XProtect Remediator and BadGacha

After installing the latest stable version of Chromium, I have been getting the following warnings when running an XProtect Remediator scan. I'm not sure if this is a bad issue, but I think it is something Apple should look at. Thanks.

Latest version of XProtectPayloads_10_15-120 now shows the following:

2023-12-03 14:45:17.487 BadGacha 👉 no status_message report time 0.0000000 {"process":{"pid":2265,"name":"crashpad_handler"},"status":null,"action":"report"} 2023-12-03 14:45:17.488 BadGacha 👉 no status_message report time 0.0000000 {"process":{"pid":2263,"name":"GoogleSoftwareUpdateAgent"},"status":null,"action":"report"} 2023-12-03 14:45:17.488 BadGacha 👉 no status_message report time 0.0000000 {"process":{"pid":2235,"name":"crashpad_handler"},"status":null,"action":"report"} 2023-12-03 14:45:17.488 BadGacha 👉 no status_message report time 0.0000000 {"process":{"pid":2233,"name":"GoogleSoftwareUpdateAgent"},"status":null,"action":"report"} 2023-12-03 14:45:17.512 BadGacha NoThreatDetected status_code 20 time 0.0000191

Replies

I'm seeing them too, but for 1Password-Crash-Handler and SnagitHelper2024.

2023-12-18 21:41:29.920 BadGacha 👉 no status_message report time 0.0000000 {"status":null,"action":"report","process":{"pid":3217,"name":"1Password-Crash-Handler"}} 2023-12-18 21:41:29.921 BadGacha 👉 no status_message report time 0.0000000 {"process":{"pid":1569,"name":"1Password-Crash-Handler"},"status":null,"action":"report"} 2023-12-18 21:41:29.921 BadGacha 👉 no status_message report time 0.0000000 {"status":null,"action":"report","process":{"pid":1541,"name":"SnagitHelper2024"}} 2023-12-18 21:41:30.001 BadGacha ⚠️ ThreatDetected time 0.0000330 {"status_message":"ThreatDetected","execution_duration":3.3020973205566406e-05,"status_code":21,"caused_by":[]}

Same for me:

2024-01-31 10:58:06.154 BadGacha 👉 no status_message report time 0.0000000 {"process":{"pid":2001,"name":"1Password-Crash-Handler"},"status":null,"action":"report"} 2024-01-31 10:58:08.464 BadGacha ⚠️ ThreatDetected time 0.0000371 {"status_message":"ThreatDetected","execution_duration":3.707408905029297e-05,"caused_by":[],"status_code":21}

Any update here?

  • ditto...

    2024-02-04 13:18:24.889 BadGacha 👉 no status_message report time 0.0000000 {"status":null,"process":{"pid":4625,"name":"1Password-Crash-Handler"},"action":"report"} 2024-02-04 13:18:25.901 BadGacha ⚠️ ThreatDetected time 0.0000521 {"status_message":"ThreatDetected","status_code":21,"caused_by":[],"execution_duration":5.2094459533691406e-05}

Add a Comment