Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Help with Creating a Custom Scan to remove a Threat

I would appreciate help with a problem identified when I did a
scan using the free Sophos Anti-Virus for IMac Home Edition that
uses Mac OS X 10.5.  The scan detected Mal/EncPk-LF threat and
the action advised was to "clean up manually" by creating a
custom scan, but I cannot figure out how to do that.
Herbert Marx (hjmarxmd@pol.net)

:1001625


This thread was automatically locked due to age.
Parents
  • This is what worked for me, step by step:

    The 3 threats found after my first full scan on my Macbook were 

    users/myname/library/cache/java……

    which needed to be cleaned up manually.

    In the Quarantine Manager, click on the blue link file name of the threat to get it's details.

    You need to note the path & file name.

    In my example I will use users/myname/library/cache/java……

    You will need to make a custom scan.

    1. In the window that's titled Scan Local Drives, click on the arrow next to Custom Scans

    2. Click on the + sign.  You will see a message untitled - No items in scan, this scan has never been run.

    3. Double click on it and another window will open asking for a Scan Name (can fill in later).  At the bottom of this window, click the + sign - this       will open a finder window called Open.

    4. Double click on the file called Users (another window opens)

    5. Double click on the home file with your name on it (another window opens)

    6. Double click on the Library folder (another window opens)

    7. Single click on the Caches folder and then click on the Open button bottom right

       You should now see the folder Caches with a tick next to it in the window described in step 3.

    8. Type in whatever name you want to call the custom scan.  I called mine Caches.

    9. Under the title you've just typed are 3 buttons. Click on the Options button.

    10. Click on the drop down menu where it says log only and choose Delete threat.  So it now says When a threat is found: Delete threat.

           Click on the Done button.

    11. In the customs scan window from step 1. you should see a new custom scan called Caches (or whatever you named it).  Click on the Play           button next to the pencil button.

    12. A drop down dialogue box asks you to Scan with privileges, Cancel or Scan All.

          Click on the Scan All button & type in your administrator password & click OK.

    13. The scan is performed.  If you Open Quarantine Manager, the threats should be gone.  

    Cheers.

    :1001639
Reply
  • This is what worked for me, step by step:

    The 3 threats found after my first full scan on my Macbook were 

    users/myname/library/cache/java……

    which needed to be cleaned up manually.

    In the Quarantine Manager, click on the blue link file name of the threat to get it's details.

    You need to note the path & file name.

    In my example I will use users/myname/library/cache/java……

    You will need to make a custom scan.

    1. In the window that's titled Scan Local Drives, click on the arrow next to Custom Scans

    2. Click on the + sign.  You will see a message untitled - No items in scan, this scan has never been run.

    3. Double click on it and another window will open asking for a Scan Name (can fill in later).  At the bottom of this window, click the + sign - this       will open a finder window called Open.

    4. Double click on the file called Users (another window opens)

    5. Double click on the home file with your name on it (another window opens)

    6. Double click on the Library folder (another window opens)

    7. Single click on the Caches folder and then click on the Open button bottom right

       You should now see the folder Caches with a tick next to it in the window described in step 3.

    8. Type in whatever name you want to call the custom scan.  I called mine Caches.

    9. Under the title you've just typed are 3 buttons. Click on the Options button.

    10. Click on the drop down menu where it says log only and choose Delete threat.  So it now says When a threat is found: Delete threat.

           Click on the Done button.

    11. In the customs scan window from step 1. you should see a new custom scan called Caches (or whatever you named it).  Click on the Play           button next to the pencil button.

    12. A drop down dialogue box asks you to Scan with privileges, Cancel or Scan All.

          Click on the Scan All button & type in your administrator password & click OK.

    13. The scan is performed.  If you Open Quarantine Manager, the threats should be gone.  

    Cheers.

    :1001639
Children
No Data