Hello,
Today I have received a few alerts from our ePO. And I'm a bit confused because I'm seeing opposite information in different placed.
Backgroud: uder plugged in a USB drive and the autorun.inf was accessed. Common scenario.
But when I'm looking at the Even Log, I'm seeing something like this:
Event Description: file infected. Undetermined clean error, denied access and continued |
|
and below:
Description: xxx\Admin ran mcshield.exe, which tried to access L:\autorun.inf. The Trojan named Generic!atr was detected. The scanner took the following action: Allow access. |
|
I'm curious why do I see denied access in one place and allow access a few lines below it.
Kind regards,
Wojciech