Endpoint Protection

 View Only
Expand all | Collapse all

configuration value changed..???/endpoint protection

Migration User

Migration UserMay 23, 2011 04:35 PM

Migration User

Migration UserMay 23, 2011 04:50 PM

Migration User

Migration UserMay 23, 2011 05:03 PM

Migration User

Migration UserMay 23, 2011 05:04 PM

  • 1.  configuration value changed..???/endpoint protection

    Posted May 23, 2011 12:43 PM

    my antivirus and antispyware protection failed to load resulting in a warning. today there was NO warning but by checking system log it indcates a:

    change in configuration value....HKLM\SOFTWARE\Symantec\Smantec Endpoint Protection

    my concern is is this an indication of a major problem in my protection?

    hope someone can help. thanks in advance.



  • 2.  RE: configuration value changed..???/endpoint protection

    Posted May 23, 2011 12:45 PM

    can you post the full path?

    if you change something on the manager ; the change would get propagated to clients in terms of change in registry value.

    check the complete path; it should be related to u r policy change..

    no problem with security.



  • 3.  RE: configuration value changed..???/endpoint protection

    Trusted Advisor
    Posted May 23, 2011 12:57 PM

    Hello,

    Please Run the Symantec Support Tool and Let us know what Errors do you receive?

     

    About the Symantec Endpoint Protection Support Tool
     
     
    Symantec Support Tool: How to collect suspicious files and submit the samples to the Symantec Security Response Team.
     


  • 4.  RE: configuration value changed..???/endpoint protection

    Posted May 23, 2011 03:06 PM

    sorry..dummy re the full path. where can i check that to give to you. thanks so much for replying. i may be ok but i've never seen a configuration change before in my log.



  • 5.  RE: configuration value changed..???/endpoint protection

    Posted May 23, 2011 03:16 PM

    open sep client

    click on logs

    check the system log ; this wil show u the configuration change.



  • 6.  RE: configuration value changed..???/endpoint protection

    Posted May 23, 2011 03:28 PM

    mithun, it stated WARNING. some services and drivers are not running

                                              some of the client services are not running.

    i'm a home user so not too good with this. i was able with your help to run the support tool. thanks. but obviously my concerns were well founded even tho system tells me i'm ok. your suggestions, please.

    jan



  • 7.  RE: configuration value changed..???/endpoint protection

    Posted May 23, 2011 03:34 PM

    config change in system log

    HKLM\SOFTWARE\Symantec\Symantec Endpoint Protection

    am i sending you this correctly? i've never had a conf. change. i did not do it. thus my concerns.

    ran support tool-said some systems and drivers aren't running, some client services aren't running

    FYI i use SEP for private use. NO other pc's involved with my SEP. 



  • 8.  RE: configuration value changed..???/endpoint protection

    Trusted Advisor
    Posted May 23, 2011 03:43 PM

    Hello,

    Please Let us know, does it specify what services and drivers are not running?

    If you are unable to find it, please collect the Log by saving the same for support.

    Upload the Logs and we will get back to you.



  • 9.  RE: configuration value changed..???/endpoint protection

    Posted May 23, 2011 03:49 PM

    as far as I know It will show information like value changed from 0 to 1; if u change something live update settings from manual to automatic, so any changes in settings will change in registry. Not related with security issue. can ignore that if thats not showing a full path of the key which is changed.



  • 10.  RE: configuration value changed..???/endpoint protection

    Posted May 23, 2011 04:11 PM

    rafeeq

    value changed from 1 to 0, then 0 to '13060667041', etc



  • 11.  RE: configuration value changed..???/endpoint protection

    Posted May 23, 2011 04:21 PM

    as I mentioned earlier; there should be complete path so that we can know which settings value changed :)

    I'm not sure why full path is not showing up :) 

    do u see any such path??



  • 12.  RE: configuration value changed..???/endpoint protection

    Posted May 23, 2011 04:35 PM

     

    Event Computer User Logged By Description          
    Scan Omission GRAMMY-PC Grammy Scheduled scan Could not scan 1 files inside c:\Windows\winsxs\x86_microsoft-windows-localizeddrivers_31bf3856ad364e35_6.0.6000.16386_en-us_7c961b0ac7cd3eec\locdrv.cab due to extraction errors encountered by the Decomposer Engines.
    Scan Omission GRAMMY-PC Grammy Scheduled scan Could not scan 1 files inside c:\hotfix\WINDOWS6.0-KB955430-X86.MSU due to extraction errors encountered by the Decomposer Engines.
    Scan Omission GRAMMY-PC Grammy Scheduled scan Could not scan 1 files inside c:\hotfix\Windows6.0-KB955430-x86.cab due to extraction errors encountered by the Decomposer Engines.
    Scan Omission GRAMMY-PC Grammy Scheduled scan Could not scan 2 files inside c:\hotfix\WINDOWS6.0-KB955430-X64.MSU due to extraction errors encountered by the Decomposer Engines.
    Scan Omission GRAMMY-PC Grammy Scheduled scan Could not scan 2 files inside c:\hotfix\Windows6.0-KB955430-x64.cab due to extraction errors encountered by the Decomposer Engines.
    Definition File Loaded GRAMMY-PC Grammy System New virus definition file loaded. Version: 130522b.    
    Scan Omission GRAMMY-PC Grammy Scheduled scan Could not scan 1 files inside c:\Windows\winsxs\x86_microsoft-windows-localizeddrivers_31bf3856ad364e35_6.0.6000.16386_en-us_7c961b0ac7cd3eec\locdrv.cab due to extraction errors encountered by the Decomposer Engines.
    Scan Omission GRAMMY-PC Grammy Scheduled scan Could not scan 1 files inside c:\hotfix\WINDOWS6.0-KB955430-X86.MSU due to extraction errors encountered by the Decomposer Engines.
    Scan Omission GRAMMY-PC Grammy Scheduled scan Could not scan 1 files inside c:\hotfix\Windows6.0-KB955430-x86.cab due to extraction errors encountered by the Decomposer Engines.
    Scan Omission GRAMMY-PC Grammy Scheduled scan Could not scan 2 files inside c:\hotfix\WINDOWS6.0-KB955430-X64.MSU due to extraction errors encountered by the Decomposer Engines.
    Scan Omission GRAMMY-PC Grammy Scheduled scan Could not scan 2 files inside c:\hotfix\Windows6.0-KB955430-x64.cab due to extraction errors encountered by the Decomposer Engines.
    Configuration Changed GRAMMY-PC Grammy System Changed value 'HKLM\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Storages\Filesystem\RealTimeScan\APEOff' from '1306066764' to '0'
    Configuration Changed GRAMMY-PC Grammy System Changed value 'HKLM\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Storages\Filesystem\RealTimeScan\OnOff' from '0' to '1'
    Configuration Changed GRAMMY-PC Grammy System Symantec Endpoint Protection Internet E-mail Auto-Protect Enabled
    Configuration Changed GRAMMY-PC Grammy System Changed value 'HKLM\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Storages\InternetMail\RealTimeScan\OnOff' from '0' to '1'
    Configuration Changed GRAMMY-PC Grammy System Symantec Endpoint Protection Internet E-mail Auto-Protect Disabled
    Configuration Changed GRAMMY-PC Grammy System Changed value 'HKLM\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Storages\InternetMail\RealTimeScan\OnOff' from '1' to '0'
    Configuration Changed GRAMMY-PC Grammy System Changed value 'HKLM\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Storages\Filesystem\RealTimeScan\APEOff' from '0' to '1306066764'
    Configuration Changed GRAMMY-PC Grammy System Changed value 'HKLM\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Storages\Filesystem\RealTimeScan\OnOff' from '1' to '0'
    Symantec Endpoint Protection Startup GRAMMY-PC SYSTEM System Symantec Endpoint Protection services startup was successful.

    Symantec Endpoint Protection Auto-Protect load error

    i hope i'm doing this right. does this help?-JAN

    GRAMMY-PC SYSTEM System Symantec Endpoint Protection Auto-Protect failed to load.  


  • 13.  RE: configuration value changed..???/endpoint protection

    Posted May 23, 2011 04:50 PM

     

    Event

    Computer

    User

    Logged By

    Description

     

     

     

     

     

    Scan Omission

    GRAMMY-PC

    Grammy

    Scheduled scan

    Could not scan 1 files inside c:\Windows\winsxs\x86_microsoft-windows-localizeddrivers_31bf3856ad364e35_6.0.6000.16386_en-us_7c961b0ac7cd3eec\locdrv.cab due to extraction errors encountered by the Decomposer Engines.

    Scan Omission

    GRAMMY-PC

    Grammy

    Scheduled scan

    Could not scan 1 files inside c:\hotfix\WINDOWS6.0-KB955430-X86.MSU due to extraction errors encountered by the Decomposer Engines.

    Scan Omission

    GRAMMY-PC

    Grammy

    Scheduled scan

    Could not scan 1 files inside c:\hotfix\Windows6.0-KB955430-x86.cab due to extraction errors encountered by the Decomposer Engines.

    Scan Omission

    GRAMMY-PC

    Grammy

    Scheduled scan

    Could not scan 2 files inside c:\hotfix\WINDOWS6.0-KB955430-X64.MSU due to extraction errors encountered by the Decomposer Engines.

    Scan Omission

    GRAMMY-PC

    Grammy

    Scheduled scan

    Could not scan 2 files inside c:\hotfix\Windows6.0-KB955430-x64.cab due to extraction errors encountered by the Decomposer Engines.

    Definition File Loaded

    GRAMMY-PC

    Grammy

    System

    New virus definition file loaded. Version: 130522b.

     

     

    Scan Omission

    GRAMMY-PC

    Grammy

    Scheduled scan

    Could not scan 1 files inside c:\Windows\winsxs\x86_microsoft-windows-localizeddrivers_31bf3856ad364e35_6.0.6000.16386_en-us_7c961b0ac7cd3eec\locdrv.cab due to extraction errors encountered by the Decomposer Engines.

    Scan Omission

    GRAMMY-PC

    Grammy

    Scheduled scan

    Could not scan 1 files inside c:\hotfix\WINDOWS6.0-KB955430-X86.MSU due to extraction errors encountered by the Decomposer Engines.

    Scan Omission

    GRAMMY-PC

    Grammy

    Scheduled scan

    Could not scan 1 files inside c:\hotfix\Windows6.0-KB955430-x86.cab due to extraction errors encountered by the Decomposer Engines.

    Scan Omission

    GRAMMY-PC

    Grammy

    Scheduled scan

    Could not scan 2 files inside c:\hotfix\WINDOWS6.0-KB955430-X64.MSU due to extraction errors encountered by the Decomposer Engines.

    Scan Omission

    GRAMMY-PC

    Grammy

    Scheduled scan

    Could not scan 2 files inside c:\hotfix\Windows6.0-KB955430-x64.cab due to extraction errors encountered by the Decomposer Engines.

    Configuration Changed

    GRAMMY-PC

    Grammy

    System

    Changed value 'HKLM\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Storages\Filesystem\RealTimeScan\APEOff' from '1306066764' to '0'

    Configuration Changed

    GRAMMY-PC

    Grammy

    System

    Changed value 'HKLM\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Storages\Filesystem\RealTimeScan\OnOff' from '0' to '1'

    Configuration Changed

    GRAMMY-PC

    Grammy

    System

    Symantec Endpoint Protection Internet E-mail Auto-Protect Enabled

    Configuration Changed

    GRAMMY-PC

    Grammy

    System

    Changed value 'HKLM\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Storages\InternetMail\RealTimeScan\OnOff' from '0' to '1'

    Configuration Changed

    GRAMMY-PC

    Grammy

    System

    Symantec Endpoint Protection Internet E-mail Auto-Protect Disabled

    Configuration Changed

    GRAMMY-PC

    Grammy

    System

    Changed value 'HKLM\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Storages\InternetMail\RealTimeScan\OnOff' from '1' to '0'

    Configuration Changed

    GRAMMY-PC

    Grammy

    System

    Changed value 'HKLM\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Storages\Filesystem\RealTimeScan\APEOff' from '0' to '1306066764'

    Configuration Changed

    GRAMMY-PC

    Grammy

    System

    Changed value 'HKLM\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Storages\Filesystem\RealTimeScan\OnOff' from '1' to '0'

    Symantec Endpoint Protection Startup

    GRAMMY-PC

    SYSTEM

    System

    Symantec Endpoint Protection services startup was successful.

    Symantec Endpoint Protection Auto-Protect load error

    GRAMMY-PC

    SYSTEM

    System

    Symantec Endpoint Protection Auto-Protect failed to load.

     



  • 14.  RE: configuration value changed..???/endpoint protection

    Posted May 23, 2011 04:50 PM

    Yes, this is the path I was talking about ( not sure if we need to read top to bottom or bottom to top, let me know the order)

     

    Changed value 'HKLM\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Storages\InternetMail\RealTimeScan\OnOff' from '0' to '1'

    it changed from disabled to enable.this happens when system scans the files and makes the settigns changes accordingly.

    Changed value 'HKLM\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Storages\Filesystem\RealTimeScan\APEOff' from '1306066764' to '0'

    Real time scan is disabled.

    Changed value 'HKLM\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Storages\Filesystem\RealTimeScan\OnOff' from '0' to '1'

    Enabled 

    http://aka-community.symantec.com/connect/articles/symantec-endpoint-protection-few-registry-tweaks



  • 15.  RE: configuration value changed..???/endpoint protection

    Posted May 23, 2011 04:56 PM

    its showing how symantec settings changed values during the scan and enabled themselves to perform the scan with all the outlook, internet email protection.

     

    "Could not scan [#] files inside [path][filename] due to extraction errors encountered by the Decomposer Engines" during a scan

     

    http://www.symantec.com/business/support/index?page=content&id=TECH99755&key=54619&actp=LIST



  • 16.  RE: configuration value changed..???/endpoint protection

    Posted May 23, 2011 05:01 PM

    Can you tell us what is the version number of the product you have installed? Click Help>About to show build number.

     

    Thanks,

    Thomas



  • 17.  RE: configuration value changed..???/endpoint protection

    Posted May 23, 2011 05:03 PM
      |   view attached

    i'm so frustrated.

    Attachment(s)

    zip
    endpoint.zip   2 KB 1 version


  • 18.  RE: configuration value changed..???/endpoint protection

    Posted May 23, 2011 05:04 PM

    11.0

    thanks for helping me!



  • 19.  RE: configuration value changed..???/endpoint protection

    Posted May 23, 2011 05:08 PM

    if i leave my pc for awhile with symantec site up is my pc safe-meaning no intrusion? i know it's a secured site but not sure re my pc. 



  • 20.  RE: configuration value changed..???/endpoint protection

    Posted May 23, 2011 05:09 PM

    We need the build number for SEP 11.

    Example 11.0.6300 803



  • 21.  RE: configuration value changed..???/endpoint protection

    Trusted Advisor
    Posted May 24, 2011 06:20 AM

    Hello,

    Momacita, let me get things  absolutely clear and right here for you.

    Previous you said: - 

    1) Your antivirus and antispyware protection failed to load resulting in a warning. Later, there was NO warning but by checking system log it indcated a change in configuration value....HKLM\SOFTWARE\Symantec\Smantec Endpoint Protection.

    2) Later on the Logs uploaded shows as follows:

     

    Event

    Computer

    User

    Logged By

    Description

     

     

     

     

     

    Scan Omission

    GRAMMY-PC

    Grammy

    Scheduled scan

    Could not scan 1 files inside c:\Windows\winsxs\x86_microsoft-windows-localizeddrivers_31bf3856ad364e35_6.0.6000.16386_en-us_7c961b0ac7cd3eec\locdrv.cab due to extraction errors encountered by the Decomposer Engines.

    Scan Omission

    GRAMMY-PC

    Grammy

    Scheduled scan

    Could not scan 1 files inside c:\hotfix\WINDOWS6.0-KB955430-X86.MSU due to extraction errors encountered by the Decomposer Engines.

     

     

    After looking at these Logs, I would simply request you to Simply not to worry. 

    These errors do not indicate a malfunction in the product. The decomposer errors cannot be eliminated from system logs; they may be useful in alerting a customer to corrupt archives or deeply-compressed files that should be excluded from scans. 

    This event is typically encountered when any of the following occurs:

     

    • You scan a file whose content resembles a MIME-encoded archive.
    • You scan an archived file whose compressed size is less than the decomposer's 10-byte minimum.
    • You scan a compressed archive that contains a password-protected file;
      The decomposer engine cannot provide the password required to gain access to the file, so it will be omitted during a scan.
    • You scan files that have been locked for access by the operating system and access cannot be released to the scanner because the file is in use.
    • You scan files that are recursively compressed to a depth that is more than the scan engine is set to scan. 
      By default, the scan engine is set to scan a maximum depth of three levels (for example, a zip file contained within a zip file contained within another zip file).
    • You scan files with LH7 compression, which is not a supported format. 
      These compressed files commonly have a .lzh extension, and they are omitted by the scan.
    • You scan files that are in use by another user. 
      This is most commonly seen when you scan user directories and shared folders and that user has the document in question opened for editing.
    • You scan files that have file system permissions set to deny access.
    • Corruption exists in the virus definitions.
    • Archived files have an extension that is not set in a Custom Scan's "selected extensions".

     

     

    Work on the steps provided below for checking few things on your machine.

    1) Click on Start > Run> Type "servicers.msc" (without quotes)

    2) Services window would open up. Scroll down to the Service that says "Symantec Endpoint Protection" and "Symantec Management Client"

    Make sure these services are in status "Started" and Startup Type is "Automatic", you have nothing to worry.

     

    3) Open the Symantec Endpoint Protection Client, and check it the Virus definitions are Latest and upto date.

    4) If, the Definitions are not updated, Visit the Below Website:

    http://www.symantec.com/business/security_response/definitions/download/detail.jsp?gid=savce

    Download and Run the Symantec Intelligent Updater, to Update your SEP Client on your machine.

     

     

     

    Hope these Steps are clear!!!

     



  • 22.  RE: configuration value changed..???/endpoint protection

    Posted May 24, 2011 03:54 PM

    just to be safe i went to intel.updater. the only thing i'm not sure of is this-

    your example listed 20110523-034-v5i32.exe FTP

    when i went to site the listing WAS

    20110524-002-v5i32.exe FTP

    is this the one i should download from the list tho it's different from your circled listing?

     

    AS for the other things u suggested your procedures were very clear!...thanks so much..but i couldn't find if definitions were current. however, i do have it set for everyday/LU and checked in my log. so can i assume i'm ok relying on that?

    FYI this all happened after microsoft downloaded IE9 and an important update on my pc... right after. i don't know but it makes me suspicious. they also turned on the windows firewall. i knew when checking everything that they had done that with the download. i believe symantec advises windows firewall not be on when using their product. so i turned it back off. am i correct?

    sincerely

    jan



  • 23.  RE: configuration value changed..???/endpoint protection
    Best Answer

    Trusted Advisor
    Posted May 26, 2011 06:12 AM

    Hello,

    Yes, you are correct. This is because the dates keeps changing every day.

    Incase, you are carrying IE 9, I would recommend checking these few articles provided below ( we found few issues customers facing with IE 9.

     

    To find more, Simply Click on the Link below and it would direct you to the Symantec Articles:
     
     
     
     
     
    If, my solutions have Helped you please click on the "Solved" Button.