Endpoint Protection

 View Only
  • 1.  Endpoint Protection Scanning Quarantine Directory Causing Endless Loop

    Posted Apr 20, 2012 12:34 AM

    I am runing Endpoint Protection on Vista64. I dont know the version because there does not seem to be an about tab or any other place where I can check the version number.

    Endpoint protection seems to have gone into an endless loop scanning the quarantine directory. I fixed the problem temporarily by shutting it down and deleting the contents of the directory. I would imangine that the problem will reoccur as soon as another file gets put in the quarantine directory.

    I tried to create a scanning exception, but the program apprears to only allow individual files to be specified rather than directories.

    This is such a silly problem. I cannot believe that Endpoint does not know not to scan its own quarantine directory!

     



  • 2.  RE: Endpoint Protection Scanning Quarantine Directory Causing Endless Loop

    Posted Apr 20, 2012 12:45 AM

    You can check SEP Version.

    As per your comment you need to scan quarantine directory ?

     



  • 3.  RE: Endpoint Protection Scanning Quarantine Directory Causing Endless Loop

    Posted Apr 20, 2012 05:29 AM

    Sounds like a known issue, mostly resolved in SEP 11.0.7101. First of all, you should upgrade SEP to the newest versions (SEP 11.0.7101 or SEP 12.1.1000).

    For background of the issue see this post by Ryan_Dasso:

    https://www-secure.symantec.com/connect/forums/generic-trojan-dwhtmp-temp-folder#comment-5191661

    If you have access to a SEPM, you can disable the re-scanning of the quarantine:

    When new virus definitions are in place and the quarantine is being scanned, a DWH file is created and detected by Auto-Protect

    http://www.symantec.com/docs/TECH102953

     

     



  • 4.  RE: Endpoint Protection Scanning Quarantine Directory Causing Endless Loop

    Posted Apr 20, 2012 05:56 AM

    Hello,

    Greg refers you to right solutions however i also prefer to don't use Quarantine action. Clean and Delete actions are much effective due to some kind problems of Quarantine like this one.

     

    Regards,

    Oykun



  • 5.  RE: Endpoint Protection Scanning Quarantine Directory Causing Endless Loop

    Posted Apr 20, 2012 06:00 AM

    Hi Randy,

    "Thumbs up" to the advice, above.  Note that it is possible to configure SEP not to scan the quarantine after new LiveUpdate definitions arrive- you can disable that, too.

    Is the behavior that you are seeing on these same APQ or DWH files?  Or is there another issue you are seeing?