<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title type="text">Sophos - trojan detected, now what?</title>
  <updated>2012-06-02T18:45:30+01:00</updated>
  <generator uri="http://framework.zend.com" version="1.12.20">Zend_Feed_Writer</generator>
  <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/768"/>
  <link rel="self" type="application/atom+xml" href="https://www.augwessex.org.uk/discussions/view/768/feed"/>
  <id>https://www.augwessex.org.uk/discussions/view/768</id>
  <author>
    <name>AUGW</name>
    <email>info@augwessex.org.uk</email>
    <uri>https://www.augwessex.org.uk/</uri>
  </author>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Sophos - trojan detected, now what?]]></title>
    <updated>2012-06-01T17:40:20+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/768#3379"/>
    <id>https://www.augwessex.org.uk/discussions/view/768#3379</id>
    <author>
      <name>Mark Ford</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">Just run Sophos as Euan suggested and it returned up this: Troj/JSRedir-BV in a file named YouTube Message,html [not a comma].<xhtml:br/>
I cleaned it up following the very clear instructions.<xhtml:br/>
Do I now need to run a check on the Time Machine files?  If so which ones I wonder.</xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: Sophos - trojan detected, now what?]]></title>
    <updated>2012-06-01T20:23:03+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/768#3380"/>
    <id>https://www.augwessex.org.uk/discussions/view/768#3380</id>
    <author>
      <name>Mark Ford</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">Well, Sophos must have gone on searching and a message has popped up saying that it has found the same trojan in the Time Machine backup. This time it says I have to remove it manually.<xhtml:br/>
<xhtml:br/>
The path to it is:  <xhtml:strong>Vol/Ext WD TimeMachine 550GB/Backup.backup/Mark Ford's iMac/2012-06-01-0956/Lion/Users/Mark/Library/Mail Downloads/YouTube Message.html</xhtml:strong><xhtml:br/>
<xhtml:br/>
Trouble is I can't find it!<xhtml:br/>
Searching in the Finder I loose the trail after  <xhtml:strong>/Mark/</xhtml:strong><xhtml:br/>
there it starts being different.     <xhtml:strong>/Library/Mail Downloads/YouTube Message.html</xhtml:strong>      are nowhere to be seen.<xhtml:br/>
I'm stumped, can anyone offer a way forward please?</xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: Sophos - trojan detected, now what?]]></title>
    <updated>2012-06-01T22:59:32+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/768#3381"/>
    <id>https://www.augwessex.org.uk/discussions/view/768#3381</id>
    <author>
      <name>Steve Ryder</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">Mark,<xhtml:br/>
<xhtml:br/>
This must surely reflect the fact that the User Library folder is invisible in Lion. You will have to try one of the tricks shown in http://www.macworld.co.uk/macsoftware/news/?newsid=3293365 in order to see this folder, and then find the file which you wish to remove.</xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: Sophos - trojan detected, now what?]]></title>
    <updated>2012-06-02T12:49:33+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/768#3383"/>
    <id>https://www.augwessex.org.uk/discussions/view/768#3383</id>
    <author>
      <name>Derek Wright</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">This is interesting  - on my Yahoo email address I have been receiving a lot of Youtube messages that have been trapped as spam and so not moved to the machine.<xhtml:br/>
<xhtml:br/>
I also think that the Gmail spam filter has been trapping them as well.<xhtml:br/>
<xhtml:br/>
Apologies for the thoughts</xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: Sophos - trojan detected, now what?]]></title>
    <updated>2012-06-02T18:45:30+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/768#3385"/>
    <id>https://www.augwessex.org.uk/discussions/view/768#3385</id>
    <author>
      <name>Mark Ford</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">Thanks Steve, I t does seem likely. I am busy backing up everything I can see to everywhere I have available because my machine is behaving badly (unrelated to this issue I think). When that is done I will see what I can find &amp; report..</xhtml:div>
    </content>
  </entry>
</feed>
