This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Threat with no filename/path, can't be removed. So what do I do?

I occassionally get entries like this in my log:

com.sophos.intercheck: 2013-09-20 13:17:37 -0400 Threat: 'Mal/DrodZp-A' detected in
com.sophos.intercheck: Access to the file denied
com.sophos.intercheck:

There is no filename/path ("detected in" is all the log says -- eol) so I can't view in finder and attempts to remove hang/fail as would be expected. If I remove from the quarantine list, it'll just show up again later.

I have Time Machine/Time Capsule and I suspect it's something in a backup file on that volume but that's just my wild guess -- it is weird that Sophos finds it, doesn't/can't indicate the location, offers removal as an option, but is unable to remove it.

  1. Anyone have any insight into what this is (the "no file/path" aspect of the result, not the trojan itself)?
  2. Recommended course of action?

I've searched a bunch on this forum and haven't seen a definitive explanation for the null filename/path.

Thanks!

:1013519


This thread was automatically locked due to age.
Parents
  • I have the same type of problem, specifically with a mal/generic-s file.  Additionally, I have some macs that are scanning that report "issues detected" but there is nothing showing up in the Quarantine Manager.  I have tried to clean up the mal/generic-s threat but it keeps failing.  I do not get an option message for manual removal.

    :1019333
Reply
  • I have the same type of problem, specifically with a mal/generic-s file.  Additionally, I have some macs that are scanning that report "issues detected" but there is nothing showing up in the Quarantine Manager.  I have tried to clean up the mal/generic-s threat but it keeps failing.  I do not get an option message for manual removal.

    :1019333
Children
No Data