The symptom I see is that the same malware is repeatedly detected and cleaned up, Malware detected: 'Mal/Phish-A' at '/' THREATJAN 2, 2016 12:42:34 PM Malware cleaned up: 'Mal/Phish-A' at '/' THREATJAN 2, 2016 12:38:45 PM Malware cleaned up: 'Mal/DrodZp-A' at '/' THREATJAN 2, 2016 12:38:45 PM Malware detected: 'Mal/Phish-A' at '/' THREATJAN 2, 2016 12:36:23 PM Malware detected: 'Mal/DrodZp-A' at '/' THREATJAN 2, 2016 12:35:09 PM Malware cleaned up: 'Mal/Phish-A' at '/' THREATJAN 2, 2016 12:10:18 PM Malware cleaned up: 'Mal/DrodZp-A' at '/' THREATJAN 2, 2016 12:10:18 PM Malware detected: 'Mal/Phish-A' at '/' THREATJAN 2, 2016 7:45:07 AM Malware detected: 'Mal/DrodZp-A' at '/' THREATJAN 2, 2016 7:43:49 AM Malware cleaned up: 'Mal/Phish-A' at '/' THREATJAN 2, 2016 6:37:40 AM Malware cleaned up: 'Mal/DrodZp-A' at '/' THREATJAN 2, 2016 6:37:40 AM Malware detected: 'Mal/Phish-A' at '/' THREATJAN 2, 2016 1:49:08 AM Malware detected: 'Mal/DrodZp-A' at '/' THREATJAN 2, 2016 1:48:01 AM When I looked in the console, I see that Sophos AVAgent has been repeatedly crashing. I am assuming that this is related. 1/2/16 10:09:49.356 AM SophosSXLD[87997]: 20160102 160949.356 P 87997 T 1919315 ------ 2 - Warning: EARLY TIMEOUT: dns context 44 has 13965 ms before it should time out\n 1/2/16 10:09:49.410 AM SophosSXLD[87997]: 20160102 160949.409 P 87997 T 1919315 ------ 2 - Warning: EARLY TIMEOUT: dns context 44 has 13967 ms before it should time out\n 1/2/16 10:11:07.161 AM ReportCrash[93592]: Saved crash report for SophosAVAgent[93589] version ??? to /Library/Logs/DiagnosticReports/SophosAVAgent_2016-01-02-101107_AppleMini62.crash 1/2/16 10:11:51.033 AM ReportCrash[93592]: Saved crash report for SophosAVAgent[93593] version ??? to /Library/Logs/DiagnosticReports/SophosAVAgent_2016-01-02-101151_AppleMini62.crash 1/2/16 10:13:28.524 AM ReportCrash[93597]: Saved crash report for SophosAVAgent[93596] version ??? to /Library/Logs/DiagnosticReports/SophosAVAgent_2016-01-02-101328_AppleMini62.crash 1/2/16 10:14:59.558 AM SophosSXLD[87997]: 20160102 161459.557 P 87997 T 1919315 ------ 2 - Warning: EARLY TIMEOUT: dns context 23 has 13948 ms before it should time out\n 1/2/16 10:15:22.619 AM SophosSXLD[87997]: 20160102 161522.618 P 87997 T 1919315 ------ 2 - Warning: EARLY TIMEOUT: dns context 23 has 13967 ms before it should time out\n 1/2/16 10:20:09.350 AM SophosSXLD[87997]: 20160102 162009.350 P 87997 T 1919315 ------ 2 - Warning: EARLY TIMEOUT: dns context 44 has 13961 ms before it should time out\n 1/2/16 10:25:09.662 AM SophosSXLD[87997]: 20160102 162509.662 P 87997 T 1919315 ------ 2 - Warning: EARLY TIMEOUT: dns context 44 has 13967 ms before it should time out\n The crash report has: Process: SophosAVAgent [93589] Path: /Library/Sophos Anti-Virus/SophosAntiVirus.app/Contents/MacOS/SophosAVAgent Identifier: SophosAVAgent Version: ??? Code Type: X86-64 (Native) Parent Process: SophosAntiVirus [87998] Responsible: SophosAVAgent [93589] User ID: 0 Date/Time: 2016-01-02 10:11:06.386 -0600 OS Version: Mac OS X 10.11.2 (15C50) Report Version: 11 Anonymous UUID: F20BB0CB-9772-26EB-AE58-758CE7863454 Sleep/Wake UUID: 195F6038-9E42-440B-A1BA-C656788F8E2A Time Awake Since Boot: 670000 seconds Time Since Wake: 45000 seconds System Integrity Protection: enabled Crashed Thread: 4 Exception Type: EXC_CRASH (SIGABRT) Exception Codes: 0x0000000000000000, 0x0000000000000000 Exception Note: EXC_CORPSE_NOTIFY Application Specific Information: *** Terminating app due to uncaught exception 'NSInvalidArgumentException', reason: '*** -[NSFileManager fileSystemRepresentationWithPath:]: nil or empty path argument' abort() called terminating with uncaught exception of type NSException Application Specific Backtrace 1: 0 CoreFoundation 0x00007fff91d70ae2 __exceptionPreprocess + 178 1 libobjc.A.dylib 0x00007fff99c3273c objc_exception_throw + 48 2 CoreFoundation 0x00007fff91d7098d +[NSException raise:format:] + 205 3 Foundation 0x00007fff90fd8ca9 -[NSFileManager fileSystemRepresentationWithPath:] + 122 4 SophosAVAgent 0x00000001000038e3 -[AdHocScanExecutor scanJob:] + 248 5 SophosAVAgent 0x000000010000279e -[ScanChild(BackgroundScanning) backgroundScanWorker] + 577 6 Foundation 0x00007fff911a5c6f How can I fix this?
↧
Forum Post: SophosAVAgent repeatedly crashing, looks like a bad file path - how can I clean this up?
↧