Weird one with Symantec Endpoint 12.1

Hey Guys,
I'm just wondering if anyone also burdened with Symantec Endpoint Protection is having the problem we now seem to be facing.
Whenever we download the Zenworks agent from our ZCM Server (linux) to a PC, symantec Quarantines it. This has only started happening this week (there was a definition update yesterday).
We usually download the the full 32bit version (i've had trouble with the network install before).
The Symantec risk log gives a really obscure reason for blocking the "PreAgentPkg_AgentComplete.exe" file, it says the risk is "WS.Reputation.1" :
WS.Reputation.1 | Symantec
Our Symantec build is 12.1.601.4699 I would post this on the symantec forums, but I think there is more chance of finding one of you guys running Symantec, than someone on the Symantec forums using Zenworks.
Our Antivirus Monkey is off this week, but I was just curious if anyone else was having the same problem, it seems to be happening on all our PC's.
Thanks
Dave

I have run into the same thing with our ZCM deployment. Have you found a solution I submitted files to Symantec with no answer yet. I am showing all our PC's that received the Client via the ZCM Server infected and quarantined. The only difference is I show it being a Suspicious.Cloud2 infection. Any info would be greatly appreciated.
Originally Posted by Cptdave
Hey Guys,
I'm just wondering if anyone also burdened with Symantec Endpoint Protection is having the problem we now seem to be facing.
Whenever we download the Zenworks agent from our ZCM Server (linux) to a PC, symantec Quarantines it. This has only started happening this week (there was a definition update yesterday).
We usually download the the full 32bit version (i've had trouble with the network install before).
The Symantec risk log gives a really obscure reason for blocking the "PreAgentPkg_AgentComplete.exe" file, it says the risk is "WS.Reputation.1" :
WS.Reputation.1 | Symantec
Our Symantec build is 12.1.601.4699 I would post this on the symantec forums, but I think there is more chance of finding one of you guys running Symantec, than someone on the Symantec forums using Zenworks.
Our Antivirus Monkey is off this week, but I was just curious if anyone else was having the same problem, it seems to be happening on all our PC's.
Thanks
Dave

Similar Messages

  • I can't print with symantec endpoint protection

    I can't print with symantec endpoint protection.
    I have to disable the firewall, or reboot my windows 7 computer for the print job to print.  Any ideas what is blocking the printing process and how do I allow so I can print using my HP P2033dn that is connected via ethernet to my time capsule.  Thanks

    In the meanwhile I detected the problem. I made a new user account in windows and now it works correctly. So it isn't a photoshop problem but probably a register error. I have to find out furtherThanks for your reaction.
    [ excessive quoting removed by admin ]

  • Problem with Symantec Endpoint protection and iCloud

    iCloud does not function on my PC with Symantec Endpoint Protection. I think it is the stopping of Auto-run that is the problem, but I don't know how to solve this

    Hi Xung,
    Can you elobrate as what is that you are trying to achive and its blocking
    IS it TMG not getting updated
    Client is unable to get live update from internet
    SEPM manager unable to get updates ?
    can you do a logging and share the screenshot of the traffic getting blocked.
    If TMG is unable to get updates then allow the belwo
    From : Localhost
    To : SEPM / GUP servers
    Port : 2967 - Outbound and 8014 Outbound
    Allow for All Users

  • Weird one with my fx 5200 after deleting old drivers and installing from scratch.

    Ok, now I got a weird question, but seems to be a problem. I have a MSI Geforce FX 5200 as seen here and I was having a few problems with my drivers, and I figured it was my video card since it would mostly happen in games with 3D acceleration. So, I used Driver Cleaner and got rid of every nVidia driver on my computer. Rebooted, and installed the latest of the MSI website (45.33) and now, when I look in my settings, I have an option for DOT?!?!?! as seen here
    My question is, did I install the wrong drivers or did DOT become part of the 5200? (it's the one with only monitor out and s video out, no DVI or anything special, heatsinks and not fans)
    Thanks for the info in advance.

    Quote
    Originally posted by GlennVidia
    What is the actual marketing name for the 5200...there are lots of them BTW...
    http://www.msi.com.tw/program/products/vga/vga/pro_vga_detail.php?UID=467
    That one is the one I have. And my board isn't supposed to have DOT on it, it's not in the Bios setup.

  • LabView / DSC / FieldPoint with Symantec Endpoint Encryption Device Control

    I am developing a LabView DSC based control program to communicate with multiple FieldPoint modules (cFP2200/cFP1808) for a client. Their IT department has implemented Symantec Endpoint Encryption Device Control ( http://www.symantec.com/endpoint-encryption-device-control ) and I was wondering if anyone has had experience with this software?
    From what I have read and had explained to me, it is much more than an antivirus program. It operates at a very low level within Windows and restricts reading/writing to external devices, USB sticks, network shares, etc. It can also monitor / restrict network traffic and WiFi access.
    Thanks,
    Steve

    Hi MillerMech,
    I believe it will cause some errors to be thrown due to its restrictive nature. Symantec has a discussion forum which will most likely be more helpful:
    http://www.symantec.com/business/support/index?page=home
    Sunaina K.
    Product Manager
    Embedded Systems

  • Issue with Symantec EndPoint Protection 11.0

    I am experiencing the exact issue in this article on Symantec's KB:
    http://tinyurl.com/5x6fay
    Can someone at Lenovo please acknowledge this issue (confirm or deny) and let me know how to resolve this without disabling the security features I paid for on this new T400?
    Thank you.
    Michael Reinders

    Ask in a Symantec forum how to configure your software correctly. Your Symantec software blocks LAN access and should be configured to allow it. The E2000 has nothing to do with that.

  • Did Flash Player 11 patch cause problem with Symantec Endpoint?

    I downloaded Flash Player 11. Now each time I attempt to get new antivirus definitions from Symantec I get a warning message that the process failed.

    Unless your Symantec updater uses Flash content and uses it to enable download links, it's highly unlikely that the Flash Player update had any effect on it at all. Your best bet in determining this would be to contact Symantec suport and ask if their updater uses Flash content to enable download links.
    I don't use ANYTHING from Symantec because I used to test it for another software company and I know what it does to a system. It was the first thing I removed from a new laptop in June.

  • Symantec Endpoint Protection (SEP) adds support for Windows 10 with 12.1.6 MP1.

    Hello Everyone,
    Symantec Endpoint Protection (SEP) adds support for Windows 10 with 12.1.6 MP1.For Symantec Endpoint Protection 12.1, a maintenance patch has been released on July 29, 2015. Customers will need to be current on maintenance to receive the maintenance patch update. For more information, visit our SEP 12.1 Windows 10 Knowledge Base.You can upgrade to Windows 10 with Symantec Endpoint Protection 12.1.6 MP1 installed. You must uninstall earlier versions of Symantec Endpoint Protection. The operating system upgrade stops if it detects an earlier version of Symantec Endpoint Protection.The following operating system upgrade paths are supported with 12.1.6 MP1 installed:Windows 8.1 to Windows 10Windows 8 to Windows 10Windows 7 to Windows 10For more details check the following article:http://www.symantec.com/docs/INFO2746SEP...
    This topic first appeared in the Spiceworks Community

    Hello,
    Just to give an update. We were able to make this work but we used Symantec Protection Engine for Cloud Services instead. Also, for anyone having problems with the parameters - we used the exact same parameters listed in Peoplebooks or on the delivered virusscan.xml file, just update the IP address. We also saved the xml file on both the Portal.war and PSIGW.war directories.

  • Symantec Endpoint Protection 12.1 and Peopletools 8.53

    Hello,
    We're currently enabling virus scan for PT 8.53 with Symantec Endpoint Protection (SEP) v12. However, we are unable to configure it correctly. Our set up looks like this:
    * PS webserver is insatalled on server 1, this is where we configure the virusscan.xml file
    * SEP 12 is installed on a separate server, server 2. client and SEP manager is installed on this server.
    * OS is Windows 2008 R2 64-bit for both servers.
    May I know if  anyone here have successfully used SEP for scanning attachments?
    Unfortunately, as per oracle, only symantec scan engine was verified to work with peoplesoft, other versions are still not tested to work.
    another question is, what should be the value for the virusscan.xml parameters below?
        <Provider>
         <name>SymantecManagementClient</name>
        <class>psft.pt8.virusscan.provider.GenericVirusScanProviderImpl</class>
        <icapversion>ICAP/1.0</icapversion>
        <service-name>/SmcService</service-name>
        <policycommand>?action=SCAN</policycommand>
        <address>server2</address>
        <port>8014</port>
        <disable>false</disable>
         </Provider>
    we've mixed and matched the available service names from server 2, but we are still getting the error below:
    Sep 10, 2013 11:14:19 PM psft.pt8.virusscan.ICAPClient connectAndCheckOptions
    INFO: Input OPTIONS Header = OPTIONS icap://server2:8014/SmcService ICAP/1.0
    Sep 10, 2013 11:14:19 PM psft.pt8.virusscan.ICAPClient connectAndCheckOptions
    INFO: OPTIONS recieve header= HTTP/1.1 200 OK
    Date: Tue, 10 Sep 2013 15:14:19 GMT
    Server: Apache
    Allow: GET,HEAD,POST,OPTIONS
    Content-Length: 0
    Connection: close
    Content-Type: text/plain
    ICAP header = ICAP/1.0 200
    Sep 10, 2013 11:14:19 PM psft.pt8.virusscan.ICAPClient scanStream
    SEVERE: Unable to connect to the Scan server SymantecManagementClient; Reason = CONNECTERROR
    Sep 10, 2013 11:14:19 PM psft.pt8.virusscan.VirusScanProviderManager scanStream
    INFO:  Scanning completed using provider = SymantecManagementClient Provider classname = psft.pt8.virusscan.provider.GenericVirusScanProviderImpl
    Sep 10, 2013 11:14:19 PM psft.pt8.virusscan.VirusScanProviderManager scanStream
    INFO: Finish Scanning Request.
    port 8014 is the client communications port for SEP and its the only port that gives us a response (INFO: OPTIONS recieve header= HTTP/1.1 200 OK..etc), when we try other ports we get a "SEVERE: Unable to connect to SymantecManagementClient" message on this line.
    Hoping for your responses, thank you in adance for your help.

    Hello,
    Just to give an update. We were able to make this work but we used Symantec Protection Engine for Cloud Services instead. Also, for anyone having problems with the parameters - we used the exact same parameters listed in Peoplebooks or on the delivered virusscan.xml file, just update the IP address. We also saved the xml file on both the Portal.war and PSIGW.war directories.

  • Symantec Endpoint Protection on Mavericks Reviews??

    It seems like everyone has a review or has reviewed Symantec Norton Internet Security and Norton Antivirus yet not too much has been tested or written on Symantec Endpoint Protection.
    Unfortunately we are moving in a direction where we will be installing Symantec Endpoint Protection on all our macs and I am trying to find reviews, whether personal or professional, about SEP and macs.
    I know Symantec products in general have been trashed on for mac for a while now but it seems I can't find a good AV test out there that includes it for Mac (as most only contain the two symantec products I mentioned above)
    Anyone have any personal experience, or know of any testing done with the Symantec Endpoint Protection on macs within the past year?

    Hello Everyone,
    I am Chetan Savade from Symantec Technical Support Team.
    You can directly install an unmanaged or managed Symantec Endpoint Protection client on a Mac computer if you cannot use or do not want to use Remote Push. The steps are similar whether the client is unmanaged or managed. The only way to install a managed client is with a package you create with Symantec Endpoint Protection Manager. You can convert an unmanaged client to a managed client at any time by importing client-server communication settings into the Mac client.
    Check the following articles:
    Compatibility between Symantec Endpoint Protection for Mac and versions of Mac OS X
    http://www.symantec.com/docs/TECH131045 
    Symantec Endpoint Protection for Macintosh Frequently Asked Questions (SEP for Mac FAQ)
    http://www.symantec.com/docs/TECH134203
    Send me DM here https://www-secure.symantec.com/connect/user/chetan-savade if you need any assistance with SEP for MAC.
    Best Regards,
    Chetan

  • BSOD on XP with Zenworks and Symantec Endpoint Protection

    After upgrading to Symantec Endpoint Protection (SEP) we are getting Blue Screen after imaging.
    We have SEP included in our image and after pushing the image to another computer, we instantly get a BSOD, when trying to boot up the newly imaged machine:
    *** STOP: 0x00000024 (0x00190203,0x8A4B0DE8,0xC0000102,0x00000000)
    Disable or uninstall any anti-virus, disk defragmentation or backup utilities. Check your hard drive configuration, and check for any updated drivers. Run CHKDSK /F to check for hard drive corruption, and then restart your computer.
    For test purpose I have tried doing the imaging job with Ghost 2003. This works perfectly, so I guess it is the combination of SEP and ZfD that is causing the problem. If I exclude SEP from the image, imaging with ZfD works fine. Imaging with Symantec antivirus ver. 10 also works perfect.
    Anyone out there running ZfD and SEP 11?
    Environtment:
    Windows XP SP3
    ZfD 7.01 sp1 ir1 running on Netware 6.5
    Symantec Enpoint Protection 11.0.3001.2224 (getting the same error with 11.0.2010.25)

    There should an updated patch for ZDM7 available withing a few days. (ZDM7
    SP1 IR3A HP1.)
    I would strongly suggest testing with the updated files when they are
    released.
    The is a much newer Linux Kernal starting with IR3A which could effect your
    problem.
    If you are still seeing an issue, I would suggest opening a ticket with
    Novell.
    Unless somebody here happened to have a copy of SEP, helping here would be
    tough.
    But I have not heard of this issue myself, but anything is possible.
    Craig Wilson - MCNE, MCSE, CCNA
    Novell Support Forums Volunteer Sysop
    Novell does not officially monitor these forums.
    Suggestions/Opinions/Statements made by me are solely my own.
    These thoughts may not be shared by either Novell or any rational human.
    "martinusen" <[email protected]> wrote in message
    news:[email protected]...
    >
    > After upgrading to Symantec Endpoint Protection (SEP) we are getting
    > Blue Screen after imaging.
    >
    > We have SEP included in our image and after pushing the image to
    > another computer, we instantly get a BSOD, when trying to boot up the
    > newly imaged machine:
    >
    > *** STOP: 0x00000024 (0x00190203,0x8A4B0DE8,0xC0000102,0x00000000)
    >
    > Disable or uninstall any anti-virus, disk defragmentation or backup
    > utilities. Check your hard drive configuration, and check for any
    > updated drivers. Run CHKDSK /F to check for hard drive corruption, and
    > then restart your computer.
    >
    > For test purpose I have tried doing the imaging job with Ghost 2003.
    > This works perfectly, so I guess it is the combination of SEP and ZfD
    > that is causing the problem. If I exclude SEP from the image, imaging
    > with ZfD works fine. Imaging with Symantec antivirus ver. 10 also works
    > perfect.
    >
    > Anyone out there running ZfD and SEP 11?
    >
    > Environtment:
    > Windows XP SP3
    > ZfD 7.01 sp1 ir1 running on Netware 6.5
    > Symantec Enpoint Protection 11.0.3001.2224 (getting the same error with
    > 11.0.2010.25)
    >
    >
    > --
    > martinusen
    > ------------------------------------------------------------------------
    > martinusen's Profile: http://forums.novell.com/member.php?userid=26795
    > View this thread: http://forums.novell.com/showthread.php?t=345351
    >

  • I am facing a weird problem with my iphone 4s Wi-Fi connectivity. As i connect my iphone to my office Wi-Fi, internet works in one building, but it doesnt work in the other building, although the phone shows Wi-Fi is connected. Please help me out!!

    I am facing a weird problem with my iphone 4s Wi-Fi connectivity. As i connect my iphone to my office Wi-Fi, internet works in one building, but it doesnt work in the other building, although the phone shows Wi-Fi is connected in the other building. This problem was not there earlier but has occured recently. I would also like to mention that none of my other colleauges who uses iphone are not facing this issue. Please help me out!!

    Assuming you entered the correct WiFi password for your network, see these articles:
    iOS: Troubleshooting Wi-Fi networks and connections
    iOS and OS X: Recommended settings for Wi-Fi routers and access points

  • Symantec Endpoint Protection incompatible with Win7?

    I had Symantec Endpoint Protection running under Vista Ultimate.  Upgrading to Win7 i get a message that SEP's "Confidence Online Utility Driver" has been disabled because it may create stability problems.  Symantec says they're working on it. In the meantime? Are end users are still protected?  No answer from Symantec.  Is there a Microsoft soluition?

    Hi Craig,
    Symantec Endpoint Protection is compatible with windows 7.Please check the below link.
    http://www.microsoft.com/windows/compatibility/windows-7/en-us/Search.aspx?type=Software&s=Symantec%20Endpoint%20Protection
    Because of compatibility issues, the currently provided versions of Symantec Endpoint Protection do not install properly .To install Symantec properly on Windows 7,you can follow the below link wherein the steps are mentioned in clearly.
    http://kb.wisc.edu/helpdesk/page.php?id=12029
    SEP 11.0.5 is also released. If you have the serial number for the SEP you can use it in the below link.
    https://fileconnect.symantec.com/licenselogin.jsp?localeStr=en_US
    Please check the below link for further detials.
    http://snydersoft.com/2009/09/23/windows-7-and-symantec-endpoint-protection/
     If you have SMP 11.0.2 you need to call Customer care and can ask for a serial number to download SEP 11.0.5.
    Thanks,
    Saraga Mala
    NOTE - Disclaimer
    The links in this message may lead to third-party Web sites. Microsoft provides third-party resources to help you find customer service and/or technical support resources. Information at these sites may change without notice. Microsoft is not responsible for the content at any third-party Web sites and does not guarantee the accuracy of third-party information.

  • Symantec Endpoint Protection Manager Installer Information Script Error

    hi
    I can't install SEP Manager 14.1 in our windows 2012 R2 server I got an error during the installation.While was installing symantec endpoint production 14.01 , I am getting an error right at the end of the install. I understand that . I should do it with
    vbs running for symantec installing. however I dont know How can I do it ?,
    "Symantec Endpoint Protection Manager Installer Information - Error 1722. There is a problem with this Windows Installer package. A
    program run as part of the setup did not finish as expected. Contact your support personnel or package vendor. Action RunFIPSScript, location: c:\Program Files (x86)\Symantec\Symantec Endpoint Protection Manager\bin\, command: C:\Windows\SysWOW64\...\FIPSMode.vbs"
    -install"

    Hi,
    I am Chetan Savade from Symantec Technical Support Team.
    I think you are talking about SEP 12.1 product. There is not any product by code 14.1.
    With reference to mentioned issue there is a Public Kb available. Refer the following KB:
    Symantec Endpoint Protection "Error 1722: There is a problem with this Windows Installer package..."
    http://www.symantec.com/docs/TECH103131
    Possible Solution as per KB: To fix the problem, run the Windows Installer CleanUp utility and then remove Symantec AntiVirus manually. Then, install Symantec Endpoint Protection again.
    To learn how to obtain and use the Windows Installer CleanUp utility, read the
    Microsoft article Description of the Windows Installer CleanUp Utility.
    Click the entry for Symantec AntiVirus or Symantec Client Security, and then click Remove.
    If more than one entry appears, remove the earliest program version first. After you remove all entries for Symantec AntiVirus and Symantec Client Security, remove Symantec AntiVirus manually.
    To find directions for your version of Symantec AntiVirus, read
    Manual uninstallation documents for Symantec Client Security products.
    Symantec connect forum link to raise SEP related issue: https://www-secure.symantec.com/connect/security/forums/endpoint-protection-antivirus
    Best Regards,
    Chetan

  • Symantec endpoint protection vs intego virusbarrier

    Hi Everyone,
    My school requires me to get some sort of virus protection on my mac. They provide symantec endpoint protection (11.063) for free. I know that over the past few years, symantec has been a resource hog and generally poorly reviewed. I'd be willing to get the license for intego virusbarrier as I've read better reviews about that.
    Does anyone have any experience with intego or symantec endpoint protection here? Any preferences, comments, suggestions? Thanks for your help!

    I had some problems with Norton version 10, but none whatsoever with version 11. I've also used VirusBarrier X6.
    VirusBarrier is very configurable but on can give some false warnings if you set it to watch network traffic, monitor for virus-like activities, etc (like it thought Data Rescue was acting suspiciously). VB has warned me about a compromised web page I visited, so that feature works. I've never had a false alert from Norton but  neither has ever found an actual Mac virus so I have no experience with that (NAV has found Windows viruses in attachments, and a Word macro virus).
    If you don't want to configure anything and don't want false alerts use NAV. If you want more configuration options such as monitoring Internet port connections, web threats, etc. and don't mind dismissing an occasional false alarm the VB is a good choice.
    NAV has never slowed anything down. VB usually is transparent but on rare occasion one of the subprograms has run wild (virusbarrierd or virusbarrierb) forcing me to either kill it or restart my computer.

Maybe you are looking for

  • In app run if no list generated what are the possible causes

    afetr the app run when i click on execute system showing no list generated.  what r the possible causes?

  • Dynamic Linking has stopped working in Illustrator CS6 16.0.4

    Dynamic linking no longer appears to be working since the new update to 16.0.4. I have it set in the preferences to ask me if I would like to update when a change is made to a document that is dynamically linked to any AI file. It just simply doesn't

  • Stuck in restore

    Stuck in restore. Plugged the iphone into the computer hit restore and the bar made it half way across and stopped any ideas.

  • Response time issue querying a view

    Hi All, The following query is taking more than 20-25 mins to run and it does not return any result. Ideally it should return 0 rows but still it takes 20-25 mins to achieve that. Select * from WV_WMS_STOCK_MOVEMENT; --> it’s a View Database: Oracle

  • Bypass guest webauth for Blackberry Service

    Hi Folks, Our wireless deployment has two wireless networks - one with 802.1x auth for corporate machines and the other is an open one with internet access for guests (but with a web auth page). What I'd like to do is allow staff to connect their Bla