Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos AV Mac Edition 7.3.5C - hangs trying to clean up non-existent file?

Since I came back this afternoon (family have been using the Mac), SAV keeps popping up a message to say it has detected a threat. When I open the quarantine manager, it says the threat is Mal/KeyGen-M and the filename is '...'

Under threat details, for the Path and Filename is says "To view all components of the threat, you must authenticate as an administrator", and under Action Available is says "The threat can be cleaned up". However, when I authenticate as admin, the Path and Filename is still blank. If I then choose the clean up the threat, quarantine manager says "Cleaning up threats", shows me a progress bar and then goes no further. Even leaving iot for an hour or more this window doesn't go anywhere and the only way out of it is to Force Quit the app. Later on the message pops up again and so the cycle repeats.

I have noticed the following console messages for Sophos:

25/11/2011 21:51:34.910 com.sophos.notification: 2011-11-25 21:51:34.909 SophosAVAgent[1331:207] <IPCConnection: 0x429200> exception raised in delegate's message handler: *** -[__NSArrayM insertObject:atIndex:]: object cannot be nil

25/11/2011 21:52:42.953 com.apple.SecurityServer: Failed to authorize right 'com.sophos.cleanup' by client '/Library/Sophos Anti-Virus/SophosAntiVirus.app' [1084] for authorization created by '/Applications/Sophos Anti-Virus.app' [1302]

25/11/2011 22:12:37.319 com.apple.launchd.peruser.501: ([0x0-0x42042].com.sophos.sav[1302]) Exited: Terminated: 15

Any ideas - is this a false alarm of some sort, and if not how can I find out what file SAV is complaining about and how to clean it up?

:1004577


This thread was automatically locked due to age.
Parents
  • Just wanted to provide an update on where I got to with this.

    I noticed that every time the message popped up to say a threat had been found, OSX 10.7 Time Machine was actively backing up. Unfortunately the details I found when looking at the Quarantime Manager were still no more helpful than before, with "...," being all that was shown in the path/filename for the suspect file(s).

    I assumed that 'on access' scanning might be checking one or more files it felt were questionable so I erased my Time Machine backup disk and started Time Machine backing up from scratch. This appears to have fixed the problem as I haven't seen the warning message since doing this a few days ago.

    So it looks like my problem is solved for now. I still don't know why SAV had a problem showing me which files were problematic or why full scans appeared to fail, but for now I'm just happy the messages have gone away.

    Many thanks for your assistance and patience.

    :1004665
Reply
  • Just wanted to provide an update on where I got to with this.

    I noticed that every time the message popped up to say a threat had been found, OSX 10.7 Time Machine was actively backing up. Unfortunately the details I found when looking at the Quarantime Manager were still no more helpful than before, with "...," being all that was shown in the path/filename for the suspect file(s).

    I assumed that 'on access' scanning might be checking one or more files it felt were questionable so I erased my Time Machine backup disk and started Time Machine backing up from scratch. This appears to have fixed the problem as I haven't seen the warning message since doing this a few days ago.

    So it looks like my problem is solved for now. I still don't know why SAV had a problem showing me which files were problematic or why full scans appeared to fail, but for now I'm just happy the messages have gone away.

    Many thanks for your assistance and patience.

    :1004665
Children
No Data