Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Scanning for viruses

When I try scanning for viruses, Sophos appears to shut itself down and the information box tells me my last scan was performed on 12/09/12.  My on-access scanning option also turns itself off, even when I have saved the changes in my preferences.  Is it possible I already have a virus or some kind of malware in my computer?

Thanks.

:1010558


This thread was automatically locked due to age.
Parents

  • vlb wrote:

    I am having the same problem.  I have Mac Mountain Lion 10.8.

    I am sorry I do not understand these instructions.  Where do I find the Library/preferences?  I have not idea where to find these things to delete them.

    I also have no idea where the scan is stalling.  It does not show on the scanning page.  

    If there is a malicious virus or malwar interfereing wiht Sophos, then what?  I thought Sophos was supposed to protect me.

    VLB


    "go into ~/Library/Preferences/ (hold down option and select Library from the Finder's Go menu) and search for sophos" -- the other Library folder is at the root of your computer, next to the Applications and System folders.

    If you are scanning inside an archive file (which is where scans sometimes unexpectedly end if there's a problem), the file name will be listed below the progress bar.  If there's nothing there, then you probably just need to uninstall and reinstall the product (and restart your computer).

    For some users, this problem may be related to http://www.sophos.com/en-us/support/knowledgebase/118516.aspx
     -- note: this KBA is released for Enterprise products, so some of the terminology or path details may not be fully accurate for the Home product.

    If there is software interfering with Sophos, either Sophos or the other software will need to be uninstalled.  For example, it is generally not a good idea to have multiple AntiVirus programs running at the same time; they could prevent each other from correctly scanning for malware.  A test for interfering software is to restart your computer with the shift key held down, and then run the on-demand scanner.  If it's a configuration issue or the installation is damaged, this will fail to run.  If it's being interfered with by third party software, it should run -- at which point you need to start investigating launch daemons and login items to see what else is running alongside Sophos that has low-level access to the entire file system of your computer.

    In the unlikely event that you are hit with malware that intentionally disables Sophos, we would likely receive multiple submissions of this software in very short order and release an advisory regarding it.  There is currently a proof of concept that attacks Sophos Anti-Virus 8.0.6 and earlier via a malicious PDF file, but it is not in the wild, and will not function on 8.0.8 and later.

    If you feel that something malicious has made it onto your computer and is actively avoiding detection by Sophos, first try

    1. restart the computer with the shift key held down and log in using an account with administrator priveleges (if you only have one account, it has them)
    2. Launch Terminal.app (it's in the Utilities folder) and type "sudo sweep /" and enter your login password when prompted.
    3. If the software functions and finds no malware, you likely just have something conflicting.  Get someone with a bit of in-depth OS X knowhow to remove any launch agents or login items that may be causing the problem.
    4. try uninstalling the software and installing a different AV solution.  If this also fails to operate correctly, you best bet is to follow Apple's instructions to restore from your restore partition. 
    5. If it operates correctly and fails to find anything malicious,  it's up to you which of the above steps you take.  Most likely you just need to ensure your preferences files are all uncorrupted, you have a clean install of Sophos, and you don't have unwanted launch agents or login items enabled.
    :1010616
Reply

  • vlb wrote:

    I am having the same problem.  I have Mac Mountain Lion 10.8.

    I am sorry I do not understand these instructions.  Where do I find the Library/preferences?  I have not idea where to find these things to delete them.

    I also have no idea where the scan is stalling.  It does not show on the scanning page.  

    If there is a malicious virus or malwar interfereing wiht Sophos, then what?  I thought Sophos was supposed to protect me.

    VLB


    "go into ~/Library/Preferences/ (hold down option and select Library from the Finder's Go menu) and search for sophos" -- the other Library folder is at the root of your computer, next to the Applications and System folders.

    If you are scanning inside an archive file (which is where scans sometimes unexpectedly end if there's a problem), the file name will be listed below the progress bar.  If there's nothing there, then you probably just need to uninstall and reinstall the product (and restart your computer).

    For some users, this problem may be related to http://www.sophos.com/en-us/support/knowledgebase/118516.aspx
     -- note: this KBA is released for Enterprise products, so some of the terminology or path details may not be fully accurate for the Home product.

    If there is software interfering with Sophos, either Sophos or the other software will need to be uninstalled.  For example, it is generally not a good idea to have multiple AntiVirus programs running at the same time; they could prevent each other from correctly scanning for malware.  A test for interfering software is to restart your computer with the shift key held down, and then run the on-demand scanner.  If it's a configuration issue or the installation is damaged, this will fail to run.  If it's being interfered with by third party software, it should run -- at which point you need to start investigating launch daemons and login items to see what else is running alongside Sophos that has low-level access to the entire file system of your computer.

    In the unlikely event that you are hit with malware that intentionally disables Sophos, we would likely receive multiple submissions of this software in very short order and release an advisory regarding it.  There is currently a proof of concept that attacks Sophos Anti-Virus 8.0.6 and earlier via a malicious PDF file, but it is not in the wild, and will not function on 8.0.8 and later.

    If you feel that something malicious has made it onto your computer and is actively avoiding detection by Sophos, first try

    1. restart the computer with the shift key held down and log in using an account with administrator priveleges (if you only have one account, it has them)
    2. Launch Terminal.app (it's in the Utilities folder) and type "sudo sweep /" and enter your login password when prompted.
    3. If the software functions and finds no malware, you likely just have something conflicting.  Get someone with a bit of in-depth OS X knowhow to remove any launch agents or login items that may be causing the problem.
    4. try uninstalling the software and installing a different AV solution.  If this also fails to operate correctly, you best bet is to follow Apple's instructions to restore from your restore partition. 
    5. If it operates correctly and fails to find anything malicious,  it's up to you which of the above steps you take.  Most likely you just need to ensure your preferences files are all uncorrupted, you have a clean install of Sophos, and you don't have unwanted launch agents or login items enabled.
    :1010616
Children
No Data