Endpoint Protection

 View Only
  • 1.  SEPM Risk Log and Virus Email Notifications Have incorrect Username

    Posted Oct 17, 2013 08:29 AM

    I have noticed on numerous occasions when viewing the risk logs and Virus detection email notifications that an incorrect user and computer name is displayed. The detection identifies a path location for the virus under a user who does not even have a user profile on the computer. How does this occur?



  • 2.  RE: SEPM Risk Log and Virus Email Notifications Have incorrect Username

    Posted Oct 17, 2013 08:34 AM

    Does the username exist at all? Where is the detection at? Perhaps it is from an attac on the network

    What version of SEPM?



  • 3.  RE: SEPM Risk Log and Virus Email Notifications Have incorrect Username

    Posted Oct 17, 2013 09:15 AM

    Yes the username is valid. No, it is not a network attack. The risk log continues to change computer names. Within the last hour the computer name changed three times on the Risk log. Email notifications are also showing incorrect computer names.

    Attachment(s)

    doc
    1Document.doc   95 KB 1 version
    doc
    2Document.doc   91 KB 1 version


  • 4.  RE: SEPM Risk Log and Virus Email Notifications Have incorrect Username

    Posted Oct 17, 2013 10:01 AM
      |   view attached

    Here is another post showing another different computer name on the Risk log from the same attack. I have also noticed this issue occuring at another school location. While the correct endpoint can usually be determined, it is incorrect and misleading. I was hoping there would be an answer or if someone else has noticed this in their system.

    Attachment(s)

    doc
    3Document.doc   91 KB 1 version


  • 5.  RE: SEPM Risk Log and Virus Email Notifications Have incorrect Username

    Posted Oct 17, 2013 10:08 AM

    This could be due to the type malware detected. I'm not sure what you know about zeroaccess but it's pretty nasty to say the least.

    I'll see what I can find on it.



  • 6.  RE: SEPM Risk Log and Virus Email Notifications Have incorrect Username

    Posted Nov 27, 2013 11:17 AM

    Is this still occurring?



  • 7.  RE: SEPM Risk Log and Virus Email Notifications Have incorrect Username

    Posted Dec 03, 2013 08:28 AM

    Brian,

    Yes, it is still occurring. I noticed the issue the other day on a client report. Our school resource officer had Malware on his computer and it was cleaned. We deleted the client logs, but I continued to receive the reports until I sent a content and scan command. I notice on one of the reports that the computer name was incorrect but I was not concerned because of the history of the problem. I have email copies of the reports.

    The only way to prove this it to have a Symantec webex in to prove the issue.

    Pat

     

     

     

    Pat