This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Cannot remove a quarantined item - Troj/Backdr-DI

OS is Windows XP professional SP2. Sophos is Endpoint Security and Control, version 9. Application control and firewall not currently in use on the computer in question.

Quarantine contains an entry about virus/spyware Troj/Backdr-DI as D:\Documents and Settings\%user%\Start Menu\Programs\Startup\Updpxe32.exe (hidden), with available actions "No actions (manual cleanup required)".

Most of the usual right-click choices for 'details' field (view details, open location, select all) are greyed - and so unavailable.

If I manually navigate to the folder in question I can't find the offending program (neither in explorer nor in command box). Specifically, there is only 'desktop.ini' file to be seen in the folder in both cases.

Using Enterprise console before showed the threat as far as I recall as 'not cleanable'.

Search for 'manual cleanup required' on Sophos found nothing relevant (there was a thread supposing a problem about application controll and/or Sophos 7, which is neither applicable here, and both cases were old, and also not resolved)

Regards, Marjan T.

:5154


This thread was automatically locked due to age.
Parents
  • Hello Marjan,

    do you have the [more...] link under Details? If so, click it.

    If the file has the System attribute it is not visible by default. You might see it if you use dir /A:S from a command prompt or uncheck the Hide protected operating system files in Explorer. Has Sophos blocked running the file? See also the section about using SAV23CLI in Remove Trojans.

    Christian

    :5161
Reply
  • Hello Marjan,

    do you have the [more...] link under Details? If so, click it.

    If the file has the System attribute it is not visible by default. You might see it if you use dir /A:S from a command prompt or uncheck the Hide protected operating system files in Explorer. Has Sophos blocked running the file? See also the section about using SAV23CLI in Remove Trojans.

    Christian

    :5161
Children
No Data