I have recently uninstalled Symantec endpoint client from a few machines that were having some performance issues. I went to add/remove programs and selected remove on symantec endpoint. I input the Symantec administrator password, and then completed the uninstall.
We had a symantec managing server.. where we would put in an ip address and it would locate the machine on the domain. It would then install. I'm not sure if there was a group policy in place. Looking now at group policy, I don't see a Symantec policy anywhere. Is there someway to block the install? Or what should I look for in group policy ?
Anyway, Uninstall the client again. Remove the inheritance attribute from the "%programfiles%\symantec" directory. Make sure no identifier has access to it. Reboot. If you are lucky, You will get an error from the source thats trying to install it. If you are not, The client will not be installed.
I went further with my investigation to answer your concerns.
Even if at the moment I don't have an article explicitly talking about those scheduled tasks, the telemetry they are serving is fully explained here:
The general SEP Privacy Notice is available here:
-protection-privacy-notice-en.pdf
Both of them are shown to you for review and acceptance at installation time and it appears you may toggle telemetry from SEPM 14 console.
About "patches", to be precise, we are talking about updating some scan engines or libraries along with new antivirus definitions to ensure the product can handle new threats. Malware is evolving too fast to wait for new full product releases; without such updates the product will rapidly become obsolete not differently than having old definitions. This is not a new feature added in SEP 14. I understand you may have some concerns about such patches and no system change is completely without risks, indeed; yet, the risk of generic incidents due to those patches is much lower than facing security incidents due to their absence.
Please, let me know if there's something else you need.
I have Symantec Endpoint Protection (SEP Client Version 11.0.4000.2295) running on every computer in my small network. One of our laptops recently began running slow so I did a virus scan, neither the Active Scan or the Full Scan found any infections. The next day the computer was largely inoperable so I booted using a Kaspersky Virus CD and discovered multiple infections of the W32.Virut.CF virus. I don't understand why my expensive symantec product did not catch this infection. I asume I need to get rid of SEP and get something better but does anyone know why this product has failed to protect me? My liveupdate runs daily and the virus definations were up to date.
Thank you.
I'm running SEPM out of a Windows 2012 server, trying to push SEP clients to my endpoints. The whole process goes fine until the very end, at the "Deployment Summary" screen, where under "Deployment Status" it says "Failed." The same thing happens when I push communications packages.
you might want to have a look at the below article. in any case I (as an Ex symantec Technician) can tell you that this case is not headed in the right direction. I second brain here, have the case handled by a senior technican or get it escalated to advanced engineer as we cannot directly work with backline engineer.
Any idea where this IDSvia64.sys file is located? I cannot find this on my system. I did however uninstall all symantec features except the basic virus, spyware protection. I am getting an average of 4Gbps throughput but that is still only half what the system can do without syamntec installed. I am thinking this file doesnt exist in Symantec Endpoint 12.1.6a
Thanks for following. I will post Symantec's official response after I get it. Currently It is escalated and handed off to the Backline Engineers. I had another support vendor of ours who I was working with before we realized it was Symantec causing our slowness. They have recreated this in their labs. I have asked Symantec to recreate this in their labs. At this point that is what they are doing. I have requested daily updates but was told due to the nature of this issue it could take a week or two to get more information. Very frustrating problem. I have been playing with different components being installed and here are some interesting results. The best I can do is to install the client with basic protection only and no download insight (Which I am ok with on a server) but I am not ok with losing 3 Gbps of my total possible bandwidth.
I installed a competitors endpoint agent and performed the same tests. The results were much better, I was able to get full or nearly full bandwidth using a non symantec product. I also tested its functionality by downloading the eicar.org test virus and it caught it as we would expect.
The issue must be with specifying Service. If I remove 3389 from the rule, and simply allow all traffic between the two endpoints, I can RDP fine. As soon as I specify TCP Remote Port 3389, the rule no longer permits RDP. Yet the logs show Remote Port 3389 was blocked. Even if I specify Local and Remote TCP 3389 in the Service, still will not connect unless it specifies "Any".
The server and all but one client have Symantec Endpoint Protection version 12.1.1101.401 (Release) RV1MP1. It's been a few years since I've used SEP but it looks to me like all the clients were installed in managed mode as I'm unable to change some settings. I would've thought the server would have the SEP manager installed but it does not, it has the SEP client same as all the workstations. One workstation has nothing installed. Is there a way to locate what computer had the endpoint manager installed or can I just install it on the server and try to connect the clients to it? I'm wondering if the previous IT people installed the manager on one of their computers in order to deploy?
i have randomely checked 6,7 systems and found SEP installed, after that i checked symantec endpoint protection service which is already started, but when i try to start the SEP client from system tray or from start menu it is showing Symantec Endpoint Protection cannot open because some Symantec Services arestopped. Restart the Symantec services, and then open Symantec Endpoint Protection. Symantec Endpoint Protection cannot open because some Symantec Services are stopped. Restart the Symantec services, and then open SymantecEndpoint Protection.
When Broadcom acquired Symantec in 2019, they continued to support Symantec Endpoint Protection but chose in late 2020 to end-of-life the product. As CrowdStrike became the Penn-recommended endpoint detection and response solution, there was no longer a need to keep a relationship with Symantec.
The contract for individually owned systems ends on May 24th, 2022. Though these endpoints will still provide protection for some time after the contract ends, people should plan to transition away from SEP as soon as possible.
For University-owned systems, ISC recommends using CrowdStrike or an equivalent endpoint detection and response solution. If you have SEP deployed alongside CrowdStrike, we recommend first removing SEP from those endpoints and then applying more aggressive prevention settings to ensure CrowdStrike is providing the protection levels you need.
df19127ead