This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Indestructible virus Mal/Phish-A

Sophos detected a virus Mal/Phish-A is located in the file "containers” of a "Library”. Sophos seems unable to Clean Up Threat. I am administrator of this machine, but the access of "containers” is forbidden for me. How could I get rid of yhis virus?

I use Mac OS X.9.3 on a MacBookPro.

:1018229


This thread was automatically locked due to age.
Parents
  • "perhaps the threat HAS been cleaned up". Nope, I go to Quarantine Manager and it's still there. 

    Everytime that I run a scan now, I get an error saying something along the lines of the scan was not able to be completed. So now the scans don't work, the clean up process doesn't work, the reveal in finder doesnt work.

    NOTHING WORKS!!!!!!! AT ALL. WITH THIS SOFTWARE. doesn't really make me want to buy the paid version. And I just left Mac

    I used your trick with Command F to find the path of ONE of the threats. (the "Mal/Phish-A" threat). I successfully deleted it just now. The file was InstantBooster.htm (in a folder called 2 which came from my Mail app) and there is a folder right underneath it called 3 and in it is a text file that says mentions unsubscribing from www.advertise-bz.cn (whoever the hell that is) so it makes me wonder if Advertise-bz.cn is the culperate of that virus.

    Onto the next threat.... another Mal/Phish-A threat (even though there was only ONE Mal/Phish-A listed in the quaranteen manager, not two)... this one is LinkDirectorySubmitter.htm.... and sure enough, a folder accompanying it....www.advertise-bz.cn

    Another one called FeedBlaster.htm

    and BlogBlaster.htm

    HitBooster.htm

    dataentryjob.htm

    cashcreation.htm

    I'm having to create a filter in gmail to send ALL messages from admin2@advertise-bz.cn  and admin@advertise-bz.cn  straight to the trash. I dont really like to use the Mail app... only gmail on my browser because I feel like the Mail app is too stupid to prevent you from these downloads getting on your computer.

    Then I continue that Command F search in the log to get the threat, the Troj/PHPBdoor-T treat, and this is what the log shows me..... so does this threat still exist? It must if its showing up in the list but I cant find the file path....

    com.sophos.intercheck: 2014-06-21 19:58:56 -0500 Threat: 'Troj/PHPBdoor-T' detected in
    com.sophos.intercheck: Access to the file denied
    com.sophos.intercheck:
    com.sophos.intercheck: 2014-06-21 20:02:17 -0500 Threat: 'Troj/PHPBdoor-T' detected in
    com.sophos.intercheck: Access to the file denied
    com.sophos.intercheck:
    com.sophos.intercheck: 2014-06-21 20:07:51 -0500 Threat: 'Mal/Phish-A' detected in
    com.sophos.intercheck: Access to the file denied
    com.sophos.intercheck:
    com.sophos.intercheck: 2014-06-21 20:13:53 -0500 Threat: 'Mal/Phish-A' detected in
    com.sophos.intercheck: Access to the file denied

    :1018263
Reply
  • "perhaps the threat HAS been cleaned up". Nope, I go to Quarantine Manager and it's still there. 

    Everytime that I run a scan now, I get an error saying something along the lines of the scan was not able to be completed. So now the scans don't work, the clean up process doesn't work, the reveal in finder doesnt work.

    NOTHING WORKS!!!!!!! AT ALL. WITH THIS SOFTWARE. doesn't really make me want to buy the paid version. And I just left Mac

    I used your trick with Command F to find the path of ONE of the threats. (the "Mal/Phish-A" threat). I successfully deleted it just now. The file was InstantBooster.htm (in a folder called 2 which came from my Mail app) and there is a folder right underneath it called 3 and in it is a text file that says mentions unsubscribing from www.advertise-bz.cn (whoever the hell that is) so it makes me wonder if Advertise-bz.cn is the culperate of that virus.

    Onto the next threat.... another Mal/Phish-A threat (even though there was only ONE Mal/Phish-A listed in the quaranteen manager, not two)... this one is LinkDirectorySubmitter.htm.... and sure enough, a folder accompanying it....www.advertise-bz.cn

    Another one called FeedBlaster.htm

    and BlogBlaster.htm

    HitBooster.htm

    dataentryjob.htm

    cashcreation.htm

    I'm having to create a filter in gmail to send ALL messages from admin2@advertise-bz.cn  and admin@advertise-bz.cn  straight to the trash. I dont really like to use the Mail app... only gmail on my browser because I feel like the Mail app is too stupid to prevent you from these downloads getting on your computer.

    Then I continue that Command F search in the log to get the threat, the Troj/PHPBdoor-T treat, and this is what the log shows me..... so does this threat still exist? It must if its showing up in the list but I cant find the file path....

    com.sophos.intercheck: 2014-06-21 19:58:56 -0500 Threat: 'Troj/PHPBdoor-T' detected in
    com.sophos.intercheck: Access to the file denied
    com.sophos.intercheck:
    com.sophos.intercheck: 2014-06-21 20:02:17 -0500 Threat: 'Troj/PHPBdoor-T' detected in
    com.sophos.intercheck: Access to the file denied
    com.sophos.intercheck:
    com.sophos.intercheck: 2014-06-21 20:07:51 -0500 Threat: 'Mal/Phish-A' detected in
    com.sophos.intercheck: Access to the file denied
    com.sophos.intercheck:
    com.sophos.intercheck: 2014-06-21 20:13:53 -0500 Threat: 'Mal/Phish-A' detected in
    com.sophos.intercheck: Access to the file denied

    :1018263
Children
No Data