Sophos Unveils Malware Removal Tool Which Cleans Exploit Code
Sophos, a global leader in network and endpoint security, today launched Sophos Clean, the latest addition to its Enduser protection portfolio of advanced malware detection, remediation and removal software. The signature-less technology uses progressive behavior analytics, forensics and collective intelligence to discover and remove code from zero-day threats, Trojans, rootkits, polymorphic malware, irritating cookies, spyware and adware.
Built on technology acquired from SurfRight B.V. in December 2015, Sophos Clean represents the next generation of malware detection and removal tools that can detect known and unknown threats. The on-demand scan does not need to be installed, which is particularly useful in cases of ransomware infection or in situations where malware is manipulating installed security software.
“The need for next-generation endpoint protection that doesn’t rely on signatures is long established. Zero-day threats and some ransomware like Cryptolocker can only be detected by the integrated capabilities of exploit prevention, behavior analytics and pre-execution heuristics built into our endpoint protection software today,” commented Dan Schiappa, general manager and senior vice president for Enduser Security at Sophos. “Sophos Clean can complement any installed anti-malware software by providing a second opinion on suspected files. With a minimal footprint and fast scan, Sophos Clean will quickly identify and remove all residual traces of malware.”
Resilient malware attacks critical system files or boot records to manipulate Windows and antivirus software – even before the operating system boots. Sophos Clean can remove persistent threats from within the operating system and replaces infected Windows resources with safe original versions. Reinfection attempts are proactively blocked until threat remediation has finished.
“Today’s malware is persistent by design: difficult to detect, difficult to remove and difficult to recover from,” commented Simon Reed, vice president of SophosLabs. “Our researchers are seeing an ever increasing sophistication of malware, both the techniques being used and the heavy use of automation. Polymorphism is becoming the norm, and previously unknown malware is on the rise. These attacks, once active on your system, embed themselves deeply using multiple techniques to ensure long term persistence. Using the latest removal technology, Sophos Clean is able to remove all fragments of a malware infection and return the system to a pristine state.”
Sophos Clean is an on-demand malware scanner of just 11 MB and can be started directly from a USB flash drive, CD/DVD or network attached storage device. The tool can scan and remediate without leaving a footprint on the local system. A typical scan with Sophos Clean takes less than five minutes because it can immediately distinguish safe applications from malicious software through advanced behavior analysis and verification of content with a database of trusted applications. This also dramatically reduces the instances of false-positives which some other signature-less malware detection tools have struggled to achieve.
Source | CXOToday