This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Quarantine Manager Found Threat But Says Cleanup Failed. How To Remove?

I scanned my computer using the Sopho Anti-Virus program, and downloaded their "Removal Tool" and it detected on virus called: OSX/Geonei-A

I have no idea how to remove this threat. I thought that's what the tool was for. My computer is running VERY SLOW and I don't know what to do

Can anyone please help me? I am using a MacBook.

:1019899


This thread was automatically locked due to age.
  • I'd suggest starting with this article:

    http://www.sophos.com/en-us/support/knowledgebase/118117.aspx

    :1019904

     - - - - - - - - - - - -

    Communities Moderator, SOPHOS
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • I am on an iMac running Yosemite and have the free SAV for Mac Home edition Version 9.2.2   A scan has alerted me to 4 threats but I am unable to do anything as I cannot unlock the Quarantine Manager and have no record of any user name nor password, nor do I recall having a username or password, and have been frustrated at every turn when attempting to do anything about it.  This may not be the right place to raise this issue but I am at a total loss otherwise.  I would like to uninstall the SAV program and reinstall it but have not been able to accomplish that, either.  I'm sure a large part of the problem is my lack of knowledge and I would greatly appreciate any assistance anyone can provide.   Just trying out how to post this message has been an enormous task for me.   Thanks in advance for your help and suggestions.

    :1019929
  • I've read the article, but it doesn't tell me what to do with "Cleanup Failed." I tried following the instructions for a manual cleanup, but I can't trash the offening item. I get a message that says, "The operation can't be completed because backup items can't be modified."

    Also, the only way I can actually find the malware in the finder is by clicking on "Reveal in finder" in the Quarantine window. I took a screenshot of the path, only to find that it doesn't actually exist when I go looking for it. The path, once I get into the Library, is apparently Mail>V2>POP-[the email address to which it was sent]>Junk.mbox etc. But there's no POP[email address] or, for that matter, Junk.mbox to be found anywhere in the V2 folder …

    I'd be very grateful for any help on this issue. After several email exchanges with Sophos tech support and much studying of the knowledge base, I'm still unable to get rid of both this nasty piece of malware.

    :1020256
  • Hi. I am having a very similar problem. I am using Sophos for Mac version 9.1.8. I am working in 10.10.2. 

    When my troubles began the other day, I got a message from Sophos that a threat had been found (Troj/HTML) and that it would be cleaned up automatically. Yet when I looked in the quarantine manager it appeared as though no cleanup had been done (it was asking me what I want to do). Then it disappeared from the list. This happened three times over about an hour, at which point I got a message saying the cleanup had failed. When I tried to find the file (where it told me to go), no such folder existed. I've done a full scan of the computer umpteen times and it keeps telling me there are "issues" but no threats detected. There is nothing listed in the quarantine manager. Can somebody please help? Thanks.    

    :1020263
  • Hi Writty,

    Sorry to hear you're having trouble with this. I know you said you've already been speaking with support, so I'm sorry if you've already seen this, but it sounds like the threat might be in one of your backups, so here's a couple videos I think might help you do an effective manual cleanup. Oh, and this post has details on how to show hidden files and folders, just in case that helps.

    If that still doesn't help, I'd be curious to know more of what you see in the logs. Here's another video that shows how to look at those.

    Hope that helps!

    :1020283