Some SEP scanning questions - we're stumped!

dan43's picture

Hi,

We have a few questions about SEP scanning, if anyone knows about any known scanning bugs, could you get back to us as soon as possible?

1.  When SEP performs a nightly full scan, does it change the parameters of any files, for example, date or  time?   Does SEP modify the date and time during the scan and then set it back to its original file date and time?

2.  Does SEP's full scan have any known side effects on any application or system services running other than its own?

3.  Has anyone out there come across SEP locking any files during a scan (realtime or nightly)?

We have POS software running on a Windows XP machine with SEP installed on it.  While using the software, an error message appears that says "Record cannot be found".  If we remove SEP, the problem seems to disappear.

Thanks for any information anyone has.

Dan

dfnkt_'s picture

Process Monitor

 Have you tried running proc mon? I would try running process monitor and seeing if I can duplicate the issue. Proc mon should show you what read/write to a file or reg key is causing the issue. 

Do you have other machines that run the same POS software you could test on?

You can find proc mon @ http://technet.microsoft.com/en-us/sysinternals/bb896645.aspx

Scuba Steve's picture

Does the POS software use a

Does the POS software use a database file? If there is a large file, then we may have a thread on it, and could cause an issue if the software attempts to write to it while we are scanning it. Usually this isn't an issue with smaller files as we can scan and move on pretty quickly.

It is a best practice to setup an exception so that we don't scan large DB files.

I hope this helps for you.
Also here is the link on setting up centralized exceptions:
http://service1.symantec.com/support/ent-security....

Bijay.Swain's picture

Try removing NTP and check

Try removing NTP and check whether your application workingor not.

Rafeeq's picture

Hi

1.  When SEP performs a nightly full scan, does it change the parameters of any files, for example, date or  time?   Does SEP modify the date and time during the scan and then set it back to its original file date and time?

it changes the last access time, does not put that back to original.still have some issues when trying to take incremental backup, as it changes the access time.

2.  Does SEP's full scan have any known side effects on any application or system services running other than its own?

It does not conflict with its own services however there are cases with UPHclean and VNC , conflicting (tamper protecion)
if you find any application conflicting u need to create an centralized exception.

3.  Has anyone out there come across SEP locking any files during a scan (realtime or nightly)?

Not much, but used to lock profiles ntuser.dat files its all fixed in MR5 now.

let me know if you have any further questions.

Rafeeq