<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Malicious Traffic Detection</title><link>https://community.sophos.com/on-premise-endpoint/f/sophos-endpoint-software/76910/malicious-traffic-detection</link><description>I followed these directions&amp;hellip;.. www.sophos.com/.../121665.aspx and was told the detected components of the virus/spyware is &amp;quot;wscript.exe&amp;quot;. Why doesn&amp;rsquo;t it tell me the problem is with &amp;ldquo;mtd.vbs&amp;rdquo; ?</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Malicious Traffic Detection</title><link>https://community.sophos.com/thread/295521?ContentTypeID=1</link><pubDate>Wed, 04 May 2016 09:55:43 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:799300d5-4573-4dc8-812b-f76b70ee3da9</guid><dc:creator>CraigJones</dc:creator><description>&lt;p&gt;Ok, that&amp;#39;s &amp;nbsp;disappointing - &amp;nbsp;PM me your case no, I&amp;#39;ll follow it up with the engineer who dealt with it.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Malicious Traffic Detection</title><link>https://community.sophos.com/thread/295517?ContentTypeID=1</link><pubDate>Wed, 04 May 2016 09:48:58 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:620d4058-a15f-4dd0-93f5-0f59965e6da8</guid><dc:creator>DavidL</dc:creator><description>&lt;p&gt;Thanks.... I asked that question to &lt;a href="mailto:support@sophos.com"&gt;support@sophos.com&lt;/a&gt;.&amp;nbsp;&amp;nbsp; 2 weeks and a few Emails later, no answer. They even asked me to send them a sample.....&amp;nbsp; I should probably come here more often.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Malicious Traffic Detection</title><link>https://community.sophos.com/thread/295514?ContentTypeID=1</link><pubDate>Wed, 04 May 2016 09:45:24 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:cf6279d6-693a-4c69-b0bd-8f5f6b6588b8</guid><dc:creator>CraigJones</dc:creator><description>&lt;p&gt;It&amp;#39;s because mtd.vbs uses wscript.exe (Windows-Based Script Host)&amp;nbsp;to execute, this means the actual running application is wscript.exe and the detection quite rightly is against this. In a real world scenario the detection would be against an actual piece of Malware rather than a vbs script.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Hope this helps.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Craig&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>