Endpoint Protection

 View Only
  • 1.  Tamper Protection Query

    Posted Sep 13, 2010 04:50 PM

     

    A client who is running SEP 10 got this message and asked me what it meant. It looks like SEP is blocking itself. Can anyone throw any light on this?

    Target: DefWatchWizardMutex
    Event Info: Create Internal Mutex
    Action Taken: Blocked
    Actor Process: C:\Program Files\Symantec AntiVirus\DWHWizard.exe(PID 2032)

    Target: LDVP_LPC_SEM
    Event Info: Open Enternal Event
    Action Taken: Blocked
    Actor Process: C:\Program Files\Symantec AntiVirus\DWHWizard.exe(PID 2032)

     



  • 2.  RE: Tamper Protection Query

    Posted Sep 13, 2010 05:12 PM

    What is the exact version of SEP 11 you are using..there was a issue with  DWHWizard.exe that was fixed in 11.0.4202.xx version..

    Make sure you have installed latest version of SEP 11.0.6100.xx

     

    Or else create tamper protection exclusion for  C:\Program Files\Symantec AntiVirus\DWHWizard.exe.

    Or Disable Tamper Protection on affected machine



  • 3.  RE: Tamper Protection Query

    Posted Sep 13, 2010 10:38 PM

    create tamper protection exclusion for  C:\Program Files\Symantec AntiVirus\DWHWizard.exe.



  • 4.  RE: Tamper Protection Query



  • 5.  RE: Tamper Protection Query

    Posted Sep 14, 2010 08:25 PM

    Thanks for the suggestions Vikram. It's actually SAV, not SEP. My mistake, and it's v10, not v11.

    I can't see how to create a tamper protection exclusion, is this possible in v10?



  • 6.  RE: Tamper Protection Query

    Posted Sep 15, 2010 01:13 AM

    Hi Rgs,

    Regarding the tamper protection alert in the SAV 10.x it is not possible and the only thing you can do is to disable the tamper protection

    To disable the tamper protection

    open the SAV and goto configure and then click tamper protection.

    Now, Uncheck the box which says " Enable tamper protection "



  • 7.  RE: Tamper Protection Query

    Posted Sep 15, 2010 11:21 PM

    Thanks Narendran.