I am unable to delete malware; I have upgraded Sophos as well. Please see attached file.
This thread was automatically locked due to age.
I am unable to delete malware; I have upgraded Sophos as well. Please see attached file.
Again I ask how to I get rid of this virus as the app cannot I have it showing in finder in a download folder for which it says I have no access. I have to gain access via get info but cannot get at the suspect file. Help requested.
GH
sandy wrote:Hello gjh,
if you read the full message you will see that it clearly states "Automatic cleanup was not successfu. Manual cleanup required". (My red)
For a description of how to do this, please follow this article exactly https://www.sophos.com/en-us/support/knowledgebase/118117.aspx
You can also do a search on this forum for 'manual cleanup' which will provide lots of information.
Hi gjh,
just taking a quick look at the screenshot you sent over shows me that the file in question (/Users/gjheth/Downloads/download.dmg) has been backed up onto a time machine backup that is stored on a removeable hard drive (I see reference to both a Goflex as well as a My Passport). In order to clean the threat, you'll need to make sure those drive(s) are available. Can you confirm this?
Ok, cool. Now you can follow the steps below, and let me know how you get on? (taken from this KB article)
Thanks,
Not all the path is available in the quaratine window and when I go to 'reveal in finder' I am taken to a download folder in the backup hard drive (in this case goflex) but it says I do not have permissions to open the folder. I went to "get info" it says I have no access, even though I have selected "everyone read and write". Please see attachment.
Thanks for your continued interest,
gjh
It looks like you tried to acces the file from withih Finder, but you won't be able to access the backup files from Finder because Time Machine manages the permissiosn so users can't accidentally mess with their backups. You have to go into Time Machine to remove the file.
Please take a look at steps 3-6 in my last message - essentually what you're going to do is:
1. Open finder and navigate to /users/gjheth/downloads
2. Click the time machine icon (small circle with a clock icon in the top right corner) and choose Enter time machine
3. From within time machine, alt click download.dmg and select Delete all backups of download.dmg
Note: If download.dmg is not available under "Now", you may need to go back in the time machine until you find a copy of the file. Then proceed to Delete all backups of download.dmg
4. When prompted click ok, and enter your password
5. When complete you can cancel out of Time Machine
6. Make sure you re-enable on-access scanning once you're done