JoesCat Posted November 29, 2017 ID:1187581 Share Posted November 29, 2017 On the cloud console dashboard, Infected: 1 . Now what? Where to go to see what's still showing as "infected"? The only place I found, which would be highly inconvenient as the deployment grows, is under the "Detections" left pane item, scrolling through ALL of the entries. Under Action Taken, some were "quarantined", some "blocked", and only one was "Found", just a registry value, "PUM.Optional.DisableShowMyComputer" , "HKU\S-1-5-21-2342763795-823332892-3551160719-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED|START_SHOWMYCOMPUTER". I'm pretty sure it is benign. Yet there's nothing to click on to allow it for all endpoints like the old Enterprise for Business product. Link to post Share on other sites More sharing options...
JoesCat Posted November 30, 2017 Author ID:1187637 Share Posted November 30, 2017 Added info: I added a new endpoint (that was getting a lot of detections and quarantines in the old product), and submitted a scan+quarantine. Now in the dashboard I have 2 "Infected". Four items were found and quarantined on this new endpoint. Nothing else occurred in the scan apparently - no "Found" or "Blocked". So if all four items the scan found were quarantined, why does the "Infected" count in the dashboard increment up? Link to post Share on other sites More sharing options...
djacobson Posted December 1, 2017 ID:1187949 Share Posted December 1, 2017 That is a Group Policy Object modification to force Windows 10 machines to open "This PC" instead of "Quick Access", add it to your exclusions like this... HKU\*\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED|START_SHOWMYCOMPUTER Link to post Share on other sites More sharing options...
djacobson Posted December 1, 2017 ID:1187950 Share Posted December 1, 2017 Found means a detection was found but no action took place - this happens when you use scan and report on-demand scan, and for scheduled scans if you do not have the quarantine threats automatically option turned on in the schedule entry. Quarantined means a detection was found by the realtime or the scanner and the object was quarantined. Blocked means the web blocker blocked a connection attempt to a known malicious IP. Link to post Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now