Tamper protection does not work as expected.
search cancel

Tamper protection does not work as expected.

book

Article ID: 231204

calendar_today

Updated On:

Products

Endpoint Protection

Issue/Introduction

Tamper protection is enabled and action is [Block and do not log] or [Block and log]. However, even if you try to modify some registry key under HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Symantec\Symantec Endpoint Protection for example, Tamper protection does not block it.

Environment

  • Following error is logged in OS Application log.
Log Name:      Application
Source:        Symantec AntiVirus
Event ID:      74
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Description:   SONAR has generated an error: code 0: description: Definitions Failed: 0. Binary version: 0
  • There is no definition folder under
    C:\ProgramData\Symantec\Symantec Endpoint Protection\CurrentVersion\Data\Definitions\BashDefs\ other than [newdefs-trigger].

This may happen when you set up Symantec Endpoint Protection Manager (SEPM) in closed network (no internet connection) and update virus definitions only by JDB file.

Cause

Tamper protection has dependency on SONAR definition but there is no SONAR definition on SEP client.

Resolution

Install at least 1 SONAR definition on SEP client. You can install SONAR definition on SEPM by SONAR JDB file, or can install on each SEP client by standalone installer.