SAV: Symantec Antivirus Corporate Edition 10.1

List all SAV client services C:>net start | grep -i symantec    Symantec AntiVirus    Symantec AntiVirus Definition Watcher    Symantec Event Manager    Symantec Settings Manager    Symantec SPBBCSvc C:> Client configuration, Log file locations and check-in times: DAT’s File  : C:Program FilesCommon FilesSymantec SharedVirusDefs GRC.DAT File: C:Documents and SettingsAll UsersApplication DataSymantecSymantec AntiVirus Corporate Edition7.5 folder GRC.DAT Quarantine  : C:Documents and SettingsAll UsersApplication DataSymantecSymantec AntiVirus Corporate Edition7.5Quarantine Logs        : C:Documents and SettingsAll UsersApplication DataSymantecSymantec AntiVirus Corporate Edition7.5Logs Install log    : tempsav_inst.log SSC cmd line: "C:Documents and SettingsAll UsersStart MenuProgramsSymantec Client SecuritySymantec AntiVirus.lnk" Check-in time: By default,     – clients […]

Read more

INFO: Explanation of Action field values in Symantec Endpoint Protection logs

From Symantec KB article: http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2006112010562148 < p>The following table describes the different values that can appear in the Action field in Symantec Endpoint Protection and Symantec AntiVirus 10.1. Action Description Quarantined Symantec Endpoint Protection quarantined a file Deleted Symantec Endpoint Protection deleted an object, such as a file or registry key, to remove a risk. Backed Up Symantec Endpoint Protection placed an item into quarantine before a repair attempt. Left Alone Symantec Endpoint Protection detected a risk but did not take action. This can occur if the first configured action is Leave alone or if the second configured action was […]

Read more