Here's an example of an infection alert we receive:
An endpoint has recently detected an infection:
Site Name: ABC
Hostname: ABC-RDS
Group Name: Desktops
Policy Name: ABC Desktops
Keycode: XXXXXXXXXXXXXXXXXXXXX
Infection List:
INSTALL[1].EXE, Adware.Installcore, %cache%, http://snup.webrootcloudav.com/SkyStoreFileUploader/upload.aspx?MD5=5E5D720DCE18612641FE
Here's the problems I have:
1) Alert does not indicate what was done with the infected file (was it quarantined?)
2) Path included (%cache%) is incomplete, i.e. which user profile is this (it's a terminal server)
Am I missing something here? This seems like basic stuff that should be included.
Infection Alert - missing important info
Login to the community
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.