WelcomeProducts & ServicesSecurity ResponseSupportSolutions & IndustriesLicensingTrainingStore
Enterprise
Symantec.com > Enterprise > Support > Knowledge Base


Release notes for Symantec Endpoint Protection 11.0.x and Symantec Network Access Control 11.0.x

Question/Issue:
This article documents the changes and fixes in each update to Symantec Endpoint Protection 11.0.x and Symantec Network Access Control 11.0.x.


Solution:
As updates to Symantec Endpoint Protection are released, they are added as sections in this document. The sections are added in chronological order, with the most recent additions at the top.

Note: To download the latest release of Symantec Endpoint Protection, read the following document: Obtaining an upgrade or update for Symantec Endpoint Protection 11.x or Symantec Network Access Control 11.x.

This document should be read in conjunction with the appropriate Readme files:



Release Update 5 (RU5)

What's new in this version
The current release includes the following improvements that make Symantec Endpoint Protection and Symantec Network Access Control easier and more efficient to use.

Symantec Endpoint Protection Manager now supports the following operating systems:
Symantec Endpoint Protection Manager can now be used with Microsoft SQL Server 2008.

The Symantec Endpoint Protection or Symantec Network Access Control client now supports:
The size of the exported client installation package has been reduced.

You can configure the following features for the Group Update Provider:
The client now includes a Download Support Tool command on the Help and Support menu.
Symantec Network Access Control includes the following enhancements:

Components included in this version


ComponentVersion
Symantec Endpoint Protection 11.0.5002
Symantec Network Access Control11.0.5002
Auto-Protect 10.3.0.15
Avengine20081.1.1
Behavior Blocking3.3.0.015
ccEraser2007.0.1.6
COH6.1.9.44
Common Client106.5.0.10
DecABI1.2.5.130
Defutils4.1.1
ECOM81.3.0.13
VxMS (MS Light)5.2.0.4
LiveUpdate 3.3.0.92
LiveUpdateAdmin2.2.1.16
Microdefs2.7.0.13
QServer3.6.20
WpsHelper12.0.1.41
SyKnAppS3.0.3.3
SymEvent12.8.0.11
SymNetDrv7.2.5.9
Teefer211.0.5

Product fixes by category

Symantec Endpoint Protection Antivirus and Antispyware
This section describes the customer fixes for Antivirus and Antispyware since the release of MR4 MP2 (11.0.4.4200).



Maintenance Release 4 Maintenance Pack 2 (MR4 MP2)
This section describes the new features and fixes included in Maintenance Release 4 Maintenance Patch 2 (MR4 MP2) of Symantec Endpoint Protection 11.0 (also known as version 11.0.4202). This maintenance pack cannot be installed over any versions of Symantec Endpoint Protection or Symantec Endpoint Protection Manager prior to MR4. It must be installed over Maintenance Release 4 (MR4), (MR4-MP1), or (MR4-MP1a).


What's in this release
This maintenance patch resolves in-field reported issues within Symantec Endpoint Protection client, Symantec Endpoint Protection Manager. These release notes also list updated and new Readme items for this release.

Note: The latest available release of Symantec Network Access Control is MR4 MP1. There have been no customer fixes since the release of Symantec Network Access Control MR4 MP1.


ComponentVersion
Symantec Endpoint Protection 11.0.4202
Symantec Network Access Control11.0.4010
AutoProtect 10.2.10.2
Avengine20081.2
Behavior Blocking3.3.7.15
ccEraser2007.0.1.6
COH6.1.8.8
Common Client6.3.8.004
DecABI1.1.1.39
Defutils4.1.0.19
ECOM61.3.0.17
VxMS (MS Light)5.2.0
LiveUpdate 3.3.0.85
LiveUpdateAdmin2.2.1.13
Microdefs2.5.37.0
QServer3.6.16
WpsHelper11.0.717.804
SyKnAppS2.5.12
SymEvent12.5.3.2
SymNetDrv7.2.3.302
Teefer211.0.697



Product Fixes by category

Symantec Endpoint Protection: Antivirus/Antispyware
RTVScan.EXE terminates unexpectedly when initiating a scheduled scan
Fix ID: 1523740
Symptom: RTVScan.exe terminates unexpectedly when initiating a scheduled scan.
Solution: A common client component, MSL, was updated to prevent the crash.

Quarantine scan causes Auto-Protect detections in %temp% folder
Fix ID: 1525749
Symptom: DWHWizard.exe starts the quarantine scan and moves quarantined files in to the %temp% folder for scanning. Auto Protect will occasionally detect these infected files.
Solution: After extracting and re-scanning each quarantine item, the TMP file is deleted unless the state is now REPAIRABLE. Repairable files are used later, either to restore to the original location or to save back to Quarantine (REPAIR_ONLY mode). These files should be clean, so Auto-Protect should not detect anything in them.

Intermittent Outlook crashes
Fix ID: 1511242
Symptom: Outlook exits unexpectedly when using "Previous Item" or "Next Item" option.
Solution: The Outlook plug-in was changed to keep track of the most recent ExchangeCallback Pointer correctly.

Sysfer crashes Adobe Elements
Fix ID: 1522283
Symptom: Sysfer crashes Adobe Elements when using context to convert .doc(x) files to PDF format.
Solution: Changed a function to read a string-type parameter correctly so that the memory address is properly accessed.

Windows 2008 x64 share connectivity problems
Fix ID: 1442447
Symptom: After a period of time (hours to a day or so) file shares become unresponsive on Windows 2008 x64.
Solution: Auto-Protect update.

TempProfile_Nlnhook is created for each user that logs into a multi-user Lotus Notes installation
Fix ID: 1519913
Symptom: A directory named "TempProfile_Nlnhook" is created in customer's Citrix Presentation Server environment under the user profile folder (%USERPROFILE%).
Solution: Changed to use the CAccessToken class to get the currently logged in user name from the access token, and to send it to the LoadUserProfile () instead of the temporary directory name.

CleanWipe fails to properly remove Symantec AntiVirus 10.2 from a 64-bit operating system
Fix ID: 1532299
Symptom: Symantec AntiVirus still appears in Add/Remove Programs, the CleanWipe log will show various deletion errors, and key folders and files are left behind after using CleanWipe to remove Symantec AntiVirus 10.2.
Solution: A different API is used to detect that Symantec AntiVirus 10.2 is installed on a 64-bit operating system.

Proactive Threat Protection displays the status "Waiting for Update" after a client migration
Fix ID: 1456698
Symptom: Proactive Threat Protection displays the status "Waiting for Update" after a client migration.
Solution: After migration, Proactive Threat Protection should be "on" and should display the latest version.

Antivirus performance is slow when scanning the procmail.log
Fix ID: 1415668
Symptom: It may take a few minutes to scan the procmail.log file. Rtvscan.exe CPU usage increases up to 99%.
Solution: Decomposer engine update.

The Symantec Endpoint Protection installation fails with a "Return value 2" when CP_USASCII is disabled
Fix ID: 1499625
Symptom: The Symantec Endpoint Protection installation fails.
Solution: Symantec Endpoint Protection now uses CP_ACP instead of CP_USASCII when the installation path is validated during installation.

CLT_INST temp folder is left behind whenever a remote install is done (through wizard or Find Unmanaged)
Fix ID: 1527791
Symptom: A CLT_INST folder is left behind after installation.
Solution: VPREMOTE now marks the CLT_INST folder for deletion upon next reboot.

During migration from Symantec AntiVirus 10 MR 7 to Symantec Endpoint Protection 11 MR4 the installation removes all log-files from C:\Temp\Logs
Fix ID: 1509069
Symptom: Upon completion of the installation, the log files are moved to %ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\Logs.
Solution: Updated the installer to use a unique temporary folder to store the Symantec logs.

SMCGUI.exe causes users to lose windows focus
Fix ID: 1460045
Symptom: SMCGUI.exe often stops and starts, causing a user to lose window focus.
Solution: When loading a profile, a return value is checked to see if it is NULL upon calling a specific function.

High paged pool memory usage for Auto-Protect
Fix ID: 1511152
Symptom: Pool monitor shows high memory usage for SavE and SaEe pooltags.
Solution: AV engine update.

Stand-alone Quarantine Console installation cannot connect to any remote Quarantine Server
Fix ID: 1506385
Symptom: Trying to connect to selected server fails with the following error message: Cannot connect to server <SERVER NAME>.
Solution: The installer was changed to make the installation directory available to post-install script functions.

A Defwatch scan does not run on Microsoft Windows Vista if no user is logged on to the computer
Fix ID: 1508276
Symptom: The Defwatch scan does not run on Microsoft Windows Vista unless a user is logged on.
Solution: If no user is logged on, an elevated access token is used to run the Defwatch scan.

Windows Security displays the warning "MALWARE PROTECTION out of date" after a user manually runs an Active Scan or a Complete Scan
Fix ID: 1486799
Symptom: Windows Security displays the warning "MALWARE PROTECTION out of date" after a user manually runs an Active Scan or a Complete Scan.
Solution: Symantec Endpoint Protection was modified to allow the product to query the Windows Security Center information correctly.

Users with local administrator privilege can bypass the Symantec Endpoint Protection uninstall password
Fix ID: 1515363
Symptom: A user is able to bypass the uninstall password by using an undisclosed procedure.
Solution: The MSI file was updated to prevent administrators from bypassing the uninstall password.

While running CleanWipe (RunCleanWipe.bat) with the -silent switch, a dialog box prevents uninstallation from completing
Fix ID: 1588132
Symptom: A modal dialog box appears indicating the Symantec AntiVirus has been uninstalled, and prevents the uninstallation from completing.
Solution: Modified the MSIUnst.bat file to change a command line switch to MsiExec that removed the modal dialog.

Auto-resume of content-package does not resume across reboots or restart of SMC.exe
Fix ID: 1557479
Symptom: Content package download does not resume after either the computer or SMC.exe is restarted.
Solution: Preserve the partially downloaded files and use the HTTP range header information to download the remaining bytes from Symantec Endpoint Protection Manager.

Clients cannot download content from Group Update Provider (GUP)
Fix ID: 1588869
Symptom: Clients attempt to connect to the GUP to download content, but the clients are rejected. The sylink.log shows "<GetLUFileRequest:>Send Request failed. Error code = 12152". The GUP allows for only 100 cached entries, and if that number was exceeded, the GUP fails and does not accept any new connections.
Solution: Updated the GUP caching functionality to use to the administrator's configurations for file count or size.

During installation of LiveUpdate, lucheck.exe returns an invalid error code
Fix ID: 1545886
Symptom: Installing Symantec Endpoint Protection fails as a result of an lucheck.exe error.
Solution: LiveUpdate component change.

System performance decreases when virus definitions are downloaded
Fix ID: 1488785
Symptom: When Symantec Endpoint Protection downloads and applies virus definitions, the system performance for other applications can become sluggish due to excessive disk I/O. Performance returns to normal after the virus definition upgrade is complete.
Resolution: Several components were updated to significantly improve disk I/O during virus definition download and processing.


Symantec Endpoint Protection: Firewall

When a scheduled scan starts, SMC.exe intermittently crashes
Fix ID: 1472880
Symptom: SMC.exe crashes when a scheduled scan starts.
Solution: Additional checks were built into SMC to avoid crashes.

Unable to daisy chain Remote Desktop Protocol (RDP) sessions with sysplant enabled
Fix ID: 1499711
Symptom: When creating a second RDP session from within an existing RDP session, the second RDP session hangs.
Solution: Subsequent RDP sessions are now established normally.

Ping response times increase in releases since Symantec Endpoint Protection 11 MR3
Fix ID: 1510782
Symptom: The ping response time increased.
Solution: The process ID of incoming ICMP packets was not set correctly. The process ID has been modified.

DNS suffix-based location switching does not detect the "disconnected" status of the network card
Fix ID: 1486618
Symptom: DNS suffix-based location switching does not detect the "disconnected" status of the network card when a user joins a domain.
Solution: DNS suffix-based location switching now detects the "disconnected" status of the network card correctly.

After enabling a "Block USB" write policy, files located on network shared folders take longer to open and save
Fix ID: 1475460
Symptom: Access to files located on network shared folders is slow.
Solution: The Application and Device Control cache was increased to improve performance.

A third party management folder "Inbox" is created in the wrong location
Fix ID: 1514511
Symptom: The third party management folder "Inbox" is created in the default location when Threat Protection is enabled and custom user shell folders are used.
Solution: SMC.exe was changed to use "SHGetFolderPath", which allows the Inbox to be created in a custom folder rather than the default.

SMC.exe CPU spikes when no user is logged in on virtual machines
Fix ID: 1517849
Symptom: SMC.exe CPU processing time is greater than 10%.
Solution: SMC.exe was incorrectly querying a process list twice. The extra call was removed and the existing call modified to increase performance.

Symantec Endpoint Protection does not switch locations when using Dial-Up or PPP/SLIP interface
Fix ID: 1530050
Symptom: You configure Symantec Endpoint Protection to switch locations when dial-up or PPP/SLIP interfaces are used. When the client switches interfaces, it does not automatically change locations as expected.
Solution: Change to properly detect dial-up, PPP, SLIP, and PPoE network connections.

Inconsistent behavior with NTP "Microsoft Windows Networking" settings
Fix ID: 1509179
Symptom: Settings are not handled correctly in the Symantec Endpoint Protection GUI when a computer contains more than one network adapter.
Solution: Modified the user interface to display the settings correctly.


Symantec Endpoint Protection Manager
Scheduled reports run with different parameters than the ones that were originally set
Fix ID: 1505248
Symptom: Scheduled Reports for Top Risk Detections Correlation always use the default Group/RiskName filters (X-Y axis), even though a different parameter is used.
Solution: Modified the PHP file to retrieve the filter to be used from the database.

"Enable LiveUpdate Scheduling" should not work after unselecting "use a LiveUpdate server"
Fix ID: 1595629
Symptom: "Enable LiveUpdate Scheduling" still works after unselecting "use a LiveUpdate server".
Solution: LiveUpdate scheduling is disabled when LiveUpdate is not used and LiveUpdate UI options are disabled unless a user is allowed to configure the LiveUpdate schedule.

Group names text in the group tree is truncated when exporting packages or assigning limited administrator rights
Fix ID: 1528898
Symptom: Only part of the client-group name is visible.
Solution: The label width of the tree renderer was extended to accommodate the need for additional space.

An exported Computer Status report does not provide IPS definition information
Fix ID: 1508289
Symptom: The information for the IPS definitions is missing from an exported Computer Status report.
Solution: A new column called "IPS Version" was added to the exported Computer Status report.

When using Windows Authentication for Microsoft SQL, no special characters are allowed in the password
Fix ID: 1503301
Symptom: A user cannot input special characters in the password field.
Solution: Special passwords are now allowed, including additional support for Windows Authentication mechanisms and improvements that affect IIS and the IIS configuration wizard to allow special handling of characters.

NTP logs exported as CSV files from Symantec Endpoint Protection Manager cannot be processed correctly due to double quotes within the text field
Fix ID: 1510799
Symptom: The column order and the values are incorrect after exporting the data to CSV format.
Solution: Quotes were changed to double quotes for the column description.

Deleting old packages generates errors in the Symantec Endpoint Protection Manager during manual LiveUpdate
Fix ID: 1515458
Symptom: Removed packages fail to update.
Solution: Filter out the suspended packages when initializing SesmContentCatalog.

"Query Failed" appears in the Action Summary by Detection Count window on the Home Page of Symantec Endpoint Protection Manager when logging in with a Limited Administrator account
Fix ID: 1538866
Symptom: The Action Summary by Detection Count window in the Home Page shows "Query Failed.
Solution: A query was changed to prevent the failure from occurring.

Slow process of DAT files in the Inbox\Agentinfo folder on the Manager
Fix ID: 1513330
Symptom: Large numbers of files in the Inbox\Agentinfo folder. The number of files continually increases.
Solution: Updates to Avman and Agentinfo processing along with SQL batching of statements, and configurable multi-threading to the Agentinfo processing.

Client does not report the correct IP address when a NIC is assigned more than one IP address
Fix ID: 1511355
Symptom: Client properties may reveal an IP-address of "0.0.0.0".
Solution: Symantec Endpoint Protection Manager displays the IP address that the client uses to connect to Symantec Endpoint Protection Manager.

Symantec Endpoint Protection comprehensive risk report shows incorrect month
Fix ID: 1512110
Symptom: Comprehensive risk reports shows threats as occurring in the wrong month when a report of more than one month is run.
Solution: SQL script update.

Symantec Endpoint Protection Manager replication fails with ASA error 193: "Primary Key for Table 'COMMAND' is not unique" when using an embedded database
Fix ID: 1533903
Symptom: Replication fails when the HARDWARE key is NULL.
Solution: Made changes to the query that finds the data.

Large number of BCP queries during DAT-file processing causes high CPU usage on SQL Server
Fix ID: 1533966
Symptom: SQL Server will show high CPU usage in conjunction with a Symantec Endpoint Protection Manager database.
Solution: The code was modified to address database deadlock issues.

Symantec Endpoint Protection Manager displays error "Object cannot be found [0x16010000]" when going to Policies > Policy Components > Host Groups
Fix ID: 1533012
Symptom: You are unable to edit a Firewall/IDS policy.
Solution: Update USN for reference when updating objects which contains references.

Unable to edit policies, and an incorrect location use count for policies is displayed
Fix ID: 1532253
Symptom: The location use count shows 0.
Solution: The location use count should no longer display 0 unless it is truly not applied to any groups.

Symantec Endpoint Protection 11 MR4 does not provide an option to deploy to clients using a URL
Fix ID: 1516419
Symptom: The URL option is disabled.
Solution: The URL option was enabled to support the handling of a single executable file.

Client can't get the correct setup file after resetting the 3rd party URL to a correct location
Fix ID: 1520249
Symptom: If a third party download URL is set to an incorrect setup file, after it fails to apply and a new URL that points to a correct file is set, the client continues to download from the original, incorrect URL. This persists until the client restarts.
Solution: Sylink update to import a new URL after a failed download.

Symantec Endpoint Protection Manager does not update content for clients after upgrading from MR4 to MR4 MP1
Fix ID: 1539713
Symptom: Content on clients is not updated after upgrading from MR4 to MR4 MP1.
Solution: When moniker and sequence number are not synchronized between Inetpub, symcdata and registry, SesmLU needs the full folder and if necessary SesmLU will create this folder by extracting the related full.zip file.

Replication fails with a reference to "Violation of PRIMARY KEY constraint 'PK_SEM_CONTENT'"
Fix ID: 1534131
Symptom: Symantec Endpoint Protection Manager may log a PRIMARY KEY violation during replication.
Solution: Symantec Endpoint Protection Manager replication was modified to prevent this error from occurring.

Configuration wizard does not allow user to specify domain name
Fix ID: 1522005
Symptom: User cannot type "\" for user name when using windows authentication.
Solution: Allow domain extraction from the textbox and make PHP use real windows authentication mechanisms.

Symantec Endpoint Protection Manager console experiences performance issues when PackageTask is running
Fix ID: 1532312
Symptom: PackageTask memory usage is high.
Solution: Optimized memory usage by the PackageTask process.

Microsoft Excel is unable to parse an exported Computer Status report correctly due to a comma in the Service Pack column
Fix ID: 1507303
Symptom: After introducing one or more computers that contain a comma in the Service Pack field, the data in the exported Computer Status report shifts to the right.
Solution: The value was enclosed with double-quotes for service packs that contain a comma.

When an Active Directory Sync mode-enabled Symantec Endpoint Protection Manager has clients in user mode, the Symantec Endpoint Protection Manager GUI shows duplicate client entries
Fix ID: 1514585
Symptom: The Symantec Endpoint Protection Manager GUI displays duplicate client entries with the same user and computer names.
Solution: Symantec Endpoint Protection Manager now displays the actual user name which registered and the last online user for the client instead of the current user for the agent.

SESMLU connectivity to Tomcat can time out while a lock in the database is held, causing automatic notification of content availability to fail
Fix ID: 1510207
Symptom: Certain content may not be updated automatically but can be updated manually.
Solution: The default receive time-out value was increased (defaults to 30 minutes) and is now configurable through the registry: HKEY_LOCAL_MACHINE\Software\Symantec\Symantec_Endpoint_Protection\SEPM\LUReceiveTimeout (DWORD), which is the time in seconds that the timeout is set to. This value is set to 1800 seconds by default, and the minimum value that it will accept is 600 seconds. If a value lower than the minimum is set, the minimum value is used.

The virus definition distribution reports in a replicated environment show the same report for each server
Fix ID: 1523677
Symptom: The same virus definition distribution report will show for all servers.
Solution: The virus definition distribution report now shows the correct information per server.

Replication fails with remote sites after migrating to MR4 MP1 with string index out of range
Fix ID: 1587973
Symptom: StringIndexOutOfBoundsException happens during replication.
Solution: Turned off escapes in embedded database's BCP command.


Symantec Network Access Control
There have been no customer fixes since the release of Symantec Network Access Control MR4 MP1.


Readme items

"Error 1327. Invalid Drive" when installing Symantec Antivirus 10.2 after pointing "Documents" folder to a mapped drive
Fix ID: 1589016
Symptom: "Error 1327. Invalid Drive" error is displayed during the installation of Symantec AntiVirus 10.2 for Windows Vista.
Solution: For full details see readme_sep.txt section titled "Installing to a reassigned Documents folder displays Invalid Drive error message".

Temporary Files should not be opened during automatic scan after updating virus definitions
Fix ID: 1525749
Symptom: An auto-protect detection is triggered upon opening a temporary file (DWH****.tmp) that was created by an automatic scan after updating virus definitions.
Solution: For full details see readme_sep.txt section titled "Temporary Files should not be opened during automatic scan".

Hardware change may create duplicate clients in Default group
Fix ID: 1528038
Symptom: Making hardware changes to a client computer that is in a group synchronized with Active Directory might cause the client to be duplicated and registered to the Default group.
Solution: For full details see readme_sep.txt section titled "Hardware changes might create duplicate clients in the Default group".

Auto-location's NIC description condition is not available for dial-up connections
Fix ID: 1544958
Symptom: The auto-location NIC description is not available for dial-up connections.
Solution: For full details see readme_sep.txt section titled "Auto-location's NIC description is not available for dial-up connections".

IPv6 and Network Protection affects performance on Windows Vista virtual machines
Fix ID: 1545253
Symptom: On virtual machines running Windows Vista, copying large files to network shares might take longer when Symantec Endpoint Protection NTP (Network Protection) is enabled.
Solution: For full details see readme_sep.txt section titled "IPv6 and Network Protection affects performance on Windows VISTA virtual machines".



Maintenance Release 4 Maintenance Pack 1a (MR4 MP1a)
Symantec Endpoint Protection MR4 MP1a provides a fix for a specific problem that occurred in MR4 (11.0.4). This maintenance pack cannot be installed over any versions of Symantec Endpoint Protection or Symantec Endpoint Protection Manager prior to MR4. It must be installed over MR4 or MR4 MP1.

Components updated in this release
ComponentVersion
Symantec Endpoint Protection 11.0.4014

Fixes in this release
Symantec Endpoint Protection: Firewall
After installing MR4 MP1, when a networked application is run, all connections to the client computer are dropped.
Fix ID: 1530477
Symptom: Client loses network connectivity when Network Threat Protection is installed and an application is launched from a UNC path.
Solution: API calls from the thread which were causing firewall deadlocks have been fixed.


Maintenance Release 4 Maintenance Pack 1 (MR4 MP1)
Symantec Endpoint Protection MR4 MP1 (11.0.4010) and Symantec Network Access Control MR4 MP1 (11.0.4010) provide customer fixes since the release of MR4 (11.0.4). This maintenance pack cannot be installed over any versions of Symantec Endpoint Protection or Symantec Endpoint Protection Manager prior to MR4. It must be installed over Maintenance Release 4.

What's in this release
This Maintenance Pack resolves in-field reported issues within Symantec Endpoint Protection client, Symantec Network Access Control client, and Symantec Endpoint Protection Manager. These release notes also list updated and new Readme items for this release.

Components in this release

ComponentVersion
Symantec Endpoint Protection 11.0.4010
Symantec Network Access Control11.0.4010
AutoProtect 10.2.8
LiveUpdate 3.3.78
ccEraser108.2.2.8
Avengine20081.2
SyKnAppS2.5.12
SymEvent12.5.3.2
DecABI1.1.1.39
ECOM61.3.0.17
Defutils3.3.20.0
LiveUpdateAdmin2.2.1.13
Microdefs2.5.37.0
SymNetDrv7.2.3.302
Common Client6.3.8.004
Behavior Blocking3.3.7.15
COH6.1.8.8
QServer3.6.16
Teefer211.0.697
WpsHelper11.0.717.804
VxMS5.2.0


Product fixes by category:

Symantec Endpoint Protection: Antivirus/Antispyware

After restart, communication between the client and Symantec Endpoint Protection Manager is not established.
Fix ID: 1443855
Symptom: Communication is not established immediately, or drops intermittently after restart.
Solution: Registration information and the last known connected server are now saved in the registry on client shutdown.

Large PowerPoint files open slowly with Symantec Endpoint Protection Auto-Protect enabled.
Fix ID: 1432356
Symptom: It takes several minutes for a 5MB or larger Power-Point file to completely open on Vista.
Solution: Fixed with an update to the Auto-Protect component.

"Tamper protection alert" appears after upgrading from an older version.
Fix ID: 1395857
Symptom: Tamper Protection alert pops up near the end of installation.
Solution: Fixed with an update to the Behavior Blocking component.

Symantec Endpoint Protection clients using the Outlook Scanner are unable to preview JPEG images sent from a Macintosh.
Fix ID: 1461975
Symptom: Clients using the Outlook Scanner for Symantec Endpoint Protection are unable to preview JPEG images sent from a Macintosh machine.
Solution: Implemented a check if this attachment is AppleDouble-encoded. If it is, it is not saved, allowing Outlook to handle it.

LiveUpdate cannot update the virus definitions after an old Intelligent Updater is applied.
Fix ID: 1407607
Symptom: Applying an Intelligent Updater of a couple weeks or older will prevent LiveUpdate from updating virus definitions.
Solution: Fixed with an update to Intelligent Updater.

Symantec Endpoint Protection client uninstallation does not remove LiveUpdate from the system in some migration patterns.
Fix ID: 1441612
Symptom: After an unmanaged 11.0 MR2 Symantec Endpoint Protection client is migrated to 11.0 MR2 MP2 and uninstalled, Live Update will be left on the machine.
Solution: LiveUpdate is now removed correctly upon uninstallation.

Opening Microsoft Word 2007 "docx" files on Windows Vista takes longer than on Windows XP.
Fix ID: 1399868
Symptom: Noticeable delays occur when trying to open Microsoft Word 2007 "docx" files on Windows Vista.
Solution: Fixed with an update to the Auto-Protect component.

Veritas clustering is unable to fail over due to Symantec Endpoint Protection locking volumes.
Fix ID: 1439705
Symptom: Attempts to take a server offline are initially possible but cease to work after an undetermined length of time. Once you stop the Symantec Endpoint Protection service, taking the server offline works correctly again.
Solution: Fixed in an update to the Common Client component.

After uninstalling Symantec Endpoint Protection and restarting, some registry keys still exist.
Fix ID: 1223463
Symptom: After uninstalling Symantec Endpoint Protection and restarting, some registry keys are left behind in the HKEY_CURRENT_USER hive.
Solution: Added custom action to Symantec Endpoint Protection installer to enumerate and delete necessary registry keys during uninstall.

LUALL CPU usage of 50% and memory size increases until system stops responding when LiveUpdate launches via a schedule.
Fix ID: 1473616
Symptom: LUall.exe consumes CPU and memory starting at 50% until the system stops responding.
Solution: Fixed hard loop when certain scenarios or states are detected during LiveUpdate.

Offline Microsoft Office files opening as "corrupt" or "encrypted."
Fix ID: 1442180
Symptom: When opening Office documents, the Office file conversion assistant will open and show what appears to be a corrupted (or encrypted) document.
Solution: Fixed with an update to the Auto Protect component.

Workstation freezes when copying over a network share.
Fix ID: 1383615
Symptom: Copying files over a network share freezes the share or the workstation.
Solution: Fixed with an update to the Behavior Blocking component.

When migrating from Symantec AntiVirus 10.1.7, the installation pauses for up to five minutes at the end of the installation before completing.
Fix ID: 1423539
Symptom: When migrating from Symantec AntiVirus 10.1.7 to Symantec Endpoint Protection 11.0 MR2, MR3, or MR4, the installation pauses for about 5 minutes at the end of the installation before actually completing.
Solution: Improved the checks for proper registry key settings.

Outlook Auto-Protect corrupts files with Unicode characters in the file name.
Fix ID: 1405173
Symptom: Attachments with Unicode file names appear empty.
Solution: If the file name passed to the Outlook Plug-in is invalid, Auto-Protect now lets Outlook write the attachment.

MSL crash in Common Client.
Fix ID: 1407121
Symptom: Logs show MSL crash in component Common Client 6.3.7.
Solution: Fixed with an update to the Common Client component.

UPHClean points to RTVScan.exe as the root cause of a profile unloading issue on Windows 2000 Professional.
Fix ID: 1484409
Symptom: RTVscan does not shut down within the time allowed by the Windows 2000 system shutdown, causing a Userenv error.
Solution: Added extra checks to verify if COM already initialized.

Cleanwipe tool prompt asks, "Do you want to uninstall Windows related files that Symantec installed?"
Fix ID: 1469385
Symptom: Cleanwipe presents a confusing prompt which asks, "Do you want to uninstall Windows related files that Symantec installed?".
Solution: The prompt text has been changed to "Do you want to uninstall the files that Symantec installed under the Windows directory, if removing these files will not harm your system?"

When Cleanwipe runs silently, the blank DOS box does not indicate that the tool is working.
Fix ID: 1469470
Symptom: When Cleanwipe runs silently, the blank DOS box does not indicate that the tool is working.
Solution: New command line parameter -showprogress is added, which displays verbose output to the command window.

When Scheduled LiveUpdate configuration is used from the Symantec Endpoint Protection user interface, it is saved incorrectly.
Fix ID: 1484916
Symptom: Set the weekly LiveUpdate schedule to a particular day. Re-open the LiveUpdate schedule dialog to see the day moved back 2 days.
Solution: While saving the schedule in the registry, convert the local day index to the Symantec Endpoint Protection day index.

USB hard drives can't be safely removed after context menu scan completes successfully.
Fix ID: 1410194
Symptom: After running a scan with default settings, an attached USB hard drive can no longer be safely removed. If you terminate RTVScan.exe, you can then safely remove the drive.
Solution: Fixed in an update to the Common Client component.

Symantec Endpoint Protection displays two Symantec Tamper Protection Alerts when installing Backup Exec over the network.
Fix ID: 1473579
Symptom: Tamper Protection Alerts occur during Backup Exec installation.
Solution: Network installation no longer triggers Tamper Protection alerts.

Symantec Endpoint Protection patching may cause "Resolve Source" after LiveUpdate of WpsHelper.
Fix ID: 1505190
Symptom: Patching Symantec Endpoint Protection 11.0 may result in a "Resolve Source" during the patch process.
Solution: Added WpsHelper to the full file patch list.

High Explorer.exe CPU usage when touching exported Symantec Endpoint Protection client package.
Fix ID: 1470577
Symptom: Explorer.exe has high CPU usage in Task Manager.
Solution: Fixed in an update to the Auto-Protect component.


Symantec Endpoint Protection: Firewall

A managed Symantec Endpoint Protection client displays a "Collect User Info" pop-up before the delay time has elapsed.
Fix ID: 1455613
Symptom: User information collection pop-up reappears, even though the delay time has not elapsed after logging in again or restarting.
Solution: Save the delay time to Registry on firewall service stop, and restore its value on firewall service start.

The Driver_Level_Protection_(DLP) doesn't work even when the option shows normal in Profile.xml.
Fix ID: 1481759
Symptom: Cannot block IPX packets.
Solution: Updated the handling of IPX packets.

SMC.EXE application crashes when more than 16 DNS servers are configured in the TCP/IP properties.
Fix ID: 1471456
Symptom: If a user creates more than 16 DNS servers, SMC.exe will crash.
Solution: Add the boundary check when copying DNS servers from Netport to SMC.

Teefer driver is still shown under network properties after upgrade to Symantec Endpoint Protection 11.0 MR3 or later.
Fix ID: 1293420
Symptom: Teefer2 driver appears in the network properties.
Solution: Teefer2 driver no longer appears in the network properties.

Microsoft Expression Design 2 will not start when Application and Device Control policy is enabled.
Fix ID: 1482773
Symptom: This .NET program crash when Application and Device Control is enabled.
Solution: Updated a Symantec driver to prevent the crash.

Application and Device Control causes custom application to fail on Windows 2000 computers.
Fix ID: 1470672
Symptom: If Application and Device Control is enabled, "TASKING EDE" will fail to start on Windows 2000 SP4.
Solution: Updated a Symantec driver to prevent the error.

Portscan detections are inconsistent.
Fix ID: 1456195
Symptom: Some port scan parameters result in inconsistent detections.
Solution: Check all the TCP packets, regardless of the TCP flags.

Application and Device Control causes Inova Lightlink software to fail.
Fix ID: 1472582
Symptom: If Application and Device Control is enabled, Inova Lightlink software crashes.
Solution: Application and Device Control was corrected to support such .NET applications.

Unable to connect to any shares on Windows XP with Symantec Endpoint Protection MR 3 or later installed and Network Threat Protection enabled on Japanese-language operating system.
Fix ID: 1447741
Symptom: On a Japanese language Windows XP operating system, ports 139 and 445 are blocked by default after Symantec Endpoint Protection 11.0 is installed. This does not occur on English Windows XP.
Solution: Added TCP and UDP rules for file sharing.

Symantec Endpoint Protection Manager Quick Reports show OS codes instead of OS names.
Fix ID: 1447318
Symptom: Client inventory report shows an odd entry.
Solution: Added appropriate localization entry for Windows 2003 Enterprise Domain Controller and Windows 2000 Advanced Server Domain Controller.

Pillar Trim application does not start when Symantec Endpoint Protection is installed.
Fix ID: 1482423
Symptom: This .NET program will crash when Application and Device Control is enabled.
Solution: Application and Device Control was corrected to support such .NET applications.

Application rules do not persist after restart.
Fix ID: 1447262
Symptom: Once a user chooses which applications to allow or deny, they are added to the application list. This list is cleared when the computer is shut down. The user is presented with the alerts again the next time the applications are started
Solution: Application rules now persist across restart.

VNCon application will not start when Application and Device Control policy is enabled.
Fix ID: 1473568
Symptom: VNCon application cannot run when the Application and Device Control Policy is in effect.
Solution: Updated a Symantec driver to allow the application to run.

If only one Symantec Endpoint Protection client exists, the client is unable to establish communication with Symantec Endpoint Protection Manager.
Fix ID: 1486698
Symptom: A single client cannot communicate with the server.
Solution: Improved handling of a single client count.

Application and Device Control conflicts with DMES software.
Fix ID: 1477161
Symptom: With Application and Device Control enabled and when DMES is running, the newly launched Internet Explorer will hang.
Solution: A Symantec driver was modified to allow the application to run.

Fingerprint no longer takes effect when an .exe file is moved to a new folder and the folder is re-named.
Fix ID: 1295598
Symptom: With OS Protection enabled, add a rule to block an application running with file fingerprint. When renaming the folder containing the application the rule doesn't work.
Solution: Fixed in OS Protection block rules.

SMB protocol traffic is sent to the detection engine with a 1-6 minute delay.
Fix ID: 1480679
Symptom: SMB protocol traffic triggers the Intrusion Protection signature, but traffic to the IPS engine is delayed by 1-6 minutes.
Solution: Fixed in a component update.

Computer stops responding with a blue screen while the computer is idle.
Fix ID: 1480602
Symptom: Computer stops responding with a blue screen while the computer is idle.
Solution: Fixed in a component update.

Port client connection timeout from Symantec Endpoint Security Maintenance Release 3.
Fix ID: 1486881
Symptom: Client timeout value for establishing connection with the server to download client packages is low and causes frequent failures, particularly if the network is slow between the client and Symantec Endpoint Protection Manager.
Solution: Increased timeout value.

Symantec Endpoint Protection continues downloading the same definition file when the disk is full.
Fix ID: 1472608
Symptom: Even when the disk space is full, the client will make attempts to download and apply LiveUpdate content.
Solution: Roughly estimate how much disk space is required before attempting the content download.

Cannot configure Veritas Cluster Service (VCS) when Symantec Endpoint Protection is present.
Fix ID: 1487863
Symptom: Cannot configure VCS with Symantec Endpoint Protection present.
Solution: A Symantec driver was modified to allow the application to run.


Symantec Endpoint Protection Manager

Limited Administrator scheduled reports can become "invisible."
Fix ID: 1472513
Symptom: Limited Admin's Scheduled reports can become "invisible."
Solution: Kept the "created by" field when updating a report.

Auto-refresh of Computer Status Logs causes different logs to be shown.
Fix ID: 1469309
Symptom: When viewing the Computer Status Logs with the count per page at 1000 entries, enable auto-refresh at 30 second intervals. After a refresh, the row count drops dramatically (between 20-30). The full list is restored if auto-refresh is disabled.
Solution: All entries are now viewable when auto-refresh is enabled.

Server certificate is missing from the client's Sylink.xml.
Fix ID: 1472560
Symptom: Some Symantec Endpoint Protection Manager sites and server certificates are missing in sylink.xml.
Solution: Symantec Endpoint Protection Manager was modified to resolve the problem.

Configured Notifications fail to be created as expected.
Fix ID: 1446178
Symptom: No Application Device Control events trigger notifications, even when the option is configured.
Solution: Added a new attribute to policies for checking whether a notification should be sent.

Cannot open location-independent policies and settings for certain Symantec Endpoint Protection Manager client groups.
Fix ID: 1474607
Symptom: Clicking Clients > Policies > General Settings does nothing.
Solution: Get default attribute value if Symantec Endpoint Protection Manager cannot get optional one.

In the Computer status log, the sort function does not work for the "Infected" column.
Fix ID: 1453826
Symptom: In the Computer status log, the sort function does not work for the "Infected" column.
Solution: Added a sort function to column "Infected."

After repair, Symantec Endpoint Protection Manager malfunctions in some environments.
Fix ID: 1470381
Symptom: User cannot log into the console after the installation is repaired.
Solution: Back up files and restore them later, so that those files are always kept during repair and migrate installations.

Replication fails after deleting the default domain.
Fix ID: 1458968
Symptom: Replication fails after deleting the default domain.
Solution: Bypass conflicting check when policy and policy component's Symantec Endpoint Protection Manager domain is deleted; add more null pointer checking.

Firewall rules keep inheriting from the parent when opening the child firewall policy for editing.
Fix ID: 1449215
Symptom: The rules in parent group keep growing when editing a subgroup firewall policy.
Solution: Rules from the parent group are no longer saved.

Virus Definition Distribution reports show many different sequence numbers for the same date/revision definitions.
Fix ID: 1440933
Symptom: The Reports > Computer Status > Virus Definitions Distribution report shows 0 and XXXX(sequence number) for the same date/definitions.
Solution: Removed the sequence from the grouping in the virus definitions report.

When viewing a LiveUpdate policy, the "Last Modified" entry actually reflects when the policy was created.
Fix ID: 1454394
Symptom: When you update the LiveUpdate Policy or LiveUpdate Content Policy, the "Last Modified" entry is not updated.
Solution: Added code to update the LiveUpdate Policy and Content Policy.

Slow Symantec Endpoint Protection Manager performance when assigning policies to a large number of groups.
Fix ID: 1454359
Symptom: The console takes a long time when assigning policies to a large number of groups.
Solution: Optimized code to remove unused objects and improve efficiency of queries.

Console freezes when opening Policies tab in Symantec Endpoint Protection Manager.
Fix ID: 1443849
Symptom: After replication, when switching to the policy tab, the policy tab will freeze or show wrong group information.
Solution: When doing replication, if there are any other schemas, reference to them to eliminate hangs or incorrect data.

Configured Notifications fail to be created as expected.
Fix ID: 1459053
Symptom: On Symantec Endpoint Protection Manager, even if the "alert" flag has been set, no logs can be received from the client when an Operating System Protection policy is sent.
Solution: Import "Alert" flag and copy this alert to registry.

Heartbeat time configuration not synchronized with client number in the client group.
Fix ID: 1473493
Symptom: If client-number/heartbeat is greater than 1000 in a one-minute timeframe, there will be communication problems.
Solution: Added a warning dialog for short heartbeat settings.

Symantec Endpoint Protection Manager query to SQL database is causing a very high CPU spike.
Fix ID: 1460880
Symptom: A very high CPU spike appears in the task manager.
Solution: Resolved a JDBC issue.

Upgrade failure from Symantec Sygate Enterprise Protection MR9 to Symantec Endpoint Protection when the Manager has multiple domains.
Fix ID: 1407636
Symptom: Error occurs during upgrade.
Solution: Detect and clean up broken data before upgrade.

Possible broken link after replication.
Fix ID: 1480062
Symptom: Error: "No SemAgentPolicy GUID in Group Policy."
Solution: When updating a group policy, update all the references' USNs so that they will be replicated together.

Copied or moved Active Directory user continues to use the policy from the original group.
Fix ID: 1453632
Symptom: Cannot register the client when there are duplicate clients with the same hardware key.
Solution: Added source to register to the client ID marked first to eliminate this problem.

After installing Symantec Endpoint Protection Manager on Windows XP Professional, there are two performance objects for "memory," and their counters have been changed.
Fix ID: 1198477
Symptom: Two "Memory" performance objects appear when using Performance Monitor tool.
Solution: Added registry values needed in the Symantec Endpoint Protection Manager installer.

Replication server is missing partner's certificates.
Fix ID: 1472563
Symptom: Some Symantec Endpoint Protection Manager sites and server certificates are missing in sylink.xml.
Solution: Added source during replication process to help resolve the broken link during upgrade process.

Replication error when trying to resolve a conflict.
Fix ID: 1481287
Symptom: Replication fails after deleting default domain.
Solution: Fixed conflicting check when policy and policy component's Symantec Endpoint Protection Manager domain is deleted.

Unexpected console error 0x80010000 when unchecking Inherit Policies from the client policy tab in Symantec Endpoint Protection Manager.
Fix ID: 1449208
Symptom: Error: "No SemAgentPolicy GUID in Group Policy."
Solution: When updating a group policy, update all the references' USNs so that they will be replicated together.

After replication, all Symantec Endpoint Protection Manager data on the client is marked as deleted when one record is deleted at its partner.
Fix ID: 1488176
Symptom: Version will be different between partners.
Solution: Added source during the replication process ensuring correct data deletion and avoiding making other data deletion errors.

Non-English users see English text describing a Host Integrity condition.
Fix ID: 1470295
Symptom: Non-English users see English text describing an HI IF condition.
Solution: Provided translatable string for description.

Symantec Endpoint Protection Manager service stops when unchecking Policy inheritance for client group.
Fix ID: 1482253
Symptom: Symantec Endpoint Protection Manager server stops when unchecking Policy Inheritance feature.
Solution: Added source to avoid recursive calls.

Unable to complete the migration to Symantec Endpoint Protection 11.0 from Symantec Sygate Enterprise Protection 5.1.
Fix ID: 1485857
Symptom: Exception errors during upgrade.
Solution: Problematic exception has been removed.

Console input field is one character too short .
Fix ID: 1461702
Symptom: The console input field is incorrect.
Solution: Now users can input a value equal or less than 4294967295(0xffffffff), same as the behavior of Registry Editor.

Static date is displayed in Symantec Endpoint Protection Manager client installation package pane after migration.
Fix ID: 1499357
Symptom: Creation Time column shows static date "January 9, 2009 4:35pm EST" for all packages created after migration.
Solution: Set "Created Time" as current time during upgrade.

Reports show conflicting IPS dates after replicating Symantec Endpoint Protection Managers via Computer Status report: IPS distribution.
Fix ID: 1447222
Symptom: Reports show conflicting IPS dates.
Solution: Removed the offending string and reset USN for all the tables which cannot be replicated during upgrade from MR4 to MR4 MP1.

Hourly Scheduled Replications fails with "String index out of range: -1"
Fix ID: 1476198
Symptom: Scheduled replication causes failure.
Solution: Corrected the string index to resolve the issue.

Symantec Endpoint Protection Maintenance Release 3 service crashes when exporting a client package.
Fix ID: 1457431
Symptom: After replicating a site, an "Invalid Management Server List" error occurs when trying to export a client installation Package from a group that is originally communicating with the deleted site.
Solution: In "Export Client Install Package", a dialog box is displayed asking the user to select a valid Management Server List to be used for the group if it is invalid. The dialog box will be displayed for any group having an invalid server list. In "Delete Remote Site", a dialog box is displayed preventing the user from proceeding if its default Management Server List is still being used by any group. In "Policy Summary Panel", before displaying the Communications Setting dialog, a dialog box is displayed if the Management Servers list is invalid for that group.

When you navigate to the Monitors > Logs > Risk log and sort by User, only the first page sorts correctly.
Fix ID: 1483276
Symptom: Navigate to Monitors > Logs > Risk and view the Risk log. Sort by User Name. Only the first page sorts the User Names, not additional pages of user names.
Solution: Added sort function to the logs for multiple pages.

Incorrect IPS failure information and computer count in the database.
Fix ID: 1488007
Symptom: IPS failure information or computer count is different between partners when there is deleted Symantec Endpoint Protection Manager content.
Solution: Enhanced filtering when there is deleted Symantec Endpoint Protection Manager content.

Symantec Endpoint Protect Manager LiveUpdate cannot install virus definitions when it matches LuDownloadedContentArray.xml.
Fix ID: 1478558
Symptom: Cannot install virus definitions.
Solution: Changed the .xml file to eliminate this issue.

Clients managed by other replication partners indicate no definitions are present when viewing the client properties.
Fix ID: 1456697
Symptom: When clients are viewed from replication partners besides their own manager, the clients show "no definitions" or different versions.
Solution: Removed the offending string and reset USN for all the tables which cannot be replicated during upgrade from MR4 to 11.0 MR4 MP1.

Cannot select some groups in the advanced settings for computer status logs with long nested OUs.
Fix ID: 1483311
Symptom: In Computer Status Logs Advance Setting, Group drop-down list, when you mouse over a group, it jumps to the top of the list of the drop-down.
Solution: Since the horizontal scrollbar is available for longer OU names, resolved this by preventing the content from wrapping to the next line.

Symantec AntiVirus Corporate Edition changes to "AhnLab V3 Internet Security" in custom Host Integrity policies.
Fix ID: 1503283
Symptom: You see "AhnLab V3 Internet Security" selected instead of the expected choice "Symantec Endpoint Protection" in policies that were migrated from SPM 5.1 MR8.
Solution: The UI was changed to accept both values, which now correctly map to "Symantec Endpoint Protection."

Replication failure between SQL 2000 and embedded database.
Fix ID: 1481901
Symptom: SQL exception occurs because Primary Key is not unique.
Solution: Saved the multi-key in all columns for the table and added a cache.

Symantec Endpoint Protection Manager 11.0 Maintenance Release 3 policies do not update.
Fix ID: 1502048
Symptom: Broken link produced when trying to edit a command scan via Antivirus policy. You cannot open the Edit dialog, and see an exception when creating a policy for groups.
Solution: Added additional policy checking upon creation and upgrade.

Hourly Scheduled Replications fail 3 - 4 times a day.
Fix ID: 1471437
Symptom: Replication failures can be seen in the reports.
Solution: Eliminated possible deadlocks.

The "agentinfo" folder does not get processed after 00:00 AM.
Fix ID: 1476443
Symptom: You see "java.lang.OutOfMemoryError" in the scm_server.log
Solution: Merged two SQL statements into one to avoid putting compliance IDs into memory.

Replication partner cannot be set up again after migration from Symantec Sygate Enterprise Protection 5.x MR 9 to Symantec Endpoint Protection.
Fix ID: 1501797
Symptom: Replication couldn't be set up again after upgrade.
Solution: Fixed code so that it will handle the case of upgrade from 5.X.

The "Command" column data does not sort correctly within the Command Status page.
Fix ID: 1504788
Symptom: In the Command Status result page the "Command" column data does not sort correctly.
Solution: Re-sort the "Command" in PHP code.


Symantec Network Access Control

SNAC.exe takes up to 100% CPU.
Fix ID: 1474538
Symptom: SNAC.exe takes up to 100% CPU on single CPU computers after migration to MR4. Can take up to 50% CPU usage on dual core CPU.
Solution: Removed an event handler which will reset the triggered event. When this issue happens, restarting the computer resolves this issue.

Symantec transparent mode settings cannot be saved. After restart it resets to PEAP authentication type.
Fix ID: 1476298
Symptom: If the user selects "Symantec NAC Transparent Mode" in the network property window, the setting is lost after restart.
Solution: Made corrections within the registry.

DHCP Plug-in Enforcer cannot get entire serverprofile.xml with 16,000 trusted MAC addresses from Symantec Endpoint Protection Manager.
Fix ID: 1465088
Symptom: Policy is not effective in Integrated Enforcer if the policy contains large numbers of trusted MAC addresses.
Solution: Use dynamic memory to receive policy from Symantec Endpoint Protection Manager.

Sylink module crashes during auto-upgrade.
Fix ID: 1487223
Symptom: Sylink crashes during upgrade.
Solution: Improved the object handling.


Readme items

Peer to peer enforcer authentication doesn't work.
Fix ID: 1483085
Symptom: Peer-to-peer authentication and host integrity policies block access to shared folders.
Solution: For full details see the readme_sep.txt or readme_snac.txt section titled "Peer-to-peer authentication and host integrity policies block access to shared folders."

Client fails to show tray icon when "Display the notification area icon" is checked.
Fix ID: 1483345
Symptom: Missing tray icon.
Solution: For full details, see the readme_sep.txt or readme_snac.txt section titled "Icons do not display in system tray."



Maintenance Release 4 (MR4)

What's in this release
Symantec Endpoint Protection Manager now supports Windows 2008 Server. Symantec Endpoint Protection Manager now supports the following versions of Windows 2008 Server (all applicable 32-it and 64-bit versions): Windows Server 2008 Standard, Enterprise, DataCenter, Web, Small Business Server (Standard and Premium), and Essential Business Server (Standard and Premium).

Specific Symantec Endpoint Security features include:
Specific Symantec Network Access Control features include:

Components in this release

ComponentVersion
Symantec Endpoint Protection 11.0.4
Symantec Network Access Control11.0.4
AutoProtect 10.2.7.11
Live Update 3.3.0.69
ccEraser108.2.2.8
Avengine20081.2
SyKnAppS2.5.12
SymEvent12.5.3.2
DecABI1.1.1.39
ECOM20081.2
Defutils3.3.20.0
LiveUpdateAdmin2.2.1.13
Microdefs2.5.32.0
SymNetDrv7.2.3.302
Common Client106.3.7.9
Behavior Blocking3.3.7.4
COH6.1.8.8



Product fixes by category:

Symantec Endpoint Protection: Antivirus/AntiSpyware

A Full Scan with compressed files level set to 1 reports 0 files scanned.
Fix ID: 1371190
Symptom: On the client UI, the total files scanned count either reflects an incorrect value or 0 (if the count was negative).
Solution: Do not decrement the total scanned files count for files in archives past the maximum file scan depth.

Miscellaneous files such as - slu****.tmp, mdf****.tmp, and CValidateCom.txt files are generated in Temp folder.
Fix ID: 1298906
Symptom: Temp folders are left over in the Windows Temp folder.
Solution: Delete Temp folder files.

Temp files left over in the 7.5 folder after scans.
Fix ID: 1405018
Symptom: After a scan, Symantec Endpoint Protection does not clean up all temporary files from the "7.5" folder.
Solution: The heuristic scan engine was incorrectly holding on to the temporary files in the 7.5 folder during the scan. Modified the engine to prevent this issue from occurring.

SymCorpUI error when trying to do a Symantec Endpoint Protection scan in safe mode on Windows 2000 SP4.
Fix ID: 1300088
Symptom: After clicking Scan Now,a "SymCorpUI error" message appears, after which the "Run active" scan doesn't work.
Solution: Passed API calls check in Win2k safe mode (without networking).

Location-based scans that are defined in the policy trigger when locations switch.
Fix ID: 1380226
Symptom: Having a scheduled scan in one location but not another results in the scan being triggered incorrectly.
Solution: Fixed incorrect scan entries in the registry for these scheduled scans.

Auto-Upgrade installation rolls back with Error 1308: Source file not found on OEHeur.dll.
Fix ID: 1371851
Symptom: Client installations may fail while re-creating the delta package, or attempting to install a bad full package.
Solution: Implemented better error checking to ensure that a good client package folder is created. If installations are failing, it is suggested that the 'full' directories corresponding to the package are removed.

Installation fails when installing as part of Windows XP unattended install.
Fix ID: 1383539
Symptom: Installation of Symantec Endpoint Protection as a part of an unattended Windows XP installation rolls back.
Solution: Corrected registration of Symantec Endpoint Protection components with LiveUpdate during installation.

Possible hang/crash after applying Active Directory folder exclusions on the server.
Fix ID: 1406310
Symptom: After applying Active Directory folder exclusions on the server and during scanning of the system files, NTDS may encounter a hang or crash.
Solution: This hang was caused by Auto-Protect trying to read from certain files. The hang occurred when Auto Protect does a scan of files in the clean file cache when new virus definitions arrive. This is resolved by disabling the Rescan the cache option by navigating to: AntiVirus/AntiSpyware Protection Settings > File System Auto-Protect > Advanced File Cache > Rescan the cache when new definitions load.

File backups are at least 80% slower with Symantec Endpoint Protection installed.
Fix ID: 1275606
Symptom: Poor backup performance when Symantec Endpoint Protection is installed.
Solution: Modified the engine to prevent this issue from occurring by skipping files opened with backup semantics.

The Symantec Endpoint Protection client interface wraps to the second monitor.
Fix ID: 1304016
Symptom: Parts of the window are seen on the second screen.
Solution: Resized the main frame to fit the display area of the first screen.

64-bit clients are sending Tamper Protection status to Symantec Endpoint Protection Manager as "Off" rather than as "Not Installed."
Fix ID: 1412863, 1098328
Symptom: Symantec Endpoint Protection Manager shows Tamper Protection as Off rather than as Not Installed.
Solution: Added new interface registration information to the installer.

Custom service written in .NET bloats memory usage with Proactive Threat Protection installed.
Fix ID: 1438181
Symptom: If the Windows service CMISImageHandler.exe is running, Symantec Endpoint Protection service grows from 14MBs to 68-71MBs.
Solution: Resolved through a Confidence Online component update.

Application Error after a push install.
Fix ID: 1361697
Symptom: During push install process, user receives an error.
Solution: This was caused by a timing issue during service shutdown. Added improvements to the cleanup process and added sanity checks to prevent this from happening again.

Windows Security Center status is not updated for out-of-date definitions until a service cycle.
Fix ID: 1405083
Symptom: Windows Security Center will not show correct status until the computer restarts.
Solution: The definition status in Windows Security Center is now updated every 60 minutes.

Symantec Endpoint Protection service starts and stops repeatedly on Windows 2000 Terminal Server.
Fix ID: 1179755
Symptom: Repeated service starts and stops on Windows 2000 Terminal Server.
Solution: Fixed NULL parameter causing the problem.

The scroll bars at the bottom are slightly off the screen on the client.
Fix ID: 1304020
Symptom: Parts of the window are seen on the second screen.
Solution: Resized the main frame to fit the display area of the first screen.

User registry hive in Symantec Endpoint Protection 11 MR 2 MP 2 and newer is locked after logging off of a RDP session.
Fix ID: 1431936
Symptom: An error in logs states Symantec Endpoint Protection is holding on to the user hive registry.
Solution: Disabled the scheduled scan service notify thread.

Cannot save changes in Word 2000 files to FDD.
Fix ID: 1201116
Symptom: Word cannot complete the save due to a file permission error.
Solution: Modified the Auto Protect engine to prevent this issue from occurring.

Constant 5% Rtvscan CPU usage.
Fix ID: 1389006
Symptom: Constant 5% Rtvscan CPU usage seen from Process Explorer or Task Manager.
Solution: Changed to cache the state of Auto-Protect ,thus reducing excessive calls which gather state information. The state is now updated once on startup, on change notification from Auto-Protect, and occasionally on the main timer, eliminating this issue.


Symantec Endpoint Protection: Firewall

Firewall rule ignored if Description field is populated for the Application List.
Fix ID: 1284625
Symptom: If the Description field is set, the Firewall rule containing the description will not be triggered.
Solution: Modified the firewall to correctly set the appropriate flags in the registry.

CardSpace service fails to launch with client running.
Fix ID: 1417019
Symptom: While trying to start the CardSpace service, a popup message states that the service was not able to start. Errors also appear in the System Event logs.
Solution: Resolved via a component update.

Laptops with Symantec Endpoint Protection and 4GB RAM stop responding.
Fix ID: 1444613
Symptom: With Symantec Endpoint Protection installed on a laptop running Windows Vista Business 32-bit, upgrade the amount of RAM from 2-3 GB to 4GB. The laptop stops responding after 20-30 minutes.
Solution: Resolved infinite loop in the firewall code.

Sysplant blocks certain Network based apps.
Fix ID: 1430654
Symptom: IRIS Practice Software is blocked by the firewall.
Solution: Firewall now allows this software to run.

Blue Screen while Incredibuild 3.2 is in use.
Fix ID: 1431699
Symptom: With Symantec Endpoint Protection and Incredibuild 3.2 installed, the system stops responding with a blue screen.
Solution: Removed the data structure that caused the problem.

IncrediBuild 3.2 does not work unless Sysplant is disabled.
Fix ID: 1394288
Symptom: After enable OSP policy, Microsoft Visual Studio can't compile program with IncrediBuild program.
Solution: Application is now compatible.

SMCinst.exe is not replaced when Symantec Endpoint Protection or Symantec Network Access Control Client is migrated using MSI patch.
Fix ID: 1301423
Symptom: Smcinst.exe is not replaced when Symantec Endpoint Protection/Symantec Network Access Control client is migrated by MSI+MSP installation package.
Solution: Latest Smcinst.exe is added to the MSI+MSP package, and is replaced upon successful migration.

Wireless connections at 104Mb/second do not register with Location Awareness as Wireless connections.
Fix ID: 1441489
Symptom: Auto Location Awareness does not work when using 104Mbps wireless network.
Solution: Added 130Mbps/117Mbps to the list that detects when the wireless speed is not stable.

Symantec Endpoint Protection client management system logs report incorrect IP address for the Manager.
Fix ID: 1220138
Symptom: Incorrect IP address shows in the logs.
Solution: If DNS cannot resolve the hostname, incorrect IP address is not reported.

Smc.exe stops responding and reports errors citing address 0x00006ad0 under low memory conditions.
Fix ID: 1372843
Symptom: Unexpected SMC crash encountered.
Solution: Corrected the usage of the function causing the problem.

Random, limited, or no connectivity on laptops with Symantec Endpoint Protection and Juniper VPN client.
Fix ID: 1433195
Symptom: Network connections randomly have limited or no connectivity on laptops with Symantec Endpoint Protection and Juniper VPN client installed.
Solution: Fixed a deadlock issue with the SMC process.

Event "Connected to Symantec Endpoint Protection Manager (%1)" logs the wrong IP Address for the manager.
Fix ID: 1387845
Symptom: In the System log on the client, the event "Connected to Symantec Endpoint Protection Manager" reports an IP address that is not the address of the Symantec Endpoint Protection Manager.
Solution: If DNS cannot resolve the hostname, incorrect IP address is not reported.

Last Download Time field never updates.
Fix ID: 1423529
Symptom: "Last Download Time" in Symantec Endpoint Protection Manager Reports always shows "Never".
Solution: Stopped zeroing out the last content check time inadvertently and started handling situations in which the value had not changed correctly.

Google Chrome browser cannot be launched if the firewall is running.
Fix ID: 1403244
Symptom: With Symantec Endpoint Protection installed, an application error occurs when launching Google Chrome.
Solution: Application is now compatible.

Errors with Google Talk Plug-in.
Fix ID: 1441738
Symptom: The Google Talk plugin cannot be launched.
Solution: Application is now compatible.

Symantec Endpoint Protection Application and Device control prevents Wild Tangent software from running.
Fix ID: 1422627
Symptom: After clicking "PLAY" button, "FATE.EXE" crashes.
Solution: Application is now compatible.

Firewall rules configured to "ASK" do not log incoming traffic.
Fix ID: 1363282
Symptom: No incoming traffic is logged when configuration option is set to Ask.
Solution: Fixed code that could not find the Process ID or App name.

There is no dialog warning that Application and Device Control will not function unless TruScan is installed at install time.
Fix ID: 1238501
Symptom: Application and Device Control will not function unless TruScan is installed.
Solution: Removed dependency on TruScan.

C++ runtime errors with Think Vantage Client Security Solution for Vista.
Fix ID: 1267801
Symptom: Smc.exe crashes on boot up or service restart on Vista Enterprise laptops.
Solution: Added the appropriate flag to avoid crashes and security issues.

Unable to run whois from within Symantec Endpoint Protection client Traffic logs successfully more than once.
Fix ID: 1370712
Symptom: Running whois from within Symantec Endpoint Protection client Traffic logs successfully more than once is not possible.
Solution: Every time the detail dialog box was opened, the UI sent two requests. The issue was resolved by sending only one request.

Application "Calyx Point" will not run with Sysplant enabled.
Fix ID: 1408234
Symptom: Winpoint crashes when launched.
Solution: Application is now compatible.

Sysplant does not allow MATLAB 2008a software to launch.
Fix ID: 1389109
Symptom: Run the Matlab exe. After two error message boxes, the process exits.
Solution: Do not allow sysfer.dll into "matlab.exe" process.

The firewall prevents the 3G HSDPA connection adapter from properly disconnecting.
Fix ID: 1284609
Symptom: Attempts to re-establish a VPN connection with the client fail.
Solution: Added additional checks on known ports used by 3G card driver allowing connections.

"Block all traffic until firewall starts" prevents Vista hibernation.
Fix ID: 1383703
Symptom: Configuring Symantec Endpoint Protection firewall to "Block all traffic until firewall starts and after firewall stops" will prevent Vista from sleeping or hibernating.
Solution: Component update resolved this issue.

Application and Device Control causes Microsoft Excel to give XMLoader errors.
Fix ID: 1282072
Symptom: Unexpected results when clicking a button in Excel file.
Solution: OSP prevents some processes from being executed normally.

Event ID 6004 error appears in logs repeatedly on Symantec Endpoint Protection clients.
Fix ID: 1259196
Symptom: System log shows Event ID 6004: "A driver packet received from the I/O subsystem was invalid. The data is the packet".
Solution: Modify the WPS driver to remove the unnecessary hooking in XP.

Reverse DNS lookup sometimes does not work.
Fix ID: 1413853
Symptom: Firewall policy allowing traffic from those hosts matching a specified domain name are at times blocked by the firewall.
Solution: No matter whether the first packet is incoming from or outgoing to a remote host, if domain name is configured in rule, RDNS is triggered.

Upgrade should resume download where it left off.
Fix ID: 1369301
Symptom: If network connectivity errors are encountered, the currently downloading client package will be deleted and download will start fresh when connectivity is restored.
Solution: Package updates now use HTTP download resumption protocol.

Conflict between Symantec Endpoint Protection and Checkpoint installation.
Fix ID: 1421768
Symptom: Checkpoint's secure client (SC NGX R60 HFA2) does not finish installation and will eventually blue screen the computer if the customer has Symantec Endpoint Protection client installed.
Solution: Resolved a problem in the firewall driver.

Tamper Protection causing a deadlock when program is run from a mapped drive.
Fix ID: 1422553
Symptom: With Windows 2000 Pro SP4 and Symantec Endpoint Protection AntiVirus/AntiSpam-only client installed, the system eventually stops responding when trying to browse folders within a program called "OpenFile.exe."
Solution: Component update resolved this issue.

Apparent firewall driver memory leak.
Fix ID: 1406226
Symptom: Srtsp.sys driver memory leak and driver (ofant.sys) hangs and causes 20 other processes, including srtsp.sys, to stay locked.
Solution: This was actually an Auto Protect hang issue during file reads, not a firewall memory leak. Resolved.

Large temp files in the Symantec Endpoint Protection\LiveUpdate folder.
Fix ID: 1391636
Symptom: Large temp files produced during content delta building and content download.
Solution: Improved temp file cleanup.

SMC.exe continually accesses rasphone.pbk.
Fix ID: 1318905
Symptom: Smc.exe takes 100% of the CPU time regularly due to smc.exe accessing file rasphone.pbk.
Solution: Corrected the need for smc.exe to continually access the *.pbk.

Aventail client causes smc.exe appcrash in msvcr80.dll
Fix ID: 1432369
Symptom: Installing Aventail VPN client results in SMC crash.
Solution: Fixed a Windows APIs call failure and added a check to ensure that the call succeeded, to prevent a memory access violation.

"Disable NTP" command sent to AntiVirus/AntiSpam-only client causes Symantec Endpoint Protection tray icon to show a red X.
Fix ID: 1416668
Symptom: Sending a "disable NTP" command from Symantec Endpoint Protection Manager causes a red X to be displayed on the tray icon.
Solution: When the command to disable NTP is received by the client, it checks that the firewall is installed and no longer displays the red X.

Symantec Endpoint Protection with custom policy causes uninstallation hangs.
Fix ID: 1223775
Symptom: Using Windows XP SP2 or Vista, uninstalling with a custom policy hangs.
Solution: Component update resolved this issue.

GUP throttling enhancement.
Fix ID: 1414302
Symptom: GUP overloaded network when used across a wide area network.
Solution: Added a configurable fixed delay to reduce overload.

Blue screen error when starting computer.
Fix ID: 1434623
Symptom: Symantec Endpoint Protection 11 MR3 generated a blue screen error on startup, referencing wpsdrvnt.sys.
Solution: Corrected invalid memory condition error.


Symantec Endpoint Protection Manager

System Administrator accounts can be added and deleted but not modified through a remote Symantec Endpoint Protection Manager console.
Fix ID: 1426040
Symptom: System administrator properties and password cannot be changed remotely.
Solution: From the Symantec Protection Endpoint Manager console, you can now modify accounts.

Database administrator name and password are not encrypted during communication.
Fix ID: 1389362
Symptom: User is given the option to select Windows authentication to the database in the configuration wizard.
Solution: The security data is encrypted now.

Symantec Endpoint Protection Manager Host Integrity configuration does not have Windows Vista as an operating system selection.
Fix ID: 996535
Symptom: Windows Vista is not an available option.
Solution: Added Windows Vista to Symantec Endpoint Protection Manager Host Integrity configuration types.

Scheduled replication occurs 30 minutes earlier than expected when Symantec Endpoint Protection Manager is in IST time zone.
Fix ID: 1442805
Symptom: Scheduled replication occurs 30 minutes too soon when in IST time zone.
Solution: Server now converts time based on both hours and minutes.

Symantec Endpoint Protection Manager System Event Notifications do not report errors.
Fix ID: 1362428
Symptom: The report shows 'Nothing to report'.
Solution: Change the SQL query string used.

Copied clients are not listed as expected in non-default views of Symantec Endpoint Protection Manager console.
Fix ID: 1424210
Symptom: Copy a user or computer to the manually-created group from OU. Change the client view to one of the non-default choices (Client status, Protection technology, Network information, or Client system). The client list is blank in the imported OU and each client is listed twice in the manually-created group.
Solution: Altered the SQL query used, improving the filter query results.

Symantec Endpoint Protection Manager does not provide NTLM Authentication when running LiveUpdate.
Fix ID: 1434288
Symptom: Launching LiveUpdate from Symantec Endpoint Protection Manager, using a proxy server configured for NTLM authentication, fails.
Solution: Added a new UI check box that allows enabling the use of Windows Authentication.

Some client reports do not include all client systems.
Fix ID: 1227607
Symptom: The count of clients in some reports is incorrect.
Solution: Modified the Product Version report to show all clients, even if they are not currently reporting status or if AntiVirus is not installed. There is a separate row in the dashboard action summary to show clients that are not reporting status. There are two new rows for the Site Status Report. One row shows computers that do not have clients. One row shows clients that are not reporting status.

AntiVirus/AntiSpyware Policies for a group created during a legacy version migration can be exported but not imported.
Fix ID: 1322745
Symptom: You receive an error message: "Failed to import the policy. Error: Invalid import file".
Solution: Improved import process during migration from Symantec AntiVirus policy file or upgrading from MR3.

Slow login with Symantec Endpoint Protection and Novell client software.
Fix ID: 1447337
Symptom: With Novell client installed, logging on to the console is very slow.
Solution: Improved login time with Symantec Endpoint Protection and Novell client software installed.

New Management Server Lists default to port 80 instead of 8014 creating mismatch.
Fix ID: 1437959
Symptom: MR3 fresh install package with a policy including a non-default Management Server list. The clients that were rolled out were unable to communicate with the Manager.
Solution: Read http port and https port information at login time of Symantec Endpoint Protection Manager.

"Last scanned time" shows 1970/01/01 08:00:00 in scan report.
Fix ID: 1397861
Symptom: The last scan time show incorrect time.
Solution: Converted the time to the correct format.

Setting to accept legacy Symantec AntiVirus 10.x logs is deselected after migration.
Fix ID: 1395850
Symptom: After setting LegacySupport configuration via the Preferences dialog on the homepage and then performing an upgrade, the configuration is lost.
Solution: This preference is now honored and persists after migration.

Renaming groups in Symantec Endpoint Protection Manager does not take effect until a policy change.
Fix ID: 1416751
Symptom: Clients do not show the group name change until a policy change.
Solution: Clients now show the group name change immediately.

Status icon for client is not the correct status for all views except default via Symantec Endpoint Protection Manager.
Fix ID: 1447203
Symptom: When selecting the Default view, the Client Status shows a red arrow. When selecting other views, it changes to a green dot.
Solution: Default view now displays the accurate client status.

Event times in scheduled and alert based reports are an hour later than correct times.
Fix ID: 1299108
Symptom: Reports are an hour later than correct times.
Solution: Added a condition to determine whether the system is using daylight saving time to decide how to compute the local time.

Symantec Endpoint Protection Manager Notifications do not run batch files.
Fix ID: 1427063
Symptom: Symantec Endpoint Protection Manager Notifications do not run batch files.
Solution: Removed the function that prevented the process of batch or executable files.

Javaw.exe takes up to 90% CPU during backup, and event is not logged.
Fix ID: 1365401
Symptom: Backup task leads to 90% CPU usage and leads to Monitoring tab hangs.
Solution: Use specified cache to read and write methods and write binary files to back up zip packages. The backup tool does not support writing to a log.

SemSvc takes up to 90% CPU during backup.
Fix ID: 1365396
Symptom: Backup task leads to 90% CPU usage, and leads to Monitoring tab hangs on
Solution: Use specified cache to read and write methods and write binary files to backing up zip packages.

Symantec Endpoint Protection clients report to incorrect Symantec Endpoint Protection Managers.
Fix ID: 1418576
Symptom: Location-specific communication setting does not honor the preferred group and preferred mode. Symantec Endpoint Protection Client reports to Default Group.
Solution: While exporting a package, preferred group information and preferred mode information is set to these location-specific communication settings.

Sylink watcher log shows 400 responses when trying to download definitions from Symantec Endpoint Protection Manager.
Fix ID: 1418637
Symptom: Client receives 400 bad requests in the Sylink Watcher log.
Solution: Updated product to skip the content and package delta generation.

Symantec Endpoint Protection Manager firewall policy editor does not gracefully handle blank rule names.
Fix ID: 1301097
Symptom: If you blank a firewall rule name and click "OK". The editor warns that a name is required, but then quits without letting you make the change. If you try to import firewall rules with blank rule names, all the rules listed after the blank rule name cannot be imported into firewall policy without a warning message.
Solution: Validate firewall rule panel before updating the firewall policy. Validate input dialog if a blank rule name exists in Import Firewall Rules.

Symantec Endpoint Protection Manager "AgentInfo" folder fills with multiple .DAT files.
Fix ID: 1261236
Symptom: Symantec Endpoint Protection Manager "AgentInfo" folder fills up with .DAT event files.
Solution: Symantec Endpoint Protection Manager now better processes the events sent by the client so the folder will not fill up.

Database admin name and password are not encrypted during connection.
Fix ID: 790931
Symptom: With Symantec Endpoint Protection Manager and SQL 2000 DB installed on the same computer, during a connection from another manager to the manager with SQL installed, the database name and password are not encrypted.
Solution: Name and password are now encrypted.

Pull-down items within Symantec Endpoint Protection Manager Console show different wording.
Fix ID: 1303194
Symptom: Pull-down items within Symantec Endpoint Protection Manager console show different wording.
Solution: Improved the resource file responsible for making the display string identical with the other one, eliminating the problem.

Home, Monitors, and Reports pages are blank on the remote console after updating Java to version 1.6 Update 10.
Fix ID: 1450539
Symptom: After installing JDK or JRE 6 Update 10 from Sun, the Home, Monitors, and Reports pages are blank and will not load.
Solution: Added workaround message in Symantec Endpoint Protection Manager and Symantec Endpoint Protection Manager remote console installation page.

Symantec Endpoint Protection Manager reports generated in .MHT format display a blank page in Internet Explorer.
Fix ID: 1281050
Symptom: Symantec Endpoint Protection Manager Reports generated in .MHT format display a blank page in Internet Explorer.
Solution: By default, Auto-select is checked, which prevents this issue from occurring.

Last Update Time does not match heartbeat time.
Fix ID: 1316833
Symptom: When the client is offline, the last update time in the database does not reflect the last connect time to server. When the client is online for an extended period, the last update time may not change for quite some time. It does not post any client information to the server, and also has no state change.
Solution: Added a new task to pull the client's last update time on a more frequent basis.

Notifications are not triggered when the first Symantec Endpoint Protection Manager in an environment is stopped or removed.
Fix ID: 1421789
Symptom: Email notification does not alert.
Solution: Added a prioritized reporting server list into the site properties.

"Query Failed" when exporting log data after sorting specific columns within Symantec Endpoint Protection Manager.
Fix ID: 1381232
Symptom: "Query Failed" displays when exporting log data.
Solution: Removed duplicate columns and added a lost column in SQL query statement when performing exports.

Time Zone Offset is not listed correctly in Symantec Endpoint Protection Manager for clients whose zone has a fractional hour offset.
Fix ID: 1364622
Symptom: Time Zone Offset is not listed correctly in Symantec Endpoint Protection Manager for clients whose zone has a fractional hour offset.
Solution: The time changed on Symantec Endpoint Protection is now reflected correctly in Symantec Endpoint Protection Manager.

"Per group" option on the Virus Infection and Virus Clean reports is missing.
Fix ID: 1396514
Symptom: The Detection Action Summary report does not show the actions taken as a percentage of the total number of detections, nor does it show those statistics on a per-group basis.
Solution: The Detection Action Summary report now has a new table showing the number of repaired, suspicious, and infected detections per group. It also shows those numbers as a percentage of the total detections for any one group.

Attempting to view scans, risks, or computer status logs results in the inability to select a specific group.
Fix ID: 1407987
Symptom: The dialog box and selection control jumps back to Global.
Solution: Resolved by narrowing the width of dropdown list by 10% so that the max dropdown list width is 90%.

Report files containing Japanese characters sent from Symantec Endpoint Protection Manager are corrupted.
Fix ID: 1157909
Symptom: Scheduled report files (*.mht files) sent from Symantec Endpoint Protection Manager are corrupted.
Solution: Updated the encoding to use the correct method, eliminating the issue.

After upgrading to MR3, "Invalid log record: Too few fields" appears in logs.
Fix ID: 1416913
Symptom: Unnecessary log messages and alerts are generated.
Solution: Removed unnecessary logging

"Query Failed" displays when exporting specific log data.
Fix ID: 1426052
Symptom: This happens only when Symantec Endpoint Protection Manager uses MSSQL 2005, and does not happen if Symantec Endpoint Protection Manager uses Embedded DB. From the "Monitors" tab, any attempt to export "Log Type" Compliance Logs, Enforcer Client, Default filter, Past 24 hours, View log, or Export queries fails.
Solution: Removed the duplicate column and added a lost column in SQL query statement used during export process.

Apostrophe cannot be displayed on exported scan logs
Fix ID: 1366835
Symptom: Specific characters encoded in the first line of the exported log files are not displayed.
Solution: Fixed the display issue of specific characters in the log export.

After deployment of MR3, performance issues with Remote Consoles
Fix ID: 1437482
Symptom: Console slowness from remote consoles.
Solution: Changed default settings and attributes to resolve the performance issue.

Exported computer status logs report missing and incorrect information.
Fix ID: 1414968
Symptom: Computer status logs show complete information in Symantec Endpoint Protection Manager Monitors page, but when the data is exported, it is missing column information.
Solution: Exported logs now contain all columns and data.

Exported Scan Log summaries show End Date/time references of 12/31/1969 for some scans.
Fix ID: 1406234
Symptom: Exported Scan Log summaries show End Date-time references of 12/31/1969 for some scans.
Solution: Display the log entries with state 'In Progress' other than '12/31/1969' or '01/01/1970'.

Symantec Endpoint Protection Manager does not accurately list Active Directory OU members - Duplicate Clients in temp and OU groups.
Fix ID: 1410087
Symptom: Duplicate entries appear in temporary group and also in OU group.
Solution: Improved and optimized the replication process which handles finding and reporting the duplicate Computer Mode and User Mode entries.

When Symantec Endpoint Protection Manager is using a custom server certificate, client auto-upgrade fails.
Fix ID: 1314772
Symptom: The server certificate is an internally signed certificate using Microsoft Certificate Authority Server. The server CSR file was created using IIS to request a digital server certificate. After the CA-signed certificate was imported into IIS, the entire certificate (public and private key) was exported to a .pfx file. That .pfx file was imported into the policy manager under Admin > Servers > Manage Server Certificate. The
certificate was applied prior to any client deployments. When deploying the client , the following appears: "Signature verification error: 2148073478" "Invalid Signature."
Solution: Re-sign all of the affected files when Symantec Endpoint Protection Manager updates certificate.

Symantec Endpoint Protection Manager client status icons are displayed incorrectly.
Fix ID: 1409105
Symptom: Client online status is not shown properly.
Solution: Improved the registration of clients with Symantec Endpoint Protection Manager so that now the reporting of which clients are online is accurate.

Symantec Endpoint Protection Manager Monitor logs have incorrect packet details.
Fix ID: 1382330
Symptom: Symantec Endpoint Protection Manager Monitor logs have incorrect data.
Solution: Fixed the SQL statement used to ensure the details are correct.

Symantec Endpoint Protection clients register with Symantec Endpoint Protection Manager in User mode instead of Computer Mode.
Fix ID: 1421859
Symptom: Client packages exported with computer mode and a preferred group set appear in the wrong group and in user mode after install.
Solution: That behavior is as designed if installing as a workgroup user, but registration now ensures that it does not accidentally change an entry from computer mode to user mode.

[0x80020000] error when navigating to Clients > Policies > Communications settings.
Fix ID: 1457416
Symptom: Navigating to a group's communication policy could crash the server under certain conditions.
Solution: When accessing a default list, provide an empty one if site doesn't exist.

Exception is generated every 14 seconds after replication failure.
Fix ID: 1458441
Symptom: Repeated exceptions appear in the scm-server-0.log.
Solution: When accessing a default list, provide an empty one if site doesn't exist.

"Make all removable drives read-only" rule composed solely of wildcards causes all drives (including non-removable) to be read only.
Fix ID: 1298890
Symptom: If an Application and Device Control "Make all removable drives read-only" composed only of wild cards "*" and no other defining parameters is assigned, the local hard drive (C:) is now Read-Only, as is any other media (removable or otherwise).
Solution: Only removable drives are made read only when selecting this option.

An inherited Live Update policy displays an incorrect Live Update policy setting.
Fix ID: 1403339
Symptom: An inherited LiveUpdate policy displays an incorrect LiveUpdate policy setting, which is confusing.
Solution: Incorrect settings have been eliminated when inheriting LiveUpdate policies.

Symantec Endpoint Protection Manager does not accurately list Active Directory OU members
Fix ID: 1380112
Symptom: Member display may not work properly in Symantec Endpoint Protection Manager during an Active Directory server synch. New users may fall into a Temporary group.
Solution: Fixed Active Directory sync issue.

Importing an AntiVirus/AntiSpyware policy from a migrated Symantec AntiVirus server group into a new domain fails.
Fix ID: 1195565
Symptom: The import fails, the policy does not appear, and no error or exception is visible.
Solution: The command scan policy component is now kept as private metadata when AntiVirus/AntiSpam policies are migrated from a Symantec AntiVirus server.

Host Integrity rule title changes from "Symantec AntiVirus Corporate Edition" changes to "AhnLab V3 Internet Security" after migration to Symantec Endpoint Protection Manager.
Fix ID: 1414333
Symptom: This is a policy migration issue from Symantec Sygate Policy Manager 5.1.x to Symantec Endpoint Protection Manager 11.0.x. If you make a Host Integrity policy of AntiVirus Enforcement on Symantec Sygate Policy Manager 5.1.8, then select "Symantec AntiVirus Corporate Edition" as the antivirus product to be checked, it will be changed to "AhnLab V3 Internet Security" after migration to Symantec Endpoint Protection Manager 11.0.x.
Solution: Fixed the command scan policy component when we migrate antivirus policies from a legacy Symantec AntiVirus server.

Last Update Time does not match heartbeat time.
Fix ID: 1294572
Symptom: The Last Update Time is set when a site marks a client as offline. This looks as if the client were actually checked in at that time, but that is not the case.
Solution: The "Last Online Time" (Clients properties) or the "Last Check-in" (Computer Status log) or the "Last update time" (Computer Status log details) refer to the same client property. This time is updated when one of the client's properties changes. For example, this time is updated to the current time when a client goes from online to offline, from offline to online, or when any one or more of its properties as shown in its Computer Status log details changes. This date/time value, therefore, is the time of last change on the client and is not updated every heartbeat. Use the "Online" property to determine whether a particular client is still communicating with Symantec Endpoint Protection Manager.

Logged out client systems are missing the green dot icon when viewed from Symantec Endpoint Protection Manager.
Fix ID: 1195364
Symptom: Symantec Endpoint Protection Manager does not show the green dot icon for clients which are offline.
Solution: Altered the queries used during the Symantec Endpoint Protection Manager client audit process to fix this issue.

Tomcat hangs when generating a scheduled report.
Fix ID: 1379201
Symptom: The Java task that generates reports for either scheduled reporting or notifications hangs when it is unable to access IIS, and returns error code 502 or 503.
Solution: Reporting's custom error pages are all static now. Other custom error pages are all IIS default pages.


Discrepancies between the client and server on the Known Security Risk Exceptions list.
Fix ID: 1201020
Symptom: Symantec Endpoint Protection Manager Console shows fewer known risks than the client user interface.
Solution: Symantec Endpoint Protection Manager Console now loops to retrieve all known risks that match the client's data.

While exporting the "Search for Applications" results, invalid characters or missing rows appear in the results of the query.
Fix ID: 1439734
Symptom: Exported CSV file contains invalid characters or only has the header row.
Solution: Certain characters were causing problems with exporting to CSV. By removing these characters, the issue was resolved.

"Display notification icon" should only be available when "Display client UI" is enabled
Fix ID: 1223896
Symptom: The "Display notification icon" checkbox is still available after unchecking "Display client user interface."
Solution: The "Display notification icon" checkbox is disabled and unchecked when you uncheck "Display client user interface."

"Object cannot be found [0x16010000]" error when navigating to Admin > Install packages.
Fix ID: 1429789
Symptom: In Symantec Endpoint Protection Manager, navigating to Admin > Install packages causes an "object cannot be found" [0x16010000] error. When trying to export a client package encounter, the same error appears.
Solution: Three-part solution involving updates to the client packages, UI improvements, and improvements to ensuring deleting and reading of the client packages.

Cannot Set the Expiration Option to "Never" in Symantec Endpoint Protection Manager.
Fix ID: 1440744
Symptom: In Symantec Endpoint Protection Manager, it is not possible to set an Administrator's password to "Never Expire." It remains set at the 60 days radio button.
Solution: Can now set this option to Never.

Logs seem to continue to grow with no end.
Fix ID: 1212700
Symptom: Ersecreg.log and exsecars.log log file continue growing.
Solution: Improved the logging.

Symantec Endpoint Protection Manager client data is blank when client is logged off.
Fix ID: 1422562
Symptom: The tabs "Clients" and "User info" at client properties are blank.
Solution: Improved the registration of clients with Symantec Endpoint Protection Manager so that now the reporting of which clients are online is accurate.

"Daisy chain" replication of Symantec Endpoint Protection Manager causes incomplete data in the replication partners.
Fix ID: 1405310
Symptom: Replication from a third site fails after installation of Symantec Endpoint Protection Managers that "daisy chain" multiple sites. Certain components such as packages and policies are missing. Some packages cannot be exported due to missing policies. The following error may occur: "Failed to replicate."
Solution: All incomplete data in replication partners have been fixed.

During upgrade, Symantec Endpoint Protection Manager deletes user-created batch files found in the 'bin' folder.
Fix ID: 1413514
Symptom: Missing batch files.
Solution: Fixed the function responsible for deleting the files by replacing it with a function more mindful of possible user-created batch files housed in this folder.

User is unable to delete old client packages.
Fix ID: 1431008
Symptom: Nothing happens after attempting to delete old 32-bit client packages.
Solution: Corrected the issue with additional software package deployment checks.

Cannot delete a custom installed feature set.
Fix ID: 1371772
Symptom: When trying to delete a custom feature set, the following error appears: "This feature is currently in use; you cannot delete it!"
Solution: Improved the process of deletion.

Symantec Endpoint Protection Manager Application and Device Control log view is missing the "user" column.
Fix ID: 1430747
Symptom: Symantec Endpoint Protection Manager does not present the user account in the "Details" of the selected event.
Solution: Added User column in Results and Details page of ADC log.

Symantec Endpoint Protection Manager Time/OS Time mismatch in non-DST Time zones.
Fix ID: 1268881
Symptom: Symantec Endpoint Protection Manager does not account correctly for time zones without Daylight Saving Time.
Solution: Changed the function used to return the correct current time.

When using the Find Unmanaged Clients function, the client install fails. Errors appear in the server log.
Fix ID: 1374314
Symptom: User cannot copy the package files to the export folder. The product fails to prepare the package.
Solution: Destination folder did not exist when unzipping the full.zip to the export path. The fix was to create the folder.

Replication fails and "Object cannot be found: [0x16010000]" error when going to Admin > Servers.
Fix ID: 1417598
Symptom: User sees an "Object can't be found" error in Symantec Endpoint Protection Manager when entering the Admin >Servers tab.
Solution: Symantec Network Access Control now always replicates all sites.

Policy is not updated consistently.
Fix ID: 1387071
Symptom: Switching to a group detail panel does not change the group name.
Solution: Problem was caused by invalid translation of the code. This is now correctly parsed and resolves the issue.

Homepage shows "Still Infected" count even though all infections are cleared on Computer Status log.
Fix ID: 1408109
Symptom: When you clear infections using the Computer Status log "Clear Infected Status" option, it is still possible to see "Still Infected" counts in the Homepage "Action Summary by Detection Count."
Solution: Added additional checks and updated queries used on the Homepage.

Symantec Endpoint Protection Manager hangs when generating a scheduled report.
Fix ID: 1362174
Symptom: Error appears when generating a scheduled report.
Solution: Added static .htm error pages for PHP and updates to IIS configuration.


Symantec Network Access Control

Wireless Zero Configuration and related services stop with Network Access Control in Transparent mode.
Fix ID: 1409097
Symptom: Wireless Zero Configuration and Wired Auto Configuration services stop when Network Access Control is set to Transparent mode on the client.
Solution: Improved handling of the Identity response to eliminate the need to stop the Microsoft services and to prevent the "authentication failed" message in policy-based transparent mode.

Slow login with Symantec Endpoint Protection and Novell client software.
Fix ID: 1396418
Symptom: User may experience a three-second login delay if they use the Novell client or use login scripts, even if an 802.1x environment is not used.
Solution: Make the wait timeout value configurable through Symantec Endpoint Protection Manager and disable the SNACNP.DLL if 802.1x is not configured in policy.

Snac.exe stops responding when connecting to wireless AP in home environment, but not office.
Fix ID: 1435705
Symptom: When a user attempts to connect to the Linksys wireless router at home, snac.exe stops responding.
Solution: The SSID length that was passed into memory was too large.

Snac.exe stops after about 30 seconds.
Fix ID: 1409297
Symptom: Snac.exe stops after about 30 seconds, and a popup message appears.
Solution: Symantec Network Access Control service was unable to receive incoming EAP packets, causing a false alarm. In turn, Symantec Network Access Control service was restarting. Compatibility updates for necessary drivers have been made to resolve this issue.

Snac.exe application fault.
Fix ID: 1425246
Symptom: During startup, computers that were upgraded to MR3 show the message "Faulting application SNAC.EXE, version 11.0.3001.155, faulting module ntdll.dll, version 5.1.2600.5512, fault address 0x0001b1fa."
Solution: Fault has been resolved.

Gateway Enforcer failover causes ARP flood.
Fix ID: 1323897
Symptom: Symantec Network Access Control sends many ARP packets to both internal and external networks when failover occurs.
Solution: Added data to the end of the ARP packet when it is forwarded by Enforcer. When another Enforcer receives this packet, it sees the added data and does not forward the packet again.

"Add Trusted External IP Range" feature changes do not take effect.
Fix ID: 1448412
Symptom: IP address or IP range info is not saved.
Solution: When adding a new IP address or IP range in the trusted list, it now takes effect immediately.

Users are unable to connect to network via Gateway Enforcer when using Jiangnan VPN.
Fix ID: 1444422
Symptom: When connecting to the network via the Jiangnan VPN, you are unable to successfully communicate with Symantec Endpoint Protection Manager or authenticate to the network.
Solution: Fixed the dll causing the issue.

Unable to add more than 300 trusted IP addresses.
Fix ID: 1448404
Symptom: Cannot add more than 300 rows successfully.
Solution: Can now add more than 300 rows successfully.

The syntax checking for Gateway Enforcer protocol filtering does not work correctly.
Fix ID: 1250187
Symptom: The syntax checking for Gateway Enforcer protocol filtering does not work correctly. It will not allow you to type in "allow 802.3" and "allow 224.0.1.0/255.255.255.0", both of which are valid entries.
Solution: Change was made to allow 802.3 for one independent protocol string, but not in protocol range.

Client authentication will not fail to second RADIUS server if first RADIUS server is down.
Fix ID: 1448406
Symptom: With LAN Enforcement using Symantec Network Access Control 6100 Enforcer 11.0.2000, the first attempt at client authentication will fail because LAN enforcer does not switch RADIUS server from 1 to 2 immediately.
Solution: Change RADIUS server timeout to 3 seconds so that Enforcer will not send out RADIUS reject due to too many identity packets being received.

Enforcer fails to match correct action rule during startup with Transparent Mode.
Fix ID: 1448410
Symptom: In transparent mode, when the computer is starting up, the computer sends HI Pass, EAP unavailable, and Profile Unavailable.
Solution: Mismatching of Client GUID issue has been fixed.

Thirty second delay in client sending EAP packets results in unavailable resources.
Fix ID: 1447050
Symptom: The Symantec Network Access Control module does not send EAP packet until 30 seconds after the network card service starts. Due to this, if any network service has to be started immediately after the logon screen and before Symantec Network Access Control finishes authentication, it will not be available and may cause downloaded failures (for logon scripts, for example).
Solution: Delay has been resolved.

LAN enforcer MAB local database can only store 450 MAC addresses.
Fix ID: 1448400
Symptom: With a large amount of MAC addresses, an error message appears saying that the file size is too big.
Solution: Modified the MAC range control to allow a user to input a large number of MAC addresses.

LAN Enforcer does not fail over to secondary Radius server when primary Radius server goes offline.
Fix ID: 1440873
Symptom: When the primary Radius server goes offline, the LAN Enforcer does not fail over to the secondary Radius server, resulting in clients not being authenticated.
Solution: Resolved Radius failover function of LAN Enforcer for MAB authentication.


Readme items
The help topics for Damper settings state specifically that "Client List Changed" only has one setting, "Auto."
Fix ID: 1365700
Symptom: The help states specifically that "Client List Changed" only has one setting, "Auto".
Solution: For full details see readme section titled "The Configure Notifications help includes some incorrect information".

Page 60 in MR4 Admin guide contains an incorrect description of last icon
Fix ID: 1453627
Symptom: The last icon is a user mode icon. The PDF incorrectly states that it is in computer mode.
Solution: Added a readme item correcting the Admin guide error.



Maintenance Release 3 (MR3)

Component versions in MR3

Major Components
Symantec Endpoint Protection11.0.3001.2224
Client Management Component11.0.3001.2224
Symantec Network Access Control11.0.3001.155
Symantec Endpoint Protection Manager11.0.3001.2224
Minor Components
Auto-Protect10.2.6.5
Behavior Blocking 3.3.7.004
COH 6.1.6.3
Common Client 6.3.7.009
DecABI 1.1.1.39
Defutils 3.3.20.0
QServer 3.6.16
SyKnAppS 2.5.0.12
SymEvent 12.5.3.3
SymNetDrv 7.2.3.302
WpsHelper 11.0.717.804

Symantec Endpoint Protection client fixes



Symantec Endpoint Protection Manager fixes



Symantec Network Access Control fixes



Maintenance Patch 2 for Symantec Endpoint Protection Maintenance Release 2 (MR2 MP2)
This section describes the fixes in Maintenance Patch 2 for Maintenance Release 2.

About Maintenance Patch 2
This Maintenance Patch cannot be installed over the 11.0.0 or 11.0.1 versions of Symantec Endpoint Protection Manager. It must be installed over Maintenance Release 2, either with or without Maintenance Patch 1. For information about how to obtain the latest build of Symantec Endpoint Protection, read the following document: Obtaining an upgrade or update for Symantec Endpoint Protection 11.x or Symantec Network Access Control 11.x.

Components included in Maintenance Patch 2
ComponentVersion
AMS6.12.0.148
Auto-Protect10.2.4
Behavior Blocking3.3.7
COH6.1.2.3/6.1.3.20
Common Client106.3.6.9
DecABI1.1.1.39
DefUtils3.3.11.0/3.3.16.0
ECOM61.3.0.17
QServer10.1.8.8000
SyKnAppS2.5.0.12
SymEvent12.5.3.3
SymNetDrv7.2.1.110
Teefer211.0.1836.12
WpsHelper11.0.717.804
VxMs (MSLight)5.1.1.0
New fixes in Maintenance Patch 2

Symantec Endpoint Protection Manager fixes
Symantec Endpoint Protection client fixes



Point Patch 1 for Symantec Network Access Control Maintenance Release 2 Maintenance Patch 1
Point Patch 1 is a patch specific to Symantec Network Access Control. It can only be installed over Maintenance Release 2 with Maintenance Patch 1.


Maintenance Patch 1 for Maintenance Release 2 (MR2 MP1)
This section describes the fixes in Maintenance Patch 1 for Maintenance Release 2.

About Maintenance Patch 1
This Maintenance Patch cannot be installed over the 11.0.0 or 11.0.1 versions of Symantec Endpoint Protection Manager. It must be installed over Maintenance Release 2. For information about how to obtain the latest build of Symantec Endpoint Protection, read the following document: Obtaining an upgrade or update for Symantec Endpoint Protection 11.x or Symantec Network Access Control 11.x.

Components included in Maintenance Patch 1

ComponentVersion
AMS6.12.0.148
Auto-Protect10.2.4.2/10.2.4.3
Behavior Blocking3.3.6.7/3.3.6.8
ccEraser 20072.0.1.7
COH6.1.2.3/6.1.3.20
Common Client106.3.6.9
DecABI1.1.1.39
Defutils 3.3.11.0/3.3.16.0
Deuce Engine 2007-06-06-1
ECOM 61.3.0.17
Intelligent Updater5.0 (Release .006)
LiveUpdate 3.3 (Release .002)
LiveUpdateAdmin 2.1.2 (Release .002)
LiveUpdateCCPA 1.0 (Release .002)
LOTS Manager3.3 (Release .001)
Microdefs 2.5 (Release .007)
SyKnAppS 2.5.0.12
SymEvent 2.5.3\3
SymNetDrv 7.2.1
Teefer211.0.1836.12
WpsHelper11.0.717.804
VxMS (MSLight) 5.1.1.0


New fixes in Maintenance Patch 1

Symantec Endpoint Protection Manager fixes Symantec Endpoint Protection client fixes


Maintenance Release 2 (MR2)
This section describes the new features and fixes included in Maintenance Release 2 of Symantec Endpoint Protection 11.0 and Symantec Network Access Control 11.0.


About Maintenance Release 2 for Symantec Endpoint Protection and Symantec Network Access Control
Symantec Endpoint Protection 11.0.2 and Symantec Network Access Control 11.0.2 provide enhancements on top of the existing 11.0 functionality to support the Microsoft Windows 2008 Server. In addition to providing compatibility with the new operating system, this release adds compatibility to the Microsoft Network Access Protection (NAP) framework. Fixes for customer problems and minor enhancements since the release of Symantec Endpoint Protection and Symantec Network Access Control are included this release. This release also adds support for Windows Vista Service Pack 1 and XP Service Pack 3.

New features

Components included in Maintenance Release 2

ComponentVersionComments
Auto-Protect10.2.3Certified on Windows 2008
Behavior Blocking3.3.6\008
ccEraser 20072.0.1.7
COH6.1.3\020
Common Client6.3.6\009
DecABI1.1.1
Defutils 3.3 (Release .002)
Deuce Engine 2007-06-06-1
ECOM 20071.3
Intelligent Updater5.0 (Release .006)
LiveUpdate 3.3 (Release .002)
LiveUpdateAdmin 2.1.2 (Release .002)
LiveUpdateCCPA 1.0 (Release .002)
LOTS Manager3.3 (Release .001)
Microdefs 2.5 (Release .007)
SyKnAppS 2.5Certified on Windows 2008
SymEvent 12.5.3\3
SymNetDrv 7.2.1Certified on Windows 2008


New fixes in Maintenance Release 2

Symantec Endpoint Protection Manager fixes


Symantec Endpoint Protection client fixes


Symantec Network Access Control client fixes




Maintenance Patch 1 for Maintenance Release 1 (MR1 MP1)
This section describes the fixes in Maintenance Patch 1 for Maintenance Release 1.

About Maintenance Patch 1
Maintenance Patch 1 updates only Symantec Endpoint Protection Manager. It does not need to be installed to clients.

This Maintenance Patch cannot be installed over the original 11.0.0 version of Symantec Endpoint Protection Manager. It must be installed over Maintenance Release 1, or onto a computer with no Manager installed. For information about how to obtain the latest build of Symantec Endpoint Protection, read the following document: Obtaining an upgrade or update for Symantec Endpoint Protection 11.x or Symantec Network Access Control 11.x.

You can use the Maintenance Patch 1 installer to install the Manager on computers that do not already have Symantec Endpoint Protection Manager. The Manager contains client installation packages for Symantec Endpoint Protection Maintenance Release 1.


Symantec Endpoint Protection Manager fixes



Maintenance Release 1 (MR1)
This section describes the fixes in Maintenance Release 1 of Symantec Endpoint Protection 11.0 and Symantec Network Access Control 11.0.

Components


ComponentVersion
AutoProtect10.2.2.5/10.2.2.6
AVComp2.0.58.0
Behavior Blocking3.3.3.015
ccEraser20072.0.1.6
COH 6.1.2.054
Common Client106.6.3.2
DecABI 1.1.0.37
Defutils 3.3.11.0
Deuce Engine 3.0.2.2007-06-06_01
ECOM71.1.0.11
Intelligent Updater5.0.25
LiveUpdate 3.3.0.61
LiveSubReg2.4.2
LiveUpdateAdmin2.1.77
LiveUpdateCCPA 1.0.2
LOTS Manager3.3.0.61
Microdefs 2.5.36.0
Packager 1.2.3.924
QServer 3.5.76
SAV 11.0.1000.1112
SAV for Linux 1.0.3.8
Scan And Deliver 2005.15.0.14
SESCMC 11.0.1000.1091
SESM 11.0.1000.1049
SyKnAppS 1.5.3.7
SymEvent 12.4.0.25
SymNetDrv 7.2.0.15
SymSentry 2.1.101
SymStat 24.0.0.0
Teefer211.0.690
WpsHelper11.0.717.804
VxMS (MSLight) 5.0.71.0

 

Symantec Endpoint Protection fixes

Symantec Network Access Control fixes



References:
This document is available in the following languages:



 

Available Translations:



Document ID: 2007121216360648
Last Modified: 11/04/2009
Date Created: 12/12/2007
Product(s): Endpoint Protection 11
Release(s): Endpoint Protection 11.0, Endpoint Protection 11.0.1, Endpoint Protection 11.0.2, Endpoint Protection 11.0.3, Endpoint Protection 11.0.4


Site Index · Legal Notices · Privacy Policy · · Contact Us · Global Sites · License Agreements
©1995 - 2009 Symantec Corporation