Collecting samples blocked by on-access scanning
This method can be used for collecting samples of files otherwise blocked by on-access scanning, for example 'Mal/' files. You can then submit the file to SophosLabs for further analysis.
What to do
Provided that the file is still present on the computer, you can set up an on-demand scan to capture it safely.
Unless the file that you want to capture is on removable media (CDs, floppy disks, USB cards, etc.), remove all such items from the computer before starting.
Windows 2000/XP/2003/Vista
These instructions assume that you are using Sophos Anti-Virus for Windows 2000+, version 5 or above.
- Log onto the computer with administrator rights.
- Open Sophos
Anti-Virus . - Select 'Set up a new scan'.
- Select all drives marked 'Local disk'. (Alternatively, select 'My Computer', but the scan may take longer.)
- Select 'Configure this scan'.
- In the 'Individual scan settings' dialog, select the Cleanup tab.
- Deselect 'Automatically cleanup items that contain a virus' if it has been enabled.
- Select 'Move to'. (If you use a non-default location, make a note of it.) The default locations are:
- Windows operating systems except Vista
C:\Documents and Settings\All Users\Application Data\Sophos\Sophos Anti-Virus\INFECTED - Windows Vista
C:\Program Data\Sophos\All Users\Application Data\Sophos\Sophos Anti-Virus\INFECTED
- Windows operating systems except Vista
- Click 'OK'.
- Click 'Save and start'.
- Wait for the scan to finish.
Any files found will be saved with a file extension that prevents them from being run.
Note: The 'INFECTED' folder is a hidden folder. You may need to make it visible.
As the Sophos on-access scanner will intercept the file when you attempt to upload it to the Sophos website, you will need to exclude that file from on-access scanning.
- In the Sophos
Anti-Virus home page, select 'Configure SophosAnti-Virus '. - Select 'On-access scanning'.
- Select the Exclusions tab.
- Click 'Add'.
- In the 'Exclude item' dialog, in the 'Item type' dropdown list, select File.
- Click 'Browse'.
- Browse to one of the following:
- Default on Windows operating systems except Vista,
the default is, C:\Documents and Settings\All Users\Application Data\Sophos\Sophos Anti-Virus\INFECTED - Default on Windows Vista,
the default is, C:\Program Data\Sophos\All Users\Application Data\Sophos\Sophos Anti-Virus\INFECTED - Non-default
your alternative folder if you did not use the default
- Default on Windows operating systems except Vista,
- Select your infected file (it will have a name similar to 'program.exe.000').
- Click 'OK'.
- Repeat this process for any other infected files.
- When you have finished excluding files, click 'OK' to save your exclusions list.
You can now upload the file to the Sophos website.
- Open a web browser.
- Browse to http://www.sophos.com/support/samples/.
- Enter your details and click 'Continue'.
- In the 'Operating system' dropdown list, select the operating system of the affected computer.
- In the 'Why do you want to send this sample?' field
- give the reported analysis name (e.g. Mal/Dload-A)
- say "Submitting file for further analysis".
- Click 'Continue'.
- Click 'Browse'.
- Browse to one of the following
- Windows operating systems except Vista,
the default is, C:\Documents and Settings\All Users\Application Data\Sophos\Sophos Anti-Virus\INFECTED - Windows Vista,
the default is, C:\Program Data\Sophos\All Users\Application Data\Sophos\Sophos Anti-Virus\INFECTED - your alternative folder if you did not use the default.
- Windows operating systems except Vista,
- Select the file.
- Click 'Open'.
- If you have any further files to submit, click 'Upload another file'. Otherwise, click 'Submit'.
Your file will be submitted for analysis.
After you have submitted the file, you should remove the on-access exclusion from that file.
- In the Sophos
Anti-Virus home page, select 'Configure SophosAnti-Virus '. - Select 'On-access scanning'.
- Select the Exclusions tab.
- Select the exclusion that you want to remove.
- Click 'Remove'.
- Repeat this process for any other exclusions you need to remove.
- Click 'OK' to save your exclusions list.
If you need more information or guidance, then please contact technical support.
- Article ID: 17327
- Created: 21 Sep 2006
- Last updated: 27 Nov 2006
