SEPM: Remediating LiveUpdate component

1) Stop the service Symantec Endpoint Protection Manager in the task manager. Delete the following folders : C:Program FilesCommon FilesSymantec SharedSymcDatasesmvirdef32 C:Program FilesCommon FilesSymantec SharedSymcDatasesmvirdef64 C:Program FilesCommon FilesSymantec SharedSymcDatasesmipsdef64 C:Program FilesCommon FilesSymantec SharedSymcDatasesmipsdef64 2) Execute regedit and make a backup of : HKEY_LOCAL_MACHINESOFTWARESymantec;  Go into HKEY_LOCAL_MACHINESOFTWARESymantecInstalledApps; and delete the following values : HKEY_LOCAL_MACHINESOFTWARESymantecInstalledAppsSymcData-sesmvirdef32 HKEY_LOCAL_MACHINESOFTWARESymantecInstalledAppsSymcData-sesmvirdef64 HKEY_LOCAL_MACHINESOFTWARESymantecInstalledAppsSymcData-sesmipsdef32 HKEY_LOCAL_MACHINESOFTWARESymantecInstalledAppsSymcData-sesmipsdef64; Go into HKEY_LOCAL_MACHINESOFTWARESymantecSharedDefs; and delete the following values : HKEY_LOCAL_MACHINESOFTWARESymantecSharedDefsSymcData-sesmvirdef32 HKEY_LOCAL_MACHINESOFTWARESymantecSharedDefsSymcData-sesmvirdef64 HKEY_LOCAL_MACHINESOFTWARESymantecSharedDefsSymcData-sesmipsdef32 HKEY_LOCAL_MACHINESOFTWARESymantecSharedDefsSymcData-sesmipsdef64 3) Click Start > Settings > Control Panel. Click Add/Remove programs. Click LiveUpdate. Click on Remove. Follow the screens to uninstall liveupdate. In Windows explorer, delete the following folders if present […]

Read more

SEP: Enable SyLink logging for SEP client communication troubleshooting

To create a Sylink log manually: Locate the following value in the registry at the specified location found below: [HKEY_LOCAL_MACHINESOFTWARESymantecSymantec Endpoint ProtectionSMCSYLINKSyLink] Right Click on the SyLink Key, and chose New > String Value. In the field provided type DumpSylink, then hit Enter. Right Click on DumpSylink, and click Modify. In the Value data field, specify the location and name desired for the dump file. (I.E. C:logsSylink.log) Then click OK. A restart the SMC service after the change is necessary. <p>Go to <b>Start</b>, select <b>Run</b>, and in the field provided type: <b>smc -stop, </b>then click<b> OK.</b> Go to Start, select […]

Read more

Enable debug logging for SEP Manager

Stop the Symantec Endpoint Protection Manager service Add the line scm.log.loglevel=fine to the bottom of the file: C:Program FilesSymantecSymantec Endpoint Protection Managertomcatetcconf.properties Start the Symantec Endpoint Protection Manager service Log file will be created with debug statements under below folder: C:Program FilesSymantecSymantec Endpoint Protection Managertomcat

Read more