32-bit Windows 2003 Servers with Symantec Endpoint Protection (SEP) 12.1.x Proactive Threat Protection Installed Hang or Crash with Event id 333 Errors in System Event Log
Last Updated October 16, 2013
32-bit Windows 2003 Servers with SEP 12.1.x Proactive Threat Protection (PTP) and PTP Definitions Dated 24 September 2013 revision 11 start showing performance issues since the beginning of October. Servers may become unresponsive or crash with a Blue Screen of Death.
The Windows Event log may have errors such as:
Event ID 333:
An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files that contain the system's image of the Registry.
Symantec is aware of this issue and will update this document when a solution becomes available.
To workaround the issue, disable the BHDrvx86.sys driver.
3rd Party Management tools such as HP Openview are installed.
The SONAR Engine version in the PTP definitions dated 24 September 2013 revision 11 is 22.214.171.124.
This SONAR Engine corresponds to the BHDrvx86.sys driver in \Definitions\BASHDefs\20130924.011\
Not every PTP Defintions set dated 20130924.011 will have SONAR Engine version 126.96.36.199.
In some cases the version may be 188.8.131.52. With this version 184.108.40.206 this particular issue should not occur. Having another version than 220.127.116.11 is not an indication of problems with the SONAR Definitions update, but is the result of Symantec's Staged Content Rollout Strategy. See www.symantec.com/docs/TECH206118 for further information.
Imported Document ID: TECH211583
Subscribing will provide email updates when this Article is updated. Login is required to Subscribe