Basic Troubleshooting the New Ivanti Antivirus(Bitdefender Engine)
This document assumes you have completely followed the “Introducing the New Ivanti Antivirus in Ivanti Endpoint Manager” instructions in document Introducing the New Ivanti Antivirus in Ivanti Endpoint Manager 2017.3 SU2 . If you have not, review this document and follow its instructions before continuing before continuing. It also assumes you are familiar with the console and where to go to configure Download Updates and Agent Settings.
Note: Clicking a photo will enlarge it.
Issue: I do not see the Ivanti Antivirus Core Installation Files option in the Download Updates dialog, even though I have the correct licensing and service pack installed on the core.
Resolution: Run a Download Updates manually with any item(s) selected. After completion reopen Download Updates. The Ivanti Antivirus Core Installation Files option should be present. Check the box and run Download Updates again to get the needed antivirus install files.
Issue: The task to install the new Ivanti Antivirus on a client failed with: Ivanti Antivirus failed to Install code: 448.
Resolution:
Step 1: On the core itself, navigate to %ldms_home%\ldlogon\avclientbd. Make sure the epsecurity_x64.exe and epsecurity_x86.exe files exist. If they do not, go and run Download Updates again with the Ivanti Antivirus Core Installation Files option checked so the files download.
Step 2: Make sure you ran the AVsetup.exe file on the core and it completed successfully as outlined in https://community.ivanti.com/docs/DOC-62435#jive_content_id_Core_Install_files_in_Default_Drive_Letter_C The installation of the definition download utility on the core is needed before you can install the client portion on devices.
Step 3: Make sure any other Antimalware/Antivirus programs are removed prior to installing the new Ivanti Antivirus. Currently the New antivirus solution does not auto uninstall other security applications. You will need to uninstall sure programs before you install our antivirus solution. Windows Defender is the exception this can be left running on the client devices if you like.
Removal tools (uninstall tools) for common antivirus software
Step 4: Log information on the installation of antivirus can be found in: C:\ProgramData\LANDesk\Log\ldav_install.log
Issue: I installed the new Ivanti Antivirus on a client device and upon opening the GUI on the client it says Antimalware-Advanced Threat component(s) are disabled and a message: You are at Risk.
Resolution: It is normal for the Advanced Threat Control module to be disabled. In the future this will be enabled as we improve the product. To clear the You are at Risk message, Run a full scan on the device and allow it to complete. Click the radar icon , then click Full Scan. Allow the scan to complete. When done the main window should display You are Protected in green.
Issue: My definitions do not seem to be updating on the clients. Clicking in the GUI on the client does nothing.
Resolution:
Step 1: The Check for Updates button in the GUI is not functioning at this time. It tmay be functional in the future as we improve the product. You need to schedule definition updating on the clients through the Agent Settings. By default, definition updates are not turned on in the agent settings.
Open Agent Settings. Expand Security and Ivanti Antivirus New. Double Click you agent setting on the right window. Click Scheduled Tasks and Check the Update box then Change Settings to adjust the update times. When done Save the settings. The agent settings will get applied to the client devices the next time a security scan is ran.
Step 2: To force an immediate update on the client run the following command as administrator on the device:
"C:\Program Files (x86)\LANDesk\LDClient\Antivirus\LDAV.exe" /update
Remember the above command must be ran as administrator.
Step 3: The log containing update information for the client can be found in: C:\ProgramData\LANDesk\Log\ldav_update.log