Reply
Visitor
lorczy
Posts: 1
Registered: ‎02-25-2011
0

cleaned malware manually - threat gone but files still there

I found 6 threats when I ran Sophos the first time. I followed PhilCat's instructions on how to manually remove them. It removed the file names in the quarantine, 

 

but the files that were said to be a threat are still on my computer. I ran another scan just on the Java cache where they were and it said there were no threats.

 

So was a threat removed that was attached to those files?

Anyone have an explanation for this?

 

thanks,

lorczy

Employee
Agile
Posts: 1,191
Registered: ‎11-02-2010
0

Re: cleaned malware manually - threat gone but files still there

Some threats are Trojans or worms, and as such, the actual files are malicious and must be deleted.  In other cases, the threats are viral or archived, in which case only the threat needs to be removed; the file the threat is hiding in can often be left alone.

 

So if the files were flagged as a threat and now they aren't, it's likely the case that the malicious part has been removed, leaving you with all the non-malicious parts.

-
Andrew
Threat Researcher
SophosLabs


For our other self-service and peer-to-peer online support systems: