Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Removal of Threat found on my iMac

Hi, after running my first SOPHOS scan a threat called Mal/Behav-285 has appeared in Quarantine Manager.  My own research suggests that this malware only affects the Windows OS and so I am confused as to why/how it has appeared on my iMac?  Other info in Quarantine Manager says Filename  "$R75IUL9.rar"  and "Cleanup failed".  Is there any need for me to be concerned and if so does anyone know how I should go about removing this threat?

:1017779


This thread was automatically locked due to age.
  • I downloaded the program and ran it - it took approx 2 hours.  Roughly half-way through, "Issue detected" appeared on the left side.  At the end of the scan, I clicked on "Quarantine manager" and there was nothing there.  What do I do?  Thank you (First time post)

    :1017803

  • Songbird56 wrote:

    Hi, after running my first SOPHOS scan a threat called Mal/Behav-285 has appeared in Quarantine Manager.  My own research suggests that this malware only affects the Windows OS and so I am confused as to why/how it has appeared on my iMac?  Other info in Quarantine Manager says Filename  "$R75IUL9.rar"  and "Cleanup failed".  Is there any need for me to be concerned and if so does anyone know how I should go about removing this threat?


    As you mention it is a Windows threat.  Hence your Mac can't be infected/affected by it but since SAV for Mac scans for Windows and Mac malware, if the file exists on your Mac you will be alerted to it.

    I'd suggest clearing the item from the Quarantine Manager and running a scan of your computer.  If the detection comes back you can see where the item is located (folder path) and see if cleanup now works.  Often files are detected in a browser's cache or a spam email attachment and having detected the malware another program or the operating systm removes (empties) the folder containing it - leaving SAV referencing a file that no longer exists.

    :1017831

     - - - - - - - - - - - -

    Communities Moderator, SOPHOS
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.


  • sfoklnd wrote:

    I downloaded the program and ran it - it took approx 2 hours.  Roughly half-way through, "Issue detected" appeared on the left side.  At the end of the scan, I clicked on "Quarantine manager" and there was nothing there.  What do I do?  Thank you (First time post)


    Your referring to the 'Issues detected' message.  There are plenty of post on here about this.  Also there is a video on our YouTube channel:

    :1017833

     - - - - - - - - - - - -

    Communities Moderator, SOPHOS
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • Ran mine for the first time with the "issue detection." The only file it flagged was an encrypted file related to the installer for Adobe Acrobat. I'm presuming that isn't something to be concerned about. But the video doesn't make clear what files we should be on the lookout for. 

    Neil

    :1017857

  • neilb422 wrote:

    the video doesn't make clear what files we should be on the lookout for. 


    Could be a lot of things.  The video mentions (1) a file in Trash that isn't formatted correctly; (2) a USB pen drive that was unplugged during the scan; (3) encrypted files; (4) corrupt files.

    That gives you four things to be on the look out for.  If you find more, and they are common, pls post.

    :1017871

     - - - - - - - - - - - -

    Communities Moderator, SOPHOS
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?