Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

Symantec Endpoint Protection –Few Registry Tweaks..

Updated: 09 Sep 2009 | 42 comments
Vikram Kumar-SAV to SEP's picture
+48 48 Votes
Login to vote
Here are a few registry tweaks and information about Symantec Endpoint Protection.

1. To check the Version of currently installed SEP client

HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\SMC

ProductVersion  

Value will be something like 11.0.4014.26

 
2. Client is communicating with SEPM or is OFFLINE

HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\SMC\SYLINK\SyLink

PolicyMode  1 – means communicating 0- means offline.

3. Which Group the client is pointing to

HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\SMC\SYLINK\SyLink

Preferredgroup

4. Policy Serial Number on Client

HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\SMC\SYLINK\SyLink

SerialNumber

Value will be something like 2DD9-09/09/2009 00:05:14 125

5. To know the Hardware ID for the Client

HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\SMC\SYLINK\SyLink

HardwareID

6. What is the version of Virus Defintion the client is currently using .

HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\SharedDefs

DEFWATCH_10

The value will be some like C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20090907.050

7. To know what IPS Signature SEP is using

HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\SharedDefs\SymcData-cndcipsdefs

cndcIps

The value will be like: C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\CNDCIP~1\20090826.002

8. To check if Network Threat Protection is installed and is Turned ON.

HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\SMC

smc_engine_status  0 – means turned OFF 1- turned ON.

 

9. Exclusion –Centralized Exceptions

32 bit

i. Security Risk Exceptions

User Defined Exceptions

HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Exclusions\ClientRiskExceptions

Lock – 0- means the client can create Centralized Exceptions for Known Security Risks 1 – means this optioned is locked by the administrator in SEPM.

And Under the ClientRiskExceptions\1234567890 (normally a 10 digit numerical folder )  you will find the Known Security Risk exceptions created by the users.

 

HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Exclusions\AdminRiskExceptions

Under the AdminRiskExceptions\1234567890 (normally a 10 digit numerical folder )  you will find the Known Security Risk exceptions created by the Admin from SEPM.

 

ii. Proactive Threat Protection Exclusions

HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Exclusions\HeuristicScanning\FileHash

\Client\ 0728bd2bb1774b9728f60d33bc1f95172374e950–(The long hexadecimal numbers point to the filehash for the excluded file )  For the exclusions created by the user

\Admin\ 0728bd2bb1774b9728f60d33bc1f95172374e950 - (The long hexadecimal numbers point to the filehash for the excluded file ) -  For exclusions made by Admin from SEPM.

Same with Directory , Files and Folder Exclusions

iii. Directory

HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Exclusions\ScanningEngines\Directory

\Admin  and \Client

iv. Files

HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Exclusions\ScanningEngines\FileName

\Admin  and \Client

 
v.Extensions

HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Exclusions\ScanningEngines\Extensions\

\Admin  and \Client

vi. Symantec also excludes it own Embedded Database from Scanning

HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Exclusions\Symantec Embedded Database\FileExceptions

Out.log, Sem5.log and Sem5.db are excluded.

vii. To Verify Exchange Server exclusions on 32 Bit System

HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Exclusions\Exchange Server

\FileExceptions and \NoScanDir

On 64 Bit system

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Symantec\Symantec Endpoint Protection\AV\Exclusions

\FileExceptions and \NoScanDir

  

10. Now say you have remote laptops you exported a Default client install package and sent them.

Now you want to change them to Unmanaged.

You replaced sylink.xml for Unmanaged SEP Cd1\SEP\Sylink.xml

Still clients are not able to do the liveupdate and the default admin defined Scan runs.

Here is the default Admin Defined Scanand if you have created few more scans for this users it will also be listed in the same location but with a different name.

HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\LocalScans\5df13630-79f7-4c70-002b-16b8952f5533 ( name can be any hexadecimal name )

So you can delete this and then you can create your own scan.

Liveupdate button is greyed out even after replacing sylink.

HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\LiveUpdate

AllowManualLiveUpdate  0- means liveupdate button will be greyed out. 1-means it will be available to click.

In the same place you can enable product updates by changing the value of

EnableProductUpdates  to 1

For Scheduling and Enabling automatic liveupdates.

HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\LiveUpdate\Schedule

Change the value of

Enabled to 1 – for Automatic updates.

 

11. Handling Quarantine

Sometimes due to infection the size of the quarantine folder grows huge.

It is not accessible via the GUI.So to know where and to change settings for Quarantine for the client

HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Quarantine

Important keys

QuarantinePurgeBySizeEnabled set it to 1 –To enable Sizing of quarantine folder then

QuarantinePurgeBySizeDirLimit   Default value is 50 ( Megabytes)  either leave it at 50 or reduce it as much you want.

You can also lower the age of purging Quarantine items from default 30 days to any number of days you want

QuarantinePurgeAgeLimit   30 days by default.

12. How to disable Application and Device Control via registry

 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SysPlant

Change the Value of Start to 4 . 1 –means enabled.

13. Check this discussion on Creating Scan via registry 
https://www-secure.symantec.com/connect/forums/way-create-scan-registry

14. For Logging options via registry
How to debug the Symantec Endpoint Protection 11.x client
http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007090611252048

 15. GUP information via registry
Troubleshooting the Group Update Provider (GUP) in Symantec Endpoint Protection
http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2008040113243148

Comments

jeffwichman's picture
09
Sep
2009
1 Vote +1
Login to vote

Great article.... lots of

Great article.... lots of useful information.

thanks

Sandeep Cheema's picture
09
Sep
2009
1 Vote +1
Login to vote

Good auditing info.

Good auditing info.

De facto when AV does something, it starts jumping up and down, waving its arms, and shouting "Hey!  I found a virus!  Look at me!  I'm soooo goooood!"

Satyam Pujari's picture
09
Sep
2009
1 Vote +1
Login to vote

good info for sym customers.

It's really a good article to assist sym customer to understand the product's internal working better.All regs in one place...nice effort !  

Inviting good karma to CPU...0xal0ne

Symantec World's picture
09
Sep
2009
3 Votes +3
Login to vote

Re

Good and Knowledgeable.

Regards, M.R

shp's picture
10
Sep
2009
2 Votes +2
Login to vote

Thanks yaar... I was looking

Thanks yaar...

I was looking for this.. You got my vote.....
Thanks once again.... 

Regards,
Srinivas H.P.
HCL Infosystems Ltd

Maximilian's picture
10
Sep
2009
0 Votes 0
Login to vote

 Very good! I could use some

 Very good!

I could use some more of this good stuff :)

Thanks!!! 

AravindKM's picture
10
Sep
2009
1 Vote +1
Login to vote

Useful article

Useful article. Thank you

Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind

Symantec World's picture
11
Sep
2009
1 Vote +1
Login to vote

Re

All have to vote this article....

Regards, M.R

Int3rn3t's picture
17
Sep
2009
0 Votes 0
Login to vote

very useful article.

very useful article.

ragunayaka@gmail.com's picture
18
Sep
2009
0 Votes 0
Login to vote

 Nice article dude.. Best of

 Nice article dude..

Best of Luck

Aniket Amdekar's picture
22
Sep
2009
4 Votes +4
Login to vote

Here is one mroe: To

Here is one mroe:

To enable/disable Scan Process Dialogue for Custom Scans:

HKLM\Software\Symantec\Symantec Endpoint Protection\AV\LocalScans\Default CustomScan Option

On the right pane check for the DWORD "DisplayStatusDialog"  the value must be 1, if not change it to 1.

The same is applicable to most of scans present at the location:

HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\LocalScans

Best,
Aniket

mssym's picture
23
Sep
2009
5 Votes +5
Login to vote

@Vikram Kumar-SAV to SEP

Vikram Kumar-SAV to SEP

It seems to me that you cover the keys based on computer mode observation. If it is User mode or fix mode. The following two keys are

2. Client is communicating with SEPM or is OFFLINE

HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\SMC\SYLINK\SyLink

PolicyMode  1 – means communicating 0- means offline.

PolicyMode 1 -- means "Computer Mode", 0 -- means User mode.

3. Which Group the client is pointing to

HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\SMC\SYLINK\SyLink

Preferredgroup

In a User Mode configuration, This is defautl group, but not necessarily the group client point to, in User Mode, the SerialNumber key in the same registry locaiton is the group that client point to.

Vikram Kumar-SAV to SEP's picture
24
Sep
2009
7 Votes +7
Login to vote

 File System

 File System Auto-Protect

HKEY_LOCAL_MACHINESOFTWARESymantecSymantec EndpointProtectionAVStoragesFilesystemRealTimeScan

OnOff : 1- means enabled 0 - means disabled

Jamit's picture
10
Nov
2010
0 Votes 0
Login to vote

I have found this setting is

I have found this setting is not always true. I had a case today where the SEPM Logs and Client console flagged File System Auto-Protect was not running. I checked HKEY_LOCAL_MACHINESOFTWARESymantecSymantec EndpointProtectionAVStoragesFilesystemRealTimeScan OnOff on the workstation and it was set to 1 (enabled) however File System Auto-Protecwas not. 

To resolve I had to repair the client. If someone can advise why I saw the above behaviour it would be appreciated?

 

Thanks

Jamit

 

manish-SecPol's picture
05
Oct
2009
0 Votes 0
Login to vote

this helped me.nice article.

this helped me.nice article.

Ghent's picture
17
Oct
2009
2 Votes +2
Login to vote

Hardware ID in RU5

Hi, in RU5 the HardwareID was moved out of the registry and onto the disk. It's now located at %ProgramFiles%\Common Files\Symantec Shared\HWID\sephwid.xml

justin-new2SEP's picture
22
Oct
2009
0 Votes 0
Login to vote

Very useful article..i was

Very useful article..i was looking for these info.

Kedar Mohile's picture
03
Nov
2009
1 Vote +1
Login to vote
wosteen's picture
12
Nov
2009
0 Votes 0
Login to vote

It looks like this one is (at

It looks like this one is (at least partially) incorrect: 

6. What is the version of Virus Defintion the client is currently using .

On my machine, running Windows 7 64-bit and SEP 11.0.5002.333, there is no registry key HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\SharedDefs

The only other machine I have quick access to had SAVCE 10.1.6.6000 on it before I upgraded it, and the SharedDefs key *is* there.

Any idea where I could find the information?

Thanks,
Wayne

Vikram Kumar-SAV to SEP's picture
17
Nov
2009
3 Votes +3
Login to vote

 I have just tested that on

 I have just tested that on WIn XP 32 bit reg keys for 32 and 64 are little bit different.

Maximilian's picture
19
Nov
2009
0 Votes 0
Login to vote

 Great stuff! Anyone know if

 Great stuff!

Anyone know if these still apply after MR5 release?

Vikram Kumar-SAV to SEP's picture
01
Dec
2009
3 Votes +3
Login to vote
Maximilian's picture
02
Dec
2009
0 Votes 0
Login to vote

 Great! Any new reg keys for

 Great!

Any new reg keys for MR5?

Frank019's picture
02
Dec
2009
0 Votes 0
Login to vote

very nice article, thank you

very nice article, thank you for making this one

GWA's picture
15
Dec
2009
0 Votes 0
Login to vote

Excellent article.

Excellent article.

jayancharles's picture
02
Mar
2010
1 Vote +1
Login to vote

HI  vikram Great ya i know ur

HI  vikram Great ya i know ur in other field but u doing well....I think u get from google any  nice..............

by

  Jayan charles

Vikram Kumar-SAV to SEP's picture
02
Mar
2010
1 Vote +1
Login to vote

I am either in football field

I am either in football field or SEP field..no other field..

Wally's picture
16
Mar
2010
1 Vote +1
Login to vote

Great article - especially

Great article - especially the EnableProductUpdates tweak - will save me a lot of time!!!

JRV's picture
24
Mar
2010
0 Votes 0
Login to vote

If you can't think of any

If you can't think of any other reasons not to let your users run as admins (and most of us can think of many!), the fact that SEP stores its config in the registry for all to see is a great one.

If you run as an admin, it is trivial for malware or malicious users to disable SEP.

BrooksGarrett's picture
09
Apr
2010
0 Votes 0
Login to vote

Application and Device

Application and Device Control. Done.

IE: Do not allow any process to modify SEP Registry Keys.

John Cooperfield's picture
16
Jul
2010
0 Votes 0
Login to vote

Very good article. 

postechgeek's picture
16
Jul
2010
0 Votes 0
Login to vote

Nice, thanks.

VKalani's picture
22
Aug
2010
0 Votes 0
Login to vote

this applies for ru6mp1

this applies for ru6mp1 too!!!

-VKalani

SymSEP's picture
11
Sep
2010
0 Votes 0
Login to vote

One for informative articles

One for informative articles of urs that i have book  marked

Ian_C.'s picture
13
Feb
2011
2 Votes +2
Login to vote

About Content Cache Control

Please can we add this list of Registry keys to the list.

http://www.symantec.com/business/support/index?page=content&id=TECH106042&locale=en_US

These keys are about caching client content

  • Caching install files
  • location of cached files
  • number of revisions to keep
Ian_C.'s picture
17
Feb
2011
2 Votes +2
Login to vote

Client to use GUP

Do the clients know that they are to use a GUP?

You can verify by looking in the registry.

[HKLM\SOFTWARE\Symantec\Symantec Endpoint Protection\LiveUpdate]
UseMasterClient = 1 This says the client knows to use a GUP
MasterClientHost = "host name of the GUP"

Thanks to blenahan from https://www-secure.symantec.com/connect/forums/propagation-clients-server-capability-sep-wan#comment-5189451

 and officially from  "Symantec Endpoint Protection 11.0 Group Update Provider (GUP)" http://www.symantec.com/docs/TECH102541 right at the bottom.

yang_zhang's picture
25
May
2011
0 Votes 0
Login to vote

So greate! I will bookmark

So greate! I will bookmark this!

If a forum post solves your problem, please flag it as a solution. If you like an article, blog post or download vote it up.
Moab.baom's picture
04
Nov
2011
0 Votes 0
Login to vote

Monitoring Windows definition displayed on SEPM home page

Great article,

But I'm not just interesting to know the client virus definitions (HKLM\SOFTWARE\Symantec\SharedDefs\DefWatch\VirusDefs) ,

but the windows definitions on the SEPM console home page:

Latest from symantec

Latest On Manager

Because I want first to monitor this information . I found a very good nagios pluggin, but it displays the Virus definition of the client installed on the server. The server can be the client of another SEPM, up to date, and my local server out of date, and I will not know this with this information.

https://www.monitoringexchange.org/inventory/Check-Plugins/Operating-Systems/Windows-NRPE/check_symantec_av

Me I need to know the entry in registry of the windows definitions displayed on the SEPM console.

Best regards

Wally's picture
23
Nov
2011
0 Votes 0
Login to vote

Registry entry for Disabling the Windows Firewall

Vikram - do you know if there is a registry entry on the SEP 11 RU6 or RU7 client for "Disable the Windows Firewall"?

LGL's picture
07
Dec
2011
0 Votes 0
Login to vote

SEP12.1 update

Is there any update from anyone according to the latest release SEP12.1 RU1 and registry entries, maybe there is some new useful registry entries to know in that version?

rinklekmahajan's picture
13
Dec
2011
0 Votes 0
Login to vote

Gr8

Gr8

Thanks,

Rinkle

Srikanth_Subra's picture
21
Jan
2012
1 Vote +1
Login to vote

Nice article

Nice article

Thanks & Regards,

 Srikanth.S

"Defeat the Defeat before the Defeat Defeats you"
(Swami Vivekananda)