Windows Defender marking iCloud files as … (2024)

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

User profile for user: solomani

solomani Author

User level: Level1

126 points

Every few minutes this gets flagged and Windows Defender removes it and then it comes back again.

It says:

AFFECTED ITEMS:

file: C:\Users\[USERNAME]\AppData\Local\Packages\AppleInc.iCloud_nzyj5cx40ttqa\LocalCache\Local\Apple Inc\iCloudDrive\Staging\51013A73-7387-438C-8A75-7F28AAE3D054.bin

Is this a real threat? How do I get rid of it? I have tried the following:

  • As its something to do with iCloud disabling iCloud fixes the problem. But I like to have access to my iCloud files. So this is not a long term strategy.
  • I tried scanning all my iCloud folder from the command line with windows defender, and it finds nothing.
  • I also scanned all my iCloud files and folders with an MacOS anti-virus software and it found nothing (ClamXV).
  • Offline scan did not help.
  • When I go to the folder its empty, but, if I watch it files appear there and then disappear. I am assuming this is a tmp folder used by iCloud to move files around and keep things in sync.

Windows Defender is catching it but I wonder if its even a real threat?

Thank you.

Windows, Windows 10

Posted on Jul 5, 2023 3:16 AM

Question marked as Best reply

User profile for user: bbpowers

bbpowers

User level: Level1

14 points

Posted on Feb 27, 2024 4:46 AM

Getting similar warning about PWS:Win32/Prast!rfn.

D:\iCloudDriveCache\Apple Inc\iCloudDriveAppData\Staging\28285376-D0DA-44BD-AD63-7848B9857D85.bin

I've tried to remove it with Defender and even resorted to removing all traces of iCloud and the cache folder from my PC and it still is flagging it somehow.

View in context

Similar questions

  • how do I turn off deletion warnings from icloud drive. Every time I try and delete a file I get a very annoying warning from icloud drive before it will delete the file. for windows 10 is there any way to turn off these warnings?how do I turn off deletion warnings from icloud drive. Every time I try and delete a file I get a very annoying warning from icloud drive before it will delete the file. for windows 10 is there any way to turn off these warnings?The same warning occurs if you are deleting 1 or 1,000 files so you have to literally answer yes to 1,000 files to be deleted. Surely this cannot be as poorly designed as it seems. 5721
  • Ramsomware againYesterday I was hit by email ransomware. I have 4 email accounts. The attack came in on an inactive company blog email account (POP).He demanded $850 by bitcoin or he would shut down my computer.A little while later, all my email accounts quit sending (offline), and my internet connection became flaky (ok sometimes, slow at others). I dont know if connected to ransomware attack.Today, I got 5 more threatening emails demanding I pay up.I am now trying to figure out how to proceed: I have 1 month old Superduper and Tme Machine backups.If I restore my computer image (SuperDuper/Time Machine), does that destroy my Bootcamp? I used Winclone to save my bootcamp, but I dont know where it is.I have a lot of Photo pics, CAD files, etc, added since the last back up. I want to keep them. I guess I could save them to other drives for later reinstall.It seems my outgoing email is the central focus of the attack. Email will not connect to server. Can I somehow fix the email accounts?4. I got on another computer and downloaded Bitdefender (trial). Then I tried to transfer the files to the infected computer, but I couldnt get it to work. When the internet was working I tried to download Bitdefender directly to the infected computer, but it would not install, saying there was a copy there already, and it couldn't uninstall it.Suggestions please 19210
  • iCloud files not appearing on MacA few months ago, I had to factory reset one of my Macs and after logging into iCloud my Desktop and Documents files and folders never appeared. Since then I received a new Mac, logged into my iCloud and nothing appeared either. When I create files on the Mac, those don't sync up either.This only happens on Macs. On iPhone, iPad and iCloud on the web, files appear. I'm using Catalina, but on the Big Sur beta it happened too.I've tried the following:Waiting it out, more than a day runningLogging out of iCloud, restarting and logging in againReinstalling macOSClearing PRAMCreating a new computer user and logging into iCloud in thereDeleting iCloud cache on Library/ClouddocsKilling the bird and cloudd processesLogging into another user's iCloud account on the same computer results in their files correctly appearing after a few minutes, so I think the problem might be on my account. Curiously, only files on the Desktop and Documents container do not sync. Files on 3rd party app containers sync without issue.Checking at the logs from brctl, I see the following pattern repeating endlessly:[dbg 2020-11-05 21:18:58.940-0300] bird[348] o got a deletion in operation <private>[info 2020-11-05 21:18:58.940-0300] bird[348] ┃ record was deleted: <private>[info 2020-11-05 21:18:58.941-0300] bird[348] ┗ end[dbg 2020-11-05 21:18:58.941-0300] bird[348] o received updated server change token <private> client change token (null) in operation <private> status 1[dbg 2020-11-05 21:18:58.941-0300] bird[348] ┃ ┏ saving inconsistent sync-down batch (edits:0 deletions:200) directly:NO[dbg 2020-11-05 21:18:59.007-0300] bird[348] ┃ ┃ broadcasting to framework clients container <private> change BRContainerlastServerUpdateKey=Fri Dec 29 19:17:14 0000[dbg 2020-11-05 21:18:59.007-0300] bird[348] ┃ ┗ end[info 2020-11-05 21:18:59.007-0300] bird[348] ┗ end[dbg 2020-11-05 21:18:59.678-0300] bird[348] o got a deletion in operation <private>The timestamp that appears on the line: BRContainerlastServerUpdateKey=Fri Dec 29 19:17:14 0000Is always the same when it repeats. I checked and the only December 29 that falls on a Friday was on 2017.Also, when giving focus to a Finder window, the following text which is interesting:...[dbg 2020-11-05 21:36:54.825-0300] bird[348] ┃ Not registering for pushes on container <private> because sync is disabled due to no corresponding app being installed...This repeated about a hundred times in a fraction of a second.So, does anyone know if there's something I'm at able to do from my end? Or is it something internal that may need more involvement?Thanks for reading! 9693

1 reply

Loading page content

Page content loaded

Question marked as Best reply

User profile for user: bbpowers

bbpowers

User level: Level1

14 points

Feb 27, 2024 4:46 AM in response to solomani

Getting similar warning about PWS:Win32/Prast!rfn.

D:\iCloudDriveCache\Apple Inc\iCloudDriveAppData\Staging\28285376-D0DA-44BD-AD63-7848B9857D85.bin

I've tried to remove it with Defender and even resorted to removing all traces of iCloud and the cache folder from my PC and it still is flagging it somehow.

Link

Windows Defender marking iCloud files as Exploits - Exploit:JS/Blacole.A

Windows Defender marking iCloud files as … (2024)
Top Articles
Latest Posts
Article information

Author: Terrell Hackett

Last Updated:

Views: 6349

Rating: 4.1 / 5 (72 voted)

Reviews: 95% of readers found this page helpful

Author information

Name: Terrell Hackett

Birthday: 1992-03-17

Address: Suite 453 459 Gibson Squares, East Adriane, AK 71925-5692

Phone: +21811810803470

Job: Chief Representative

Hobby: Board games, Rock climbing, Ghost hunting, Origami, Kabaddi, Mushroom hunting, Gaming

Introduction: My name is Terrell Hackett, I am a gleaming, brainy, courageous, helpful, healthy, cooperative, graceful person who loves writing and wants to share my knowledge and understanding with you.