Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.
User profile for user: solomani
solomani Author
User level: Level1 126 points
Every few minutes this gets flagged and Windows Defender removes it and then it comes back again.
It says:
AFFECTED ITEMS:
file: C:\Users\[USERNAME]\AppData\Local\Packages\AppleInc.iCloud_nzyj5cx40ttqa\LocalCache\Local\Apple Inc\iCloudDrive\Staging\51013A73-7387-438C-8A75-7F28AAE3D054.bin
Is this a real threat? How do I get rid of it? I have tried the following:
- As its something to do with iCloud disabling iCloud fixes the problem. But I like to have access to my iCloud files. So this is not a long term strategy.
- I tried scanning all my iCloud folder from the command line with windows defender, and it finds nothing.
- I also scanned all my iCloud files and folders with an MacOS anti-virus software and it found nothing (ClamXV).
- Offline scan did not help.
- When I go to the folder its empty, but, if I watch it files appear there and then disappear. I am assuming this is a tmp folder used by iCloud to move files around and keep things in sync.
Windows Defender is catching it but I wonder if its even a real threat?
Thank you.
Windows, Windows 10
Posted on Jul 5, 2023 3:16 AM
Question marked as Best reply
User profile for user: bbpowers
bbpowers
User level: Level1 14 points
Posted on Feb 27, 2024 4:46 AM
Getting similar warning about PWS:Win32/Prast!rfn.
D:\iCloudDriveCache\Apple Inc\iCloudDriveAppData\Staging\28285376-D0DA-44BD-AD63-7848B9857D85.bin
I've tried to remove it with Defender and even resorted to removing all traces of iCloud and the cache folder from my PC and it still is flagging it somehow.
View in context
Similar questions
- how do I turn off deletion warnings from icloud drive. Every time I try and delete a file I get a very annoying warning from icloud drive before it will delete the file. for windows 10 is there any way to turn off these warnings?how do I turn off deletion warnings from icloud drive. Every time I try and delete a file I get a very annoying warning from icloud drive before it will delete the file. for windows 10 is there any way to turn off these warnings?The same warning occurs if you are deleting 1 or 1,000 files so you have to literally answer yes to 1,000 files to be deleted. Surely this cannot be as poorly designed as it seems. 5721
- Ramsomware againYesterday I was hit by email ransomware. I have 4 email accounts. The attack came in on an inactive company blog email account (POP).He demanded $850 by bitcoin or he would shut down my computer.A little while later, all my email accounts quit sending (offline), and my internet connection became flaky (ok sometimes, slow at others). I dont know if connected to ransomware attack.Today, I got 5 more threatening emails demanding I pay up.I am now trying to figure out how to proceed: I have 1 month old Superduper and Tme Machine backups.If I restore my computer image (SuperDuper/Time Machine), does that destroy my Bootcamp? I used Winclone to save my bootcamp, but I dont know where it is.I have a lot of Photo pics, CAD files, etc, added since the last back up. I want to keep them. I guess I could save them to other drives for later reinstall.It seems my outgoing email is the central focus of the attack. Email will not connect to server. Can I somehow fix the email accounts?4. I got on another computer and downloaded Bitdefender (trial). Then I tried to transfer the files to the infected computer, but I couldnt get it to work. When the internet was working I tried to download Bitdefender directly to the infected computer, but it would not install, saying there was a copy there already, and it couldn't uninstall it.Suggestions please 19210
- iCloud files not appearing on MacA few months ago, I had to factory reset one of my Macs and after logging into iCloud my Desktop and Documents files and folders never appeared. Since then I received a new Mac, logged into my iCloud and nothing appeared either. When I create files on the Mac, those don't sync up either.This only happens on Macs. On iPhone, iPad and iCloud on the web, files appear. I'm using Catalina, but on the Big Sur beta it happened too.I've tried the following:Waiting it out, more than a day runningLogging out of iCloud, restarting and logging in againReinstalling macOSClearing PRAMCreating a new computer user and logging into iCloud in thereDeleting iCloud cache on Library/ClouddocsKilling the bird and cloudd processesLogging into another user's iCloud account on the same computer results in their files correctly appearing after a few minutes, so I think the problem might be on my account. Curiously, only files on the Desktop and Documents container do not sync. Files on 3rd party app containers sync without issue.Checking at the logs from brctl, I see the following pattern repeating endlessly:[dbg 2020-11-05 21:18:58.940-0300] bird[348] o got a deletion in operation <private>[info 2020-11-05 21:18:58.940-0300] bird[348] ┃ record was deleted: <private>[info 2020-11-05 21:18:58.941-0300] bird[348] ┗ end[dbg 2020-11-05 21:18:58.941-0300] bird[348] o received updated server change token <private> client change token (null) in operation <private> status 1[dbg 2020-11-05 21:18:58.941-0300] bird[348] ┃ ┏ saving inconsistent sync-down batch (edits:0 deletions:200) directly:NO[dbg 2020-11-05 21:18:59.007-0300] bird[348] ┃ ┃ broadcasting to framework clients container <private> change BRContainerlastServerUpdateKey=Fri Dec 29 19:17:14 0000[dbg 2020-11-05 21:18:59.007-0300] bird[348] ┃ ┗ end[info 2020-11-05 21:18:59.007-0300] bird[348] ┗ end[dbg 2020-11-05 21:18:59.678-0300] bird[348] o got a deletion in operation <private>The timestamp that appears on the line: BRContainerlastServerUpdateKey=Fri Dec 29 19:17:14 0000Is always the same when it repeats. I checked and the only December 29 that falls on a Friday was on 2017.Also, when giving focus to a Finder window, the following text which is interesting:...[dbg 2020-11-05 21:36:54.825-0300] bird[348] ┃ Not registering for pushes on container <private> because sync is disabled due to no corresponding app being installed...This repeated about a hundred times in a fraction of a second.So, does anyone know if there's something I'm at able to do from my end? Or is it something internal that may need more involvement?Thanks for reading! 9693
1 reply
Loading page content
Page content loaded
Question marked as Best reply
User profile for user: bbpowers
bbpowers
User level: Level1 14 points
Feb 27, 2024 4:46 AM in response to solomani
Getting similar warning about PWS:Win32/Prast!rfn.
D:\iCloudDriveCache\Apple Inc\iCloudDriveAppData\Staging\28285376-D0DA-44BD-AD63-7848B9857D85.bin
I've tried to remove it with Defender and even resorted to removing all traces of iCloud and the cache folder from my PC and it still is flagging it somehow.
Link
Windows Defender marking iCloud files as Exploits - Exploit:JS/Blacole.A