Endpoint Protection

 View Only
  • 1.  Current Risks VS Current Virus'

    Posted Feb 23, 2010 10:22 AM
    I've been told before that Current Virus' are detections that have been addressed, and that Risks still put your system at "Risk" as they have not been cleaned. If this is the case, why don't "Current Virus's" automatically get cleared from our Computer Status logs? Do I just need to manually go in and Clear infected file status for all these infections???


  • 2.  RE: Current Risks VS Current Virus'

    Posted Feb 23, 2010 10:25 AM
    yes you need to inspect and then clear it.

    How to clear an erroneous "Still Infected" status from Reports in the Symantec Endpoint Protection Manager

    http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007111913145448 


  • 3.  RE: Current Risks VS Current Virus'

    Posted Feb 23, 2010 10:27 AM
     Yes Still infected status has to be manually removed from the logs.
    You have to first read whether what action was taken
    left-alone, partially-Cleaned,blocked,access-denied etc
    if it says deleted, cleaned then you can just go ahead and clear the status however if anything else then should visit the system and make sure it is clean by running full scans etc.


  • 4.  RE: Current Risks VS Current Virus'

    Posted Feb 23, 2010 10:54 AM
    where do you view the action taken from the Computer Status Logs screen? Am I goign to have to run a seperate report to know that?


  • 5.  RE: Current Risks VS Current Virus'

    Posted Feb 23, 2010 11:01 AM
    open sepm
    logs
    scan log or system log wil give you more info 


  • 6.  RE: Current Risks VS Current Virus'

    Posted Feb 23, 2010 11:04 AM
    You need to check risk log Risk log


  • 7.  RE: Current Risks VS Current Virus'

    Posted Feb 23, 2010 11:05 AM
    vikram is rigth, its under risk log.i was wrong.:) 


  • 8.  RE: Current Risks VS Current Virus'

    Posted Feb 23, 2010 11:24 AM
    maybe I'm just exceptionally lazy, but is there a way to view the action taken on a virus, and to clear it status from the same report??

    I'd assume that if somethings no longer a "Risk", and his moved to Current Virus', that a cleaning action took place: left-alone, partially-Cleaned. If it were blocked, or access-denied, wouldn't it still be a Risk? If thats the case it seems a little redundant to check the Risk Log.


  • 9.  RE: Current Risks VS Current Virus'

    Posted Feb 23, 2010 11:26 AM
    in that case, remove all the infected status as per the above doc,
    monitors - logs - computer status
    at the bottom
    click on advanced and select infected only.
    clear all ( control + click) 
    check if it comes back tomorrow, if infected wil surely come, if not all is well ;)  


  • 10.  RE: Current Risks VS Current Virus'

    Posted Feb 23, 2010 03:15 PM
    What version are you running LoXodonte? 

    Grant-