VirusBarrier found infected files

Joined
Apr 30, 2012
Messages
463
Reaction score
14
Points
18
Location
Wales, UK
Your Mac's Specs
I Mac 27-inch 3.2 GHz Intel Core i5 24GB ram. MacBook Pro 13-inch 2.5GHz dual-core Intel i5 16GB ram
Hi
I ran a full scan with VirusBarrier and it found two infected files.
Both said. imagesnap OSX/RobSnap.A
I cant delete or repair as don't have permission to access it.
Does anyone know what this is and should I be worried.
Thanks
 

IWT


Joined
Jan 23, 2009
Messages
10,288
Reaction score
2,230
Points
113
Location
Born Scotland. Worked all over UK. Live in Wales
Your Mac's Specs
M2 Max Studio Extra, 32GB memory, 4TB, Sonoma 14.4.1 Apple 5K Retina Studio Monitor
These links give information on what "imagesnap" is:


Do any of these "ring a bell" with you in terms of your buying or downloading "imagesnap"?

I don't see any malware in relation to "imagesnap".

I can't find and data about "RobSnap.A" Is your name "Rob" by any chance?

Ian
 
OP
D
Joined
Apr 30, 2012
Messages
463
Reaction score
14
Points
18
Location
Wales, UK
Your Mac's Specs
I Mac 27-inch 3.2 GHz Intel Core i5 24GB ram. MacBook Pro 13-inch 2.5GHz dual-core Intel i5 16GB ram
Thanks for replying.
No my name is not Rob
At this point I think that maybe I should do a clean install.
 
Joined
Jan 5, 2023
Messages
35
Reaction score
22
Points
8
Location
United Kingdom
Your Mac's Specs
2020 M1 MacBook Pro 16/1000 GB Sonoma ; 2017 Intel MacBook Air 8/256 GB Monterey
OP
D
Joined
Apr 30, 2012
Messages
463
Reaction score
14
Points
18
Location
Wales, UK
Your Mac's Specs
I Mac 27-inch 3.2 GHz Intel Core i5 24GB ram. MacBook Pro 13-inch 2.5GHz dual-core Intel i5 16GB ram
Thanks. I'll give that a go
 
Joined
Oct 16, 2010
Messages
17,541
Reaction score
1,576
Points
113
Location
Brentwood Bay, BC, Canada
Your Mac's Specs
2011 27" iMac, 1TB(partitioned) SSD, 20GB, OS X 10.11.6 El Capitan
Might be worth running MalwareBytes first?

+1.
I would also suggest running FIND ANY FILE.app, and giving it full permissions to access or delete it by pressing and holding your option key just before searching on the filename you are looking for:



- Patrick
=======
 
Joined
Sep 30, 2007
Messages
9,962
Reaction score
1,235
Points
113
Location
The Republic of Neptune
Your Mac's Specs
2019 iMac 27"; 2020 M1 MacBook Air; macOS up-to-date... always.
Might be worth running MalwareBytes first?


Eh, not really. MalwareBytes has fallen out of favor here for various reasons. Besides, VirusBarrier already found the files. If it can't delete them for permissions reasons, MB won't be able to either.

I've done some digging and there's very little information about this. As Ian pointed out, there's an app known as ImageSnap that this seems to be related to, and the developer's name happens to be Robert. Thus... RobSnap.

One other app in doing some googling is associated with this... Prey. It's an iOS app with a Mac companion used for finding and protecting iOS devices.

I'm not entirely convinced that this is a "legit" piece of malware, but misidentified as one, or flagged as a "possible" one due to what it does, by necessity. ImageSnap's function is to capture still images from a webcam, which could be used for nefarious reasons, but that's more a matter of misuse than maliciousness. What I would do is check to see if you have ImageSnap or Prey installed, then delete them. Empty the Trash, then re-scan with VirusBarrier. You may have to use Find Any File as Patrick suggested to root out more files... search for "Prey" and "ImageSnap" when you do.
 
Joined
Oct 16, 2010
Messages
17,541
Reaction score
1,576
Points
113
Location
Brentwood Bay, BC, Canada
Your Mac's Specs
2011 27" iMac, 1TB(partitioned) SSD, 20GB, OS X 10.11.6 El Capitan
Both said. imagesnap OSX/RobSnap.A
I cant delete or repair as don't have permission to access it.


What Mac and MacOS version are you running, and what drive path location is this nasty file actually located???



- Patrick
=======
 
Joined
Feb 1, 2011
Messages
4,434
Reaction score
2,151
Points
113
Location
Sacramento, California
Hi
I ran a full scan with VirusBarrier and it found two infected files.
Both said. imagesnap OSX/RobSnap.A
I cant delete or repair as don't have permission to access it.
Does anyone know what this is and should I be worried.

First, read this Intego article and see if it helps:


If that doesn't help, I recommend that you contact Intego's tech support and ask for guidance:

https://support.intego.com/hc/en-us/requests/new

All Macintosh malware is known. Looking at the archive for all Macintosh malware, I can tell you that an "Imagesnap" malware for the Macintosh doesn't exist. So I strongly doubt that you are "infected" with anything. More than likely it is something legitimate that VirusBarrier doesn't recognize. I recommend that you sit tight and wait to hear what Intego suggests.
 

Rod


Joined
Jun 12, 2011
Messages
9,702
Reaction score
1,888
Points
113
Location
Melbourne, Australia and Ubud, Bali, Indonesia
Your Mac's Specs
2021 M1 MacBook Pro 14" macOS 14.4.1, Mid 2010MacBook 13" iPhone 13 Pro max, iPad 6, Apple Watch SE.
At this point I think that maybe I should do a clean install.
I think thats a bit extreme, it may be that the files are PUP's, that is, Potentially Unwanted Programs. Some virus (malware) scanners will list these in a search.
Try DetectX Swift, available free from the developer here; https://sqwarq.com/detectx/
You can quarantine or remove fires direct from the app, no system file access required.
 
Joined
Sep 30, 2021
Messages
64
Reaction score
20
Points
8
Location
England
Is DetectX Swift still being supported? There was some doubt expressed here a few months ago so I stopped using it and switched to MWB.
 
Joined
May 21, 2012
Messages
10,745
Reaction score
1,193
Points
113
Location
Rhode Island
Your Mac's Specs
M1 Mac Studio, 11" iPad Pro 3rd Gen, iPhone 13 Pro Max, Watch Series 7, AirPods Pro
OP
D
Joined
Apr 30, 2012
Messages
463
Reaction score
14
Points
18
Location
Wales, UK
Your Mac's Specs
I Mac 27-inch 3.2 GHz Intel Core i5 24GB ram. MacBook Pro 13-inch 2.5GHz dual-core Intel i5 16GB ram
OP
D
Joined
Apr 30, 2012
Messages
463
Reaction score
14
Points
18
Location
Wales, UK
Your Mac's Specs
I Mac 27-inch 3.2 GHz Intel Core i5 24GB ram. MacBook Pro 13-inch 2.5GHz dual-core Intel i5 16GB ram
I'm almost sure it was Pray.
I followed the instructions to uninstall but it didn't work. I've decided to clean install anyway as it well overdue.
Thank you all for the help. This forum is a great help.
Brad
 

PhDMac

Member
Joined
Oct 16, 2023
Messages
6
Reaction score
2
Points
3
I have the same issue, virusbarrier detects the file RobSnap.A almost every day at around the same time.
It is in /private/var/folders/9q/rfx19hx17_b76k3t05pfvy8r0000gn/T/com.blacey.SuperDuper/8AA616B8-A4FC-454E-BCF4-2C3C6B8BA2D5/snapshot/usr/local/lib/prey/versions/1.11.9/lib/agent/providers/webcam/mac/imagesnap

@docx -> You think the RobSnap.A file was from Prey Project?
And with what did you do a clean install? With Prey?

FWIW, I also contacted Prey some time ago but they don't answer :-(
 
Last edited:
OP
D
Joined
Apr 30, 2012
Messages
463
Reaction score
14
Points
18
Location
Wales, UK
Your Mac's Specs
I Mac 27-inch 3.2 GHz Intel Core i5 24GB ram. MacBook Pro 13-inch 2.5GHz dual-core Intel i5 16GB ram
I have the same issue, virusbarrier detects the file RobSnap.A almost every day at around the same time.
It is in /private/var/folders/9q/rfx19hx17_b76k3t05pfvy8r0000gn/T/com.blacey.SuperDuper/8AA616B8-A4FC-454E-BCF4-2C3C6B8BA2D5/snapshot/usr/local/lib/prey/versions/1.11.9/lib/agent/providers/webcam/mac/imagesnap

@docx -> You think the RobSnap.A file was from Prey Project?
And with what did you do a clean install? With Prey?

FWIW, I also contacted Prey some time ago but they don't answer :-(
Hi.
I did a clean install of the OS. As I said it was well overdue anyway so it seemed like the right thing to do.
 
OP
D
Joined
Apr 30, 2012
Messages
463
Reaction score
14
Points
18
Location
Wales, UK
Your Mac's Specs
I Mac 27-inch 3.2 GHz Intel Core i5 24GB ram. MacBook Pro 13-inch 2.5GHz dual-core Intel i5 16GB ram
I did a clean install of the OS.
As I said it was well overdue anyway so it seemed like the right thing to do.
 

PhDMac

Member
Joined
Oct 16, 2023
Messages
6
Reaction score
2
Points
3
I did a clean install of the OS.
As I said it was well overdue anyway so it seemed like the right thing to do.
Thanks for your reply, but you didn't suspect it was caused by Prey (Prey Project)?
 
OP
D
Joined
Apr 30, 2012
Messages
463
Reaction score
14
Points
18
Location
Wales, UK
Your Mac's Specs
I Mac 27-inch 3.2 GHz Intel Core i5 24GB ram. MacBook Pro 13-inch 2.5GHz dual-core Intel i5 16GB ram
I was 90 percent sure it way prey. I think its to allow use of the camera if your device is stolen.
 

Shop Amazon


Shop for your Apple, Mac, iPhone and other computer products on Amazon.
We are a participant in the Amazon Services LLC Associates Program, an affiliate program designed to provide a means for us to earn fees by linking to Amazon and affiliated sites.
Top