Endpoint Protection

 View Only
  • 1.  Clearing "Still Infected" status from malware detected on DVD-R (SEP 12.1)

    Posted May 14, 2013 02:50 PM

    I'm trying to figure out how to clear an issue where one of my user's system is showing a false positive of still being infected.  

    Here's the situation:

    The user had a disc of personal documents and programs on their machine that Symantec Endpoint Protection detected during a scan (anybody remember Kazaa?).  Because the detected malware was on a read-only disc, SEP reported the issue and that it wasn't able to quarantine or kill it.  

    Since then the disc has been removed from the system, but I'm still showing it as an infection for the file on the user's disc.  The user has stated that the disc hasn't been put back into their machine since then (mid-April).  By now, the system should have had multiple scans, both full and active, since the malware was detected, but SEP Manager still shows the system as being "still infected" even though the user's program states there are no problems.  

    I'm trying to remove "false positive" this from the summary of Virus and Risk activities.  I understand that in SEP 12.1 you can no longer manually clear an infection status, but is there anything I can do to get SEPM to recognize that the DVD-R disc and detected infected file is no longer there?  

    Any recommendations as to what I can do?

     



  • 2.  RE: Clearing "Still Infected" status from malware detected on DVD-R (SEP 12.1)
    Best Answer

    Posted May 14, 2013 02:55 PM

    Correct, you can no longer clear it like you could in 11.x, it happens automatically for 12.1.

    I found a similar thread here:

    http://www.symantec.com/connect/forums/sep-121-cannot-clear-still-infected-status

    Sounds like you just need to put in a "clean" disc and re-scan it.



  • 3.  RE: Clearing "Still Infected" status from malware detected on DVD-R (SEP 12.1)

    Posted May 15, 2013 08:54 AM
    Thanks! I grabbed the nearest copy a Microsoft product on disc (which is becoming a rarity today, it seems), ran the scan on the drive, and it cleared up the issue. Thanks! I've marked your response as the solution.


  • 4.  RE: Clearing "Still Infected" status from malware detected on DVD-R (SEP 12.1)

    Posted May 15, 2013 11:26 PM
    Thanks! I grabbed the nearest copy a Microsoft product on disc (which is becoming a rarity today, it seems), ran the scan on the drive, and it cleared up the issue. Thanks! I've marked your response as the solution.