This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Virus/Spyware 'Troj/Badsrc-M' detected \\.\GLOBALROOT\Device\HarddiskVolumeShadowCopy62\pagefile.sys | false positve?E

Hello,

one of endpoint seems to be infected with Virus/Spyware 'Troj/Badsrc-M

from the logs in german:
20180111 220124 Virus/Spyware 'Troj/Badsrc-M' wurde erkannt in "\\.\GLOBALROOT\Device\HarddiskVolumeShadowCopy62\pagefile.sys". Bereinigung steht nicht zur Verfügung.
20180111 220124 On-Access-Scanner hat den Zugriff auf den Speicherort "\\.\GLOBALROOT\Device\HarddiskVolumeShadowCopy62\pagefile.sys" für folgenden Benutzer verweigert: NT-AUTORITÄT\SYSTEM

Client OS = Windows Server 2016 (a virtual machine)
Sophos Endpoint Security and Control 11.0.13 UTM
Latest Update: today 20min ago

Is this false positive or should I be concerned?

Kind regards,
Roland



This thread was automatically locked due to age.