Endpoint Protection

 View Only
  • 1.  Cleanwipe deleted ENTIRE D:\Program Files folder

    Posted Mar 31, 2015 11:18 AM

    Hello there,

    I'm my company we've got several installations of SEP 12.1.4100.4126.105, for which the home folder is C:\Program Files\Symantec\Symantec Endpoint Protection\12.1.4100.4126.105, but in order to save space from the C drive, the definitions are stored in D:\Program Files\12.1.4100.4126.105.

    Last weekend we had to reinstall SEP on a few server for which we had to execute CleanWipe, as a result, almost all D:\Program Files folder was deleted. We have Object Auditing enabled on D drive for that server. Severll events like the following were registered:

    Object Server:    Security
        Object Type:    File
        Object Name:    D:\Program Files\PostgreSQL\
        Handle ID:    688
        Operation ID:    {0,943412}
        Process ID:    3268
        Image File Name:    C:\Fix-Temp\CleanWipe.exe
        Primary User Name:    XXXXXXXX
        Primary Domain:    XXXXXXXX
        Primary Logon ID:    (0x0,0x98276)
        Client User Name:    -
        Client Domain:    -
        Client Logon ID:    -
        Accesses:        DELETE
                ReadData (or ListDirectory)
                
        Privileges:        -
        Restricted Sid Count: 0

     

    Cleanwipe version is 12.1.5337.5000.

    I need to understand how CleanWipe works. Is is possible to know exactly everything that will delete before execution?

    Thanks in advance for any help provided,

    Kind Regards!



  • 2.  RE: Cleanwipe deleted ENTIRE D:\Program Files folder

    Posted Mar 31, 2015 11:57 AM

    You may need to contact support to get an exact list of every directory and file that it removes



  • 3.  RE: Cleanwipe deleted ENTIRE D:\Program Files folder

    Trusted Advisor
    Posted Apr 01, 2015 02:17 AM

    Hello,

    " While CleanWipe is not a “secret” utility, it is a very powerful one.  The reason Symantec requests that people engage technical support to get this utility is because of the potential to remove more than intended (for example, all AV from an entire environment).  As a best practice, we have recommended that users as well as partners consult with tech support to ensure that it is being used in the best way for that specific situation and environment.

    After thoughtful consideration and conversation we have determined that Symantec’s best practice recommendation for the availability and usage of CleanWipe remains for users and/or partners to engage Technical Support prior to using this tool.  We kept this recommendation because of the security risks to users and environments beyond what may be initially intended. 

    CleanWipe has a specific use. Generally speaking, users should be able to use Add/Remove Programs to uninstall SEP.  CleanWipe exists for those situations where Add/Remove programs may not solve the users problems.  CleanWipe used by an inexperienced technician can result in loss of functionality beyond what is intended which could cause severe customer dissatisfaction.  By working with Support we can ensure that the CleanWipe tool is being used appropriately and with full understanding of the situation that can help mitigate potential misapplication."

     

    Please create a Case with Symantec Technical Support

     

    QuickStart Guide - Create and Manage Support Cases in SymWISE

    http://www.symantec.com/docs/HOWTO31132

    How to update a support case and upload diagnostic files with MySupport

    http://www.symantec.com/docs/TECH71023

    OR

    Regional Support Telephone Numbers:

    United States: https://support.broadcom.com (407-357-7600 from outside the United States)

    Australia: 1300 365510 (+61 2 8220 7111 from outside Australia)

    United Kingdom: +44 (0) 870 606 6000

    Additional contact numbers: http://www.symantec.com/business/support/contact_techsupp_static.jsp

    Hope that helps!!



  • 4.  RE: Cleanwipe deleted ENTIRE D:\Program Files folder

    Posted Apr 02, 2015 01:03 AM

    contact with symantec tech support.