Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Manual Cleanup - Having no effect! HELP!!!!

Hi,

Recently opened a webpage sent by my university, which has infected my mac with both a Troj/Keygen-GZ and a Mal/Phish A.

These, are both limited to Windows (according to Sophos), but I want them off both my harddisk and by backup in Timemachine.

I have tried to follow the procedure listed, but I can't seem to get to the point where I can delete these files. I have tracked down the volume path, navigated to it, but then can't get Sophos to do what it can do, according to the advice and FAQ.

HELP!!!! I know I probably sound really stupid - but I just can't seem to crack this one.

Cheers :manhappy:

:1010750


This thread was automatically locked due to age.
  • Mal/Phish-A isn't actually imited to Windows, as it's a social engineering attempt, usually found in emails (and sometimes on web pages).  It doesn't actually "infect" your computer, it just pretends to be something reputable (like an email from your university) while in fact being from someone else, and trying to get you to download something malicious or to capture personal information (student ID, name, phone number, credit card info, etc.).

    Check that email from your university, and view the message source.  You will likely find that while the From: lists someone at your university, the Received: headers will indicate it came from somewhere else.

    Within Time Machine, you'll need to navigate to the path where the file is listed, then control-click the file and delete all backups of the file.  Do this AFTER temporarily disabling on-access scanning, so Sophos doesn't prevent the deletion of the file.

    Does this help?

    :1010798