Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Mal/Kuluoz-C recurring threat on iMac

Sophos detects every other day the same Kuluoz threat which burrows deep into my mail files as a "Royal Mail Tracking Label" zip.   Sophos then cleans up the threat, only for it to reappear two days later.  Anyone got any suggestions for removing it completely and blocking its reappearance?

:1007955


This thread was automatically locked due to age.
  • Are they new messages coming in, or do you keep on getting it detected every time you access the same mail folder?

    Deleting the Bredo spam message containing the zip attachment should fix the problem; you may need to delete it on your backups and via your web interface to your mail system as well, depending on your configuration.

    If you're on a Bredo mail list, unfortunately you're going to keep receiving these in your mailbox, with "Royal Mail/UPS/USPS/FedEx/Etc Tracking Label.zip" attachments.  You'll likely also get the "Airline reservation/notification" variant as well.  You can probably block these with a mail filter on the mail exchange side (ISP/webmail provider/etc.) so it never gets to your computer.

    :1007965