How to update virus definitions inside the installation Packages ???
Updated: 21 May 2010 | 12 comments
I have created several SEP packages like silent, progress bar etc...
I want to know how to update virus definitions inside the Installation Packages so that even installation packages will have latest definitions.
discussion Filed Under:
Comments
Go to \Program
Go to \Program Files\Symantec\Symantec Endpoint Protection
Manager\Inetpub\Contents\
Here you will see a folder which starts with
{C60 go inside that folder and find out the directory with latest modified date and copy full.zip file in the new package
you are created.Remove vdefhub.zip from that folder and rename this full.zip as
vdefhub.zip.Now you will get a package with latest update(AV/AS).
Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind
this is manual task... is
this is manual task...
is there any automate process where installation packages will get updated automatically when there is any new definitions
As per my knowledge noting up
As per my knowledge noting up to now.
Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind
Your best bet would be to
Your best bet would be to automate the process with a scheduled task(daily) on the server that is hosting the install package. Should be very easy to accomplish.
De facto when AV does something, it starts jumping up and down, waving its arms, and shouting "Hey! I found a virus! Look at me! I'm soooo goooood!"
This idea is in development
This idea is in development stage you can also vote for that
Ref: https://www-secure.symantec.com/connect/idea/inclu...
Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind
Info
Greetings,
Generating packages in this fashion is not really necessary. The new RU5 release doesn't even have definitions included in the package. As soon as you deploy and install the client it will immediately contact the Endpoint Manager and check for a virus definition update whether you did the above process or not.
You may save on some bandwidth by doing this, though if bandwidth is a concern you probably should be looking at GUP's or something similar.
Remote Product Specialist, Business Critical Services, Symantec
Quantify
Only MR5 packages pushed from the SEPM do not include any defs.
The deployed package uses the definitions that it finds on the client while it waits for the new definitions.
Clients with no antivirus on are in trouble anyway, and a few minutes extra while they wait for definitions is not going to change anything.
You would naturally want to deploy your GUP's first, give them a chance to update, and then start deploying clients.
You can however create packages that contain the latest definitions and then deploy them through different methods according to your requirements. Bear in mind, you're looking at +- 50 MB per client X x-amount of clients over a WAN and you could be saving GIG's of bandwidth
Obviously installing directly from the CD installs with the creation date definitions.
Re: Quantify
Hi Standaround. I disagree with you on waiting a few minutes for new defs to arrive.
Depending on how old the defs are on the system, you can be in a world of hurt when there are no defs present. There is plenty of malware around that will find and infect a system that has no protection.
That is also one of the reasons new PC's are not put on our network before all patches and virdefs are up to date.
JohnSn, That's not the point
JohnSn, That's not the point as far as I can relate.
When you are deploying to tens of thousands of machines, there are always couple hundred that do not communicate with the manager for whatever reason. Having the latest defs ensures that these clients stay protected on a best effort basis before they are attended to.
Updating the package repository with a script on the server through a task, which copies over the zip file from the SEPM folder and renames it will just enhance the package with latest definitions. I personally think he has a point.
De facto when AV does something, it starts jumping up and down, waving its arms, and shouting "Hey! I found a virus! Look at me! I'm soooo goooood!"
Re: Sandeep
isn't that what I just stated? Installing a client, including the latest virdefs/content, is better than installing a client without virdef/content and wait for the client to update?
Right. Multitasking here. I
Right. Multitasking here. I apologize.
De facto when AV does something, it starts jumping up and down, waving its arms, and shouting "Hey! I found a virus! Look at me! I'm soooo goooood!"
@JohnSN
Hi JohnSN
I must admit, that when I first heard about it I hyperventilated a little... and then I gave it some thought.
If your clients deffs are outdated... You're already in pain, and should probably be focusing on sorting the definitions out, rather than upgrading. Depending on the type of infection/pain, your installation exe's could well get infected. If your machine is infected, it should also be taken off the network, cleaned, and then have an AV installed/repaired.
If you're installing SEP off the network, then you're not deploying from the SEPM, therefore, you're able to create packages with the latest deffs, or use the intelligent updater. Remember, it's only when deploying from the SEPM that the package goes out without deffs, and it will use whatever deffs are there.
Feel free to message me if you would like to discuss this further...
Would you like to reply?
Login or Register to post your comment.