Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Clean up option

Quaranting Manager has found 3 threats. It indicates "Cleanup" for all 3 under the "Action Available" column.  However, when I click on the lock and enter my password to access and make changes in the options at the bottom, only the "Clear List" option is available to click on.  The "Clean up Threat" (and the "Reveal in Finder") option is grey-ed out and I cannot choose them.  It would seem that I would want to have the 3 threats cleaned up.  How can I do that.  Or is it that they have already been cleaned up and all I have to do is "clear from list"?  I'm confused.

:1014287


This thread was automatically locked due to age.
  • You have multiple items and there isn't a global option for what should be done.  Hence select an item.  Example:

    2013-11-11_17-19-22.png

    2013-11-11_17-20-03.png

    :1014295
  • You are so helpful rukus.  I really appreciate it.  By doing what you told me to do, indeed I could click on "Clean Up Threat".  However, I got a "Cleanup Failed" on two of the three threats.  What does that mean?  Any suggestions?

    (Haven't yet gotten around to trying your Sophos stalling instructions)   --hatual

    Screen Shot 2013-11-12 at 10.35.39 AM.png

    :1014341
  • If you select one of the items and click the 'Show Details' to expand the lower panel where is the file(s) located?  Then select the second item and see where that is located.  Can you screenshot the Quarantine Manager with the lower panel expanded and post back?

    :1014349
  • I took a screenshot of the beginning of the details of the Mal/VB-ACR screen and then the end of the screen.  There was a lot more in teh middle to scroll through.

    Screen Shot 2013-11-12 at 11.29.53 AM.png

    Screen Shot 2013-11-12 at 11.30.20 AM.png

    And  here are similar screenshots for  Troj/ZAccess-IY:

    Screen Shot 2013-11-12 at 11.34.38 AM.png

    Screen Shot 2013-11-12 at 11.34.50 AM.png

    :1014371
  • Thanks - very helpful.  The screenshot you posted shows that the file detected is in Time Machine and multiple backups.  This requires manual cleanup.  Watch the video below to see what to do for files detected in Time Machine.  Post back how you get on and whether the video was useful.

    :1014377
  • Video was clear and helpful except that when I got to the following page, it gives me no date to use to go back in TimeMachine.  There are a lot of zbots and 3 vbs (vb-gro, vb-gwe and vbs-cq).  

    Screen Shot 2013-11-12 at 2.19.44 PM.png

    :1014395
  • Thanks.  Your screenshot shows all of the IDE files listed that are then used in the scan (and the file names look a lot like the viruses).  Ignore them and look below the scan summary (example screenshot below).  As the video showed you may have to click through a couple of scan logs (left-hand side of Console) to locate the log that shows the full path.

    2013-11-12_20-35-30.png

    :1014401
  • When Troj/ZAccess-IY  shows up on a lot of different dates, do I just select the latest date (which is today) and then when I click on "delete all backward" in TimeMachine, all the previous dates will be cleared?  Or do I start with the oldest date on which it appeared? The oldest date for it is 3/9/13 and the most recent is 11/1/13.

    :1014403
  • Select the newest -- I imagine that's easier than scrolling back through time.  If the file is the same (size, name, folder location - basically the same checksum) all copies should be deleted that match.

    Work through the log and make sure you get all the files detected in Time Machine.

    Once you're happy the backups are cleared out: Go to the Quarantine Manager and 'Clear from list' anything that remains and scan the computer again.  Something may come so check the details in the Quarantine Manager for the location and now select 'clean up'.  Post a screenshot if you get stuck.

    :1014405
  • Last year you were extremely helpful to me in cleaning up this virus.  Like MacArthur, it has returned.  I have gone back and followed your instructions carefully.  But I am at a point where I must locate the date of the virus and what comes up on my screen has two dates imbedded.  I need to know which date to use.  Here are two screen shots.  Please help me to determine the date I must locate in TimeMachine to rid myself of this virus.  Hatu

    Screen Shot 2014-02-03 at 9.50.12 AM.png

    Screen Shot 2014-02-03 at 9.50.40 AM.png

    :1015729