Endpoint Protection

 View Only
  • 1.  compress file scan and left alone

    Posted Jun 23, 2016 04:52 AM

    Could you please suggest why it only left alone when run scheduled scan

    Compressed File 10.64.123.167 SGB8646VJP5 Scheduled scan W97M.Downloader 1 \\?\Volume{674ee134-ff45-11dc-9c64-00170854720c}\Users\A996371\Delivery for package # 7036733030540492 - Failed.msg Still contains 1 infected items Left alone
    Virus found 10.64.123.167 SGB8646VJP5 Scheduled scan W97M.Downloader 1 \\?\Volume{674ee134-ff45-11dc-9c64-00170854720c}\Users\A996371\Delivery for package # 7036733030540492 - Failed.msg>>__substg1.0_37010102   Left alone
    Compressed File 10.64.123.167 SGB8646VJP5 Scheduled scan Downloader.Upatre 1 \\?\Volume{674ee134-ff45-11dc-9c64-00170854720c}\Users\A92991\RECYCLER\S-1-5-21-98787294-1557172059-2965833559-8306\D@10.zip Still contains 1 infected items Left alone
    Virus found 10.64.123.167 SGB8646VJP5 Scheduled scan Downloader.Upatre 1 \\?\Volume{674ee134-ff45-11dc-9c64-00170854720c}\Users\A92991\RECYCLER\S-1-5-21-98787294-1557172059-2965833559-8306\D@10.zip>>fax.exe   Left alone


  • 2.  RE: compress file scan and left alone

    Posted Jun 23, 2016 08:08 AM

    Was the zip file encrypted or password protected? If so, SEP can't scan it. It's also possible that SEP doesn't have a decomposer signature to open the zip file and scan it.



  • 3.  RE: compress file scan and left alone

    Posted Jun 23, 2016 01:55 PM

    Please follow the best practice

    Best Practices for responding to "Left Alone" in the virus or threat history log

    https://support.symantec.com/en_US/article.TECH101661.html



  • 4.  RE: compress file scan and left alone

    Posted Jun 24, 2016 04:24 AM

    Hi simpi sateesh,

    What exactly are you scanning-?  If this is a mail database then SEP is the wrong tool for the job.  SEP is designed to protect endpoints- mail-borne threats should be scanned and stopped before they reach the endpoint. Here's a good article:

    Support Perspective: W97M.Downloader Battle Plan
    https://www-secure.symantec.com/connect/articles/support-perspective-w97mdownloader-battle-plan

    SEP has decomposers and eraser engines which can scan inside many compression/container formats, but it's not possible to cover every kind.  If this scan is flagging a message attachment inside of a mail client as malicious, but cannot delete it, then take manual action.  Open the mail client and delete the message (without opening the message or attachment!). 

    With thanks and best regards,

    Mick



  • 5.  RE: compress file scan and left alone

    Broadcom Employee
    Posted Jun 24, 2016 05:56 AM

    Hi,

    Thank you for posting in Symantec community.

    If file present under temp folder does not exist then you can simply ignore that event because if SEP detects a malicious file attempting to write to the drive, it may deny the file access.  A marker will be temporarily placed in the Temp directory, but no file actually exists.  This can be verified by reviewing the location of the detection and checking for the presence of the detected file.

    For other locations can manually check the file to take necessary action or can configure the settings suggested below.

    Left alone means Symantec Endpoint Protection detected a risk but did not take action. This can occur if the first configured action is Leave alone or if the second configured action was Leave alone and the first configured action was not successful. This may mean that a risk is active on the endpoint.

    To ger around of this change the client settings.

    1. Click on Change Settings in the SEP client console,
    2. Click on Antivirus and Antispyware Protection, Configure Settings and then switch to File System Auto-Protect tab and click on the Advanced button,
    3. Checkbox next to "Delete newly created infected files if the action is “Leave alone (log only)” 

     Left alone_1.jpg

    1. You can enable this option to delete a new file that is infected with a type of risk that you configured Auto-Protect to leave alone.
    2. This does not apply to infected files already detected as infected by Auto-Protect with the status of "Leave alone (log only)", "Quarantined" or any other status since Auto-Protect runs in real-time it will only apply to those new detections.
    3. Although this is an added feature of protection you should be aware of a possible issue if you encounter false positive detections. Those files which are detected as infected may need to be restored from a backup.