You suspect that the virus definitions currently in use by Symantec Endpoint Protection (SEP) clients are corrupt, and would like to roll back to a previous virus definition set. These clients are managed by a Symantec Endpoint Protection Manager (SEPM).
This example shows reverting AntiVirus definitions to an earlier version. The procedure works with other SEP components as well (reverting to an earlier release of IPS definitions, etc)
To rollback definitions, the [LiveUpdate Settings] policy -> Server settings -> [Use default management server] must be enabled.
The method described below can also be used to circumvent a confirmed False Positive (FP) until definitions are available that remove the detection.
In the case of False Positives, though, creating a specific exclusion or awaiting new Rapid Release definitions is the recommended approach. As each set of new definitions includes protection against new threats, reverting to an older revision will always introduce security risk into an organization.
Follow the steps below to roll back virus definitions in SEPM:
Note: Remember to later return to your LiveUpdate Content Policy and change back to the Use latest available option. Definitions on all endpoints must be kept current in order to protect against the latest threats in circulation.