Академический Документы
Профессиональный Документы
Культура Документы
Share
http://www.symantec.com/connect/articles/symantec-endpoint-protecti...
Language Translations
+60
Like
Share
60 Votes
Tweet
Here are a few registry tweaks and information about Symantec Endpoint Protection.
1. To check the Version of currently installed SEP client
HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\SMC
ProductVersion
Value will be something like 11.0.4014.26
1 de 17
17/06/2015 09:32
http://www.symantec.com/connect/articles/symantec-endpoint-protecti...
v.Extensions
HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Exclusions\ScanningEngines
\Extensions\
\Admin and \Client
vi. Symantec also excludes it own Embedded Database from Scanning
HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Exclusions\Symantec
2 de 17
17/06/2015 09:32
http://www.symantec.com/connect/articles/symantec-endpoint-protecti...
Embedded Database\FileExceptions
Out.log, Sem5.log and Sem5.db are excluded.
vii. To Verify Exchange Server exclusions on 32 Bit System
HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Exclusions\Exchange Server
\FileExceptions and \NoScanDir
On 64 Bit system
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Symantec\Symantec Endpoint Protection\AV\Exclusions
\FileExceptions and \NoScanDir
10. Now say you have remote laptops you exported a Default client install package and sent them.
Now you want to change them to Unmanaged.
You replaced sylink.xml for Unmanaged SEP Cd1\SEP\Sylink.xml
Still clients are not able to do the liveupdate and the default admin defined Scan runs.
Here is the default Admin Defined Scanand if you have created few more scans for this users it will also be listed in
the same location but with a different name.
HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\LocalScans
\5df13630-79f7-4c70-002b-16b8952f5533 ( name can be any hexadecimal name )
So you can delete this and then you can create your own scan.
Liveupdate button is greyed out even after replacing sylink.
HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\LiveUpdate
AllowManualLiveUpdate 0- means liveupdate button will be greyed out. 1-means it will be available to click.
In the same place you can enable product updates by changing the value of
EnableProductUpdates to 1
For Scheduling and Enabling automatic liveupdates.
HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\LiveUpdate\Schedule
Change the value of
Enabled to 1 for Automatic updates.
11. Handling Quarantine
Sometimes due to infection the size of the quarantine folder grows huge.
It is not accessible via the GUI.So to know where and to change settings for Quarantine for the client
HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Quarantine
Important keys
QuarantinePurgeBySizeEnabled set it to 1 To enable Sizing of quarantine folder then
QuarantinePurgeBySizeDirLimit Default value is 50 ( Megabytes) either leave it at 50 or reduce it as much you
want.
You can also lower the age of purging Quarantine items from default 30 days to any number of days you want
3 de 17
17/06/2015 09:32
http://www.symantec.com/connect/articles/symantec-endpoint-protecti...
/connect/forums/way-create-scan-registry)
14. For Logging options via registry
How to debug the Symantec Endpoint Protection 11.x client
http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007090611252048 (http://service1.symantec.com
/SUPPORT/ent-security.nsf/docid/2007090611252048)
15. GUP information via registry
Troubleshooting the Group Update Provider (GUP) in Symantec Endpoint Protection
http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2008040113243148 (http://service1.symantec.com
/SUPPORT/ent-security.nsf/docid/2008040113243148)
16. Enable debugging of Auto Location switching (ALS) and this Reg key
HKLM\SOFTWARE\S ymantec\Symantec Endpoint Protection\SMC\Trident\AutoLocationDump
4 de 17
17/06/2015 09:32
Comments
http://www.symantec.com/connect/articles/symantec-endpoint-protecti...
jeffwichman
+1
Sandeep Cheema
Actions
+1
Satyam Pujari
It's really a good article to assist sym customer to understand the product's internal working better.All regs
in one place...nice effort !
Inviting good karma to CPU...beep
Actions
Symantec World
PARTNER
+1
Actions
shp
+3
Thanks yaar...
I was looking for this.. You got my vote.....
Thanks once again....
Regards,
Srinivas H.P.
HCL Infosystems Ltd
5 de 17
17/06/2015 09:32
http://www.symantec.com/connect/articles/symantec-endpoint-protecti...
Actions
+2
Maximilian
Very good!
I could use some more of this good stuff :)
Thanks!!!
Actions
AravindKM
TRUSTED ADVISOR
Actions
Symantec World
PARTNER
+1
Actions
Int3rn3t
+1
ragunayaka@gmail.com
Aniket Amdekar
6 de 17
17/06/2015 09:32
http://www.symantec.com/connect/articles/symantec-endpoint-protecti...
+4
mssym
+6
Actions
7 de 17
+8
17/06/2015 09:32
http://www.symantec.com/connect/articles/symantec-endpoint-protecti...
Jamit
I have found this setting is not always true. I had a case today where the SEPM Logs and Client
console flagged File System Auto-Protect was not running. I checked
HKEY_LOCAL_MACHINESOFTWARESymantecSymantec
EndpointProtectionAVStoragesFilesystemRealTimeScan OnOff on the workstation and it was set to 1
(enabled) however File System Auto-Protecwas not.
To resolve I had to repair the client. If someone can advise why I saw the above behaviour it would be
appreciated?
Thanks
Jamit
Actions
manish-SecPol
Ghent
Hi, in RU5 the HardwareID was moved out of the registry and onto the disk. It's now located at
%ProgramFiles%\Common Files\Symantec Shared\HWID\sephwid.xml
+2
Actions
justin-new2SEP
Kedar Mohile
Nice article
Kedar Mohile http://kedarmohile.blogspot.com
(http://kedarmohile.blogspot.com)
Actions
wosteen
8 de 17
+1
17/06/2015 09:32
http://www.symantec.com/connect/articles/symantec-endpoint-protecti...
I have just tested that on WIn XP 32 bit reg keys for 32 and 64 are little bit different.
Vikram Kumar
Symantec Consultant
The most helpful part of entire Symantec connect is the Search button..do use it.
Actions
+3
Maximilian
Great stuff!
Anyone know if these still apply after MR5 release?
Actions
Actions
Maximilian
9 de 17
+4
17/06/2015 09:32
http://www.symantec.com/connect/articles/symantec-endpoint-protecti...
Great!
Any new reg keys for MR5?
Actions
Frank019
GWA
Excellent article.
Actions
jayancharles
HI vikram Great ya i know ur in other field but u doing well....I think u get from google any nice..............
by
Jayan charles
Actions
+1
Actions
+1
Wally
Great article - especially the EnableProductUpdates tweak - will save me a lot of time!!!
Actions
10 de 17
+1
17/06/2015 09:32
http://www.symantec.com/connect/articles/symantec-endpoint-protecti...
JRV
If you can't think of any other reasons not to let your users run as admins (and most of us can think of
many!), the fact that SEP stores its config in the registry for all to see is a great one.
If you run as an admin, it is trivial for malware or malicious users to disable SEP.
Actions
BrooksGarrett
John Cooperfield
postechgeek
Nice, thanks.
Actions
VSK
Actions
SymSEP
11 de 17
17/06/2015 09:32
Ian_C.
http://www.symantec.com/connect/articles/symantec-endpoint-protecti...
13 Feb 2011 : Link
PARTNER
Please mark the post that best solves your problem as the answer to this thread.
Actions
Ian_C.
+2
PARTNER
Please mark the post that best solves your problem as the answer to this thread.
Actions
yang_zhang
+2
If a forum post solves your problem, please flag it as a solution. If you like an article, blog post
Actions
12 de 17
17/06/2015 09:32
http://www.symantec.com/connect/articles/symantec-endpoint-protecti...
Moab.baom
Great article,
But I'm not just interesting to know the client virus definitions (HKLM\SOFTWARE\Symantec\SharedDefs
\DefWatch\VirusDefs) ,
but the windows definitions on the SEPM console home page:
Latest from symantec
Latest On Manager
Because I want first to monitor this information . I found a very good nagios pluggin, but it displays the
Virus definition of the client installed on the server. The server can be the client of another SEPM, up to
date, and my local server out of date, and I will not know this with this information.
https://www.monitoringexchange.org/inventory/Check-Plugins/Operating-Systems/WindowsNRPE/check_symantec_av (https://www.monitoringexchange.org/inventory/Check-Plugins/OperatingSystems/Windows-NRPE/check_symantec_av)
Me I need to know the entry in registry of the windows definitions displayed on the SEPM console.
Best regards
Actions
Wally
Vikram - do you know if there is a registry entry on the SEP 11 RU6 or RU7 client for "Disable the
Windows Firewall"?
Actions
LGL
Is there any update from anyone according to the latest release SEP12.1 RU1 and registry entries, maybe
there is some new useful registry entries to know in that version?
Actions
consoleadmin
Gr8
Thanks.
Actions
Srikanth_Subra
13 de 17
17/06/2015 09:32
http://www.symantec.com/connect/articles/symantec-endpoint-protecti...
Nice article
Thanks & Regards,
Srikanth.S
"Defeat the Defeat before the Defeat Defeats you"
(Swami Vivekananda)
Actions
+1
HSS
Hi,
I would like to know the the reg key to chagne the Start up Type (from Auto to Manual) of 'Symantec
Endpoint protection'.
Any urgent reply will be appreciated.
Thanks,
Actions
Ian_C.
PARTNER
What you are trying to do is not advisable. However, if you want to experiment with this, have a look
at this key:
HKEY_LOCAL_MACHINE\SYSTEM\Current ControlSet\Services\SmcService
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Symantec AntiVirus
The Auto value determines the start up type.
Please mark the post that best solves your problem as the answer to this thread.
Actions
NRaj
Ian_C.
PARTNER
Dear Vikram.
Please add the Reg key discussed in https://www-secure.symantec.com/connect/forums/locationawareness-and-vpn-switching#comment-6811491 (https://www-secure.symantec.com/connect/forums
14 de 17
17/06/2015 09:32
http://www.symantec.com/connect/articles/symantec-endpoint-protecti...
Please mark the post that best solves your problem as the answer to this thread.
Actions
SG Raj
A Lara
I can find the registry key that gives Antivirus and Antispyware definition date, and the Network Threat
Protection definition date, but I cannot find the registry key that gives the definition date for Proactive
Threat Protection.
Where is this registry key?
Actions
Ian_C.
PARTNER
+1
Thanks to Mithun for posting in this article (https://www-secure.symantec.com/connect/forums/registrykey-or-log-file-last-full-scan#comment-7270141) how to decode the time stamps for the values of
date and time of last full scan
date and time of last infection
How to decode the TimeOfLastVirus and TimeOfLastScan registry values: KB 99873
(http://www.symantec.com/docs/TECH99873)
Please mark the post that best solves your problem as the answer to this thread.
Actions
tygrus
15 de 17
17/06/2015 09:32
http://www.symantec.com/connect/articles/symantec-endpoint-protecti...
rojopipe
PARTNER ACCREDITED
Hi,
Anyone have an update of this post for SEP 12.1 RU3, the idea is to protect the registry keys necessary
using ADC.
Thank you.
Actions
Bran
Actions
rojopipe
PARTNER ACCREDITED
Thanks Brian81
I seek to identify registry keys SEP that can protect through policies of ADC in case someone malicious
attempts to erase. Greater protection to tamper protection
Actions
_Damian
16 de 17
17/06/2015 09:32
http://www.symantec.com/connect/articles/symantec-endpoint-protecti...
Hi all,
If I change the ADC value on the registry, will this enable the devices that were being blocked by the
policy?
Thanks
Actions
17 de 17
17/06/2015 09:32