DISCLAIMER:The following instructions are for the Symantec Endpoint Protection product ONLY.
If there are any other Symantec products installed on the system that
share the virus definitions please contact Symantec Technical Support.
Instructions for 32-bit Operating Systems: For Windows 2000/2003/XP
- Stop the Symantec Endpoint Protection Services:
- Click Start, Run, typing in smc -stop, and pushing Enter.
- Click the Start button and then click Run
- Type services.msc and click OK
- Right-click Symantec Endpoint Protection and click Stop.
- Minimize the Services window
Note: If you
are unable to stop the Symantec Management Client you will need to
temporarily disable Tamper Protection. Please see the Technical
Information at the bottom of this document for instructions.
- Delete the data from the Definition folders:
- Virus Definitions
C:\Program Files\Common Files\Symantec Shared\VirusDefs\
- Delete all files and subfolders
- Delete the downloaded data in the "C:\Documents and Settings\All Users\Application Data\Symantec\Liveupdate\downloads"
WARNING:
In the next steps you will edit the Windows registry. Back up the
registry before you make any changes to it, because incorrect changes to
the registry can result in permanent data loss or corrupted files.
Modify only the registry values that are specified. For instructions,
see How to back up the Windows registry.
- Delete the data from the registry:
- Click the Start button and then click Run
- Type regedit and click OK
- Navigate to:
HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\SharedDefs
- Delete the following values:
- SRTSP
- NAVCORP_70
- DEFWATCH_10
- SepCache3
- SepCache2
- SepCache1
- Restart the Symantec Endpoint Protection Services stopped in the previous step, 3.c.
- Click Start, Run, type in smc -start, and push Enter.
- Maximize the Services window.
- Right-click Symantec Endpoint Protection service and click Start.
For Windows Vista/Server 2008/Windows7
- Stop the Symantec Endpoint Protection Services:
- Click Start, Run, type in smc -stop, and push Enter
- Click the Start button.
- In the search bar type services and then press Enter.
Note: If the User Account Control prompt pops up click Continue.
- Right-click Symantec Endpoint Protection and click Stop.
Note:
If you are unable to stop the Symantec Management Client you will need
to temporarily disable Tamper Protection. Please see the Technical
Information at the bottom of this document for instructions.
- Delete the data from the Definition folders:
- Virus Definitions
C:\ProgramData\Symantec\Definitions\VirusDefs\
- Delete all files and subfolders
WARNING:
In the next steps you will edit the Windows registry. Back up the
registry before you make any changes to it, because incorrect changes to
the registry can result in permanent data loss or corrupted files.
Modify only the registry values that are specified. For instructions,
see How to back up the Windows registry.
- Delete the data from the registry:
- Click the Start button
- Type regedit and press Enter
- Navigate to:
HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\SharedDefs
- Delete the following values:
- SRTSP
- NAVCORP_70
- DEFWATCH_10
- SepCache3
- SepCache2
- SepCache1
- Restart the Symantec Endpoint Protection Services stopped in the previous step, 3.c.
- Click Start, Run, type in smc -start, and push Enter.
- Maximize the Services window.
- Right-click Symantec Endpoint Protection and click Start.
Instructions for 64-bit Operating Systems: For Windows 2000/2003/XP
- Stop the Symantec Endpoint Protection Services:
- Click Start, Run, type in smc -stop, and push Enter.
- Click the Start button and then click Run
- Type services.msc and click OK
- Right-click Symantec Endpoint Protection and click Stop.
- Minimize the Services window
Note: If you
are unable to stop the Symantec Management Client you will need to
temporarily disable Tamper Protection. Please see the Technical
Information at the bottom of this document for instructions.
- Delete the data from the Definition folders:
- Virus Definitions
C:\Program Files (x86)\Common Files\Symantec Shared\VirusDefs\
- Delete all files and subfolders
WARNING:
In the next steps you will edit the Windows registry. Back up the
registry before you make any changes to it, because incorrect changes to
the registry can result in permanent data loss or corrupted files.
Modify only the registry values that are specified. For instructions,
see How to back up the Windows registry.
- Delete the data from the registry:
- Click the Start button and then click Run
- Type regedit and click OK
- Navigate to:
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Symantec\SharedDefs
- Delete the following values:
- SRTSP
- NAVCORP_70
- DEFWATCH_10
- SepCache3
- SepCache2
- SepCache1
- Restart the Symantec Endpoint Protection Services stopped in the previous step, 3.c.
- Click Start, Run, type in smc -start, and push Enter.
- Maximize the Services window.
- Right-click Symantec Endpoint Protection service and click Start.
For Windows Vista/Server 2008/Windows 7
- Stop the Symantec Endpoint Protection Services:
- Click Start, Run, type in smc -stop, and push Enter.
- Click the Start button.
- In the search bar type services and then press Enter.
Note: If the User Account Control prompt pops up click Continue.
- Right-click Symantec Endpoint Protection and click Stop.
Note:
If you are unable to stop the Symantec Management Client you will need
to temporarily disable Tamper Protection. Please see the Technical
Information at the bottom of this document for instructions.
- Delete the data from the Definition folders:
- Virus Definitions
C:\ProgramData\Symantec\Definitions\VirusDefs\
- Delete all files and subfolders
WARNING:
In the next steps you will edit the Windows registry. Back up the
registry before you make any changes to it, because incorrect changes to
the registry can result in permanent data loss or corrupted files.
Modify only the registry values that are specified. For instructions,
see How to back up the Windows registry.
- Delete the data from the registry:
- Click the Start button
- Type regedit and press Enter
- Navigate to:
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Symantec\SharedDefs
- Delete the following values:
- SRTSP
- NAVCORP_70
- DEFWATCH_10
- SepCache3
- SepCache2
- SepCache1
- Restart the Symantec Endpoint Protection Services stopped in the previous step, 3.c.
- Click Start, Run, type in smc -start, and push Enter.
- Maximize the Services window.
- Right-click Symantec Endpoint Protection and click Start.
References In some instances, Symantec
Technical Support may recommend the use of an unsupported tool that
automates the removal of corrupted SEP definitions. For details please
see
Using the "Rx4DefsSEP" utility at
http://www.symantec.com/business/support/index?page=content&id=TECH93036&locale=en_US
Technical Information How to disable Tamper Protection:
- Open and log into the Symantec Endpoint Protection Manager console
- Click the Clients view.
- Select the appropriate group.
- Under the Policies tab, in the "Settings" section, click General Settings.
- Under the Tamper Protection tab, uncheck Protect Symantec security software from being tampered with or shut down.
- Click OK.
IMPORTANT: Once definitions will be purged, the following popup message will appear:
"Virus definitions are missing on this computer. This
computer will remain unprotected until definitions are downloaded from
the network. Contact your system administrator for help updating your
virus definitions."
This message will keep showing (after every smc -stop/smc -start or
session opening), even when Symantec Endpoint Protection will
receive/apply new set of definitions, until "Symantec Endpoint
Protection" service is restarted. To avoid this, it is possible either:
- to drop JDB file to update client then restart "
Symantec Endpoint Protection" service
- to use Rx4DefsSEP
- to use a script which is checking Antivirus/Antispyware definition status and restart "
Symantec Endpoint Protection" service if appropriate
NOTE: this behavior is as designed.
No comments:
Post a Comment