This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Mal/Phish-A threat from mail keeps coming back

I have been dealing with this Mal/Phish-A threat for a couple of months now. I keep getting a Sophos Alert to clean this Mal/Phish-A threat and when I clean it up, it pops up again. At first after a couple of days, now sometimes multiple times an hour. Needless to say this makes work very difficult, and I am also scared that the safety of my (professional) Mac is compromised.

The threat appears to be an email attachment always called FullDetails.html. I read my mails using the Mac's Mail programme, and this particular account is a gmail account. I use the imap.gmail.com server to pull in email. 

The path of the threat is something like /Users/MYCOMPUTER/Library/Mail/IMAP-MYEMAIL@imap.gmail.com/[Gmail]/Alle berichten.imapmbox/Attachments/110344/2/FullDetails.html. I have tried the following:

Clean up the threat using Sophos

Scanning the computer (finding nothing every time) using Sophos after cleanup

Removing the attachments in Finder

Finding emails containing FullDetails.thml and removing the mails

Emptying out my trash immediately after

Threat keeps coming back. I don't know what to do. Please help!

:1015243


This thread was automatically locked due to age.
Parents
  • So you have found the mail in your junk folder and already deleted from there?...

    Screen Shot 2013-12-04 at 19.41.49.png

    Similar to this post.  Since it's an imap connection log into your gmail through a browser and delete the mail from there.  The video below mentions deleting threats that are in web mail boxes.

    :1015277

     - - - - - - - - - - - -

    Communities Moderator, SOPHOS
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

Reply
  • So you have found the mail in your junk folder and already deleted from there?...

    Screen Shot 2013-12-04 at 19.41.49.png

    Similar to this post.  Since it's an imap connection log into your gmail through a browser and delete the mail from there.  The video below mentions deleting threats that are in web mail boxes.

    :1015277

     - - - - - - - - - - - -

    Communities Moderator, SOPHOS
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

Children
No Data