Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Can't remove Windows threat found on my Mac

I ran Sophos for the first time a short while ago and the scan found one threat I have to remove manually  :  Mal/Zbot-I

But it's a Window (exe) file. and I have a Mac running Snow Leopard.  How can I get rid of a Windows file on a Mac?

All suggestions greatfully accepted.

:1009564


This thread was automatically locked due to age.
  • Hello gbtbag,

    QM should show the path - simply delete it.

    Christian
    :1009570
  • Hi, Christian.  Thanx for getting back to me.

    I tried highlighting the virus in QM then pressing delete and nothing happened.

    I see the path below in the threat details window.  It appears that the threat is on my backup drive.  Would a threat on my backup drive affect the performance of the computer's actual drive?  My Mac has been running slow for the past several days, which is why I downloaded and ran Sophos.

    Thank you.

    :1009580

  • gbtbag wrote:

    Hi, Christian.  Thanx for getting back to me.

    I tried highlighting the virus in QM then pressing delete and nothing happened.

    I see the path below in the threat details window.  It appears that the threat is on my backup drive.  Would a threat on my backup drive affect the performance of the computer's actual drive?  My Mac has been running slow for the past several days, which is why I downloaded and ran Sophos.

    Thank you.


    Try this:

    1. If the file path contains “/Backups.backupdb/”,

                                                                   i.      make note of the complete file path.  Eg: /Volumes/<Time Machine Volume Name>/Backups.backupdb/<Computer Name>/YYYY-MM-DD-NNNNNN/<User Name>/Library/Caches/Java/cache/6.0/8/123456-123456

                                                                 ii.      temporarily disable on-access scanning from the Sophos Preferences window,

                                                                iii.      In the finder, navigate as close to this location as you can, starting from the <User Name> portion.  When the next level down no longer exists (or when you’’’’ve found the file indicated), select “Enter Time Machine” from the Time Machine menu item (a clock face with an arrow around the outside).

                                                               iv.      Navigate to the date and time indicated by YYYY-MM-DD in the file path, and then follow the path to the detected file within Time Machine.

                                                                 v.      Control or right-click the file, and select “Delete All Backups of <detected filename>”.

                                                               vi.      Click OK

    Re-enable on-access scanning from the Sophos Preferences.

    A threat on your backup drive wouldn't affect performance however, and neither would a Windows threat.

    To check performance, you ahve two useful apps: first is Activity Monitor, and the second is Console.  The first will show you if some process is using large amounts of processing time or memory; the second will let you check the log files for your computer to see if the OS is warning you about something that's gone wrong.  The system log in Console has a LOT of information, but may be the best place to check.

    :1009588
  • Thank you for those tips.  I have an mds virus.  At the moment it's using 71.5 MB of my real memory.  A couple of minutes ago it was using over 400 MB.  I'd really appreciate any information you can give me about getting rid of it.  I would buy an anti-virus program that will delete it if it's easier than doing it with the free Sophos.

    :(

    :1009598
  • MDS isn't a virus -- it's the Metadata Service of the OS: it manages all the information used by Spotlight search indexing, QuickLook, and various other services on the operating system.

    If MDS is using large amounts of system resources and slowing down your computer, it's highly likely that Spotlight is re-indexing your hard disks to add new metadata to the search engine.  After this has been done once, things should speed up, as new data will be added as part of the file writing operation.  If you look at the magnifying glass icon in your menu bar, does it have a dot in the middle?  If you click on it, does it say "Indexing..." or similar?

    :1009608