Endpoint Protection

 View Only
  • 1.  Is Our SEP Scan the Registry of the system.

    Posted Oct 19, 2012 05:19 AM

    Hi,

    Is our SEP doing the Registry scan in every time while schedule scan as well as manually?

    If so then how we will get the log for the same?



  • 2.  RE: Is Our SEP Scan the Registry of the system.

    Posted Oct 19, 2012 05:26 AM

    HI,

    Check this artical may be help

    Information on Symantec Endpoint Protection Scans

    https://www-secure.symantec.com/connect/articles/information-symantec-endpoint-protection-scans

     

    You can find it in the Scan log on the client

    In the SEPM, go to Monitors >> Logs and set the log to show Scan

    Check this thread

    https://www-secure.symantec.com/connect/forums/when-did-full-scheduled-scan-end



  • 3.  RE: Is Our SEP Scan the Registry of the system.

    Posted Oct 19, 2012 06:03 AM

    Hi Ashish,

    Thanks to response but if I enable to client debug log for scanning I can see the all the file which had been scanned by SEP but I could not see any registry Entry which has been Scan on it.



  • 4.  RE: Is Our SEP Scan the Registry of the system.

    Posted Oct 19, 2012 08:47 AM

    Try Process Monitor, it should show the registry events:

     

    How to Configure Sysinternals' Process Monitor to Record Symantec's Auto-Protect Events

    http://www.symantec.com/business/support/index?page=content&id=TECH98079



  • 5.  RE: Is Our SEP Scan the Registry of the system.

    Posted Oct 20, 2012 12:31 AM

    Thanks Brian81,

    But if our SEP scan the registry of System then there must be some evidence that we can enable through SEP End Also?



  • 6.  RE: Is Our SEP Scan the Registry of the system.

    Posted Oct 21, 2012 02:37 AM

    Can you please suggest.

    yet this is not close.



  • 7.  RE: Is Our SEP Scan the Registry of the system.

    Posted Oct 22, 2012 05:06 AM

    can any one suggest on this?



  • 8.  RE: Is Our SEP Scan the Registry of the system.

    Broadcom Employee
    Posted Oct 22, 2012 05:23 AM

    enable vpdebug and check for the files that are scanned

    http://www.symantec.com/business/support/index?page=content&id=TECH102939&locale=en_US



  • 9.  RE: Is Our SEP Scan the Registry of the system.

    Posted Oct 22, 2012 05:36 AM

    Hi Pete_4u2002,

     

    I already did this and I have not found any entry of registry.