Endpoint Protection

 View Only
Expand all | Collapse all

how to administering SEP 12.1

Migration User

Migration UserJul 01, 2014 03:40 PM

  • 1.  how to administering SEP 12.1

    Posted Jul 01, 2014 02:29 PM

    I want to know how can i do to delete all virus on thedesk stop, because after scan there always some virus still infected,

     



  • 2.  RE: how to administering SEP 12.1

    Posted Jul 01, 2014 02:32 PM
    Did you configure the scan to delete when a risk is found? What action is it taking?


  • 3.  RE: how to administering SEP 12.1

    Posted Jul 01, 2014 03:09 PM

    yes, but the virus such as : vbs.runauto, w32.chir.b@mm, trojan.gen, and suspicius.epi , still infect



  • 4.  RE: how to administering SEP 12.1

    Posted Jul 01, 2014 03:28 PM
    Download the symhelp tool and run the threat analysis scan from it


  • 5.  RE: how to administering SEP 12.1

    Posted Jul 01, 2014 03:40 PM

    Thank you i 'm try to do it,and i 'll feedback



  • 6.  RE: how to administering SEP 12.1

    Posted Jul 02, 2014 01:25 AM

    Update your system with latest defintion and scan for clean it.

    Submit the pending virus file to symantec for analysis. They can provide you the link of

    Submit the virus for analysis. Symantec team will provide you the rapid release defintion against that viruses.

    https://submit.symantec.com/websubmit/bcs.cgi

    Run threat analysis scan and submit the report to symantec

    How to run the Threat Analysis Scan in Symantec Help (SymHelp)

    Article:TECH215519  |  Created: 2014-03-03  |  Updated: 2014-03-07  |  Article URL http://www.symantec.com/docs/TECH215519

     



  • 7.  RE: how to administering SEP 12.1

    Posted Jul 10, 2014 07:13 AM

    Incase you have find any of the suspected file in your system which is not be detect by antivirus, you can chech the result of that virus from virustotal site. You can submit virus here, it will show you the report of the company which have detect that file as a virus.

    https://www.virustotal.com

    If number of site detect it as avirus and symantec not be detected then you can submit it to symantec security for analysis.

    https://submit.symantec.com/websubmit/gold.cgi

    Symantec will provide you the ticket and will release the rapid release defintion against that virus and confirm you on email.

    http://www.symantec.com/security_response/definitions/rapidrelease/

    You can upload that file to clean it.

     

     



  • 8.  RE: how to administering SEP 12.1

    Posted Sep 15, 2014 01:15 PM

    Hi all,

    please i have SEPM 12.x on and sqlserver2008R2, but when i want to loggin the SEPM always error 4096 and 17806 ; also 17452,  i want can you tell me what to do, because the clients still no uodate from SEP,



  • 9.  RE: how to administering SEP 12.1

    Posted Sep 15, 2014 01:19 PM

    Have you restarted the SEPM?

    Enable SEPM debugging:

    How to debug the Symantec Endpoint Protection Manager



  • 10.  RE: how to administering SEP 12.1

    Posted Sep 15, 2014 01:20 PM

    check this articles

    Event ID 4096 Java -1 error in event viewer, SEPM service will not stay in started state. "Failed to connect to server" message during login to SEPM.

    Article:TECH181655 | Created: 2012-02-17 | Updated: 2012-12-17 | Article URL http://www.symantec.com/docs/TECH181655


  • 11.  RE: how to administering SEP 12.1

    Posted Sep 15, 2014 02:05 PM

    Hi james and Brian,

    thanks alot for showing insterest to my request

    but i 'm already many times restart the SEPM but no thing change only the same error in the windos log, so currently sepm service doen't yet stoped itself,but it couldn't put the client up to date due to error17806  and 17452



  • 12.  RE: how to administering SEP 12.1

    Posted Sep 15, 2014 02:07 PM

    Is there plenty of space on C:?

    Run the symhelp tool to see what it shows:

    Troubleshooting computer issues with the Symantec Help support tool

    http://www.symantec.com/docs/HOWTO80839



  • 13.  RE: how to administering SEP 12.1

    Posted Sep 15, 2014 03:24 PM

    Hi

     

    Please download norton power eraser from the link below

    https://security.symantec.com/nbrt/npe.aspx

    Please connect the PC online and opne Norton Power eraser and run "Scan for risk" and also go to advanced->system scan.

    If the infection still presists

     

    Then run Symantec Endpoint Recovery Tool (SERT)

    http://www.symantec.com/docs/TECH131685

    For which you will require a PIN you have to contact support for that

     

    Create an Case with Technical Support. They will provide you the Serial Number for SERT Tool.

    Followers of this thread may be interested in a new white paper on how to customize SERT.  The steps it contains are powerful, though unsupported.

    How to Customize Symantec Endpoint Recovery Tool (3rd Party Utility Integration)
    https://www-secure.symantec.com/connect/articles/how-customize-symantec-endpoint-recovery-tool-3rd-party-utility-integration

    To create a Case OR call Symantec Technical Support, check below:

    How to create a new case in MySupport

    http://www.symantec.com/docs/TECH58873

    Regional Support Telephone Numbers:

    United States: https://support.broadcom.com (407-357-7600 from outside the United States)
    Australia: 1300 365510 (+61 2 8220 7111 from outside Australia)
    United Kingdom: +44 (0) 870 606 6000
    Additional contact numbers: http://www.symantec.com/business/support/contact_techsupp_static.jsp

    Hope that helps!!