Symantec Connect - Security - Discussions
http://www.symantec.com/connect/security/forums/feed
enSEP 11.05 Client install has no progress on SBS 2008
http://www.symantec.com/connect/forums/sep-1105-client-install-has-no-progress-sbs-2008
<p>We are setting up a new SBS 2008 server. We are using SEP 11.05 SEPM installed flawlessly and works well on the server.</p>
<p>When we go to install SEP (64bit) the installation process just sits there. The SEP_INST.log file is only at 1kb and goes no further. There are no entries in the Event Viewer about any installation process starting or failing.</p>
<p>I am baffled by this behavior. I have checked for the Pending registry keys of which there are none. UAC is turned off. I have tried server reboots and it still will not install.</p>
<p>I look forward to some ideas and a solution.</p>
<div class="og_rss_groups"></div>http://www.symantec.com/connect/forums/sep-1105-client-install-has-no-progress-sbs-2008#comments11.xEndpoint Protection (AntiVirus)InstallingWindowsTroubleshootingSecuritySat, 20 Mar 2010 22:20:29 +0000REBOOTWNY1250951 at http://www.symantec.com/connectScan omissions
http://www.symantec.com/connect/forums/scan-omissions
<p>Can someone explain to me why there are scan omissions during scheduled FULL scans? I understand there is an issue with busy and or compressed files. For example, on a client one scheduled scan reported 2,848,810 files and the other 1,085,105 files; a difference of 1.7 million files!?</p>
<p>Thanks!</p>
<div class="og_rss_groups"></div>http://www.symantec.com/connect/forums/scan-omissions#comments11.xEndpoint Protection (AntiVirus)DocumentationReportingSecuritySat, 20 Mar 2010 18:17:14 +0000rickd1250901 at http://www.symantec.com/connectCan not get Chat support / Norton file error 1316
http://www.symantec.com/connect/forums/can-not-get-chat-support-norton-file-error-1316
<p>I tried to do a chat, but the file they had me to download will not install. <br />
File nae: SymADataWeb.msi<br />
Give me Error 1316 network error<br />
I are ran in administrator mode, and I have unblocked, I have turned antivirus and fire wall off and still get same error.</p>
<div class="og_rss_groups"></div>http://www.symantec.com/connect/forums/can-not-get-chat-support-norton-file-error-1316#commentsSecurity Information ManagerError messagesTroubleshootingSecuritySat, 20 Mar 2010 17:36:09 +0000alpine41331250881 at http://www.symantec.com/connectCombined Message Queue Size
http://www.symantec.com/connect/forums/combined-message-queue-size
<p>Dear Adnan</p>
<p>Thanks your valuable support.<br />
**************************************<br />
Please find a mail that I recived from SBG.<br />
----- Original Message ----- From: <a class="moz-txt-link-rfc2396E" href="mailto:postmaster@kfupm.edu.sa"><postmaster@kfupm.edu.sa></a><br />
To: <a class="moz-txt-link-rfc2396E" href="mailto:postmaster@kfupm.edu.sa"><postmaster@kfupm.edu.sa></a><br />
Sent: Saturday, March 20, 2010 1:34 PM<br />
Subject: Symantec Brightmail Gateway Alert Notification</p>
<p></p>
<blockquote type="cite"><p>
Symantec Brightmail Gateway Alert Notification for <a class="moz-txt-link-abbreviated" href="mailto:postmaster@kfupm.edu.sa">postmaster@kfupm.edu.sa</a></p>
<p> ======================= ALERT NOTIFICATION ================================</p>
<p> The combined message queue for the following Scanners is larger than 1048576 KB</p>
<p> Scanner Combined Message Queue Size (KB)<br />
---------------------------------------------------------------------------<br />
antispam2.kfupm.edu.sa 1069635<br />
---------------------------------------------------------------------------</p>
<p>
===========================================================================</p>
<p> PLEASE DO NOT REPLY TO THIS MESSAGE. This email was sent from a<br />
notification-only address that cannot accept incoming e-mail.</p></blockquote>
<p>***************************************</p>
<p>
Is it an error or a notification only.?<br />
Kindlu update</p>
<div class="og_rss_groups"></div>http://www.symantec.com/connect/forums/combined-message-queue-size#commentsBrightmail GatewaySecuritySat, 20 Mar 2010 13:25:16 +0000Ashruakkode1250851 at http://www.symantec.com/connectSEP 11 "Installation Interrupted"
http://www.symantec.com/connect/forums/sep-11-installation-interrupted
<p>I am attempting to install Endpoint version 11 on my home computer (licensed for civilian home use by the Department of Defense). I have attempted several of the fixes posted in other forums. Any help that you can provide would be much appreciated!</p>
<div class="item-list"><ul class="attachment-list"><li class="first last"><a href="http://www.symantec.com/connect/sites/default/files/SEP_INST.pdf">SEP_INST.pdf</a></li>
</ul></div><div class="og_rss_groups"></div>http://www.symantec.com/connect/forums/sep-11-installation-interrupted#commentsEndpoint Protection (AntiVirus)SecuritySat, 20 Mar 2010 11:53:06 +0000sixpence1250831 at http://www.symantec.com/connectSEP clients are not reflecting under replication server
http://www.symantec.com/connect/forums/sep-clients-are-not-reflecting-under-replication-server
<p>
Hi all,</p>
<p> SEP clients are directly taking updated from main management server. How to point same to replication serevr.</p>
<div class="og_rss_groups"></div>http://www.symantec.com/connect/forums/sep-clients-are-not-reflecting-under-replication-server#comments11.xEndpoint Protection (AntiVirus)SecuritySat, 20 Mar 2010 07:25:04 +0000sanoj1250801 at http://www.symantec.com/connectQurantine message release problem
http://www.symantec.com/connect/forums/qurantine-message-release-problem
<p>
<br />
Dear Adnan</p>
<p>When we try to release our quarantied messages,we were not able to release massages and have been getting the following error</p>
<p><img alt="" src="https://antispam.kfupm.edu.sa:41443/brightmail/images/Icon_Warning.gif" /><img alt="" height="1" src="https://antispam.kfupm.edu.sa:41443/brightmail/images/Spacer.gif" width="3" /> Cannot release the message. It has either been released or was unable to contact the SMTP host.</p>
<p>Kindly help</p>
<p>Regards<br />
Ashraf</p>
<div class="og_rss_groups"></div>http://www.symantec.com/connect/forums/qurantine-message-release-problem#comments11.xEndpoint Protection (AntiVirus)SecuritySat, 20 Mar 2010 07:20:24 +0000Ashruakkode1250791 at http://www.symantec.com/connectFile Hash from SEP 11...
http://www.symantec.com/connect/forums/file-hash-sep-11
<p>How do I convert a file hash from sep 11? I am part of an operation where sometimes SEP 11 fails to log the file name for one reason or another. I would like to know how to convert the file hash accordingly thus getting a file name. Thanks.</p>
<p>Brian</p>
<div class="og_rss_groups"></div>http://www.symantec.com/connect/forums/file-hash-sep-11#commentsEndpoint Protection Small BusinessSecuritySat, 20 Mar 2010 05:56:23 +0000ekopalm1250771 at http://www.symantec.com/connectSEP State Event Collector: Invalid Date Alert
http://www.symantec.com/connect/forums/sep-state-event-collector-invalid-date-alert
<p>Some of the events I receive from SEP State Event Collector generate an invalid date error, showing this as the Original Event Date:</p>
<p>Original Event Date -- Thu Jan 01 00:00:00 PST 1970</p>
<p>Has anyone else seen an issue like this?</p>
<div class="og_rss_groups"></div>http://www.symantec.com/connect/forums/sep-state-event-collector-invalid-date-alert#commentsSecurity Information ManagerSecuritySat, 20 Mar 2010 01:59:28 +0000UltraMagnus1250711 at http://www.symantec.com/connectQuestion About SEPM Manager Logs - Network Attack?
http://www.symantec.com/connect/forums/question-about-sepm-manager-logs-network-attack
<p>
So, It seems I have a "trojan" on my computer that SEP is not picking up on one of my local computers, but SEPM is logging and notifying me regarding the attack. Eventually the continuous probing / scanning of ports blocks the client computer out of existance for awhile, then back online-- unfortunately this annoyance blocks the client computer from accessing network features + shared resources (printers network drives etc) -- here is a log detail generated by sepm monitor.</p>
<p> </p>
<table border="0" width="500">
<tbody>
<tr>
<td valign="top" width="125">
<b>Event Description:</b></td>
<td class="Menue" width="375">
Somebody is scanning your computer. Your computer's UDP ports: 1900, 3702, 50809, 45507 and 42659 have been scanned from 192.168.100.201.</td>
</tr>
<tr>
<td valign="top" width="125">
<b>Attack Type:</b></td>
<td class="Menue" width="375">
Port Scan</td>
</tr>
<tr>
<td valign="top" width="125">
<b>Event Time:</b></td>
<td class="Menue" width="375">
03/19/2010 21:06:52</td>
</tr>
<tr>
<td valign="top" width="125">
<b>Remote Host IP:</b></td>
<td class="Menue" width="375">
192.168.100.201</td>
</tr>
<tr>
<td valign="top" width="125">
<b>Occurrence:</b></td>
<td class="Menue" width="375">
1</td>
</tr>
<tr>
<td valign="top" width="125">
<b>Alert:</b></td>
<td class="Menue" width="375">
1</td>
</tr>
<tr>
<td valign="top" width="125">
<b>Begin Time:</b></td>
<td class="Menue" width="375">
03/19/2010 21:07:06</td>
</tr>
<tr>
<td valign="top" width="125">
<b>End Time:</b></td>
<td class="Menue" width="375">
03/19/2010 21:07:06</td>
</tr>
<tr>
<td valign="top" width="125">
<b>Domain Name:</b></td>
<td class="Menue" width="375">
Default</td>
</tr>
<tr>
<td valign="top" width="125">
<b>Site Name:</b></td>
<td class="Menue" width="375">
Symantec Media Vault</td>
</tr>
<tr>
<td valign="top" width="125">
<b>Server Name:</b></td>
<td class="Menue" width="375">
HomeServer</td>
</tr>
<tr>
<td valign="top" width="125">
<b>Group Name:</b></td>
<td class="Menue" width="375">
Global\Symantec Media Vault</td>
</tr>
<tr>
<td>
<b>Computer Name</b></td>
<td class="Menue">
</td>
</tr>
<tr>
<td width="150">
<b>Current:</b></td>
<td class="Menue">
HomeServer</td>
</tr>
<tr>
<td width="150">
<b>When event occurred:</b></td>
<td class="Menue">
HomeServer</td>
</tr>
<tr>
<td colspan="2">
</td>
</tr>
<tr>
<td width="125">
<b>IP Address</b></td>
<td class="Menue" width="375">
</td>
</tr>
<tr>
<td width="150">
<b>Current:</b></td>
<td class="Menue">
192.168.100.200</td>
</tr>
<tr>
<td width="150">
<b>When event occurred:</b></td>
<td class="Menue">
229.157.60.79</td>
</tr>
<tr>
<td colspan="2">
</td>
</tr>
<tr>
<td valign="top" width="125">
<b>Operating system:</b></td>
<td class="Menue" width="375">
Windows Server 2003 Family Standard Edition</td>
</tr>
<tr>
<td valign="top" width="125">
<b>Location Name:</b></td>
<td class="Menue" width="375">
Default</td>
</tr>
<tr>
<td valign="top" width="125">
<b>User Name:</b></td>
<td class="Menue" width="375">
Administrator</td>
</tr>
<tr>
<td valign="top" width="125">
<b>Severity:</b></td>
<td class="Menue" width="375">
Minor</td>
</tr>
<tr>
<td valign="top" width="125">
<b>Local MAC:</b></td>
<td class="Menue" width="375">
01005E****</td>
</tr>
<tr>
<td valign="top" width="125">
<b>Remote MAC:</b></td>
<td class="Menue" width="375">
001D60****</td>
</tr>
<tr>
<td valign="top" width="125">
<b>Hardware Key:</b></td>
<td class="Menue" width="375">
BF6956C1A8429***************</td>
</tr>
<tr>
<td valign="top" width="125">
<b>Network Protocol:</b></td>
<td class="Menue" width="375">
UDP</td>
</tr>
<tr>
<td valign="top" width="125">
<b>Traffic Direction:</b></td>
<td class="Menue" width="375">
Inbound</td>
</tr>
<tr>
<td valign="top" width="125">
<b>Send SNMP trap:</b></td>
<td class="Menue" width="375">
1</td>
</tr>
<tr>
<td valign="top" width="125">
<b>Remote Host Name:</b></td>
<td class="Menue" width="375">
</td>
</tr>
<tr>
<td valign="top" width="125">
<b>Hack Type:</b></td>
<td class="Menue" width="375">
0</td>
</tr>
<tr>
<td valign="top" width="125">
<b>Application Name:</b></td>
</tr>
</tbody>
</table>
<p>Of course there is little to any information as to what is scanning the computers in local subnet, but at least i've narrowed it down to one computer -- but sep, full virus scan, nothing has come up... is there a method i can use within SEP on the local computer thats "infected" to monitor what program is causing this port scanning issue? Thanks, any help will be appreciated</p>
<div class="og_rss_groups"></div>http://www.symantec.com/connect/forums/question-about-sepm-manager-logs-network-attack#comments10.xEndpoint Protection (AntiVirus)Internet Security Threat ReportSecuritySat, 20 Mar 2010 01:36:18 +0000Diesel2NV1250701 at http://www.symantec.com/connect