Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

Risk Details --> Status: Still contains xx infected items

Created: 17 Jan 2012 | 10 comments
cus000's picture
0 0 Votes
Login to vote

Hi All,

As per above, have you all encounter it?

SEP Action taken is actually quarantined but mentioned in the Risk Details,  "Status: Still contains 1 infected items"

 

Sample is a zipped file.

Comments

mon_raralio's picture
17
Jan
2012
0 Votes 0
Login to vote

RE: Risk Details --> Status: Still contains xx infected items

Yes, it does happen on 11.x versions. It is not present in version 12.1

You could clear them up immediately by going to the Monitors > Logs

Then select Computer Status > Compliance options >>

Check the "Infected only" then click on "View Log"

Choose "All" on the right drop-down box and click on "Clear Infected "Status"

“Your most unhappy customers are your greatest source of learning.”

Simpson Homer's picture
17
Jan
2012
0 Votes 0
Login to vote

 Still Infected status

check this Article:

Still Infected status not clearing on Symantec Endpoint Protection Manager home page

http://www.symantec.com/docs/TECH95463

Mithun Sanghavi's picture
18
Jan
2012
0 Votes 0
Login to vote

Check these Articles

Hello,

Please work on the steps provided in the Article below:

How to clear an erroneous "Still Infected" status from Reports in the Symantec Endpoint Protection Manager

http://www.symantec.com/docs/TECH102954

How to delete Quarantined items from the Symantec Endpoint Protection Manager.

http://www.symantec.com/docs/TECH106444

Sweeping SEPM log data from the database manually.

http://www.symantec.com/docs/TECH105351

Managing log data in the Symantec Endpoint Protection Manager (SEPM)

http://www.symantec.com/docs/TECH90856

Hope that helps!!

Mithun Sanghavi
Symantec Technical Support Engineer, SEP
MIM | MCSA | SCTS | ITIL v3

Follow me on Twitter: @mithun_sanghavi

Don't forget to mark your thread as 'SOLVED' with the answer that best helped yo

cus000's picture
18
Jan
2012
0 Votes 0
Login to vote

Thanks all.   This status is

Thanks all.

 

This status is actually from the client itself, not from SEPM.

 

I wonder what actually this mean, because main sample ".exe" file inside the zipped file has been deleted...

pete_4u2002's picture
18
Jan
2012
0 Votes 0
Login to vote

are there any other files

are there any other files apart from .exe in zip?

if you extract the zip file do you see the exe?

Mithun Sanghavi's picture
19
Jan
2012
0 Votes 0
Login to vote

I understand.

Hello,

I understand, that's because the file was Quarantined. That is the reason, you see no .exe in the zip folder.

Check this:

Understanding Quarantine.

What to do after you quarantine a file

So, that is the reason: SEP Action taken is actually quarantined but mentioned in the Risk Details,  "Status: Still contains 1 infected items"

Hope that explains.!!

Mithun Sanghavi
Symantec Technical Support Engineer, SEP
MIM | MCSA | SCTS | ITIL v3

Follow me on Twitter: @mithun_sanghavi

Don't forget to mark your thread as 'SOLVED' with the answer that best helped yo

cus000's picture
25
Jan
2012
0 Votes 0
Login to vote

Ok thanks, but in any case

Ok thanks, but in any case this is weird... the file is already quarantined... it shouldn't say

"still contains 1 infected items"

 

and yes.. there's other non-malicious files in the zip file....

mon_raralio's picture
25
Jan
2012
0 Votes 0
Login to vote

Check the logs

Hi,

For a particular PC with a "Still infected status", could you generate a Risk log and see when the last infection report date was, and compare that with the PC's last scan date.

“Your most unhappy customers are your greatest source of learning.”

SameerU's picture
30
Jan
2012
0 Votes 0
Login to vote

Hi

Please do the following:

Stop the Symantec Endpoint Protection Manager service

    1. Click Start, then Run
    2. Type services.msc
    3. Click OK
    4. Locate and right-click Symantec Endpoint Protection Manager in the list, then click Stop

  1. Open Windows Explorer and navigate to the following folder; back up all files residing in this folder before proceeding:

    \Program Files\Symantec\Symantec Endpoint Protection Manager\data\inbox\agentinfo

  2. After backing up the files, delete the contents of the folder so that the agentinfo folder is empty
  3. Start the Symantec Endpoint Protection Manager service
    1. Click Start, then Run
    2. Type services.msc
    3. Click OK
    4. Locate and right-click Symantec Endpoint Protection Manager in the list, then click Start

  4. Log into the Symantec Endpoint Protection Manager
    • Go into Monitors & Logs and clear any remaining clients of their infected status
    • The homepage should now update the "still infected" field

Regards