
Thanks
Message Edited by Screen_Name on 02-14-2008 06:31 AM
Jim Waggoner Director Product Management, Symantec Endpoint Protection, Enterprise Security Group, Symantec
I'm very glad to hear that a solution is in the works. Standard Event ID 55/58's are showing up but, they are back to the heartbeat intervals (rather than every 1-2 minutes). I can't wait until this little bugger goes the way of the dodo.
Jim Waggoner Director Product Management, Symantec Endpoint Protection, Enterprise Security Group, Symantec
Jim Waggoner Director Product Management, Symantec Endpoint Protection, Enterprise Security Group, Symantec
Jim Waggoner Director Product Management, Symantec Endpoint Protection, Enterprise Security Group, Symantec
Jim Waggoner Director Product Management, Symantec Endpoint Protection, Enterprise Security Group, Symantec
Would you like to reply?
Login or Register to post your comment.