Reply
Visitor
Yurika
Posts: 3
Registered: ‎10-14-2011
0

virus name

I made a mess: I was wandering around internet when Sophos detected a virus in the cache. As quickly as possible I deleted the cache, unfortunately in the confusion the virus name has disappeared and i don't remeber it. So I run a check on the whole Mac and it came out as free of viruses. My question is: how can I recover the name of the virus so that I can be sure it has been deleted? Thanks for the answer.
Employee lex
Employee
lex
Posts: 9
Registered: ‎11-12-2010
0

Re: virus name

You should be able to find the name of the file in your log file. The log file can be found under /Library/Logs/Sophos Anti-Virus.log.

 

HTH,

Alex

Visitor
Yurika
Posts: 3
Registered: ‎10-14-2011
0

Re: virus name

Thanks. I think i have found it: Threat: 'Exp/MS04-028' detected in /Users/belor/Library/Caches/Firefox/Profiles/wy7ah1ge.default/Cache/0/F1/BCBD4d01 What is it?
Employee
Agile
Posts: 1,191
Registered: ‎11-02-2010
0

Re: virus name

It's a JPEG GDI+ exploit for Windows: "Buffer Overrun in JPEG Processing (GDI+) Could Allow Code Execution (833987)"

Yes, you heard that right: unpactched Windows computers can get infected by viewing a JPEG image in a web browser.

-
Andrew
Threat Researcher
SophosLabs


For our other self-service and peer-to-peer online support systems:


Visitor
Yurika
Posts: 3
Registered: ‎10-14-2011
0

Re: virus name

Thanks ( a late thanks but whatever). I don't have any of the programs listed there and since the antivirus doesn't detect anymore I guess that's it. Thanks again.