Endpoint Protection

 View Only
  • 1.  \System Volume Information\EfaData\SYMEFA.DB seems to block 'Safely Remove'

    Posted May 23, 2015 02:48 PM
    Hi, I have Symantec Endpoint Protection 12.1.671.4971 on a Windows7 computer. After connecting a new external USB drive, SEP created this file: System Volume Information\EfaData\SYMEFA.DB. It can't be removed, and Symantec says such is _by design_ of Symantec. Same problem, if I temporary disable SEP. Do I really need to shut down the PC, just to safely remove the external USB drive?? (If such is needed, then of course, I would need alternative anti virus software.) After I connected this USB drive (which otherwise is functioning properly), the appearing 'Safely remove' button on the system tray doesn't work at all. Left click, right click, double click: none of these has _any_ effect. If I do "rundll32.exe shell32.dll,Control_RunDLL hotplug.dll" and want to stop the device, it says: 'The ... device is not removable and cannot be ejected or unplugged'. Unlocker 1.9.1. says both the SYMEFA.DB-file and drive have no locking handles (if I run it from a command prompt). If I use the utility 'USB_Disk_Eject', it says: 'The disk could not be ejected. Close any programs that might be using the disk and try again'. I _have_ no programs open which could use the drive; apart from Symantec. I have disabled shadow copies and system restore points, have no encyption and no 'ready boost', which could use 'System Volume Information' also; but the only file in there is the Symantec file anyway. The Windows system log has entries like: "The application System with process id 4 stopped the removal or ejection for the device USB\(code)&(code)\(code)." If I have tamper protection on, there are entries in the Windows application log that Symantec blocked acces to unlocker or eraser (utility from heidi computers Ltd). Any help? Of course I could shut down the PC now and disconnect the drive (although normally I have turned on the PC 24h/day), but probably the problem with the Symantec file will stay after restart.


  • 2.  RE: \System Volume Information\EfaData\SYMEFA.DB seems to block 'Safely Remove'

    Posted May 23, 2015 03:26 PM

    This problem is likely due to the fact that you're running the first version of 12.1 which had known issues similar to this.

    Can you get up to 12.1.6?

    Upgrade or migrate to Symantec Endpoint Protection 12.1.6



  • 3.  RE: \System Volume Information\EfaData\SYMEFA.DB seems to block 'Safely Remove'

    Posted May 24, 2015 04:09 PM
    There is no update available via 'LiveUpdate...'.


  • 4.  RE: \System Volume Information\EfaData\SYMEFA.DB seems to block 'Safely Remove'
    Best Answer

    Posted May 24, 2015 04:17 PM

    Try the 12.1.5 client patch (12.1.6 is not up yet)

    Symantec Endpoint Protection 12.1.5 client-only patches



  • 5.  RE: \System Volume Information\EfaData\SYMEFA.DB seems to block 'Safely Remove'

    Posted May 24, 2015 05:38 PM
    I installed the patch and rebooted. Now the 'Safely remove' icon works again, thank you. BTW, I now have two of those pesky unremovable files: System Volume Information\EfaData\SYMEFA.DB System Volume Information\EfaSIDat\SYMEFA.DB On every drive (external or not). But I guess I won't get rid of those as long as I use SEP.


  • 6.  RE: \System Volume Information\EfaData\SYMEFA.DB seems to block 'Safely Remove'

    Posted May 24, 2015 06:08 PM

    Sounds good, happy to help. 12.1.5 should take care of that.