locked
KB956280 RRS feed

  • Question

  •  Hi Guys,

    Firstly, I am not 100% sure if this is the correct forum for this question but other guys may hvae experienced the problem as well. I am deploying via SCCM 2007 R2

    I am trying to deploy update 956280 to all workstations. This update pertains to Forefron Client security. But the installation fails. There have been tons of other updates that have deployed successfully but this specific one fails.

    I went into the cache folder and located the actual update and when trying to install it manually, it fails as well.

    Has anyone seen this issue before?
    Thursday, December 11, 2008 11:45 AM

Answers

  • check program files\microsoft fcs\client\antimalware\logs I believe and look for the setup log there which should give some better indication as to why it failed.
    CSS Security Support Engineer (FCS/MBSA/WUA/Incident Response) Check out my blog http://blogs.technet.com/kfalde
    • Marked as answer by AKDT Wednesday, December 17, 2008 6:47 AM
    Tuesday, December 16, 2008 3:20 PM

All replies

  • check program files\microsoft fcs\client\antimalware\logs I believe and look for the setup log there which should give some better indication as to why it failed.
    CSS Security Support Engineer (FCS/MBSA/WUA/Incident Response) Check out my blog http://blogs.technet.com/kfalde
    • Marked as answer by AKDT Wednesday, December 17, 2008 6:47 AM
    Tuesday, December 16, 2008 3:20 PM
  • Actually never mind that was for the client install itself.. check in your windows dir for a kb956280.log file to see what type of errors you are seeing in there.
    CSS Security Support Engineer (FCS/MBSA/WUA/Incident Response) Check out my blog http://blogs.technet.com/kfalde
    Tuesday, December 16, 2008 3:21 PM
  • I did not find a kb956280.log in the windows dir for some reason but there were lots of other updates logs.strange
    So I went to the  Mp_ampbits.log and it all looked like jargon, so I deleted the log and retried the installation with trace32 open on the filename. as soon as the install started, I seen the messages being posted.

    It ended up being some "quarantined" virus in the "\\computer\c$\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\LocalCopy" folder which was highlighted clearly in the log. I deleted the items manually and the update installed with no issues.

    The strange thing is that according to my FCS console, it suppose to delete after 3 days - This is for another forum altogether...

    Thanks Guys
    Wednesday, December 17, 2008 6:44 AM