This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Mal/Generic-S alert on Sophos Enterprise Console

Hi there,

This is my first post :).

I would like to say hello to everyone, and thanks for any help in advance!

Anyway, I work in a school of around 700 computers. Slowly, 1 by 1, they are starting to show up in the Enterprise Console as having a Virus on them.

When I check, it is a Sophos update file (this seems to be much like the problem back in Sept 2012).

It is in the following location:

C:\System Volume Information\_restore{***random numbers/letters***}\RP310(***this changes as well***)\A0418322.exe (Again, the file name can change as well lol).

Anyway, I have looked at the file, and it is a Sophos file, presumably for the updates (quite new to Sophos, I used to use another product in my old job, only started here recently lol).

I was wondering what I can do to stop it being quarentined and showing up on the list? So far it has been qurentined on around 50 computers.

Is anyone else having the same problem?

I hope this all makes sense!!!

Looking forward to hearing some feedback :).

Phil

:36359


This thread was automatically locked due to age.
Parents
  • Hi Christian,

    I have done nothing to it so far. I didn't turn off anything. I just went to the file and looked at it, as you can see. I am able to copy and paste it as well...etc.

    I have not ran it of course, but it seems like I would be able to if I wanted.

    I will submit it though. I presume that the best thing might just be to "clean" the item as they come in? Sophos is catching them and putting them in quarentine.

    Regards,

    Phil

    :36371
Reply
  • Hi Christian,

    I have done nothing to it so far. I didn't turn off anything. I just went to the file and looked at it, as you can see. I am able to copy and paste it as well...etc.

    I have not ran it of course, but it seems like I would be able to if I wanted.

    I will submit it though. I presume that the best thing might just be to "clean" the item as they come in? Sophos is catching them and putting them in quarentine.

    Regards,

    Phil

    :36371
Children
No Data