How to block windows hot keys by using sepm(windows+r etc)?
Windows hot keys blocking
Right click block
Is it possible to block right click(Mouse) by using sepm?
Windows can not be updated with SCCM while Symantec 14.2 is installed.
Hello,
We Have different versios of Windows like 1507, 1511, 1607, 1703 and 1709.
We want to upgrade all version to 1709 or 1803 using SCCM.
But;
1-If the client has no SEP installed we get success.
2-If the client has the latest version of SEP installed the task (1709 installation) fails with SCCM.
3-If we use the clean / wipe tool of Symantec, The installation succeed.
4-If the client has the latest version of SEP installed the task succeed with "Check For update" (Windows Creator/Windows Update)
We did all test on a new operating system so the client does not have the oldest version. We have 700 clients because of that any ideas on how to get updates with SCCM?
Thanks & regards.
SEP 14.1 client not connecting to SEPM
Hi all,
SEP clients are cannot connecting to SEPM.
Shows below error SEPM ersecreg.log
07/17 08:43:10 [376:4180] 4 Bad format.
07/17 08:43:10 [376:4180] IP address--FAILED.
Java removed during SEP client installation process?
My team and I are in the process of creating a uninstall/install package of our current AV(ESET) and install of SEP 14.2. We've noticed our uninstall/install package which includes Symantec's third party AV remover + SEP Client 14.2 for Windows64bit also removes Java...other programs we've noticed that have been removed (winPcap, irfanview).
We've narrowed it down to the third party AV remover as the culprite deleting Java but we're not sure if this is configurable. We have memory exploit mitigration to log-only and have vanilla-out-of-the-box policies applied to the group the client installer sends new clients to. What's also strange is that we have quarantines/blocks from Symantec to show notifications of actions but the removal of Java is completely silent and gets rid of the whole file directory. We're in an environment with SAP and Java not being able to run is quite worrisome.
Any advice/thoughts would be greatly appreciated.
Log info:
Mon Jul 16 17:26:02 2018 Unsupport Product: Vendor:Adobe Systems Inc., Name:Adobe Flash Player, Version:30.0.0.134, Product Category:WAAPI_CATEGORY_UNCLASSIFIED
Mon Jul 16 17:26:02 2018 Unsupport Product: Vendor:Microsoft Corporation, Name:Windows Update Agent, Version:10.0.17134.1, Product Category:WAAPI_CATEGORY_PATCH_MANAGEMENT
Mon Jul 16 17:26:02 2018 Unsupport Product: Vendor:Microsoft Corporation, Name:Windows VPN Client, Version:10.0.17134.1, Product Category:WAAPI_CATEGORY_VPN_CLIENT
Mon Jul 16 17:26:02 2018 Unsupport Product: Vendor:Microsoft Corporation, Name:Microsoft Publisher, Version:16.0.10228.20080, Product Category:WAAPI_CATEGORY_UNCLASSIFIED
Mon Jul 16 17:26:02 2018 Unsupport Product: Vendor:Microsoft Corporation, Name:Microsoft PowerPoint, Version:16.0.10228.20080, Product Category:WAAPI_CATEGORY_UNCLASSIFIED
Mon Jul 16 17:26:02 2018 Unsupport Product: Vendor:Microsoft Corporation, Name:Microsoft Outlook, Version:16.0.10228.20080, Product Category:WAAPI_CATEGORY_UNCLASSIFIED
Mon Jul 16 17:26:02 2018 Unsupport Product: Vendor:Microsoft Corporation, Name:Microsoft OneNote, Version:16.0.10228.20080, Product Category:WAAPI_CATEGORY_UNCLASSIFIED
Mon Jul 16 17:26:02 2018 Unsupport Product: Vendor:Microsoft Corporation, Name:Microsoft Excel, Version:16.0.10228.20080, Product Category:WAAPI_CATEGORY_UNCLASSIFIED
Mon Jul 16 17:26:02 2018 Unsupport Product: Vendor:Microsoft Corporation, Name:Microsoft Word, Version:16.0.10228.20080, Product Category:WAAPI_CATEGORY_UNCLASSIFIED
Mon Jul 16 17:26:25 2018 Success removed Product: Vendor:Oracle Corporation, Name:Java, Version:8.0.1710.11, Product Category:WAAPI_CATEGORY_UNCLASSIFIED
Feedback on SQL database Cluster
Hi,
We are re-thinking our SEP management infrastructure and we are considering setting up a SQL database Cluster as the backend SEP site database.
We have noticed that the document "Symantec™ Endpoint Protection 14 Sizing and Scalability Best Practices White Paper" mentionned using database cluster but we cannot find anymore information about it.
Anyone have any feedback on using SQL database Cluster with SEPM, any limitations or problems ?
Thanks in advance !
Can manager send the .csv file from logs automatically
Hi All,
We are trying to automate the reporting part for symantec. We are trying to see if there is a way for the manager to send the .csv file to system admins.
I have attached the criteria that we are looking for. Please let me know if there is a way for the manager to email this with our manual intervension.
[ SEP ] "Memory Exploit Mitigation is not functioning" not working
Hello,
I got the following message on SEP endpoint.
What could be the cause of this problem?
I'm not able to analyze logs now, but anyone knows a fast and rapid workaround (No KB found either).
7/17/18 64-bit Virus Defs Not Available
Is it just me or has anyone else noticed that there's no regular (i.e. not reduced) 64-bit virus definitions available right now in your SEPM? I tried downloading again but no change.
Upgrade Endpoint Protection Manager
What are the steps that I need to take to upgrade Endpoint Protection Manager on Server 2008 & 2012 from 14.0 to 14.2. Is it a seamless upgrade? Are all policesc, etc. retained. I have 16 campuses that need upgrading and want to make sure that the upgrade goes smoothly.
Thanks
AJW
AutoUpgrade not work on some computers (14.2)
Hello. I upgrade the Symantec Endpoint Protection clients (12.1.6;14.01) to 14.2 version. I use AutoUpgrade feature - assign client packages to groups in the manager console. Source set to "management server". Scheduler time unset, and set "0 days". On some computers, AutoUpgrade does not work. Where can I see the installation logs for the AutoUpgrade task ?
Installing SEPM to handle 2600 clients
I am installing SEPM on a server to manage 2600 clients.i need a little help with installation.which database should i use: the Default embedded database or Microsoft SQL server database?
SEP Causing Extremely Slow Logon after Windows Updates - lsass.exe Local Security Authority
Hello everyone,
Our network is currently running mainly Windows 7 computers with about 5 Windows 10 (which do not experience this issue).
Our DC is a virtual server running Server 2008 Standard 32-bit - being hosted by a Windows 2012 server
We have recently upgraded from WebRoot to Symantec, and since installing Symantec (14.0 RU1 MP2) we have had major issues every Weds & Thurs after normal Window Updates. I should state that we currently are running SEP unmanaged as our server was apparently set up as 32-bit, and we were unaware of that after our previous managed-service IT company split. So limping along until we can switch out our servers, we have been dealing with all the pop-ups everytime something changes.
The main issue though, is after our computers install updates and are logging in again, they just sit and spin at the welcome screen for anywhere from 2-10 minutes; usually at least 5 minutes! It is not finalizing updates or anything (at least it doesn't show that on the screen, just the welcome screen and the blue spinning circle). Once it is finally done loading, the computer shows a black screen with the SEP pop-up stating that Local Security Authority (lsass.exe) has changed, blah blah blah. This is always the routine, and even adding the "lsass.exe" to the security exception did not help.
I've read all sorts of "hotfixes" for windows and such, but I am very skeptical to install any of them, as it seems to be a SEP issue rather than a standalone windows issue. Has anyone experienced this, or have any ideas to test?
P.S. - I have tried a suggested hotfix for SEP 14.X that says to disable the popups on unmanged clients, to disable and then re-enable network monitoring, and I have had the same problems with that hotfix, the SEP pop-ups change to Windows Notifications that are constant (1-2x per minute) that svchost.exe and a few other things are trying to access the internet. So we uninstalled SEP and reinstalled to get back to our normal SEP popup issue as they are a lot less frequent. Worth noting that we did not leave SEP running with the hotfix long enough to see if that remedied our lsass.exe issue, it was too much to deal with multiple notifications every minute of the day, very interuptive for our typists / data entry positions.
After updating to sep 14.2 on windows 10 clients with hyper-v, the command connect on the managment consol of hyper-v no longer works
Summarize the situation.
Windows 10 with virtual machines hiper-v and sep 14.0.3876 everything works regularly.
After upgrading to SEP 14.2.758, if a connection is initiated, from the hyper-v virtual machine management console, nothing is displayed .
If you run c: \ windows \ system32 \ vmconnect.exe instead, the virtual machine is displayed correctly.
I tried to disable all features of Sep 14.2 but the problem persists.
If I uninstall sep 14.2 and reinstall a previous version, everything goes back to working
SEP Disabled Endpoints
Our SEP Manager is showing 3 different desktops as disabled endpoints, and none of them are able to do LiveUpdates, as the option is greyed out on the status screen. However, under clients tab I can find all 3 of them as being managed, online and up-to-date with their protections. Does anyone know why this would be the case? As far as being able to perform LiveUpdates, is there a command I could run that would help?
Thanks in advance
SEP 14 Upgrade Benefits
Hey People..
Im looking for some business benefits that I can exhibit for SEP 14 upgrade from Sep 12. I have afew points pulled from SEP14 whats' new article.. but looking for something that might help the higher management.
Any suggestions/Ideas will really help me! TIA
proactive threat protection and network threat protection not updating from manager
Hi,
I am using Endpint Protection manager 12.1.67
My clients not updating PTP and NTP automatically from server, but Virus and spyware protection updates without any problem. This is a closed network and not connected to internet. I downloads all the three jdb file and updates manager regularly. Now, for PTP and NTP I download the .exe file and manually updates all clients.
Suggest some solution.
Sajith
Alert for : Malicious traffic blocked: Web Attack: Fake TechSupport Domains 2
Hi Team,
We are using 14.0.3929 verion in our environment along with ATP version 3.1.0-678 . From the last couple of days we are getting this alert in ATP:
2018-07-18 14:21:59 UTC | 4124: Endpoint (IP/URL/Domain) Detection | Malicious traffic blocked: Web Attack: Fake TechSupport Domains 2 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Could you please explain what this attack actually means? Bing.com is blocked already in this environment .
Regards,
Jagadeesh
I need the symantec Endpoint protection installer
I need a symantec Endpoint protection installer and can you give me a link to download it
Failed to authenticate with the proxy server
Hi Team,
We see that when the files are getting submitted from the client machine, its reaching proxy.
However in our environment we have ATP and the files are ideally supposed to go to ATP without the
need of goin to proxy. Here is the error:
Submitting file to Symantec failed. File : 'D:\CB all Soft\CANOSCAN 110\MSETUP4.EXE'. Network
error : 'HTTP Error 407. Failed to authenticate with the proxy server using supplied credentials.
Please verify username/password are correct.'.
Also please help us understand the flow of suspected file submission , since it just says
submitting file to symantec we are unsure if it means symantec ATP or Symantec site
Plkease find the screenshot for more referance .