Would someone be able to tell me how to download the resetpass.bat file for password resets in v14.0 MP2?
Password Reset
It Analytics StandAlone Cube from Sep
Hello,
Already have install a It Analytics StandAlone Pack for DLP 14 and I like to have the "Cube" from Sepm 14, Its possible to obtain this from import the zip files in the same console and later combine some reports?
My scope of version beginning with 12.1 a 14
Regards
Miguel Angel
SEPM 14.2 - Daily Status report not displaying systems in virus def distribution in email attachment.
After upgrading to 14.2 the daily status report no longer shows systems when expanded in the emailed version on the virus definition distribution. The systems are visible when the report is run locally on the admin console.
I have run the report locally.
Recreated the same scheduled report with the same results
Tried to open the open the emailed HTML file in Chrome and IE on Windows 10 and Windows 7
I have attached screenshots of the emailed html file and the server generated report.
Has anyone else seen this issue or found a fix? I am unable to find a technical article regarding this exact issue.
symantec endpoint 14.0 MP2 blocked download address list of MS Outlook 2016
i have and issue with all pc have symantec , i cannot download address list from email server to my outlook . i try another pc no have antivirus software is ok .
Please help me to fix it.
Thanks !
SEPM 14.2 - Error when trying to connect to AD servers over Secure Connection
Hi!
I try to use Directory Servers synchronisation to use my AD account for SEPM.
It's working OK only over unsecure connection. When I check "Use Secure Connection" I got error:
Server AD has open 636 port.
Symantec client blocking update of Windows 10
Hi,
Windows 10 clients need to be updated. Problem I am having is that Symantec client 14.2.0 is blocking the update. 1 person uninstalled the client so that the updates in installed. Today I stopped Symantec client smc -stop then updates were installed. Please help.
Thanks
New version of CleanWipe
Hello.
I want to uninstall a client using CleanWipe, which I am downloading from here: https://support.symantec.com/en_US/article.HOWTO12...
The problem is that my client version is 14.2.770 and CleanWipe is 14.2.760 and I cannot do it this way.
Can someone tell me when can I expect the new version of this utility?
Will Endpoint Protection work on Server 2003?
Hi,
I'm running Symantec Endpoint Protection Small Business Edition 14.2. I was wondering if this will work on my old 2003 Server until I'm able to migrate away from it? Thanks.
Symantec Endpoint Protection blocked Docker Community installer for Windows 10 Pro operating System
Hi
I have Symantec Endpoint Protection installed on my Windows 10 pro. When I am trying to install Docker Community Edition its been blocked and deleted from my system.
Can someone provide me a solution on this ?
Thanks
SEP 14.2 MSI command line reference - extended options?
Hello all,
Having recently joined the SEP userbase, I'm trying to automate installs and updates as much as possible.
Unfortnately we are not currently in position currently to push use SEPM, but with some major network overhauls on the horizon, I do see us using it eventually.
I've been referencing this TECH doc: https://support.symantec.com/en_US/article.TECH102668.html
- also I've adapted some portions from other discussions I've seen on this forum.
This is my current setAid.ini:
; NOTE: Do not edit the config below
[PREDEFINED_SMC_CONFIG]
AppType=105
VendorID=4096
PlatformType=WIN64BIT
PackageChecksum=cb6a907f5bdc7e9e3ef0383d31fc99bd
; User configureable options
[CUSTOM_SMC_CONFIG]
InstallNewInstanceOnly=0
InstallUserInterfaceLevel=s
KeepPreviousSetting=1
InstallationLogDir=C:\Logs\SEP14.2.770-silentinstall.LOG
DestinationDirectory=
LaunchIt=1
AddProgramIntoStartMenu=1
OptOutRepSubmission=1
UIRebootMode=0
ReducedSize=0
PromptType=SNOOZE
RebootMinutes=180
HardReboot=false
AutoReboot=false
RebootRandomize=true
RebootRandomizeHours=2
RebootMethod=NONE
SnoozeInterval=60
RebootDay=TODAY
RebootDisplayTimeout=60
Countdown=5
RebootPromptUser=true
RebootPromptMessage=The Symantec Endpoint Protection installation requires this computer to restart.
RebootMaxSnoozeCount=3
RebootSchedule=LATER
[LU_CONFIG]
ServerProduct=SESM AntiVirus Client Win64
ServerLanguage=English
ServerVersion=14.2.770
SequenceNumber=0
ServerMoniker=
ClientProduct=SESC AntiVirus Client Win64
ClientLanguage=English
ClientVersion=14.2.770
ClientMoniker=
SequenceTag=PATCH
ShortName=spcAvClient64en_14_2
DisplayName=Symantec Endpoint Protection Win64 14.2.770.0000 (English)
Language=en_us
CONNECT_LU_SERVER=1
[FEATURE_SELECTION]
Core=1
SAVMain=1
Download=1
NotesSnapin=0
OutlookSnapin=1
Pop3Smtp=1
PTPMain=1
TruScan=1
DCMain=0
NTPMain=0
Firewall=0
ITPMain=0
LANG1033=1
Now here is where my questions begin.
- Using "KeepPreviousSetting=1" will preserve custom-configured scans?
- I can't seem to find reference to the option to specify Client Type? Standard/Embedded/Dark
- Will my "FEATURE_SELECTION" be adhered to even though the installer defaults to the "Typical" Installation, not "Custom" ?
- Setting "InstallUserInterfaceLevel=s" doesn't appear to have actually done anything. I'm still clicking through all of the same pages, except my features and other setttings are already populated. I assume changing to "InstallUserInterfaceLevel=u" should automate the entire process once I'm ready?
- Similar to "OptOutRepSubmission=1" is there an option to Opt-Out of the "Data Collection - Installation Options" ?
Thank you very much!
J
Network applications holding connections to network share
Running SEP 14.2.770.0000 on Windows 10 workstation. During software development programs are copied from local workstation to network share. Application is executed from network share. After program stops execution for about 5 min time frame new versions of the application cannot be copied to the network share. Something has the files (exe's and dll's) still locked up an in use.
Tried various exclusions. Tried Disabling SEP. Only un-installing the Endpoint Protection fixes the problem. What is holding a lock on the program, it seems that it SEP 14.2 but even with the program disabled we still have issue. SEP is only loaded on workstation and not on network server. We did not have issue with version 14.0.3.
use SEP 14 to block Network Access for Win10 1703 and older win10
Is there a way to use SEP 14 to block network access on Windows 10 1703 and older Windows 10 versions?
we have some win10 users who are dragging their feet on upgrading to Win10 1709 and so we want to see if we can use SEP14 to implement Firewall Rules or IPS or anything in SEP's arsenal to automatically block network access if the OS is Windows 10 1703 and older Win10 versions? and automatically unblock when Win10 1709 is installed?
Getting way more alerts- A high-risk intrusion was detected on Web server
Went from a few a week to hundreds in a week- see below- A high-risk intrusion was detected- on www Server Similar to below- many different exploits in attack sig- Has something changed with the Symantec software in the past couple of weeks that may have caused this? Is there a way to limit the alerts?
Attack: an intrusion attempt was blocked.
Blocked
Attack: D-Link DSL 2750B Arbitrary Command Execution
SYSTEM
192.168.0.x
80
Symantec touching files even with exclusions set?
We have an exclusion set for F:\Imagenow and all subdirectories in Endpoint Protection. I see the exclusion in HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Symantec\Symantec Endpoint Protection\AV\Exclusions\ScanningEngines\Directory\Admin. However, on the server we see ccSvcHst.exe (Symantec) touching a ton of files in the F:\Imagenow directory. Our onsite Symantec support tells us that "Symantec touches the files anyway even though the exclusion is set". It is using 4x the disk IO of our application! Is this statement correct or have they configured the exclusion wrong?
Boot. Malmo Virus detected but no action
Dear Team,
Boot.Malmo is detected but no action is taken by symantec ( left alone). Need your help please!!! Thanks in advance ...
SEP clients length of time to update Virus Definitions.
Hi All,
I was wondering how long it generally takes for new clients to download content from Group Update Providers.
I have installed new clients and it has been around 4 days where the logs show that the client has been downloading new content successfully. However, I still have the error indicating that the Virus Definitions are out of date on the SEPM and on the Client, it indicates that the Virus definitions are missing or corrupted. As indicated there are new installs and has so far happened on a number of PCs.
Can anyone assist?
Corey.
Symantec blocking printer
When i try to print something from mac machine its not getting printed. And cheked the traffic log in Sepm it shows outbound connection is getting blocked by block all ip traffic... i have 70 printer servers i will not be able to add all 70printer serer ip adress as exclusion wat can i do other than creating exception and exclude host
left alone and partially repaired
Dear Team,
IN our environment some clients not able to clear its showing left alone and partially repaired for this virus W32.Chir.B@mm and W32.SillyFDC still
please help me to resolve..
"Leave Alone" status on Mac malware/PUA
Hello all, I am recently using SEP in my work environment. Some MacOS machines have been hit by different malware and PUA strains that are detected by SEP, but when checking the logs, the vendor actions shows "Left alone". Is there any reason for this to happen? Is there any way, such as console configuration, to ensure this threats are properly detected/deleted/cleaned?
Very slow boot device control (block USB) on MAC
Hello all.
I have problem whith MAC devices. Very slow boot SEP on MAC devices and for this resason my users can get access for USB devices during 10-60 sec. from start OS. Can you help me with it ?