Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Troj/Zbot - HAD

Hi everybody,

I am using Sophos Anti-Virus 8.0.20C on the Mac and I am having a very annoying alert recurring constantly throughtou the day.

I have an alert come up saying that it has detected the Troj/Zbot - HAD (sometimes the HAD is replaced with something else).  So I open up Quarantine Manager and Authenticate to be able to remove it, but as soon as I have authenticated, the threat in the window disappears without giving me a chance to clear it.

This has been going on for weeks and I have run the full scan of the machine a number of times, which comes up clean, but it keeps coming up.

Does anyone know why this is and how I can stop this happening?

UPDATE - I have since truned off the Scan inside archives and compressed files option in the preferences pain as suggetsed on another post but this hasn't solved the issue.

:1014787


This thread was automatically locked due to age.
Parents

  • dakotaspurs wrote:

    I have 2 warnings, I go to them in quarantine manager and there is no thread identifying where they are.  So I select them and click Clean Up Threat, and then it just spins for ages saying Clean Up In Progress ... never actually cleaning anything up!


    This now sounds like the detection is an item in the Time Machine backup or an email - something it can scan, but can't delete.

    Go back to console and location what is detected (the Quarantine Manager may not show the item, but the log should).  Watch/listen to the videos below as they should help explain what to do.

    :1015419
Reply

  • dakotaspurs wrote:

    I have 2 warnings, I go to them in quarantine manager and there is no thread identifying where they are.  So I select them and click Clean Up Threat, and then it just spins for ages saying Clean Up In Progress ... never actually cleaning anything up!


    This now sounds like the detection is an item in the Time Machine backup or an email - something it can scan, but can't delete.

    Go back to console and location what is detected (the Quarantine Manager may not show the item, but the log should).  Watch/listen to the videos below as they should help explain what to do.

    :1015419
Children
No Data