CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer
image AVP: Sophos Antivirus flags CCleaner as malware image
Cyber Security
Ian-OG writes "Since the Sophos IDE (virus definition file) updates of July 11, all PCs running Sophos AV and the CCleaner cache/Registry cleaning tool have flagged the application as Mal-VB/K.

A technical support query has been raised with Sophos to verify that this is a false-positive.

Since the Sophos IDE (virus definition file) updates of July 11, all PCs running Sophos AV and the CCleaner cache/Registry cleaning tool have flagged the application as Mal-VB/K.

Since Sophos is an enterprise-level AV, and unlikely to be installed by individuals (Sophos do not sell single-user licenses, the smallest quantity is a 5-license Small Business product), this may not affect most of the CastleCops members. However, Sophos key markets include education and government, so anyone with overview/network management responsibility of those areas may begin to see this virus in daily or weekly reports from their workstations!

Here is the initial threat analysis from Sophos on the ccleaner.exe file, based on the locally-loaded IDE:
---------------
Name: Mal/VB-K
Type:
Malicious Behavior

Affected operating systems:
Windows

Side effects:
Downloads code from the internet
Installs itself in the Registry

Protection:
Download virus identity (IDE) file

Protection available since 11 July 2007 19:53:56 (GMT)
Detected by:
All versions of Sophos Anti-Virus
---------------

Sophos also flags up the Registry entry that runs CCleaner on Windows startup, if enabled by the user.

A technical support query has been raised with Sophos to verify that this is a false-positive. "
Posted on Friday, 13 July 2007 @ 13:12:54 UTC by Paul (2062 reads)
[ Trackback ]
image

"AVP: Sophos Antivirus flags CCleaner as malware" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· Microsoft
· HotScripts
· W3 Consortium
· More about Cyber Security
· News by Paul


Most read story about Cyber Security:
Booby Trapped software!

block bottom
Article Rating
spacer
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer