Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

TROJAN/ZBOT-GGD AND GGM

Hi. 

I was advised this morning that Sophos had detected 2 threats on my Mac - Trojan/Zbot-GGD and GGM.  Looking up these threats on the internet, it says that the affected operating systems are windows.  I don't have windows.  I used the anti-virus to clear up these threats - and all seems to be ok.  I am just interested in learning more about this, as I really am ignorant is this area.  Any advice or comments would be great.  Many thanks. 

:1013909


This thread was automatically locked due to age.
  • Hello kimmo,

    any decent AV will alert you about the threats it finds (when it happens to stumble over them) even if they won't affect your OS the OS it is running on. You might run an emulator, you might run this other OS on the same computer, you might have it on another one - and last but not least, you could pass the threat on (it is regularly argued by some that others should take care of themselves and bad luck if they have no AV or an AV which does not, perhaps only yet, detect the threat - while others opine alerting about/dealing with "xenogenic" threats the conscientious thing to do).

    Whether the AV detects them in the first place is another thing - it depends on the vector (e.g. a threat might be specific to Windows but contained in a Java archive or a PDF - as both could contain threats to Mac OS as well they will be scanned), the detection data (vendors/volunteers providing protection for several platforms usually don't subset their data). what's considered as potentially executable or potentially harmful and last but not least, whether the above is taken into account. Sophos does (to a certain extent) scan cross-platform files (like Windows executables) and thus it detects these ZBot variants.

    HTH

    Christian

    :1013917
  • Thank you so much for this reply!
    :1013919
  • Maybe the file is located in a System folder or another user's home folder.  It doesn't know who's looking at the screen so is hiding it?

    :1013927