Hi,
I am currently conducting a trial of Webroot installed at a remote office in Malaysia, from Australia. Yesterday I received an email that one of the PC's there had been "Attacked", and checking the console this morning I see the message :
Alert 1 Endpoint needs attention We recommend you check whether this endpoint has automatic remediation enabled on the assigned policy.
The endpoint shows as "Infected" by Malware called "W32.Rogue.32". The PC was last seen yesterday afternoon, a few minutes after the Malware was detected. There is no clean scan recorded.
My question is : How do I know what action was taken by Webroot, or do I have to assume the file was quarantined ? There does not seem to be any way to see a log of the actions performed either successfully or not.
I find the message "Infected" rather alarming as it implies there is still an infection .....
Thanks
Solved
Can you clarify what "Infected" really means against an endpoint
Best answer by Shawn
Hello,
After further testing, I found that if I have the Silent Audit policy assisnged to an endpoint that becomes infected, it will desplay that message in the console. This is also the case when you have a policy configured to not auto-remediate threats, which is the main function of Silent Audit.
If that is not the case this could be a new variant of a rootkit that we would like to investigate further.
Please let us know if you have any further questions or need further assistance with that endpoint.
Shawn
Webroot Enterprise Support
View originalAfter further testing, I found that if I have the Silent Audit policy assisnged to an endpoint that becomes infected, it will desplay that message in the console. This is also the case when you have a policy configured to not auto-remediate threats, which is the main function of Silent Audit.
If that is not the case this could be a new variant of a rootkit that we would like to investigate further.
Please let us know if you have any further questions or need further assistance with that endpoint.
Shawn
Webroot Enterprise Support
This topic has been closed for comments
Login to the community
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.