Why does Norton find a Portscan attack associated with /mach_kernel?

Norton keeps blocking Portscan attacks from /mach_kernel. Why? Is this a virus that is copying the real /mach_kernel file?

Mac OS X (10.6.8)

Posted on Dec 21, 2011 9:37 AM

Reply
7 replies

May 1, 2014 9:27 AM in response to claireELP

Hi,

the file located at /mach_kernel is not a virus.

Is just mac os kernel


mach_kernel file is detected as: Mach-O 64-bit executable x86_64

WARNING: don't delete it, this file is needed to startup


IF YOU DELETE mach_kernel, system not be able to start and should reinstall the operating system to continue


Norton is giving you bad information yes an false positive cause mach_kernel is is filtering network like accept or reject incoming connexions


Thanks,

Giuseppe.P

May 1, 2014 10:26 AM in response to claireELP

Norton Antivirus (made by Symantec) has a very long and illustrious reputation for mangling Mac OS X systems, sometimes to the point where a complete reinstall is necessary. Among other things, it installs kernel extensions which are known to cause kernel panics and system freezes; it contains known and documented bugs which can silently corrupt Adobe Photoshop and Adobe InDesign files, destroy a user's ability to authenticate as an administrator, and (on PPC systems) can cause Classic to stop functioning; and Symantec has on at least two occasions now released flawed .dat file updates which erroneously report certain critical Mac OS X files as "viruses." (Deleting these "viruses" causes damage to the system that in some cases renders it unbootable.)


Norton Removal Tool (Symantec Uninstaller):

http://www.symantec.com/business/support/index?page=content&id=TECH103489&locale =en_US

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Why does Norton find a Portscan attack associated with /mach_kernel?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.