This thread was automatically locked due to age.
Hello Joseph,
Mal/Generic-S - please submit a sample for Mal/Generic-S detections, especially if system files are flagged.
High risk website blocked popup - the popup is usually for elements of a page where it's not possible to display the substitute page/frame. when I'm not browsing the web - the browser is not open at all or is it idling? If the latter, it could be a script (e.g. "serving" ads) on one of the pages displayed or a rogue add-on.
Christian
Hello Joseph,
so it has been moved to the INFECTED folder (not ideal if it's important for windows functioning)? Has it been moved from the \Windows\system32\ folder or some other location? If the latter the detection is likely correct. I don't have permission - did you get another Sophos alert (this time for the .000 file in the INFECTED folder)? If so it might be necessary to (temporarily) exclude it (or *.000 files) from scanning. I don't think it is locked if it could be moved.
website popups
I've seen such alerts on legitimate (and in principle clean) sites caused by ads or remote (third-party) content. If you constantly get alerts (e.g. when this Community is your only open page) then there's probably "something" on your system. If it's only certain sites and only as long as you stay on them there's likely no immediate danger but you should nevertheless be careful.
Christian
Hello Joseph,
from program data
ah, this is not the place where a Windows component should reside, makes it pretty certain it's malicious. BTW - you shouldn't log in for everyday work with an admin account, too easy for a threat to take root. Do you still get the Blocked notifications?
Now as to the upload: Open the Sophos GUI, Configure -> Anti-Virus -> On-access scanning -> in the pop up window tab Exclusions -> Add. As Item type select File, enter either the full name FntCache.dll.000 or *.000 as Item name, confirm with Ok.. This should enable you to upload the file.
Christian