Endpoint Protection

 View Only
  • 1.  SEP 12.1 tamper protection alert fills up event log

    Posted May 10, 2012 12:31 PM

    We are running SEP version 12.1.671.4971 and getting the event log getting foilled up with Symantec Tamper Protection Alerts. The exact details are below. Is there a way to exclude this alert on the client side? Why do we get these alerts in a first place? Thanks!

    Event

    Date: 5/9/2012         Source: Symantec Antivirus

    Time: 12:59:17 PM   Category: None

    Type: Error               EventID: 45

    User: NT Authority\System

    Computer: xxx-xxx-xxxx

    Description:

    Target: C:\Program Files\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Bin\ccSvcHst.exe

    Event Info: Open Process

    ActionTaken: Logged

    Actor Process: C:\Program Files\NETSUPPORT MANAGER\CLIENT32.exe (PID 232)

    Time: Wednesday, May 09, 2012 12:59:17 PM



  • 2.  RE: SEP 12.1 tamper protection alert fills up event log

    Trusted Advisor
    Posted May 10, 2012 12:47 PM

    Hello,

    Is this a Citrix server / Terminal Server?

    Check these Articles: 

    Symantec Endpoint Protection 12.1 triggers Tamper Protection on Citrix server

    http://www.symantec.com/docs/TECH163672

    Tamper Protection alerts are triggered on Citrix servers running Symantec Endpoint Protection 12.1.

    http://www.symantec.com/docs/TECH162566

    Steps:

    1 Logon to the server you wish to configure with an administrator account 
    2 Click Start, Run and type “regedit” then click OK 
    3 Browse to HKLM\SOFTWARE\Symantec\Symantec Endpoint Protection\SMC 
    4 Find the entry LaunchSmcGui and change it from DWORD 1 to DWORD 0 

    Reference: Best Practices for Symantec Endpoint Protection on Citrix and Terminal Servers

    http://www.symantec.com/docs/TECH91070

    Secondly on a kind note, you are carrying the RTM version of SEP 12.1, please migrate to the Latest version of SEP 12.1 RU1 and then to SEP RU1 MP1.
     
    Hope that helps!!


  • 3.  RE: SEP 12.1 tamper protection alert fills up event log
    Best Answer

    Posted May 10, 2012 12:59 PM

    Create a  Tamper Protection exception for C:\Program Files\NETSUPPORT MANAGER\CLIENT32.exe.

    Below KB can help you in this

    Creating a Tamper Protection exception



  • 4.  RE: SEP 12.1 tamper protection alert fills up event log

    Posted May 10, 2012 01:38 PM

    It's not a Citrix or a terminal server. Anyway thanks a lot for the quick reply.



  • 5.  RE: SEP 12.1 tamper protection alert fills up event log

    Posted May 10, 2012 01:40 PM

    I am checking with my customer if this is a safe application or not. If it is safe app, then we'll add it to the exception list. Thanks!