Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Virus: Troj/ObfJS-BK

I recieved this virus in an email attachment without warning. It came in via a standard account user. My back-up software was denied access to copy it. This is how it was discovered without any warning from Sophos. I know this is a Windows virus and doesn't affect the Mac, but still I should recieve an alert that Sophos qurantined it.

:1006257


This thread was automatically locked due to age.
Parents
  • Hello Tom,

    one reason for an item to disappear is that the threat is no longer found by QM when you open it. This can happen when the threat is detected in a cache or temporary location and later deleted by the application which stored it. Deletes are not blocked or intercepted so QM isn't notified of this - but it checks for the existence of the files when it is opened and prunes the list (i.e. removes the items for which it is safe to assumed to be no longer there).

    Another possible reason (but it doesn't apply in your case) is that the detection triggers a more complex cleanup routine which takes some time to complete. From detection to cleanup completion the item will appear in QM.

    BTW: it is not a quarantine folder, what's displayed when you open Quarantine Manager is the list of detected and presumably still existing threats.

    Christian

     

    :1006269
Reply
  • Hello Tom,

    one reason for an item to disappear is that the threat is no longer found by QM when you open it. This can happen when the threat is detected in a cache or temporary location and later deleted by the application which stored it. Deletes are not blocked or intercepted so QM isn't notified of this - but it checks for the existence of the files when it is opened and prunes the list (i.e. removes the items for which it is safe to assumed to be no longer there).

    Another possible reason (but it doesn't apply in your case) is that the detection triggers a more complex cleanup routine which takes some time to complete. From detection to cleanup completion the item will appear in QM.

    BTW: it is not a quarantine folder, what's displayed when you open Quarantine Manager is the list of detected and presumably still existing threats.

    Christian

     

    :1006269
Children
No Data