FEP and SCEP Client updates

There multible versions of client deployed at same time. I'm using stadard software updates deployment process to keep clients up to date. NOT talking about definitions, but client version!
I have FEP and SCEP clients out there. When I go to All software updates and search for "endpoint protection client" I will have four FEP (4.1.552.0, 4.3.215.0, 4.5.236.0, 4.6.305.0) updates and three SCEP updates (4.3.215.0, 4.5.216.0, 4.6.305.0)
to client deployed in the same update packages! All of them with various number of Required and Installed status.
The obious reason for this is that older client update packages are not marked as superseeded updates. Any thoughts on why? I am going to exclude old ones with custom severity method, but is there a automatic method available?
.Marko

Multiple SCEP/FEP updates are required, because SCEP/FEP agent can update only N-2 versions e.g. you cannot install SCEP version 4.6.305.0 to a computer with SCEP 4.3.215.0. You need first to upgrade 4.3 to 4.5 and then to 4.6.Because there might be earlier
versions in the environment, there must be multiple SCEP/FEP versions available.
Check the following blog article for more details:
http://blogs.technet.com/b/configmgrteam/archive/2014/03/27/anti-malware-platform-updates-for-endpoint-protection-will-be-released-to-mu.aspx
Panu

Similar Messages

  • SCCM Client and SCEP Client Uninstall

    Hi, I have below questions with regard to the SCCM client software and the SCEP client software.
    Does SCCM client uninstallation removes SCEP client as well? If not, how does the Endpoint Protection get the updates after SCCM client is removed? How to remove/uninstall SCEP client?
    If the SCCM client uninstallation removes the SCEP client as well (by running ccmsetup.exe /uninstall), how to make it to NOT uninstall the SCEP client?
    Thanks.
    NM

    Yes, your SCEP client should still be able to update.
    If you're installing the ConfigMgr client again, and have manage SCEP client enabled in the ConfigMgr client settings, it does more then just adding the update source. It allows you to manage the SCEP client configuration (like scan settings, exclusions,
    etc), perform remote actions (like initiating a scan) and report about them.
    My Blog: http://www.petervanderwoude.nl/
    Follow me on twitter: pvanderwoude

  • Windows 8.1 will not get Forefront Client Updates from WSUS

    Recently I noticed that my Windows 8.1 clients were not getting updates from WSUS 3.2.  After some searching I found it was an issue with HTTPS and the solution was to disable HTTPS or enable TLS.  So I enabled TLS on the Server 2008 R2 WSUS server
    and that fixed the issue with my 8.1 clients not getting updates except for Forefront Endpoint Protection 2010.   My SCCM server deploys the client fine but it is version 2.1 and normally the client and definition updates come from WSUS with the
    latest client version being 4.5.  However, my Windows 8.1 machines will not get the client updates even though they are automatically approved for all machines.
    I am just wondering what else I can check or change to make sure my Windows 8.1 clients get the Forefront client updates as they should??   I am wondering if I manually install the 4.1 client update if it will take the client updates after that.  
    I only have about eight Windows 8.1 machines so if I have to do that by hand for now then I will and I think my organization will be moving to Server 2012 and SCCM 2012 this summer sometime.

    I reread your post and have another suggestion. If your SCCM 2007 server is still deploying the old 2.1 FEP client version, then you should install the latest anti-malware platform update for the SCCM server so you can deploy it from there instead of WSUS:
    http://support.microsoft.com/kb/2952678
    http://blogs.msdn.com/b/minfangl/archive/2013/08/15/guidance-on-install-anti-malware-platform-updates-for-fep-2010-su1-and-scep-2012-sp1.aspx
    Also, you may be affected by this:
    "Anti-malware platform updates on MU will use special detection logic and applicability rules to make the anti-malware platform updates available only on computers with previous N-2 anti-malware platforms installed. For example, on April 8<sup>th</sup>,
    anti-malware platform of version 4.5.x will be released on MU, and it will only be offered to computers where anti-malware platform version 4.3.x or 4.4.x is available. If a computer has FEP or SCEP client with version 4.1.x, it has to be upgraded to version
    4.3.x first, then to the latest version (4.5.x). If a computer has FEP or SCEP client with version older than 4.1.x, because of the same N-2 rule, it has to be upgraded to 4.1.x first, then to 4.3.x, and then to the latest version (4.5.x). Required updates
    will be kept on MU to ensure that this upgrade process is available for computers running older versions of the Microsoft anti-malware platform."
    http://blogs.technet.com/b/configmgrteam/archive/2014/03/27/anti-malware-platform-updates-for-endpoint-protection-will-be-released-to-mu.aspx

  • Client Update Packages (SCCM CUs)

    What is the proper way of deploying these?  I have the x64 package deployed to a dynamic collection which consists of x64 clients.  It's configured to install as soon as possible.  This is causing issues with new client installs since the
    SCEP install and client update seem to interfere with each other.  How can I ensure clients receive the client update in a timely manner but don't interfere with the SCEP  install?

    A common approach is to make collections with queries that target x86 and x64 OS architectures.
    Then deploy the x86 and x64 client update packages (that get created for you when applying the CU) to those collections.
    When you say new client installs do you mean during OSD? If this is the case then you should be patching your client at the point of installation during your OSD Task Sequence.
    If you mean that the Client Update package is attempting to install before the major client update - i.e. your on SCCM 2012 SP1 and you have upgraded to 2012 R2 CU1 - then you should be adjusting your queries so they only target clients with the R2 version.
    This way you will not have the Client Update package trying to run before the full client upgrade has occurred.
    As an example - this is the query I have used to upgrade my SCCM 2012 CU1 client to CU2:
    select SMS_R_SYSTEM.ResourceID,SMS_R_SYSTEM.ResourceType,SMS_R_SYSTEM.Name,SMS_R_SYSTEM.SMSUniqueIdentifier,SMS_R_SYSTEM.ResourceDomainORWorkgroup,SMS_R_SYSTEM.Client from SMS_R_System inner join SMS_G_System_SYSTEM on SMS_G_System_SYSTEM.ResourceID = SMS_R_System.ResourceId
    where SMS_R_System.Active = "1" and SMS_G_System_SYSTEM.SystemType = "X64-based PC" and SMS_R_System.ClientVersion < "5.00.7958.1303" and SMS_R_System.ClientVersion >= "5.00.7958.1000"
    There are plenty of blogs which talk about client updates using queries.
    Cheers
    Damon
    I have a dynamic collection built already.  I guess my question revolves around how  you should configure the available/deadline part of the deployment.  My issue is that the SCEP install after a client is upgraded from 2007 -> 2012 is kicking
    off at the same time as the client upgrade.  The FEP client gets uninstalled, the client upgrade gets stuck in "Waiting for install" and nothing continues until I restart the SMS service.

  • SCEP definition updates for clients in DMZ via UNC is not working.

    Hello,
    I have configured SCEP definition updates via UNC method for my Win 8.1 clients in DMZ and its not working.
    Script is properly associated with task scheduler and downloading definition to shared folder properly.
    Even running the mpcmdrun.exe -SignatureUpdate, gives the below error:
    C:\Program Files\Microsoft Security Client>mpcmdrun.exe -SignatureUpdate
    Signature update started . . .
    ERROR: Signature Update failed with hr=80070002
    CmdTool: Failed with hr = 0x80070002. 
    MpCmdRun: Command Line: mpcmdrun.exe  -SignatureUpdate
     Start Time: ‎Sun ‎Jul ‎06 ‎2014 11:05:09
    Start: MpSignatureUpdate()
    Update started 
    Search Started (UNC share) (Path: \\sccm\SCEP_UNC_DEFS\Updates\x64)...
    Search Completed 
    Download Started...
    Download Completed 
    Installation Started...
    Installation Completed 
    Update completed with hr: 0x80070002
    ERROR: Signature Update failed with hr=80070002
    MpCmdRun: End Time: ‎Sun ‎Jul ‎06 ‎2014 11:05:17

    Hi,
    Please check logs on the client to see whether there are any helpful information.(ScanAgent.log, Windowsupdate.log and UpdatesHandler.log)
    Best Regards,
    Joyce
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • SCEP client not updating settings after policy retrieval

    I have a computer assigned a SCEP policy, that seems to have been found and Applied fine by the SCCM Client, looking at the registry.
    I find the policy in the regkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CCM\EPAgent\GeneratedPolicy, With the DWORD values
    Just a test to my computer (Excluded)                   REG_DWORD         0x00000002 (2)
    Just a test to my computer (Scan Schedule)           REG_DWORD         0x00000002 (2)
    What I have configured in this test policy is just "Limit CPU usage during scan to: 10%" and "Start the scheduled scan only when my PC is on but not in use"
    But the SCEP Client, in the settings, do not show the correct settings. The CPU limit setting is set to 20% and the "Start the scheduled scan" setting is unchecked, these settings come from the "Default Client Antimalware Policy"
    The EndpointProtectionAgent.log says:
    Endpoint is triggered by WMI notification. EndpointProtectionAgent 28.10.2014 16:54:39 3504 (0x0DB0)
    EP State and Error Code didn't get changed, skip resend state message. EndpointProtectionAgent 28.10.2014 16:54:39 3504 (0x0DB0)
    State 1, error code 0 and detail message are not changed, skip updating registry value EndpointProtectionAgent 28.10.2014 16:54:39 3504 (0x0DB0)
    Previous state is same with current one: 1, skip notification. EndpointProtectionAgent 28.10.2014 16:54:39 3504 (0x0DB0)
    File C:\Windows\ccmsetup\SCEPInstall.exe version is 4.5.216.0. EndpointProtectionAgent 28.10.2014 16:54:39 3504 (0x0DB0)
    EP version 4.6.305.0 is already installed. EndpointProtectionAgent 28.10.2014 16:54:39 3504 (0x0DB0)
    EP 4.6.305.0 is installed, version is higher than expected installer version 4.5.216.0. EndpointProtectionAgent 28.10.2014 16:54:39 3504 (0x0DB0)
    The trigger 10 doesn't make ANY state change. EndpointProtectionAgent 28.10.2014 16:54:39 3504 (0x0DB0)
    Handle EP AM policy. EndpointProtectionAgent 28.10.2014 16:54:39 3504 (0x0DB0)
    Policy group lose, group name: Scan Schedule, settingKey: {d6961d76-070d-46af-b898-6d24562fb219}_201_201 EndpointProtectionAgent 28.10.2014 16:54:39 3504 (0x0DB0)
    Policy deployment result: <?xml version="1.0"?><Group Name="Scan Schedule">    <Policy Name="Just a test to my computer" State=2/>    <Policy Name="Default Client Antimalware
    Policy" State=1/></Group><Group Name="Threat Default Action">    <Policy Name="Default Client Antimalware Policy" State=2/></Group><Group Name="Excluded">   
    <Policy Name="Default Client Antimalware Policy" State=2/>    <Policy Name="Just a test to my computer" State=2/></Group><Group Name="Realtime Config">    <Policy Name="Default
    Client Antimalware Policy" State=2/></Group><Group Name="Advance Setting">    <Policy Name="Default Client Antimalware Policy" State=2/></Group><Group Name="Spynet">   
    <Policy Name="Default Client Antimalware Policy" State=2/></Group><Group Name="Signature Update">    <Policy Name="Default Client Antimalware Policy" State=2/></Group><Group Name="Scan">   
    <Policy Name="Default Client Antimalware Policy" State=2/></Group> EndpointProtectionAgent 28.10.2014 16:54:39 3504 (0x0DB0)
    Generate Policy XML successfully at C:\Windows\CCM\EPAMPolicy.xml EndpointProtectionAgent 28.10.2014 16:54:39 3504 (0x0DB0)
    Generate AM Policy XML while EP is disabled. EndpointProtectionAgent 28.10.2014 16:54:39 3504 (0x0DB0)
    Any idea what happened to the New settings?
    Freddy

    Antimalware Client Version: 4.6.305.0
    Engine Version: 1.1.11104.0
    Antivirus definition: 1.187.618.0
    Antispyware definition: 1.187.618.0
    Network Inspection System Engine Version: 2.1.11005.0
    Network Inspection System Definition Version: 113.5.0.0
    Policy Name: Antimalware Policy
    Policy Applied: 02.09.2014 at 14:16
    The above is information in "About"
    This is the information about the Antimalware policies assigned to this computer
    Name                                             
    Collection name       Priority    Policy Application state Last update time         Policy Application Return code
    Default Client Antimalware Policy                                   10000     
    Succeeded                     02.09.2014 16:16:00      0x00000000  
    Just a test to my computer              VITN-SC-OSL-112  1
    This tells me that there is no policy Application Return code for the custom policy i am testing, and that is something I would like to solve. Any ideas? Thank you

  • Some clients not receiving SCEP definition updates

    I have a collection for some of our application servers that is used in conjunction with an ADR to deploy the SCEP definition updates. 12 of the servers in this collection recently had the SCCM 2012 R2 client installed on them. (The collection has a total
    of 23 servers in it)
    I can see that these 12  servers have the Antimalware policy applied, but are not getting the SCEP updates.  The summary for SCEP is:  Service started without any malware protection engine; AV signatures out of date; AS signatures out
    of date.
    The policy application state is "Succeeded" with the recent date and time.
    When I view the status of the deployment, the enforcement state is "Failed to install update(s) " with an error code of 0X87D00667 - No current or future service window exists to install software updates.
    These servers are members of another collection that is used for deploying the Monthly updates.  This "update" collection does have a maintenance window on it specific to software updates, with no recurrence schedule.
    Do maintenance windows apply to the machine then, regardless of what collection they are in?
    These 12 servers, for the Endpoint Protection client settings have the "Allow EP client installation and restarts outside MW" set to No, and the Suppress any required computer restarts after the EP client is installed set to Yes. 
    For the Software Updates client setting, the update scan schedule and deployment re-evaluation is set to every 7 days.
    So, in looking at this, it appears that these servers will never get any SCEP updates because they are members of another collection that has a MW, even though the SCEP collection does not have a MW?
    Is that correct?

    I added a MW on the collection that is used for SCEP updates.  I made the MW effective yesterday, but the MW hours were from 5:30am-7:30am daily (which should have started this morning, 1/30, at 5:30am).
    In the updatesdeployment.log, I see the MW starting:
    CUpdateAssignmentsManager received a SERVICEWINDOWEVENT START Event UpdatesDeploymentAgent 1/30/2015 5:30:00 AM 3004 (0x0BBC)
    No current service window available to run updates assignment with time required = 1 UpdatesDeploymentAgent 1/30/2015 5:30:00 AM 3004 (0x0BBC)
    CUpdateAssignmentsManager received a SERVICEWINDOWEVENT END Event UpdatesDeploymentAgent 1/30/2015 7:30:00 AM 3312 (0x0CF0)
    No current service window available to run updates assignment with time required = 1 UpdatesDeploymentAgent 1/30/2015 7:30:00 AM 3312 (0x0CF0)
    Attempting to cancel any job started at non-business hours. UpdatesDeploymentAgent 1/30/2015 7:30:00 AM 3312 (0x0CF0)
    However, the definitions are not installed. These 12 servers have the SCEP client, but no definitions installed.
    There are 11 servers in this collection that are getting the definition updates, but the 12 servers in this collection that have recently had the SCCM client installed on it are not getting the updates.    So I know that the ADR is working.
    What am I missing to get these 12 servers to install/update the definitions?

  • SCEP definition updates for clients in DMZ

    Hello,
    I do want to enable SCEP definition updates for small group of clients in DMZ (apprx 30 -40)
    I have created a separate  AD OU and SCCM collection for such computers.
    Google shows me different ways like using Definition Update Automation Tool, WSUS, scripts, shares etc, and I am quite confused for which way to adopt.
    can any one suggest me which is the best automated way?
    I do have SCCM 2012 sp1 and all win 8 cleints.
    Thanks in Advance

    You can use whathever method you prefer. All will most likely work. As there's already Configmgr in place I'd use it to do this job. ADRs (automatic deployment rules) can be used to automate this process.
    Torsten Meringer | http://www.mssccmfaq.de

  • SCCM 2012 OSD Task Sequence - force Policy and SCEP update?

    Hi,
    How can I force a policy update to update machine policy and scep definitions at the end of
    SCCM 2012 OSD Task Sequence,
    Thanks,
    Ward.

    Hi,
    I normally use this solution from Chris Nackers to deploy the latest EP definitions during OSD and deploy a custom EP policy, it works great. The policy will be downloaded when the client is registered.
    Regards,
    Jörgen
    -- My System Center blog ccmexec.com -- Twitter
    @ccmexec

  • Updating SCEP Clients

    Hi,
    We are currently running SCEP 4.1 client and I want to update them to the latest version.  Our server is SCCM 2012 SP1
    We have no applied cumulative updates to the server.  Am I required to apply the CUs to the server before I can update the clients? or how does it work?
    When I apply the CUs to the server is it updating the Endpoint Protection piece of the server as well, then I deploy out the updates to the clients?
    Thanks,
    Travis

    Hi,
    Yes, when you install the CU on the server then the SCEPinstall.exe which is used to install the SCEP client is updated as well. Probably not to the latest version as that was released just a couple weeks ago but the version before that, the latest version
    is available through Windows Update/WSUS.
    Regards,
    Jörgen
    -- My System Center blog ccmexec.com -- Twitter
    @ccmexec

  • Are admin and office clients always updated for each service pack.

    Hi,
    I am investigating upgrading our BPC version from 7.0 SP3.   The question I have been asked by my business clients is "do the admin and office clients of BPC always get updated with each service pack?"  I assume they do because the install guide indicates that you must update them to the same version as the server.  Upgrading the client versions is always a concern here because since we don't allow the automatic update our plans have to include packaging an SMS deployment to over 500 workstations of several different configurations and locations.

    Hi,
    Yes, there are changes in the clients in every service pack. This is why it's important that the version of the client matches the version on the server. We've seen issues where there was a mismatch and no one could log in because of the changes in the client.
    I would advise always updating the clients when adding a new service pack.
    Regards,
    Jason

  • SUS - updates copied and enabled, clients won't pull them

    My SUS is set to copy and enable all updates automatically, and it's working fine. I have my client machines set to pull updates from the SUS (confirmed by the server name in the software update title bar), but every time I run it, it says no updates are available. I can see updates in Server Admin that I know for a fact my client systems don't have, but my clients don't seem to recognize that the updates are there.
    Any ideas?

    I've followed the instructions, yet some updates are not presented to the clients. Snow Leopard server's Software Update Service is pretty unreliable... STILL.

  • HT2492 When I try to update Adobe Flash Player I'm prompted to quit Safari and Dashboard Client. I quit Safari but I don' know how to quit Dashboard Client. Can anyone help with this challenge?

    When I try to update Adobe Flash Player I'm prompted to quit Safari and Dashboard Client. I quit Safari but I don' know how to quit Dashboard Client. Can anyone help with this challenge?

    Carolyn,
    Thank you. It worked
    Angus.

  • HT201068 In the Ap Store "Updates" window, it says that "Remote Desktop Client Update" was installed today.  I never intentionally installed "Remote Desktop".  How did it get there, Where is it on my computer, and How can I remove it?  Thank You!

    In the Ap Store "Updates" window, it says that "Remote Desktop Client Update" was installed today.  I never intentionally installed "Remote Desktop".  How did it get there, Where is it on my computer, and How can I remove it?  Thank You!

    I don't know if you have been there, but a very suspicious icon!  (Like this one on a NSA satellite: http://b-i.forbesimg.com/kashmirhill/files/2013/12/Satellite-logo-for-spying.jpg)  Yikes!
    Are they after the French too?!?  I thought we were allies?!?  Wait a minute . . . I'm an American citizen with the Constitutional Right (which they vowed to uphold when they took their job!) of privacy!!!
    What do you think of all this?
    How did you find it in the OS?
    Do I just trash it with "Secure Empty"?

  • I am surprised to see that Remote Desktop Client update 3.7.1 been updated without my authorisation and creating now lot of problems from December 7, 2013, any one can tell, how?

    Remote Desktop Client update 3.7.1 has been updated without any permission and now creating umpteen number of problems since December 7, 2013. Now my gmail is empty and unable to see any email.  Most of the time my local host is: 92.242.132.27, I do not know why?
    Now I want to uninstall my update 3.7.1.
    I seek help to resolve my problem.
    Traceroute has started...
    traceroute to www.localhost.com (92.242.132.27), 64 hops max, 72 byte packets 1  192.168.1.1 (192.168.1.1)  1.554 ms  0.995 ms  0.972 ms 2  abts-tn-dynamic-001.0.164.122.airtelbroadband.in (122.164.0.1)  28.460 ms 3  abts-tn-static-093.227.95.61.airtelbroadband.in (61.95.227.93)  27.732 ms 4  61.95.240.129 (61.95.240.129)  27.433 ms  28.015 ms  27.758 ms
    5  59.145.7.133 (59.145.7.133)  187.777 ms  186.806 ms  236.866 ms 6  182.79.243.18 (182.79.243.18)  179.356 ms  179.188 ms  178.033 ms 7  182.79.248.234 (182.79.248.234)  178.512 ms  179.033 ms  179.084 ms 8  aes-static-029.37.144.59.airtel.in (59.144.37.29)  178.879 ms  177.540 ms 9  xe-0-0-0-0.edge00.thn.uk.hso-group.net (195.66.224.226)  177.235 ms  178.6
    10  xe-0-0-0.edge00.the.uk.hso-group.net (93.89.91.13)  177.571 ms  177.667 ms 11  ert1-the-gi1-8.router.uk.catalyst2.net (93.89.90.10)  187.420 ms  185.670 12  84.18.192.130 (84.18.192.130)  178.729 ms  178.521 ms  178.316 ms 13  * * *
    14  * * * 15  * * * 16  * * * 17  * * * 18  * * * 19  * * * 20  * * * 21  * * * 22  * * * 23  * * * 24  * * *

    Remote Desktop Client update 3.7.1 has been updated without any permission and now creating umpteen number of problems since December 7, 2013. Now my gmail is empty and unable to see any email.  Most of the time my local host is: 92.242.132.27, I do not know why?
    Now I want to uninstall my update 3.7.1.
    I seek help to resolve my problem.
    Traceroute has started...
    traceroute to www.localhost.com (92.242.132.27), 64 hops max, 72 byte packets 1  192.168.1.1 (192.168.1.1)  1.554 ms  0.995 ms  0.972 ms 2  abts-tn-dynamic-001.0.164.122.airtelbroadband.in (122.164.0.1)  28.460 ms 3  abts-tn-static-093.227.95.61.airtelbroadband.in (61.95.227.93)  27.732 ms 4  61.95.240.129 (61.95.240.129)  27.433 ms  28.015 ms  27.758 ms
    5  59.145.7.133 (59.145.7.133)  187.777 ms  186.806 ms  236.866 ms 6  182.79.243.18 (182.79.243.18)  179.356 ms  179.188 ms  178.033 ms 7  182.79.248.234 (182.79.248.234)  178.512 ms  179.033 ms  179.084 ms 8  aes-static-029.37.144.59.airtel.in (59.144.37.29)  178.879 ms  177.540 ms 9  xe-0-0-0-0.edge00.thn.uk.hso-group.net (195.66.224.226)  177.235 ms  178.6
    10  xe-0-0-0.edge00.the.uk.hso-group.net (93.89.91.13)  177.571 ms  177.667 ms 11  ert1-the-gi1-8.router.uk.catalyst2.net (93.89.90.10)  187.420 ms  185.670 12  84.18.192.130 (84.18.192.130)  178.729 ms  178.521 ms  178.316 ms 13  * * *
    14  * * * 15  * * * 16  * * * 17  * * * 18  * * * 19  * * * 20  * * * 21  * * * 22  * * * 23  * * * 24  * * *

Maybe you are looking for

  • HT1657 How can I delete a rented movie from my ipad before its expiration date?

    How can I delete a watched rented movie from my Ipad before its expiration date?

  • Videos Do Not Play on PC After iOS6 Update

    I am having a very big problem.  I have an iPhone 4S that is less than one year old.  Prior to updating my iOS firmware, I was able to record and transfer video to my PC and view it with a variety of programs without any modifications.  Since updatin

  • Officejet j6480 loses wireless

    A little over a year ago I was participating in a conversation on the officejet 6480 all in one printer.  At first boot the wirelss was up but eventually connection was lost. Myself and others in the forum were having the same issues. I was wondering

  • Referencing Jar inside a Jar

    Hi, i have a jar file. the classes inside the jar file refers to classes within another jar file. i packaged the second jar into my jar file but during runtime i get NoClassDefFoundError when i refer to the classes inside the second jar. i tried givi

  • Saving As Oggs Truncates Audio?

    I'm having a problem I can't understand. I edit a short audio file (wav), and save it as .ogg. It's fine as long as it is still open in AA. but when I close it and open it again, the end of the file gets cut off (like the last .25 seconds). Does anyo