I have managed a few Symantec Endpoint Protection or Corporate Edition servers in the past few years and I have had to reconnect the clients to the server from time to time due to a server move, disaster recovery, or flaky client install. Symantec provides a tool called SylinkDrop.exe that can update the XML files needed in order to reconnect the antivirus clients. Grab the SylinkDrop.exe and Sylink.xml files from your Symantec server and save them to whereever you plan to run the script from. You will need to run this tool from the client computer directly, so we can use the pstools to automate this action. You can download the pstools for free online. We will use the “psexec” tool, which allows you to run a command on a remote computer. I like to make the command silent so the user is not aware. Read the rest of this entry »
March 22, 2010
Symantec AntiVirus Client Reconnect
March 21, 2010
Virus Hunt
Recently I was hunting a worm on a corporate network and based on the output of the worm. Symantec Antivirus would find MarioForever.exe files on any network shares where the Everyone group had full access. I decided to search the LAN for the files that this worm is supposed to have infected the origin computer with: Read the rest of this entry »
