Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

Here today, gone tomorrow - Server 2003 Issue

Updated: 03 Sep 2010 | 17 comments
Jason1222's picture
0 0 Votes
Login to vote
This issue has been solved. See solution.

So, like many others, I am having an issue re-installing SEPM on my ADC.
Server 2003.
Definitions decided not to load today.  This was the only machine out of dat definitions.
So, I decided, uninstall -> Reinstall.  No big deal, done it many times before.
*******
Add/remove Symantec, plug-in password for uninstall...  After a while, I get: "Fatal error..."
Nice, Symantec won't start.
Can't be upgraded.
Service running, but no task in the task manager.
No more icon in the tray.
********
Like any one else would, Clean Wipe time.

That was a mistake.  Something else went horribly wrong there.
Upon reboot, the machine no longer had any network communications.

Command Prompt: IPCONFIG
"Windows IP configuration"

No big deal.  Went over to the machine, logged on locally
NETSH INT IP RESET LOG.TXT
reboot
Re-enter IP information (no DHCP)
Machine lives again.

Tragedy averted.
******************
Reinstall Symantec time:

Event ID: 11708 MsiInstaller
Product Symantec Endpoint Protection -- Installation Operation failed.

Unfortunately, login here is setup to "flush" the temp folders on login.
The temp folders are used for deploying software and can add up to a lot of information quickly.
So no sep-install logs as of yet.
Gonna have to wait a few minutes for those.

Comments

Vikram Kumar-SAV to SEP's picture
29
Jul
2010
1 Vote +1
Login to vote
Warrior6945's picture
29
Jul
2010
0 Votes 0
Login to vote

Hi

Hi 

If possible delete all the remaining Symantec files and then install SEP again

Delete the following folders and check if Symantec is removed

 
C:\Prog Files\Symantec
C:\Prog Files\Common Files\Symantec
C:\Doc & Settings\All Users\Application Data\Symantec
 
Also delete the Symantec folder from the registry from the following location
 
HKLM\Software\Symantec
HKey Current User\Software\Symantec
HKey Users\.Default\Software\Symantec

Shaizad's picture
29
Jul
2010
0 Votes 0
Login to vote

I Agree

I agree with Vikram's point ...you can follow the manual removal Documet.  which i agree it's a lengthly process however that will definetly help you in resolving the Issue.

yang_zhang's picture
29
Jul
2010
0 Votes 0
Login to vote

Follow the Manual remove SEP guide provided by Vikram, then check the folders and registry which mentioned by Warrior6945.

If a forum post solves your problem, please flag it as a solution. If you like an article, blog post or download vote it up.
AravindKM's picture
29
Jul
2010
0 Votes 0
Login to vote

If non of the above suggestion helps,attach the SEP_inst.log which will be present in %temp%

Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind

Constantine's picture
30
Jul
2010
0 Votes 0
Login to vote

problems in reinstalling

i had such problem on times,

first i uninsalled it fully, and then reinstalled again

Jason1222's picture
30
Jul
2010
0 Votes 0
Login to vote

Alrighty, sorry

Sometimes you just got to go home.
Here is the infamous SEP_install logs.

Thanks Vikram, I'll give you a +1 for being the first to mention the manual uninstall, which I thought I wrote in the original post, I was in the process of doing.
Before leaving last night:
- After manual install process
- Rebooted Server
- Ran Chkdsk on file system
- Removed all "rogue" folders.
- And hit the re-install button.

Here for your viewing pleasure this morning is the log file...

AttachmentSize
SEP_INST.zip 391.83 KB
AravindKM's picture
30
Jul
2010
0 Votes 0
Login to vote

Look like some virus issues are preset in your server.Try by scab using Norton Power Eraser.

You may also use symantec recovery media....

Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind

Jason1222's picture
30
Jul
2010
0 Votes 0
Login to vote

I'll run a scan

I'll run a scan, but would be really surprised if the machine is infected.
I did get some notifications about quarantines. 
If it's infected and all it does is act as an ADC, noone logs into it, the infection would have to come from the network. 

Could you point where you see that in the log file?

AravindKM's picture
30
Jul
2010
0 Votes 0
Login to vote

Default path of Norton Power Eraser is C:\Documents and Settings\<logon user>\Local Settings\Application Data\NPE

Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind

Jason1222's picture
30
Jul
2010
0 Votes 0
Login to vote

Where in the logfile

Where in the logfile do you see an indication of a Virus?

I am going to need to make a report to the up and ups if we have been infected.

Than, I am going to need to spend the weekend ensuring that it is not propagated everywhere.

If the case is just the server being flaky, it will be decomiisionned and a new one put in it's place by EOB.

AravindKM's picture
30
Jul
2010
0 Votes 0
Login to vote

Your log says
Module: ImagePath=C:\WINDOWS\system32\ntdll.dll
Module: ImagePath=C:\WINDOWS\system32\SHELL32.dll
Module: ImagePath=C:\WINDOWS\system32\SHLWAPI.dll
Module: ImagePath=C:\WINDOWS\system32\ADVAPI32.dll
MSI (s) (10:B8) [17:48:06:796]: User policy value 'DisableRollback' is 0
MSI (s) (10:B8) [17:48:06:796]: Machine policy value 'DisableRollback' is 0
Action ended 17:48:06: InstallFinalize. Return value 3.

Previously I had seen same problem because of virus issue.I am not sure this is a virus issue.But it is possible.That is why I suggested you to do a scanning.....

Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind

Jason1222's picture
02
Aug
2010
0 Votes 0
Login to vote

Still can't reinstall

Still can't reinstall SEP on this machine.
One thing I have noticed and is really annoying, every time I reboot I lose my network capabilities.  "Failed to load a driver..."

SEP was completely uninstalled.
After every reboot, I run 'NETSH INT IP RESET LOG.TXT' reboot again, reassign my static IP and it works until next reboot.  Being as this machine is behaving badly, it is being rebooted frequently. 

This morning, while "looking into the problem further", I noticed this is in the device manager.
I cannot uninstall, nor can I update the drivers...

See screenshot below...

teefer.JPG
JohnSn's picture
02
Aug
2010
0 Votes 0
Login to vote

SEP problem installing

Jason,

If you are installing on a server, only install AntiVirus and AntiSpyware.
The Teefer2 driver is notorious for causing problems on servers.
Make sure you have the latest Cleanwipe tool.
Run that on teh server. Afterwards, make sure teh 'leftover' Symantec directories are removed.
Make sure that ALL temp directories are emptied.
Then install the SEP client with AntiVirus and AntiSpyware only.

Vikram Kumar-SAV to SEP's picture
02
Aug
2010
0 Votes 0
Login to vote

Re-install NIC card drivers.

Jason1222's picture
02
Aug
2010
0 Votes 0
Login to vote

Re-install Intel Drivers did not help

Hi Vikram,
I re-installed the Intel NIC drivers, but that did not help.
* * * *
I "updated drivers" on the Teefer (all 3) and connected to another 2003 server. 
C:\windows\inf and it installed the drivers, although had a warning about Not Signed by Microsoft, but wahtever.  It worked.

The 3 problematic NICs completely dissappeared as if they were not there.

Rebooted the system and it came up properly for the first time since uninstalling SEP.

Sstill can't install SEP on the client though.

Log file included from most recent attempted install.

AttachmentSize
SEP_INST.zip 358.61 KB
Jason1222's picture
02
Aug
2010
0 Votes 0
Login to vote

Manually removed

Manually removed all keys in the registry relating to Symantec.
Ran Auslogic Registry Cleaner.
Removed all "Common files" relating to Symantec.

Created a new installation package for Symantec from the SEPM.

Installation completed successfully.