Jump to content
MAXBAR1

Test of Malwarebytes for macOS 4.5 Beta

Recommended Posts

TEST OF MALWAREBYTES for macOS 4.5 Beta

  • Installed without problems
  • It works properly both after a Reboot and after a Shutdown and Start of the Mac
  • I have tried all EICAR files that are correctly detected by real-time protection.
  • Manual and scheduled scan work correctly and detect both EICAR files. (To do the test I had to disable temporarily the RTP)
  • Quarantine work correctly

 

  • The only drawback could be that with five EICAR files it signals me 6 items scanned and 5 threats detected and corrected; I assume, correct me if I'm wrong, that the 6th item is the Malwarebytes folder under \ Users \ Shared (I attach screenshots)

 

  • It always remains just too easy, for those who shouldn't, turn off real-time protection

1652961789_Schermata2020-07-27alle17_20_19.jpg.6f5e749736bf4e65bd4a980df0793b00.jpg

1101550805_Schermata2020-07-27alle17_20_26.jpg.9ec4c5125155f70c913045190f2adbca.jpg

 

Only thing: a question.

  • I keep having the old extension in StagedExtension.
  • In SystemExtension I only have the extension of the Beta VPN MWB
  • I have not been able to understand where the new SystemExtension is and I can no longer find the old KEXT (except in StagedExtension).

I DON'T KNOW IF IT IS NORMAL?

@treed can you clarify?

Thank you

Have a good day

Massimiliano

 

 

My Mac configuration

MacBook Pro 9,2 (A1278) 13" Mid 2012 Non-Retina Display 

macOS 10.15.6 (19G73)

10GB Ram

240 GB SSD Kingston

 

Share this post


Link to post
Share on other sites

All this is normal.

  • Folders are counted as well as files, so the Malwarebytes folder counts as one. (Remember apps on macOS are folders and thus are counted as equal to files.)
  • There are a few different ways to use a system extension, and only one of them results in entries being created in the SystemExtensions folder
  • The StagedExtensions folder is entirely managed by Apple, and is protected by SIP, so it's not possible to remove items from that location without turning off SIP. It would be nice if macOS removed items from StagedExtensions once they have been successfully allowed, but that doesn't seem to happen, leading to the extension hanging around in there long term. It's not actually running from there, though.

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

  • Recently Browsing   0 members

    No registered users viewing this page.

×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.