Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Threats in a Time Machine Backup

I have a friend who has 100's of threats stored in his time machine backups.

Each of them say 'Remove threat manually'

Is there a way to just delete these threats instead of manually deleting the files?

I don't want him to accidently restore these files.

:1001485


This thread was automatically locked due to age.
Parents
  • If he's running Sophos in on-access mode, he won't be able to restore the files -- the action will be blocked.

    For now, the only way to remove them is from inside Time Machine -- do not try removing them with any other tool.

    To remove files from within Time Machine:

    1. Enter Time Machine
    2. If you know where the file is located, navigate to it.  If you don't, do a search for it.  Make sure that "This Mac" and "File Name" are selected as search criteria.
    3. right/control click on the file and select Delete All Backups

    All copies of the file will now be deleted.

    If he has 100's of detections, it might be that one file is infected and is being detected in each backup snapshot.  Also, if the detected files are cache files (for example, the Java webcache), get him to exclude his cache directories from TM backup -- they aren't needed after all.

    :1001487
Reply
  • If he's running Sophos in on-access mode, he won't be able to restore the files -- the action will be blocked.

    For now, the only way to remove them is from inside Time Machine -- do not try removing them with any other tool.

    To remove files from within Time Machine:

    1. Enter Time Machine
    2. If you know where the file is located, navigate to it.  If you don't, do a search for it.  Make sure that "This Mac" and "File Name" are selected as search criteria.
    3. right/control click on the file and select Delete All Backups

    All copies of the file will now be deleted.

    If he has 100's of detections, it might be that one file is infected and is being detected in each backup snapshot.  Also, if the detected files are cache files (for example, the Java webcache), get him to exclude his cache directories from TM backup -- they aren't needed after all.

    :1001487
Children
No Data