Quantcast
Channel: Symantec Connect - Endpoint Protection - Discussions
Viewing all 10484 articles
Browse latest View live

Windows hot keys blocking

$
0
0
I need a solution

How to block windows hot keys by using sepm(windows+r etc)?

0

Right click block

$
0
0
I need a solution

Is it possible to block right click(Mouse) by using sepm?

0

Windows can not be updated with SCCM while Symantec 14.2 is installed.

$
0
0
I need a solution

Hello,

We Have different versios of Windows like 1507, 1511, 1607, 1703 and 1709.

We want to upgrade all version to 1709 or 1803 using SCCM.

But;

1-If the client has no SEP installed we get success.

2-If the client has the latest version of SEP installed the task (1709 installation) fails with SCCM.

3-If we use the clean / wipe tool of Symantec, The installation succeed.

4-If the client has the latest version of SEP installed the task succeed with "Check For update" (Windows Creator/Windows Update)

We did all test on a new operating system so the client does not have the oldest version. We have 700 clients because of that any ideas on how to get updates with SCCM? 

Thanks & regards.

0

SEP 14.1 client not connecting to SEPM

$
0
0
I need a solution

Hi all,

SEP clients are cannot connecting to SEPM.

Shows below error SEPM ersecreg.log

07/17 08:43:10 [376:4180] 4 Bad format.

07/17 08:43:10 [376:4180] IP address--FAILED.

0
1531877096

Java removed during SEP client installation process?

$
0
0
I need a solution

My team and I are in the process of creating a uninstall/install package of our current AV(ESET) and install of SEP 14.2. We've noticed our uninstall/install package which includes Symantec's third party AV remover + SEP Client 14.2 for Windows64bit also removes Java...other programs we've noticed that have been removed (winPcap, irfanview). 

We've narrowed it down to the third party AV remover as the culprite deleting Java but we're not sure if this is configurable. We have memory exploit mitigration to log-only and have vanilla-out-of-the-box policies applied to the group the client installer sends new clients to. What's also strange is that we have quarantines/blocks from Symantec to show notifications of actions but the removal of Java is completely silent and gets rid of the whole file directory. We're in an environment with SAP and Java not being able to run is quite worrisome. 

Any advice/thoughts would be greatly appreciated. 

Log info: 

Mon Jul 16 17:26:02 2018 Unsupport Product: Vendor:Adobe Systems Inc., Name:Adobe Flash Player, Version:30.0.0.134, Product Category:WAAPI_CATEGORY_UNCLASSIFIED
Mon Jul 16 17:26:02 2018 Unsupport Product: Vendor:Microsoft Corporation, Name:Windows Update Agent, Version:10.0.17134.1, Product Category:WAAPI_CATEGORY_PATCH_MANAGEMENT
Mon Jul 16 17:26:02 2018 Unsupport Product: Vendor:Microsoft Corporation, Name:Windows VPN Client, Version:10.0.17134.1, Product Category:WAAPI_CATEGORY_VPN_CLIENT
Mon Jul 16 17:26:02 2018 Unsupport Product: Vendor:Microsoft Corporation, Name:Microsoft Publisher, Version:16.0.10228.20080, Product Category:WAAPI_CATEGORY_UNCLASSIFIED
Mon Jul 16 17:26:02 2018 Unsupport Product: Vendor:Microsoft Corporation, Name:Microsoft PowerPoint, Version:16.0.10228.20080, Product Category:WAAPI_CATEGORY_UNCLASSIFIED
Mon Jul 16 17:26:02 2018 Unsupport Product: Vendor:Microsoft Corporation, Name:Microsoft Outlook, Version:16.0.10228.20080, Product Category:WAAPI_CATEGORY_UNCLASSIFIED
Mon Jul 16 17:26:02 2018 Unsupport Product: Vendor:Microsoft Corporation, Name:Microsoft OneNote, Version:16.0.10228.20080, Product Category:WAAPI_CATEGORY_UNCLASSIFIED
Mon Jul 16 17:26:02 2018 Unsupport Product: Vendor:Microsoft Corporation, Name:Microsoft Excel, Version:16.0.10228.20080, Product Category:WAAPI_CATEGORY_UNCLASSIFIED
Mon Jul 16 17:26:02 2018 Unsupport Product: Vendor:Microsoft Corporation, Name:Microsoft Word, Version:16.0.10228.20080, Product Category:WAAPI_CATEGORY_UNCLASSIFIED
Mon Jul 16 17:26:25 2018 Success removed Product: Vendor:Oracle Corporation, Name:Java, Version:8.0.1710.11, Product Category:WAAPI_CATEGORY_UNCLASSIFIED

0

Feedback on SQL database Cluster

$
0
0
I need a solution

Hi,

We are re-thinking our SEP management infrastructure and we are considering setting up a SQL database Cluster as the backend SEP site database.

We have noticed that the document "Symantec™ Endpoint Protection 14 Sizing and Scalability Best Practices White Paper" mentionned using database cluster but we cannot find anymore information about it.

Anyone have any feedback on using SQL database Cluster with SEPM, any limitations or problems ?

Thanks in advance !

0

Can manager send the .csv file from logs automatically

$
0
0
I need a solution

Hi All,

We are trying to automate the reporting part for symantec. We are trying to see if there is a way for the manager to send the .csv file to system admins.

I have attached the criteria that we are looking for. Please let me know if there is a way for the manager to email this with our manual intervension.

0
1531841457

[ SEP ] "Memory Exploit Mitigation is not functioning" not working

$
0
0
I need a solution

Hello,

I got the following message on SEP endpoint.

What could be the cause of this problem?

I'm not able to analyze logs now, but anyone knows a fast and rapid workaround (No KB found either).

0

7/17/18 64-bit Virus Defs Not Available

$
0
0
I need a solution

Is it just me or has anyone else noticed that there's no regular (i.e. not reduced) 64-bit virus definitions available right now in your SEPM?  I tried downloading again but no change.

0

Upgrade Endpoint Protection Manager

$
0
0
I need a solution

What are the steps that I need to take to upgrade Endpoint Protection Manager on Server 2008 & 2012 from 14.0 to 14.2.  Is it a seamless upgrade?  Are all policesc, etc. retained. I have 16 campuses that need upgrading and want to make sure that the upgrade goes smoothly.

Thanks

AJW

0

AutoUpgrade not work on some computers (14.2)

$
0
0
I do not need a solution (just sharing information)

Hello. I upgrade the Symantec Endpoint Protection clients (12.1.6;14.01) to 14.2 version. I use AutoUpgrade feature - assign client packages to groups in the manager console. Source set to "management server". Scheduler time unset, and set "0 days". On some computers, AutoUpgrade does not work. Where can I see the installation logs for the AutoUpgrade task ?

0

Installing SEPM to handle 2600 clients

$
0
0
I need a solution

I am installing SEPM on a server to manage 2600 clients.i need a little help with installation.which database should i use: the Default embedded database or Microsoft SQL server database?

0

SEP Causing Extremely Slow Logon after Windows Updates - lsass.exe Local Security Authority

$
0
0
I need a solution

Hello everyone,

Our network is currently running mainly Windows 7 computers with about 5 Windows 10 (which do not experience this issue).

Our DC is a virtual server running Server 2008 Standard 32-bit - being hosted by a Windows 2012 server

We have recently upgraded from WebRoot to Symantec, and since installing Symantec (14.0 RU1 MP2) we have had major issues every Weds & Thurs after normal Window Updates. I should state that we currently are running SEP unmanaged as our server was apparently set up as 32-bit, and we were unaware of that after our previous managed-service IT company split. So limping along until we can switch out our servers, we have been dealing with all the pop-ups everytime something changes. 

The main issue though, is after our computers install updates and are logging in again, they just sit and spin at the welcome screen for anywhere from 2-10 minutes; usually at least 5 minutes! It is not finalizing updates or anything (at least it doesn't show that on the screen, just the welcome screen and the blue spinning circle). Once it is finally done loading, the computer shows a black screen with the SEP pop-up stating that Local Security Authority (lsass.exe) has changed, blah blah blah. This is always the routine, and even adding the "lsass.exe" to the security exception did not help. 

I've read all sorts of "hotfixes" for windows and such, but I am very skeptical to install any of them, as it seems to be a SEP issue rather than a standalone windows issue. Has anyone experienced this, or have any ideas to test?

P.S. - I have tried a suggested hotfix for SEP 14.X that says to disable the popups on unmanged clients, to disable and then re-enable network monitoring, and I have had the same problems with that hotfix, the SEP pop-ups change to Windows Notifications that are constant (1-2x per minute) that svchost.exe and a few other things are trying to access the internet. So we uninstalled SEP and reinstalled to get back to our normal SEP popup issue as they are a lot less frequent. Worth noting that we did not leave SEP running with the hotfix long enough to see if that remedied our lsass.exe issue, it was too much to deal with multiple notifications every minute of the day, very interuptive for our typists / data entry positions.

0

After updating to sep 14.2 on windows 10 clients with hyper-v, the command connect on the managment consol of hyper-v no longer works

$
0
0
I need a solution

Summarize the situation.

Windows 10 with virtual machines hiper-v and sep 14.0.3876 everything works regularly.

After upgrading to SEP 14.2.758, if a connection is initiated, from the hyper-v virtual machine management console, nothing is displayed .

If you run c: \ windows \ system32 \ vmconnect.exe instead, the virtual machine is displayed correctly.
 

I tried to disable all features of Sep 14.2 but the problem persists.

If I uninstall sep 14.2 and reinstall a previous version, everything goes back to working

0

SEP Disabled Endpoints

$
0
0
I need a solution

Our SEP Manager is showing 3 different desktops as disabled endpoints, and none of them are able to do LiveUpdates, as the option is greyed out on the status screen. However, under clients tab I can find all 3 of them as being managed, online and up-to-date with their protections. Does anyone know why this would be the case? As far as being able to perform LiveUpdates, is there a command I could run that would help?

Thanks in advance

0

SEP 14 Upgrade Benefits

$
0
0
I need a solution

Hey People..

Im looking for some business benefits that I can exhibit for SEP 14 upgrade from Sep 12. I have afew points pulled from SEP14 whats' new article.. but looking for something that might help the higher management.

Any suggestions/Ideas will really help me! TIA

0

proactive threat protection and network threat protection not updating from manager

$
0
0
I need a solution

Hi,

I am using Endpint Protection manager 12.1.67

My clients not updating PTP and NTP automatically from server, but Virus and spyware protection updates without any problem. This is a closed network and not connected to internet. I downloads all the three jdb file and updates manager regularly. Now, for PTP and NTP I download the .exe file and manually updates all clients.

Suggest some solution.

Sajith

0

Alert for : Malicious traffic blocked: Web Attack: Fake TechSupport Domains 2

$
0
0
I need a solution

Hi Team,

We are using 14.0.3929 verion in our environment along with ATP version  3.1.0-678 . From the last couple of days we are getting this alert in ATP:
 

2018-07-18 14:21:59 UTC
4124: Endpoint (IP/URL/Domain) Detection

Malicious traffic blocked: Web Attack: Fake TechSupport Domains 2

    app_name   
    C:/PROGRAM FILES/INTERNET EXPLORER/IEXPLORE.EXE
    categories   
    Attack
    data_source_url_domain   
    172.*.*.*
    deepsight_domain   
    notavailable
    description   
    Malicious traffic blocked: Web Attack: Fake TechSupport Domains 2
    device_ip   
    172.*>*>*
    device_name   hostname
    device_time   
    2018-07-18 14:21:59 UTC
    device_uid   
    39c4147
    domain_name   abc
    event_desc   
    [SID: 30529] Web Attack: Fake TechSupport Domains 2 attack blocked. Traffic has been blocked for this application: C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
    event_id   
    206: Intrusion detected
    external_ip   
    172*>*>*
    host_name   hostname
    infected   
    false
    intrusion_url   
    www.bing.comwww.bing.com:443
    local_host_mac   
    000000000000
    log_time   
    2018-07-18 14:25:06 UTC
    network_protocol   
    2: TCP
    remote_host_mac   
    000000000000
    severity   
    3: Critical
    sid   
    30529
    signature_id   
    30529
    signature_name   
    Web Attack: Fake TechSupport Domains 2
    symc_device_action   
    1: Blocked
    time   
    2018-07-18 14:21:59 UTC
    timezone   
    UTC
    traffic_direction   
    1: Inbound
    type_id   
    4124: Endpoint (IP/URL/Domain) Detection
    user_name   
    60891

    Could you please explain what this attack actually means? Bing.com is blocked already in this environment . 

    Regards,
    Jagadeesh

    0

    I need the symantec Endpoint protection installer

    $
    0
    0
    I need a solution

    I need a symantec Endpoint protection installer and can you give me a link to download it

    0

    Failed to authenticate with the proxy server

    $
    0
    0
    I need a solution

    Hi Team,

    We see that when the files are getting submitted from the client machine, its reaching proxy.
    However in our environment we have ATP and the files are ideally supposed to go to ATP without the 
    need of goin to proxy. Here is the error:

     Submitting file to Symantec failed.  File : 'D:\CB all Soft\CANOSCAN 110\MSETUP4.EXE'. Network 
    error : 'HTTP Error 407. Failed to authenticate with the proxy server using supplied credentials. 
    Please verify username/password are correct.'.

    Also please help us understand the flow of suspected file submission , since it just says 
    submitting file to symantec we are unsure if it means symantec ATP or Symantec site

    Plkease find the screenshot for more referance .

    0
    Viewing all 10484 articles
    Browse latest View live


    <script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>