Endpoint Protection

 View Only
  • 1.  Need instructions on how to Disable Scanning of Quarantined files

    Posted Jun 08, 2010 01:08 PM

    I'm running SEP MR6, and encountering the problem exactly as described in the Article http://service1.symantec.com/support/ent-security.nsf/854fa02b4f5013678825731a007d06af/5acc619d5a30571b882573980069a3cd?OpenDocument 
    The first workaround step is to:

    1.  Disable rescanning of quarantine upon receipt of new virus definitions.

    There are no instructions on how to do this, and I've looked through all the policies we have, but I didn't find a place to do this.  Google returns people talking about this step, but not a single result on how to achieve this in SEPM.  Anyone know what's up with this?  I'm running out of time, and the customer is understandably upset that their PC is reporting infections on a daily basis even though we've cleaned this PC already.

    Jake


  • 2.  RE: Need instructions on how to Disable Scanning of Quarantined files
    Best Answer

    Posted Jun 08, 2010 01:19 PM
    Try the folloing steps

    1. Login to the SEPM Console and Go to Policies Tab
    2. Edit the Antivirus and Antispyware policy of affected clients.
    3. In the policy editor click "Quarantine" on the left-hand menu.
    4. On the general tab click "Do nothing" under the heading "When new Virus Definitions Arrive"

    Check this article as well

    Title: 'Large amounts of temp files are being created in the xfer_tmp or 7.5/xfer folder and are being detected as threats.'
    Web URL: http://service1.symantec.com/support/ent-security.nsf/docid/2009042217073548?Open&seg=ent