Symantec Security Response

Best practices information

Sat, 09/04/2010 - 07:43

I'm looking for best practices information for how to deploy SIM in my environment.  What things should I consider, in deploying SIM, I need anything and everything that could help me properly deploy SIM.  Thanks.

Gathering required information stage!!!!!!!

Sat, 09/04/2010 - 06:36

Hi

In one windows xp pc, I tried to install symantec endpoint protection client and it took a long time to cross the "Gathering required information" and after few hours it finished completely.

now i decided to uninstall and load the latest version but still it is the same symptom

Please figure out why it is taking so long time since we have to load the same in couple of pc's!

Swaminathan

Can't Login to SSIM Java Console using Client... Certificate error occured

Sat, 09/04/2010 - 05:17

Hi,

I have installed SSIM 4.7 on a machine and I was able to login to the web console successfully, but when I am trying to login to the Java console using SSIM Client.. Its showing me the following Error Message

Certificate error occured while trying to connect to the specified host.

avax.net.ssl.SSLHandshakeException: Remote host closed connection during handshake
 at com.sun.net.ssl.internal.ssl.SSLSocketImpl.readRecord(Unknown Source)
 at com.sun.net.ssl.internal.ssl.SSLSocketImpl.performInitialHandshake(Unknown Source)
 at com.sun.net.ssl.internal.ssl.SSLSocketImpl.startHandshake(Unknown Source)
 at com.sun.net.ssl.internal.ssl.SSLSocketImpl.startHandshake(Unknown Source)
 at sun.net.www.protocol.https.HttpsClient.afterConnect(Unknown Source)
 at sun.net.www.protocol.https.AbstractDelegateHttpsURLConnection.connect(Unknown Source)
 at sun.net.www.protocol.https.HttpsURLConnectionImpl.connect(Unknown Source)
 at com.symantec.sim.app.SimApplication.validateIP(SimApplication.java:907)
 at com.symantec.sim.app.SimApplication$2.construct(SimApplication.java:637)
 at com.symantec.sim.uilib.util.SwingWorker$2.run(SwingWorker.java:176)
 at java.lang.Thread.run(Unknown Source)
Caused by: java.io.EOFException: SSL peer shut down incorrectly
 at com.sun.net.ssl.internal.ssl.InputRecord.read(Unknown Source)
 ... 11 more

I have gone through a process mentioned in the Connect article "Can't log into SSIM after 4.6.2 upgrade" and I have tried doing the same.. But still I am getting the same error..

I am trying to trouble shoot this issue since 2 days.. but No Luck.. Please help me in resolving this Issue.

Thanks in Anticipation...

Regards,
Naresh

SEP installed to windows 7 64bit. No right click to Scan USB or HD

Sat, 09/04/2010 - 03:14

How can I enabled the right click button to scan my usb in a fastest way?

Excluding a particular day in scheduled daily scan

Sat, 09/04/2010 - 00:43

We have installed Endpoint RU5 and we have set the scanning schedule as  active scan from Monday  to Friday and FULL scan on Saturday. But on saturdays i have to go to  the console and untick the daily scan otherwise both scans run. Any method to exclude Saturday & Sunday from Daily scan 

how to create rule for subject block

Fri, 09/03/2010 - 23:52

how to create rule for subject block with word containing only ecard for incoming mails in Symantec brightmail Filter

4444931 1283589944

Cannot Install SEP Small Business Edition 12.0 on Windows SBS 2008 64-Bit

Fri, 09/03/2010 - 17:40

Greetings to all,

I received Symantec Endpoint Protection Small Business Edition 12.0 from a network service company that is contracted with my place of business.  This company is essentially the ISP, providing email services, databases, software and additional support. 

The installation files that I have received are only for unmanaged SEP Small Business Edition clients.  This is an entirely separate, additional issue and a discussion on this has been posted in the appropriate sections (Features, Install, Licensing, Security) of this SEP Small Business Edition forum.  Nonehtless, these files seem to be only for 32-bit architecture.

For example, when I attempt to install SEP Small Business Edition 12.0 as an unmanaged client install on Windows Small Business Server 2008 (64-bit), I receive an error message indicating that the version of Windows is not supported.  Additionally, the message also references 32-bit.  I apologize for not having the exact message at this time, but I am not at the office right now.  I can, however, update this pertinent information.

Is there an SEP Small Business Edition 12.0 64-bit version?

Are the installation files for 64-bit computing installations available to download?

Any and all assistance that could be provided is greatly appreciated.  Thanks to all for taking the time to read this discussion post.  Hope to hear from you soon!

-Steve

No SEP Management Console Feature - Not Licensed For Use?

Fri, 09/03/2010 - 17:23

Greetings to all,

I received Symantec Endpoint Protection Small Business Edition 12.0 from a network service company that is contracted with my place of business.  This company is essentially the ISP, providing email services, databases, software and additional support. 

The installation files that I have received are only for unmanaged SEP Small Business Edition clients.  Upon request of the SEP Management Console installation files, I was told that they were not available because they were not aquired with the purchased license agreement.  However, through much research and observed advertising, I can only conclude that the SEP Management Console is in fact apart of the Symantec Endpoint Protection Small Business Edition 12.0 software.

Does Symantec issue different license agreements for unmanaged client installations only?

Is it possible to download these SEP Management Console files from a Symantec FTP location? 

Any assistance that can be provided is greatly appreciated.  Thank you for taking the time to review my posting and inquiries.

-Steve

Does SAV 10 need Browser service? Does SEP?

Fri, 09/03/2010 - 14:01

We are currently in the process of moving from SAV 10.1.8 to SEP 11.6.  In the middle of this transition, our management is hoping to drop WINS support on our network.  I'm wondering if this will create any issues for us.

I'm told that SAV depends on the browser service to support the connection between clients and servers.  Is this true?  If so, what (if anything) will continue to work, and what will fail, if the browser service no longer works.

Presumably SEP does rely on the browser service.  But I'd like to confirm that.

Does SAV 10 need Browser service? Does SEP?

Fri, 09/03/2010 - 14:01

We are currently in the process of moving from SAV 10.1.8 to SEP 11.6.  In the middle of this transition, our management is hoping to drop WINS support on our network.  I'm wondering if this will create any issues for us.

I'm told that SAV depends on the browser service to support the connection between clients and servers.  Is this true?  If so, what (if anything) will continue to work, and what will fail, if the browser service no longer works.

Presumably SEP does rely on the browser service.  But I'd like to confirm that.

Multiple Bloodhound.Exploit.45 detections on print server

Fri, 09/03/2010 - 10:41

Since mid August,  we have been experiencing multiple daily heuristic detections of "Bloodhound.Exploit.45" on one of our print servers.  The files detected as risks are always found in C:\Temp and have a naming convention of SPLxxxx.tmp (where xxxx is a string of four numbers/letters ie SPL392C.tmp).   Using Process Monitor I can see that these temp files are being generated by the spoolsv.exe process (the windows print spooler).   The spool folder is set to E:\spool\ in the print server options.

The server is running Windows Server 2003 SP2, and SEP RU6A.   Definitions are current.  Nobody logs into this machine interactively except for a handful of administrators.  No web browsing or other high risk behavior occurs on the server.     I have submitted files to Symantec for review on two occassions (tracking numbers are 17223368 and 17013426).  I have also opened a case with tracking number 412-654-398 but am not really getting anywhere.   Has anyone encountered this before or have any suggestions?

Disable the default password

Fri, 09/03/2010 - 09:53

I would like to stop my users being able to set a default password on removeable disks.

Is this possible ?

Installed SEP on Win 7

Fri, 09/03/2010 - 07:55

After a successful installation of SEP on Win 7 I am getting this “No Symantec Protection technologies are Installed”. Now what is this?
 

Win 7

Fri, 09/03/2010 - 07:34

I am installing SEP on W7 and it is asking me to reboot . I have rebooted so many times but it is still asking to reboot as it is pending.
Why is this happening?

4441511 1283521789

What do I have to do to move endpoint protection manager to a new server?

Fri, 09/03/2010 - 06:05

We bought new servers.  What are the steps required to move endpoing protection manager to a new server? 
Thanks.

CCS v10.0: General discussion & migrating from SecurityExpressions

Fri, 09/03/2010 - 06:02

Hello all!
I'm new to the Symantec Forums but a 5 year customer of SecurityExpressions software and at least 10 year customer of AntiVirus (Norton, SAV, & SEP).
I'd wanted to drop a quick message to start a discussion with not only those who are migrating from SecurityExpressions but hopefully to network with those that are running Control Compliance Suite (CCS).

Some questions I'm interesting in hearing from others on:

  • Are you, have you already, or will you be migrating from SecurityExpressions to CCS?
  • For those who have migrated from SE, what's your biggest stumbling block or what issues have you experienced so fart?
  • CCS v10.0 training:  Anyone know of some excellent hands-on training being offered (beside the limited CCS 10 Admin WBT)?
  • For those who have upgraded to CCS v10 from CCS v9, should I attend v9 hands-on training now or wait until v10?  Or, are there enough differences in v10 that I should just attend v10 training?
  • Who all is running CCS v10.0?  And what kind of installation do you have (i.e. all in one install vs distributed)? 
  • How many servers are you running checks against? 
  • How many workstations are you running checks against?
  • What is your experience using CCS?  For example, do you normally run all checks within CCS Console? Or do you typically run most checks in the RMS side?
  • Being new to CCS, on the Windows side I want to just get a list of Active Directory domain Global Groups and their members.  How do I get this?  Do I import all the AD groups as Assets first then somehow run data collection to gather the member info? 

That's all for now.
Hopefully, we can make this an active discussion and I'll be able to meet and talk with some valuable resources with experience in CCS v10.
Thanks!
Aaron Humphries
American Modern Insurance Group
Amelia, OH
ahumphries@amig.com

Using AntiVirus SDK

Fri, 09/03/2010 - 04:58

Hello all,
         My friend who has started a firm is interested in norton SDK information. The below is the information he is interested.

"I would like to know details about using the Symantec AntiVirus SDK in our
product. I hope you would be able to give me some lead on how to go about
this. To simplify the requirements, I would say that our desktop application
would use the SDK to find viruses or malwares in the computer and disinfect
them.

I would like to know the licensing and other technical terms for obtaining
the SDK."

         It would be great if you can help.

~VV.

External mails stops after installing SEPM

Fri, 09/03/2010 - 04:53

Hello Team,

I am facing problem with my Exchange 2007 server. When installing SEPM on Exchange 2007, internal mail is working fine, but external mails are not received & CAS stops working.
Pls. suggest.

 

Regards,

Harshal.

External mails stops after installing SEPM

Fri, 09/03/2010 - 04:53

Hello Team,

I am facing problem with my Exchange 2007 server. When installing on Exchange 2007, internal mail is fine, but no external mail is received & CAS stops working.
Pls. suggest.

 

Regards,

Harshal.

How good is RU6 MP1, is it worth to upgrade to RU6 MP1

Fri, 09/03/2010 - 03:36

We are thinking of upgrading to RU6 MP1, would like to know about the Pros and Cons

Also, wondering about the naming convention RU6a and RU6 MP1 and what is the latest version called RU6 MP1 or RU6a MP1 :)

Thanks


Google