查看: 5890|回复: 18
收起左侧

[资讯] SEP 11 RU6 MP2 英文版发布

[复制链接]
lincom2
发表于 2010-12-5 11:09:37 | 显示全部楼层 |阅读模式
Release Update 6 Maintenance Patch 2 (RU6 MP2)

What's new in this version
The current release includes the following improvements that make Symantec Endpoint Protection and Symantec Network Access Control easier and more efficient to use. This maintenance patch cannot be installed over any versions of Symantec Endpoint Protection or Symantec Endpoint Protection Manager prior to RU6. It must be installed over RU6, RU6a, or RU6-MP1.
Symantec Protection Center
Symantec Protection Center is a Web-based console that allows you to access and manage multiple Symantec products. The console provides visibility and analytics across products as well as useful security feedback and attack statistics.
The console provides a single sign-on screen for the following registered Symantec products:
Symantec Endpoint Protection
Symantec Critical System Protection
Symantec Web Gateway
Symantec Brightmail Gateway
Symantec IT Analytics
Symantec Data Loss Prevention
Symantec Endpoint Protection Manager Web-based console
You can access Symantec Endpoint Protection Manager remotely in a Web-based console. The Java-based remote console is also still available.
Symantec Endpoint Protection for Macintosh
You can use Symantec Endpoint Protection Manager to manage Mac OS X clients that run Symantec software.
Randomized scheduled scans
You can specify a time interval during which scheduled scans start, and enable the scans to start at different times within that time interval. By running scans at random times, you can increase scan performance, especially in virtualized environments.
Enhanced default Antivirus and Antispyware security policies
For new product installations, changes in the default security policies make Symantec Endpoint Protection more efficient at detecting malware.
Customers who upgrade to Symantec Endpoint Protection version 11 RU6a MP2 do not receive new default policies. To see the new recommended Antivirus and Antispyware security policies settings so that you can make the settings changes in your policies manually, see Security Response recommendations for Symantec Endpoint Protection settings.
The Symantec Endpoint Recovery Tool
The Symantec Endpoint Recovery Tool provides an image that you can burn on a disc, and then use to scan and remove malware from client computers. You use this tool for the computers that are too infected for Symantec Endpoint Protection to clean effectively.
You can download the tool from the following URL: https://fileconnect.symantec.com/.
You need your Symantec Endpoint Protection serial number to download the tool.
Host Integrity policies check for additional security software
You can run a Host Integrity check to see whether the client computers run the following software:
Norton Antivirus 2010
Norton Internet Security 2010
Norton 360 Version 3.0
Symantec Endpoint Protection Version 11 Release Update 6a, MP2
McAfee Internet Security 2010
McAfee VirusScan Plus 2010
McAfee Total Protection 2010
McAfee VirusScan Enterprise 8.7i







本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x

评分

参与人数 1经验 +10 收起 理由
ikimi + 10 感谢提供分享

查看全部评分

lincom2
 楼主| 发表于 2010-12-5 11:11:03 | 显示全部楼层
本次更新中:
全新安装将设置新的安全与扫描策略
更新安装请参考 http://www.symantec.com/business ... t&id=TECH122943 自行修改
lincom2
 楼主| 发表于 2010-12-5 11:12:05 | 显示全部楼层
官方文件 SHA1: b21733f4c39cc95a863ee0ba95f66b1cbddc1536
salmon5
发表于 2010-12-5 11:14:00 | 显示全部楼层
看那支持平台,不得不佩服,铁壳 就是牛。安软界的老大哥啊。
lincom2
 楼主| 发表于 2010-12-5 11:16:55 | 显示全部楼层
具体更新(相当长)
Behavior and user interface changes

Performance improvements made for AutoProtect to reduce system slowdown when applications load
Fix ID: 2080191 & 2178828
Symptom: System performance slowdown when applications load a large number of temp files on startup with FileSystem AutoProtect enabled.
Solution: AutoProtect performance was enhanced to skip scanning of deleted files on close. Files will still be scanned if they are opened again prior to cleanup.

User-defined exclusions can now be added to 64-bit operating systems
Fix ID: 2026019 & 1895102
Symptom: You add user-defined exclusions on an unmanaged Symantec Endpoint Protection client, but the exclusions are not honored by the client. You are running a 64-bit operating system.
Solution: Windows 64-bit folder redirection was preventing the exclusions from being honored. The file dialog boxes for exclusion creation were modified to handle 64-bit redirected paths correctly.

"CCApp is trying to close" dialog no longer appears on shutdown
Fix ID: 2077858
Symptom: Under a high workload while a computer is shutting down, occasionally the dialog box "CCApp is trying to close" appears.
Solution: Code changes to ensure the shutdown signal is correctly received and processed by all application processes that are running.

When changing from DST to Standard Time, Scheduled Reports now run at the correct time
Fix ID: 1911213
Symptom: When changing from DST to Standard Time, the time in Scheduled Report is one hour off.
Solution: Resolved by storing the Timezone Name in the DB when configuring the Scheduled Report/Notification. This Timezone Name is used to calculate the correct Timezone offset used to generate the report. The schema was changed for this new column.

Added support for MacBinary format files to the Outlook Auto-Protect plug-in
Fix ID: 1871464
Symptom: Some Microsoft Excel attachments cannot be opened in Outlook 2003 SP3
Solution: Support for MacBinary format files was added to the Outlook Auto-Protect plug-in

Clients are no longer auto-upgraded when their group has no assigned package
Fix ID: 2052034
Symptom: A client is in a group with an upgrade package. Before the upgrade can occur, the client is then moved to a group without an upgrade package. The client is still upgraded.
Solution: The client's package information is flushed when it is moved, so the download thread will not detect and download the update.

When File System AutoProtect non-viral threat actions are set to Quarantine/Deny Access, AutoProtect always denies access and never tries to quarantine. If the file is newly created, AutoProtect deleted the file.
Fix ID: 1954266
Symptom: You have configured File System AutoProtect actions to Quarantine/Deny Access on non-viral threats. When a non-viral threat is accessed, AutoProtect denies access and does not attempt to quarantine per your configuration.
Solution: The interaction between the Symantec Endpoint Protection client and File System AutoProtect was modified to better process these types of threats. Specific changes

The UI option "Block security risks from being installed" was removed
New UI options have been added to File System AutoProtect > Advanced settings
- "Delete newly created infected files if the action is 'leave alone (log only)'" will get a new sub-option:
"Delete newly created security risks if the action is 'leave alone (log only)'".
The default state for "Delete newly created security risks if the action is 'leave alone (log only)'" will be checked.
- If the parent option "Delete newly created infected files if the action is 'leave alone (log only)'" is unchecked, "Delete newly created security risks if the action is 'leave alone (log only)'" will also be unchecked and grayed out.
lincom2
 楼主| 发表于 2010-12-5 11:18:03 | 显示全部楼层
续1
Client and Manager fixes

SMC.exe accessing an application with Network Application Monitoring no longer generates network overhead
Fix ID: 2115750
Symptom: You have configured Symantec Endpoint Protection for Network Application Monitoring, and are running an application from a network share. SMC.exe accesses the application repeatedly which generates unnecessary network traffic.
Solution: The firewall engine was attempting to read information from the network share too often. The code was modified to request the information only once.

Ping Flood and Ping of Death are now named correctly in log files
Fix ID: 2030682
Symptom: You experience a "Ping-of-Death" false positive.
Solution: The description of Ping-of-Death was incorrectly set to Jolt 2. The description of Ping Flood was incorrectly set to Ping-of-Death. The descriptions have been corrected.

SCANS table SCAN_TYPE and COMMAND_ID fields are now populated correctly for a number of scan types
Fix ID: 2052884
Symptom: You are using a tool to view the SCANS table in the Symantec Endpoint Protection Manager database. In that table, the SCAN_TYPE and COMMAND_ID fields are not populated for some scan types.
Solution: The SCAN TYPE and COMMAND ID fields are now populated for scan commands that are issued from the remote console.

User domain and host domain changes reported from the client no longer result in a network loss
Fix ID: 2060622
Symptom: The user domain name changes unexpectedly and is reported incorrectly in the Symantec Endpoint Protection Manager console. This may lead to loss of communication between the client and the server.
Solution: The code that collects the DNS domain information was modified to prevent this issue.

A missed scan event no longer triggers outside of the configured window for the first scan
Fix ID: 2049664
Symptom: You are installing the Symantec Endpoint Protection client for the first time (not an upgrade). After receiving the policy from the server, an antivirus scan occurs outside the expected scan window.
Solution: On a first-time install, the LastStartTime registry value is not set, which was triggering a scan to run unexpectedly. The scan logic was modified to account for this case so the scan is not considered a missed event.

DHCP suffix matching now looks at the active interface and will switch locations
Fix ID: 2077809
Symptom: You have configured your location-based criteria to use a DHCP connection DNS suffix. The client network changes so the rule does not match, yet the client does not switch locations.
Solution: After the computer shuts down and switches to another network interface, the offline interface's DHCP DNS suffix was still being used to choose the location. The client was modified to use the online interface suffix only.


Network Threat Protection windows appeared when using mixed mode or client mode
Fix ID: 1764415
Symptom: A message appears: "Network Threat Protection: <Application> has changed since the last time you used it." This message appears if you use client mode or mixed mode.
Solution: A new option was added to mixed mode. The Symantec Endpoint Protection Manager administrator can now correctly configure the message settings

Clients no longer take several minutes to switch locations
Fix ID: 2072812
Symptom: When using auto-location, it takes the client a long time (approximately 2 minutes or more) to switch between locations.
Solution: The hardware ID (HWID) calculation was delaying the auto-location switch. The HWID calculation now occurs closer to the start of the heartbeat cycle.

Fixed a Primary Key Violation on SEM_CONTENT during Replication
Fix ID: 2109504
Symptom: In the Symantec Endpoint Protection Console, you see the message "Primary Key Violation" during replication.
Solution: A SQL statement was modified to avoid primary key violation.

Resolved a system crash (blue screen error) when Symantec Endpoint Protection is installed with the Network Threat Protection feature
Fix ID: 2052946
Symptom: System crash (blue screen error) when Symantec Endpoint Protection is installed with the Network Threat Protection feature.
Solution: A third party NDIS6 driver was not compatible with the Symantec Endpoint Protection Teefer2.sys driver. The driver was modified to prevent the crash.

Auto-Upgrade installation no longer initiates on the client when a restart required is flagged from previous installation
Fix ID: 2064479
Symptom: During Auto-Upgrade, the installation package will run when a client has requested a restart.
Solution: The Auto-Upgrade process should not run if the client has a pending restart. The upgrade package will be ignored if there is a pending restart.

Saved Outlook attachments on Windows 7 no longer have a temporary file attribute
Fix ID: 2034671
Symptom: Saved Outlook attachments on Windows 7 have a temporary file attribute.
Solution: The temporary attribute was removed for attachments saved from Outlook.

Duplicate Serial_Number, Group_ID records were preventing the Policy Serial Number from displaying on the Symantec Endpoint Protection Manager Client > Group Details tab
Fix ID: 2028624
Symptom: The Policy Serial Number does not display on the Client > Group Details tab in the Symantec Endpoint Protection Manager console.
Solution: Duplicate Serial_Number and Group_ID records were preventing the Policy Serial Number from displaying. A primary key was added to avoid duplicate entries in the serial_number table.

Edit and Delete of Network Service events are now logged
Fix ID: 2100779
Symptom: Edit and Delete of Network Services in the Symantec Endpoint Protection Manager console are not logged as events.
Solution: Logging of events was added when the administrator edits or deletes a network service.

Symantec Endpoint Protection Manager Console refreshes when a client description is updated
Fix ID: 2032910
Symptom: The changed description for a Computer or User is not reflected immediately on the Symantec Endpoint Protection Manager Console.
Solution: A local cache is now updated when changes are made to ensure they immediately appear in the Symantec Endpoint Protection Manager console.

Symantec Endpoint Protection will no longer download the same definition file repeatedly when the disk is full
Fix ID: 2171888
Symptom: The Symantec Endpoint Protection client downloads the same content repeatedly when the disk is full
Solution: The client will now estimate the disk space needed to apply an update before deciding to download the content.

Server logs no longer show messages "Not in GZIP format"
Fix ID: 2096442
Symptom: You see the message "Not in GZIP format" when you generate a report or notification
Solution: The issue occurs when the administrator who originally created the report is locked. Reports and notifications were modified to prevent this message from appearing.

LiveUpdate content creation is no longer delayed
Fix ID: 2081458
Symptom: Delta creation of LiveUpdate content takes longer than expected. In addition, external logging of these events may take a long time to display in the Symantec Endpoint Protection Manager console.
Solution: Delta creation was on a shared timer with other Symantec Endpoint Protection Manager tasks. Delta creation was moved into a timer that is separate from the backup, scheduled reporting, and external logging tasks.

Resolved a crash (blue screen error) on the Symantec Endpoint Protection client when Network Threat Protection is installed
Fix ID: 2097548
Symptom: The computer crashes (blue screen error) on Windows 7 64-bit running Symantec Endpoint Protection 11.0 RU5 or RU6 with Network Threat Protection installed
Solution: The teefer2.sys driver was modified to fix an issue unbinding from the miniport.

Clients will now download content even with a restart pending after a migration
Fix ID: 2048485
Symptom: Clients migrating from Symantec Sygate Enterprise Protection 5.x to Symantec Endpoint Protection 11.0 do not download content until after a restart.
Solution: A mismatch between old and new versions of the sysplant.sys driver prevented the driver from accepting the new codes. Symantec Endpoint Protection was updated to send the old code if the new code failed.

.TMP files no longer fill the AgentInfo directory
Fix ID: 1785223
Symptom: Partial .tmp files are leftover in the inbox\agentinfo folder on the Symantec Endpoint Protection Manager server.
Solution: Partial .tmp files were left due to incorrect xml processing while updating .tmp files. Xml processing related to .tmp file creation was modified to ensure opstate information from legacy clients is handled properly.

Risk distribution over time report now shows all expected data
Fix ID: 1960293
Symptom: Risk events generated after a particular time are not included in the report. For example, assume the local time zone is GMT+10. If a risk event is generated before 10AM, it would not be counted as event of that day.
Solution: Risk events database entries are now translated into local time when grouping by day.

Scheduled reports no longer cause Symantec Endpoint Protection Manager to throw "Unexpected parameter value" errors
Fix ID: 2088937
Symptom: When viewing scheduled reports in the Symantec Endpoint Protection Manager console, you see "Unexpected parameter value" errors.
Solution: A SQL statement was modified to prevent the error.

Symantec Endpoint Protection firewall notifications are no longer displayed when notifications are disabled
Fix ID: 2038728
Symptom: When switching locations quickly, the application blocking notification will display, even though the notification should be suppressed by policy.
Solution: The location tracking code was modified to correctly suppress the notification.

Unmanaged Detector updates the IP Address for previously-detected MAC Address
Fix ID: 2035608
Symptom: Unmanaged Detector fails to update the IP address for previously-detected MAC Address.
Solution: A SQL prepared statement was modified to correctly update the IP address in the database.

Symantec Endpoint Protection Manager no longer displays PHP warning messages if display_errors is enabled
Fix ID: 2035626
Symptom: When "display_errors = On" is set in the php.ini for the Symantec Endpoint Protection Manager, the following messages may appear in the remote console:
"Warning: date() [function.date]: It is not safe to rely on the system's time zone settings"
"PHP Deprecated: Function session_is_registered() is deprecated..."
Solution: The message "It is not safe to rely on the system's time zone settings" may be resolved by adding both "display_error=on" and "date_timezone=<timezone>" (e.g. "date_timezone=America/Chicago") in the php.ini file.
The message "Deprecated: Function session_is_registered() is deprecated" is resolved with better session handling in Symantec Endpoint Protection Manager. No user action is required.

Sorting Antivirus policies by date now displays correctly
Fix ID: 2052537
Symptom: In the Symantec Endpoint Protection Manager remote console, when sorting the AV Policies History by Event Time, the sort order is incorrect.
Solution: Symantec Endpoint Protection Manager was modified to better handle exceptions in order to properly sort the policies.

LiveUpdate "Low Disk Space Warning" now runs Windows Cleanup correctly
Fix ID: 1877483
Symptom: If you are low on disk space, running LiveUpdate prompts you to run Windows Cleanup. Windows Cleanup fails to start if the user chooses to open this application.
Solution: The environment block of LUALL.EXE was modified to allow Windows Cleanup to run.

Scan and Deliver now submits threat samples correctly to gateways.dis.symantec.com
Fix ID: 2047967
Symptom: You have a .txt file in your quarantine that you want to submit to Symantec Response. Scan and Deliver fails to submit the threat sample to Symantec.
Solution: A date-processing issue when handling the samples was corrected to allow the submission to complete.

Default User folder on a Citrix server can now be renamed when SMC.exe is running
Fix ID: 1833529
Symptom: You are running Symantec Endpoint Protection 11.0 on a Citrix server, and the SMC.exe process is running. You want to rename the Default User folder but cannot because it is locked by the SMC process.
Solution: The SMC.exe process user profile directory can now be configured via a registry key.
HKLM\Software\Symantec\Symantec Endpoint Protection\SMC\UserProfileOverride
(REG_EXPAND_SZ)
Its value is the desired user profile directory path. This path may contain environment variables and DBCS chars.

Client activity log now identifies the GUP used by the client
Fix ID: 2028334 & 2103398
Symptom: In the client activity log, you wish to see which GUP the client connects to. There is no log message providing this information. Previous releases of Symantec Endpoint Protection 11.0 contained this message.
Solution: The following log message was re-introduced:
"Start using Group Update Provider (proxy server) @ <hostname>:2967"

Policies are now always applied to Symantec Endpoint Protection 11.0 client
Fix ID: 2047203
Symptom: You want to apply a policy to your Symantec Endpoint Protection 11.0 client The policy is never applied.
Solution: A COM interface ID was modified to prevent a compatibility issue with some versions of msxml2.dll.

The "Total" row is reintroduced to a number of reports
Fix ID: 2074989
Symptom: The "Total" row was removed from a number of reports in Symantec Endpoint Protection 11.0 RU6.
Solution: The HTML legend and total row were re-introduced in the following reports:
App and Device Control > Top Groups With Most Alerted Application Control
Network Threat Protection > Top Traffic Notifications by Group
Network Threat Protection > Security Events by Severity
Computer Status > Symantec Endpoint Protection Product Versions
Computer Status > Compliance Status Distribution
Computer Status > Client Online Status
Computer Status > Client Inventory
System > Top Clients That Generate Errors and Warnings
Application and Device Control > Top Devices Blocked
Application and Device Control > Top Targets Blocked

Clients remain online after a database restore prior to establishing any communications between clients and Symantec Endpoint Protection Manager
Fix ID: 1855354
Symptom: You have performed a database restore, and communication between clients and Symantec Endpoint Protection Manager has not yet been reestablished. In the remote console the clients show as connected (green dot).
Solution: The online status for clients is reset to "not connected" during a database restore.

Daily scheduled scans now run once per day only
Fix ID: 2047179
Symptom: A scan is configured to run once per day. The scan inadvertently runs two or more times per day.
Solution: Some computers automatically adjust the clock backwards to re-synchronize with a time server. In some cases this may cause the scheduled scan to run more than once per scheduled time. The scan logic was modified to detect and correct for this condition.
lincom2
 楼主| 发表于 2010-12-5 11:18:29 | 显示全部楼层
续2
Resolved an error indicating COH32.exe has crashed
Fix ID: 2107090
Symptom: Symantec Endpoint Protection clients receive a SONAR error indicating that Symantec Endpoint Protection needs to close. coh32.exe is listed as the faulting application.
Solution: Named pipe communication in COH was enhanced to prevent this crash.

Client status on the Symantec Endpoint Protection Manager home page now matches logs and reports
Fix ID: 1925448
Symptom: Home > Status Summary and Monitors > Logs > Computer Status reports do not show the same number of clients.
Solution: SQL queries for the affected reports were modified to display the correct number of clients.

Source IP address is now correctly displayed in Monitors > Logs > Risks
Fix ID: 1966483
Symptom: The risk monitor logs show a source IP address of "0.0.0.0".
Solution: The Symantec Endpoint Protection Manager server was modified to display a blank if the IP doesn't exist, instead of 0.0.0.0. The client was updated to ensure the source computer IP is correctly transferred to the server.

Content delivery via GUP is successful if HTTPS is used for client-server communication
Fix ID: 1829698
Symptom: You configure the HTTPS protocol for client-server communication, and you have GUP configured. GUP fails to deliver the content to the clients.
Solution: GUP over HTTPS was not supported until this release. This release adds HTTPS support to GUP via the WinHTTP Microsoft API.

Symantec Endpoint Protection now sets correct PathBackup values in RasMan\PPP\EAP Keys
Fix ID: 2054817
Symptom: On a 64-bit computer, you perform an upgrade of Symantec Endpoint Protection 11.0. After the upgrade, the RasMan\PPP\EAP Keys have replaced "SysWOW64" with "System32".
Solution: The Symantec Endpoint Protection 11.0 upgrade was accessing an incorrect registry key to determine the path to rastls.dll on 64-bit computers. The upgrade was modified to use the correct registry location.

Unnecessary DNS requests from Symantec Endpoint Protection clients are no longer generated
Fix ID: 2086881
Symptom: Higher than necessary network traffic as Symantec Endpoint Protection clients send unnecessary DNS requests. This happens if duplicate DNS server entries are listed in the client profile.
Solution: Check for duplicate DNS name entries in profiles, to eliminate unnecessary requests.

Resolved memory leak during start up
Fix ID: 2107165
Symptom: On start up, approximately 800Kb of memory is allocated for the IPS engine and is not released.
Solution: Free this non-paged memory immediately after the IPS engine loads.

Scheduled scans run at the wrong time on Vista or later operating systems when users are logged off
Fix ID: 2047067
Symptom: Scheduled scans run at logon instead of scheduled time on Vista or later operating systems
Solution: Code changes to ensure the scheduled scan is executed in scenarios where the user is logged off, or where a Windows scheduled task is running at the scheduled time. This applies to Windows Vista or later operating systems.

Application name missing from exported Network Threat Protection Attacks logs
Fix ID: 2067063
Symptom: Application name is missing from exported Network Threat Protection Attacks logs.
Solution: Added the APP_NAME column when exporting the Network Threat Protection Attacks Logs.

Updated scan exclusion lists on 64bit operating systems
Fix ID: 2000574
Symptom: DHCP files, DNS files and WINS files are not added into the scan exclusion list automatically on 64bit operating systems.
Solution: Add DHCP, DNS and WINS files into the 64bit scan exclusion list automatically .

RunOnce reg key added for the Teefer2 driver during installation
Fix ID: 2043246
Symptom: When RunOnce key is not present during an installation, the Teefer2 driver may not be installed correctly.
Solution: HKLM\Software\Microsoft\CurrentVersion\RunOnce key is created during installation of the Teefer2 driver, if it is not already present.

Symantec Endpoint Protection 11.0 Client and Quarantine Server now communicate correctly on a specified port
Fix ID: 2114451 & 2100542
Symptom: Symantec Endpoint Protection 11.0 client and Quarantine Server send and receive data on an unexpected port when configured to use a specific port.
Solution: Code changes to allow the Symantec Endpoint Protection 11.0 client and Quarantine Server to listen on specified ports by adding several registry keys:
32-bit platform - Quarantine Server:
HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Quarantine\SendToUIPort
32-bit platform - Symantec Endpoint Protection 11.0 client:
HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Quarantine\Server\ListenToUIPort
64-bit platform - Quarantine Server:
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Symantec\Symantec Endpoint Protection\AV\Quarantine\SendToUIPort
64-bit platform - Symantec Endpoint Protection 11.0 client:
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Symantec\Quarantine\Server\ListenToUIPort
All clients and Quarantine Servers must have one of the above keys to ensure they all communicate on the same port.

32bit clients no longer download 64bit definitions
Fix ID: 2084734
Symptom: 32 bit Symantec Endpoint Protection client download 64bit AntiVirus definitions.
Solution: Code changes to ensure the correct definitions are downloaded for the client.

Network Threat Protection no longer causes applications to crash with an image base address of 0x10000000
Fix ID: 1915141
Symptom: Occasional application crashes with Network Threat Protection enabled.
Solution: Code changes to Network Threat Protection to obtain the image base address dynamic rather than assigning a static address.

Network Threat Protection no longer causes applications to hang
Fix ID: 2030478
Symptom: Occasional system hangs with Network Threat Protection enabled.
Solution: Code changes made to prevent the hang from occurring.

System crash (blue screen error) no longer occurs when Application and Device control is enabled
Fix ID: 2142085
Symptom: System crash (blue screen error) when Application and Device control is enabled.
Solution: Code changes made to no longer block access to the system volume.

Computer status report now shows correct totals
Fix ID: 2083627
Symptom: Symantec Endpoint Protection Manager Computer Status report (Protection Content versions) shows incorrect client totals for "Commercial Application List Versions" and "Permitted Applications List Versions".
Solution: Modified the SQL for the Protection Content Versions report to exclude the old content revisions from the database.

Resolved conflicts between FileSystem AutoProtect and the Windows indexing service
Fix ID: 1717040
Symptom: Domain controller hangs with Symantec Endpoint Protection 11.0 installed and FileSystem AutoProtect enabled.
Solution: Oplocks are now monitored when the AutoProtect driver is not running, preventing conflicts with the Windows indexing system.

Corrected the FileSystem AutoProtect exclusions for network drives
Fix ID: 2029493
Symptom: FileSystem AutoProtect exclusions do not take effect properly on shared drives. Detections that should have been excluded are detected via a UNC path or from browsing Windows Networking.
Solution: AutoProtect was modified to correctly handle exclusions on network drives.

Changes to GUP behavior to preserve shared content after the GUP is restarted
Fix ID: 2061670
Symptom: All content in folder SharedUpdates on a GUP is purged if a download is in progress and the machine is restarted or SMC is restarted.
Solution: Code changes made to preserve downloaded content after a GUP is restarted while a download is in progress.

Corrected the port number displayed in Symantec Endpoint Protection Manager for use of log forwarding
Fix ID: 2060618
Symptom: Symantec Endpoint Protection Manager's log forwarding allow TCP port 514 to be entered, but displays the default port value of 1468.
Solution: Corrected the display in Symantec Endpoint Protection Manager to show the correct report instead of the default port.

Added logging of client mode changes
Fix ID: 2100770
Symptom: When switching clients from Computer mode to User mode (and vice-versa), the event is not logged.
Solution: Added logging of events when an administrator switches the mode of clients.

Scheduled replication will now run correctly following a database restart
Fix ID: 2020597
Symptom: Scheduled replication will not run after restarting the database
Solution: Code changes to ensure that replication will start again following a database restart.


Correct memory usage reported in the Site Status report
Fix ID: 2040220
Symptom: Memory usage reported in the Site Status report is different from the memory usage shown in Windows Task Manager in virtual environments.
Solution: Display both the memory usage shown in Task Manager and the total memory used. When a user hovers over each number, the data is shown with a tooltip.

Corrected site reporting status in the Site Status report
Fix ID: 2063758
Symptom: The Monitors > Summary tab incorrectly shows a site as "good" when one of the servers is offline.
Solution: Code changes to the algorithm for determining if a server is offline. The same logic changes apply when calculating the Health Status of a site in the Site Status Report.

Clients can now be sorted correctly by free memory and disk space available
Fix ID: 2083346
Symptom: When sorting clients by Free Memory, Free Disk Space and Total Disk Space, clients are not sorted correctly.
Solution: Modifications made to string handling to return numeric values, correcting the sorting algorithm.

Dial-up modem rules are now skipped if no dial-up modem is present
Fix ID: 2069798
Symptom: A firewall rule that blocks traffic for dial up modems will be triggered even if the computer does not have a dial-up modem.
Solution: Code changes to correctly skip dial-up related rules if there is no dial-up connection.

Export of "Packet" logs from Symantec Endpoint Protection Manager now contains an "Action" field
Fix ID: 2003486
Symptom: Exports of "Packet" logs from Symantec Endpoint Protection Manager are missing the "Action" field.
Solution: Code changes made to export the "Action" field in "Packet" log exports.

Host Compliance Logs and Compliance Report on Symantec Endpoint Protection Manager now shows all data shown in the logs from the client
Fix ID: 1968807
Symptom: Host Compliance Logs and Compliance Report on Symantec Endpoint Protection Manager is different than the logs uploaded from the client.
Solution: Code changes made to correct the separators used in the log files which were preventing all data from being processed.

Computers Not Scanned report no longer contains duplicate entries
Fix ID: 1993921
Symptom: Clients are mistakenly shown multiple times in the "Computers Not Scanned" report.
Solution: SQL query was modified to report on clients based on the scan completed times, rather than scan started.

Firewall Policy rule changes are now displayed correctly
Fix ID: 2019390
Symptom: When a Firewall policy rule changes due to location change, the rule change is not shown on the client UI (View Network Activity page).
Solution: Changes to the client UI code to ensure the dialog box is closed and the rule change is displayed correctly.

English text shown in German localized version
Fix ID: 2096003
Symptom: English text appears in German Symantec Endpoint Protection Manager remote console.
Solution: The text was correctly localized.

Changes to prevent a crash with BugCheck F7
Fix ID: 2065490
Symptom: Microsoft Vista computers running Symantec Endpoint Protection 11.0 crash with BugCheck F7.
Solution: The AutoProtect kernel driver was modified to prevent a stack overflow condition.

Quarantine Server now shows the correct version number
Fix ID: 2098739
Symptom: Incorrect version number showing for the Quarantine Server within "Add or Remove Programs" control panel and "About Symantec Central Quarantine" dialog.
Solution: updated the .ism and .rc files to show the correct product version number within the "Add or Remove Programs" control panel and "About Symantec Central Quarantine" dialog.

Resolved situation where clients do not download content until a user logs in
Fix ID: 1978998
Symptom: In some cases, clients in computer mode configured to pull content from Symantec Endpoint Protection Manager, will fail to get content if no user is logged in.
Solution: Code changes to ensure computer description is valid when comparing database entries to active directory entries.

Resolved issue where client updates are reported as "In Progress" instead of "Completed"
Fix ID: 2035728
Symptom: After an Update Content command is issued, some clients report as In Progress instead of Completed in the status field.
Solution: Code change to correctly reset the uploaded flag for the command after the client update has completed successfully.

Changes to correct client search functionality
Fix ID: 2034712
Symptom: Client Search function returns incorrect results if the search involves more than 200 groups.
Solution: Code changes to fix the SQL commands used to query and group clients.

Restored ClientRemote option to select concurrent client deployments
Fix ID: 2071053
Symptom: The Deployment Number option is missing when using the client Migration & Deployment Wizard.
Solution: Code changes to the client remote tool to restore the Deployment Number option and folder page in the ClientRemote tool.

Corrected the labeling of security risks in the Symantec Endpoint Protection Manager Risk log when a threat is detected in a compressed file
Fix ID: 1928203 & 2086588
Symptom: When the Symantec Endpoint Protection client detects a security risk in a compressed file, the Risk log in Symantec Endpoint Protection Manager console displays it as "Virus found" instead of "Security risk found".
Solution: Show the alert record for a zip file as "Compressed File" instead of "Virus Found" to match the client side behavior.

Corrections to pie charts shown in Risk Reports
Fix ID: 2055022
Symptom: Risk Report pie charts are displayed incorrectly with duplicate colors appearing and inaccurate percentages shown on the chart.
Solution: Multiple code changes to correct the pie chart display.

Changes made to limit the size of the GUP list
Fix ID: 2120293
Symptom: When the GUP list contains thousands of items there may be performance problems resulting in a delayed content updates and higher than normal bandwidth usage.
Solution: Code changes to limit the size of the GUP list to 1Gb.

Cleanwipe 4.2 now removes SCS 3.1 Quarantine and SCFPolcy folder
Fix ID: 1827639
Symptom: When running in silent mode, Cleanwipe 4.2 does not remove the SCS 3.1 Quarantine or SCFPolcy folders.
Solution: Code changes to delete these folders when running in silent mode. When not run in silent mode, the MSI uninstaller will display a dialog allowing the user to chose to delete these folders.

Resolved LiveUpdate error preventing content from being downloaded
Fix ID: 2006319
Symptom: "<LUThreadProc>@@@@@@@@@ LU DEBUG ONLY- Download file failed due to wrong file size" error message appears in the sylink log and LU content is not downloaded by clients.
Solution: Code changes to resolve the edge-case scenario where the error message occurs and the content is not downloaded correctly.

Resolved issue where GUP accepts a client connection but does not deliver content
Fix ID: 2094762
Symptom: With multiple clients requesting the same content file from a GUP, in some cases a client will not receive the content if a previous attempt to download the same content failed. Restarting the GUP's smc service resolves the issue.
Solution: GUP code changes to improve error handling of content distribution logic.

Resolved issue where clients are unable to download content deltas when Symantec Endpoint Protection Manager load balancing is used
Fix ID: 2049824
Symptom: In multi-Symantec Endpoint Protection Manager environments where load balancing is used and clients are managed by GUPs, situations can occur where clients do not receive content. In these scenarios, clients contact one Symantec Endpoint Protection Manager to generate a content delta, but the GUP contacts a different Symantec Endpoint Protection Manager. The delta does not exist on the Symantec Endpoint Protection Manager contacted by the GUP, and nothing is downloaded.
Solution: Code changes to allow the GUP to contact multiple Symantec Endpoint Protection Managers if the requested content delta is not available.

Log files now respect the log limit values set in Symantec Endpoint Protection Manager
Fix ID: 2007845
Symptom: When a log file is being read by an external application, if Symantec Endpoint Protection Manager Symantec Endpoint Protection Manager is attempting to delete the file, additional log entries are made to the log file.
Solution: Code changes made to allow for synchronization between Symantec Endpoint Protection Manager and external log reading applications. Symantec Endpoint Protection Manager will retry 30 times with an interval of 1 second if the log file is locked by another application. The settings are configurable in the conf.properties file. The following are the two settings that can be configured: scm.externallog.retrycount=30 and scm.externallog.retryinterval=1000

Resolved a system crash (blue screen error) caused by Wpsdrvnt.sys
Fix ID: 2051421
Symptom: Crash (blue screen error) caused by Wpsdrvnt.sys with BugCheck 50.
Solution: The wpsdrvnt.sys driver was modified to prevent a memory condition leading to a crash.

Resolved an issue causing network connectivity issues with Network Threat Protection enabled
Fix ID: 2085484
Symptom: A computer running Java applications with Network Threat Protection installed experiences network connectivity problems.
Solution: Code changes made to the teefer2.sys odriver to avoid this issue.

Resolved an issue where Internet Explorer 9 Beta prevents clients from downloading content from Symantec Endpoint Protection Manager
Fix ID: 2167737
Symptom: After installing Internet Explorer 9 Beta, the Symantec Endpoint Protection client is no longer able to download content from Symantec Endpoint Protection Manager.
Solution: Code changes to support API changes made by Microsoft in Internet Explorer 9 Beta.

Fixed an issue where a full scan runs instead of an active scan
Fix ID: 1991159
Symptom: When startup scans are configured to run on managed clients, a full scan is run instead of an active scan if the user logs off before the active scan finishes.
Solution: Code changes to correct the issue. When a startup scan is configured for a managed client, an active scan runs correctly.

Scheduled scans now run on Windows Server 2008 after a user has logged off
Fix ID: 2047880
Symptom: Scheduled scans do not start as scheduled when a user logs off of Windows Server 2008.
Solution: Code changes to resolve the issue.

Resolved a scenario where clients download a full.zip instead of a delta file
Fix ID: 2145102
Symptom: After a client is restarted, a full.zip file is downloaded instead of a delta file if a previous download attempt has failed.
Solution: Code changes to ensure the delta file can be downloaded after a previous failed attempt to download.

Resolved a scenario where clients download an unnecessary full.zip file
Fix ID: 2158533
Symptom: When download randomization is turned on, a full.zip file is downloaded unnecessarily after a client starts up.
Solution: Code changes to address the issue, preventing an unnecessary additional download.

Network Threat Protection now passes UDP traffic correctly on port 39999
Fix ID: 2079287
Symptom: Network Threat Protection on 64-bit operating systems does not pass UDP traffic on port 39999 correctly.
Solution: The SNAC64.exe process was interfering with traffic on this port. Symantec Endpoint Protection was modified to prevent this interference.

Corrected the time shown for "End Datetime" in exported scan logs from Symantec Endpoint Protection Manager
Fix ID: 2066917
Symptom: The time shown for "End Datetime" in Scan logs exported from Symantec Endpoint Protection Manager always contains the local time equivalent of GMT 00:00.
Solution: Code changes to prevent the scan end time from being truncated.

File access times are now correctly preserved when using Hierarchical Storage Management
Fix ID: 2028790
Symptom: In a Hierarchical Storage Management (HSM), the NoFileMod registry setting is not correctly preserving file access times.
Solution: The Common Client and Decomposer components were modified to honor the NoFileMod registry setting to prevent USN journal updates.

Resolved a UDP flood attack false positive
Fix ID: 2058022
Symptom: After upgrading to Symantec Endpoint Protection 11.0 RU6, the client detects a UDP flood attack.
Solution: The UDP flood detection thresholds were modified to reduce the occurrence of false positive flood attacks.

Removed unnecessary logon prompt when creating a report filter
Fix ID: 2112270
Symptom: In the Symantec Endpoint Manager Web interface the administrator is prompted to log on again when creating a report filter.
Solution: A p3p header was added to some .php files to avoid lost sessions using the Web interface.

Log entries for 'DBData_Event_Type_x0' are now handled correctly
Fix ID: 1987624
Symptom: After applying a GUP Policy, user will see 'DBData_Event_Type_x0' entries in the client-server activity logs.
Solution: Unique Event IDs and descriptions were defined for two client request types. These requests for updated GUP lists did not previously have descriptions, causing unknown events to be written in the log files.

Resolved issue where replication fails due to insufficient available memory
Fix ID: 2057061
Symptom: Failed replication between SQL and embedded database with error "OutOfMemoryError: GC overhead limit exceeded".
Solution: Code changes to ensure adequate memory is available before table data is retrieved.

Auto-Location Switching on Windows 7 now works correctly with Juniper VPN
Fix ID: 2023564
Symptom: Auto-Location is not effective for Juniper SSL VPN configurations on 64bit platforms.
Solution: Check the correct registry settings on 64bit platforms.

Changes to reduce unwanted AutoProtect detections while the client loads a policy
Fix ID: 1978553
Symptom: Known Security Risk Exclusion is not always honored when the client policy is being loaded, resulting in unwanted AutoProtect detections.
Solution: Code changes to ensure the policy is loaded correctly before scanning, reducing the chance of these unwanted detections.

Resolved compatibility issue with Parallels Virtuozzo Containers (PVC) application
Fix ID: 2015424
Symptom: Parallels Virtuozzo Containers (PVC) installation hangs while Symantec Endpoint Protection is running.
Solution: Code changes to handle the null pointer received during stack tracing.

Improved the console responsiveness when viewing the Admin > Servers page
Fix ID: 2072316
Symptom: The Symantec Endpoint Protection Manager console is slow in the Admin > Servers page.
Solution: Code changes to optimize the query on server side which is returning the client log data.
flyskyz
发表于 2010-12-5 11:37:14 | 显示全部楼层
2005年至今一直在用企业版,都没什么事,前几天突然有台服务器被机房封了,说是中了木马,郁闷,看来SEP对木马不感冒是真的。
lawmaker
发表于 2010-12-5 13:04:01 | 显示全部楼层
等待提取版
lincom2
 楼主| 发表于 2010-12-5 14:09:29 | 显示全部楼层
安装后的版本号为 11.0.6200.754



本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-10-4 15:37 , Processed in 0.140672 second(s), 19 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表