Windows Defender marking iCloud files as Exploits - Exploit:JS/Blacole.A

Every few minutes this gets flagged and Windows Defender removes it and then it comes back again.

It says:


AFFECTED ITEMS:

file: C:\Users\[USERNAME]\AppData\Local\Packages\AppleInc.iCloud_nzyj5cx40ttqa\LocalCache\Local\Apple Inc\iCloudDrive\Staging\51013A73-7387-438C-8A75-7F28AAE3D054.bin


Is this a real threat? How do I get rid of it? I have tried the following:


  • As its something to do with iCloud disabling iCloud fixes the problem. But I like to have access to my iCloud files. So this is not a long term strategy.
  • I tried scanning all my iCloud folder from the command line with windows defender, and it finds nothing.
  • I also scanned all my iCloud files and folders with an MacOS anti-virus software and it found nothing (ClamXV).
  • Offline scan did not help.
  • When I go to the folder its empty, but, if I watch it files appear there and then disappear. I am assuming this is a tmp folder used by iCloud to move files around and keep things in sync.


Windows Defender is catching it but I wonder if its even a real threat?


Thank you.

Windows, Windows 10

Posted on Jul 5, 2023 3:16 AM

Reply

Similar questions

1 reply

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Windows Defender marking iCloud files as Exploits - Exploit:JS/Blacole.A

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.