You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Pulse Secure.app will damage your computer - Malware

Just yesterday I received the pop-up pictured below. From doing a little research, it looks like this is a known malware attack, but I can't figure out how to clear it. I'm running Big Sur v11.5.2 and BitDefender v9.0.0.3 (I do not have Traffic Light turned on for BitDefdender), yet the problem got through. A full scan with BitDefender didn't find a problem. I downloaded MalwareBytes this morning and ran a check with it, also no problems found. Any suggestions on how to repair? Thank you!!!


MacBook Pro 16″, macOS 11.5

Posted on Aug 26, 2021 6:27 AM

Reply
Question marked as Top-ranking reply

Posted on Aug 26, 2021 8:15 AM

The Application " Pulse Secure App " - the Developer may have revoked the Certificate for this version of the Application or has allowed the Certificate to lapse and / or Apple does not recognize the supplied Certificate included in this version of Application. Thusly the error message in original post.


The OS Big Sur is alerting you with this cryptic message.

Similar questions

24 replies
Question marked as Top-ranking reply

Aug 26, 2021 8:15 AM in response to MalwareTrouble

The Application " Pulse Secure App " - the Developer may have revoked the Certificate for this version of the Application or has allowed the Certificate to lapse and / or Apple does not recognize the supplied Certificate included in this version of Application. Thusly the error message in original post.


The OS Big Sur is alerting you with this cryptic message.

Aug 26, 2021 6:59 AM in response to MalwareTrouble

BitDefender v9.0.0.3 << Remove it ASAP.

Are there any AntiVirus, Disk Cleaner, Optimizers, Un-installers, etc installed which should be removed as per Developers Instructions. They are useless, unneeded, cause havoc and interfere with the normal operation of the OS and may even Corrupt the OS requiring a Reinstallation. The Built-in Security of Big Sur is all that is required.


There are no known Viruses in the wild that self replicate and affect macOS. There are Malware and Adware that does affect macOS and are often times downloaded as part of an Application from Third Party UnTrusted Site and get installed along with the Application.

Aug 26, 2021 7:28 AM in response to PRP_53

Hi "P" - and thank you for the quick reply.


I'm still getting the pop-up when I restart the computer with Wifi OFF and with no applications running on startup.


Here's what I've done:

-- uninstalled BitDefender

-- uninstalled MalwareBytes

-- uninstalled Secure Pulse (I can always re-install when I need it)

-- uninstalled Box and other unused apps that appear to run on start-up

-- ran disk repair utility on all volumes in recover mode (no errors found)

-- deleted all Safari extensions

-- deleted all Safari content blockers

-- deleted all Safari notifications

-- deleted all Safari pop-up windows


Problem is occurring on re-boot with Wifi off and before I load Safari.


Something is launching on startup but I don't know what!


Thoughts/suggestions?

Aug 26, 2021 7:34 AM in response to MalwareTrouble

First place to look is Users & Groups in System Preferences and you User Account ?? login Items. Anything in there that looks like it should not be there, the little minus (-) sign and Remove. Test after another reboot.


If that does not resolve the issue >>


Suggest downloading the Application Etrecheck directly from a Trusted Developer and well Respected ASC Contributor. The application is free or paid from added features. Run the application with Full Disc Access ( Security & Privacy - Full Disc Access ). It will take a Snap Shot -  both the hardware and software. The Report will Not Reveal Any Personal Information. Post back the Full Report - copy and paste - using the Additional Text Icon ( 3rd Icon to last )


We can have a look at the report for possible issues and may have possible suggestions to resolve the issues.

Aug 26, 2021 8:31 AM in response to PRP_53

Seems like you're not sure what's going on?


It's odd to me that Big Sur would provide this message when Pulse Secure has been uninstalled successfully. And it comes up every time I restart the system - not a one-time notice and no option to ask it not to tell me about this again.


The error message is consistent with other similar "xyz.app" will damage your computer messages that have been around for some number of years (based on a quick Google search) with other apps being flagged - the chatter on Google is that this is a malware problem.


I'm stumped. Anyone else know what might be the problem, or encountering something similar? At some point, I'll need to re-install Pulse Secure (VPN for work) and it would be nice to know the problem can be made to go away.


Thanks again for all your help getting this far - it's definitely progress.

Aug 26, 2021 9:57 AM in response to Keith Barkley

Hi Keith. Thank you for your thoughts.


I totally trust my IT department (I know, perhaps unusual), so I trust their selection of Pulse Secure as well.


On that basis, I did as you suggested: re-installed the app directly from the link on my company IT website (to make sure I got the version they're supporting) and matched it up with the version on the Pulse Secure website for Big Sur. Successful install, successful configuration of the VPN connection into the company private network. All good.


Except... The popup still appears. At this point, I think it's a nuisance, but am still concerned that something is running that I'm not aware of and that might be capturing data. I just can't figure out where the popup is coming from.


Any other suggestions?



Aug 26, 2021 10:22 AM in response to IdrisSeabright

Thank you!


I just realized after I wrote my post to Keith that I should loop in my company IT people: they really are world class based on my experience and I haven't included them yet because this is my personal laptop and not the one they issued me. Still: I'm going to share this thread with them and see if they know of a resolution. I'll reply on this thread with any insights they might provide in case it helps someone else.


Ugh - lots of wasted time!

Aug 26, 2021 11:52 AM in response to IdrisSeabright

While all the universities are cash-strapped right now, I'm fortunate to work for a big monster one with excellent resoures.


They got back to me right away and told me to delete the Pulse from the App folder, and delete the Pulse folder as well, then re-install off our internal intranet.


While I thought I had done this before to no avail, it now appears that this worked and I'm no longer getting the popup. I'm considering this resolved.


My thanks to all of you who weighed in with guidance and suggestions: it was all good and despite the time sync, I'm grateful that I've spent a few hours cleaning up stray "stuff" on my laptop in the process.

Aug 26, 2021 1:08 PM in response to MalwareTrouble

MalwareTrouble wrote:

The only login item is Dropbox, which I left turned on. No other entries in login items.

Ran Etrecheck and posting the full report below...

If it were just a login item, then it would be easy to fix. Unfortunately, when Apple issues these certificate revocations like this, they leave users in the lurch. It actually disables all of the software, including the uninstaller. There is no way you ever get rid of this software except manually and the error message will continue to show up until then.


Your EtreCheck report lists the files you'll need to remove. Here they are:


Launch Daemons:

[Other] net.pulsesecure.AccessService.plist (? 1d36417 - installed 2020-03-12)

[Loaded] net.pulsesecure.UninstallPulse.plist (? 54408489 - installed 2020-03-12)


Launch Agents:

[Other] net.pulsesecure.pulsetray.plist (? 3d73aecc - installed 2020-03-12)


The launch daemon files are in /Library/LaunchDaemons and the Launch Agents files are in /Library/LaunchAgents. Just go in there and manually delete the files listed above. Then delete the "Pulse Secure" file in /Library/Application Support. Then restart.

Aug 26, 2021 1:17 PM in response to etresoft

etresoft wrote:

If it were just a login item, then it would be easy to fix. Unfortunately, when Apple issues these certificate revocations like this, they leave users in the lurch. It actually disables all of the software, including the uninstaller. There is no way you ever get rid of this software except manually and the error message will continue to show up until then.

The Cisco AnyConnect revocation essentially rendered my computer unusable until I found and deleted everything Apple deemed harmful. And then I was in a panic as the only information that has ever been on the Univerisity website for working remotely is for Windows. When we went remote in 2020, I had the devil of a time finding someone who could give me the link for the Mac version. This time around, they came through pretty quickly, fortunately, and I'm back up and running.

Sep 23, 2021 5:23 AM in response to Pedro Canelas

The solution for me was to completely uninstall Pulse Secure, including searching the entire hard drive for anything related to it, then re-installing the app from the Pulse Secure website. I have since updated my OS to v11.6 with no issues.


I hope this is helpful! Thanks to Cynbeline (above) - that was the correct guidance. My IT department had seen the problem and knew what to do right away.


Good luck!

Sep 29, 2021 6:07 AM in response to Pedro Canelas

I agree with Pedro's response above: need to install a newer version. I found that this problem was NOT the result of malware as I originally thought, but rather caused by unsigned/improperly signed/out-of-date certificates from the developer. When Apple created an update in Big Sur (not sure exactly which version), they tightened their policies on developer certificates and generated this error message when the developer certificates didn't match Apple's requirements. After posting (and resolving) the issue with Pulse Secure that started this thread, I received similar messages with some HP printer drivers as well - with the same solution: deleting the driver in question then installing the latest version from develop websites.

Pulse Secure.app will damage your computer - Malware

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.