fiza Posted October 10, 2017 Posted October 10, 2017 We have Sophos Central with Intercept X deployed to our EndPoints. Yesterday we had an alert to say Ransomware had been detected on a machine. It said Sophos was cleaning it up. When we look at the details on Sophos Central all it states is that "CryptoGuard detected Ransomware in C:\Program Files (x86)\Microsoft Office\Office15\WINWORD.EXE" No other information, no indication of the file that caused it. We isolated the machine, wiped it and re-imaged it but it would be useful to know where the Ransomware came from. Anyone else using Sophos Central with Intercept X know if it can provide this information?
Steve21 Posted October 10, 2017 Posted October 10, 2017 If they didn't change it it writes to application event log I think 911? Steve
fiza Posted October 10, 2017 Author Posted October 10, 2017 If they didn't change it it writes to application event log I think 911? Steve where do we find this log please?
computer_expert Posted October 10, 2017 Posted October 10, 2017 where do we find this log please? In the application log in event viewer on the machine you have reimaged (not much use now, I know!)
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now