Solved KB4056897 (January 2018 Security Only update) prerequisites

stmarco

New member
Local time
11:07 AM
Messages
2
Hello,

I would like to ask you quite curious question related to W7 patches that has been released since January 2018.

In our environment I have discovered multiple workstations that did not get OS patches installed - first of missing updates is KB4056897 (January 2018 Security Only update).

It is well known that AV compatibility registry key is required before these patches can be applied by WU. But all the affected clients have had this reg key already (QualityCompat / cadca5fe-87d3-4b96-b7fb-a231484277cc).

After long investigation the findings are following:
- Clients have McAfee for several years already
- Before McAfee has been installed - there has been Symantec Endpoint Protection installed.
- It seems there remained some leftovers after SEP has been replaced by McAfee
- solution was to run CleanWipe from Symantec to remove any leftovers. After that action clients can find and apply KB4056897 (January 2018 Security Only update) and others that follow.

So the conclusion is that WU is actually checking more things than just AV compatibility registry key (QualityCompat / cadca5fe-87d3-4b96-b7fb-a231484277cc) before the KB4056897 is verified as applicable.

And the question is - do you know what exactly could be blocking KB4056897 to get applicable until CleanWipe from SEP is run? I would assume it could be some more registry keys related to Symantec. And it would be very helpful to know which key(s) it is exactly. Having this information we could apply the fix more easily. Running SEP cleanwipe on tens of computers seems quite aggressive solution which I would like to avoid to.

Thank you in advance for any advice
 

My Computer My Computer

At a glance

Windows 7 Enterprise x64
Computer type
PC/Desktop
OS
Windows 7 Enterprise x64
Hi stmarco,

As you had to wipe the previous AV's registry entries for WU to work, Endpoints original uninstall must have left behind the ORIGINAL parent key, obviously not updated as program removed.
The criteria was for a registry search ONLY, it did not look for - is it still installed as well.

Roy
 

My Computer My Computer

At a glance

W7 home premium 32bit/W7HP 64bit/w10 tp insid...E5300 dual core3gbNvidia Geforce 7100 Nforce 630i
Computer type
PC/Desktop
Computer Manufacturer/Model Number
medionl/Aspire 6930G/acer x55a
OS
W7 home premium 32bit/W7HP 64bit/w10 tp insider ring
CPU
E5300 dual core
Motherboard
medion MS7366
Memory
3gb
Graphics Card(s)
Nvidia Geforce 7100 Nforce 630i
Monitor(s) Displays
avixc
Internet Speed
n (isp resticted to 72)
Antivirus
mse/pands
Browser
palemoon
Other Info
Belkin Fd7050 n USB using Railink RT2870 drivers, more upto date

My Computer My Computer

At a glance

W7 home premium 32bit/W7HP 64bit/w10 tp insid...E5300 dual core3gbNvidia Geforce 7100 Nforce 630i
Computer type
PC/Desktop
Computer Manufacturer/Model Number
medionl/Aspire 6930G/acer x55a
OS
W7 home premium 32bit/W7HP 64bit/w10 tp insider ring
CPU
E5300 dual core
Motherboard
medion MS7366
Memory
3gb
Graphics Card(s)
Nvidia Geforce 7100 Nforce 630i
Monitor(s) Displays
avixc
Internet Speed
n (isp resticted to 72)
Antivirus
mse/pands
Browser
palemoon
Other Info
Belkin Fd7050 n USB using Railink RT2870 drivers, more upto date
Hi,

Thank you for your replies.

I have done some more testing and I have found the exact registry removal that fixes this issue!

I just need to run this command:
reg delete "HKLM\SOFTWARE\Symantec\InstalledApps" /v AVENGEDEFS /f

After that - once new update scan is triggered - patches are being installed.

It so great that this mystery is solved for me now!
 

My Computer My Computer

At a glance

Windows 7 Enterprise x64
Computer type
PC/Desktop
OS
Windows 7 Enterprise x64
Back
Top