Endpoint Protection

 View Only
Expand all | Collapse all

How to prevent users smc.exe -stop

  • 1.  How to prevent users smc.exe -stop

    Posted Apr 17, 2009 04:35 AM
    Hi,

    Do you have any ideas on how to prevent managed users from initiating the smc.exe -stop command from windows run command?
    Can we do a policy on the SEP which will block users from initiating the smc.exe -stop command?

    thanks,
    jun


  • 2.  RE: How to prevent users smc.exe -stop

    Posted Apr 17, 2009 04:37 AM
     Why not disable run option for users? Control Admin access for users. Not sure if we can do it from SEP policy


  • 3.  RE: How to prevent users smc.exe -stop

    Posted Apr 17, 2009 04:52 AM
    Hi Jhun,

    Pls enable tamper protection from SEPM and deploy accross all the machines in your netwrok.

    Select the option Block & Log.

    User will be able ot run the smc.exe -stop command but the SMC service always run in kernel mode. It will show the user as stop, but it is still running in the background.

    Also You can put password protection in SEPM to stop the SMC services.

    Rgrds,
    SAM


  • 4.  RE: How to prevent users smc.exe -stop

    Posted Apr 17, 2009 05:01 AM
    go to clients -> policies -> general settings for a group amd in security settings set a password to stop sep this way smc -stop won't work (you will have to use smc -p password -stop)


  • 5.  RE: How to prevent users smc.exe -stop

    Posted Apr 17, 2009 05:23 AM
    The best thing is to set a password so user cannot stop the service of smc.


  • 6.  RE: How to prevent users smc.exe -stop

    Posted Apr 17, 2009 08:49 AM
    Tamper protection works - we don't have a password, but I still can't stop the services..........


  • 7.  RE: How to prevent users smc.exe -stop

    Posted Apr 17, 2009 08:58 AM
    Set a password  for  this in  group settings  so that it will ask for password if some one tries the command


  • 8.  RE: How to prevent users smc.exe -stop

    Posted Apr 17, 2009 09:46 AM
    You can add a password to make it tough for them but to be clear, You can never prevent an administrator from getting across whatever security you put. The simplest is to disable the service and reboot the computer, Use Drwatson to debug and kill the process...... 


  • 9.  RE: How to prevent users smc.exe -stop

    Posted Apr 20, 2009 07:14 AM
    You can do it by Dissabling the Dissable Symantec Endpoint Protection from the users machine


  • 10.  RE: How to prevent users smc.exe -stop

    Posted Apr 20, 2009 10:56 PM
    Enabling password to stop the service would be the most effective and easiet way to achieve this.


  • 11.  RE: How to prevent users smc.exe -stop

    Posted Apr 20, 2009 11:45 PM
     Enabling passwords does not stop it. As Sandeep put it rightly, admin accounts are kings. You have to do passoerds plus remove admin access for users...Its a two pronged approach. Hope this answers your question