Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Threat (Troj/Invo-Zip) comes back after manually deleting it from Time Machine backup. What now!?

I've been having an issue with this detected threat:

threat.png

Every time I open the Quarantine Manager I see this threat in the list, but after a few seconds it disappears by itself before I have the chance to do anything about it.

I suspect the reason is that it has only been existing in my Time Machine backup, so I followed the steps from a thread in this forum about how to manually remove threats from TM backups.


In my case I have found out that the location for my threat seems to be in my mail 'Junk folder'. Through the Sophos Anti-Virus.log I found the pathway to where this threat is to be found:

(please note that I've replaced my e-mail account information with XXXXXXX)

V2/POP-XXXXXXX@XXXXXXXX.XX@mail.XXXXXXXX.XX/Junk.mbox/12A0ABC9-74E3-4CAB-ADBD-31C5B00D9360/Data/3/Attachments/3612/2/invoice.zip

I used Finder to locate the exact place for this threat, entered TM and removed it from all TM backups.


I then believed that the issue was solved, until the threat started to pop up again a couple of days later.

What do do now? I would really appreciate some help with this so I can get rid of this nasty thing once and for all.

:1014693


This thread was automatically locked due to age.
Parents
  • I know that I am intelligent, because I know that I know nothing. - Socrates :smileyhappy:

    Screenshot is too small to make out what the quarantine is showing you, however I don't really need to see it.  I assume the path will be something SAV cannot delete from ('write access' required) or the item was saved there temporarily and is now gone (I'm saying that so you're not confused if you get to the end folder and it's empty).

    I'd suggest the way forward is to go back to the log (in Console) for the scan type that detected the items and getting the full path from there.  Use that to guide you.  Of course the 'reveal in Finder' button may also allow you to jump straight to the location - can't see in the screenshot if that's available after you click the padlock and select one of the items(?).

    Note:  If you encounter a hidder folder use the thread below to reveal it in Finder - I'm not saying this is necessary but just adding it in case you need to check a path that doesn't seem to be shown in Finder.

    http://openforum.sophos.com/t5/Mac-tools-help/How-to-show-all-hidden-files-in-Finder/td-p/18485

    :1018555

     - - - - - - - - - - - -

    Communities Moderator, SOPHOS
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

Reply
  • I know that I am intelligent, because I know that I know nothing. - Socrates :smileyhappy:

    Screenshot is too small to make out what the quarantine is showing you, however I don't really need to see it.  I assume the path will be something SAV cannot delete from ('write access' required) or the item was saved there temporarily and is now gone (I'm saying that so you're not confused if you get to the end folder and it's empty).

    I'd suggest the way forward is to go back to the log (in Console) for the scan type that detected the items and getting the full path from there.  Use that to guide you.  Of course the 'reveal in Finder' button may also allow you to jump straight to the location - can't see in the screenshot if that's available after you click the padlock and select one of the items(?).

    Note:  If you encounter a hidder folder use the thread below to reveal it in Finder - I'm not saying this is necessary but just adding it in case you need to check a path that doesn't seem to be shown in Finder.

    http://openforum.sophos.com/t5/Mac-tools-help/How-to-show-all-hidden-files-in-Finder/td-p/18485

    :1018555

     - - - - - - - - - - - -

    Communities Moderator, SOPHOS
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

Children
No Data
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?