Current Risks VS Current Virus'
Updated: 24 Aug 2010 | 9 comments
I've been told before that Current Virus' are detections that have been addressed, and that Risks still put your system at "Risk" as they have not been cleaned. If this is the case, why don't "Current Virus's" automatically get cleared from our Computer Status logs? Do I just need to manually go in and Clear infected file status for all these infections???
Discussion Filed Under:
Comments
hi
yes you need to inspect and then clear it.
How to clear an erroneous "Still Infected" status from Reports in the Symantec Endpoint Protection Manager
http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007111913145448
Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq
Yes Still infected status
Yes Still infected status has to be manually removed from the logs.
You have to first read whether what action was taken
left-alone, partially-Cleaned,blocked,access-denied etc
if it says deleted, cleaned then you can just go ahead and clear the status however if anything else then should visit the system and make sure it is clean by running full scans etc.
VMWARE-- SEP 12.1 vs McAfee vs Trend Micro
where do you view the action
where do you view the action taken from the Computer Status Logs screen? Am I goign to have to run a seperate report to know that?
hi
open sepm
logs
scan log or system log wil give you more info
Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq
You need to check risk log
You need to check risk log Risk log
VMWARE-- SEP 12.1 vs McAfee vs Trend Micro
hi
vikram is rigth, its under risk log.i was wrong.:)
Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq
maybe I'm just exceptionally
maybe I'm just exceptionally lazy, but is there a way to view the action taken on a virus, and to clear it status from the same report??
I'd assume that if somethings no longer a "Risk", and his moved to Current Virus', that a cleaning action took place: left-alone, partially-Cleaned. If it were blocked, or access-denied, wouldn't it still be a Risk? If thats the case it seems a little redundant to check the Risk Log.
hi
in that case, remove all the infected status as per the above doc,
monitors - logs - computer status
at the bottom
click on advanced and select infected only.
clear all ( control + click)
check if it comes back tomorrow, if infected wil surely come, if not all is well ;)
Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq
What version are you running
What version are you running LoXodonte?
Grant-
Please don't forget to mark your thread solved with whatever answer helped you : )
Would you like to reply?
Login or Register to post your comment.