Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Troj/Bredo-ACC-Sophos warnings coming up 8-10 times a day!

Since the past couple of weeks Sophis has popped up a warning about the Troj/Bredo-ACC virus and it is always in a different path/place. Since I have Sophos set to automatically clean up the threat, it disappears within a couple of seconds. I ran a complete scan of the HD and backup HD with nothing coming up. Yet this is continuing. The last position of the bit was in my Agile 1Password folder. I'm running OS 10.7.4 with the latest Sophos.

What in the world is this creepy trojan thing and why won't it go away?

:1010092


This thread was automatically locked due to age.
  • I too am recieving multipal warnings - Troj/Berdo-anc - file name is aa_ticket_Print_document.zip.  that document does not exist on the computer.  HELP  Runing Mac 10.7.5 with a University updated version of Sophos.

    :1010194
  • Does anybody know what this thing is and how to get rid of it? A full scan of the HD reveals nothing, This thing pops up in a different place 15 times or more a day, the path is different almost all the time. Quarantine Manager opens up, I see the threat and the path, then it disappears from the window. Where is it coming from, it is a Windows Trojan, yet like a microbe keeps trying to find a place to plant itself on my Mac. Can it be stopped? Am I constantly picking this up from the Junk Mail folder? Where is it coming from?

    :1010200
  • Thank you for the suggestions, however I had already checked that page. It is for Windows, this is a Windows-based Trojan and I'm on a Mac. The instructions for removing malware from a Mac do not apply in this case BECAUSE THE THREAT DISAPPEARS FROM THE WINDOW. Please  focus on the issue that is happening which is:

    1. Sophos pops up identifying the Troj/Bredo-ACC virus. 15+ times a day and in DIFFERENT locations.

    2. It disappears from the Sophos main window in 6-7 seconds. 

    3. If I am quick enough to unlock the lock icon and select "Clean Up Threat", Sophos goes into action, keeps running, nothing happens (after 20 minutes of letting it run) and I have to Force Quit Sophos.

    4. Troj/Bredo keeps popping up in different locations. Mail, my Library, etc. basically in different parts of the system.

    Since this is a Windows malware, is there something about the Mac version of Sophos that just doesn't know how to clean it up? If it disappears from the window I have no time to note the full path to go in and locate the item manually.

    Do you have other suggestions?

    :1010212
  • Just want to add that when I perform a full scan, Sophos says my system comes up clean. 0 threats. Yet this keeps happening. One possibility that occurs to me after reading a few other posts is that Sophos might be up malware in email that goes into Junk folder that I move to my server's learn_spam folder. Once this moves off the system, perhaps Sophos still picks up something.

    Yet that possibility doesn't make sense when I see the path is not in Mail, but somewhere in the system, like the Library.

    :1010214
  • I'm finally back on the forums, and can put your mind at ease fairly quickly I hope...

    Bredo is an email-based malware attack targeting Windows machines via infected zipped executables.  So your initial theory is probably correct.

    That said, if you're seeing Bredo identities show up in non-mail folders, please note the file name and path -- my guess is that it's being detected in cache folders and temporary library locations, but without the paths, I couldn't say for sure.

    If you're using IMAP to connect to your mail server, it is possible that the same malware is being downloaded and detected again and again, resulting in a constant detect/clean cycle.

    Personally, I recommend not setting AV products to automatically delete -- quarantine and move is usually good enough, and quarantine in place is generally all you need to do.

    :1010248