Possible / probable false positive Trojan.OSX.Generic detection on SABnzbd.app
Posted: September 4th, 2025, 1:54 pm
I suspect what's happening is a false positive detection, but wanted to check to see if this is happening with anyone else.
2.) Scheduled full scan ran on boot drive on Tuesday, 26 August with definition version 1.4.1_update_06 2380.2443. Nothing was detected.
3.) Scheduled full scan ran on boot drive on Tuesday, 2 September with definition version 1.4.1_update_06 2382.2445. Detected SABnzbd.app as Trojan.OSX.Generic. (That's as detailed as the scan report gets.)
I only mentioned the definitions version because that's the only thing between the two programs that changed between the two scans. This suggests to me that either the definitions improved and this is a valid detection, or the definitions changed such that it's now detecting something within the app as a false positive. I strongly suspect the latter.
I've already reached out to ClamXAV and provided a link to the SABnzbd Mac download page for them to check the file (today, I re-downloaded the 4.5.3 DMG file for Mac, and when I tried mounting the disk image, the QuickScan detected the same thing; couldn't be quarantined because it was on the disk image). However, I have no idea when I'll hear from them.
I tried looking around the SABnzbd site and the forums to see if there was any note about the packages being checked for malware before release. (I tried looking around the site and I couldn't find anything.) Mind you, I've been using SABnzbd for years, and I have no reason not to trust it, but if I could find such a note, I would feel better about releasing the app from quarantine.
Thanks in advance,
sandra
- Using ClamXAV 3.9.1
- Using SABnzbd 4.5.3
2.) Scheduled full scan ran on boot drive on Tuesday, 26 August with definition version 1.4.1_update_06 2380.2443. Nothing was detected.
3.) Scheduled full scan ran on boot drive on Tuesday, 2 September with definition version 1.4.1_update_06 2382.2445. Detected SABnzbd.app as Trojan.OSX.Generic. (That's as detailed as the scan report gets.)
I only mentioned the definitions version because that's the only thing between the two programs that changed between the two scans. This suggests to me that either the definitions improved and this is a valid detection, or the definitions changed such that it's now detecting something within the app as a false positive. I strongly suspect the latter.
I've already reached out to ClamXAV and provided a link to the SABnzbd Mac download page for them to check the file (today, I re-downloaded the 4.5.3 DMG file for Mac, and when I tried mounting the disk image, the QuickScan detected the same thing; couldn't be quarantined because it was on the disk image). However, I have no idea when I'll hear from them.
I tried looking around the SABnzbd site and the forums to see if there was any note about the packages being checked for malware before release. (I tried looking around the site and I couldn't find anything.) Mind you, I've been using SABnzbd for years, and I have no reason not to trust it, but if I could find such a note, I would feel better about releasing the app from quarantine.
Thanks in advance,
sandra