Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Troj/JSRedir

On a new IMac.. and timeMachine backing up to an external drive...

I keep getting a trojan alert for ftscft.html. as a Troj/JSredir

It calls for manual deletion...

If I exit out of Sophos and wait a few min.  It mysteriously disappears from the quarentine manager.

Im thinking this is a false positive.. and should just ignore it..  or is something else going on here?

:1004495


This thread was automatically locked due to age.
  • Check your web browsers... you likely have a web page ftscft.html open inside an iframe in another web page, and it likely has a JavaScript Redirect tag on it, which is being detected.  This will be cached to disk, and the On-Access scanner is detecting the cached copy.  As the temporary cache is flushed, the file will vanish from quarantine (no exit needed).  As the file is re-loaded into the cache, the detection will come back.

    This detection is often associated with SEO poisoned pages, so would show up in poisoned image search results, for example.

    :1004513
  • Ok.. but why does it only show up on a time machine backup?  Shouldn't it also be on my hard drive?  

    And it shows up in different directories on the backup... never same place.... and never more than once.  I would figure that it would also show up in several time machine backup times as well.

    I am assuming its harmless and should be ignored..   I have run a test... taking the time machine backup that found it and restoring that backup on my machine.. ran the scanner... and it didnt show up except on the time machine backup.

    :1004551
  • That's an interesting one... what kind of file was it that was being detected?  HTML?

    :1004553
  • it was an HTML file... ftscft.html

    :1004557
  • And did you verify that the file still existed locally when the scan was complete?  This definitely sounds like cache files being deleted by the system and sometimes cached by TimeMachine.

    In any case, it's likely not an FP, but also not anything to worry about too much, as it isn't actively doing anything malicious on your system.

    :1004559
  • I located the file and had to delete the whole backup folder for that day... we'll see if that works

    :1004561