Endpoint Protection

 View Only
Expand all | Collapse all

GRC.DAT file not updating '!KEY!=$REGROOT$\storages\filesystem\realtimescan'

  • 1.  GRC.DAT file not updating '!KEY!=$REGROOT$\storages\filesystem\realtimescan'

    Posted Dec 16, 2014 02:45 PM

    I am using SAVFL 1.10.14-13.    following http://www.symantec.com/business/support/index?page=content&id=TECH102882, 'How to configure scanning of compressed files in Symantec AntiVirus for Linux' I want to manually edit a GRC.DAT file to include from the instructions: 

    Disabling RealTime scanning of compressed files by deploying a GRC.DAT file

    You can use the ConfigEd tool to create custom setting files for deployment with SAVFL. 
    See "Configuring Symantec AntiVirus for Linux" in SAV_Linux_Impl.pdf and How to use rpm to package a GRC.DAT file into a Symantec AntiVirus for Linux installation

    The ConfigEd GUI does not have an option for disabling auto-protect scanning of compressed files, but the GRC.DAT file will include such an option (disabled by default). 

    You can edit the GRC.DAT manually; look for the following line:

    !KEY!=$REGROOT$\storages\filesystem\realtimescan 

    This line will be followed by various realtimescan (auto-protect) options, one per line. 

    ZipFile=D0 indicates auto-protect scanning of compressed files is disabled. 
    ZipFile=D1 is enabled.

    I only have SAV on Linux not windows.   But I got the tool ConfigEd.exe from your website, and ran it.   it generate a GRC.DAT that did NOT have the key '!KEY!=$REGROOT$\storages\filesystem\realtimescan'.    I manually edited the GRC.DAT and added to the end of the file:  

     

    !KEY!=$REGROOT$\storages\filesystem\realtimescan
    ZipFile=D1

     

    I update the 'GRC-State-Counter' by one.  I place the GRC.DAT in /var/symantec and the system does update but this configuration is NOT set.   I can change other values that were originally in the generated GRC.DAT file but NOT this option.  Other values such as 

    !KEY!=$REGROOT$
    LogFrequency=D1

    And after running, I see a change from "D0" to "D1".   Is it possible to manually ADD lines to a GRC.DAT file?  Is there an order in which i can add files such as this in the GRC.DAT file?   

    Thanks

     

     



  • 2.  RE: GRC.DAT file not updating '!KEY!=$REGROOT$\storages\filesystem\realtimescan'

    Posted Dec 19, 2014 02:31 PM

    Best to call support if you don't get any help here.