SCEP Remediation question

So we had a Warning in SCCM show up today that some machines had some sort of malware on it.  When I viewed the info there was an item called SoftwareBundler:Win32/SquareNet that showed as Computers Infected 6, Computers Remediated 6.  The circle
at the bottom was also green.
To me, if something has been remediated, I would assume that means it had been fix up and is now good to go.  However, when I double clicked on the item to view the 6 machines, under the column called Endpoint Protection Remediation Status, 1 of them
says Cleaned and the other 5 say None.
Does that mean those other 5 are still infected?  If so, why does it say that all 6 have been remediated on the main screen.
On the 5 that show None, should I kick off a definition update and then a full scan in order to get rid of whatever it is?  We're just getting started with getting all this setup and configured so I want to make sure I'm reading this all correctly and
taking the proper actions.
Thanks!!

> I would assume that means it had been fix up and is now good to go. 
That's correct - it means the detected item is no longer there.
> However, when I double clicked on the item to view the 6 machines, 1
of them says Cleaned and the other 5 say None.
As long as that column doesn't show that that device still needs remediation, they should be good.
> On the 5 that show None, should I kick off a definition update and then a full scan in order
to get rid of whatever it is?  
I think it is always a good idea to follow up a detection/remediation with a full scan to ensure there
isn't anything else on there that wasn't triggering real-time protection. Furthermore, you consider spending time investigating how it got there in the first place.  Are the devices patched?  Do people who shouldn't have admin rights have admin rights?
etc.
I hope that helps,
Nash
Nash Pherson, Senior Systems Consultant
Now Micro -
My Blog Posts
If you found a bug or want the product to work differently,
share your feedback.
<-- If this post was helpful, please click the up arrow or propose as answer.

Similar Messages

  • Is there a way to restrict the number of attempts for a remediated question using advanced actions?

    I have the following slides in my project:
    content slide 1
    content slide 2
    question slide 1
    question slide 2
    Question slide 1 is a question about content slide 1. Question slide 2 is a question about content slide 2. I would like to restrict the total number of attempts to two for each question. If question 1 is answered incorrectly on the first attempt, the learner would be returned to content slide 1 for review. Clicking the next button will take the learner back to the missed quiz question and allow them a second attempt to answer it correctly. If they answer it incorrectly again, it is scored as incorrect and the learner is taken to question slide 2.
    Can this be done or does remediation keep repeating until the learner answers the question correctly?
    If that is the case, can I achieve my objective by using advanced actions? And, if so, can you provide step by step instructions on how to do this?

    I think it could be possible, but giving you step-by-step instructions, sorry, that would take a lot of time. Did you use advanced actions already? My archived blog has a lot of use cases and tutorials, but I think it is not fair to ask on a forum for step-by-step instructions for each use case you want to create.  The most important thing will be to make sure that the user always remains in the Quiz scope, you can use the new system variable cpInQuizScope while testing. There is no system variable for attempts on question level, only one on Quiz level, so you'll have to create a user variable to track the attempts on question level. A big problem is that when you leave a question slide, without using the remediation work flow, the attempts are considered as finished. Personally I would prefer for that reason to not use the default question slides. You could try out a combination of remediation and advanced actions, never did test that?
    Lilybiri

  • SCEP remediation failed

    Hi,
    we are using SCEP which is continuously failing the remediation of below threats. We perform the full scan but still same result. Further, it is observed that some viruses detected in outlook pst in a zip file or exe, but SCEP is unable to remediate.
    Please suggest.
    Joke:Win32/ScreenRoses
    Moderate
    Joke Program
    MonitoringTool:MSIL/Limitless
    Severe
    Monitoring Software
    PWS:Win32/Fareit.gen!C
    Severe
    Password Stealer
    PWS:Win32/Zbot.gen!GO
    Severe
    Password Stealer
    Virus:W97M/VMPCK1.BY
    Severe
    Virus
    Virus:Win32/Chir.B@mm
    Severe
    Virus
    Virus:Win32/Virut.EPO_DEBRIS
    Severe
    Virus
    Virus:X97M/Laroux.HT
    Severe
    Virus
    Regards, Syed Fahad Ali

    Why the SCEP might doesn't have access to the location where the infection is located?
    If virus is in attached email, zip file or exe then is it possible to give full access to SCEP?
    Further, what are the default permissions of SCEP?
    Further many SCEP client are not getting updates initially when SCEP is newly installed. That systems are showing in "no definitions found on the client. I already
    see the below link and configured accordingly but still the same result.
    http://support.microsoft.com/kb/2688242
    I have to force latest update via software update then client is updating.
    Please assist.
    Regards, Syed Fahad Ali

  • Remedial question... How to get a development distribution?

    I have an extremely basic question: What do I have to do in order to get the Flash Lite for the Digital Home source distribution?
    I have searched the website and forums for hours, clearly I have missed something basic. My emails to the Developer Support have gone unanswered, my phone calls to the sales department haven't resulted in progress.
    My company is building a high-volume consumer electronic device - based on what I have read in the document "Getting Started with ADOBE FLASH LITE for the Digital Home" that is exactly what we are looking for. We are running an embedded Linux, and this document describes in detail how to compile the player and get it running on Linux but it does not tell you where to get the distribution.
    Any advice or help would be appreciated.
    --steve

    well it's called proper recording and mixing. Seems the first part got left out. You can just mix and match in STP -- put the clips with the same base level in one track and set the volume where you want for each different set. Normalize really isn't meant to do that but it works sometimes.
    Another thing to try is Levalator. Preprocess the VO tracks and get all the levels the same. Then bring them in. I'd try that.
    http://download.cnet.com/The-Levelator/3000-2170_4-143304.html

  • [OIA] Certification & remediation question

    Hi, all!
    When I create a certification task, the job runs immediately, but user, can't see a certification. Somehow the next day the user was able to see this certification, did all steps, but now Remediation hangs in the state "In Progress". Are there any time delays and how to fix them? How to create a certification which is visible to a valid user immediately after creation and how to have remediation run immediately after certification is done?
    Thanks.
    O.

    Hi,
    Dependent on the size of the certification determines how long it will take to show up in the certification page
    On the older versions there was a bug with the certifications taking 1 day to show up on the page. This can be resolved by doing doing a query and searching for certifications between certain days -1 day.
    Example, if you create a certfication on the 11th Feb 2011, do a search for any certifications that were created 10th Feb 2011 onwards
    To get the remediation working on the day of the certification completion, Go to administrator --> Identity Certification --> Revoke and Remediation --> Perform Closed Loop Remediation on: Certification Completion Date
    If this is a 1-day issue all round make sure your time is correct on your server ;-)
    Regards,
    Daniel

  • Remedial question: How do you transfer music from Limewire to iPods?

    I have an iPod (2nd gen) and I also have Limewire, where ALL of my music is stored, becuase I'm a horrible person and I download music. My problem is I cannot figure out how to transfer the music from my lime wire to my iPod, I would just burn all of te music onto cds but that would take FOREVER because there's well over 800 songs. Also not all of the songs that I do have come up when i want to burn no matter how many times I scan my system. Please if you know how to transfer from lime wire to Ipod tell me!

    Some say that they can successfully use the "Add File To Library" option in iTunes under "File" in regards to importing Limewire music to iTunes. I don't use Limewire so I can't confirm this. All you can do is try. If that doesn't work then you are going to have to burn your music and then import it into iTunes from the CD.

  • PSE8 & Dual Monitor Question

    I just connected an external display to my MacBook Pro & have a couple of very remedial questions.
    I have the displays set up in the "extended desktop" mode. But when I open an image in ACR, I cannot drag the ACR window to my external display. Can you please help me here?
    Also, for those of you using dual displays, I assume a desirable way to set up the 2 screens is to keep the PSE tools on one screen & the image to be edited in the other. I'm curious about how you set up your workspace.
    Thank you very much.

    Well, you're using dual monitors the way I've always heard it was to be done.
    First unless the monitors are identical, it does seem like quite a logistics issue to have both screens color balanced and calibrated. So, obviously keep the image on the one that "prints best".
    For the sake of disucssion, if both displays were very close to identical, I suppose you could use the "clone display" mode as a constant before and after.
    My own slightly eccentric self would like to have one monitor vertical, and the other horizontal. This would present both horizontal and vertical images full frame simultaneously. As it stands now, I can get this, but I need two computers to do it.
    I seem to be in a minority, as none of the current graphics drivers permit this, without one of the images being sideways that is. Is this too eccentric?

  • Basic N1 SSH config questions...

    At the risk of asking remedial questions, are these actions correct?: <p>
    <li> When generating SSH keys, I am to generate one set with the ID used to install/owner of the MS (agent, server, cli)? (i cant remember now if cli installed w/ the master seerver or not, i think it did)</li><p>
    <li> I am to create a second user and generate keys, and place this users pub key into the authorized_keys2 file of the first user (product install/owner of MS) </li><p>
    <li>How do I tell N1 about the existance of this second user? Is this what pe.defaultUserToRunAs is for? I cannot find this in the docs. </li><p>
    <li> According to previous postings, root ssh'ing is required for OSP. This makes no sense to me when the agent can be owned by a non-root user, yet can execute native commands with root priv.</li><p>
    <li>The docs state that SSH forwarding works downstream, but can it use loop back to the master server?</li><p>
    <li>Why do I see the product use a root shell to CLI back to the Master server (OSP question)? Should this be happening?</li><p>
    Thanks for everyones help.
    <p>
    Pete.

    At the risk of asking remedial questions, are these
    actions correct?: <p>
    <li> When generating SSH keys, I am to generate one
    set with the ID used to install/owner of the MS
    (agent, server, cli)? (i cant remember now if cli
    installed w/ the master seerver or not, i think it
    did)</li><p>True for MS/LD/RA as they always run with the same uid. CLI works best, if always invoked as the install owner. If the CLI is invoked as any other user, then there are couple options,
    one is to make sure that each user has their ssh keys configured so that the connection from their machine to the MS machine with their ssh credential succeeds.
    Another is to configure CLI to always a single identity to connect to the MS. For security reasons, you may want this identity to be different from the MS install owner. If you look at the ssh man page, it allows you to override the default uid and identity file locations through options -l & -i.
    Lets say we create a new user spsuser, for CLI authentication.
    We can then generate ssh keys for spsuser and put them in this identity file, lets say /home/spsuser/ssh/identity.
    We can then configure sps CLI to override the ssh credentials that are used when connecting to the MS as
    net.client.parms.1=sshargs=-o|BatchMode yes|-l|spsuser|-i|/home/spsuser/identityThat way CLI will always try to use the same ssh identity regardless of who invokes it. However, since I haven't tested this configuration, I'm not certain if it will work. The one possible issue here is that ssh may complain about the identity file having global read permissions.
    >
    <li> I am to create a second user and generate keys,
    and place this users pub key into the
    authorized_keys2 file of the first user (product
    install/owner of MS) </li><p>Nope, the keys always belong to the same user, unless you are overriding the default user to the first user when running ssh as the second user.
    >
    <li>How do I tell N1 about the existance of this
    second user? Is this what pe.defaultUserToRunAs is
    for? I cannot find this in the docs. </li><p>I think you are talking about the CLI here. In this case you'll be running the CLI as the second user, right? In that case all you need to do is to make sure that the second user is able to connect to the MS machine from the CLI machine using ssh, without requiring any user interaction.
    >
    <li> According to previous postings, root ssh'ing is
    required for OSP. This makes no sense to me when the
    agent can be owned by a non-root user, yet can
    execute native commands with root priv.</li><p>The ability to run native commands as root is only available when the agent is running as root. Otherwise the plan that tries to run exec native as root will fail if the agent that its running on is not running as root.
    >
    <li>The docs state that SSH forwarding works
    downstream, but can it use loop back to the master
    server?</li><p>Not sure I understand the question. downstream here implies from the machine invoking ssh client to the machine thats running the ssh daemon. I don't think ssh would care if the the ssh daemon was connected to via any IP address or loopback...
    >
    <li>Why do I see the product use a root shell to CLI
    back to the Master server (OSP question)? Should
    this be happening?</li><p>My opinion is that CLI doesn't need to run as root for most of its functionality. The only case where it may need to run as root is when the files that its trying to checkin are only readable by root. However, it may make sense make those file readable by the CLI user instead of running CLI as root in that case. Don't know if it makes sense to have OSP run the CLI as a non-root user instead..
    hth,
    Aj

  • Newb Processor Question

    Hey folks - had a Titanium Powerbook G4 a couple of years ago and tried to run GB on it. Could lay down 2 or 3 tracks but after that my processor couldn't handle it. Thinking of pulling the trigger on new MacBook:
    2.0GHz Intel Core 2 Duo
    1GB memory
    80GB hard drive1
    Would this be powerful enough to effectively run the latest version of GB and lay down, say, up to 6 tracks? Sorry if this is a remedial question - I just want to make sure before I buy.
    ANY relevant feedback is appreciated - thanks!
    TBD   Mac OS X (10.4.8)  

    You shouldn't have any trouble with only 6 tracks on a machine like that, I've done more, with less.
    Good luck on the purchase (though you might want to wait 4 more days just to see what's announced at MacWorld)!

  • How do I use Adobe Media Server 5 on Amazon Web Services?

    Adobe Media Server 5 on Amazon Web Services was suggested to my project manager as a way to deal with some of the video we have to host at work, but after signing up and poking around, I'm wondering: how do you actually use it? Is it something that requires the Media Server software, or is there a web interface through AWS? I follow the links, and they tell me it's already active for my account - but I still see no way to use it.
    Thanks in advance for help on this seemingly remedial question!

    Hi,
    Please have a look at the document and let me know if it helps you get started: http://help.adobe.com/en_US/adobemediaserver/amazonec2/adobemediaserve r_5.0_amazonec2.pdf
    Thanks,
    Apurva

  • How do I find the font for a specific character in a textItem?

    I'm writing a script that builds a font list for an open document. While I could have lookup the fonts for the file as a whole, my goal is to iterate over specific layerSets to build a font list from. The issue I'm facing, is that referencing:
    app.fonts[text[n].textItem.font].name
    Only pulls the font name of the first character of the textItem. I need to get the names of all the fonts in the textItem, and while I can successfully loop through each of the letters, they do not have the character attributes associated with them.
    I tried this: app.fonts[text[n].textItem.contents.font].name
    As well as many iterations of a similar idea, and I cannot get it to pull the font name, as it's not an attribute of each character. I apologize if this is a remedial question, but I'm a bit of a novice with javascript in Adobe programs.
    For an example of what I'm trying to acheive, I was easily able to do this in illustrator, by using the following statement:
    fontName = text.characters[j].characterAttributes.textFont.name;
    When placed in a loop, this goes through each font in the text Layer.

    This should get a list of the fonts used in Type Layers in the selected Group.
    // get list of fonts used in the active group;
    // based on code by paul riggott;
    // 2014, use it at your own risk;
    #target "photoshop-70.032"
    if (app.documents.length > 0) {
    var theFonts = main ();
    alert ("the fonts used in the folder " + activeDocument.activeLayer.name + " are"+"\n"+theFonts.join("\n"))
    function main () {
    var theFonts = new Array;
    var someLayerStuff = getActiveLayerIIndex();
    if (someLayerStuff[1] != "layerSectionStart") {return []};
    var aNumber = 0;
    // get number of layers;
    var ref = new ActionReference();
    ref.putEnumerated( charIDToTypeID("Dcmn"), charIDToTypeID("Ordn"), charIDToTypeID("Trgt") );
    var applicationDesc = executeActionGet(ref);
    var theNumber = applicationDesc.getInteger(stringIDToTypeID("numberOfLayers"));
    // determine the start index;
    if (activeDocument.layers[activeDocument.layers.length - 1].isBackgroundLayer == true) {var theStart = someLayerStuff[0] - 2}
    else {var theStart = someLayerStuff[0] - 1};
    for (var p = theStart; p >= 0; p--) {
    try {
    var ref = new ActionReference();
    ref.putIndex( charIDToTypeID( "Lyr " ), p);
    var layerDesc = executeActionGet(ref);
    var layerSet = typeIDToStringID(layerDesc.getEnumerationValue(stringIDToTypeID("layerSection")));
    var isBackground = layerDesc.getBoolean(stringIDToTypeID("background"));
    var theName = layerDesc.getString(stringIDToTypeID('name'));
    // check if group closes;
    if (layerSet == "layerSectionStart") {aNumber++};
    if (layerSet == "layerSectionEnd" && aNumber == 0) {return theFonts};
    if (layerSet == "layerSectionEnd" && aNumber != 0) {aNumber--};
    // if not layer group collect values;
    if (layerSet != "layerSectionEnd" && layerSet != "layerSectionStart" && isBackground != true) {
    var hasText = layerDesc.hasKey(stringIDToTypeID("textKey"));
    if (hasText == true) {
    var textDesc = layerDesc.getObjectValue(stringIDToTypeID('textKey'));
    var paragraphStyle = textDesc.getList(stringIDToTypeID('paragraphStyleRange'));
    var kernRange = textDesc.getList(stringIDToTypeID('kerningRange'));
    var rangeList = textDesc.getList(stringIDToTypeID('textStyleRange'));
    for (var o = 0; o < rangeList.count; o++) {
    var styleDesc = rangeList.getObjectValue(o).getObjectValue(stringIDToTypeID('textStyle'));
    var aFont = styleDesc.getString(stringIDToTypeID('fontPostScriptName'));
    // add to array;
    var theCheck = true;
    for (var n = 0; n < theFonts.length; n++) {
    if (theFonts[n] == aFont) {theCheck = false}
    if (theCheck  == true) {theFonts.push(aFont)}
    catch (e) {};
    return theFonts
    ////// get some stuff from the active layer //////
    function getActiveLayerIIndex () {
    var ref = new ActionReference();
    ref.putEnumerated( charIDToTypeID("Lyr "), charIDToTypeID("Ordn"), charIDToTypeID("Trgt") );
    var layerDesc = executeActionGet(ref);
    var theIndex = layerDesc.getInteger(stringIDToTypeID("itemIndex"));
    var theSection = typeIDToStringID(layerDesc.getEnumerationValue(stringIDToTypeID("layerSection")));
    var hasText = layerDesc.hasKey(stringIDToTypeID("textKey"));
    return [theIndex, theSection, hasText]

  • How do I make a loader image similar to those shown at program opening?

    I'm looking to build a loader image, that opens up at the start of my script, and automatically closes after a few seconds. I opened up the image processor script to see how Adobe has added images to alerts, but it's an extensive doc, and I couldn't tell where the image was being pulled from, as the variable only shows up twice, and is only called, and not set. Also is there another method other than alert to call a box like this? I would prefer it have no buttons.

    I was able to boil your script down, to what I need. Works great in extendscript, but for some reason, only shows a portion of the image in photoshop and illustrator. This was happening even before i boiled it down. Thoughts? The last thing I'm trying to do with it, is figure out if I can set a transparent background for the window. I also tried using backgroundColor, but was unable to set the attribute correctly... there is a lot to learn with Adobe scripting. I also couldn't find reference to what DELTA_H is, I have a bunch of their PDFs, and googled, but couldn't find reference to this. I'm trying to be resourceful so I don't have to ask such remedial questions.
    Here's the revised script, and a link to the image I labelled test on my desktop: http://img2.wikia.nocookie.net/__cb20110725041802/logopedia/images/8/89/Logo_rolling_stone s.png
    PreviewWindow = function() {
    w = 285;
    h = 313;
    PreviewWindow.DELTA_H = 1;
    PreviewWindow.open = function(file, w, h, title, ms) {
      PreviewWindow.openFile(file, w, h, title, ms);
    PreviewWindow.openFile = function(file, w, h, title, ms) {
      var type = (ms > 0) ? 'palette' : 'dialog';
      var win = new Window(type, title || "Preview: " + decodeURI(file.name),undefined,{borderless : true});
      win.preview = win.add('image', undefined);
      win.preview.icon = file;
      win.show();
      if (ms > 0) {
        $.sleep(ms);
      delete win;
      $.gc();
      PreviewWindow.open("~/Desktop/test.png", undefined, undefined,
                         "Preview Test", 500);

  • Why can't I see the ruler even though it's selected?

    I hate asking what seems to be such a remedial question, but having recently switched from cs4 to cc2014 I'm difficulties with many of the changes. The latest is why I can't see the ruler or guides? No they are not greyed out choices from the view menu, and yes they are "checked". This has got to be something very simple, but with great frustration I can't figure it out. and in case it matters, I'm working from Windows 7.

    Rulers  (Ctrl+Alt+R) are a Design View option. Turn off Live View. See screenshot.
    Nancy O.

  • Save/Save As Confusion

    I am a newbie to PSE6 for the Mac & have a very remedial question. Please bear with me.
    I store & organize my images in iPhoto '09 and want to edit them in PSE. If I edit a JPEG & click the Save icon, the edited image seems to return to its original location in iPhoto. That's fine. However, if I want to save the edited image as a TIFF, I select Save As & choose TIFF format. But it does not seem like I have the choice to save the edited image back in its original location in iPhoto. Is that correct?
    Basic question: How can I change the file format of an image in PSE & then save it in its original location in iPhoto?
    Thanks for your patience.

    To have images saved as a version, you cannot change either the name or the format. If you do so, you must import the changed photo as a new one.

  • Lock a marker so it doesn't move w/ tempo change?

    Hi, and sorry if this is a remedial question but I'm wondering how to make a marker in the marker bar that won't move when I change tempo. I'm basically scoring a piece to picture, and I want to make markers for when certain things happen in the video, then play with tempo so that I can move my midi around to try and fit events to the picture events. If my markers move every time I change tempos it's useless! Thanks in advance for any help.
    Matt

    I think you can go to the marker list and lock the smpte position.
    I think.... Haven't done it in quite a while.
    Hang on, I'll boot Logic semiPro again, coz it just crashed on me again...
    (while we're waiting, hey wouldn't it be cool if Apple offered tech support for their 'professional' software? dum dee dum dee dum.. yeah it would. Oh, we're ready. Back to business)
    Okay, create some markers.
    Open up a "marker list" (in your 'list view').
    Make sure the marker positions are displayed in SMPTE numbers
    Then select the marker in the list you want to lock, and choose "Lock SMPTE" in the edit menu. Or use your "Lock SMPTE" key command. Mine is Control L, with Shift-Control L for unlock)
    Yer done!

Maybe you are looking for

  • Print Grid View

    I have 300+ movies in iTunes and would like to print a catalog of the artwork/titles exactly how Grid View displays it in iTunes. I know I can print an album list using the print menu, but that would take way too much paper. I can't seem to find any

  • Where can i get a press release picture for macbook 4.1

    Hi there, I'm writing for a Swedish Computer Magazine. I'm currently writing an article on how to improve performance on an aging Macbook 4.1. I've been trying to get ahold of someone at Apple who can provide me with some press images of a MacBook 4.

  • MySQL variables

    I want to write a MySQL query that selects a database table based on a variable. Lets say I have three tables: 'game_data', 'image_data', and 'video_data'. I would make a variable called 'submission_type' which gets its value from the browser variabl

  • Photoshop elements for Mac (snow leopard)

    Hi all. I recently upgraded my computer to a MacBook Pro running Snow Leopard. Previously i had a windows running acer. Just before my acer crashed i bought Adobe Photoshop Elements 7. Unfortunately this is not compatible with my Mac. I was wondering

  • Copy from through code

    Hi, I want to do the copy from functionality from Goods receipt PO   to Purchase through code in my Addon.Can we assign  a link between these two documents?How will we copy multiple goods receipt PO to one purchase Invoice.?I have no provision to add