Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

troj/bredo-ajr

Yesterday Sophos identified the troj/bredo-ajr threat. It has been cleaning it up for almost 24 hours. Is this normal? Should I let it continue?

This morning a second threat, troj/invo-zip, was identified. Sophos is working on that at well. Thanks for your help!

:1017613


This thread was automatically locked due to age.
  • In Quarantine Manager does it give a path to the location of the file detected?  You'll have to open QM, click the padlock, select the item in the top panel and expand the lower panel.

    If the path is too long to be fully displayed in QM then have a look in the logs via Console.  Post below explains how to acces the logs in more detail.

    http://openforum.sophos.com/t5/Mac-tools-help/Where-are-the-logs-for-SAV-for-Mac/td-p/16091

    :1017615

     - - - - - - - - - - - -

    Communities Moderator, SOPHOS
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • ...to add: the most common reasons for the Quarantine Manager (QM) to have a problem cleaning up an item are:

    - the item is located in your mailbox

    - the item is located in a Time Machine backup

    - the item is located in the web browser's cache (and may no longer exist on disk)

    - the item is no longer located on disk

    Hence knowing where the item is, is the first thing to find out.

    :1017617

     - - - - - - - - - - - -

    Communities Moderator, SOPHOS
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • The threats were evidently in my email:

    Screen Shot 2014-05-28 at 1.54.17 PM.png

    Screen Shot 2014-05-28 at 1.54.34 PM.png

    I regularly delete the contents of my "Junk" folder in Mail. Is that why the "original locaiton" is blank?

    Thanks for your help.

    :1017649
  • I moved a Windows .exe file from a folder on my Desktop to the Desktop itself and got this...

    2014-05-29_09-51-57.png

    Hence the 'original path' shows where the file was coming from as the on-access detected it.  The 'Path and Filename' shows where I was moving it to.

    With detections involving emails there should be (generally) no problem deleting the file but if the mail app is syncing with a webmail account the files can keep coming back.  If cleanup is failing it could be that the item no longer exists (the 'Reveal in Finder' button may help here).

    I'd suggest logging into your email account via a browser, deleting the contents of the spam/junk folders.  Ensure you check for spam folders other than the main ones as Gmail, for example, has a 'Bin', 'Junk email', '[IMAP]Archived', and '[IMAP]SPAM' and the mails can be spread around.

    Once that's done I'd clear the quarantine manager list (not cleanup) and re-scan to see what comes back.

    :1017669

     - - - - - - - - - - - -

    Communities Moderator, SOPHOS
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?