This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Virus Removal Tool - Config.xml

Hi,

I am trying to find information on the settings that are possible within Config.xml, in particular if there is any way of configuring the location of the log file.

 

Thanks



This thread was automatically locked due to age.
  • Hello Andrew Kent,

    there's no documentation AFAIK (I'm not Sophos), from the information contained within it's apparently not supposed to be modified by the user.
    Just curious - what's wrong with the standard location?

    Christian

  • Hi Christian,

    Thanks for your response, I did do a fair bit of internet searching, and even tried experimentation before deciding to post and so I was hoping that there might be someone else that had already been down the same path and had been successful.

    The background to this is that I have previously been using the command line tool SAV32CLI. No updates for this tool have been released for some time now, but thankfully the tool has continued to work with all of IDE's that have been released, until recently when it has stopped working with all of the latest IDE's. As a result of this I have been looking at alternatives. one of the benefits of using SAV32CLI was that it was similar to a portable app in that it didn't leave anything behind after the scan had been completed and l was hoping that SVRT would be similar or could at least be configured to be so.

  • Hello Andrew Kent,

    how do you get hold of all of the latest IDE's? And what exactly is stopped working?

    Christian

  • Hi Christian,

    Hopefully this isn't off topic for this forum, but the IDE's are downloaded from Sophos into a local folder \\Server\SophosUpdate\CIDs\S000\SAVSCFXP\savxp

    The systems we are scanning are not connected to the network which includes this server and so we then copy the IDE files manually to the folder structure containing SAV32CLI.

    When we run SAV32CLI the latest IDE's all produce the message:-

    Data File status    : Not Loaded

    I was assuming that this would indicate that they were in some way incompatible with the SAV32CLI tool.

    Andrew

     

  • Hello Andrew,

    not off-topic but you should better move this thread to the Endpoint group (you'd have to join the group first).

    So you have an Endpoint license and want to run a scan occasionally (but don't want to install the full product)? Which version of sav32cli are you using (sav32cli.exe -v, redirect the output to a file)?

    Christian

  • Hi Christian,

    We are scanning machines which are not connected to our main network in the hope of making sure that they are clean.

    The version of SAV32CLI.EXE we are using is dated 07/06/2016, when we run it with the -v switch we get the following output:-

    Sophos Anti-Virus
    Copyright (c) 1989-2015 Sophos Plc. All rights reserved.

    System time 13:00:59, System date 09 March 2017

    Product version           : 1.01.1
    Engine version            : 3.55.0
    Virus data version        : 5.10
    User interface version    : 2.99.000
    Platform                  : Win32/Intel
    Released                  : 06 January 2015
    Total viruses (with IDEs) : 8477637

    Thanks Again

    Andrew

  • Hello Andrew,

    are you aware that the latest sav32cli.exe is placed in the endpoint's %ProgramFiles(x86)%\Sophos\Sophos Anti-Virus\ folder?

    System time 13:05:00, System date 09 March 2017
     

    Product version           : 1.01.1
    Engine version            : 3.68.0
    Virus data version        : 5.37
    User interface version    : 2.99.004
    Platform                  : Win32/Intel
    Released                  : 07 March 2017
    Total viruses (with IDEs) : 12928138

    This one's supposed to work.

    making sure that they are clean
    Is it for licensing reasons that you don't protect these machines (as you obviously fear they might contract a something)?

    Christian

  • Hi Christian,

    Firstly I am glad to hear that sav32cli.exe has been updated.

    The server that receives the Sophos updates has an x86 version of Windows and so we are taking the sav32cli.exe file from the folder  %ProgramFiles%\Sophos\Sophos Anti-Virus\.

    We have tried running an update on the server but although this seems to behave normally it doesn't result in the file sav32cli.exe being updated.

    Do you know how we might trigger an update that will result in the file sav32cli.exe being updated?

    The systems we are scanning are being scanned when they are not connected to the network so that we can establish whether they have already contracted something with zero risk of this spreading to the machines that are connected to the network.

    Thanks again

    Andrew

     

  • Hello Andrew,

    what else besides sav32cli.exe are you taking to the off-net systems?

    As for off-net systems: We have some as well, they have the full product installed (and On-Access is running) and they are regularly updated with a removable medium.

    Christian 

  •  Hi Christian,

    The files we are taking to the off-net systems are those specified in the SAV32CLI release notes and so in addition to the IDE and VDB files we have:-

    SAVI.DLL

    OSDP.DLL

    VEEX.DLL 

    VDL.DAT

    As specified in the release notes these are in the same directory as the executable itself.

    I will now check to see whether there are newer versions of these files on the server.

    Thanks

    Andrew