• Mints and ClamXAV - Looking under stones!

    From David Brooks@21:1/5 to Snit on Fri Sep 30 08:21:16 2022
    XPost: alt.computer.workshop

    On 30/09/2022 02:20, Snit wrote:
    [....]
    On 29/09/2022 19:36, Snit wrote:
    https://arstechnica.com/information-technology/2022/09/never-before-seen-malware-has-infected-hundreds-of-linux-and-windows-devices/

    Researchers have revealed a never-before-seen piece of cross-platform >>>>>>> malware that has infected a wide range of Linux and Windows devices, >>>>>>> including small office routers, FreeBSD boxes, and large enterprise >>>>>>> servers.

    ——

    Be careful out there!

    Thanks! This is a time when it's good to be an Apple customer! 🤣 >>>>>
    Yes, though they are not 100% safe either.

    True - especially if you download rogue Apps! https://imgbb.com/X2kyxCM >>>
    Not sure I follow. Rogue apps? Wasn't that from a corrupt app?

    When I reported the error to HO he said to me, in email:-
    "That's because you didn't follow the instructions that I gave you, and
    you tried running the app from the same folder that it was unarchived
    to. Please move the app out of that, preferably into your Applications
    folder. I have also explained this in at least two articles recently.

    Aha. Though to be fair I ran it from that folder with no issues.

    But I HAD installed the Mints App exactly as instructed - in the
    Applications folder - before I ran it. I believe HO altered the coding
    in his App so that the next time I downloaded it an ran it, no error
    message was shown.

    What version numbers? Any evidence of this? Seems a bad download is more likely.

    I have no idea how an App can become corrupt, but I decided to rid this
    machine of /all/ tools supplied by HO. Over-Kill? Maybe, but who knows
    for sure.

    Use what you are comfortable with. Not sure of the concern though. Is all of this from what seems to be a bad download?

    Not really. It stems from the /attitude/ of Howard Oakley himself.

    Perhaps *he* was having a bad day personally!

    I have found THIS though! ClamXAV finds trojan in XProtect

    https://discussions.apple.com/thread/253749289

    Do you agree with the advice given?

    --
    David

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From David Brooks@21:1/5 to David Brooks on Fri Sep 30 09:20:48 2022
    XPost: alt.computer.workshop

    On 30/09/2022 08:21, David Brooks wrote:
    On 30/09/2022 02:20, Snit wrote:
    [....]
    On 29/09/2022 19:36, Snit wrote:
    https://arstechnica.com/information-technology/2022/09/never-before-seen-malware-has-infected-hundreds-of-linux-and-windows-devices/

    Researchers have revealed a never-before-seen piece of
    cross-platform
    malware that has infected a wide range of Linux and Windows
    devices,
    including small office routers, FreeBSD boxes, and large enterprise >>>>>>>> servers.

    ——

    Be careful out there!

    Thanks! This is a time when it's good to be an Apple customer! 🤣 >>>>>>
    Yes, though they are not 100% safe either.

    True - especially if you download rogue Apps!
    https://imgbb.com/X2kyxCM

    Not sure I follow. Rogue apps? Wasn't that from a corrupt app?

    When I reported the error to HO he said to me, in email:-
    "That's because you didn't follow the instructions that I gave you, and
    you tried running the app from the same folder that it was unarchived
    to. Please move the app out of that, preferably into your Applications
    folder. I have also explained this in at least two articles recently.

    Aha. Though to be fair I ran it from that folder with no issues.

    But I HAD installed the Mints App exactly as instructed - in the
    Applications folder - before I ran it. I believe HO altered the coding
    in his App so that the next time I downloaded it an ran it, no error
    message was shown.

    What version numbers? Any evidence of this? Seems a bad download is more
    likely.

    I have no idea how an App can become corrupt, but I decided to rid this
    machine of /all/ tools supplied by HO. Over-Kill? Maybe, but who knows
    for sure.

    Use what you are comfortable with. Not sure of the concern though. Is
    all of
    this from what seems to be a bad download?

    Not really. It stems from the /attitude/ of Howard Oakley himself.

    Perhaps *he* was having a bad day personally!

    I have found THIS though!  ClamXAV finds trojan in XProtect

    https://discussions.apple.com/thread/253749289

    Do you agree with the advice given?


    Here's an old query I once made!

    https://www.facebook.com/photo.php?fbid=10216207867536902

    Just for your interest!

    --
    David

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From FromTheRafters@21:1/5 to All on Fri Sep 30 06:50:16 2022
    XPost: alt.computer.workshop

    David Brooks presented the following explanation :
    On 30/09/2022 02:20, Snit wrote:
    [....]
    On 29/09/2022 19:36, Snit wrote:
    https://arstechnica.com/information-technology/2022/09/never-before-seen-malware-has-infected-hundreds-of-linux-and-windows-devices/

    Researchers have revealed a never-before-seen piece of cross-platform >>>>>>>> malware that has infected a wide range of Linux and Windows devices, >>>>>>>> including small office routers, FreeBSD boxes, and large enterprise >>>>>>>> servers.

    ——

    Be careful out there!

    Thanks! This is a time when it's good to be an Apple customer! ?

    Yes, though they are not 100% safe either.

    True - especially if you download rogue Apps! https://imgbb.com/X2kyxCM >>>>
    Not sure I follow. Rogue apps? Wasn't that from a corrupt app?

    When I reported the error to HO he said to me, in email:-
    "That's because you didn't follow the instructions that I gave you, and
    you tried running the app from the same folder that it was unarchived
    to. Please move the app out of that, preferably into your Applications
    folder. I have also explained this in at least two articles recently.

    Aha. Though to be fair I ran it from that folder with no issues.

    But I HAD installed the Mints App exactly as instructed - in the
    Applications folder - before I ran it. I believe HO altered the coding
    in his App so that the next time I downloaded it an ran it, no error
    message was shown.

    What version numbers? Any evidence of this? Seems a bad download is more
    likely.

    I have no idea how an App can become corrupt, but I decided to rid this
    machine of /all/ tools supplied by HO. Over-Kill? Maybe, but who knows
    for sure.

    Use what you are comfortable with. Not sure of the concern though. Is all
    of
    this from what seems to be a bad download?

    Not really. It stems from the /attitude/ of Howard Oakley himself.

    Perhaps *he* was having a bad day personally!

    I have found THIS though! ClamXAV finds trojan in XProtect

    https://discussions.apple.com/thread/253749289

    Do you agree with the advice given?

    IMO removing the utility is overkill, but I think I would do that too
    under these circumstances. False positives are a fact of life, but
    real-world testing of signatures should have eliminated this one.

    Again though, this is likely an engine/definition problem and not a
    problem your target can directly address.

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From David Brooks@21:1/5 to FromTheRafters on Fri Sep 30 16:26:34 2022
    XPost: alt.computer.workshop

    On 30/09/2022 11:50, FromTheRafters wrote:
    David Brooks presented the following explanation :
    On 30/09/2022 02:20, Snit wrote:
    [....]
    On 29/09/2022 19:36, Snit wrote:
    https://arstechnica.com/information-technology/2022/09/never-before-seen-malware-has-infected-hundreds-of-linux-and-windows-devices/

    Researchers have revealed a never-before-seen piece of
    cross-platform
    malware that has infected a wide range of Linux and Windows
    devices,
    including small office routers, FreeBSD boxes, and large
    enterprise
    servers.

    ——

    Be careful out there!

    Thanks! This is a time when it's good to be an Apple customer! ? >>>>>>>
    Yes, though they are not 100% safe either.

    True - especially if you download rogue Apps!
    https://imgbb.com/X2kyxCM

    Not sure I follow. Rogue apps? Wasn't that from a corrupt app?

    When I reported the error to HO he said to me, in email:-
    "That's because you didn't follow the instructions that I gave you, and >>>> you tried running the app from the same folder that it was unarchived
    to. Please move the app out of that, preferably into your Applications >>>> folder. I have also explained this in at least two articles recently.

    Aha. Though to be fair I ran it from that folder with no issues.

    But I HAD installed the Mints App exactly as instructed - in the
    Applications folder - before I ran it. I believe HO altered the coding >>>> in his App so that the next time I downloaded it an ran it, no error
    message was shown.

    What version numbers? Any evidence of this? Seems a bad download is more >>> likely.

    I have no idea how an App can become corrupt, but I decided to rid this >>>> machine of /all/ tools supplied by HO. Over-Kill? Maybe, but who knows >>>> for sure.

    Use what you are comfortable with. Not sure of the concern though. Is
    all of
    this from what seems to be a bad download?

    Not really. It stems from the /attitude/ of Howard Oakley himself.

    Perhaps *he* was having a bad day personally!

    I have found THIS though!  ClamXAV finds trojan in XProtect

    https://discussions.apple.com/thread/253749289

    Do you agree with the advice given?

    IMO removing the utility is overkill, but I think I would do that too
    under these circumstances. False positives are a fact of life, but
    real-world testing of signatures should have eliminated this one.

    Thanks. Are you using ANY AV software on your MBP?

    Again though, this is likely an engine/definition problem and not a
    problem your target can directly address.

    I'm simply pleased that I'm not subscribing to ClamXAV

    D.

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From FromTheRafters@21:1/5 to David Brooks on Fri Sep 30 12:21:45 2022
    XPost: alt.computer.workshop

    David Brooks wrote :
    On 30/09/2022 11:50, FromTheRafters wrote:
    David Brooks presented the following explanation :
    On 30/09/2022 02:20, Snit wrote:
    [....]
    On 29/09/2022 19:36, Snit wrote:
    https://arstechnica.com/information-technology/2022/09/never-before-seen-malware-has-infected-hundreds-of-linux-and-windows-devices/

    Researchers have revealed a never-before-seen piece of
    cross-platform
    malware that has infected a wide range of Linux and Windows >>>>>>>>>> devices,
    including small office routers, FreeBSD boxes, and large enterprise >>>>>>>>>> servers.

    ——

    Be careful out there!

    Thanks! This is a time when it's good to be an Apple customer! ? >>>>>>>>
    Yes, though they are not 100% safe either.

    True - especially if you download rogue Apps!
    https://imgbb.com/X2kyxCM

    Not sure I follow. Rogue apps? Wasn't that from a corrupt app?

    When I reported the error to HO he said to me, in email:-
    "That's because you didn't follow the instructions that I gave you, and >>>>> you tried running the app from the same folder that it was unarchived >>>>> to. Please move the app out of that, preferably into your Applications >>>>> folder. I have also explained this in at least two articles recently. >>>>
    Aha. Though to be fair I ran it from that folder with no issues.

    But I HAD installed the Mints App exactly as instructed - in the
    Applications folder - before I ran it. I believe HO altered the coding >>>>> in his App so that the next time I downloaded it an ran it, no error >>>>> message was shown.

    What version numbers? Any evidence of this? Seems a bad download is more >>>> likely.

    I have no idea how an App can become corrupt, but I decided to rid this >>>>> machine of /all/ tools supplied by HO. Over-Kill? Maybe, but who knows >>>>> for sure.

    Use what you are comfortable with. Not sure of the concern though. Is all >>>> of
    this from what seems to be a bad download?

    Not really. It stems from the /attitude/ of Howard Oakley himself.

    Perhaps *he* was having a bad day personally!

    I have found THIS though!  ClamXAV finds trojan in XProtect

    https://discussions.apple.com/thread/253749289

    Do you agree with the advice given?

    IMO removing the utility is overkill, but I think I would do that too under >> these circumstances. False positives are a fact of life, but real-world
    testing of signatures should have eliminated this one.

    Thanks. Are you using ANY AV software on your MBP?

    I don't think so, only the things that come with the OS. I believe
    there is some AV capability there.

    Again though, this is likely an engine/definition problem and not a problem >> your target can directly address.

    I'm simply pleased that I'm not subscribing to ClamXAV

    Whatever, it seems like a Clam problem and not a ClamXAV problem except
    by association.

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From David Brooks@21:1/5 to FromTheRafters on Fri Sep 30 17:32:46 2022
    XPost: alt.computer.workshop

    On 30/09/2022 17:21, FromTheRafters wrote:
    David Brooks wrote :
    On 30/09/2022 11:50, FromTheRafters wrote:
    David Brooks presented the following explanation :
    On 30/09/2022 02:20, Snit wrote:
    [....]
    On 29/09/2022 19:36, Snit wrote:
    https://arstechnica.com/information-technology/2022/09/never-before-seen-malware-has-infected-hundreds-of-linux-and-windows-devices/

    Researchers have revealed a never-before-seen piece of
    cross-platform
    malware that has infected a wide range of Linux and Windows >>>>>>>>>>> devices,
    including small office routers, FreeBSD boxes, and large >>>>>>>>>>> enterprise
    servers.

    ——

    Be careful out there!

    Thanks! This is a time when it's good to be an Apple customer! ? >>>>>>>>>
    Yes, though they are not 100% safe either.

    True - especially if you download rogue Apps!
    https://imgbb.com/X2kyxCM

    Not sure I follow. Rogue apps? Wasn't that from a corrupt app?

    When I reported the error to HO he said to me, in email:-
    "That's because you didn't follow the instructions that I gave
    you, and
    you tried running the app from the same folder that it was unarchived >>>>>> to. Please move the app out of that, preferably into your
    Applications
    folder. I have also explained this in at least two articles recently. >>>>>
    Aha. Though to be fair I ran it from that folder with no issues.

    But I HAD installed the Mints App exactly as instructed - in the
    Applications folder - before I ran it. I believe HO altered the
    coding
    in his App so that the next time I downloaded it an ran it, no error >>>>>> message was shown.

    What version numbers? Any evidence of this? Seems a bad download is
    more
    likely.

    I have no idea how an App can become corrupt, but I decided to rid >>>>>> this
    machine of /all/ tools supplied by HO. Over-Kill? Maybe, but who
    knows
    for sure.

    Use what you are comfortable with. Not sure of the concern though.
    Is all of
    this from what seems to be a bad download?

    Not really. It stems from the /attitude/ of Howard Oakley himself.

    Perhaps *he* was having a bad day personally!

    I have found THIS though!  ClamXAV finds trojan in XProtect

    https://discussions.apple.com/thread/253749289

    Do you agree with the advice given?

    IMO removing the utility is overkill, but I think I would do that too
    under these circumstances. False positives are a fact of life, but
    real-world testing of signatures should have eliminated this one.

    Thanks. Are you using ANY AV software on your MBP?

    I don't think so, only the things that come with the OS. I believe there
    is some AV capability there.

    Yes, there's very good AV built right into Apple devices.

    Again though, this is likely an engine/definition problem and not a
    problem your target can directly address.

    I'm simply pleased that I'm not subscribing to ClamXAV

    Whatever, it seems like a Clam problem and not a ClamXAV problem except
    by association.

    I'm uncertain why you say that. 'dialabrain' said, quite clearly, Now
    you should uninstall ClamXAV.

    --
    David

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Snit@21:1/5 to David Brooks on Fri Sep 30 16:31:46 2022
    XPost: alt.computer.workshop

    On Sep 30, 2022 at 12:21:16 AM MST, "David Brooks" wrote <MNwZK.1312461$Eeb3.222181@fx05.ams1>:

    On 30/09/2022 02:20, Snit wrote:
    [....]
    On 29/09/2022 19:36, Snit wrote:
    https://arstechnica.com/information-technology/2022/09/never-before-seen-malware-has-infected-hundreds-of-linux-and-windows-devices/

    Researchers have revealed a never-before-seen piece of cross-platform >>>>>>>> malware that has infected a wide range of Linux and Windows devices, >>>>>>>> including small office routers, FreeBSD boxes, and large enterprise >>>>>>>> servers.

    ——

    Be careful out there!

    Thanks! This is a time when it's good to be an Apple customer! 🤣 >>>>>>
    Yes, though they are not 100% safe either.

    True - especially if you download rogue Apps! https://imgbb.com/X2kyxCM >>>>
    Not sure I follow. Rogue apps? Wasn't that from a corrupt app?

    When I reported the error to HO he said to me, in email:-
    "That's because you didn't follow the instructions that I gave you, and
    you tried running the app from the same folder that it was unarchived
    to. Please move the app out of that, preferably into your Applications
    folder. I have also explained this in at least two articles recently.

    Aha. Though to be fair I ran it from that folder with no issues.

    But I HAD installed the Mints App exactly as instructed - in the
    Applications folder - before I ran it. I believe HO altered the coding
    in his App so that the next time I downloaded it an ran it, no error
    message was shown.

    What version numbers? Any evidence of this? Seems a bad download is more
    likely.

    I have no idea how an App can become corrupt, but I decided to rid this
    machine of /all/ tools supplied by HO. Over-Kill? Maybe, but who knows
    for sure.

    Use what you are comfortable with. Not sure of the concern though. Is all of >> this from what seems to be a bad download?

    Not really. It stems from the /attitude/ of Howard Oakley himself.

    Perhaps *he* was having a bad day personally!

    A lot of more technical folks can be impatient with questions they see as easy -- and can even take offense at being questioned about things like if they are a licensed developer.

    I have found THIS though! ClamXAV finds trojan in XProtect

    https://discussions.apple.com/thread/253749289

    Do you agree with the advice given?

    Not much advice given... but the false positive almost surely comes from the Clam engine and nothing that ClamXAV is doing specifically.

    --
    Personal attacks from those who troll show their own insecurity. They cannot use reason to show the message to be wrong so they try to feel somehow superior by attacking the messenger.

    They cling to their attacks and ignore the message time and time again.

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Snit@21:1/5 to FromTheRafters on Fri Sep 30 16:32:52 2022
    XPost: alt.computer.workshop

    On Sep 30, 2022 at 9:21:45 AM MST, "FromTheRafters" wrote <th7530$121f6$1@dont-email.me>:

    David Brooks wrote :
    On 30/09/2022 11:50, FromTheRafters wrote:
    David Brooks presented the following explanation :
    On 30/09/2022 02:20, Snit wrote:
    [....]
    On 29/09/2022 19:36, Snit wrote:
    https://arstechnica.com/information-technology/2022/09/never-before-seen-malware-has-infected-hundreds-of-linux-and-windows-devices/

    Researchers have revealed a never-before-seen piece of
    cross-platform
    malware that has infected a wide range of Linux and Windows >>>>>>>>>>> devices,
    including small office routers, FreeBSD boxes, and large enterprise >>>>>>>>>>> servers.

    ——

    Be careful out there!

    Thanks! This is a time when it's good to be an Apple customer! ? >>>>>>>>>
    Yes, though they are not 100% safe either.

    True - especially if you download rogue Apps!
    https://imgbb.com/X2kyxCM

    Not sure I follow. Rogue apps? Wasn't that from a corrupt app?

    When I reported the error to HO he said to me, in email:-
    "That's because you didn't follow the instructions that I gave you, and >>>>>> you tried running the app from the same folder that it was unarchived >>>>>> to. Please move the app out of that, preferably into your Applications >>>>>> folder. I have also explained this in at least two articles recently. >>>>>
    Aha. Though to be fair I ran it from that folder with no issues.

    But I HAD installed the Mints App exactly as instructed - in the
    Applications folder - before I ran it. I believe HO altered the coding >>>>>> in his App so that the next time I downloaded it an ran it, no error >>>>>> message was shown.

    What version numbers? Any evidence of this? Seems a bad download is more >>>>> likely.

    I have no idea how an App can become corrupt, but I decided to rid this >>>>>> machine of /all/ tools supplied by HO. Over-Kill? Maybe, but who knows >>>>>> for sure.

    Use what you are comfortable with. Not sure of the concern though. Is all >>>>> of
    this from what seems to be a bad download?

    Not really. It stems from the /attitude/ of Howard Oakley himself.

    Perhaps *he* was having a bad day personally!

    I have found THIS though! ClamXAV finds trojan in XProtect

    https://discussions.apple.com/thread/253749289

    Do you agree with the advice given?

    IMO removing the utility is overkill, but I think I would do that too under >>> these circumstances. False positives are a fact of life, but real-world
    testing of signatures should have eliminated this one.

    Thanks. Are you using ANY AV software on your MBP?

    I don't think so, only the things that come with the OS. I believe
    there is some AV capability there.

    There is, though Apple does not focus much on it.

    https://support.apple.com/guide/security/protecting-against-malware-sec469d47bd8/web


    Again though, this is likely an engine/definition problem and not a problem >>> your target can directly address.

    I'm simply pleased that I'm not subscribing to ClamXAV

    Whatever, it seems like a Clam problem and not a ClamXAV problem except
    by association.


    --
    Personal attacks from those who troll show their own insecurity. They cannot use reason to show the message to be wrong so they try to feel somehow superior by attacking the messenger.

    They cling to their attacks and ignore the message time and time again.

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From David Brooks@21:1/5 to Snit on Fri Sep 30 17:48:18 2022
    XPost: alt.computer.workshop

    On 30/09/2022 17:31, Snit wrote:
    On Sep 30, 2022 at 12:21:16 AM MST, "David Brooks" wrote <MNwZK.1312461$Eeb3.222181@fx05.ams1>:

    On 30/09/2022 02:20, Snit wrote:
    [....]
    On 29/09/2022 19:36, Snit wrote:
    https://arstechnica.com/information-technology/2022/09/never-before-seen-malware-has-infected-hundreds-of-linux-and-windows-devices/

    Researchers have revealed a never-before-seen piece of cross-platform >>>>>>>>> malware that has infected a wide range of Linux and Windows devices, >>>>>>>>> including small office routers, FreeBSD boxes, and large enterprise >>>>>>>>> servers.

    ——

    Be careful out there!

    Thanks! This is a time when it's good to be an Apple customer! 🤣 >>>>>>>
    Yes, though they are not 100% safe either.

    True - especially if you download rogue Apps! https://imgbb.com/X2kyxCM >>>>>
    Not sure I follow. Rogue apps? Wasn't that from a corrupt app?

    When I reported the error to HO he said to me, in email:-
    "That's because you didn't follow the instructions that I gave you, and >>>> you tried running the app from the same folder that it was unarchived
    to. Please move the app out of that, preferably into your Applications >>>> folder. I have also explained this in at least two articles recently.

    Aha. Though to be fair I ran it from that folder with no issues.

    But I HAD installed the Mints App exactly as instructed - in the
    Applications folder - before I ran it. I believe HO altered the coding >>>> in his App so that the next time I downloaded it an ran it, no error
    message was shown.

    What version numbers? Any evidence of this? Seems a bad download is more >>> likely.

    I have no idea how an App can become corrupt, but I decided to rid this >>>> machine of /all/ tools supplied by HO. Over-Kill? Maybe, but who knows >>>> for sure.

    Use what you are comfortable with. Not sure of the concern though. Is all of
    this from what seems to be a bad download?

    Not really. It stems from the /attitude/ of Howard Oakley himself.

    Perhaps *he* was having a bad day personally!

    A lot of more technical folks can be impatient with questions they see as easy
    -- and can even take offense at being questioned about things like if they are
    a licensed developer.

    Thanks. I do understand that. Something which I have learned from life
    and long experience.

    Neither HO - nor anyone else - has provided evidence that HO *IS* a
    licenced developer.

    I have found THIS though! ClamXAV finds trojan in XProtect

    https://discussions.apple.com/thread/253749289

    Do you agree with the advice given?

    Not much advice given... but the false positive almost surely comes from the Clam engine and nothing that ClamXAV is doing specifically.

    I'm uncertain why you say that.
    Adviser 'dialabrain' said, quite clearly,
    *Now you should uninstall ClamXAV*

    THAT was the advice given.

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Snit@21:1/5 to David Brooks on Fri Sep 30 17:29:25 2022
    XPost: alt.computer.workshop

    On Sep 30, 2022 at 9:48:18 AM MST, "David Brooks" wrote <m5FZK.483655$vFVf.89649@fx02.ams1>:

    On 30/09/2022 17:31, Snit wrote:
    On Sep 30, 2022 at 12:21:16 AM MST, "David Brooks" wrote
    <MNwZK.1312461$Eeb3.222181@fx05.ams1>:

    On 30/09/2022 02:20, Snit wrote:
    [....]
    On 29/09/2022 19:36, Snit wrote:
    https://arstechnica.com/information-technology/2022/09/never-before-seen-malware-has-infected-hundreds-of-linux-and-windows-devices/

    Researchers have revealed a never-before-seen piece of cross-platform
    malware that has infected a wide range of Linux and Windows devices, >>>>>>>>>> including small office routers, FreeBSD boxes, and large enterprise >>>>>>>>>> servers.

    ——

    Be careful out there!

    Thanks! This is a time when it's good to be an Apple customer! 🤣 >>>>>>>>
    Yes, though they are not 100% safe either.

    True - especially if you download rogue Apps! https://imgbb.com/X2kyxCM >>>>>>
    Not sure I follow. Rogue apps? Wasn't that from a corrupt app?

    When I reported the error to HO he said to me, in email:-
    "That's because you didn't follow the instructions that I gave you, and >>>>> you tried running the app from the same folder that it was unarchived >>>>> to. Please move the app out of that, preferably into your Applications >>>>> folder. I have also explained this in at least two articles recently. >>>>
    Aha. Though to be fair I ran it from that folder with no issues.

    But I HAD installed the Mints App exactly as instructed - in the
    Applications folder - before I ran it. I believe HO altered the coding >>>>> in his App so that the next time I downloaded it an ran it, no error >>>>> message was shown.

    What version numbers? Any evidence of this? Seems a bad download is more >>>> likely.

    I have no idea how an App can become corrupt, but I decided to rid this >>>>> machine of /all/ tools supplied by HO. Over-Kill? Maybe, but who knows >>>>> for sure.

    Use what you are comfortable with. Not sure of the concern though. Is all of
    this from what seems to be a bad download?

    Not really. It stems from the /attitude/ of Howard Oakley himself.

    Perhaps *he* was having a bad day personally!

    A lot of more technical folks can be impatient with questions they see as easy
    -- and can even take offense at being questioned about things like if they are
    a licensed developer.

    Thanks. I do understand that. Something which I have learned from life
    and long experience.

    Neither HO - nor anyone else - has provided evidence that HO *IS* a
    licenced developer.

    What else are you looking for over than this?

    ---------------------------------------------------------------------- Identifier=co.eclecticlight.Mints
    Format=app bundle with Mach-O universal (x86_64 arm64)
    CodeDirectory v=20500 size=3138 flags=0x10000(runtime) hashes=87+7 location=embedded
    VersionPlatform=1
    VersionMin=720896
    VersionSDK=787200
    Hash type=sha256 size=32
    CandidateCDHash sha256=fca0396a659854c388d954a9348f63e283a60560 CandidateCDHashFull sha256=fca0396a659854c388d954a9348f63e283a60560c302ff59665f2a46b99a8d26
    Hash choices=sha256 CMSDigest=fca0396a659854c388d954a9348f63e283a60560c302ff59665f2a46b99a8d26 CMSDigestType=2
    Executable Segment base=0
    Executable Segment limit=245760
    Executable Segment flags=0x1
    Page size=4096
    CDHash=fca0396a659854c388d954a9348f63e283a60560
    Signature size=8975
    Authority=Developer ID Application: Howard Oakley (QWY4LRW926) Authority=Developer ID Certification Authority
    Authority=Apple Root CA
    Timestamp=Aug 31, 2022 at 10:15:01 AM
    Info.plist entries=25
    TeamIdentifier=QWY4LRW926
    Runtime Version=12.3.0
    Sealed Resources version=2 rules=13 files=60
    Internal requirements count=1 size=216 ----------------------------------------------------------------------


    I have found THIS though! ClamXAV finds trojan in XProtect

    https://discussions.apple.com/thread/253749289

    Do you agree with the advice given?

    Not much advice given... but the false positive almost surely comes from the >> Clam engine and nothing that ClamXAV is doing specifically.

    I'm uncertain why you say that.
    Adviser 'dialabrain' said, quite clearly,
    *Now you should uninstall ClamXAV*

    THAT was the advice given.

    I would not go that far... do not see the need.

    Almost certainly what has happened is the Clam engine has a goof... but ALL malware checkers get false positives from time to time.

    --
    Personal attacks from those who troll show their own insecurity. They cannot use reason to show the message to be wrong so they try to feel somehow superior by attacking the messenger.

    They cling to their attacks and ignore the message time and time again.

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From David Brooks@21:1/5 to jeremy on Sat Oct 1 16:03:35 2022
    XPost: alt.computer.workshop

    On 01/10/2022 15:46, jeremy wrote:
    On 30 Sep 2022 at 16:26:34 BST, "David Brooks" <DavidB@nomail.afraid.org> wrote:

    I'm simply pleased that I'm not subscribing to ClamXAV

    Really? I thought you were a lifelong fan.

    Do, please, read here, 'jeremy' ......

    https://eclecticlight.co/2015/02/24/protecting-your-mac-against-malware-and-intrusion/

    Although the article is a little out of date, the information is sound.

    You will note, at the end, that I was the ONLY person to have 'liked'
    it! :-D

    --
    Kind regards,
    David B.

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From jeremy@21:1/5 to All on Sat Oct 1 14:46:50 2022
    XPost: alt.computer.workshop

    On 30 Sep 2022 at 16:26:34 BST, "David Brooks" <DavidB@nomail.afraid.org> wrote:

    I'm simply pleased that I'm not subscribing to ClamXAV

    Really? I thought you were a lifelong fan.
    --
    jeremy

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From jeremy@21:1/5 to All on Sat Oct 1 17:31:31 2022
    XPost: alt.computer.workshop

    On 1 Oct 2022 at 16:03:35 BST, "David Brooks" <DavidB@nomail.afraid.org>
    wrote:


    I'm simply pleased that I'm not subscribing to ClamXAV

    Really? I thought you were a lifelong fan.

    Do, please, read here, 'jeremy' ......

    Do, please, read here, 'david' .....

    https://en.wikipedia.org/wiki/Sarcasm

    --
    jeremy

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Kelly Phillips@21:1/5 to DavidB@nomail.afraid.org on Mon Oct 3 00:26:21 2022
    XPost: alt.computer.workshop

    On Sat, 1 Oct 2022 16:03:35 +0100, David Brooks
    <DavidB@nomail.afraid.org> wrote:

    On 01/10/2022 15:46, jeremy wrote:
    On 30 Sep 2022 at 16:26:34 BST, "David Brooks" <DavidB@nomail.afraid.org>
    wrote:

    I'm simply pleased that I'm not subscribing to ClamXAV

    Really? I thought you were a lifelong fan.

    Do, please, read here, 'jeremy' ......

    https://eclecticlight.co/2015/02/24/protecting-your-mac-against-malware-and-intrusion/

    Although the article is a little out of date, the information is sound.

    6 years is a lot more than a little out of date.

    You will note, at the end, that I was the ONLY person to have 'liked'
    it! :-D

    Normally, that would be embarrassing, but as usual you're oblivious.

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Kelly Phillips@21:1/5 to DavidB@nomail.afraid.org on Mon Oct 3 23:06:14 2022
    XPost: alt.computer.workshop

    On Fri, 30 Sep 2022 17:48:18 +0100, David Brooks
    <DavidB@nomail.afraid.org> wrote:

    On 30/09/2022 17:31, Snit wrote:
    On Sep 30, 2022 at 12:21:16 AM MST, "David Brooks" wrote
    <MNwZK.1312461$Eeb3.222181@fx05.ams1>:

    On 30/09/2022 02:20, Snit wrote:
    [....]
    On 29/09/2022 19:36, Snit wrote:
    https://arstechnica.com/information-technology/2022/09/never-before-seen-malware-has-infected-hundreds-of-linux-and-windows-devices/

    Researchers have revealed a never-before-seen piece of cross-platform
    malware that has infected a wide range of Linux and Windows devices, >>>>>>>>>> including small office routers, FreeBSD boxes, and large enterprise >>>>>>>>>> servers.

    ——

    Be careful out there!

    Thanks! This is a time when it's good to be an Apple customer! ? >>>>>>>>
    Yes, though they are not 100% safe either.

    True - especially if you download rogue Apps! https://imgbb.com/X2kyxCM >>>>>>
    Not sure I follow. Rogue apps? Wasn't that from a corrupt app?

    When I reported the error to HO he said to me, in email:-
    "That's because you didn't follow the instructions that I gave you, and >>>>> you tried running the app from the same folder that it was unarchived >>>>> to. Please move the app out of that, preferably into your Applications >>>>> folder. I have also explained this in at least two articles recently. >>>>
    Aha. Though to be fair I ran it from that folder with no issues.

    But I HAD installed the Mints App exactly as instructed - in the
    Applications folder - before I ran it. I believe HO altered the coding >>>>> in his App so that the next time I downloaded it an ran it, no error >>>>> message was shown.

    What version numbers? Any evidence of this? Seems a bad download is more >>>> likely.

    I have no idea how an App can become corrupt, but I decided to rid this >>>>> machine of /all/ tools supplied by HO. Over-Kill? Maybe, but who knows >>>>> for sure.

    Use what you are comfortable with. Not sure of the concern though. Is all of
    this from what seems to be a bad download?

    Not really. It stems from the /attitude/ of Howard Oakley himself.

    Perhaps *he* was having a bad day personally!

    A lot of more technical folks can be impatient with questions they see as easy
    -- and can even take offense at being questioned about things like if they are
    a licensed developer.

    Thanks. I do understand that. Something which I have learned from life
    and long experience.

    Neither HO - nor anyone else - has provided evidence that HO *IS* a
    licenced developer.

    I have found THIS though! ClamXAV finds trojan in XProtect

    https://discussions.apple.com/thread/253749289

    Do you agree with the advice given?

    Not much advice given... but the false positive almost surely comes from the >> Clam engine and nothing that ClamXAV is doing specifically.

    I'm uncertain why you say that.
    Adviser 'dialabrain' said, quite clearly,
    *Now you should uninstall ClamXAV*

    THAT was the advice given.

    Knowledgeable folks in ACW have gone over the concept of wrappers many
    times before, on your behalf. You always say that you understand, but
    now here you are, asking the question that you're asking. It makes no
    sense unless you were falsely claiming that you understood what a
    software wrapper is.

    If clamav is suspected of causing an issue, how do you propose you would uninstall it without installing its wrapper? That's why you got the
    advice that you got.

    You know, it drains me to explain such basic things to someone who
    claims to have been using computers since the 1960s. You just suck the
    light out of the room. Your ignorance seems to know no bounds.

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)