Check for Malware on MacAir M1

I read a reply from 2018 that suggested Malwarebytes as an option to check for Malware, but am wondering if that is still valid for the new M1 MacBooks?

MacBook Air 13″, OS X 10.11

Posted on Aug 29, 2021 6:56 AM

Reply
Question marked as Top-ranking reply

Posted on Aug 29, 2021 7:03 AM

Yes still valid way to check for Malware / Adware and so is Etrecheck


Suggest downloading the Application Etrecheck directly from a Trusted Developer and well Respected ASC Contributor. The application is free or paid from added features. Run the application with Full Disc Access ( Security & Privacy - Full Disc Access ). It will take a Snap Shot -  both the hardware and software. The Report will Not Reveal Any Personal Information. Post back the Full Report - copy and paste - using the Additional Text Icon ( 3rd Icon to last )




We can have a look at the report for possible issues and may have possible suggestions to resolve the issues.



Similar questions

27 replies

Aug 29, 2021 5:12 PM in response to Tamlouie

Tamlouie wrote:

I cannot find that Trusteer is on my system. I see the extensions and it states that I need to uninstall the rapportd application. I cannot find it.

You will not be able to find most of the files listed on your EtreCheck report. That is kind of the reason it exists in the first place. All these files are in hidden directories and usually require special uninstaller apps to remove. You can't just drag files to the trash to uninstall them.


Here are instructions on how to uninstall Trusteer: https://www.ibm.com/docs/en/trusteer-rapport/1955?topic=rapport-uninstalling-mac-os



Aug 30, 2021 11:49 AM in response to etresoft

I used the link you gave. Since I cannot find the.dmg file, the instructions say I will need to install it again by following the link they provide:

Note: If you cannot locate the .dmg file, or if the file does not contain the uninstallation application, you must download the installer again from the following link: https://trusteer.secure.force.com/PKB/articles/en_US/FAQ/Download-rapport.

However the link takes me to a notice about a third party site with another link to use, but that one states the page isn't found.


Am I missing something? I'd like to uninstall Trusteer for sure.

Aug 31, 2021 10:22 AM in response to etresoft

That is fabulous! I was able to remove the first two but the two Safari extensions gave me:

The “Rapport Extension” extension is part of the “rapportd” application.

To uninstall “Rapport Extension”, you must remove the “rapportd” application.


So I clicked find in Finder and it showed a lot of icon/files. I could not delete the main Rapport Icon because it stated it was open. I was able to move all the other files in the bin to the trash, but can't remove the extensions because it states each are open. Here is what I saw before moving all but one to trash:

All that is left is the green icon for Rapport app which can't be taken to trash because it is open somehow

Aug 31, 2021 10:46 AM in response to Tamlouie

You won't be able to find these files in the Finder. To make matters worse, Apple has its own "rapport" software that has nothing to do with Trusteer. Don't worry though. Recent versions of macOS won't let you damage the operating system.


Use the above procedure using the Finder's Go menu to navigate to the following folder:


/Library


Locate the Rapport folder and drag it to the trash. As instructed above, you may need to do this in Safe Mode.

Aug 31, 2021 12:23 PM in response to Tamlouie

Tamlouie wrote:

That worked thank you. I am hopeful I didn't mess up anything with macOS.

I didn't have to do this in Safe Mode. Should I check in Safe Mode to be sure?

No. I think you're good now. Restart your computer. Then generate a new EtreCheck report and make sure it doesn't say "trusteer" anywhere. You could do a search for "rapport", but you might find the system version, which is completely different.

Aug 29, 2021 7:43 AM in response to Owl-53

Thanks. From your answer does that mean your opinion is that Etrecheck works better for MacBooks than Malwarebyte? On my old MacAir I used the free version of Mbytes and it worked well and I am more familiar with it. Perhaps you suggest neither of the free versions, but a paid version?

Since I now have a brand new M1 8core I thought I was clear to continue on as normal. When I first clicked on my Google Chrome icon, a note popped that read to access it I had to download Rosetta which I thought odd, but like a dummy clicked ok since I had barely done anything with the laptop yet to have a bug. Pops ups came stating I had to get rid of Amazon Music and send to trash. I hadn't used Music yet, so clicked cancel a few times as it repeated the prompt. Then system preference opened as did a webpage that read "thank you for installing Rapport". Closed everything, uninstalled Chrome, Malwarebytes, tried to follow Apple support links to uninstall Rapport, but the link was old.

So here I am wondering what the heck? It's brand new; when I looked under Security and Privacy, I saw that my firewall was turned off! I don't get that either since I wasn't instructed at the onset that I had to turn it on since the system was new.

I am a more of a novice with tech, so since 2013 I have kept things as clean and simple as possible with my old Air. I had hoped the new system would be even better able to help with that.


This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Check for Malware on MacAir M1

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.