Applies to: Sophos Home Premium and Free (Windows and Mac)
This article shows how to resolve PUA detected alerts using the Sophos Home software installed on the computer.
To resolve the alert via the dashboard, follow this article instead Managing PUA detected Alerts in the Sophos Home Dashboard
For Windows computers
PUA threats will be automatically blocked. However, customers may allow and restore a PUA at their own discretion by following these steps:
- If the PUA detection popup was closed—> Double-click on the Sophos shield icon on the system tray. This opens the Sophos Home window.
- Click on My Activity, or, if the popup is present, click on Manage
- You will be redirected to your Sophos Home Dashboard
- Locate the computer that was affected and click on it to access the New Activity section, or, if looking for an older threat, the HISTORY tab
- Locate the PUA and click on Show Advanced Options
- At customer’s own discretion, they may choose the option Did we get this wrong? to Allow and Restore the PUA
For Mac computers
For manual removal, please see the note at the end.
- Do either of the following:
- Click the Threat Detected notification.
- If you no longer have the Threat Detected notification, open the Sophos Home main window then click on the PUA blocked notification.
- Click the Threat Detected notification.
- Select one of the following options in the next window:
- Always Allow – This opens the Sophos Home dashboard to perform the exclusion. This action allows the detected application to run.
- Clean – This option deletes the application.
- Ignore – The alert is cleared out but no action is taken. The detected PUA is neither excluded or deleted. However, the alert triggers again when the application is relaunched.
Note: Please visit these articles for steps regarding manual removal:
I received an alert stating Manual PUA cleanup required
Manual malware cleanup on a Mac computer