Video Screencast Help

How to clear "Still Infected" pcs from "Virus and Risks Activity summary on SEPM 12.1 RU1 MP1 console

Created: 07 Sep 2012 • Updated: 11 Sep 2012 | 5 comments
This issue has been solved. See solution.

Hi,

Eventhough, the virus/spyware is cleaned from the workstations, the field "Still infected" is still not cearing up for Viruses and Spyware and Risks. It shows the #of workstations infected.  Its been a while, I thought it should clear up by itself since 12.1 does it automatically but it is not working for us.  Please help!

Thanks,

Comments 5 CommentsJump to latest comment

.Brian's picture

The management console now does it automatically, see this article:

 

Cannot Delete the "Still Infected" Value From the Symantec Endpoint Protection Manager 12.1 Console

http://www.symantec.com/business/support/index?page=content&id=TECH165846

 

 

Solution

The "Still Infected" number will go down automatically as the threat is completely removed from the network.

This is a part of the enhanced management console.  The management server resets the Still Infected Status for a client computer once the computer is no longer infected. It gives a more accurate status for how many client computers really are infected.

 

There is no longer a way to do it manually from the console.

Please click the "Mark as solution" link at bottom left on the post that best answers your question. This will benefit admins looking for a solution to the same problem.

brip's picture

Thanks for your reply.

Yes, I know that SEPM 12.1 has autmatically removes it once it is completely gone from the network.  I have 4 incidents that have been there for at least 3-4 months, eventhough one of the pc is reimaged to test this but still not removing the entry from the cosole.  So, now this is not possible at all I guess. 

Thanks again.

Mithun Sanghavi's picture

Hello,

Could you try initiating a full scan on these systems.

Hopefully, the Entry wwould be removed from Still infected status.

Hope that helps!!

Mithun Sanghavi
Senior Consultant
MIM | MCSA | MCTS | STS | SSE | SSE+ | ITIL v3

Don't forget to mark your thread as 'SOLVED' with the answer that best helped you.

SOLUTION
GeoGeo's picture

Click on Monitors > Logs then in drop down select Computer Status then select Advanced settings at bottom of page at the top you will see filter settings select Compliance options then check infected only box and click View Log.

This will view all infected select all from drop down then clcik on clear infected once clear go back to Home page and refresh the screen job done. every now and again you will get a ghost figure this will clear over time but this process will delete the majority.

 

You can no longer do the process I've posted on SEP 12 symantec have removed it booo!!! frown

Process only works on a SEP 11 manager.

Please review ideas and vote there could be something useful :)

https://www-secure.symantec.com/connect/security/ideas