Skip to main content
Solved

Strange alert... Google software is ransomware?


WebRoot on my Mac just popped up that a file “/Library/Google/…./GoogleSoftwareUpdateAgent” has the threat “MacOS.MacRansomEvilQuest.1.r”

It quarantined correctly, but…. what’s going on…  is this a bad file, or does WebRoot have a mistake, or is Google pushing ransomware?

Best answer by Nathan G

Support have confirmed my case is a false positive. It’s fixed in definition 1451

View original
Did this help you find an answer to your question?

19 replies

TripleHelix
Moderator
Forum|alt.badge.img+63
  • Moderator
  • 8901 replies
  • July 16, 2020

Hello @davidpv 

 

It’s best to Submit a Support Ticket and they will let you know what is going on and make sure your system is clean.

 

Note: When submitting a Support Ticket, Please wait for a response from Support. Putting in another Support Ticket on this problem before Support responses will put your first Support Ticket at the end of the queue and support can take up to 48 hours to reply or a little longer because of COVID-19.

 

Thanks,


TripleHelix
Moderator
Forum|alt.badge.img+63
  • Moderator
  • 8901 replies
  • July 16, 2020

Forum|alt.badge.img+1

Ran in to the same issue today. Does anyone have any new information on this?


TripleHelix
Moderator
Forum|alt.badge.img+63
  • Moderator
  • 8901 replies
  • July 16, 2020

Hello @Mark Salvaleon  just the 2 of you that we know of so it would be best to contact support as well!

 

It’s best to Submit a Support Ticket and they will let you know what is going on and make sure your system is clean.

 

Note: When submitting a Support Ticket, Please wait for a response from Support. Putting in another Support Ticket on this problem before Support responses will put your first Support Ticket at the end of the queue and support can take up to 48 hours to reply or a little longer because of COVID-19.

 

Thanks,


  • New Member
  • 3 replies
  • July 16, 2020

Same issue, about an hour ago. Noticed Google Chrome had the green update available icon, then Webroot popped up shortly after, Run malwarebytes Scan doesn’t detect anything, checked the file system for other files related to this virus found nothing. Is this genuine or a false positive?


TripleHelix
Moderator
Forum|alt.badge.img+63
  • Moderator
  • 8901 replies
  • July 16, 2020

Hello @Nathan G  could be a FP but only Webroot Support would know, so it’s best that you Submit a Support Ticket as well.


  • Fresh Face
  • 2 replies
  • July 16, 2020

Thank goodness for this thread, I just experienced this as well. It seemed like an odd filename for a threat. I was pretty worried… still am. But it’s good to know I’m not the only one this has happened to.


TripleHelix
Moderator
Forum|alt.badge.img+63
  • Moderator
  • 8901 replies
  • July 17, 2020

Hello @msalud  it’s best if you contacted support as well from the link I posted above!


TripleHelix
Moderator
Forum|alt.badge.img+63
  • Moderator
  • 8901 replies
  • July 17, 2020

Is this the version of Chrome you all updated to? Chrome 84.0.4147.89

 

https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.html


  • Fresh Face
  • 2 replies
  • July 17, 2020

@TripleHelix Yes, that’s what I have


TripleHelix
Moderator
Forum|alt.badge.img+63
  • Moderator
  • 8901 replies
  • July 17, 2020

Most likely a False Positive but I can’t be sure only support can tell and fix it! @DanP  @khumphrey  @freydrew  @PVaddi 


  • New Member
  • 3 replies
  • July 17, 2020

I have same version of Chrome 84.0.4147.89


  • New Member
  • 3 replies
  • Answer
  • July 17, 2020

Support have confirmed my case is a false positive. It’s fixed in definition 1451


TripleHelix
Moderator
Forum|alt.badge.img+63
  • Moderator
  • 8901 replies
  • July 17, 2020

Thanks for the Update @Nathan G  and it’s just a False Positive.


I also have had this alert come up. I tried to delete it and run a new scan and it shows up again. I want to report to support, but I don’t have the right password to do so and it won’t email it to me, even though I’ve clicked “forgot password.”


Forum|alt.badge.img+3
  • Fresh Face
  • 2 replies
  • July 17, 2020

Got the exact same alert a few minutes ago. Glad to know it’s a false positive. Any way to get rid of it?


Forum|alt.badge.img+48
  • Retired Webrooter
  • 1550 replies
  • July 17, 2020

Webroot is aware of the unusual activity and it has been resolved in the latest update. If you have yet to receive an update, you will as soon your computer checks in. Security is at the core of what we do and securing our customers’ data is our top priority. Your device is secure and there's nothing else you need to do at this time.


TylerM
Administrator
Forum|alt.badge.img+25
  • Sr. Security Analyst & Community Manager
  • 1260 replies
  • July 17, 2020
freydrew wrote:

Webroot is aware of the unusual activity and it has been resolved in the latest update. If you have yet to receive an update, you will as soon your computer checks in. Security is at the core of what we do and securing our customers’ data is our top priority. Your device is secure and there's nothing else you need to do at this time.

For anyone who is still having this issue on an older build just uncheck the files and continue the scan


Forum|alt.badge.img+1
  • New Voice
  • 12 replies
  • July 17, 2020

I got this also - 7 alerts labeled MacOS.MacRansom.EvilQuest.1.r  in Library/GoogleSoftwareUpdate/.

All were Quarantined; I deleted ASAP, quick rescan found nothing more, I’m still in process of full rescan which is now over 8 hours and still running, nothing found so far.

Do I need to get a Ticket and more checking?

Will I get an update while WSA is still scanning?


Reply