le virus est détecté par symantec endpoint mais n'est pas supprimé, la liste des virus est mise a jours
Virus backdoor vbs dunihi
Automatic research of a risk with the SEP 12.1
Hi all,
I want to know if a particular risk is present in my network.
Now I'm able only to make a research through the following steps:
- Click on the Monitor link;
- log type=risk
- advanced settings ----> risk name = "I write the name of the risk"
Is possible to make the same research of the risk automatically and in a scheduled mode using the SEP 12.1?
Thanks
Clients downloads the virus definitions from SEPM but does not use it to update the agent
Hello,
I have this problem in all of the clients in the network. We have SEPM 11.0.6200.754 on Windows Server 2003 SP2.
The clients are connected to the SEPM and receive the latest definitions from the server, but for some reason the definitions are not used to update the client agent. The clients continue with the older virus definitions.
By configuration, Antivirus and AntiSpyware protection, ProActive protection and Network threat protection are updated in the clients. Now in most of the clients, Network threat Protection is always updated, but the other two contents (Antivirus and AntiSpyware protection, ProActive protection) keeps the definitions that are 10 days old now.
However one or two computers use the latest virus definitions. It could be because, the Hard disks crashed due to some reason and we had to reload the software using an image which had the SEP clients already installed it. But this wouldnt be a feasible solution considering 55-60 clients.
Your support is very much appreciated.
Cannot login into SEPM with AD authentication.
Hello,
I tried to login into the SEPM with my AD account but I'm receiving this error message:
"The administrator's user name or password is incorrect. Type a valid user name or password"
I read something here in another forum discussion but I can't login. The AD server is added to the console and I add a new domain instead the default one but nothing and there is another user that can login succesfully. Version is 12.1.4
Please help me to figure this out.
Regards
Logs for system tray notifications
I'm getting Heartbleed IPS notifications in the system tray, but I can find no logs of it anywhere. There is no persistent log of the details of the event (like the source of the traffic).
Where do I get or configure that information?
Bloodhound.Flash.24
Would virus def. 4/28/14 r16 protect against Bloodhound.Flash.24 or do I need 4/30/14 r2 ?
For some reason I cant update my SEPM to the latest ver. Never had an issue before - maybe because everyone is trying to download?
Will this endpoint manager (11.0.5002.333) upgrade to 12.1.4
I have looked at this article. http://www.symantec.com/business/support/index?page=content&id=TECH211821
And it says 11.x will only upgrade to enterprise version.
So how do I tell if the customer has the enterprise version?
The download says it is Symantec_Endpoint_Protection_12.1.4_MP1a.
Just to make sure before I tell them I can upgrade it and find out that I can't.
I have inculded a screen shot of the about for the 11.x version.
If you need anything else to answer this let me know.
Thanks
Mike
GUPs With Roaming Workstations
Yes, I've read this:
http://www.symantec.com/business/support/index?pag...
and this:
http://www.symantec.com/business/support/index?pag...
and the conflicting answers in this thread:
https://www-secure.symantec.com/connect/forums/exp...
However, I need someone to help me understand what this means from a policy and policy assignment perspective.
Think of the following scenario:
-1 data center with one SEPM
-20 remote facilities, each with 3 subnets and 1 GUP. Clients are NOT likely to be on the same subnet as the GUP (server subnet, wired workstation subnet, and wireless subnet at each location)
-All workstation clients are free to move between any facility at any time
Ultimately my questions:
1. Can I create one universal Live Update policy where I use the Multiple Group Update Provider list to define all of my GUP servers and then configure the Explicit Group Update Providers list to define my subnets and their mapping?
2. If I'm misunderstanding this, what's the best way to create and assign LU policies for clients so they always use the nearest GUP? What does this mean to my SEPM client structure where I basically just have a Workstations and Servers group structure? Trying to group ultra-mobile devices into static groups is not desirable.
Endpoint security options for MS Multipoint Server 2012
We have a computer lab that we will be upgrading to Microsoft Multipoint Server 2012 Premium edition. Single 64 bit server with 10 thin clients directly connected and we are needing an endpoint soilution.
We have looked at Symantec Endpoint Protection Small Business Edition 2013, Protection for 1 Endpoint as a potential solution and would like to get some feedback on this combination. Is anyone using both of these products together and what has beenb your experience? Thanks for your assistance
Deployment Status: The client decided to accept the upgrade package - log file diagnosis please?
I am finding two SEP_INST.LOG files on this PC
I am upgrading this machine from 12.1.1101.401.105 to 12.1.4013.4013
this is the log file in the C:\windows\temp
the other (not included) is under a users profile in local settings temp folder
Can someone tell me why the machine hasn't upgraded automatically yet?
package without defintion
How do i create the unmanage package where defintion not included?
sep - 12.1.2
Sylink for change
Few of the clients are not reporting to manager, i have change the communicaton file of 2 systems then client will online and report to manager again.
How can i replace it in bulk?
SEP DB Migration - Error 11504
I hate to post this when the error code is obvious but I'm running out of ideas.
I'm at the step in Management Server Configuration Wizard to specify the parameters for EXISTING Microsoft SQL Server database. And getting error 11504, which is pointing to a credentials issue.
Would appreciate other ideas as to what I might be missing here.
Last SAV Client is putting up a fight, here is what I am getting with the CleanWipe
09:56:53 INFO Initializing removal engine...
09:56:53 INFO Engine version: 12.1.4100.4126
09:56:53 INFO Engine initalized succesfully.
09:56:53 INFO [1/22]: Scanning Windows Installer cache
09:56:59 INFO [2/22]: Collecting product information
09:57:00 INFO [3/22]: Processing collected information
09:57:00 INFO [4/22]: Preparing to remove products
09:57:00 INFO [5/22]: Unregistering products from Windows Installer database
09:57:00 INFO [6/22]: Stopping LiveUpdate
09:57:00 INFO [7/22]: Stopping and removing services
09:57:00 WARN Unable to reset service DACL. SetNamedSecurityInfo failed. Error code: 0 (0x0): The operation completed successfully.
09:57:00 WARN Exception caught: QueryServiceStatusEx failed. Error code: 2 (0x2): The system cannot find the file specified.
09:57:07 WARN Teefer uninstaller returned 4. See teeferInstall.log for details.
09:57:07 INFO [8/22]: Unregistering EventLog sources
09:57:07 INFO [9/22]: Disabling startup items
09:57:07 INFO [10/22]: Verifying whether a reboot is required
09:57:37 ERROR Failed to initialize SEPRemovalToolNative. WaitForSingleObject returned 258. Last error: 0. Check C:\WINDOWS\Temp\CleanWipe_201405010956315\SepRemovalToolNative_x86.log file.
virus infection
Internet system is infected with virus and antivirus not clean it properly, please help.
SEP clients showing Out-of- Date
Hi
Need to know reason behind why SEP clients showing Out-of-date
Regards
single package
How do i create the single package for both 32 and 64 bit OS so not be confused when deploying on clients?
Set display filter for computer without antivirus?
Hi,
I just stumbled upon this option in SEPM and was wondering how this works and where do i see the computers installed in the network without antivirus software on it. How different is this from unmanaged detector?
SEPM-> Clients-> Client group-> tasks-> Set display filter
Need to block FileTransfer to Android Device
Dear All,
I have created a Policy in SEPM which blocks all mass storage devices( Enclosed the policy backup with this Thread). With this policy in place for an client machine, I am able to transfer files to and fro between Android Device and Computer. And also I found that the device listing under Portable Devices.
Kindly help me in creating a Policy in SEPM so that it blocks the Android Devices as well.
Sathish
12.1.3 SEPM policy not getting updated on 12.1.1 clients
Hello Folks:
I've an issue with the process exclusion policy which I created for endpoints. My SEPM is 12.1.3 & few of my clients are running on 12.1.1 & 11.x version. The issue is with the older version clients where this policy is not working. Any suggestions ?