cancel
Showing results for 
Search instead for 
Did you mean: 
Reliable Contributor bretzeli
Reliable Contributor
Report Inappropriate Content
Message 1 of 8

ENS 10.5.1/10.5.2 ATP TIE Client, W7 64BIT, Failed to finalize reputation for file,ErrorCode 0xc030002f for random EXE on systems

Hello,

We are investigating this at development level and we asume this may be a source for the random hangs / freeze / "Blue circle" one of our customer has with:

Around 800 clients W7 64BIT

ENS 10.5.2

AGENT 5.0.6

TIE 2.1.0338 (HF2) Latest Version (Combi Broker and TIE Server ON ONE Server)

DXL 3.1

DLP 11 latest HF (ONLY in DEVICEBLOCK Mode > USB)

Does ANYBODY has same errors if they:

* TURN on DEBUG Logging in the POLICY

* Open file c:\ProgramData\McAfee\Endpoint Security\Logs\AdaptiveThreatProtection_Debug.log

c:\ProgramData\McAfee\Endpoint Security\Logs\AdaptiveThreatProtection_Debug.log

Search for: "Failed to finalize reputation for file"

9/05/2017 01:29:01.250 PM   mfeatp(2872.432) <SYSTEM> Orchestrator.Action.Debug: Non actionable reputation score(0) recieved for C:\WINDOWS\EXPLORER.EXE

09/05/2017 01:29:02.661 PM   mfeatp(2872.3816) <SYSTEM> Remediationbl.RepairModule.Debug: Obtained hash information for raptor, path c:\windows\explorer.exe md5 38ae1b3c38faef56fe4907922f0385ba

09/05/2017 01:29:05.435 PM   mfeatp(2872.1956) <SYSTEM> Orchestrator.JCM.Debug: JCM system event scan for process C:\WINDOWS\SYSTEM32\DLLHOST.EXE pid 852

09/05/2017 01:29:05.436 PM   mfeatp(2872.5352) <SYSTEM> Orchestrator.JCM.Debug: Process C:\WINDOWS\SYSTEM32\DLLHOST.EXE reputation 99 final 0 result 0x00000000 flags 0x0000000001000000 type: 1 connectivity: 1

09/05/2017 01:29:05.474 PM   mfeatp(2872.5352) <SYSTEM> Orchestrator.JTI.Debug: Process C:\WINDOWS\SYSTEM32\DLLHOST.EXE JTI reputation 99 rule 55 threat name JTI/Trusted.65591!a8edb86fc2a4 , JCM reputation 99, IsFinal 0

09/05/2017 01:29:05.979 PM   mfeatp(2872.1748) <SYSTEM> Orchestrator.JCM.Debug: Process C:\WINDOWS\SYSTEM32\DLLHOST.EXE reputation 99 final 0 result 0x00000000 flags 0x0000000001000000 type: 1 connectivity: 1

09/05/2017 01:29:09.838 PM   mfeatp(2872.5656) <SYSTEM> Orchestrator.JCM.Debug: JCM system event scan for process C:\PROGRAM FILES (X86)\MICROSOFT OFFICE\OFFICE14\WINWORD.EXE pid 808

09/05/2017 01:29:09.839 PM   mfeatp(2872.5352) <SYSTEM> Orchestrator.JCM.Debug: Process C:\PROGRAM FILES (X86)\MICROSOFT OFFICE\OFFICE14\WINWORD.EXE reputation 99 final 0 result 0x00000000 flags 0x0000000001000000 type: 1 connectivity: 1

09/05/2017 01:29:10.339 PM   mfeatp(2872.5352) <SYSTEM> Orchestrator.Action.Debug: Orchestrator finalizing reputation for C:\PROGRAM FILES (X86)\MICROSOFT OFFICE\OFFICE14\WINWORD.EXE

09/05/2017 01:29:10.339 PM   mfeatp(2872.5352) <SYSTEM> Orchestrator.JCM.Error: Failed to finalize reputation for file C:\PROGRAM FILES (X86)\MICROSOFT OFFICE\OFFICE14\WINWORD.EXE. ErrorCode 0xc030002f (For random EXE Like explorer.exe even cmd.exe)

09/05/2017 01:29:10.488 PM   mfeatp(2872.432) <SYSTEM> Orchestrator.JTI.Debug: Async: Process C:\PROGRAM FILES (X86)\MICROSOFT OFFICE\OFFICE14\WINWORD.EXE JTI reputation 99 rule 0 threat name  , JCM reputation 99, IsFinal 0

09/05/2017 01:29:10.489 PM   mfeatp(2872.432) <SYSTEM> Orchestrator.Action.Debug: Orchestrator finalizing reputation for C:\PROGRAM FILES (X86)\MICROSOFT OFFICE\OFFICE14\WINWORD.EXE

09/05/2017 01:29:10.866 PM   mfeatp(2872.2868) <SYSTEM> Orchestrator.JCM.Debug: Process C:\PROGRAM FILES (X86)\MICROSOFT OFFICE\OFFICE14\WINWORD.EXE reputation 99 final 0 result 0x00000000 flags 0x0000000001000000 type: 1 connectivity: 1

09/05/2017 01:29:14.799 PM   mfeatp(2872.1956) <SYSTEM> Orchestrator.JCM.Debug: JCM system event scan for process C:\WINDOWS\SYSTEM32\DLLHOST.EXE pid 8148

7 Replies

Re: ENS 10.5.1/10.5.2 ATP TIE Client, W7 64BIT, Failed to finalize reputation for file,ErrorCode 0xc030002f for random EXE on systems

Server 2008 R2 getting high memory usage, ~283,792 K from mcshield.exe. Same McAfee software you have listed, just different Windows OS.

09/13/2017 09:11:18.796 AM   mfeatp(1732.4232) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file C:\WINDOWS\CCM\UPDATETRUSTEDSITES.EXE. ErrorCode 0xc030002f

09/13/2017 09:11:18.982 AM   mfeatp(1732.4224) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file C:\PROGRAM FILES\VMWARE\VMWARE TOOLS\VMWARETRAY.EXE. ErrorCode 0xc030002f

09/13/2017 09:11:20.218 AM   mfeatp(1732.4232) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file C:\SCRIPTS\LOGIN\LOGIN.EXE. ErrorCode 0xc030002f

09/13/2017 09:11:31.614 AM   mfeatp(1732.4232) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file C:\WINDOWS\SERVICING\TRUSTEDINSTALLER.EXE. ErrorCode 0xc030002f

09/13/2017 09:42:03.211 AM   mfeatp(1732.4232) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file E:\CHECKERRORLOG\CHECKERRORLOG.EXE. ErrorCode 0xc030002f

09/13/2017 10:00:05.710 AM   mfeatp(1732.4232) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file C:\WINDOWS\SERVICING\TRUSTEDINSTALLER.EXE. ErrorCode 0xc030002f

09/13/2017 10:00:17.583 AM   mfeatp(1732.4232) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file C:\WINDOWS\SYSTEM32\WUAUCLT.EXE. ErrorCode 0xc030002f

09/13/2017 10:00:27.664 AM   mfeatp(1732.4232) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file C:\WINDOWS\SERVICING\TRUSTEDINSTALLER.EXE. ErrorCode 0xc030002f

09/13/2017 10:22:03.027 AM   mfeatp(1732.4232) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file E:\CHECKERRORLOG\CHECKERRORLOG.EXE. ErrorCode 0xc030002f

09/13/2017 10:25:26.796 AM   mfeatp(1732.4232) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file C:\WINDOWS\CCM\UPDATETRUSTEDSITES.EXE. ErrorCode 0xc030002f

09/13/2017 10:25:29.916 AM   mfeatp(1732.4232) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file C:\PROGRAM FILES\VMWARE\VMWARE TOOLS\VMWARETRAY.EXE. ErrorCode 0xc030002f

09/13/2017 10:25:38.982 AM   mfeatp(1732.1624) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE. ErrorCode 0xc030002f

09/13/2017 10:25:38.990 AM   mfeatp(1732.6356) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file C:\WINDOWS\CCM\SCNOTIFICATION.EXE. ErrorCode 0xc030002f

09/13/2017 10:25:43.481 AM   mfeatp(1732.4232) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file C:\WINDOWS\SERVICING\TRUSTEDINSTALLER.EXE. ErrorCode 0xc030002f

09/13/2017 10:25:54.342 AM   mfeatp(1732.4744) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file C:\WINDOWS\SYSTEM32\SPPSVC.EXE. ErrorCode 0xc030002f

09/13/2017 11:02:03.058 AM   mfeatp(1732.4232) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file E:\CHECKERRORLOG\CHECKERRORLOG.EXE. ErrorCode 0xc030002f

09/13/2017 11:02:06.164 AM   mfeatp(1732.1624) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:658): Failed to set new reputation for process E:\CHECKERRORLOG\CHECKERRORLOG.EXE, result:0xc0300027

09/13/2017 11:02:06.612 AM   mfeatp(1732.3620) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:658): Failed to set new reputation for process E:\CHECKERRORLOG\CHECKERRORLOG.EXE, result:0xc0300027

09/13/2017 12:12:03.512 PM   mfeatp(1732.5024) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:658): Failed to set new reputation for process E:\CHECKERRORLOG\CHECKERRORLOG.EXE, result:0xc0300027

09/13/2017 01:32:03.036 PM   mfeatp(1732.4224) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file E:\CHECKERRORLOG\CHECKERRORLOG.EXE. ErrorCode 0xc030002f

09/13/2017 01:36:29.334 PM   mfeatp(1732.3620) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE. ErrorCode 0xc030002f

09/13/2017 02:42:03.007 PM   mfeatp(1732.4744) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:658): Failed to set new reputation for process E:\CHECKERRORLOG\CHECKERRORLOG.EXE, result:0xc0300027

09/13/2017 02:52:12.243 PM   mfeatp(1732.4232) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file C:\WINDOWS\CCM\UPDATETRUSTEDSITES.EXE. ErrorCode 0xc030002f

09/13/2017 02:52:12.558 PM   mfeatp(1732.4232) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file C:\PROGRAM FILES\VMWARE\VMWARE TOOLS\VMWARETRAY.EXE. ErrorCode 0xc030002f

09/13/2017 02:52:20.063 PM   mfeatp(1732.4232) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file C:\WINDOWS\SERVICING\TRUSTEDINSTALLER.EXE. ErrorCode 0xc030002f

09/13/2017 02:57:42.913 PM   mfeatp(1732.4228) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file C:\PROGRAM FILES\VMWARE\VMWARE TOOLS\VMWARETRAY.EXE. ErrorCode 0xc030002f

09/13/2017 02:57:44.090 PM   mfeatp(1732.4228) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file C:\WINDOWS\CCM\UPDATETRUSTEDSITES.EXE. ErrorCode 0xc030002f

09/13/2017 02:59:00.429 PM   mfeatp(1732.4224) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file C:\WINDOWS\EXPLORER.EXE. ErrorCode 0xc030002f

09/13/2017 02:59:19.909 PM   mfeesp(1692.5988) <SYSTEM> ApBl.AP.Error (XModule.cpp:67): Vtp get file image hash MD5 LastErr 0x0000054f An internal error occurred.

Re: ENS 10.5.1/10.5.2 ATP TIE Client, W7 64BIT, Failed to finalize reputation for file,ErrorCode 0xc030002f for random EXE on systems

I removed and re-installed the ATP module via ePO. Seems to have resolved the errors. Mcshield.exe is still running at 211,476 K (and rising) and all other processes still running higher memory then before ENS but the errors are now gone.

09/13/2017 04:11:09.772 PM   mfeatp(3452.7228) <SYSTEM> atpbl.ATP.Debug: ATP policy enforcement completed

09/13/2017 04:11:09.778 PM   mfeatp(3452.2384) <SYSTEM> Orchestrator.JCM.Debug: Process C:\WINDOWS\SYSTEM32\DLLHOST.EXE reputation 99 final 0 result 0x00000000 flags 0x0000000001000000 type: 1 connectivity: 1

09/13/2017 04:11:14.375 PM   mfeatp(3452.6596) <SYSTEM> Orchestrator.JCM.Debug: JCM system event scan for process C:\WINDOWS\SYSTEM32\DLLHOST.EXE pid 2296

09/13/2017 04:11:29.137 PM   mfeatp(3452.2384) <SYSTEM> Orchestrator.JCM.Debug: JCM system event scan for process C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE pid 728

09/13/2017 04:11:29.144 PM   mfeatp(3452.5456) <SYSTEM> Orchestrator.JCM.Debug: Process C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE reputation 99 final 0 result 0x00000000 flags 0x0000000001000000 type: 1 connectivity: 1

09/13/2017 04:11:29.258 PM   mfeatp(3452.5456) <SYSTEM> Orchestrator.JTI.Debug: Process C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE JTI reputation 99 rule 51 threat name JTI/Trusted!65587 , JCM reputation 99, IsFinal 0

09/13/2017 04:11:29.259 PM   mfeatp(3452.5456) <SYSTEM> Orchestrator.Action.Debug: Orchestrator finalizing reputation for C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE

09/13/2017 04:11:29.765 PM   mfeatp(3452.6596) <SYSTEM> Orchestrator.JCM.Debug: Process C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE reputation 99 final 0 result 0x00000000 flags 0x0000000001000000 type: 1 connectivity: 1

Re: ENS 10.5.1/10.5.2 ATP TIE Client, W7 64BIT, Failed to finalize reputation for file,ErrorCode 0xc030002f for random EXE on systems

Thought I had it solved but the problem remains:

09/20/2017 12:24:54.126 AM   mfeatp(1908.708) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file C:\WINDOWS\CCMSETUP\CACHE\CCMSETUP.EXE. ErrorCode 0xc030002f

09/20/2017 12:25:18.612 AM   mfeatp(1908.708) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file C:\WINDOWS\CCMSETUP\CACHE\CCMSETUP.EXE. ErrorCode 0xc030002f

09/20/2017 12:39:41.312 AM   mfeatp(1908.2608) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE. ErrorCode 0xc030002f

09/20/2017 01:12:03.030 AM   mfeatp(1908.3208) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file E:\CHECKERRORLOG\CHECKERRORLOG.EXE. ErrorCode 0xc030002f

09/20/2017 02:00:08.754 AM   mfeatp(1908.4616) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file C:\WINDOWS\SYSWOW64\WBEM\WMIPRVSE.EXE. ErrorCode 0xc030002f

09/20/2017 05:42:03.250 AM   mfeatp(1908.4240) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file C:\WINDOWS\SYSTEM32\DLLHOST.EXE. ErrorCode 0xc030002f

09/20/2017 05:42:03.359 AM   mfeatp(1908.4440) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file C:\WINDOWS\SYSTEM32\TASKENG.EXE. ErrorCode 0xc030002f

09/20/2017 07:02:03.010 AM   mfeatp(1908.3208) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file E:\CHECKERRORLOG\CHECKERRORLOG.EXE. ErrorCode 0xc030002f

09/20/2017 08:21:23.110 AM   mfeatp(1908.708) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:702): Failed to finalize reputation for file C:\WINDOWS\EXPLORER.EXE. ErrorCode 0xc030002f

Re: ENS 10.5.1/10.5.2 ATP TIE Client, W7 64BIT, Failed to finalize reputation for file,ErrorCode 0xc030002f for random EXE on systems

Hi there,

I got something like this with ENS 10.5.3 (TP, WC, FW, ATP)

Failed to finalize reputation for file C:\WINDOWS\SERVICING\TRUSTEDINSTALLER.EXE. ErrorCode 0xc030002f

Re: ENS 10.5.1/10.5.2 ATP TIE Client, W7 64BIT, Failed to finalize reputation for file,ErrorCode 0xc

Hi,

Meanwhile waiting for 10.5.4... oh wait  Smiley LOL

"Currently there is no further information available regarding the fix release data"

 

Errors in ENS Error log:

01/19/2018 08:19:27.812 AM   mfeatp(3984.7780) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:911): Failed to finalize reputation for file C:\PROGRAM FILES (X86)\MICROSOFT OFFICE\OFFICE16\WINWORD.EXE. ErrorCode 0xc030002f

01/19/2018 08:21:16.037 AM   mfeatp(3984.7780) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:911): Failed to finalize reputation for file C:\PROGRAM FILES (X86)\MICROSOFT OFFICE\OFFICE16\EXCEL.EXE. ErrorCode 0xc030002f

01/19/2018 08:21:34.724 AM   mfeatp(3984.7780) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:911): Failed to finalize reputation for file C:\PROGRAM FILES (X86)\ADOBE\ACROBAT READER 2017\READER\ACRORD32.EXE. ErrorCode 0xc030002f

01/19/2018 08:21:41.178 AM   mfeatp(3984.7780) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:911): Failed to finalize reputation for file C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE. ErrorCode 0xc030002f

are probably related to a known cosmetic issue which we are already working on:

In cases as in these logs we see indicators of the file reputation not finalizing, often for trusted files, such as iexplore.exe, whereby we had a reputation of 99 but still failed to finalize which is indicative of a problem in JCMCore where the reputation should have already been finalized, but for some reason has not.
 
We are already aware of this issue and investigation is ongoing. Currently there is no further information available regarding the fix release data.

 

Re: ENS 10.5.1/10.5.2 ATP TIE Client, W7 64BIT, Failed to finalize reputation for file,ErrorCode 0xc

I have the same error on my machines. 

02/06/2018 04:31:55.717 PM mfeatp(2820.8852) <SYSTEM> Orchestrator.JCM.Error (jcm_native.cpp:911): Failed to finalize reputation for file C:\PROGRAM FILES (X86)\COMMON FILES\ADOBE\ARM\1.0\ADOBEARM.EXE. ErrorCode 0xc030002f

jmcg
Level 10
Report Inappropriate Content
Message 8 of 8

Re: ENS 10.5.1/10.5.2 ATP TIE Client, W7 64BIT, Failed to finalize reputation for file,ErrorCode 0xc

Look like this has been fixed on ATP/ENS 10.5.4

Now i have some "Failed to repair process"

05/02/2018 04:36:28.801 PM   mfeatp(3372.7300) <Système> Orchestrator.Action.Error (post_scan_actions.cpp:717): Failed to repair process : C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE , process id 0 , ErrorCode: 0x31
05/02/2018 04:38:08.168 PM   mfeatp(3372.6512) <Système> Remediationbl.RepairModule.Error (real_protect_remediation.cpp:66): Failed to start remediation for process 7028 due to invalid response from raptor
05/02/2018 04:38:08.195 PM   mfeatp(3372.6512) <Système> Orchestrator.AMCoreUtil.Error (amcore_remediation_util_impl.cpp:1118): Failed to finish quarantine session, error 0xa7f40a04
05/02/2018 04:38:18.220 PM   mfeatp(3372.4720) <Système> Orchestrator.Action.Error (post_scan_actions.cpp:717): Failed to repair process : C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE , process id 0 , ErrorCode: 0x31

 

More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator
  • Community Help Hub

      New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

    • Find Forum FAQs
    • Learn How to Earn Badges
    • Ask for Help
    Go to Community Help

    Join the Community

      Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

    • Get helpful solutions from McAfee experts.
    • Stay connected to product conversations that matter to you.
    • Participate in product groups led by McAfee employees.
    Join the Community
    Join the Community