Quantcast
Channel: Symantec Connect - Products - Discussions
Viewing all articles
Browse latest Browse all 6827

Found questionable things in exclusions

$
0
0
I need a solution

In my workplace we are using Symantec Endpoint Protection on latest version of 12 with up to date definitions. I recently discovered a workstation with an unknown background process,this a more than a little suspicious as upon researching it turns out to be associated with software aimed to illegally circumvent proper activation of MS products.

I found that this had been detected, quarantined, but then somehow restored. Even more surprising was the fact that this executable and other detected files had all been added to the exclusion list to avoid re-detection.

Did this executable restore and then exclude itself? Would this had to have been restored and excluded manually? I am very concerned about the safety of our network environment.

Any insight anyone could offer is greatly appreciated!

0

Viewing all articles
Browse latest Browse all 6827

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>