This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Malware 'Unscannable' was detected

Hi all,

I have this alert today on FW Sophos in Log Viewer \Malware ( look at picture), every ~1 min

What does it mean and how to resolve this or stop it

Thanks to all



This thread was automatically locked due to age.
  • Do you use Kaspersky? 

    __________________________________________________________________________________________________________________

  • Yes i have kaspersky server on the LAN

    the address  (.5) is that of the server, but there are also clients lan addresses

    the current version of sophos AV is 1.0.17980, status is "failed" and i can't upgrade sophos AV module, it still "failed" after downloading time ,when updating pattern.

    these are all urls:

    Malware 'Unscannable' was detected and blocked in a download from:

    www.msftncsi.com
    crl.kaspersky.com
    crl4.digicert.com
    crl3.digicert.com
    crls.pki.goog
    crl.comodoca.com
    crl.verisign.com
    edgedl.me.gvt1.com
    crl.geotrust.com

    these websites are categorized as Information Technology

    What to do please , and why i get this alert only today

  • Check you pattern updates. Maybe your Avira or Sophos Update are corrupt. You should see it in Firmware - Pattern Update. 

    __________________________________________________________________________________________________________________

  • Hi Lucas,

    I think there is a problem at the Sophos end. My XG shows last updates for both Sophos and Avira AV as being on the 6th of August and the IPS on the 4th August. Current time and date is 8th August 0825.

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Why should this be a problem? Old pattern does not mean failed updates? 

    __________________________________________________________________________________________________________________

  • But, what it could mean is the last updates were corrupt and not allowing new updates to be installed, thereby causing the issue reported by the thread originator. My AVs have not updated yet, 1700.

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • If it is successful, it was successful. A pattern update does not need to be there every hour. SAVI and Avira works with families. Otherwise the pattern would have to contain millions of entries per day. You can check the /log/u2d.log to see the progress of the update.

    Likely the update broke on this installation for some reason and is in the failed status.

    If this would be a general issue, there would be more users reporting a broken HTTP update. 

    __________________________________________________________________________________________________________________

  • On a side-note, LuCar, what is "Unscannable" in general? I've occasionally gotten it I think for images in a web page or something like that -- in fact it's almost the only actual thing I've seen.

  • Unscannable in a nutshell is a encrypted and/or corrupt  format of a file. 

    The file itself could be corrupt. The file can be encrypted.

    Or the engine could be broken and gives the firewall only "Unscanable" results back. 

    __________________________________________________________________________________________________________________