Endpoint Protection

 View Only
Expand all | Collapse all

history log

Rafeeq

RafeeqAug 05, 2009 10:26 AM

Migration User

Migration UserAug 19, 2009 12:10 AM

  • 1.  history log

    Posted Aug 05, 2009 09:49 AM
    Hi Admin

    I have sav 10.xx and history log was set default (2 mont) but my admin client want to get back history log lass 5 mont ago, can symantec do it's, thank's


  • 2.  RE: history log

    Posted Aug 05, 2009 10:01 AM
    The logs would have been purged after 2 months.

    As far as i know there is no way of going further with logs.



  • 3.  RE: history log

    Posted Aug 05, 2009 10:10 AM
    Thank's but i dont know how to say, it's very imfortant for my admin client, i need a miracle from Symantec Support to get back all old history log, i'm waiting.


  • 4.  RE: history log

    Posted Aug 05, 2009 10:17 AM
    Let me also try if any thing can be done.
    Im' sorry to say but its not possible , (i'm sure, but wil be happy if i'm wrong) 


  • 5.  RE: history log

    Broadcom Employee
    Posted Aug 05, 2009 10:19 AM
    logs are saved based on settings...if it is purged..there is no way to retrieve it ( I believe)...


  • 6.  RE: history log

    Posted Aug 05, 2009 10:20 AM

    Do you have regular backups of the system?  IF so, you might be able to load the old log files from one of the backups, if that portion is backed up.  If not, as stated above, unfortunately the information would most likely have been purged.



  • 7.  RE: history log

    Posted Aug 05, 2009 10:26 AM
    They are purged and no way to get them.



  • 8.  RE: history log

    Posted Aug 06, 2009 03:18 AM
    to All....thank's alot for any comment, now i have a pbroblem with W32.IRCbot, why SEP 11 cannot clean this virus, it's make my log directory full and my system was hang because that.
    can anyone help solve this problem...




  • 9.  RE: history log

    Posted Aug 06, 2009 03:42 AM
    Hi ghomes, I suggest to run a full scan on safe mode and make sure you have the latest virus defs.


    To delete the value from the registry
    Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified subkeys only. For instructions refer to the document: How to make a backup of the Windows registry.
    1. Click Start > Run.
    2. Type regedit
    3. Click OK.

      Note: If the registry editor fails to open the threat may have modified the registry to prevent access to the registry editor. Security Response has developed a tool to resolve this problem. Download and run this tool, and then continue with the removal.
       
    4. Navigate to and delete the following registry entries:

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"winapii" = "%Windir%\Winapii\Winapii.exe"
       
    5. Exit the Registry Editor.

      Note: If the risk creates or modifies registry subkeys or entries under HKEY_CURRENT_USER, it is possible that it created them for every user on the compromised computer. To ensure that all registry subkeys or entries are removed or restored, log on using each user account and check for any HKEY_CURRENT_USER items listed above



  • 10.  RE: history log

    Posted Aug 06, 2009 08:23 AM
    did W32.IRCbot have a connection with microsoft security bulletin MS05-039


  • 11.  RE: history log

    Posted Aug 18, 2009 11:39 PM
    where i can find account number to install quarantine server, i have a license but i cannot find any account number


  • 12.  RE: history log

    Posted Aug 19, 2009 12:10 AM
    can any one help to find account number


  • 13.  RE: history log

    Posted Oct 02, 2009 12:03 AM
    Please help us, can anyone tell me why w32.pinfi still infect event SEP 11 with new updater installed and running well.  All my execute files was infect with this virus and then missing exe so my server was down...down...


  • 14.  RE: history log

    Posted Oct 10, 2009 07:00 AM
    Please help...help...and help us......., all my client server and pc was infected with w32.pinfi....please help us to clean...clean...and clean...NOT EDIT Registry....because my client have more than 30 unit server with windows server 2003 and more than 5000 unit pc with windows XP and have 5200 LICENSE SYMANTEC ENDPOINT PROTECTION, how to edit server and pc if that more than 5000 unit....please help us to create cleaner not editer for w32.pinfi.

    Now, all server and PC was going down and error because w32.pinfi, please anyone help us, we still install SEP 11 with new...new...new..updater but it's cannot help because all server and pc was infected with w32.pinfi.

    What we need is CLEANER FOR CLEAN W32.PINFI.