Dear Team,
Does symantec has a protection on malware variant known as TYPEFRAME
Malware Analysis Report (MAR)
Dear Team,
Does symantec has a protection on malware variant known as TYPEFRAME
Malware Analysis Report (MAR)
SEP 14.2 is now available
https://support.symantec.com/en_US/article.ALERT26...
Hi Team,
I have blocked the USB through Symantec Policy,but this Policy is not working on safe mode.
request you to provide any resolution or any workaround
Problem is that user login to safe mode and use the USB drives which is not permitted hence they might have infection.
Hi team,
I installed SEP to my computer for a time.
But I lost my SYMC Lic and don't know how to check from my computer the expiration date of SEP.
Please help me!
Thank you!
Hi All,
In my project we are currently using SEP 14.0.2415.0200. For the past 2-3 months we are encountering an issue that was never there before.
A few of the desktops are losing network connectivity after we install SEP in them. The network works fine up until SEP asks for restart (let's call it Re1) after the installation. After the installation the desktop stays on network for a few seconds and then the connectivity drops. We have to physically go the affected desktop and give a restart (let's call it Re2). After just 1 restart the desktop comes back on the network. One common thing i have observed in the affected desktops is this : After the SEP takes Re1 i will login into the the desktop and try to open SEP from start menu and it always gives the error saying symantec services cannot be started (attached the screenshot for that). After Re2 the same installation works like normal.
The issue is happening to a few desktops (say 2-3 out of 10). There is no recurring pattern here as well. Seems like a completely random thing that can happen to any desktop. We have tried installing symantec by manually logging into the desktop as well as tried installing it using PushDeploymentWizard. Tried taking new packages for SEP Client, still the same issue comes up.
We have not made any changes to the SEP server so i have no clue how this problem popped up. I have looked up this issue but the solutions are for Windows 10. This issue is becoming a nuance for us now because we used to push symantec and leave it to update overnight but now we do not have that peace of mind. I am worried this issue might spread to a point where we have to manually interfere in every SEP installation.
Kindly provide any solutions/inputs on this.
I installed the features of "Email Scans" and disabled (we intend to use it in the future).
When disabling, the problem message appears on the client. I do not want to show these messages to the client, how do I remove this type of notification?
Hello, all.
After trasfer SEPM to another server, GUPs stopped receiving updates.
Anyone is familiar with this problem?
Thanks in advance.
bonjour;
j'ai besoin d'un script pour désinstaller le client SEP 14MP1 via GPO, la désinstallation pour débloquer la mise à niveau des Système après je vais installer les clients de nouveau
Hi, I would like to know how much time it takes if there is update like new malware found or scan completed logs to be updated from client machine to SEP manager ? This needs to write a automation script. please help.
Hello!
We manage our Macs with the JAMF Casper Suite. Currently, we have some systems which are not updating their virus definitions. I was wondering if there is a definitive key, plist value, attribute, log string or some other data I can access, via command line, which would allow me to build smart computer group criteria in the JAMf server. This would allow us to identify all systems whose virus defs are not up to date which in turn would allow us to take remedial action through either self service or by launching Live Update remotely.
Thank you in advance for any assistance anyone may be able to provide.
I am running Windows 10 Pro, 64-bit OS, Version 1803 (OS build 17134.112) with SEP client 14.0.3929.1200.
The operating system has all current MS patches applied.
Yesterday, I downloaded Sep64_To_758_EN.zip and extracted the correct executable to upgrade my client.
The client was not upgraded.
I checked the installation files and discovered that the assumed language for the upgrade was Korean!
Perhaps the reason for the failure to upgrade was due to the presumed language (Korean) being inconsistent with my system (US English).
Someone should check to assure that the proper language version is associated with the upgrade file names.
Hello,
Currently i'm running SEPM 14(14 MP2) build 2415(14.0.2415.0200). How can i upgrade to the lates version of SEPM 14 ?
Hello All,
One my SEPM Data base is growing abrouptly,We have two SEPM consoles both are biderectional replication. We are facing issus in only one server data base.
\Program Files\Microsoft SQL Server\MSSQL12.SRVR8509\MSSQL\Data
COuld any one suggest me what action need to take on this.
Hi,
Over the weekend, I upgraded our SEPM from 14.0 RU1 MP2 to SEPM 14.2. Our server is a Hyper-V VM running W 2008R2. I noticed after the successful upgrade, some policies disappeared from our main group. This group uses customized non-shared policies. After the upgrade the non-shared policies Firewall, Intrusion Prevention, Application and Device Control, Memory Exploit Mitigation, and Exceptions were gone from the group. Any groups with shared policies were unaffected. I also noticed some the locked settings in the remaining policies were now unlocked. I created a checkpoint of the VM before the upgrade and was able to roll back to 14.0 RU1 MP2. I tried the upgrade multiple times with same results each time.
I looks like I will have to create new policies to replace the ones that disappeared. I validated the built-in db after the update and it passed validation. I have never seen this before after dozens of upgrades over the years. Can anyone offer an explanation?
Thanks,
CQ
bonjour;
j'ai besoin de désinstaller client Symantec nedpoint Protection 12.x avec un mot de passe oublié
Hello, We have a requirement to query Symantec DB using Microsoft SQL embedded database using remote. Hence I would like to have connection details like Port and Database name to connect from other application. This is purely required for Automation in our organization. Please help.
Hi There,
Please excuse me if this is posted in the wrong area, I found it difficult navigating these forums.
I am looking to get some assistance with SEP whitelisting. Our SEP administrator is on leave for 2 weeks unexpectantly and issues are now coming to me. I have basic knowledge of SEP so please excuse me if the terms I am using are not technically correct.
We have whitelisting enforced across our organistation on Windows 10. We have a user who has come back from 2 months annual leave with her machine being offline during that period. She has logged in this morning and SEP was blocking application execution on many Office products. She restarted her machine and now Windows will not boot. I have seen this before, SEP appears to block Windows from loading as the logs are full of entries relating to the OS.
I have placed the machine in "Audit Mode" and connected the machine to the LAN. However, the machine will still not boot and it's still blocking Windows from booting (checked SEP application logs). It appears that the client policy is not updating. Usually we would right click on the system tray icon and "Update Policy", however I obviously cannot get into Windows.
Is there anyway to force the client to update it's policy remotely? The machine is showing online in SEP and has been in Audit mode for more than 1 hour.
Thanks for your help,
Hi Guys
Does Symantec have an option on SEPM to remotely push install packages to Linux machines?
We're trying to install SEP clients on mutiple Linux machines.
Does anyone use a script or file script to install the packages on multiple linux machines?
Thanks
Hello,
Very soon i will upgrade my current SEPMs to 14.2 and im running 14.0.3897.1101
Are there any known issues to keep in mind? Or is the upgrade going smoothly?
Thanks,
LEVD
Upon manual scan the following log is produced:
"Jun 14 07:25:09 engs01 rtvscand: Could not scan 1 files inside /lib/firmware/vxge/X3fw-pxe.ncf due to extraction errors encountered by the Decomposer Engines."
The file permissions are ugo readable. (Though the error message does not suggest permissions anyway.)
This also occurs for "X3fw-pxe.ncf" in the same location. It occurs on four machines that I have scanned, which are all that I have tried.
Linux dist is Ubuntu 16.04.
This scan is done on behalf of a customer so I would like to be able to explain why its happening and, more importantly, that is not an issue or threat.
Thanks.