Use Process Explorer to Determine if Symantec Endpoint Protection is Monitoring a Process
search cancel

Use Process Explorer to Determine if Symantec Endpoint Protection is Monitoring a Process

book

Article ID: 233927

calendar_today

Updated On:

Products

Endpoint Protection

Issue/Introduction

Users suspect Endpoint Protection (SEP) of blocking or interfering with an application, process, or service.

NOTE: This test is often run with component isolation. Please discuss the process for component isolation with Support.

Environment

Endpoint Protection with Windows.

Cause

Users observe anomalous behavior such as uncommon convergence events in the System Event logs, trouble with Webex, or steep latency when transferring data. 

Resolution

Understanding the different versions of Process Explorer in the download:

     procexp.exe

     procexp64.exe

     procexp64a.exe

procexp.exe is the 32-bit binary, which also works on current 64-bit versions of Windows.

procexp64.exe is the 64-bit binary, for 64-bit Windows systems.

procexp64a.exe, is the binary for Windows systems running on ARM-based hardware.

 

Using Process Explorer:

1. Start or prepare to test the service in question.

 

2. Open Process Explorer.

 

3. Select View > Show Lower Pane.

4. Use the hotkey combination CTL + D, or select View > Lower Pane View > DLLs to view DLLs.

5. Replicate the issue or problem.

6. Scroll down to find the process in question.

7. Save as <process>.txt.

 

Analyzing:

1. Open Excel.

 

2. Use the text import wizard or open the file with Excel. You may need to select All Files to view the text file in File Explorer.

 

3. Select delimited, tab delimeter, and general column data format.

4. Locate Name-Description-Company Name-Version (contains DLLs).

5. Select Name above the list of DLLs.

6. Activate the filter feature (sort and filter in ribbon above/blade/panel).

7. Select the drop-down menu here and configure the parameters as Name – Contains - .dll.

 

8. Clear the check boxes as appropriate for the DLLs specified by Support or provide the results for Support as requested.

    

 

References:

https://docs.microsoft.com/en-us/answers/questions/369211/process-explorer.html

https://support.microsoft.com/en-us/topic/using-process-explorer-to-list-dlls-running-under-the-outlook-exe-process-21a705da-896d-41d3-fc05-521394001dce

http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx

https://knowledge.broadcom.com/external/article/170706/processes-and-services-used-by-endpoint.html

https://knowledge.broadcom.com/external/article/181736/how-to-create-an-application-control-exc.html