RE: Quick Norton AV question

From: O'Reilly, Tom (oreilt@jacobsons.com)
Date: 09/21/01


Message-ID: <BF47093ACF37D4119A9000A0C9B41DE00213BFAB@email.jacobsons.com>
From: "O'Reilly, Tom" <oreilt@jacobsons.com>
To: "'Kinsey, Robert'" <Robert.Kinsey@Veridian.com>, "'Gullett, Chris '" <Chris.Gullett@anchorgaming.com>, "''Panger, Erick' '" <erick.panger@trueposition.com>, "''focus-ms@securityfocus.com' '" <focus-ms@securityfocus.com>
Subject: RE: Quick Norton AV question
Date: Fri, 21 Sep 2001 17:01:37 -0400

Since we're taking Norton here maybe someone can help me. I use Norton Corp
Ed 7.51 on my clients and I have certain clients that always seem to have a
status of virus found in SSC. I reset the status, but soon they end up
virus found again. If I do a complete scan of their hard drive including
the quarantine from my machine they have no infected files. Also the log
will show the virus being found several times with the action being left
alone in every instance. I find this weird, because I have clean as the
primary action and quarantine as the secondary so I don't understand why it
could be left alone. I search their hard drive for the file listed and it
isn't there anywhere. What am I missing here?

Thanks,
Tom

-----Original Message-----
From: Kinsey, Robert [mailto:Robert.Kinsey@Veridian.com]
Sent: Friday, September 21, 2001 2:16 PM
To: 'Gullett, Chris '; ''Panger, Erick' '; ''focus-ms@securityfocus.com'
'
Subject: RE: Quick Norton AV question

Chris wrote...

>Norton Corp Ed quarantined the file the first time it was found. Then a
>definition update came in, which scans the quarantine folder to see if
>any files in quarantine can now be cleaned and restored. Since the file >in
quarantine could not be cleaned it was "Left Alone".

And this will also generate another alert and listing in the Virus History
(both on the client AND on the SSC if used).

>This will happen every time a definition comes in until you either
>delete the file from quarantine or it's cleaned and restored.

>When you run a manual scan the quarantine folder is NOT scanned.

Once you have scanned and ensured you are not infected (hopefully) you can
delete from the Quarantine folder. If an essential file is in there you
haven't been using it any way and it should not be used either. This will
remove a file the AV cannot clean. Also, if you are using the SSC you
should also remove the virus status off the client and Parent.

Good luck.

rob



Relevant Pages

  • Re: Quick Norton AV question
    ... O'Reilly, Tom wrote: ... >Since we're taking Norton here maybe someone can help me. ... >Ed 7.51 on my clients and I have certain clients that always seem to have a ... >status of virus found in SSC. ...
    (Focus-Microsoft)
  • RE: Quick Norton AV question
    ... Subject: Quick Norton AV question ... Ed 7.51 on my clients and I have certain clients that always seem to have a ... status of virus found in SSC. ... the quarantine from my machine they have no infected files. ...
    (Focus-Microsoft)
  • Re: hacktool.rootkit
    ... | This would lead one to think Symantec has wrongly identified a Virus ... | I wonder if similar reports of Hacktool.Rootkit are a result of Norton ... Note that all AV applicvations will suffer False Positive declarations from time to time. ... just has to download the corrected signatures and the restore the file from quarantine. ...
    (microsoft.public.security.virus)
  • RE: Quick Norton AV question
    ... Subject: Quick Norton AV question ... status of virus found in SSC. ... the quarantine from my machine they have no infected files. ... (both on the client AND on the SSC if used). ...
    (Focus-Microsoft)
  • Re: Is this a virus
    ... if that swen file is in quarantine it is safe to leave it there. ... > I'm running XP Pro and Norton AV. ... > screen was jumping caused by some CPU activity. ... > appears to relate to the SWEN virus. ...
    (microsoft.public.security.virus)

Loading