Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Threat (Troj/Invo-Zip) comes back after manually deleting it from Time Machine backup. What now!?

I've been having an issue with this detected threat:

threat.png

Every time I open the Quarantine Manager I see this threat in the list, but after a few seconds it disappears by itself before I have the chance to do anything about it.

I suspect the reason is that it has only been existing in my Time Machine backup, so I followed the steps from a thread in this forum about how to manually remove threats from TM backups.


In my case I have found out that the location for my threat seems to be in my mail 'Junk folder'. Through the Sophos Anti-Virus.log I found the pathway to where this threat is to be found:

(please note that I've replaced my e-mail account information with XXXXXXX)

V2/POP-XXXXXXX@XXXXXXXX.XX@mail.XXXXXXXX.XX/Junk.mbox/12A0ABC9-74E3-4CAB-ADBD-31C5B00D9360/Data/3/Attachments/3612/2/invoice.zip

I used Finder to locate the exact place for this threat, entered TM and removed it from all TM backups.


I then believed that the issue was solved, until the threat started to pop up again a couple of days later.

What do do now? I would really appreciate some help with this so I can get rid of this nasty thing once and for all.

:1014693


This thread was automatically locked due to age.
Parents
  • Hi, ruckus.

    I done another scan and it found five threats (see screenshot). This time I have paths and filenames for all five. As I feared, the auto cleanup failed and I'm being instructed to clean up manually. Despite having watched the video you recommended, I'm afraid it's all about as clear as mud to me. I consider myself a fairly articulate and intelligent person but when it comes to this kind of thing my head starts to swim. Of course, the fact that the path is incomplete doesn't help but is there something obvious I'm overlooking? 

    Screen Shot 2014-07-29 at 21.03.04.png

    :1018553
Reply
  • Hi, ruckus.

    I done another scan and it found five threats (see screenshot). This time I have paths and filenames for all five. As I feared, the auto cleanup failed and I'm being instructed to clean up manually. Despite having watched the video you recommended, I'm afraid it's all about as clear as mud to me. I consider myself a fairly articulate and intelligent person but when it comes to this kind of thing my head starts to swim. Of course, the fact that the path is incomplete doesn't help but is there something obvious I'm overlooking? 

    Screen Shot 2014-07-29 at 21.03.04.png

    :1018553
Children
No Data
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?