Hi,
It looks like WinZip includes an executable called wzwipe.exe. We still have this installed on several PCs in our environment and occasionally Intercept is identifying this as ransomware. Ours shows up as a known good hash of when I look it up on a site like this one or VirusTotal so I'm wondering if there's a way for Sophos to match its hash before declaring it malicious...?
Also, since I know you mostly hear about it when things are broken, I want to send a thank you out to everyone at Sophos collectively; this is a great product!
kind regards,
Gary
This thread was automatically locked due to age.