CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer
image Sophos AV Technical Support clears CCleaner image
Anti-Virus
Ian-OG writes "Following the recent IDE updates that flagged the CCleaner system optimization application as malware, Sophos have now confirmed that this application is safe...

...though they have stopped short of saying that the initial detection was down to a false-positive created by the recent IDE updates.

Instead, the ccleaner.exe file is said to exhibit activity or features common to known malware, which includes downloading files from the Internet (in this case they would be the updates that are occasionally released), plus that it modifies the Registry (the run-on-startup entry, for example).

It remains to be seen if a future IDE update will correct the initial analysis of CCleaner. Until that happens, Sophos quarantines both the ccleaner.exe file and the Run-on-startup Registry entry.

Users must either authorize the program locally (if permitted by their administrators - the local SAV console can be restricted for non-admin users), or wait for/persuade their Network Managers to authorize CCleaner via the Enterprise Console (see Sophos article 25227.html for details). Once these instructions are followed, the application will run once more, although it will still show in the Quarantine list until manually removed.

============================
Thank you for contacting Sophos.

The sample e-mail you have sent in for analysis does not contain viral file(s).

The application detected as Sus/Behav-1001 is clean and can be authorized .

See instructions on handling Suspicious Behaviour with Sophos Antivirus Application Control on below link under Recovery section:
http://www.sophos.com/support/knowledgebase/article/23949.html
============================

This news follows on from http://www.castlecops.com/a6809-Sophos_Antivirus_flags_CCleaner_as_malware.html "
Posted on Monday, 13 August 2007 @ 22:40:02 UTC by PCBruiser (2501 reads)
[ Trackback ]
image

"Sophos AV Technical Support clears CCleaner" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· HotScripts
· Linux Manuals
· W3 Consortium
· More about Anti-Virus
· News by PCBruiser


Most read story about Anti-Virus:
‘ErrorSafe’ Suite Fools and Pesters Users

block bottom
Article Rating
spacer
Average Score: 5
Votes: 1


Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer