SOPHOS found...

SOPHOS found...

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
SOPHOS found... Marek Kalisz 09-27-2006
Posted by Marek Kalisz on September 27, 2006, 6:01 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I did check with Sophos Anti-Root in both, Safe and Normal modes. It
pointed 3 suspicious objects:

\System Volume Information\Catalog\CiFLffd.000
\System Volume Information\Catalog\CiFLffd.001
\System Volume Information\Catalog\CiFLffd.002

It suggested, however, to not to remove those. Is Sophos correct? What
hose objects might be? Is this safe to leave them alone?
Marek Kalisz



Posted by David H. Lipman on September 27, 2006, 6:43 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| I did check with Sophos Anti-Root in both, Safe and Normal modes. It
| pointed 3 suspicious objects:
|
| \System Volume Information\Catalog\CiFLffd.000
| \System Volume Information\Catalog\CiFLffd.001
| \System Volume Information\Catalog\CiFLffd.002
|
| It suggested, however, to not to remove those. Is Sophos correct? What
| hose objects might be? Is this safe to leave them alone?
| Marek Kalisz
|

Ask Sophos.
You really shouldn't be using an Anti-RootKit utility if you don't understand
what they
report.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by Marek Kalisz on September 27, 2006, 9:37 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
As I remember, in your Multi-AV that you so often promoting here you
suggested as the first option Sophos. So, I tried it (without involving
whole Multi-AV. Second, instruction in Sophos is clear enough - no mark, no
suggested deleting. However, computers still can't (fortunately) replace
human brains and no program can do everything automatically. So, I was
hoping that someone, more knowledgeably with the deeps of Windows can give
me some idea what those items in System Volume Information are and what
their meaning/function might be.
Just this.
Besides - Sophos support is only for their customers. I used its free tool
(part of YOUR "Multi") so - no Sophos support available.
Marek Kalisz
PS. I understand. Often I have a bad day too...
>
> | I did check with Sophos Anti-Root in both, Safe and Normal modes. It
> | pointed 3 suspicious objects:
> |
> | \System Volume Information\Catalog\CiFLffd.000
> | \System Volume Information\Catalog\CiFLffd.001
> | \System Volume Information\Catalog\CiFLffd.002
> |
> | It suggested, however, to not to remove those. Is Sophos correct? What
> | hose objects might be? Is this safe to leave them alone?
> | Marek Kalisz
> |
>
> Ask Sophos.
> You really shouldn't be using an Anti-RootKit utility if you don't
> understand what they
> report.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>



Posted by David H. Lipman on September 27, 2006, 9:56 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| As I remember, in your Multi-AV that you so often promoting here you
| suggested as the first option Sophos. So, I tried it (without involving
| whole Multi-AV. Second, instruction in Sophos is clear enough - no mark, no
| suggested deleting. However, computers still can't (fortunately) replace
| human brains and no program can do everything automatically. So, I was
| hoping that someone, more knowledgeably with the deeps of Windows can give
| me some idea what those items in System Volume Information are and what
| their meaning/function might be.
| Just this.
| Besides - Sophos support is only for their customers. I used its free tool
| (part of YOUR "Multi") so - no Sophos support available.
| Marek Kalisz
| PS. I understand. Often I have a bad day too...


The Sophos Command Line Scanner uses Signature and Heuristics detection to find
and remove
infected files.

Anti-RootKit utilities look through known areas of system and Registry for
Rooted types of
Trojan infection vectors and list them as possibilities. It takes a
knowledgeable
interpretation to understand the results of such utilities. They are NOT for
novices.

Please do NOT equate the Sophos anti-RootKit utility with the Sophos command
line scanner.
They are as different as night and day.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by Marek Kalisz on September 27, 2006, 10:57 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Thanks for explanation. On the side - both: GUI and command line (which I
tried too) in a Safe Mode are limited (in my trials, at least). They can't
do the first step (I don't remember - check memory or something else). They
work in full in Normal Mode, however.
Marek Kalisz

>
> | As I remember, in your Multi-AV that you so often promoting here you
> | suggested as the first option Sophos. So, I tried it (without involving
> | whole Multi-AV. Second, instruction in Sophos is clear enough - no
> mark, no
> | suggested deleting. However, computers still can't (fortunately)
> replace
> | human brains and no program can do everything automatically. So, I was
> | hoping that someone, more knowledgeably with the deeps of Windows can
> give
> | me some idea what those items in System Volume Information are and what
> | their meaning/function might be.
> | Just this.
> | Besides - Sophos support is only for their customers. I used its free
> tool
> | (part of YOUR "Multi") so - no Sophos support available.
> | Marek Kalisz
> | PS. I understand. Often I have a bad day too...
>
>
> The Sophos Command Line Scanner uses Signature and Heuristics detection to
> find and remove
> infected files.
>
> Anti-RootKit utilities look through known areas of system and Registry for
> Rooted types of
> Trojan infection vectors and list them as possibilities. It takes a
> knowledgeable
> interpretation to understand the results of such utilities. They are NOT
> for novices.
>
> Please do NOT equate the Sophos anti-RootKit utility with the Sophos
> command line scanner.
> They are as different as night and day.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>



Similar ThreadsPosted
Sophos Antivirus- "could not contact server" March 4, 2008, 2:42 am
New Sophos facial recognition technology - RAPIL April 1, 2008, 3:52 pm
I think I've found a virus.... September 7, 2007, 3:35 pm
virus found April 6, 2008, 5:34 pm
vius found on computer February 15, 2007, 10:55 am
Adaware critical object found May 17, 2006, 8:07 am
RE: Adaware critical object found May 17, 2006, 11:19 pm
Virus found: IRC/Backdoor.flood February 5, 2007, 7:10 pm
Infection found: Win32/Parasitic-gen February 5, 2007, 7:23 pm
Trojan DND Changer not found by ONECARE February 17, 2007, 6:19 am

The site map in XML format XML site map

Contact Us | Privacy Policy