Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

Symantec EndPoint Protection and SysPrep

Updated: 21 Sep 2010 | 2 comments
LGS's picture
0 0 Votes
Login to vote

I'd like to suggest a change for the Symantec EndPoint client.  In short, I'd like to suggest that you support Microsoft's SysPrep Provider feature (http://technet.microsoft.com/en-us/library/ee676646%28WS.10%29.aspx). 

Supporting this feature would allow SysPrep to correctly remove the keys and files that Symantec suggests here (http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007110510364248) in an automated and orderly fashion.  It would also allow Symantec to match the cleanup requirements to the currently installed client, since the provider can be updated as the cleanup requirements of the other client components change.  This provides a much better solution for administrators going forward than googling symantec.com and hoping you have found the most current instructions.

If I were to spec this out, I would envision that Symantec's Sysprep provider would:

Cleanup phase:
Remove all log files
Remove all events
Empty the quarantine bin
Remove any old versions of virus definitions
(Optionally) remove current virus definitions

Generalize phase:
Remove all hardware id keys (registry and xml)

Specialize phase:
Create the new hardware id
Trigger an immediate LiveUpdate call to get both the latest program updates and definitions.

I'm tempted to write this myself as the basics of creating such a DLL are remarkably simple.  However, doing this outside Symantec is impractical.  In order to remove some of these keys/files, the related services must be shut down.  I (like many administrators) have toggled the switch from "Allow tampering" to "Disable Tampering."  As a result, shutting down those services is all but impossible.  Presumably a Symantec-provided solution could resolve that problem.

Also (presumably) a Symantec solution would be more complete, since you would know where all the bodies (files, registry keys, etc) are buried.

Comments

Grant_Hall's picture
21
Mar
2010
0 Votes 0
Login to vote

Just wanted to let you know

Just wanted to let you know that you should post this in our ideas section of the forums. That way users can vote on it, and you can track the process as it is implemented. Ideas can be created here https://www-secure.symantec.com/connect/security/ideas . I think this is a good one, so if you don't end up posting it there I think I will come back and cut and paste your idea for you.

Thanks
Grant

Please don't forget to mark your thread solved with whatever answer helped you : )

LGS's picture
21
Mar
2010
0 Votes 0
Login to vote

I was not familiar with that

I was not familiar with that section.  Thanks for pointing it out.

Per your suggestion, I have copied this idea to https://www-secure.symantec.com/connect/idea/symantec-endpoint-protection-and-sysprep

Anyone who uses SysPrep, or who is considering using it for Win7 deployments is encouraged to visit that link and click the "Agree" button.

In a related question, is there a place for 3rd party add-ins for SEP?  If Symantec elects not to do this, or if there is likely to be a lengthy delay, I might be interested in creating this myself (as best I can).  But there's little point if I am the only person who would benefit from it.