Endpoint Protection

 View Only
  • 1.  can not clear the "Still Infected" Symantec Endpoint Protection Manager 12.1

    Posted Jun 25, 2014 12:09 AM

    I have a function in the Clear still inface in the next version of symantec end point protections manager. Because there v12.1 Drive DVD and Device Extarnal log is a log of the unit depending persist and can not be cleared. Which I am seeking information from the website and found v 12.1 symantec can not do. I think in the development of the next issue will be resolved. 

    thank



  • 2.  RE: can not clear the "Still Infected" Symantec Endpoint Protection Manager 12.1

    Posted Jun 25, 2014 12:15 AM

    See Chetan comments

    In SEP 11 you may have to perform manual steps.

    But in SEP 12.1 status should update automatically.

    Following info is very important when we talk about SEP 12.1

    "The "Still Infected" number will go down automatically as the threat is completely removed from the network.

    This is a part of the enhanced management console.  The management server resets the Still Infected Status for a client computer once the computer is no longer infected. It gives a more accurate status for how many client computers really are infected."

    I would suggest to manually check those machines

    https://www-secure.symantec.com/connect/forums/still-infected-not-changing-home-page-sepm

     

    Voteup below IDEA

    https://www-secure.symantec.com/connect/ideas/sepm-121-needs-clear-infected-status-button



  • 3.  RE: can not clear the "Still Infected" Symantec Endpoint Protection Manager 12.1

    Posted Jun 25, 2014 01:33 AM

    Check if it help

    https://www-secure.symantec.com/connect/forums/clear-still-infected-items

    https://www-secure.symantec.com/connect/forums/still-infected-status-report

    Cannot Delete the "Still Infected" Value From the Symantec Endpoint Protection Manager 12.1 Console

    Article:TECH165846  |  Created: 2011-07-28  |  Updated: 2011-09-14  |  Article URL http://www.symantec.com/docs/TECH165846

    How to clear the "Still Infected" status from Reports in the Symantec Endpoint Protection Manager

    Article:TECH102954  |  Created: 2007-01-19  |  Updated: 2013-03-13  |  Article URL http://www.symantec.com/docs/TECH102954

     



  • 4.  RE: can not clear the "Still Infected" Symantec Endpoint Protection Manager 12.1

    Posted Jun 25, 2014 07:49 AM

    This is by design and the SEPM now handles this automatically.

    Put in a blank/clean DVD and re-scan and it should clear automatically.



  • 5.  RE: can not clear the "Still Infected" Symantec Endpoint Protection Manager 12.1

    Trusted Advisor
    Posted Jul 21, 2014 07:48 PM

    Hello,

    In SEPM 12.1, the "Still Infected" number will go down automatically as the threat is completely removed from the network.

    This is a part of the enhanced management console.  The management server resets the Still Infected Status for a client computer once the computer is no longer infected. It gives a more accurate status for how many client computers really are infected.

    Check this Article:

    Cannot Delete the "Still Infected" Value From the Symantec Endpoint Protection Manager 12.1 Console

    http://www.symantec.com/docs/TECH165846

    Secondly, I would suggest you to work on these Articles:

    Identifying the infected and at-risk computers

    http://www.symantec.com/docs/HOWTO80990

    Remediating risks on the computers in your network

    http://www.symantec.com/docs/HOWTO80936

    In your case, initiate a full scan on the system. Entry would be removed from Still infected status.

    You can check the scan action and rescanning the identified computers by following the steps provided in the article below:

    http://www.symantec.com/docs/HOWTO80991

    Still Infected is a subset of Newly Infected, and the Still Infected count goes down as you eliminate the risks from your network. Computers are still infected if a subsequent scan would report them as infected. 

    For example, Symantec Endpoint Protection might have been able to clean a risk only partially from a computer, so Auto-Protect still detects the risk.

    The management server resets the Still Infected Status for a client computer once the computer is no longer infected. This should produce a more accurate status for how many client computers really are infected, rather than requiring user interaction to define a computer as clean.

    Hope that helps!!



  • 6.  RE: can not clear the "Still Infected" Symantec Endpoint Protection Manager 12.1
    Best Answer

    Posted Jul 21, 2014 09:13 PM
    Yes, The "Still Infected" number will go down automatically as the threat is completely removed from the network. This is a part of the enhanced management console. The management server resets the Still Infected Status for a client computer once the computer is no longer infected. It gives a more accurate status for how many client computers really are infected. As workaround please insert blank disk to the drive in client machine and run scan as it will creat new log as cleared will clear the status in the SEPM, if it is from one system you computer 1) Disable Tamper Protection either on the SEPM or on the client (by following TECH192023). 2) Stop Symantec Management Client service by opening the "Run" box and executing the command: smc -stop 3) Delete the following files. Windows 2000/XP/2003: C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\CurrentVersion\Data\DB\atpi.db C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\CurrentVersion\Data\DB\av.db Windows Vista/7/8: C:\ProgramData\Symantec\Symantec Endpoint Protection\CurrentVersion\Data\DB\atpi.db C:\ProgramData\Symantec\Symantec Endpoint Protection\CurrentVersion\Data\DB\av.db 4) Navigate to the following registry key. HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\CurrentVersion\public-opstate Modify the DWORD "Infected" to '0'. 5) Start Symantec Management Client service by opening the "Run" box and executing the command: smc -start 6) Enable Tamper Protection.