I have the problem, that we have SEP 12.1 and Checkpoint 7.6.306.001-R73.
I did NOT choose any firewall parts for the rollout package.
After several reboot (1-10) suddenly our remote controll (Dameware) utillity is not longer working.
When i uninstall Checkpoint, Dameware is working. If i uninstall SEP12.1, Dameware is also working.
If i have both installed, i am not able to connect to dameware remotly. (Acces denied)
No events in the client, that anything was blocked.
Then i create a packacke with firewall part. The firewall parts let me see in the activity monitor which app wants communicate.
Suddenly i see trgui.exe for a sec and is gone. 5 sec later the same. So i exclude the whole Checkpoint
folder from scan. After that the, trgui.exe is showed permanent in the activity monitor.
Then i add in the exclusion policy trgui.exe to the application for monitoring.
Now i get follow:
M01Pxxxxx
xxxxx
10.22.50.198 |
Check Point Endpoint Connect
Trojan Worm |
1 |
21.07.2011 13:32:30 |
Default
w01abnav10
My Company\W01\W01 Client |
Left alone
SONAR |
c:\program files (x86)\checkpoint\endpoint security\endpoint connect\trgui.exe |
If i scan manually, but nothing was found. Perhaps the checkpoint clients have code, that symantec blocks and did not report it?