This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Is Re-Occurring Virus Infection a Concern?

I've been noticing recurring evidence of a virus/spyware in the Sophos logs called Troj/MDrop-EJU.  Sophos is unable to clean, however it states that the infection was successfully blocked, however I see remnants of the virus behaviour continuing.  In this case, this virus creates link files on share drives, and I see computers that connect to those shares also pop up in Sophos logs as being blocked.

Should this be something of concern or is it enough to accept that Sophos is actively blocking this infection?  If it is being blocked successfully, why are there files still being create from the virus? Thanks all.

:51174


This thread was automatically locked due to age.
Parents
  • It sounds like you may have a variant that is not being fully detected by Sophos.  If you can track down what process is creating teh files (using some other tools), I'd submit a sample of the executable or service doing this to Sophos Labs.

    :51176

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

Reply
  • It sounds like you may have a variant that is not being fully detected by Sophos.  If you can track down what process is creating teh files (using some other tools), I'd submit a sample of the executable or service doing this to Sophos Labs.

    :51176

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

Children
No Data