This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Mal/Phish-A threat from mail keeps coming back

I have been dealing with this Mal/Phish-A threat for a couple of months now. I keep getting a Sophos Alert to clean this Mal/Phish-A threat and when I clean it up, it pops up again. At first after a couple of days, now sometimes multiple times an hour. Needless to say this makes work very difficult, and I am also scared that the safety of my (professional) Mac is compromised.

The threat appears to be an email attachment always called FullDetails.html. I read my mails using the Mac's Mail programme, and this particular account is a gmail account. I use the imap.gmail.com server to pull in email. 

The path of the threat is something like /Users/MYCOMPUTER/Library/Mail/IMAP-MYEMAIL@imap.gmail.com/[Gmail]/Alle berichten.imapmbox/Attachments/110344/2/FullDetails.html. I have tried the following:

Clean up the threat using Sophos

Scanning the computer (finding nothing every time) using Sophos after cleanup

Removing the attachments in Finder

Finding emails containing FullDetails.thml and removing the mails

Emptying out my trash immediately after

Threat keeps coming back. I don't know what to do. Please help!

:1015243


This thread was automatically locked due to age.
  • So you have found the mail in your junk folder and already deleted from there?...

    Screen Shot 2013-12-04 at 19.41.49.png

    Similar to this post.  Since it's an imap connection log into your gmail through a browser and delete the mail from there.  The video below mentions deleting threats that are in web mail boxes.

    :1015277

     - - - - - - - - - - - -

    Communities Moderator, SOPHOS
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • thanks for the suggestion, will check it out tomorrow and let you know if it worked.

    And to answer your question: yes I deleted the mail, but maybe it gets send again and again to my mail address, and a new threat is downloaded from attachments everytime.

    :1015289
  • Hi all,

    I would love to receive some more feedback on this issue. I am able to remove the threat from my computer, but I get new mails sent with this same virus every day, and I want to find a solution that does not involve me removing the mail after it's already downloaded to my computer.

    My Mac mail client downloads all mails and attachments to my computer, even if I don't open them. This means that the attachment I get sent everyday is downloaded automatically. I use gmail als mail client, but read all mails from the Mac mail client. Solution that's been suggested is 'catch' the email from gmail webmail, delete from there and after that open my mail client on the computer. However, this is not a real solution: I use the mail client on the Mac for reasons of efficiency and speed during my work and opening up and deleting mails from gmail everyday before the working day starts is not a real solution.

    I would like to hear if there is a way to prevent mails from arriving in my mail, or to permenantly delete mails upon arrival, without them being stored in inbox, trash or spam folder.

    Hope someone here has the solution!

    :1015701
  • You could submit the email as a spam sample:

    http://www.sophos.com/en-us/support/knowledgebase/23113.aspx

    :1015755

     - - - - - - - - - - - -

    Communities Moderator, SOPHOS
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • hi all,

    thx for thinking along, I have found a solution that seems to work.

    Quite simply actually: I unchecked the checkbox in the preferences panel in the mac mail client (accounts > advanced) 'Automatically download all attachments'. This way spam that's being sent to me containing virusses is not automatically downloaded and stored on my computer. 

    I have not had a Sophos alert since, but have still been receiving the spam mails. These are marked as spam now, and shipped of to my spam folder, which is automatically emptied after one day.

    :1015763
  • KUDOs!!!  This works!!!  Haven't received this SOPHOS quarantine threat SINCE we unchecked DOWNLOAD ALL ATTACHMENTS in MAIL preferences ADVANCED!

    :1015767
  • haha great that I've helped someone with this! Couldn't find a solution online anywhere, but by trial & error (aka blood, sweat & tears) problem was solved :)

    :1015769
  • I'm getting a Mal/Phish-A threat so I click reveal in finder and nothing happens!!! I clock clean up, and after many hours it says clean up failed. How do I remove this virus then???? Where is it originating from??
    :1018073
  • Is it an email?  Where is it located?  If a spam email keeps downloading to your Mac it's keep coming back.  If the item detected (or link to it) changes then the QM can fail to clean it up.

    :1018145

     - - - - - - - - - - - -

    Communities Moderator, SOPHOS
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • Kudo's for your persistence and final solution ! Yes , is very scary when your

    livlihood is on the line and you can't get an answer from anyone. I am very new 

    with MACbook pro, and see the whole system as dominos. Their attitude towards AV ,MalW, Spywr, is idiotic. I feel like with iPhone, MacBook, iPad,a person can be networked together and spyed on 24/7. The watch is one more

    network station. They will proudly say, "we don't reccomend any programs,you don't have to worry" 

    Is Obvious, no one has changed their passwords, or put 170 Partitions on a slow night!! If I were a theif, I  would look for expensive toys!  MacBook (2 or 3 times

    cost)

    Once Again, Congratulations!! 

    :1020973