Thursday, November 12, 2009

What is 'Infection source'?


You can see this from your OfficeScan virus logs.

You may not have the Infection Source if the infection is of trojan, generic malware or backdoor. Most cases in worm typically network worm you will have Infection Source information. Some virus detection doesn't have Infection Source if the infection is local meaning it is not coming from a remote computer. Also, it doesn't require scanning of mapped drives to check or detect infection source since the detection of infection source is based on the NET SESSION on the local computer.


For example, if User A accesses a virus infected share on User B's machine, User B will become listed in the Infected Sources list.

If there are no sources on the private network sharing malware, then nothing will be shown.

No comments: