Endpoint Protection

 View Only
  • 1.  Exceptions

    Posted Oct 08, 2012 12:07 PM
      |   view attached

    Can you please look at this error message.  (see attachment)  What does this message mean EXACTLY and how do I create an exception that will allow this program to run?

    Attachment(s)

    docx
    errormsg.docx   211 KB 1 version


  • 2.  RE: Exceptions

    Posted Oct 08, 2012 12:11 PM

    HI,

    Dtlui.exe is application ?

    if yes you can create Exceptions

    1. In the Symantec Endpoint Protection Manager select Policies
    2. Select View Policies
    3. Double-click AntiVirus and AntiSpyware.
    4. Double-click the AntiVirus and AntiSpyware policy on the right hand side. This opens a new window.
    5. Click Proactive Threat Scan
    6. Select Detecting Commercial Applications
    7. Set your preferred actions and lock.

    Creating Centralized Exceptions Policies in the Symantec Endpoint Protection Manager 12.1

    http://www.symantec.com/docs/TECH183201

    Reference: https://www-secure.symantec.com/connect/forums/psftpexe-failing-servers



  • 3.  RE: Exceptions

    Trusted Advisor
    Posted Oct 08, 2012 12:16 PM

    Hello,

    Bloodhound.Sonar.9 is a heuristic detection for processes based on certain attributes. 

    http://www.symantec.com/security_response/writeup.jsp?docid=2011-122605-0918-99

    Files that are detected as Bloodhound.Sonar.9 may be malicious. We suggest that you submit any such files to Symantec Security Response. For instructions on how to do this using Scan and Deliver, read Submit Virus Samples.

    Submitting suspicious files to Symantec allows us to ensure that our protection capabilities keep up with the ever-changing threat landscape. Submitted files are analyzed by Symantec Security Response and, where necessary, updated definitions are immediately distributed through LiveUpdate™ to all Symantec end points. This ensures that other computers nearby are protected from attack. The following resources may help in identifying suspicious files for submission to Symantec.

    Reference: https://www-secure.symantec.com/connect/forums/centralized-exceptions-12

     

    Hope that helps!!



  • 4.  RE: Exceptions

    Posted Oct 08, 2012 12:20 PM

    This is for SONAR, which is part of the PTP component.

    You can add from your SONAR log.

    Login to SEPM

    Go to Monitors >> Logs

    Set log type to SONAR and click View Log

    This exe should be showing in there

    Select the check box and under Action, click the + sign. Select Allow Application. Select your policy to add this to and click Save Changes



  • 5.  RE: Exceptions

    Posted Oct 08, 2012 11:07 PM

    Is this Dtlui.exe is your commercial application.

    If it a commercail application then use the below attach link

    http://www.symantec.com/business/support/index?page=content&id=HOWTO27313

    http://www.symantec.com/business/support/index?page=content&id=HOWTO27058

    If not able to do the centerlaize configuration then use the false positive linkfor the same

    https://submit.symantec.com/false_positive/



  • 6.  RE: Exceptions

    Broadcom Employee
    Posted Oct 09, 2012 04:40 AM

    Hi,

    If you are 100% sure that it's not a malicious file then you can refer following articles.

    How to Create Exceptions or Exclusions for Tamper Protection Alerts that have already been logged

    http://www.symantec.com/business/support/index?page=content&id=TECH92553&locale=en_US

    Configuring a centralized exception for a detected process

    http://www.symantec.com/docs/HOWTO27305

    OR

    Submit it to Symantec response team to determine the next course of action.

    http://www.symantec.com/security_response/submitsamples.jsp

    Symantec Security Response usually takes half a day to a day to provide a response. In the interim, you can try these sites for a quick analysis because it's automated response: Own by Symantec only.

    http://www.virustotal.com/

     http://www.threatexpert.com/submit.aspx

     

     



  • 7.  RE: Exceptions

    Posted Oct 22, 2012 12:11 AM

    Hi MZSOLO

    Your issue is resolve or not?



  • 8.  RE: Exceptions

    Posted Oct 23, 2012 06:46 PM

    No- the issues did not resolve - we have decided to decommision the server and move the clietns to a new 2008 server.  Seem  like the easiest method (considering we were going to upgrade the server in a few months).

     

    thanks for your time