Symantec Endpoint Protection 12.1RU2, scans and finds threat in svchost.exe
We are having problems with some of our computers and I am trying to track down the exact cause and in doing so I ran across some things in the event logs of several computers that should not be there. We are running SEP server and clients 12.1.2, Server 2008 R2 and Windows 7 Enterprise 64Bit clients.
Every since we upgraded to this version, one by one people have complained that Outlook keeps locking up on them and other strange thing have happened like the machines will not get past the log off screen when they shutdown. One computer will not show the Username and password fields for about 10-20 minutes after CTRL-ALT-DLT. PS..We also deployed SEE Device Control and Removable Storage at the same time.
1st, I found this: Security Risk Found!Hosts File Change in File: c:\windows\system32\svchost.exe by: SONAR scan. Action: Leave Alone succeeded. Action Description: The file was left unchanged. (application logs)
This is showing up on a lot of machines so I don't think it is a virus.
2nd I found this(could be another application other than SEP): The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
Comments 2 Comments • Jump to latest comment
Hello,
In reference to the Case 1, check these Articles:
Error: "Security Risk Found! Hosts File Change in File: c:\windows\system32\svchost.exe by: SONAR scan"
http://www.symantec.com/docs/TECH164391
Symantec Endpoint Protection 12.1: Blocked System Change Events produce unexpected messages
http://www.symantec.com/docs/TECH161646
Creating an DNS or Host File Change Exception in Symantec Endpoint Protection Manager 12.1 RU1 MP1 and above.
https://www-secure.symantec.com/connect/articles/creating-dns-or-host-file-change-exception-symantec-endpoint-protection-manager-121-ru1-mp1
In reference to the Case 2, I am not sure if that is related to SEP issue.
Hope that helps!!
Mithun Sanghavi
Symantec Technical Support Engineer, SEP
MIM | MCSA | MCTS | STS | ITIL v3
Twitter: @mithun_sanghavi
Don't forget to mark your thread as 'SOLVED' with the answer that best helps you.<&a
Thanks for the info. After reading through this I found where the file was already added to the exceptions list as log only, but I don't remember ever seeing that when the 11.x clients were installed. I just left it alone for now and set to log only.
As far as the second error that I saw, it has nothing to do with the new clients. I went back a little further in the event logs to sometime last summer and I saw the same error so that is something different all together.
Thanks for the input.
Would you like to reply?
Login or Register to post your comment.