Endpoint Protection

 View Only

SEP 12.1 RU1 MP1 Third Party Product Removal Feature  

Jun 20, 2012 01:33 PM

Updated 20th Nov'12

 

Hello Everyone,

We will see how we can use  SEP 12.1 RU1 MP1 third party product removal feature..

Export desired package with custom client install settings.

In Enterprise Edition, logon to the SEPM console, Go to Admin --> Install Package --> Client Install Settings

Create new custom client install settings becauase you can not edit default client install settings.

Select the checkmark "Automatically uninstall existing security software".

In SBE, Go to common task --> select Install protection client to computers

 Export package with custom settings.

 

Export the pacakge

For testing purpose I have installed Macfee Viruscan Enterprise + Antispyware Enterprise 8.8 

Symantec can remove only supported products. 

Check supported products here:  http://www.symantec.com/business/support/index?page=content&id=TECH178757

Additional products will be added in future editions of the product.

Security products that are not in the supported products list can be removed using the SEPprep tool.

It's installed on System

Now we will run the exported sep client setup.exe. Customer can deploy SEP package with available other options like CDW, Web-link ,GPO etc.

If it's interactive setup it would promt you to remove installed software. Click on OK to continue.

If selected installation type to "Display progress bar only" or "Silent" then it won't prompt with following windows, it would directly remove installed antivurs and starts SEP installation immediately.

After that SEP client install process will start.

Upon successful install you will see SEP client icon at taskbar.

Reboot is not mandatory however after successful SEP install it's strongly recommended.

If you faced any issue during third party product removal you can refer SEP_Appremover logs, it would be created at %temp%.

I am attaching logs snippet for the reference

==============================================================================

Tue Jun 19 21:49:51 2012 === AppRemover logging started ===
Tue Jun 19 21:49:51 2012 AppRemover running version: 2.2.21.1
Tue Jun 19 21:49:51 2012 *** Calling CreateProductList ***
Tue Jun 19 21:49:51 2012 *** Calling DetectProducts ***
Tue Jun 19 21:49:51 2012 *** with arguments: iMode:3 option:0 fileGen:false
Tue Jun 19 21:50:05 2012 Succeeded to read QATestedProducts
Tue Jun 19 21:50:05 2012 Succeeded to read ProductReleaseNotes
Tue Jun 19 21:50:05 2012 Found McAfee, Inc. McAfee VirusScan Enterprise 8.8.0.777 (SEC_ID: 9) (INDEX: 759)
Tue Jun 19 21:50:05 2012 Found McAfee, Inc. McAfee VirusScan Enterprise 8.8.0.777 (SEC_ID: 10) (INDEX: 759)
Tue Jun 19 21:50:05 2012 Found Microsoft Corp. Microsoft Windows Firewall XP SP2+ (SEC_ID: 11) (INDEX: 1293)
Tue Jun 19 21:50:05 2012 Found Microsoft Corp. Internet Explorer 8.0.6001.18702 (SEC_ID: 1) (INDEX: 40)
Tue Jun 19 21:50:05 2012 WMI query in AddWMIDetectionsToProductsVec(), failed
Tue Jun 19 21:50:05 2012 WMI query in HeuristicDetect::GetWmiProducts() failed
Tue Jun 19 21:50:05 2012 WMI query in HeuristicDetect::GetWmiProducts() failed
Tue Jun 19 21:50:05 2012 WMI query in HeuristicDetect::GetWmiProducts() failed
Tue Jun 19 21:50:05 2012 *** Calling InternalDataConversion ***
Tue Jun 19 21:50:05 2012 *** Calling DestroyProductList ***
Tue Jun 19 21:50:45 2012 *** Calling RemoveProduct ***
Tue Jun 19 21:50:45 2012 *** with arguments: ProductId:760 removeMode:0 option:0
Tue Jun 19 21:51:02 2012 Succeeded to read QATestedProducts
Tue Jun 19 21:51:02 2012 Succeeded to read ProductReleaseNotes
Tue Jun 19 21:51:02 2012 Found McAfee, Inc. McAfee VirusScan Enterprise 8.8.0.777 (SEC_ID: 9) (INDEX: 759)
Tue Jun 19 21:51:02 2012 Found McAfee, Inc. McAfee VirusScan Enterprise 8.8.0.777 (SEC_ID: 10) (INDEX: 759)
Tue Jun 19 21:51:02 2012 Found Microsoft Corp. Microsoft Windows Firewall XP SP2+ (SEC_ID: 11) (INDEX: 1293)
Tue Jun 19 21:51:02 2012 Found Microsoft Corp. Internet Explorer 8.0.6001.18702 (SEC_ID: 1) (INDEX: 40)
Tue Jun 19 21:51:02 2012 WMI query in AddWMIDetectionsToProductsVec(), failed
Tue Jun 19 21:51:02 2012 Data collecting in UninstallProducts() succeeded
Tue Jun 19 21:51:18 2012 Verifying product exists.
Tue Jun 19 21:51:18 2012 OL uninstalling McAfee, Inc. McAfee VirusScan Enterprise 8.8.0.777 (SEC_ID: 10) (INDEX: 759)
Tue Jun 19 21:52:07 2012 McAfee, Inc. McAfee VirusScan Enterprise 8.8.0.777 OESIS Local Uninstall result = Succeeded(0)
Tue Jun 19 21:52:19 2012 Verifying OESIS Local uninstall results by detecting installed products...
Tue Jun 19 21:52:32 2012 Attempting to apply signature-based uninstall...
Tue Jun 19 21:52:32 2012 Result file produced.
Tue Jun 19 21:52:32 2012 exiting uninstall
Tue Jun 19 21:52:32 2012 No OL uninstall and signature-based uninstall failure found.
Tue Jun 19 21:52:32 2012 Some items could not be removed. They will be removed during the next reboot.
Tue Jun 19 21:52:32 2012 *** Calling IsRebootRequired ***
Tue Jun 19 21:52:32 2012 *** Calling IsFilePresent ***
===============================================================================


SEP 12.1 RU2 is released now & many new products are added in product removal list, Go through the following article

Third-party security software removal support in Symantec Endpoint Protection 12.1 RU2

http://www.symantec.com/docs/TECH195029

Statistics
0 Favorited
1 Views
0 Files
0 Shares
0 Downloads

Tags and Keywords

Comments

Mar 19, 2015 04:01 AM

Hi Steven,

Does Symantec have Information on current applications on those clients or will this log be available only locally to the customer?

--> There is a feature called 'Application Learning'. Application Learning allows Symantec Endpoint Protection (SEP) clients to report information and statistics about the executables that are run on them. This information is provided to the Symantec Endpoint Protection Manager (SEPM) and aggregated into the SEPM database. The purpose of this information is to build a list of known applications in an environment to create Application-based firewall rules, Host Integrity (HI) rules and can be used as a reference for developing Application Control rules and Centralized Exceptions.

Related articles:

Application Learning best practices for Endpoint Protection Manager

http://www.symantec.com/docs/TECH134367

Monitoring the applications and services that run on client computers

http://www.symantec.com/docs/HOWTO55218

 

Mar 18, 2015 07:30 PM

Hi Chetan, Will this product report back to Symantec the third party applications that are on the Clients? Does Symantec have Information on current applications on those clients or will this log be available only locally to the customer?

Nov 26, 2012 06:46 AM

Hi Rupesh,

If you don't want to apply default policies then you can withdraw them as well.

Oct 26, 2012 12:09 AM

Dear Chetan can you explan me how by default Application policies are working in 12.1 Ru1 Mp1 ........!

Aug 07, 2012 01:29 AM

Hi Manish,

We can not install SEP client through this feature.

You would required Competitive uninstaller. The tool is located on SEP DVD under \Tools\ No Support

OR 

You can download it from fileconnect also.

 

Aug 06, 2012 11:35 PM

hi Chetan,

Can we uninstall SEP Client through this feature ?

Jul 25, 2012 11:15 PM

Hi,

This will remove if only we install fresh setup in the system? what for the systems which is already installed?

Jul 11, 2012 08:05 AM

Hi Hakeem,

Check this article

Managing file fingerprint lists

http://www.symantec.com/docs/HOWTO55133

Jul 11, 2012 07:13 AM

Hi Cheton,

could please show how I can get the learn application information along with computer and user info.

 

Thanks

 

Hakeem

Jun 28, 2012 07:34 AM

ok.

Thanks for info...

Jun 27, 2012 02:19 PM

Hi,

As of now this feature is available only in SEP 12.1 RU1 MP1.

 

 

Jun 27, 2012 01:58 PM

hi,

this functionality appeared on sep 12?

is it possible to do such thing on sep 11?

Related Entries and Links

No Related Resource entered.