Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Bug? Sophos XG does not block EICAR file in realtime since last update

FormerMember
FormerMember

Hi,

 

since last update, Sophos XG does not block EICAR files in real-time scan mode anymore!

The file is downloaded without scanning!

In Batch mode the file is blocked as before!

 

Regards Meghan



This thread was automatically locked due to age.
Parents
  • Meghan,

    check your settings and try to switch from batch to real again. On my XG is working with no issue.

  • FormerMember
    0 FormerMember in reply to lferrara

    Hi,

    ..

    I've tried a few times now, but the download isn't blocked by XG, and my Endpoint security doesn't detects the eicar.com/.zip files as virus ...

    Does XG remove the malicious Code from the file?

     

    Regards Meghan

  • Yep, I've had this concern as well, as it was one of the first things I tried to "verify" my XG was working and I was very alarmed to see that I could download it.  However I do note that in the Malware Log, it is detected by XG as "EICAR-AV-Test" so I assume it is allowing it through so you can test your AV solution?  I have no idea, it has been that way since day one for me, not something new with the latest firmware.

Reply
  • Yep, I've had this concern as well, as it was one of the first things I tried to "verify" my XG was working and I was very alarmed to see that I could download it.  However I do note that in the Malware Log, it is detected by XG as "EICAR-AV-Test" so I assume it is allowing it through so you can test your AV solution?  I have no idea, it has been that way since day one for me, not something new with the latest firmware.

Children