Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Cannot find virus

Just before two o'clock today I started getting phone calls from contacts complaining that they had received eleven old emails from me.  On my way to a meeting, I rang home to ask someone to turn my iMac off; they had to "force quit" Mail.  This evening I went to my Sophos antivirus application to see if there was any information: there was nothing in Quarantine, but when I looked at the log I found the report below.  As you will see it reports four items of malware but does not say where they are.  What now? 

:1017005


This thread was automatically locked due to age.
  • Sorry, to completely ignore the question you asked :smileysurprised: ....so you have the whole of the hard drive excluded from the on-access scanner?  I just want to be sure I'm reading the screenshot correctly?

    The screenshot shows this...

    2014-04-23_15-26-50.png

    So does that mean you have this exclusion for the on-access scanner...?

    2014-04-23_15-27-48.png

    If so wouldn't it be easier to switch on-access scanning off with the 'Stop Scanning' button if you don't want it on.

    For the original question: Check Quarantine Manager for any kind of path - you will have to authenicate with the padlock, expand the lower panel, and select a item in the upper.  I imagine, if there are items listed, they too probably don't have paths either.  In the QM can you clean up the threat?  Or reveal in Finder?  Probably won't work either.

    This can occur when the on-access scanner couldn't record where the item was.  May have been a volume that was unmounted, a backup location, browser cache, etc.  I'd suggest clearing the item from the QM and running another scan.  I'd exclude (on-demand exclusion - not on-access :smileywink:) the seagate and/or any Time Machine volumes etc.  The video below is worth a watch...

    :1017023