Hi
I keep getting regular Adware detection notifications from 2 of our workstations. Both were clean Windows 7 installations. The initial detections occurred during the initial sync of Google Drive. Everyday I perform clean ups on the affected workstations but then only a few hours later they are detected again. Even if I authorise the detection another similar temp file flags up again.
Computer name LT-LEWISSA
Computer description
Operating system Windows 7
Service pack Service Pack 1
Domain/workgroup SCHOOL
IP address
Sophos Anti-Virus version 10.3.15 VE3.63.0
HIPS rules 10.3.178.1
HIPS configuration 1.0.65.1
Detection data 5.25
On-access scanning Active
Anti-virus and HIPS policy
Last scheduled scan completed
Last message received from computer 17/03/2016 08:17:48
Up to date Not since 17/03/2016 01:27:44
Updating policy
Time installed package became available 15/03/2016 10:56:08
Time next package became available 17/03/2016 00:27:44
Primary update server \SophosUpdate\CIDs\S000\SAVSCFXP\
Secondary update server
Client firewall enabled
Client firewall policy
Client firewall version
Client firewall mode
Sophos NAC policy
Compliance Agent (NAC) version
Sophos NAC compliance assessment
Application control policy
Application control on-access scanning Inactive
Data control scanning status Inactive
Device control scanning status Active
Data control policy compliance
Device control policy compliance
Full disk encryption
Encrypted volumes
Unencrypted volumes
Full disk encryption policy
Encryption agent version
Hardware encryption
Power-on authentication enabled
Wake on LAN enabled
Tamper protection status Inactive
Tamper protection policy compliance
Patch assessment
Patch policy
Patch agent version
Web control status Inactive
Web control policy
Group \Unassigned
Outstanding alerts and errors
Items detected Date/time first detectedType Cleanup status Name Sub-type Details File version
17/03/2016 08:17:47 Adware or PUA Cleanable 4Share DownloaderOther C:\Users\REMOVED\AppData\Local\Temp\tmprssilj
History
Items detected Date/time Type Name Sub-type Details File version Action taken Username
17/03/2016 08:17:47 Adware or PUA 4Share DownloaderOther C:\Users\REMOVED\AppData\Local\Temp\tmprssilj Blocked SCHOOL\*******
16/03/2016 09:56:20 Adware or PUA 4Share DownloaderOther C:\Users\REMOVED\AppData\Local\Temp\tmptawc4b Removed from quarantine listNT AUTHORITY\SYSTEM
16/03/2016 09:21:24 Adware or PUA 4Share DownloaderOther C:\Users\REMOVED\AppData\Local\Temp\tmptawc4b Blocked SCHOOL\********
15/03/2016 15:28:53 Adware or PUA 4Share DownloaderOther C:\Users\REMOVED\AppData\Local\Temp\tmprqzrys Removed from quarantine listNT AUTHORITY\SYSTEM
15/03/2016 15:24:22 Adware or PUA 4Share DownloaderOther C:\Users\REMOVED\AppData\Local\Temp\tmprqzrys Blocked SCHOOL\*******
I haven't got the information from the second workstation however I do remember that the apparent detections were reported as 'SoftPulse' and they were again in AppData\Local\Temp
Our Sophos Enterprise Console product version is: 5.2.0.644
Our Sophos Endpoint Security and Control version is: 10.3
We are using Windows 7 Professional X64 SP1
Please can anybody help?
Kind Regards
Tom
This thread was automatically locked due to age.