How to clear "Still Infected" pcs from "Virus and Risks Activity summary on SEPM 12.1 RU1 MP1 console
Created: 07 Sep 2012 | Updated: 11 Sep 2012 | 5 comments
This issue has been solved. See solution.
Hi,
Eventhough, the virus/spyware is cleaned from the workstations, the field "Still infected" is still not cearing up for Viruses and Spyware and Risks. It shows the #of workstations infected. Its been a while, I thought it should clear up by itself since 12.1 does it automatically but it is not working for us. Please help!
Thanks,
Discussion Filed Under:
Group Ownership:
Comments 5 Comments • Jump to latest comment
The management console now does it automatically, see this article:
Cannot Delete the "Still Infected" Value From the Symantec Endpoint Protection Manager 12.1 Console
http://www.symantec.com/business/support/index?page=content&id=TECH165846
Solution
The "Still Infected" number will go down automatically as the threat is completely removed from the network.
This is a part of the enhanced management console. The management server resets the Still Infected Status for a client computer once the computer is no longer infected. It gives a more accurate status for how many client computers really are infected.
There is no longer a way to do it manually from the console.
SEP Knowledge Base
Endpoint SWAT
Thanks for your reply.
Yes, I know that SEPM 12.1 has autmatically removes it once it is completely gone from the network. I have 4 incidents that have been there for at least 3-4 months, eventhough one of the pc is reimaged to test this but still not removing the entry from the cosole. So, now this is not possible at all I guess.
Thanks again.
Hello,
Could you try initiating a full scan on these systems.
Hopefully, the Entry wwould be removed from Still infected status.
Hope that helps!!
Mithun Sanghavi
Symantec Technical Support Engineer, SEP
MIM | MCSA | MCTS | STS | ITIL v3
Twitter: @mithun_sanghavi
Don't forget to mark your thread as 'SOLVED' with the answer that best helps you.<&a
Thank you all!
Click on Monitors > Logs then in drop down select Computer Status then select Advanced settings at bottom of page at the top you will see filter settings select Compliance options then check infected only box and click View Log.
This will view all infected select all from drop down then clcik on clear infected once clear go back to Home page and refresh the screen job done. every now and again you will get a ghost figure this will clear over time but this process will delete the majority.
You can no longer do the process I've posted on SEP 12 symantec have removed it booo!!!
Process only works on a SEP 11 manager.
Please review ideas and vote there could be something useful :)
https://www-secure.symantec.com/connect/security/ideas
Would you like to reply?
Login or Register to post your comment.