News

Mal/Autorun-R

Sophos Virus Alerts - Tue, 09/07/2010 - 17:09

Performance of the Lan Gateway

Symantec Security Response - Tue, 09/07/2010 - 17:03

Is anyone using the LAN Gateway appliance in an evironment with 25-30,000 users?  We are being told that the Gateway enforcer appliances are sized to accommodate 25,000 IP addresses per physical enforcer.  There seems to be some confusion on what we actually measure but the number is indeed 25,000 IP addresses per enforcer.   Does anyone know how many sessions per IP an enforcer can support?  So can one enforcer handle 25,000 ip addreses and x number of sessions per ip?

Any feedback on this would be most helpful!

Thank you.

 

Endpoint Protection Small Business, Clients cannot get updates from server/console

Symantec Security Response - Tue, 09/07/2010 - 16:46

I installed the management console, and have a test platform of 3 clients (1, Windows 2000, 1 XP, 1  Win 7).  Those that have internet access go to the web, those that do not get the error LU1814.  None of the pc's are supposed to go to the web as the box "Allow Liveupdate to run on the client" is not checked.  The only files I have found so far (#2007110813315548) seems to suggest that the Microsoft service WSUS is required.  Can anyone confirm this?  As far as I can tell, this service is not on the server, hence the failed updates to the clients.

Thanks.
Craig

Troj/Agent-OQK

Sophos Virus Alerts - Tue, 09/07/2010 - 16:40

Mal/Bckdr-O

Sophos Virus Alerts - Tue, 09/07/2010 - 16:11

Windows 7 Recovery with Endpoint Encryption Recovery CD

Symantec Security Response - Tue, 09/07/2010 - 16:03

I am new to Endpoint Encryption. I have a laptop with full system encryption that is coming up with a boot sector problem. This is a Windows 7 64bit laptop. Normally I would boot off the Windows 7 install cd and run the bootrec.exe to rebuild the boot sector on Windows 7 but since it is encrypted I can't. I have read that you can use the Endpoint Encryption recovery cd but the one that I have looks to be WinPE 1.0 (WinXP). Does anyone know how you can do this for this Windows 7 PC?

Been hit with a trojan and now my icons, start bar and explorer are gone

Symantec Security Response - Tue, 09/07/2010 - 15:32

It seems we've been hit with a nasty trojan and now my desktop icons, my start bar, and even my explorer.exe are gone. I have to use the task manager to access anything and that access is limited. I tried a system restore but unfortunately, it only offered a restore date that included the problems. I am in NO way computer savvy and would greatly appreciate any help. I've been able to update my Norton protection, but my it regularly reports that it is blocking intrusions. I looked in the security history and found that since August 31st there have been several quarantines. I will list them.

m7931o.dll (Trojan,Gen) on September 07, 2010
s3ei93179.sys (Hacktool.Rootkit) September 04, 2010
rbj.exe (Trojan.FakeAV!gen29) September 02,2010
g1iq31ce (Suspicious.Cloud) August 31,2010 10:49PM
mrnaosxecw.tmp (Downloader) August 31, 2010 10:48 PM
hlp.dat (Trojan.Bamital) Augusy 31, 2010 8:49PM
temp.tmp (Trojan.Bamital!inf) August 31, 2010 8:48PM
winlogon.exe (Trojan.Bamital!inf) August 31, 2010 8:27PM
Suspicious.Mystic August 31, 2010 8:26PM

I appreciate any guidance or help anyone would care to offer. Thank you!

System : Dell with Windows Xp Pro

SEP taking forever to load when not connected to network

Symantec Security Response - Tue, 09/07/2010 - 15:27

We have a lot of remote users with laptops that are rarely connected to the corporate network. When logging into one of these laptops it takes between 30sec and 2min before the little SEP shield appears in the system tray. If users try to launch other applications before the SEP shield appears they complain that their system locks up, likely because SEP is still loading and they're trying to do too much at once.

These laptops are very high-end machines (2.4GHz, 4GB RAM, 80 Intel SSD hard drive) so I don't think it's a resource issue. It seems to me that SEP is trying to contact the management server and delays starting up until some timeout period is reached. Anyone know what is really causing this and how I can get the SEP client to load quicker on startup?

Again, this only seems to happen if the PC isn't connected to our network. 

Mal/SillyFDC-F

Sophos Virus Alerts - Tue, 09/07/2010 - 14:54

SEP v11 and v12 unmanaged clients - License Expirey

Symantec Security Response - Tue, 09/07/2010 - 14:48

We have a number of small clients using SEP SBE.
We purchase the annual license renewel and upgrade their installations.
With SEP the old license file ceased to exists. So two questions:

How can I tell when an installation is coming up for renewel?

And is the Downloaded software pinned to the specifica customer?

Basically in the old days I downloaded the software and used the same install CDs for all clients with their own license files.

Do we now need to download separate copies of the install software for each licensed customer?

SEE 7.0.3 to SEE 7.0.5 questions

Symantec Security Response - Tue, 09/07/2010 - 13:53

We currently have alot of users that are not able to login to SEE and it tells them that it "Failed to communicate with the SEE Server". Also we have users in our enviornment that are currently running 7.0.3 and the server is running 7.0.5. Do we still need to upgrade the local computers to match the server version even though it was a minor upgrade? If so then can we do it remotely and is there a tool that if we need to go to each computer that we can run to upgrade them to the newest version?
 

Mal/SillyFDC-H

Sophos Virus Alerts - Tue, 09/07/2010 - 13:20

Auto reboot when pushing endpoint client?

Symantec Security Response - Tue, 09/07/2010 - 13:10

Is it possible to have Endpoint reboot the system when its finished installing via a Push install? Right now I have been pushing a single Setup.exe out, but I would still like to use the Push client even if I have to use a MSI.

Thanks

4457111 1283892724

lost symantac user/password for my server consol

Symantec Security Response - Tue, 09/07/2010 - 12:34

not having user/password for symantec server consol , try and run iFORGOT, Also check the registery for user name showing Administrator...try with all defult usr/pass too. not able to open the consol ....need help

Client can't contact Server

Symantec Security Response - Tue, 09/07/2010 - 12:06

Just the other day I created a new set up and sent it to my boss.  It appeared that what he had was having trouble updating, so I figured we'd re-deploy it. Plus, since we recently re-did the server which holds the management console, he has not been able to connect anyway.  The update worked in that it is now the latest version and appears to be downloading new AV files and everything, however, the little green dot that notes that it's connected to the management server has never appeared.  We have a VPN set up, and I just checked that and it is working just fine.  How do I troubleshoot this?

Troj/Agent-OOC

Sophos Virus Alerts - Tue, 09/07/2010 - 11:18

Fileconnect does not work SAV Corp 10.2 Int English CD1 failure!

Symantec Security Response - Tue, 09/07/2010 - 11:09

I am trying to download Symantec Antivirus Corporate Edition 10.2.4 International_English CD1 using fileconnect.  Our client is a non-profit so they purchased the software through techsoup, so noone wants to help me.  But, I can download disc 2 with NO PROBLEMS.  Disc 1 however, fails every time.  I have tried the HTTP AND Managed Downloads and the HTTP gets about 60MB in and fails.  The Managed download gets to 20% and just sits there for 12+ hours then fails as well.   I have tried this from multiple PCs and servers and always get the same result.  So, it is obvious that YOUR LINK TO DOWNLOAD CD1 IS BROKEN!!  All I need is CD1 so I can install this software which they bought!  Tech support has been no help and tells me I have to contact techsoup and purchase media!  This is outragious and should be easily downloadable from your site...not through them!  Please tell me you have an FTP setup, so I can just login to it and pull down the CD1 which I need.

Thank you in advance,
Frustrated user.

symantic exceptions

Symantec Security Response - Tue, 09/07/2010 - 10:42

I posted this in the Endpoint Management > Helpdesk Solution Forum, posting it here now.

"I cannot create a file or folder exception. symantic keeps deleting an exe file that I need. first I open symantic endpoint protection, on the left I click on "change settings" then I click on "configure settings" for centralized exceptions. Once there I click on "add" and select securicy risk exceptions > file, but nothing happens."

"I just tried again and was able to add the exception but I cant edit it or create any more"

Live update query

Symantec Security Response - Tue, 09/07/2010 - 10:21

Just looking at my most recent signatures, my personal ones are over 24hrs old, dated 06/09/10

But this http://www.symantec.com/business/security_response/definitions.jsp

says under the ''learn more''

''LiveUpdate is the most trusted way of updating virus definitions. Each set is fully tested and certified by Quality Assurance. Certified Multiple Daily LiveUpdate is published several times a day and is the best protection from fast moving threats. ''

Are signatures for SEP always at least 24hrs old, are my expectations of daily revisions too much?

Thanks

system.exe not detected as a virus by Symantec

Symantec Security Response - Tue, 09/07/2010 - 09:57

I submitted system.exe because it is not being detected as a virus while other anti-malware vendors all do detect it as a Trojan virus.
The file has been send under Tracking #17177039 number.
It infects USB memory sticks.


Google