Endpoint Protection Small Business Edition

 View Only
Expand all | Collapse all

Still infected items not being removed

  • 1.  Still infected items not being removed

    Posted Aug 18, 2010 04:19 PM

    In the management screen on the our Windows 2008 server on the start up it shows what computers are still infected with viruses that symantec couldn't remove. I went in and manually deleted the entire user folder the infections and risks were located under, yet they still show up on the start up screen. The computer in question is a Windows XP machine. Is there anyway to see if the threat is really still there and if it's not how can I make the manager realize it's gone?


  • 2.  RE: Still infected items not being removed

    Posted Aug 18, 2010 04:35 PM
    navigate to logs folder of the symantec endpoint protection; 
    it should be under documents and settings \all users\symantec \endpont \logs
    clear all the logs
    check if that goes away
    its good to run a full scan;just to make sure that viruses are removed completely


  • 3.  RE: Still infected items not being removed

    Posted Aug 18, 2010 04:38 PM

    On the server managing all of the computers or the machine in question?


  • 4.  RE: Still infected items not being removed

    Posted Aug 18, 2010 05:05 PM
    the machine in question :)


  • 5.  RE: Still infected items not being removed

    Posted Aug 19, 2010 10:18 AM

    Alright for some reason the computer has All User.WINNT and that's where I found the log folder. I deleted everything in there except for a .dat file, but the server still seems to think the computer has viruses in folders that don't exist.


  • 6.  RE: Still infected items not being removed
    Best Answer

    Posted Aug 19, 2010 01:59 PM
    Clearing the infected status from the SEPM is a manual process. This is to ensure that the threat has been handled. See the below document

    Title: 'How to clear the "Still Infected" status from Reports in the Symantec Endpoint Protection Manager'
    Document ID: 2007111913145448
    > Web URL: http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007111913145448?Open&seg=ent


  • 7.  RE: Still infected items not being removed

    Posted Aug 19, 2010 04:46 PM

    Thank you thomas_m. To be clear is there no way to only clear out one specific virus or threat from the list or do you have to put the computer is entirely clean?


  • 8.  RE: Still infected items not being removed

    Posted Aug 19, 2010 06:30 PM
    You can't clear a all of a certain threat with one click. What you can do is select multiple lines and then click the clear infected status. The SEPM will only clear lines that were selected


  • 9.  RE: Still infected items not being removed

    Posted Aug 20, 2010 10:39 AM

    Thank you for your help, but I'm still confused. Whenever I view a computer that is infected I can see what's on it by clicking the paper with the magnifying glass icon. If the computer has say Backdoor.Tidserv!inf which I'm not sure is gone and something else that I'm sure is taken care of how do I only remove the item that has been fixed? It seems if I hit clear infcted status it removes everything.


  • 10.  RE: Still infected items not being removed

    Posted Aug 20, 2010 11:25 AM
    I see, so you have multiple threats listed on the same machine on the same line. 

    You wouldn't clear the infected status of a particular threat for that machine, as the machine would still be infected. Once the machine has been cleaned completely, then clear it's infected status. Threats may try and download other threats, so until you are sure the machine is clean don't clear its infected status.


  • 11.  RE: Still infected items not being removed

    Posted Aug 20, 2010 11:51 AM

    Alright. Thank you for your responses!