How do I view the Xprotect definitions?
I just wondering how to view the Xprotect definitions. Thanks to anyone that could give input.
You can make a difference in the Apple Support Community!
When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.
When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.
I just wondering how to view the Xprotect definitions. Thanks to anyone that could give input.
Hi 🙂
if you mean the Xprotect.plist file
use Finder-Go-Go to Folder (Command-Shift-G) and enter
/System/Library/CoreServices/CoreTypes.bundle/Contents/Resources/
then select xprotect.plist & press the Space key
entering
/System/Library/CoreServices/CoreTypes.bundle/Contents/Resources/XProtect.plist
into Safari's address bar should do the same, and show the file ready-selected.
or at least that works on Snow - I haven't specifically looked in Lion
Hi 🙂
if you mean the Xprotect.plist file
use Finder-Go-Go to Folder (Command-Shift-G) and enter
/System/Library/CoreServices/CoreTypes.bundle/Contents/Resources/
then select xprotect.plist & press the Space key
entering
/System/Library/CoreServices/CoreTypes.bundle/Contents/Resources/XProtect.plist
into Safari's address bar should do the same, and show the file ready-selected.
or at least that works on Snow - I haven't specifically looked in Lion
I'm running 10.7.2. I dont think that would help. I've been looking all around for an answer and can't find one. When I try to open xprotect.plist on Lion it opens up terminal. Does your modification date say Oct. 12?
so when you select it & press space - there's no Quicklook ?
if not, drag it to textedit
when i entered it into safari it brought up text edit i believe. what was the modification date of your file? Edit: I put it up into quicklook. It had all the definitions i needed. How do i know if the file it working?
mine was automatically updated yesterday at 13.33
Then how would mine only be updated on the 12th? I have uncheck and rechecked the automatic update box. Could there be a problem with the file?
you might check that the file and/or folder is not locked, and that you have no 'security' software which might be blocking the update.
There is a malware variant which disables xprotect, or so I read - so if you installed 'Flash' other than direct from Adobe recently, or anything else not beyond suspicion, I'd certainly look into exactly what it was.
I am 100% sure that didn't download the Flashback trojan. I haven't downloaded adobe software since late July. It seems that the latest entry in the list was Flashback.A. Is that what it should be at?
using prefsetter or plisteditpro (free trial) makes it easier...
there are 31 items in mine - the last eleven (21-31) are for variants of Flashback A
millbear69 wrote:
It seems that the latest entry in the list was Flashback.A. Is that what it should be at?
Yes, Apple seems to be lumping all versions of the Flashback installer into one version whereas F-Secure has catagorized A through C and Intego says that they found A through D, the last one seen over a week ago.
Since I don't have a copy of the latest version, I can't say for certain that Apple is completely up-to-date, but the timing would indicate that they could be.
The version (1010) and format of the Lion database is slightly different with only ten malware items identified and within the last entry for OSX.Flashback.A there are eleven different signatures.
Hi,
How to now if Xprotect is working fine , i dont see the process in the Activity Monitor ?
is this normal ?
Med.amine wrote:
How to now if Xprotect is working fine , i dont see the process in the Activity Monitor ?
is this normal ?
Not sure why you are asking millbear69 this question and I already answered it for you in the other thread. Are you looking for a different response?
No,
now i know that i'am not infected cause i've verified the file that you've told me and it's okay, now i just want ton know how to verfiy that xprotect work cause i don't see it's process .
and thank you for helping me .
Med.amine wrote:
i just want ton know how to verfiy that xprotect work cause i don't see it's process .
What version of the database do you currently have? If you don't know it should still be in this file:
/System/Library/CoreServices/CoreTypes.bundle/Contents/Resources/XProtect.plist
as Andy Ball previously suggested.
Since you are posting to the Lion Forum, I'll assume that's what your are running, in which case the current version is 1010.
i'm running lion ,
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
last modified jeudi 13 octobre 2011 07:31
How do I view the Xprotect definitions?