Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

sophos finding windows malware on mac

having eventually found some older hits around the similar topic wihch confirmed some things that happened to my mac here's a summary and some asks

sophos will find windows malware - typically in downloads folder. they can not infect your mac.

it seems that under normal circumstances sophos will delete them automatically and you don't even know it which is the the most appropriate action.

I had difficulties yesterday where sophos reported a trojan. I believed it was a real threat to my Mac - there's no way of me knowing that it was a windows trojan.

I used the 'clean-up' function in quaratine manager and sophos just went into a loop, my whole system became intermittantly unresponsive and other odd things - for those that had used windoes in the past this is a sure sign of a virus.

Having performed various actions - switching on hidden files as sophos was reporting that the trojan was in '.trashes' I deleted all such files that I don't need, I went to timemachine and deleted all files in downloads for all back-ups (as sophos was also pointing to that path.

After a number of reboots and sophos still reporting the problem and going into a loop every time I tried to use clean-up.

From my post on apple support community I was advised it was windows malware and that sophos was the likely culprit from slugging my mac. this came quickly which I'm glad of as I was about to erase my disk and rebuild the system.

I removed sophos from my mac and all OK.

I re-installed sophos and it could not find any malware.

it would help greatly if sophos could simply report that it's found windows malware.

one of the possible reasons for the loop is that my timemchine backup is on wireless storage. as sophos was also reporting malware in my backups, it may have been struggling to find the infected file. however this does not warrant sophos slugging my mac to the point of real concern that I was indeed infected by real malware. I am happy that sophos provides some protection but at the same time I don't want to lose 2-3 hours trying to address an issue that doesn't actually exist.  

:1012436


This thread was automatically locked due to age.
Parents
  • Hi Philcali,


    However, I have a PC that is infected with the FBI virus. I've tried everything to get it to reboot and no dice. So, I'm going to attempt to remove the HD on the PC and hook it up to an IDE 'caddy' into the Mac. I want to run Sophos Anti-Virus on the infected PC drive.

    Is this a compatible setup (PC/caddy/Mac) and will Sophos run against that drive? If so, will it also detect the FBI virus on the infected PC drive and remove it? How dangerous is this for the Mac? I can't infect the Mac, so I want to be very cautious here. 


    This won't be dangerous to the Mac at all, however it likely won't be able to clean up any "complex" malicious code from your Windows drive that might be buried in the Windows registry or boot records. Our Mac product finds the original executables that could infect a Windows machine, but it doesn't have the capability to clean up.

    You can give our free Virus Removal Tool a spin. Its designed to run without a permanent installer (just download and run).

    :1012568
Reply
  • Hi Philcali,


    However, I have a PC that is infected with the FBI virus. I've tried everything to get it to reboot and no dice. So, I'm going to attempt to remove the HD on the PC and hook it up to an IDE 'caddy' into the Mac. I want to run Sophos Anti-Virus on the infected PC drive.

    Is this a compatible setup (PC/caddy/Mac) and will Sophos run against that drive? If so, will it also detect the FBI virus on the infected PC drive and remove it? How dangerous is this for the Mac? I can't infect the Mac, so I want to be very cautious here. 


    This won't be dangerous to the Mac at all, however it likely won't be able to clean up any "complex" malicious code from your Windows drive that might be buried in the Windows registry or boot records. Our Mac product finds the original executables that could infect a Windows machine, but it doesn't have the capability to clean up.

    You can give our free Virus Removal Tool a spin. Its designed to run without a permanent installer (just download and run).

    :1012568
Children
No Data