Solved

First ever threat found on my MacBook - can someone explain "...AppleKextExcludeList.kext/contents

  • 13 November 2015
  • 3 replies
  • 109 views

WebRoot is reporting a threat - I'd like to know more.  
Unfortunately the WebRoot screen is fixed width and I can't expand the column that names the threat
 
Here's what I know.  Details:  "...AppleKextExcludeList.kext/Contents/Info.plist"
Threat Name:  "Keylo..orPro.r"
 
Here's a screen shot.  Note that a couple weeks ago I used CarbonCopyCloner to upgrade to a new SSD and that TimeMachine has re-built it's backup a couple of times in a couple of months.
 

icon

Best answer by Ssherjj 13 November 2015, 15:15

View original

3 replies

Userlevel 7
Badge +62
Hello ?,
 
Welcome to the Webroot Community,
 
This is what our Mac Threat Researcher ? has provided on this:
 
No need to worry, there isnt a keylogger on your device.  Thie file that we are finding is the AppleExcludeList.kext on your backup. We are finding it due to the fact that apple has put the keyloggers information in the file and we are reading that.  I suggest that you allow the file, as we cannot remove it and nor should we as it is a legit file.  After allowing it please turn off scan mounted drives and this should correct the issue that you are having.
 
Please also look at this THREAD as well .
 
Hope this helps?
 
 
Thanks for a quick, clear and concise explanation!
 
 
Userlevel 7
Badge +62
Hi ?,
 
You are most Welcome. I am glad we could answer your questions!
 
 
Have a great day and weekend!:D

Reply