Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Threat (Troj/Invo-Zip) comes back after manually deleting it from Time Machine backup. What now!?

I've been having an issue with this detected threat:

threat.png

Every time I open the Quarantine Manager I see this threat in the list, but after a few seconds it disappears by itself before I have the chance to do anything about it.

I suspect the reason is that it has only been existing in my Time Machine backup, so I followed the steps from a thread in this forum about how to manually remove threats from TM backups.


In my case I have found out that the location for my threat seems to be in my mail 'Junk folder'. Through the Sophos Anti-Virus.log I found the pathway to where this threat is to be found:

(please note that I've replaced my e-mail account information with XXXXXXX)

V2/POP-XXXXXXX@XXXXXXXX.XX@mail.XXXXXXXX.XX/Junk.mbox/12A0ABC9-74E3-4CAB-ADBD-31C5B00D9360/Data/3/Attachments/3612/2/invoice.zip

I used Finder to locate the exact place for this threat, entered TM and removed it from all TM backups.


I then believed that the issue was solved, until the threat started to pop up again a couple of days later.

What do do now? I would really appreciate some help with this so I can get rid of this nasty thing once and for all.

:1014693


This thread was automatically locked due to age.
Parents
  • Hi.

    I'm a 54 year-old Mac user who has been using Macs for over 20 years now. I prefer Macs to PCs because I found that if I ever had a problem with the Mac  I could generally solve it even though I don't know that much about the inner workings of computers. 

    I recently downloaded Sophos for Mac OSX and did a complete scan which reported issues but no threats. At the time my Mac wasn't connected to my external hard drive. Upon connecting it to the hard drive in question Sophos identified two threats, one of which it successfully cleaned up. The other  - 'Troj/Invo-Zip' - I couldn't get rid of. Attempts to clean it up either returned a 'failed' message or ran for hours. On digging around the web and this site in particular, I realise I'm not the only one who has had this problem. I tried the various possible solutions suggested but nothing worked. In frustration, I eventually instructed the Quarantine Manager to 'clear from list' - my intention being to run another complete scan of my system AND external hard drive. Imagine my surprise then when the subsequent scan found nothing. Since I cleared it from the list I'm assuming it's hidden in my system somewhere and will resurface again at some point. If so, and I encounter the same problem in trying to clean it up what can I do? A manual clean up wasn't even an option first time around because there was no information on it - no path and filename or original location. Without this information, searching for it would be the computer equivalent of searching for a needle in a haystack. Any help would be much welcomed. Thanks.

    :1018545
Reply
  • Hi.

    I'm a 54 year-old Mac user who has been using Macs for over 20 years now. I prefer Macs to PCs because I found that if I ever had a problem with the Mac  I could generally solve it even though I don't know that much about the inner workings of computers. 

    I recently downloaded Sophos for Mac OSX and did a complete scan which reported issues but no threats. At the time my Mac wasn't connected to my external hard drive. Upon connecting it to the hard drive in question Sophos identified two threats, one of which it successfully cleaned up. The other  - 'Troj/Invo-Zip' - I couldn't get rid of. Attempts to clean it up either returned a 'failed' message or ran for hours. On digging around the web and this site in particular, I realise I'm not the only one who has had this problem. I tried the various possible solutions suggested but nothing worked. In frustration, I eventually instructed the Quarantine Manager to 'clear from list' - my intention being to run another complete scan of my system AND external hard drive. Imagine my surprise then when the subsequent scan found nothing. Since I cleared it from the list I'm assuming it's hidden in my system somewhere and will resurface again at some point. If so, and I encounter the same problem in trying to clean it up what can I do? A manual clean up wasn't even an option first time around because there was no information on it - no path and filename or original location. Without this information, searching for it would be the computer equivalent of searching for a needle in a haystack. Any help would be much welcomed. Thanks.

    :1018545
Children
No Data
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?