This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Security Analyses

Many vendors (including Sophos) stopped publishing detailed information for a majority of the threats - understandably so. Much work and what would you need it for? To second-guess the scanner's results? The beast should have been found in time and blocked anyway so what's the use describing what could have happened if ...?

But in some areas the information is - for my taste - too sparse. Troj/FakeAle-NB has been blocked on a client, SEC is telling me (no more details, i.e. a path to a file, given). FakeAle sounds more like joke but the analysis offers no more insight. We do no have access to most of the clients (such is life at the university). Now the policy says: automatically clean up  and otherwise deny access. First question is: why is a particular threat cleanable or why not. Second: if cleanable - why hasn't it been cleaned up (I know, sometimes a full scan is required - but sometimes it's in the analysis and sometimes not). Choosing Cleanup (if available) on Resolve alerts and errors ... most of the time results in timed out. More often than not the person you talk to has not very much knowledge and telling her where to look and what to look for is a feat. And directing them to Remove Trojans is not feasible solution.

Same problem with malware and suspiscious files. Cleaning with SEC is out of the question without more detailed information. Asking to user to send a sample ... see above (see also ).

Christian

:249


This thread was automatically locked due to age.
Parents

  • QC wrote:

    .......... Guess this is the point where I should contact support ...

    They just need deleting - would they be listed as cleanable and can this be done using SEC/Cleanup? Oh - by the way, which settings for "Cleanup" does the immediate "Full system scan ..." (from SEC) use?

    If cleanable - why hasn't it been cleaned up ... apart from timeouts I've only encountered "no longer in the quarantine list". As said, we don't have admin rights on most clients and we can't access the logs. Usually the status changes within seconds (except of course for timeout) - either the alert is cleared or the no longer appears.

    Christian


    Hi Christian,

    For this particular Trojan, you don't need to contact Support, I checked into it for you with SophosLabs - this is a php script trojan. It injects it's own (polymorphic) code into a popular blog application's PHP files. If we removed the infected files, you would lose the php files and break the application. If we tried to remove the code, we could cause damage to legit php script (as we have no way to know where the viral code starts / ends).

    As a result, the only *real* solution is to delete and replace with a known good copy of the infected files. I'd argue that this is a situation where cleanup isn't appropriate for the file, and if we outright deleted it as part of your automatic configuration, you'd be left with no files and no real awareness that we just broke your applications :smileysad:

    No longer in the quarantine list is usually encountered when you have an alert on a file, but when you come to take action, the file is gone. A good example would be a file in your temporary internet files - we block it at time of execution, but by the time you are able to try Cleanup or run a Delete scan, the file has been purged by IE itself. Our Quarantine Manager obviously has no way to know the file is already removed - you can simply clear the alert at this stage (and run a quick scan across the drive to confirm it's clear).

    The immediate "Full System Scan" in Enterprise Console runs with default options - no cleanup, no delete. It is intended to pass over the drive, report problems and let you take care of them as appropriate.

    Hope this helps!

    :284
Reply

  • QC wrote:

    .......... Guess this is the point where I should contact support ...

    They just need deleting - would they be listed as cleanable and can this be done using SEC/Cleanup? Oh - by the way, which settings for "Cleanup" does the immediate "Full system scan ..." (from SEC) use?

    If cleanable - why hasn't it been cleaned up ... apart from timeouts I've only encountered "no longer in the quarantine list". As said, we don't have admin rights on most clients and we can't access the logs. Usually the status changes within seconds (except of course for timeout) - either the alert is cleared or the no longer appears.

    Christian


    Hi Christian,

    For this particular Trojan, you don't need to contact Support, I checked into it for you with SophosLabs - this is a php script trojan. It injects it's own (polymorphic) code into a popular blog application's PHP files. If we removed the infected files, you would lose the php files and break the application. If we tried to remove the code, we could cause damage to legit php script (as we have no way to know where the viral code starts / ends).

    As a result, the only *real* solution is to delete and replace with a known good copy of the infected files. I'd argue that this is a situation where cleanup isn't appropriate for the file, and if we outright deleted it as part of your automatic configuration, you'd be left with no files and no real awareness that we just broke your applications :smileysad:

    No longer in the quarantine list is usually encountered when you have an alert on a file, but when you come to take action, the file is gone. A good example would be a file in your temporary internet files - we block it at time of execution, but by the time you are able to try Cleanup or run a Delete scan, the file has been purged by IE itself. Our Quarantine Manager obviously has no way to know the file is already removed - you can simply clear the alert at this stage (and run a quick scan across the drive to confirm it's clear).

    The immediate "Full System Scan" in Enterprise Console runs with default options - no cleanup, no delete. It is intended to pass over the drive, report problems and let you take care of them as appropriate.

    Hope this helps!

    :284
Children
No Data