Hi.
I need help with fixing an issue with Sophos AV server Free.
Issue: We have a KVM server with one website into it. On 24th August 2018 the email clients were suddenly not able to login into the email server. Seems like this happened after a Wordpress or a Sophos upgrade.
Our hosting company found out Sophos AV was blocking access to the email server. They could not find the reason and they had to disable Sophos in the server. Meanwhile, I received around 5,000 (five thousand) warning emails from Sophos AV, telling me that a file was infected: "The antivirus is detecting an infected file A threat classified as 'Mal/Generic-S' was detected in the file '/usr/lib64/libtsr.so' when attempting to open it at Fri Aug 24 16:34:00 2018 EDT -0900 (2018-08-24 20:34:00 UTC). Access to the infected file was not allowed."
Seems like this libtsr.so file belongs to Sophos AV or so has told me the hosting company. I had immediatly deleted this offending file through SSH but then the hosting company could not uninstall Sophos. They restored the file into the server and uninstalled Sophos AV Free. The offending file libtsr.so was uninstalled too.
Solution: All in all the issue was solved. We had some work to delete the 5,000 emails received from Sophos AV. But I want to use Sophos AV in my server as it is better than CLAMAV. However, I need first to be sure about why the issue happened and make sure it will not happen again.
Question: anybody can help me find out why the file libtsr.so was getting flagged by Sophos itself as an infected file. is this really a Sophos file? Was it really infected or this could be a false flagging/bug? I wonder if this issue was reported by other and is already fixed?
Any advice is welcome.
Rgs.
IM
This thread was automatically locked due to age.