Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Warning about a threat (Mal/KeyGen-M) in Quarantine Manager popup goes away after a few seconds...

I just downloasded a trial version of SOPHOS for Mac yesterday. I'm running a real time virus scan on MacAir OSX 10.8.5. A couple of times the following has happened:

Quarantine Manager popped up, warning about a detected threat Mal/KeyGen-M. It has offered to clean it up. I didn't react quickly enough, and Quarantine Manager got cleared on its own, as if there were nothing detected at all. My "Open Preferences | Scan Local Drives | When a threat is found" == "Move threat" (/Users/Shared/Infected). I checked for Infected sub-folder under /Users/Shared. No such sub-folder. The only trace of the event I was able to find is in "/Library/Logs/Sophos Anti-Virus.log". Please see below. Was the offending keygen.exe file taken out by some other program, or by some "mothership" virus process?

I'd appriciate if somebody can comment of the "vanishing act" I'm observing.

----------From /Library/Logs/Sophos Anti-Virus.log-----------------------------------------------------

com.sophos.intercheck: 2014-01-23 13:28:18 -0800 Threat: 'Mal/KeyGen-M' detected in /private/var/folders/zz/zyxvpxvq6csfxvn_n0000000000000/T/.vbfolder_ybyuYV/keygen.exe
com.sophos.intercheck: Access to the file denied
com.sophos.intercheck:
com.sophos.intercheck: Encrypted file: /private/var/folders/zz/zyxvpxvq6csfxvn_n0000000000000/T/.vbfolder_VcqzJl/=?koi8-r?B?79TexdQgwdDSxczYIDIwMDkueGxz?=
com.sophos.intercheck: Encrypted file: /private/var/folders/zz/zyxvpxvq6csfxvn_n0000000000000/T/.vbfolder_y61uke/=?koi8-r?B?79TexdQgycDO2CAyMDA5Lnhscw==?=

:1015595


This thread was automatically locked due to age.
  • The path being...

    /private/var/folders

    ...sounds like it could be a cache of something like a web browser etc.  It is possible to experience detections (pop-up) and then the thing that was detected disappears on its own.  Like if you hit a web site and that has code in the page linking off to some other place/file.  The web cache having a bit of malware in it can cause an alert but then the cache is flushed before anything is moved.  The other thing that causes this is emails downloading from web mail.

    Generally nothing to worry about, but it can seem like you're chasing a ghost.

    :1015817