Enable, disable or configure Bloodhound heuristic virus detection in Endpoint Protection
searchcancel
Enable, disable or configure Bloodhound heuristic virus detection in Endpoint Protection
book
Article ID: 177533
calendar_today
Updated On: 12-15-2021
Products
Endpoint Protection
Issue/Introduction
You need to know how to enable or disable Bloodhound heuristic virus detection in Symantec Endpoint Protection Manager (SEPM), or change the level of protection it uses.
Resolution
For pre 14.2 versions:
In the SEPM, select Policies.
Select Virus and Spyware.
Right-click the desired AntiVirus and Antispyware policy from the list of policies in the right hand window pane and click Edit.
Select File System Auto-Protect in the Antivirus and Antispyware Policy window.
Under the Scan Details tab click the Advanced Scanning and Monitoring... button.
Under Bloodhound(TM) Detection Settings you can check the setting to 'Enable Bloodhound(TM) heuristic virus detection' or disable it.
Next to Level of protection to use: you can increase (Maximum) or lower (Minimum) the Bloodhound(TM)'s level of protection from the Default setting.
From 14.2 & later versions:
In the SEPM, select Policies.
Select Virus and Spyware.
Right-click the desired Virus and Spyware policy from the list of policies in the right-hand window pane and click Edit.
Select Global Scan Options in the Antivirus and Antispyware Policy window, under Advanced Options.
Check or uncheck the Enable Bloodhound heuristic virus detection to enable/disable the component.
Select the desired sensitivity by selecting Automatic (default) or Aggressive mode from the drop-down menu on the right-hand side.
Additional Information
Note that utilizing the Aggressive setting with clients that do not have access to Symantec Reputation Servers will result in a large amount of False Positives under the detection Heur.AdvML.A Please make sure to plan your policies accordingly, and test before deploying into production.