jigglypuffs mic

Q: malware in quarantine, but clean up failed

Hi Guys!

I've been using Sophos as an extra barrier to keep my I-Mac clean. (I was a PC user in another life) Sophos identified a Mal/Fake Av-IS or a gift.exe that it has quarantined. The problem is, Sophos failed to clean it up. I know this is more a Sophos question than an Apple Support issue but....you guys are verrrrry good at what you all do. Perhaps the community can reassure me that even though the malware is quarantine, I won't see any performance issues. All suggestions or comments are welcomed. Thanks!!  JPuff

i-mac

Posted on Aug 6, 2014 2:10 PM

Close

Q: malware in quarantine, but clean up failed

  • All replies
  • Helpful answers

Previous Page 2
  • by WZZZ,

    WZZZ WZZZ Aug 8, 2014 6:05 AM in response to R C-R
    Level 6 (13,112 points)
    Mac OS X
    Aug 8, 2014 6:05 AM in response to R C-R

    Like you, the only place I ever see it writing files to the logs is when it updates, which I have set for every 12 hours, in /Library/Logs/.

     

    With 10.8.5, I'm seeing no appreciable slowdowns and I have everything enabled. On the Sophos forums, I am hearing of problems with 10.9, but I think they may have those ironed out by now.

     

    I agree that it may not be needed (I never see any malware getting quarantined, including even Windows stuff), but I don't see it causing any issues. There is this article (pdf) describing how some AV may, paradoxically, increase rather than decrease the exposure to malware, but its concerns are far too abstract and hypothetical. If it could be shown that this is really happening, I'd be much more concerned.

  • by MadMacs0,

    MadMacs0 MadMacs0 Aug 8, 2014 11:28 AM in response to R C-R
    Level 5 (4,791 points)
    Aug 8, 2014 11:28 AM in response to R C-R

    R C-R wrote:

     

    So does that mean you have more than one AV software product installed on your Mac at the same time? Is it possible they were interfering with each other in some way?

    I believe the current number is six and all but Sophos and ClamXav are totally passive with no background processes running at all. Like Sophos, ClamXav is only updating definitions and only once a day. I'm confident there was no interference involved with those two incidents. Just a runaway process and since Sophos updates itself, it could have been a bug that required a re-install, but I could not find documentation of it anywhere.

     

    There have been verified reports of MacKeeper and Avast! detecting ClamXav signature updates as infected once in awhile. It happens as an incremental update is being unpacked and integrated into the database, so I suspect it's a case of both scanners using the same or similar signatures. Once the update process is complete the complete database is no longer found to be infected. I don't have either installed for that and a few other reasons.

  • by WZZZ,

    WZZZ WZZZ Aug 8, 2014 1:30 PM in response to MadMacs0
    Level 6 (13,112 points)
    Mac OS X
    Aug 8, 2014 1:30 PM in response to MadMacs0

    It's been updated to 9.0.11. Maybe that will run better now.

  • by MadMacs0,

    MadMacs0 MadMacs0 Aug 8, 2014 1:54 PM in response to WZZZ
    Level 5 (4,791 points)
    Aug 8, 2014 1:54 PM in response to WZZZ

    WZZZ wrote:

     

    It's been updated to 9.0.11. Maybe that will run better now.

    As I said, this was months ago. If I had to guess I would say the first was with v8 on Mountain Lion and the second an early version of v9, probably with Mavericks.

     

    You are correct that there were reports of issues with Mavericks, but I couldn't verify any of what was being said and I don't recall seeing a recent report of that for some time now.

  • by jigglypuffs mic,

    jigglypuffs mic jigglypuffs mic Aug 17, 2014 3:44 PM in response to jigglypuffs mic
    Level 1 (0 points)
    Aug 17, 2014 3:44 PM in response to jigglypuffs mic

    Guys: thanks for the replys. I got the gift.exe from the Pearl Jam Ten Club web site downloading a PJ recording. So, as far as my I-Mac performance, its still stellar. Although my kid was on his Pokemon website today on my I-Mac and got a Norton notice claiming we must download to clean up my computer. I cancelled the screen and I am running Sophos. I'm kinda torn about whether to keep Sophos or not. Thanks to all of you once again!! Keep up the good work!!

  • by Allan Eckert,

    Allan Eckert Allan Eckert Aug 17, 2014 3:48 PM in response to jigglypuffs mic
    Level 9 (53,919 points)
    Desktops
    Aug 17, 2014 3:48 PM in response to jigglypuffs mic

    I suggest that you uninstall Sophos.

     

    You don't have Norton installed do you?

     

    That is even worst the Sophos.

  • by rkaufmann87,

    rkaufmann87 rkaufmann87 Aug 17, 2014 8:06 PM in response to jigglypuffs mic
    Level 9 (58,875 points)
    Photos for Mac
    Aug 17, 2014 8:06 PM in response to jigglypuffs mic

    Macs are not MS Windows boxes that require antivirus software, on a Mac not only are the unnecessary they tend to create more problems than they solve. Whatever antivirus or performance enhancing OS X app you have installed, locate the developers instructions for uninstalling and uninstall.

  • by MadMacs0,

    MadMacs0 MadMacs0 Aug 17, 2014 8:15 PM in response to jigglypuffs mic
    Level 5 (4,791 points)
    Aug 17, 2014 8:15 PM in response to jigglypuffs mic

    jigglypuffs mic wrote:

     

    my kid was on his Pokemon website today on my I-Mac and got a Norton notice claiming we must download to clean up my computer.

    Totally bogus. Just a FUD ad from Norton since there is no way to scan anything on your hard drive from a web site. You did the right thing to cancel it, now ignore it and you'll be fine.

Previous Page 2