Sophos Endpoint Threat Cleanup and malware removal
Threat Cleanup is the technical removal of a detected threat. Acknowledging, resolving or closing an Alert is only a workflow action. An incident is complete only after checking the threat, persistence, entry path and affected systems.
Immediate triage
For an active or high-risk Detection:
- Identify the device and check its latest communication.
- Preserve the Detection Name, time, user, process, path, hash and Sophos action.
- Isolate the device if further execution or spread is possible.
- Investigate the Threat Graph or process chain.
- Check automatic Cleanup and remaining artefacts.
- Search for the entry path, persistence and similar Events on other devices.
- Clear the Alert and Health State only after technical validation.
For a business-critical system, coordinate isolation with the incident process. Convenience is not a reason to leave a potentially active system unisolated.
Malware not cleaned up
Malware not cleaned up means that the Detection was not removed completely. Locked files, network shares, insufficient permissions, damaged agent components or a storage location that is no longer reachable can cause this state.
The next step depends on the path and state:
- run the local Sophos Scan again,
- inspect the file and associated processes,
- clean up a network share on the system responsible for it,
- use Endpoint Self Help and SDU for agent faults,
- involve Support if Cleanup fails reproducibly.
Treat Running malware not cleaned up as a potential active incident. A restart alone is not a root-cause analysis.
Ransomware and remotely executed ransomware
For ransomware, investigate affected files, the source process, user account, shares and neighbouring devices. A notification about remotely executed ransomware may indicate another compromised computer encrypting data across the network.
The reporting protected device is therefore not necessarily the source. Include SMB connections, sign-in Events, administration tools and other devices in the investigation. Reset credentials for affected accounts in a controlled manner.
For a local CryptoGuard detection, Sophos can remove the triggering process’s write access to file systems. This block remains until the detection is marked as technically resolved locally or in Central, or the system is restarted. Close it only after investigating the cause; a restart must not replace the investigation.
For a remote detection, correlate the reported IP address with DHCP, NAT, SMB and sign-in data. If the address was reassigned later, the wrong device could otherwise appear to be the source. Sophos deliberately provides no IP-based CryptoGuard exclusion because it would be too broad.
The ransomware policy offers Terminate Process by default and Isolate Process as an alternative. Terminate stops the source process; Isolate Process also restricts it to internal communication through Windows Filtering Platform. Isolate the entire device separately when the host is no longer trusted.
Distinguish C2/Generic-B from C2/Generic-C
C2/Generic-B is triggered by the Endpoint when Network Threat Protection detects suspicious communication with command-and-control infrastructure. This High-severity alert requires manual investigation in the Threat Case. Preserve the process chain, URL node, user and Technical Support reference. The reference represents a malicious destination hidden by Sophos and must be included in a sample or support escalation.
An apparently legitimate process such as svchost.exe or wscript.exe is not an all-clear. Malicious code may have been injected into or launched by a legitimate process. If persistence is unclear, include an SDU and a controlled Autoruns export in the investigation material.
C2/Generic-C has a different origin: a Sophos Firewall detected the connection and reported it to the Endpoint through Security Heartbeat. The Endpoint Event therefore often lacks the triggering process or original destination. The primary trail is in the Firewall’s Security Heartbeat or Threat report. This distinction avoids fruitlessly searching only Endpoint logs.
Exploit, browser and IPS Detections
A blocked exploit or browser action may have prevented an attack chain, but does not prove that no further steps occurred. Check the process tree, browser extensions, download source, target URL and child processes.
For Safe Browsing detected browser has been compromised, check Details > Show Raw data in the device Event and the loaded modules. On Windows, Application Event Log event ID 911 contains the same key details. A printer driver injected into the browser while viewing or printing a PDF can be a legitimate trigger, but accept this explanation only after verifying the vendor, signature, version, user action and similar alerts.
If the detail view is missing, an exclusion may already exist for this Detection. That is not proof of a False Positive, but an additional configuration point to check before continuing the assessment.
Correlate IPS Detections with the source and target systems, port, direction and repeated connections. Broadly allowing the application or website is not an appropriate response.
Endpoint IPS drops the triggering packet immediately. A single cleaned IPS detection therefore does not automatically require cleanup, but it does require review of the rule, direction and recurrence. If an exception does not apply, check especially whether source and destination ports were reversed for inbound or outbound traffic. Permit only the concrete rule and necessary traffic.
Malicious Traffic Detection, or Network Threat Protection, checks non-browser HTTP traffic on Windows for command-and-control destinations; web protection handles browser traffic. It operates only in real time, not during Scheduled Scans, and does not support authenticated proxies on this path. Diagnose the policy, installed component and C:\ProgramData\Sophos\Sophos Network Threat Protection\Logs\SophosIPS.log together.
BrowserCookie means a process tried to access browser cookies, which can enable session and identity theft. Review process path, signature, user, target browser and process chain. Do not allow a password, profile or support tool based only on its product name; establish why it needs cookie data and whether the vendor provides a compatible version.
AMSI detections
AMSI inspects script and memory content that integrated Windows applications pass to the antimalware interface, including PowerShell, Windows Script Host, JavaScript or VBScript and Office VBA. Python or Perl are not automatically covered. Obfuscated or runtime-generated code can be assessed before execution.
Sophos sends detection context to Central. Depending on the caller, it may contain script text, command arguments or sensitive data. Treat events and support exports as confidential. Scope an AMSI exception to the verified content or process and preferably to a narrow policy.
Names beginning with CX or Low reputation also assess reputation, location, origin and behaviour. CXmal means a new variant of known malware, CXmail email context, CXweb a download intercepted by Web Protection and CXrep a malicious low-reputation profile. A Low-Reputation PUA may instead be legitimate but unwanted software. The prefix explains context, not the final analysis.
Mal/Generic-R also indicates low file reputation, which is not based on prevalence alone. A common file can still be disreputable, for example through an abused signing certificate. Review the Threat Graph with Intercept X and report a justified false positive through Sophos Sample Submission rather than creating a global exclusion.
PUA and Application Lockdown
Potentially Unwanted Applications can be legitimate but undesirable programs. Before allowing one, check the vendor, signature, hash, business use and distribution.
Authorize PUA from the Alert view can have a global effect. For a limited requirement, a targeted policy exclusion with an owner and expiry date is safer.
Context is decisive for RMM tools. Sophos can detect Datto RMM as a PUA when components appear under unexpected paths or names because attackers abuse legitimate remote tools for access and persistence. Before allowing it, verify vendor, hash, expected installation path, filename, responsible operator, deployment request and active remote sessions.
Application Lockdown can block files associated with a detected application. First establish whether the underlying application is legitimate and unchanged, then authorise it in a controlled manner.
ML/PE-A denotes a PE file judged malicious by Deep Learning, while Generic ML PUA denotes a potentially unwanted file. Both are pre-execution detections, so the file was blocked before it ran. This lowers immediate risk but does not replace checking the download source, distribution and similar files. HPmal/ and HPsus/ are behaviour-based runtime detections where the process and event chain are particularly important.
Legitimate diagnostic and administration tools can deliberately be detected as a PUA or behavioural abuse. GMER is one example because attackers can use it to bypass security products. Allowing it requires an authorised task, original source, valid signature, controlled path and limited maintenance window.
False Positive and Sample Submission
Do not allow a Detection solely on a user’s statement. The digital signature, SHA-256, source, behaviour and process chain must be plausible. Submit suspicious or new False Positives with the required data to SophosLabs or Sophos Support.
A VirusTotal result is only an indicator. Many detections strongly suggest malicious code, a few can indicate early detection or a False Positive, and no detection does not rule out a zero day. Search for the SHA-256 first. Do not upload an internal or confidential file to a public analysis service without data approval.
Under Profile > Account Preferences > Privacy, Central controls automatic Sample Submission. Sophos requests a copy when a potentially malicious file cannot be classified from its properties alone and Sophos does not already have a sample. The limit is 10 MB per sample and the upload timeout is 30 seconds.
Samples can contain files, emails or URLs and therefore sensitive content. Sophos recommends leaving the function enabled for better protection; nevertheless, assess privacy, the legal basis and particularly confidential datasets in advance. Disabling it can restrict analysis and False Positive correction and must not be used as a blanket privacy switch.
Make exclusions as narrow as possible, using a certificate or hash. Path exclusions in writable directories are particularly risky. Details are provided in Configure Sophos Central Endpoint exclusions securely.
Machine-learning detections in temporary directories require special care. These files are often unsigned, short-lived and receive a new hash on each run. A hash or broad %TEMP% exclusion is therefore ineffective or dangerous. Assign only a small device group to a temporary policy, preserve the file before deletion and submit it to Sophos. Afterwards restore changed directory permissions, policies and exclusions completely.
Non-cleanable system files and failed restoration
A detection in pagefile.sys, hiberfil.sys or a Volume Shadow Copy is not solved with a file exclusion. Run a full scan to locate the original process or source. Shadow Copies are read-only and removing them discards complete restore points, so coordinate with backup and recovery owners. Clear pagefile or hibernation only through documented Windows mechanisms after preserving incident evidence.
If restoration of a cleaned application fails, correlate SophosCleanup.log or Clean.log with SafeStore.log using the same Threat ID. Do not bypass SafeStore_RestoreObjectById ... error 18 by repeatedly authorising. After verifying false positive, signature and business need, restart Sophos System Protection or collect an SDU and escalate with Threat ID and timestamp.
Fileless or WMI-based malware requires persistence checks outside normal paths. For a JavaScript coin miner, preserve and inspect WMI Event Filters, Event Consumers and Bindings under root\subscription. Remove only confirmed malicious objects, then run a full scan, trace the entry path and check other devices. A cleaned visible process does not prove the WMI trigger is gone.
Closure criteria
Close the incident only when:
- no active process or persistence mechanism remains,
- Cleanup or manual remediation is confirmed,
- similar devices and users have been checked,
- the entry path and vulnerability have been addressed,
- protection and agent communication are healthy again,
- evidence and decisions are documented.