<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title type="text">Trojan Horse / viruses</title>
  <updated>2014-12-18T21:49:56+00:00</updated>
  <generator uri="http://framework.zend.com" version="1.12.20">Zend_Feed_Writer</generator>
  <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/1137"/>
  <link rel="self" type="application/atom+xml" href="https://www.augwessex.org.uk/discussions/view/1137/feed"/>
  <id>https://www.augwessex.org.uk/discussions/view/1137</id>
  <author>
    <name>AUGW</name>
    <email>info@augwessex.org.uk</email>
    <uri>https://www.augwessex.org.uk/</uri>
  </author>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Trojan Horse / viruses]]></title>
    <updated>2014-12-18T12:01:32+00:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/1137#5093"/>
    <id>https://www.augwessex.org.uk/discussions/view/1137#5093</id>
    <author>
      <name>David Chaplin</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">I have been alerted by my Sophos software that it has detected the following threat :-  "Troj/DocD/-cu". It now sits in quarantine; I have tried to "clean" but appears unsuccessful by Quarantine Manager.<xhtml:br/>
 <xhtml:br/>
I have Googled it but no information is forthcoming. I am completing a full scan via Sophos (still in hand) but am wondering if this is one of those guises to persuade you to purchase a version of Sophos instead of the freebie or a real Trojan.<xhtml:br/>
<xhtml:br/>
Anyone experienced this issue?<xhtml:br/>
<xhtml:br/>
David Chaplin</xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: Trojan Horse / viruses]]></title>
    <updated>2014-12-18T13:41:24+00:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/1137#5094"/>
    <id>https://www.augwessex.org.uk/discussions/view/1137#5094</id>
    <author>
      <name>Mick Burrell</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">My guess would be a Windows Trojan. See this:<xhtml:br/>
<xhtml:br/>
<xhtml:a href="http://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/Troj~DocDl-CO/detailed-analysis.aspx" target="blank">Sophos Link</xhtml:a><xhtml:br/>
<xhtml:br/>
Or this where they specifically say that it's Windows that's affected (although I can't see a direct reference to the Trojan you give - this came up on my Google search)<xhtml:br/>
<xhtml:br/>
<xhtml:a href="http://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/Troj~DocDl-D.aspx" target="blank">Another Sophos Link</xhtml:a></xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: Trojan Horse / viruses]]></title>
    <updated>2014-12-18T15:50:35+00:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/1137#5095"/>
    <id>https://www.augwessex.org.uk/discussions/view/1137#5095</id>
    <author>
      <name>David Chaplin</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">Afternoon MIck,<xhtml:br/>
<xhtml:br/>
Many thanks for your reply &amp; have tried both of the Sophos links with no success; as you suspected this appears to be a Windows threat &amp; I couldn't open the Virus Tool Remover anyway. However, I did note there was was slight difference in the Trojan reference you found - yours ended in  "-co" whereas I recorded ending in  "-cu".<xhtml:br/>
<xhtml:br/>
The Sophos scan I had been conducting (not completed after about 12 hours)  appeared to seize, so I closed down the iMac &amp; restarted to find there is now no trace of this Trojan reference number, only the window in Scan Manager stating "i threat had been identified" but no further information is forthcoming.<xhtml:br/>
<xhtml:br/>
Perhaps I should just forget it and get on with all things Christmas!  The iMac working OK.<xhtml:br/>
<xhtml:br/>
Thanks again, &amp; Happy Christmas to you.     David.</xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: Trojan Horse / viruses]]></title>
    <updated>2014-12-18T21:49:56+00:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/1137#5096"/>
    <id>https://www.augwessex.org.uk/discussions/view/1137#5096</id>
    <author>
      <name>Euan Williams</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">Hi David. The Sophos Virus remover tool only operates under MS Windows (Sophos state this clearly). Threat removal under OS X is done within the Quarantine manager. <xhtml:br/>
<xhtml:br/>
Very basically put, AV software "recognises" the signature of a particular malware and then refers to its database of what snippets of code to remove. This is a very fast-reaction industry and databases are constantly being revised. Malware coders try to alter their code so that, at least for a brief while, the code is out in the wild and unrecognised. Wikipaedia offers more information.</xhtml:div>
    </content>
  </entry>
</feed>
