Solved.
Kudos0

Is XProtectRemediatorMRTv3 a False Positive?

Hi, I just recently noticed that Norton 360 found a threat (OSX.Trojan.Gen.2) back in March 15th 2022: XProtectRemediatorMRTv3 in /Library/System/Library/CoreServices/XProtect.app/Contents/MacOS/ From what I have found out, this is very likely a False Positive, after the macOS 12.3 update. Other AV vendors (at least two) had flagged the same file.

But I haven't found anything in the Norton Community about MRTv3. Norton 360 does not classify the file as a threat anymore in Idle Scans just a day after the 15th. But the File is still listed under "Unresolved Risks". This made me suspicious, because if it is a False Positive, it should not be listed there. Probably Norton 360 does not update the "Unresolved Risks" log, when reclassifying threats as FP. If that is the case the behavior should be updated, I think.

Because of the whole it had been flagged as a virus, but not anymore, but is still listed in "Unresolved Risks" and I just noticed it, I have submitted my file on June 4th to Norton and wait for confirmation that it is a False Positive.

What I'm hoping is that someone from Norton could just confirm that Norton 360 indeed had flagged XProtectRemediatorMRTV3 as False Positive under that specific file path in that timeframe and that it has been resolved by a signature update.

It would also be nice to get rid of the entry in "Unresolved Risks" (if it is a FP) as that file location is SIP protected and thus cannot be modified to "resolve" the risk.

Accepted Solution
Kudos2 Stats

Re: Is XProtectRemediatorMRTv3 a False Positive?

Hello @Crwmy,

I can confirm we detected XProtectRemediatorMRTv3 as OSX.Trojan.Gen.2 on the 15th of March, 2022 and resolved this false positive detection on the same day.

Thank you for reporting the issue with the unresolved threats entries in the security logs, we'll look into it.

Replies

Kudos1 Stats

Re: Is XProtectRemediatorMRTv3 a False Positive?

Apple has rolled out a new antimalware tool XProtectRemediator, of which this XProtectRemediatorMRTv3 is a component of.  It is now running side-by-side with the older MRT malware mitigation tool. Eventually it's believed that XProtectRemediator will replace MRT. See https://eclecticlight.co/2022/06/12/last-week-on-my-mac-introducing-xpro... for a more detailed explanation.

If Norton is detecting it as malware, that's indeed a false positive. 

Kudos0

Re: Is XProtectRemediatorMRTv3 a False Positive?

Report a suspected incorrect detection to Norton
https://support.norton.com/sp/en/us/home/current/solutions/v126152382

Submit a file to Norton
https://support.norton.com/sp/en/us/home/current/solutions/kb20090602171902EN

Respond to incorrect Norton alerts that a file is infected or a program or website is suspicious
https://support.norton.com/sp/en/us/home/current/solutions/kb20100222230832EN

Kudos0

Re: Is XProtectRemediatorMRTv3 a False Positive?

I have submitted the file to Norton on June 4th as potential FP. It still says "Your submission is being processed" with the last update being the date and time I uploaded it.
Kudos0

Re: Is XProtectRemediatorMRTv3 a False Positive?

Crwmy:
I have submitted the file to Norton on June 4th as potential FP. It still says "Your submission is being processed" with the last update being the date and time I uploaded it.

Please post the Submission ID
We'll try to call attention to the Submission ID  

Kudos0

Re: Is XProtectRemediatorMRTv3 a False Positive?

8be516ee-87d6-4562-ad42-80818256be10 Thank you!
Kudos1 Stats

Re: Is XProtectRemediatorMRTv3 a False Positive?

https://submit.norton.com/?type=CHECK&submission_id=8be516ee-87d6-4562-ad42-80818256be10

We'll try to call attention -

Accepted Solution
Kudos2 Stats

Re: Is XProtectRemediatorMRTv3 a False Positive?

Hello @Crwmy,

I can confirm we detected XProtectRemediatorMRTv3 as OSX.Trojan.Gen.2 on the 15th of March, 2022 and resolved this false positive detection on the same day.

Thank you for reporting the issue with the unresolved threats entries in the security logs, we'll look into it.

Kudos0

Re: Is XProtectRemediatorMRTv3 a False Positive?

Thank you @tomas_he for confirming that this was a False Positive!

Thanks also looking into the issue of the unresolved threats entries for FPs! It might also be worth to amend Malware Findings in the Security Log if they turn out to be False Positives to include the info so a less tech savvy user can see it instantly (or even remove it, but that is probably more suspicious). A FP should not be that often, but I know that especially with Apple it can be challenging with how they push out changes.

Thank you @bjm_ for bringing attention to my question.

Thank you @PE Rockwell for first response and providing additional information.

This thread is closed from further comment. Please visit the forum to start a new thread.