Wed, January 26, 2011 11:21:49 PM
RE: [#2644089] File sample submitted from the Sophos website
From:
Phanusin Sywarungsymun <phanusin@wtec.co.th>
View Contact
To: udomchok somwang <udcsw@yahoo.com>
Cc: Sophos <Sophos@wtec.co.th>
คุณโก้ครับ
จากตัวอย่าง Trojan ที่พบตามลิงค์ด้านล่างนั้น signature ออกมาวันที่ 25 ที่ผ่านมาก่อนเกิดปัญหาครับ
http://www.sophos.com/security/analyses/viruses-and-spyware/trojbancosbiz.html ผมได้ส่งไฟล์เข้า labs ให้แล้วครับ เพื่อให้ทาง Sophos ตรวจสอบว่าเป็น false positive หรือไม่ ซื่งผลที่ออกมาคือ เป็น false positive ครับ
ต้องขอโทษด้วยครับที่ signature ไปตรวจจับไฟล์ library mysql connector ทำให้ระบบงานของโรงพยาบาลรันไม่ได้
ณ ตอนนี้ เมื่อ server update signature ใหม่เรียบร้อยแล้วก็จะไม่ตรวจจับไฟล์นี้เป็น Trojan อีกต่อไป
ทางคุณโก้สามารถจะ remove windows exclusion ทั้งในส่วน on-access scanning และ schedule scanning ใน anti-virus and hips policy บน console ออกได้เลยนะครับ
แต่ถ้าไม่ต้องการให้ไปกระทบอีกก็ปล่อยไว้อย่างเดิมก็ได้ครับ
Best Regards,
Phanusin Sywarungsymun
ภาณุศิลป์ ศิวรังสิมันต์
Technical Manager
Sophos Division
WTEC Co., Ltd.
M: +66 (0) 8 0551 6052 | T: +66 (0) 2673 9484 Ext. 621 | F: +66 (0) 2673 9483
E: Phanusin@wtec.co.th
W:
www.wtec.co.th From: Sophos Support [mailto:supportasia@sophos.com]
Sent: Wednesday, January 26, 2011 2:35 PM
To: Phanusin Sywarungsymun; Sophos
Subject: Re: [#2644089] File sample submitted from the Sophos website
Hi Phanusin
thank you for your emails. This false-positive report should now have been corrected. Please do not hesitate to contact me if I can be of any further assistance.
Regards,
Martin Elliott
Sophos Technical Support
http://www.sophos.com/support/services/technical.html Support knowledgebase:
http://www.sophos.com/supportSubscribe to email notifications:
http://www.sophos.com/security/notificationsSophosTalk community (discussion forums):
http://community.sophos.comSOPHOS - simply secure
-----Original Message-----
From: phanusin@wtec.co.th
Sent: 2011-01-26 05:27 AM
To: supportasia@Sophos.com, Sophos@wtec.co.th,
Cc:
Hi,
Just follow up the case to see how is going?.
The signature that sophos launched 25 Jan 2011 which detects trojan bocon may be false positive. I'm not sure whether it detect correct or not. Customer has been using their library connector to mysql for so long until sophos distributed signature yesterday.
Please verify.
Phanusin
Sent from my BlackBerry® by dtac.
________________________________
From: Sophos File Samples
Date: Wed, 26 Jan 2011 01:19:43 +0000
To:
Subject: [#2644089] File sample submitted from the Sophos website
*NOTE: Please quote [#2644089] in the subject line of any further correspondence related to this query.
Thank you for submitting your sample(s). Our systems will analyze your sample(s) and return an automated response as soon as results are available. If you require assistance, or have any questions, please contact support@sophos.com.
Kind regards,
Sophos Technical Support
Support knowledgebase:
http://www.sophos.com/supportSubscribe to email notifications:
http://www.sophos.com/security/notificationsSophosTalk community (discussion forums):
http://community.sophos.comSOPHOS - simply secure
===================================================================================================
Disclaimer:
The information transmitted in this e-mail is intended only for the person or entity to which it is addressed, and may contain confidential
and/or privileged material. Any review, re-transmission, dissemination or other use of, or taking of any action in reliance upon this information
by persons or entities other than the intended recipient is prohibited. If you received this e-mail in error, please contact and inform the sender,
and delete the material from any computer.
WTEC Co., Ltd.
===================================================================================================
===================================================================================================
Disclaimer:
The information transmitted in this e-mail is intended only for the person or entity to which it is addressed, and may contain confidential
and/or privileged material. Any review, re-transmission, dissemination or other use of, or taking of any action in reliance upon this information
by persons or entities other than the intended recipient is prohibited. If you received this e-mail in error, please contact and inform the sender,
and delete the material from any computer.
WTEC Co., Ltd.
===================================================================================================