• Application with "conf.json" blocked without events

    Thomas_LSW
    Thomas_LSW
    Hi, I have a Application with unc path "\\server-01\test$\xyz.exe". The shortcut of the application is in the same folder with "conf.json" in it. Sophos Central blocked this program without any events! Can anybody help ? best regards, Tho…
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • A lot of WMV files deleted since last weeks for unknow reason

    Sophos User3113
    Sophos User3113
    Hello, since last week, for unknown reason our Sophos Endpoint delete all WMV files on computers. This is the event : Malware detected: 'W32/GetCodec-A' at 'XXX\Intro discours.wmv' Any idea why it's happen now?? I already created a ticket to…
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Malicious Behaviour (PrivGuard) detected

    Ingo Buyny
    Ingo Buyny
    Hello, i use gsudo.exe with Windows Terminal to start CMD or Powershell with administrative rights but since i use Sophos Endpoint it shuts down the Terminal app every time the gsudo process opens a new tab. The Error message is "Malicious Behaviour…
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • CXmal/WebAgnt-A continuously intercepted by Sophos on Exchange Server - Have I been hacked?

    Matteo Vinti
    Matteo Vinti
    Hi, I have an Exchange server 2019 wich have not been correctly patched since one month ago; it had Sophos Advanced Endopoint installed allready + Sophos Firewall Intercept X in front (protected by WAF - no DNAT) I started questioning my self as soon…
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Sophos Data Control - Data Loss Prevention Policy

    Nicholas Pelczar
    Nicholas Pelczar
    We are a SEC shop but making the transition to the Sophos Cloud. We have used the data control policies in SEC for years to monitor local activity on individual machines. Unfortunately the same rules and policies on SEC fail to allow Outlook to open in…
    • over 2 years ago
    • Sophos Central
    • Discussions
  • Sophos Intercept X identified fsquirt.exe as ransomware and then all traces of the alert are gone?

    Mark Andrich
    Mark Andrich
    We received a high alert on one of our workstations. The user was transferring files from their phone via Bluetooth. CryptoGuard detected ransomware in C:\Windows\System32\fsquirt.exe We ran a scan and it came up clean. There's nothing in the…
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Exchange Server 2016 failing to start after installation of Intercept X for Server

    Jelko Seiboth
    Jelko Seiboth
    Hello, a customer's Exchange 2016 Server (installed on Windows Server 2016) was previously running Sophos Endpoint Protection Standard. Having set the Antivirus exclusions according to the list published by Microsoft, it was running fine. After…
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Sophos Central server protection: real time scanning

    Stefano Colelli
    Stefano Colelli
    Hello, we are evaluating sophos as av for our servers: what is not understand is there any real-time scanning for linux? is that a feature only for windows system? uploading a virus test file (eicar.com) is undetected until a scan; is that how is supposed…
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Sophos interfering with NodeJS processes on Mac OSX Big Sur

    FormerMember
    FormerMember
    Ever since I upgraded to Big Sur, I've noticed that Sophos has begun to interfere dramatically whenever I run Jest tests. CPU usage for Sophos spikes to around 400% when running even a modest Jest test program, with 71 tests currently taking 98.6 seconds…
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Troj/JenxLnk-B

    adithya turaga
    adithya turaga
    Hi guys , I recently inserted a usb stick in my computer and Sophos immidiately recognized it as a virus and it said it cleaned it , my paranoia got to me and I did a full scan and it said my PC was clean , but later on the internet I was going through…
    • over 2 years ago
    • Sophos Central
    • Discussions
<