Video Screencast Help
Symantec to Separate Into Two Focused, Industry-Leading Technology Companies. Learn more.

SEP 12 Actual Action "Moved Back"

Created: 22 Apr 2013 | 7 comments

Hello,

Reviewing our logs, I've found a virus alert that SEP12 has the Actual Action listed as "Moved Back".  I've found reference to this in the Actual Action Schema (ActualAction_9 = Moved back) but I cannot determine what this means in simple terms. 

We are reviewing these events to determine if SEP12 has effectively mitigated the file in question or additional actions would need to be taken (such as with the Actual Action "Left Alone").

Any help or guidance would be much appreciated.

Thanks,

John

Operating Systems:

Comments 7 CommentsJump to latest comment

.Brian's picture

Can you provide a screenshot of this message?

These are the only ones I'm aware of:

Explanation of Action field values in Symantec Endpoint Protection 12.1 and 11, and Symantec AntiVirus 10.1

Article:TECH102052  |  Created: 2006-01-20  |  Updated: 2012-11-27  |  Article URL http://www.symantec.com/docs/TECH102052

Please click the "Mark as solution" link at bottom left on the post that best answers your question. This will benefit admins looking for a solution to the same problem.

redlazarus's picture

Thanks for the quick response.  I reviewed that list as well and didn't see "Moved Back" as an option.

I'm reviewing a CSV with the results; and for what its worth I've included a screenshot from Excel.

Moved_Back.jpg

.Brian's picture

I'd be curious to see the client Risk log to see what it shows. Or maybe from the SEPM.

Please click the "Mark as solution" link at bottom left on the post that best answers your question. This will benefit admins looking for a solution to the same problem.

redlazarus's picture

I spoke with the user who's system triggered the alert, and we suspect that this alert was caused by the user manually moving the file out of the quarantine (it was a false positive). 

Thanks for your help,

John

FbacchinZF's picture

Does anybody found out what was "Moved Back" action ???

Is it a restore from Quarantine by the user or not ???

.Brian's picture

Yes, appears to be the case.

Please click the "Mark as solution" link at bottom left on the post that best answers your question. This will benefit admins looking for a solution to the same problem.

Abhijeet Chaubey's picture

Still it is not clear that waht the actual action 'moved back' means...