Want to highlight a helpful answer? Upvote!

Did someone help you, or did an answer or User Tip resolve your issue? Upvote by selecting the upvote arrow. Your feedback helps others! Learn more about when to upvote >

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

HTML.Exploot.CVE_2014_0278-4 Dangerous or no?

Hi everyone


I just did a ClamXav on my macbook. I have Mac OS X, version 10.7.5.


The file named "Page.webarchive" with the infection name "Html.Explot.CVE_2014_0278-4". I've read before that this is just a an IE bug that can't really harm a mac. But then I saw this article:


http://www.intego.com/mac-security-blog/shellshock-vulnerability-what-mac-os-x-u sers-need-to-know


and it says that cve.2014 could be shellshock and that my mac could be at serious risk. Am I misunderstanding something? The files are located are located in a folder that is just a bunch of numbers and letters jumbled up. those folders are in ReadingListArchives folder.


Can somebody clear this all up for me? Do all I have to do is delete the files or do I have to do something much more technical?


Any response is greatly appreciated.

MacBook Pro, Mac OS X (10.7.5)

Posted on Feb 1, 2015 5:47 PM

Reply
13 replies

Feb 1, 2015 6:26 PM in response to ContainsPnuts

ContainsPnuts wrote:


Hi everyone

Am I misunderstanding something?

Yes.


CVE_2014_0278 is not discussed on the page…

http://www.intego.com/mac-security-blog/shellshock-vulnerability-what-mac-os-x-u sers-need-to-know/


You appear to have been searching for 'cve.2014', which is wrong…


CVE is Common Vulnerabilities and Exposures List. http://cve.mitre.org

It is a massive database of known 'bad things' that can effect computers & electronic devices etc. They use a numbering scheme as shown… http://cve.mitre.org/cve/identifiers/cve-ids.html


'cve.2014' is searching for every known bug that was found in 2014 - you will find may bad things, some effect the Mac, only one will match the exploit ClamXAV found…

http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0278


Delete them if you like - it may break whatever uses the ReadingListArchives, but you may not care about that?

Backup the files if you are worried about breaking things, they shouldn't effect your Mac.

Feb 1, 2015 7:04 PM in response to Drew Reece

So the one I had was just another version of the virus that only effects Internet Explorer right?


I've deleted the webpages from my reading list on safari and that seemed to have gotten rid of their ""page.webarchive" file. Doing a second scan to see if they are completely gone. They're just off my reading list now, thats what you meant by breaking whatever it uses?


So I'd say my computer is pretty safe right now, correct?


Thanks so much for all your help, I'm just super paranoid and cautious of malware and the like.

Feb 1, 2015 7:26 PM in response to ContainsPnuts

ContainsPnuts wrote:


So the one I had was just another version of the virus that only effects Internet Explorer right?

Yep

ContainsPnuts wrote:

They're just off my reading list now, thats what you meant by breaking whatever it uses?

Yes

ClamXAV has a delete option. If you are unlucky the file will be inside some structure that is managed by another app. Mail is the classic example. Deleting stuff inside mailboxes (basically special folders) can ruin the index in Mail.app. I don't know if Reading List does similar things.

ContainsPnuts wrote:

So I'd say my computer is pretty safe right now, correct?


Yup, seems like you got em.

ClamXAV can miss items so if you see any weirdness ask for help.

Adware seems to be the scourge of the internet at the moment, so avoid installing from just any old site & keep backups.

Feb 1, 2015 8:41 PM in response to ContainsPnuts

http://www.clamxav.com/faq.php#Q21


I don't know how reading list gets onto iOS, it's possible they got onto the device if iTunes or iCloud copies the entire files. I'd guess they are harmless if they made it not the device since they exploit IE.

I suspect an iOS backup made via iTunes would contain them too.


You can't AV scan iOS so unless you take it to Apple you will never know. Erase & reinstall if you are concerned, but I wouldn't be at all worried.

Feb 2, 2015 1:27 AM in response to ContainsPnuts

For fastest, most efficient answers to questions such as these, please visit the ClamXav Forum.

ContainsPnuts wrote:


and what does it mean when ClamXav says something about errors under infected files found?

Do you have the App Store version 2.6.4 or the web site version 2.7.x? If the latter, make sure it's the latest as there have been several bug fixes posted recently.


Where are you seeing these errors, in the ClamXav app window or the scan log? Can you please copy and paste a sample of what you are seeing?

Feb 2, 2015 2:52 AM in response to MadMacs0

I don't atually remember MadMacs0, which one is preferred? When I update Clamxav it says v2.2.2 so I guess it's pretty far behind on updates. Plus when I click update it says "warning cant get daily patch" in the bar at the bottom that says ClamXav v2.2.2 right now. The total error thing was in the box where it says "stopping….update finshed". Should I uninstall ClamXav and reinstall it? And if so, should I get it from the website or the app store?

User uploaded file

Feb 2, 2015 2:59 AM in response to ContainsPnuts

ContainsPnuts wrote:


When I update Clamxav it says v2.2.2 so I guess it's pretty far behind on updates.

Wow, that's from August 2011 so you are way behind.


Select "Check for ClamXav Updates..." from the ClamXav menu to automatically download and install the latest version. Then you can enable "√ Check for ClamXav update on launch" in ClamXav General Preferences.

HTML.Exploot.CVE_2014_0278-4 Dangerous or no?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.