SEP MR4 MP2 will scan swap files or virtual memory?
Updated: 01 Oct 2010 | 10 comments
I know AV scan memory option is checked but SEP will scan swap files and virtual memory?
I also noticed on SEPM console --admin ---install package which has already had MR 5 package there even I didn't install it? Why?
discussion Filed Under:
Comments
MR5 package would have got
MR5 package would have got downloaded by Liveupdate ..SEPM does download the Latest packages as well..
I think Yes SEP will scan Virtual Memory aswell..
VMWARE-- SEP 12.1 vs McAfee vs Trend Micro
hi
it downloaded from Liveudpate, it did not install it ,it just downloaded it
if you want to disable further updates you can do so by going to
admin -servers-liveudpate-uncheck content updates,
if you want you can install the MU5 to your clients using autoupgrade feature of sepm
Upgrading clients by using AutoUpgrade
http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2009101503293948
Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq
The swap file is really just
The swap file is really just an extension of the operating system's handling of memory, so if SEP would have scanned it before it got loaded into RAM, it would've scanned it before it got stored in the pagefile. Now, if a threat was not detected by SEP and it was loaded into RAM and later cleaned from the system, I imagine it could still reside in the pagefile until another process needed that space. However, there really isn't a risk there, since the OS is not going to load those unallocated chunks of the pagefile anyway.
Eric C. Lukens IT Security Policy and Risk Assessment Analyst University of Northern Iowa
page
with respect to above statement it wont scan the page file
Does Symantec AntiVirus scan the Windows pagefile?
http://service1.symantec.com/support/ent-security.nsf/854fa02b4f5013678825731a007d06af/f6a650999fa226e488256ca80060b146?OpenDocument
Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq
we are talking about symantec
we are talking about symantec enpoint proection 11.0 not AV 10.2.
I noticed scan memory, loadpoint and seucirty risk every time scheduled or full scan runs.
1) I got an email back from a symantec support outside of USA --Costa Rica, he said SEP does scan pagefiles.
2) can we exclude it in centralized exception? Any risk to do so?
3)I noticed the scheduled scan only can be either dailt or weekly, it didn't give me an option to scheduled full scan twice a wekk or three time a week, any other option can configure the scan twice a week?
hi
it wont scan the page file
Does Symantec AntiVirus scan the Windows pagefile?
http://service1.symantec.com/support/ent-security.nsf/854fa02b4f5013678825731a007d06af/f6a650999fa226e488256ca80060b146?OpenDocument
follow this doc you would know
http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007121814372348
Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq
Hi, As of now, there is no
Hi,
As of now, there is no option in the liveupdate policy to scan the machine 2 times a week.
Aniket
You can create exception for
You can create exception for paging file.As far as I know there is no problem if you do an exclusion for this.I had seen in symantec doc itself ,if I am not wrong best practices for terminal server is that doc which recommends the exclusion of this file.
<<)I noticed the scheduled scan only can be either dailt or weekly, it didn't give me an option to scheduled full scan twice a wekk or three time a week, any other option can configure the scan twice a week?>>>
You can create two or three separate scheduled scan which will scan at two or three particular days to achieve this goal..
Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind
Symantec technical support
Symantec technical support scheduled scan and auto scan using the same engine and schema so pagefiles is scanned in SEP 11.
Symantec technical support
Symantec technical support scheduled scan and auto scan using the same engine and schema so pagefiles is scanned in SEP 11.
Would you like to reply?
Login or Register to post your comment.