Musiquelavie

Q: Anti-virus software picking up "Exploit Script Null" Trojan Variant. Help!

Hi my Anti-virus software has picked up something called the Exploit Script Null Trojan Variant 8 times now in Real-time scans. What should I be doing? I've never seen anything like this happen before on my mac.

OS X Mavericks (10.9.2)

Posted on Mar 14, 2014 12:44 AM

Close

Q: Anti-virus software picking up "Exploit Script Null" Trojan Variant. Help!

  • All replies
  • Helpful answers

  • by shldr2thewheel,

    shldr2thewheel shldr2thewheel Mar 14, 2014 1:08 AM in response to Musiquelavie
    Level 7 (25,881 points)
    Mar 14, 2014 1:08 AM in response to Musiquelavie

    what is the name of the AV software? Most of it is useless on a mac.

  • by thomas_r.,

    thomas_r. thomas_r. Mar 14, 2014 4:43 PM in response to Musiquelavie
    Level 7 (30,889 points)
    Mac OS X
    Mar 14, 2014 4:43 PM in response to Musiquelavie

    This is not the name of any known Mac malware. It is a name that is used for some Windows malware by McAfee... note that if you're using McAfee, you should get rid of it immediately. Although you certainly can find anti-virus software that is more worthless than McAfee on the Mac, it would be difficult. See the results of my Mac anti-virus testing 2014.

     

    Most likely, this is simply Windows malware attached to an e-mail message, or something similar. Removing it is not something you should trust anti-virus software to do. To get rid of it, see How to remove infected files. Note that removing it yourself will help you identify where it is, and how it keeps getting back on your computer, and thus may help you diagnose an infection on some other Windows machine.

     

    Finally, I would recommend that you read my Mac Malware Guide for more information on protecting yourself from malware.

  • by Musiquelavie,

    Musiquelavie Musiquelavie Mar 14, 2014 6:13 PM in response to thomas_r.
    Level 1 (0 points)
    Mar 14, 2014 6:13 PM in response to thomas_r.

    I am running McAfee but I am also running Sophos.

     

    It was picked up by McAfee, but the detection reads

     

    Accessed by SophosAvAgent

    Status detection found

    Total detection 1

     

    McAfee ran clean right up until January. About a week after I downloaded Mavericks. Then the problems began.

     

    My computer has crashed three times this week. I have never seen my Mac crash before.

  • by etresoft,

    etresoft etresoft Mar 14, 2014 6:50 PM in response to Musiquelavie
    Level 7 (29,081 points)
    Mar 14, 2014 6:50 PM in response to Musiquelavie

    Musiquelavie wrote:

     

    My computer has crashed three times this week. I have never seen my Mac crash before.

    Try uninstalling the antivirus software. We spend far more time here on the support forums cleaning up problems with antivirus software than we do cleaning up problems with viruses.

     

    It isn't a question of whether there is or isn't Mac malware. The problem is that Mac antivirus software is just ports of Windows software to the Mac that doesn't run well and spends 99.9% of its time checking for Windows viruses. Apple includes XProtect antivirus that checks for any malware that might actually be a threat to your machine.

  • by thomas_r.,

    thomas_r. thomas_r. Mar 15, 2014 3:38 AM in response to Musiquelavie
    Level 7 (30,889 points)
    Mac OS X
    Mar 15, 2014 3:38 AM in response to Musiquelavie

    Running two anti-virus apps with active "on-access" scanning capabilities enabled is a very bad idea. It should never be done. This looks like it could potentially be a case of the two interfering with each other, and nothing more than that.

     

    As I've already said, McAfee needs to go. It's garbage. Not only is it not doing a decent job of protecting you against anything, but it's probably causing a lot of the problems you're experiencing. Remove it using the McAfee uninstaller, found in the Applications folder.

     

    Regarding Sophos, it is normally well-behaved, but has been known to cause spontaneous shutdown problems with Mavericks in some cases. (Outdated versions of Sophos cause more problems than that with Mavericks.) I have asked a contact at Sophos, and they say that it should be fixed "soon." (I don't know how soon "soon" might be.) It would probably be a good idea to uninstall it for now (using the Sophos Remove app in the Applications folder). You can make the choice about whether to reinstall it later, after it has been updated, and after you have read my Mac Malware Guide.