Endpoint Protection

 View Only
  • 1.  How to determine what files are being scanned by Auto-Protect in real-time

    Posted Feb 24, 2012 09:23 AM

    Is it possible to determine exactly what files are being scanned by SEP in real-time?

    I'm using process monitor with a filter set to show only activity from rtvscan.exe but I'm not getting much other than a bunch of registry activity.

    There is an option in SEP under Antivirus and Antispyware Protection >> Options >> View File System Auto-Protect Statistics. This appears to be Ok but I would prefer something I could save to a file and drop into Excel and go from there.

    Running SEP RU6 MP3. Curious to see if anyone has done anything with this.

    Any help would be appreciated.



  • 2.  RE: How to determine what files are being scanned by Auto-Protect in real-time

    Broadcom Employee
    Posted Feb 24, 2012 09:40 AM

    enabling vpdebug will help in this case.

    http://www.symantec.com/business/support/index?page=content&id=TECH102939

    the log will show waht files have been scanned .



  • 3.  RE: How to determine what files are being scanned by Auto-Protect in real-time

    Posted Feb 24, 2012 09:52 AM

    As Pete already mentioned, the best for you would be to use VPdebug.

    Keep in mind as well that ProcessMonitor require some modifications to capture Auto-Protect events (see http://www.symantec.com/docs/TECH98079 for more details).



  • 4.  RE: How to determine what files are being scanned by Auto-Protect in real-time

    Posted Feb 24, 2012 11:14 AM

    Is there a particular string within vpdebug to look for?  I see a ton of info but nothing referring to the scanning of files.



  • 5.  RE: How to determine what files are being scanned by Auto-Protect in real-time

    Posted Feb 24, 2012 11:27 AM

    You should see lines like this:

     

    05:19:27.453691[_9548]|Processing directory ...
    05:19:27.454757[_9548]|Processing file ...


  • 6.  RE: How to determine what files are being scanned by Auto-Protect in real-time

    Broadcom Employee
    Posted Feb 24, 2012 11:43 AM

    Thumbs up to John Q.

    You should be looking for entry like

    Processing file  



  • 7.  RE: How to determine what files are being scanned by Auto-Protect in real-time

    Posted Feb 24, 2012 01:38 PM

    Been running for over an hour and there is nothing with "processing" in the string