Sophos Scan & Clean

Discussion in 'other anti-malware software' started by XIII, Nov 27, 2022.

  1. XIII

    XIII Registered Member

    Joined:
    Jan 12, 2009
    Posts:
    1,383
    We don’t seem to have a topic yet for the free Sophos Scan & Clean second opinion scanner?

    I have a question/bug to report and hope @RonnyT can help:

    Recently a family member received a used/discarded laptop from her work to use at home. The laptop does not fit Windows 11 requirements, but is quite able to run Windows 10 and way better than her current (much older) PC.

    I’m trying to set up this laptop for her. So far I have only wiped its SSD and installed Windows 10. To my surprise this was already activated (with a digital license), but I guess that’s the advantage of a used computer. Even though I wiped the drive I next installed Sophos Scan & Clean to let it scan for malware.

    Immediately after starting (even before scanning), Sophos Scan & Clean reported that I might be the victim of software piracy, in a yellow bar at the bottom of its window. The text contained a blue link to solve the issue, but no matter how often I click on that link, nothing happens (I expected a browser page to open).

    Since I wiped the drive, have a legitimate Windows 10 installed and only installed this free scanner I don’t understand the warning (and how to solve it).

    Who can help? (Ronny?)
     
  2. Brummelchen

    Brummelchen Registered Member

    Joined:
    Jan 3, 2009
    Posts:
    5,920
    sophos should stay on its focus and not about crap that happens.
    the key is probably inserted from BIOS and thus fixed to the hardware. to change windows edition user need to insert another key and windows do the rest. the key from bios belongs to the previous owner, if it is allowed to re-use then, ok, user need to ask -> admin. if not, user need to purchase (or use) another license (which means a new key in general)
    sophos is now not determining a proper activation, which is not their business, should keep off.

    BTW keep sophos away from windows 10/11. its a decent business software for servers and its clients, but for end user not recommended.
     
  3. XIII

    XIII Registered Member

    Joined:
    Jan 12, 2009
    Posts:
    1,383
    So you think the “piracy” refers to Windows? Windows itself says it’s activated with a digital license.

    PS: Sophos Scan & Clean is a (non-resident) second opinion (on-demand) scanner; very similar to HitmanPro.
     
  4. TairikuOkami

    TairikuOkami Registered Member

    Joined:
    Oct 10, 2005
    Posts:
    3,434
    Location:
    Slovakia
    It probably considers generic key as pirated, you can check key via https://www.microsoft.com/en-us/p/showkeyplus/9pkvzcprx9nv

    You can use this command to clean key from registry, if there is any: slmgr /cpky

    P.S. Sophos Scan & Clean is rebranded HitmanPro, but with the ability clean for free, though registration is required to download.
     

    Attached Files:

  5. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    Only has two choices: Default scan(recommended) and Quick scan.

    Does not have have: Early Warning Scoring (EWS)
     
  6. Bill_Bright

    Bill_Bright Registered Member

    Joined:
    Jun 29, 2007
    Posts:
    4,042
    Location:
    Nebraska, USA
    I think that Sophos web page is pretty much a deluge of marketing hogwash.

    It says,
    All malware (which, BTW, includes the malicious software category of viruses) attempt to bypass standard defenses. So nothing new, unique or special there.

    Advanced threats may effectively hide from computer "users" (which is why we must keep our computers current and avoid being "click-happy" on unsolicited links), but it is not true they are effective at hiding from security software. That is just marketing FUD.

    While it may be true security programs that rely on "prior threat knowledge" (aka, signature/definitions files) are ineffective against some of the newest, most sophisticated, advanced malware, that is exactly why today's real-time security software does not rely only on definition files. Instead, they ALSO use behavior analysis and other techniques to detect and neutralize those threats BEFORE they have a chance to deliver their payloads.

    This may be a decent "second-opinion" scanner. But I agree with you and it is just another "second-Bopinion" like HitmanPro, Malwarebytes, and a couple others - for users to use just to make sure they (the user and always weakest link in security) or their primary scanner of choice, didn't let something slip by. I use Malwarebytes for that and see no reason to dump it for this Sophos one.

    I am NOT saying you wasted your time. It is wise to scan the heck out of used drives you don't know the full history of. I am just saying don't fall for the marketing hype that other security programs are so weak and ineffective that this Sophos is something you must have.

    "Wipe" has significant meaning when it comes to drives. Did you mean "wipe" - which writes a bunch of random 1s and 0s to every storage location on the drive - effectively obliterating any and all previously saved data? Or do you mean you simply deleted? Or do you mean you formatted and reinstalled the OS?

    And do note you do not "wipe" a SSD. It does not harm the SSD but wipe programs are not effective at destroying "all" previously saved data due to the way TRIM and wear-leveling function to extend the drive's longevity. "Secure Erase" must be used on SSDs to completely erase a SSD.

    Correct. That is one of the advantages [most of the time] of UEFI.
     
  7. XIII

    XIII Registered Member

    Joined:
    Jan 12, 2009
    Posts:
    1,383
    Yes, I formatted and reinstalled the OS.
     
  8. Bill_Bright

    Bill_Bright Registered Member

    Joined:
    Jun 29, 2007
    Posts:
    4,042
    Location:
    Nebraska, USA
    If you formatted and reinstalled W10, got it fully updated, then, for good measure, scanned with Microsoft Defender, IMO, you were good to go in confidence the system was clean. If you needed an extra warm fuzzy, running 1 "second-opinion" scanner is fine.
     
  9. Brummelchen

    Brummelchen Registered Member

    Joined:
    Jan 3, 2009
    Posts:
    5,920
    HMP IS part of sophos portfolio
    https://www.hitmanpro.com/en-us/hmp-business

    so sophos is dealing like any other security giant: "cant beat it - buy it"
     
  10. XIII

    XIII Registered Member

    Joined:
    Jan 12, 2009
    Posts:
    1,383
    This family member had access to another (identical) laptop.

    I was curious whether it could run Windows 11 if I would Rufus to bypass some checks. To my surprise Windows 11 installed fine and seems to run without issues.

    Again Windows 11 is already activated with a digital license, without me entering one.

    However, this time Sophos Scan & Clean does not complain about piracy (which seems correct to me; I don't pirate software).

    Still wondering why it complains on the other laptop (and still hoping that @RonnyT has an explanation).
     
  11. RonnyT

    RonnyT QA Engineer

    Joined:
    Aug 9, 2016
    Posts:
    636
    Location:
    Planet Earth
    That message appears in HMP and Scan & Clean when the binary integrity check fails for the scanner, that does not imply that the OS is pirated.
    The check was build against cracked builds for HMP, but it can also trigger if the download got corrupted somehow.
    I'd advise to delete this one and download a fresh copy that should solve the issue.
     
  12. XIII

    XIII Registered Member

    Joined:
    Jan 12, 2009
    Posts:
    1,383
    Oh, wow, did not expect that. Thanks!

    Will try to download again and report back.
     
  13. XIII

    XIII Registered Member

    Joined:
    Jan 12, 2009
    Posts:
    1,383
    A new download & re-install indeed fixed it. Thanks again.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.