Endpoint Protection

 View Only
Expand all | Collapse all

Symantec ENDPOINT 11 on Windows 7

  • 1.  Symantec ENDPOINT 11 on Windows 7

    Posted Jun 24, 2011 10:38 AM

    Hi, I am submitting the following probelma on a computer based on a Windows 7.

    Currently I have installed Endpoint on a domain controller as a server, and the clientes ofcourse.

    The infrastructure is mixed, there are computers with windows xp and windows 7. In the past I spent the next problem.

    When we are working EndPoint skip message notifying you that risk has been found and put them to analyze, followed analyzes and gives us the option to close. The issue is that is too many - in my opinion is pretty risk- 1700, which makes the sign is constantly jumping - this makes it annoying, and the result it is that the computer becomes slower. Files that are detected as virus spread, a file with the dot "tmp" extention, on the temporary folder. I tried deleting them by hand, but there's still something I'm generating and I realize that application can be.

    I tried a scan in Safe mode, ran it all, then restart and it worked fine for a day, but the problem returned.

    This dangerous problem that seems to be much more annoying. I would not know soluciorlo as the origin and therefore unaware of the scope.

    Search on the Symantec site and I get like that is a threat of generic type. One of the options is to analyze the scan.

    Any idea where to attack this?

    thank you very much



  • 2.  RE: Symantec ENDPOINT 11 on Windows 7

    Posted Jun 24, 2011 03:02 PM

    Hi,

    please, provide the risk logs,



  • 3.  RE: Symantec ENDPOINT 11 on Windows 7

    Posted Jun 24, 2011 05:06 PM

    Files that are detected as virus spread, a file with the dot "tmp" extention, on the temporary folder.

    This sounds like one of those cases in which .tmp files created when the Quarantine is rescanned as new definitions are received are being erroneously detected as a threat. This would explain why the number grows exponentially. Which version is SEP, and what is the actual threat name in your log?

    Provided this is not actually a live infection--it is suggested that you upgrade to the newest version (RU6 MP3) and remove all instances of the temp files (clearing the quarantine would probably help, too).

    Hope this helps,

    sandra