This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

\\.\Globalroot infection

Sophos A.V. is reporting a Trojan at \\. \GLOBALROOT\Device\HarddiskVolumeShadowCopy7\Program Files\Sophos\PureMessageT\empxxxxx.
 As far as I am aware Shadow Copy has never been enabled on this machine and if I do a "vssadmin list shadows" the response is that no shadows exist.
Anyone know how I can access this file so that I can delete the infection?

:2168


This thread was automatically locked due to age.