Endpoint Protection

 View Only
  • 1.  SEP /xfer/xxxx.tmp always prompt infection

    Posted Mar 07, 2012 09:15 PM

    Dear All

    Recently I always received the Risk Event report which tell the following location found the virus :-

    c:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\xfer\4f4eaa22.tmp

    I read some of the document that it need to clear up the xfer and xfertemp folder and also to clear up the quarantine folder of the SEP.

    I did the above actions, but the report still there.  How can I solve it?



  • 2.  RE: SEP /xfer/xxxx.tmp always prompt infection



  • 3.  RE: SEP /xfer/xxxx.tmp always prompt infection

    Trusted Advisor
    Posted Mar 08, 2012 06:44 AM

     

    Hello,

    That issue is largely resolved in the latest release of SEP 11 (RU6 MP3) and will be entirely resolved in the forthcoming SEP 12.1.

    I recommend upgrading as soon as is possible!

    Please Work on the Following Steps.

     

    Stop the Symantec service

    • Symantec Endpoint Protection

      • Click Start, then Run
      • Type: smc -stop
      • Click OK

    Deleting the files

    NOTE: The following instructions are to be done from the Command Prompt as attempting to perform the deletions from the Windows user interface may result in delays and application hangs due to the large amount of files that can reside in these locations. Please note that these instructions will delete the files in the targeted directories, not the directories themselves. Do not remove the directories themselves, only the contents of those directories.

     

    Open the Command Prompt

    Deleting files from User Temp folder

    • Click Start, then Run
    • Type: cmd
    • Click OK

    1. Type the following command in Command Prompt. (The following string will vary depending on the user name.) Replace "<NAMEOFUSER>" with the username of the desired Windows user you wish to empty the temp folder for:

     

    • For Windows 2000/XP/2003
       DEL /F /Q "C:\Documents and Settings\<NAMEOFUSER>\Local Settings\Temp"
    •  For Windows Vista/7/2008
       DEL /F /Q "C:\Users\<NAMEOFUSER>\AppData\Local\Temp"

    2. Deleting the contents of the temp folder at the root of C:\

    • Type the following command in Command Prompt:

      DEL /F /Q C:\temp

    3. Deleting the contents of the Windows Temp folder

    • Type the following command in Command Prompt:

      DEL /F /Q C:\WINDOWS\Temp

    4. Deleting the contents of the xfer and/or xfer_temp directories

    • Type the following command in Command Prompt:
        • Windows 2000/XP/2003
          DEL /F /Q "C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\xfer_tmp\"

          DEL /F /Q "C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\xfer\"

        • Windows Vista/7/2008
          DEL /F /Q "C:\ProgramData\Symantec\Symantec Endpoint Protection\xfer_tmp\"

          DEL /F /Q "C:\ProgramData\Symantec\Symantec Endpoint Protection\xfer\"

     

    The Quarantine Folder

    NOTE: The following instructions are to be done from the Command Prompt as attempting to open the Quarantine folder in the Windows user interface may result in delays and Windows Explorer application hangs due to the large amount of files that can reside there.

     

    Delete the Quarantine Folder

    Type the following commands in the Command Prompt:

    • Windows 2000/XP/2003
      DEL /F /S /Q "C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine"

      RD /S /Q "C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine"

    • Windows Vista/7/2008
      DEL /F /S /Q "C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine"

      RD /S /Q "C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine"

    Recreate the Quarantine Folder

    Type the following command in Command Prompt:

    • Windows 2000/XP/2003
      MD "C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine"
    • Windows Vista/7/2008
      MD "C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine"

    Start the Symantec service

    • Click Start, then Run
    • Type: smc -start
    • Click OK

     

  • If you have frequent recurrences of this issue and would like to disable re-scanning of the quarantine folder please follow these steps:
  • Disable re-scanning of quarantine files.

    From the SEP-Manager:
    - Edit the Antivirus and Antispyware policy of affected clients.
    - In the policy editor click "Quarantine" on the left-hand menu.
    - On the general tab click "Do nothing" under the heading "When new Virus Definitions Arrive"

     

    Hope that helps!!!!



  • 4.  RE: SEP /xfer/xxxx.tmp always prompt infection
    Best Answer

    Posted Mar 08, 2012 05:37 PM

    The "xfer" and "xfer_temp"

    The "xfer" and "xfer_temp" folders still store files scanned by AutoProtect transferred from migrations of legacy Symantec AntiVirus (SAV) or SEP installations".
    To be honest it seems that for some unexpected circumstances (for example a damaged file) SEP starts a loop where a file goes in quarantine (.vbn archives), then it is extract this file in a .tmp file to rescan it, it is again detected and quarantined, and so on...

     

    Try re-installing sep client and check .

    & check article below for 12.1 http://www.symantec.com/business/support/index?page=content&id=TECH102953 



  • 5.  RE: SEP /xfer/xxxx.tmp always prompt infection

    Posted Mar 10, 2012 09:24 PM

    hi,

    have you receive solution ?

     



  • 6.  RE: SEP /xfer/xxxx.tmp always prompt infection

    Posted Mar 12, 2012 06:27 AM

    I agree with Mithun's steps. In addition you can run a script for this. As far as I know these files would re-create after deletion.



  • 7.  RE: SEP /xfer/xxxx.tmp always prompt infection

    Posted Mar 12, 2012 09:09 PM

    Thank for all advice, I tried to reinstall the SEP client then the problem is solved. thanks



  • 8.  RE: SEP /xfer/xxxx.tmp always prompt infection

    Posted Apr 19, 2012 10:36 AM

    Hi Jackie ,

    Thank you for the update and nice to hear your issue is fixed , if you could please mark this as solution which helped you would be great as it would help other Users if experiencing same issue to follow steps .

    Thanks