Xcode - Virus BitCoinMiner-AS [Trj]

Hello,


I use Avast antivirus and it finds a virus "MacOS:BitCoinMiner-AS [Trj]"

The virus was detected in Xcode application ("Application/Xcode.app/contents/Framework/libSwiftDispatch/dylib")

and a scan finds it in several systems libraries.

Is this virus dangerous for Mac?

Is it possible that it comes from Xcode download in App Store?

How to prevent from this?



Thank you,

Jean


MacBook Pro (15-inch, 2016)

macOS High Sierra version 10.13.3

Xcode

iMac, OS X Yosemite (10.10.5)

Posted on Feb 21, 2018 11:42 AM

Reply
18 replies

Feb 22, 2018 5:09 AM in response to Eric Root

Hi,


I did download the MalwareBytes but it did find nothing.

However, I had other Avast popup for the same virus in other location all related to the library libSwiftDispatch

I asked Avast to remove all ...

Next I had Xcode not working anymore and restoring Xcode from a previous backup did not help...

Therefore I reloaded Xcode from AppStore and now everything looks ok: A full scan detected nothing.

I believe that somehow Xcode was infected by this BitcoinMiner.


Kind regards

Jean

Feb 25, 2018 5:28 PM in response to AnalogHeart

Did you read my post above yours? I recommend you follow the advice in my earlier post.


Simple put, Apple attempts to provide all the malware detection and removal you need in Mac OS X. Malwarebytes has come to be accepted as the only malware detector you should consider. For those pestered by browser attacks consider Malwarebytes.


Discusses Mac OS X operating system wide malware detection and removal

See Linc Davis, thomas_r., and etresoft comprehensive write ups on

https://discussions.apple.com/thread/5728993


etresoft steps back and states that the frequency of malware is increasing on the Mac. thomas_r. reveals his involvement in Malwarebytes as Director of Mac Offerings

https://discussions.apple.com/thread/7343915

https://discussions.apple.com/thread/7940701?answerId=31698261022#31698261022


"Malwarebytes Anti-Malware for Mac Removes adware and malware Revives your Mac"

https://www.malwarebytes.org/antimalware/mac/


"visibility & protection to the core"


https://objective-see.com/


Web browser malware removal:

see Esquared, Linc Davis

https://discussions.apple.com/thread/6689392


Fixing Safari malware attacks. See thunderzzz approach.

https://discussions.apple.com/thread/7307569


The best techniques for securing your Mac from the professionals.

http://www.macworld.com/article/2048160/how-the-nsa-snoop-proofs-its-macs.html



phishing

"fake" panic warnings

https://discussions.apple.com/docs/DOC-8771

Feb 27, 2018 2:10 PM in response to jean-mariefromrixensart

My Avast 13-4 virus definition version 18022706 also detected and quarantined :

  • /System/Library/CoreServices/MRT.app/Contents/Frameworks/libswiftDispatch.dylib
  • /Applications/BandWidthX.app/Contents/Frameworks/libswiftDispatch.dylib

I'm not 100% sure but it may come from a software called BandWidthX (Copyright © 2016 Kris Lau. All rights reserved.)

Hope this help

Feb 25, 2018 6:18 PM in response to rccharles

rccharles wrote:


Apple provides all the malware detection software you will ever need.

Current protection is adequate today for most users, but those methods are somewhat limited and far too easy to be disabled by the user. I wish I was more confident that Apple will be able to keep up with malware developers in the future. Even EtreSoft is starting to come to this same conclusion recently.

Feb 25, 2018 7:04 PM in response to MadMacs0

MadMacs0 wrote:


I wish I was more confident that Apple will be able to keep up with malware developers in the future. Even EtreSoft is starting to come to this same conclusion recently.

I'm confident that Apple could keep up with malware developers now and in the future. I don't think Apple care much at all about macOS in general anymore. Malware and adware problems on macOS get just a small fraction of the small fraction of attention that Apple gives to the Mac.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Xcode - Virus BitCoinMiner-AS [Trj]

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.