Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

Current Risks VS Current Virus'

Updated: 24 Aug 2010 | 9 comments
LoXodonte's picture
0 0 Votes
Login to vote

I've been told before that Current Virus' are detections that have been addressed, and that Risks still put your system at "Risk" as they have not been cleaned. If this is the case, why don't "Current Virus's" automatically get cleared from our Computer Status logs? Do I just need to manually go in and Clear infected file status for all these infections???

Comments

Rafeeq's picture
23
Feb
2010
0 Votes 0
Login to vote

hi

yes you need to inspect and then clear it.

How to clear an erroneous "Still Infected" status from Reports in the Symantec Endpoint Protection Manager

http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007111913145448 

Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq

Vikram Kumar-SAV to SEP's picture
23
Feb
2010
0 Votes 0
Login to vote

 Yes Still infected status

 Yes Still infected status has to be manually removed from the logs.
You have to first read whether what action was taken
left-alone, partially-Cleaned,blocked,access-denied etc
if it says deleted, cleaned then you can just go ahead and clear the status however if anything else then should visit the system and make sure it is clean by running full scans etc.

LoXodonte's picture
23
Feb
2010
0 Votes 0
Login to vote

where do you view the action

where do you view the action taken from the Computer Status Logs screen? Am I goign to have to run a seperate report to know that?

Rafeeq's picture
23
Feb
2010
0 Votes 0
Login to vote

hi

open sepm
logs
scan log or system log wil give you more info 

Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq

Vikram Kumar-SAV to SEP's picture
23
Feb
2010
1 Vote +1
Login to vote
Rafeeq's picture
23
Feb
2010
0 Votes 0
Login to vote

hi

vikram is rigth, its under risk log.i was wrong.:) 

Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq

LoXodonte's picture
23
Feb
2010
0 Votes 0
Login to vote

maybe I'm just exceptionally

maybe I'm just exceptionally lazy, but is there a way to view the action taken on a virus, and to clear it status from the same report??

I'd assume that if somethings no longer a "Risk", and his moved to Current Virus', that a cleaning action took place: left-alone, partially-Cleaned. If it were blocked, or access-denied, wouldn't it still be a Risk? If thats the case it seems a little redundant to check the Risk Log.

Rafeeq's picture
23
Feb
2010
0 Votes 0
Login to vote

hi

in that case, remove all the infected status as per the above doc,
monitors - logs - computer status
at the bottom
click on advanced and select infected only.
clear all ( control + click) 
check if it comes back tomorrow, if infected wil surely come, if not all is well ;)  

Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq

Grant_Hall's picture
23
Feb
2010
0 Votes 0
Login to vote

What version are you running

What version are you running LoXodonte? 

Grant-

Please don't forget to mark your thread solved with whatever answer helped you : )