Live update symantec

Author: m | 2025-04-24

★★★★☆ (4.7 / 2680 reviews)

all in one mahjong 2

Symantec Endpoint Live update tutorial

sandboxie plus 1.9.8 (64 bit)

Symantec Live Update - kb.k12usa.com

My live update is not working since 5th Jan 2015. I also check everything and found no problem. Plz find below live update log from management server for your information.January 26, 2015 11:40:33 AM PKT: LiveUpdate failed. [Site: Site Symantec] [Server: Symantec] January 26, 2015 11:40:33 AM PKT: LUALL.EXE finished running. [Site: Site Symantec] [Server: Symantec] January 26, 2015 11:40:33 AM PKT: LiveUpdate encountered one or more errors. Return code = 4. [Site: Site Symantec] [Server: Symantec] January 26, 2015 11:40:26 AM PKT: Symantec Endpoint Protection Win64 11.0.7000.975 (English) is up-to-date. [Site: Site Symantec] [Server: Symantec] January 26, 2015 11:40:25 AM PKT: Symantec Endpoint Protection Win64 11.0.6005.562 (English) is up-to-date. [Site: Site Symantec] [Server: Symantec] January 26, 2015 11:40:24 AM PKT: Symantec Endpoint Protection Win32 11.0.7000.975 (English) is up-to-date. [Site: Site Symantec] [Server: Symantec] January 26, 2015 11:40:24 AM PKT: Symantec Endpoint Protection Win32 11.0.6005.562 (English) is up-to-date. [Site: Site Symantec] [Server: Symantec] January 26, 2015 11:40:09 AM PKT: TruScan proactive threat scan engine Win32 11.0 is up-to-date. [Site: Site Symantec] [Server: Symantec] January 26, 2015 11:40:09 AM PKT: TruScan proactive threat scan commercial application list Win32 11.0 is up-to-date. [Site: Site Symantec] [Server: Symantec] January 26, 2015 11:40:09 AM PKT: TruScan proactive threat scan whitelist Win64 11.0 is up-to-date. [Site: Site Symantec] [Server: Symantec] Detection of DLL as Heuristic Virus after Recent Symantec Update Hello,I’m encountering an issue where Symantec Endpoint Protection is detecting one of the DLL files used in my application as a heuristic virus. Let us say the file name is "abc.dll". This detection has started with the update released on 13th September 2024 - Live Update ID: 20240913.061 - of the Symantec Endpoint Protection. Before receiving this update (20240913.061) there was no issue with respect to the same DLL file. I have attached the screenshot of the quarantine logs. Currently we have the Symantec Endpoint Protection v14.3.7393.4000 installed in our systems. The details of the issue are as follows:The DLL file has been in use without issue prior to the update 20240913.061 received on 13th September 2024.The issue is only observed on Windows 10 22H2 systems. It does not occur on Windows 10 21H2 or Windows 11 with same version of Symantec Endpoint Protection.After adding a digital signature to the DLL, the issue is no longer observed on affected systems.Could you provide any insight as to why this detection might be occurring. Is there a way to prevent this from happening in the future?Any assistance or guidance on resolving this would be greatly appreciated.NOTE: I have also observed that a DLL related to Symantec has also been detected as Heuristic Virus. You can find it in the attached screenshot.Regards,Pannag

Symantec Live Update Error: Live Update Failed to Start

| M] (Motorola Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\motfilt.sys -- (BTCFilterService)DRV - [2013/01/16 16:46:44 | 002,087,664 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\VirusDefs\20130130.004\ex64.sys -- (NAVEX15)DRV - [2013/01/16 16:46:44 | 000,126,192 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\VirusDefs\20130130.004\eng64.sys -- (NAVENG)DRV - [2013/01/15 21:51:11 | 001,388,120 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\BASHDefs\20130116.013\BHDrvx64.sys -- (BHDrvx64)DRV - [2012/11/23 16:36:10 | 000,513,184 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\IPSDefs\20130130.001\IDSviA64.sys -- (IDSVia64)DRV - [2012/11/16 01:00:00 | 000,138,912 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)DRV - [2012/08/09 10:41:07 | 000,484,512 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys -- (eeCtrl)DRV - [2009/07/13 20:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [binary data]IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htmIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [binary data]IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-3579413699-2492492864-3023678563-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = - HKU\S-1-5-21-3579413699-2492492864-3023678563-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [binary data]IE - HKU\S-1-5-21-3579413699-2492492864-3023678563-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = - HKU\S-1-5-21-3579413699-2492492864-3023678563-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}IE - HKU\S-1-5-21-3579413699-2492492864-3023678563-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = - HKU\S-1-5-21-3579413699-2492492864-3023678563-1000\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = - HKU\S-1-5-21-3579413699-2492492864-3023678563-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not foundFF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not foundFF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\coFFPlgn\ [2013/01/30 07:39:00 | 000,000,000 | ---D | M]FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\IPSFFPlgn\ [2012/11/24 19:29:51 | 000,000,000 | ---D | M]FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\UnfriendApp\Firefox\ [2012/11/26 22:21:50 | 000,000,000 | ---D | M] ========== Chrome ========== CHR - homepage: - default_search_provider: Google (Enabled)CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}CHR -. Symantec Endpoint Live update tutorial Symantec Endpoint Live update tutorial

Symantec Antivirus Live Update URL

AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exeO23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXEO23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exeO23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exeO23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exeO23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe Back to top"> Back to top #4 MFDnSC MFDnSC Ret. Director I/T Members 4,310 posts OFFLINE Local time:10:12 AM Posted 20 October 2006 - 08:24 AM Some things hide from HiJack - right click hijackthis.exe and rename it to bleep.exe=======================Download AVG Anti-Spyware from and save that file to your desktop.When the trial period expires it becomes feature-limited freeware but is still worth keeping as a good on-demand scanner.1. Once you have downloaded AVG Anti-Spyware, locate the icon on the desktop and double click it to launch the set up program.2. Once the setup is complete you will need run AVG Anti-Spyware and update the definition files.3. On the main screen select the icon "Update" then select the "Update now" link.o Next select the "Start Update" button. The update will start and a progress bar will show the updates being installed.4. Once the update has completed, select the "Scanner" icon at the top of the screen, then select the "Settings" tab.5. Once in the Settings screen click on "Recommended actions" and then select "Quarantine".6. Under "Reports"o Select "Automatically generate report after every scan"o Un-Select "Only if threats were found"Close AVG Anti-Spyware. Do Not run a scan just yet, we will run it in safe mode.1. Reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode then hit enter.IMPORTANT: Do not open any other windows or programs while AVG Anti-Spyware is scanning as it may interfere with the scanning process:2. Launch AVG Anti-Spyware by double clicking the icon on your desktop.3. Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".4. AVG will now begin the scanning process. Please be patient as this may take a little time.Once the scan is complete, do the following:5. If you have any infections you will (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exeO23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeO23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exeO23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exeO23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exeO23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exeO23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exeO23 - Service: NICSer_WPC54GS - Unknown owner - C:\Program Files\Linksys\Wireless-G Notebook Adapter with SpeedBooster\NICServ.exeO23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exeO23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exeO23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe 0 Back to top --> #6 RiP Posted 23 May 2006 - 03:28 PM RiP Malware Expert Retired Staff 8,430 posts Hello, jwoo0414.I need you to reconnect the internet cable and see if the computer has internet back, otherwise this will be much more difficult. You have an anti-virus program running so you should be alright for now, just don't do anything online that involves sensitive information. 0 Back to top --> #7 jwoo0414 Posted 23 May 2006 - 03:35 PM #8 RiP Posted 23 May 2006 - 03:38 PM RiP Malware Expert Retired Staff 8,430 posts Hello, jwoo0414.That's excellent news, now let's get to cleaning your computer.You will need to update ewido to the latest definition files.On the left hand side of the main screen click update.Then click on Start Update.The update will start and a progress bar will show the updates being installed.(the status bar at the bottom will display ("Update successful")Exit Ewido, do not run the scan yet!If you are having problems with the updater, you can use this link to manually update ewido.ewido manual updates2. Please download Brute Force Uninstaller to your desktop.Right click the BFU folder on your desktop, and choose Extract AllClick "Next"In the box to choose where to extract the files to,Click "Browse"Click on the + sign next to "My Computer"Click on "Local Disk (C:) or whatever your primary drive is Click "Make New Folder"Type in BFUClick "Next", and Uncheck the "Show Extracted Files" box and then click "Finish".3. RIGHT-CLICK HERE and choose "Save As" (in IE it's "Save Target As") in order to download Alcra PLUS

Symantec Scheduled Live Update Not Working

Shared\ccEvtMgr.exeO23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exeO23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exeO23 - Service: ISEXEng - Unknown owner - C:\WINDOWS\System32\angelex.exe (file missing)O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exeO23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exeO23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exeO23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exeO23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exeO23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exeO23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exeO23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exeO23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exeO23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe 0 Back to top --> #6 Michelle Posted 19 June 2005 - 04:04 PM Michelle Malware Removal Goddess Retired Staff 8,928 posts Yes, there is definitely more nasties that need to go. I will be back as soon as possible. 0 Back to top --> #7 Michelle Posted 19 June 2005 - 04:06 PM Michelle Malware Removal Goddess Retired Staff 8,928 posts First, download, install, and run CleanUp! (so the scan won't take as long because cleanup will clear temporary files) *NOTE* Cleanup deletes EVERYTHING out of temp/temporary folders. If you have anything in a temp folder, backup it up or move it to a permanent folder prior to running Cleanup!Please download Ewido Security SuiteInstall ewido security suiteLaunch ewido, there should be a big E icon on your desktop, double-click it.The program will prompt you to update click the OK button The program will now go to the main screenYou will need to update ewido to the latest definition files.On the left hand side of the main screen click updateClick on StartThe update will start and a progress bar will show the updates being installed.Once the updates are installed do the following:Reboot into Safe Mode, you can do this by restarting your computer, then contiunally tapping F8 until a menu appears. Use your up arrow key to highlight Safe Mode, then hit enter. Then, run Ewido.Click on scannerMake sure the following boxes are checked before scanning:BinderCrypterArchivesClick on Start ScanLet the program scan the machineWhile the scan is in progress you will be prompted to clean the first infected file it finds. Choose "clean", then put a check next to "Perform

Symantec Endpoint Live update Failure

(ATP) is now Symantec Endpoint Detection and Response (Symantec EDR).All software downloads and licensing details are now available through MySymantec.Removed Lotus Notes and Internet Email protection in the Virus and Spyware Protection policy. You can still configure legacy client installation packages with these features through Symantec Endpoint Protection Manager.For more information, see:Version 14.2 RU1 (cloud-managed only)For more information, see:Version 14.2 MP1 (refresh)Improvements to Symantec Endpoint Protection Hardening - Application Control and Application IsolationFor more information, see:Version 14.2 MP1 (refresh)Support for compatibility with Symantec Endpoint Protection Hardening - Application ControlREST API enhancements for Symantec Advanced Threat Protection: EndpointSupport for the following operating systems: Windows Server 2019Windows 10 October 2018 Update (version 1809), including support for case-sensitivity macOS 10.14 (Mojave) Red Hat Enterprise Linux Server (RHEL) 7U5 (7.5)Support for Linux inode64 and XFS Support for Windows Server 2016 Hyper-V For more information, see:Support for compatibility with Symantec Endpoint Protection HardeningAdded support for the following operating systems: Windows Server 2019Windows 10 October 2018 Update (version 1809), including support for case-sensitivitymacOS 10.14 (Mojave)Red Hat Enterprise Linux Server (RHEL) 7U5 (7.5)Support for Linux inode64 and XFSSupport for Windows Server 2016 Hyper-VRemoved support for Windows Server 2008 (RTM) for Symantec Endpoint Protection Manager.REST API enhancements for Symantec EDRFor more information, see:By default, groups and devices are managed by the Symantec Endpoint Protection Manager rather than by the cloud portal: After you enroll a domain, the Symantec Endpoint Protection Manager manages groups and devices by default. In version 14.1, the cloud portal was the default. Automatically upgrading clients with Symantec Endpoint Protection Hardening: Symantec Endpoint Protection Hardening was introduced between the 14.0 and the 14.2 releases. As a result, you could not upgrade 14.0.x clients with Symantec Endpoint Protection (SEP) Hardening automatically. In 14.2, you can install Symantec Endpoint Protection Hardening on Windows clients using AutoUpgrade even if the feature was not previously installed. In the client installation package, even if Maintain existing client features when updating is checked, you can still install Hardening. You must also make sure that Application Hardening is selected in the custom feature set (enabled by default), or else Symantec Endpoint Protection Hardening does not install. 14.2 supports Symantec Endpoint Protection Hardening on both 32-bit and 64-bit Windows desktop operating systems. Earlier clients only support 64-bit Windows desktop operating systems. Symantec Endpoint Protection Hardening is not supported on server operating systems. Support for roaming clients: Roaming clients intermittently connect to the management server. In 14.2, when the clients cannot connect to the management server, roaming clients automatically send critical events to the cloud portal. After the client reconnects to the management server, the clients send any new critical events to the management server. Integration with the Symantec Content Analysis System: The Symantec. Symantec Endpoint Live update tutorial

SEPM Live Update Error: could not update Symantec

The Symantec Data Loss Prevention schema user name.The Symantec Data Loss Prevention schema password.The Update Readiness Tool database account user that you created.The password for the Update Readiness Tool database account user. The database system ID (SERVICE_NAME), typically "protect." If you are running the database on RAC, provide the database system ID as /protect. The Symantec Data Loss Prevention version that you are upgrading to. The Data Pump directory name. You use this optional parameter if you have opted to use a custom data pump directory location. The optional parameter directs the Update Readiness Tool to test data. The tool copies data to be tested and does not test data in production. LOB data that is associated with incidents is not included with the test. Before you run this command, confirm that you have enough disc space to accommodate the data extracted from the database. The optional parameter prevents the Update Readiness Tool from exporting from the Symantec Data Loss Prevention schema during the Update Readiness Tool test. Use this parameter for the following scenarios: If you have already created an export DMP file.If you plan to export data manually. The optional parameter prevents the Update Readiness Tool from importing data to the Update Readiness Tool schema during the Update Readiness Tool test. Use this parameter if you plan to import the data manually. The optional parameter prevents extra logging detail from being included with the Update Readiness Tool test command prompt results.The optional parameter runs the database object check, lists Endpoint Servers and their associated policies, but skips the update readiness test. The optional parameters returns a detailed list of policies, policy size, associated detection servers, and information about individual policies. When you use this parameter, all other URT checks are disabled.

Comments

User7509

My live update is not working since 5th Jan 2015. I also check everything and found no problem. Plz find below live update log from management server for your information.January 26, 2015 11:40:33 AM PKT: LiveUpdate failed. [Site: Site Symantec] [Server: Symantec] January 26, 2015 11:40:33 AM PKT: LUALL.EXE finished running. [Site: Site Symantec] [Server: Symantec] January 26, 2015 11:40:33 AM PKT: LiveUpdate encountered one or more errors. Return code = 4. [Site: Site Symantec] [Server: Symantec] January 26, 2015 11:40:26 AM PKT: Symantec Endpoint Protection Win64 11.0.7000.975 (English) is up-to-date. [Site: Site Symantec] [Server: Symantec] January 26, 2015 11:40:25 AM PKT: Symantec Endpoint Protection Win64 11.0.6005.562 (English) is up-to-date. [Site: Site Symantec] [Server: Symantec] January 26, 2015 11:40:24 AM PKT: Symantec Endpoint Protection Win32 11.0.7000.975 (English) is up-to-date. [Site: Site Symantec] [Server: Symantec] January 26, 2015 11:40:24 AM PKT: Symantec Endpoint Protection Win32 11.0.6005.562 (English) is up-to-date. [Site: Site Symantec] [Server: Symantec] January 26, 2015 11:40:09 AM PKT: TruScan proactive threat scan engine Win32 11.0 is up-to-date. [Site: Site Symantec] [Server: Symantec] January 26, 2015 11:40:09 AM PKT: TruScan proactive threat scan commercial application list Win32 11.0 is up-to-date. [Site: Site Symantec] [Server: Symantec] January 26, 2015 11:40:09 AM PKT: TruScan proactive threat scan whitelist Win64 11.0 is up-to-date. [Site: Site Symantec] [Server: Symantec]

2025-04-18
User6954

Detection of DLL as Heuristic Virus after Recent Symantec Update Hello,I’m encountering an issue where Symantec Endpoint Protection is detecting one of the DLL files used in my application as a heuristic virus. Let us say the file name is "abc.dll". This detection has started with the update released on 13th September 2024 - Live Update ID: 20240913.061 - of the Symantec Endpoint Protection. Before receiving this update (20240913.061) there was no issue with respect to the same DLL file. I have attached the screenshot of the quarantine logs. Currently we have the Symantec Endpoint Protection v14.3.7393.4000 installed in our systems. The details of the issue are as follows:The DLL file has been in use without issue prior to the update 20240913.061 received on 13th September 2024.The issue is only observed on Windows 10 22H2 systems. It does not occur on Windows 10 21H2 or Windows 11 with same version of Symantec Endpoint Protection.After adding a digital signature to the DLL, the issue is no longer observed on affected systems.Could you provide any insight as to why this detection might be occurring. Is there a way to prevent this from happening in the future?Any assistance or guidance on resolving this would be greatly appreciated.NOTE: I have also observed that a DLL related to Symantec has also been detected as Heuristic Virus. You can find it in the attached screenshot.Regards,Pannag

2025-04-18
User2592

| M] (Motorola Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\motfilt.sys -- (BTCFilterService)DRV - [2013/01/16 16:46:44 | 002,087,664 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\VirusDefs\20130130.004\ex64.sys -- (NAVEX15)DRV - [2013/01/16 16:46:44 | 000,126,192 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\VirusDefs\20130130.004\eng64.sys -- (NAVENG)DRV - [2013/01/15 21:51:11 | 001,388,120 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\BASHDefs\20130116.013\BHDrvx64.sys -- (BHDrvx64)DRV - [2012/11/23 16:36:10 | 000,513,184 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\IPSDefs\20130130.001\IDSviA64.sys -- (IDSVia64)DRV - [2012/11/16 01:00:00 | 000,138,912 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)DRV - [2012/08/09 10:41:07 | 000,484,512 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys -- (eeCtrl)DRV - [2009/07/13 20:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [binary data]IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htmIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [binary data]IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-3579413699-2492492864-3023678563-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = - HKU\S-1-5-21-3579413699-2492492864-3023678563-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [binary data]IE - HKU\S-1-5-21-3579413699-2492492864-3023678563-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = - HKU\S-1-5-21-3579413699-2492492864-3023678563-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}IE - HKU\S-1-5-21-3579413699-2492492864-3023678563-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = - HKU\S-1-5-21-3579413699-2492492864-3023678563-1000\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = - HKU\S-1-5-21-3579413699-2492492864-3023678563-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not foundFF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not foundFF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\coFFPlgn\ [2013/01/30 07:39:00 | 000,000,000 | ---D | M]FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\IPSFFPlgn\ [2012/11/24 19:29:51 | 000,000,000 | ---D | M]FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\UnfriendApp\Firefox\ [2012/11/26 22:21:50 | 000,000,000 | ---D | M] ========== Chrome ========== CHR - homepage: - default_search_provider: Google (Enabled)CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}CHR -

2025-04-22
User8530

AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exeO23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXEO23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exeO23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exeO23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exeO23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe Back to top"> Back to top #4 MFDnSC MFDnSC Ret. Director I/T Members 4,310 posts OFFLINE Local time:10:12 AM Posted 20 October 2006 - 08:24 AM Some things hide from HiJack - right click hijackthis.exe and rename it to bleep.exe=======================Download AVG Anti-Spyware from and save that file to your desktop.When the trial period expires it becomes feature-limited freeware but is still worth keeping as a good on-demand scanner.1. Once you have downloaded AVG Anti-Spyware, locate the icon on the desktop and double click it to launch the set up program.2. Once the setup is complete you will need run AVG Anti-Spyware and update the definition files.3. On the main screen select the icon "Update" then select the "Update now" link.o Next select the "Start Update" button. The update will start and a progress bar will show the updates being installed.4. Once the update has completed, select the "Scanner" icon at the top of the screen, then select the "Settings" tab.5. Once in the Settings screen click on "Recommended actions" and then select "Quarantine".6. Under "Reports"o Select "Automatically generate report after every scan"o Un-Select "Only if threats were found"Close AVG Anti-Spyware. Do Not run a scan just yet, we will run it in safe mode.1. Reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode then hit enter.IMPORTANT: Do not open any other windows or programs while AVG Anti-Spyware is scanning as it may interfere with the scanning process:2. Launch AVG Anti-Spyware by double clicking the icon on your desktop.3. Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".4. AVG will now begin the scanning process. Please be patient as this may take a little time.Once the scan is complete, do the following:5. If you have any infections you will

2025-03-31

Add Comment