Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

'Scan Local Drives' detects _zipped_ eicar.com long before eicar.com

At http://openforum.sophos.com/t5/Sophos-Anti-Virus-for-Mac-Home/Blue-Sophos-Shield-Black-Sophos-shield-question/m-p/455#M324


paul84 wrote:

… test your AV by visiting www.eicar.org. Here you can download a very small text file called eicar …


1. create a folder

2. disable on-access scanning

3. populate the folder with three test files:  

  • eicar.com
  • eicar_com.zip
  • eicarcom2.zip

5. use Time Machine, backup to a local volume, wait for the backup to complete

6. Scan Local Drives, do nothing more than log detections

Issue

Scan Local Drives (ongoing) detects the test signature: 

  • on the Time Machine volume, in the .zip files 
  • on the Time Machine volume, not in the .com file.
 

Comparison

 
7. create a custom scan, targeting the folder and its three files
 
8. scan
 
— the custom scan detects the signature in all three files. 
 
I'll post a follow-up after Scan Local Drives is complete. 
:1000813


This thread was automatically locked due to age.
Parents Reply Children
No Data