You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Install files randomly created on MacBook Pro 16”, 2019


I have something on my drive that has been randomly creating Install files for the past two weeks or so. I can eject them, but more are created. I have gone into Disk Utility and found the drive there, but that just ejects the file, but still more are created. If I click on it, it wants to install Ept and I have no clue as to what that might be.


I’d appreciate any help ideas that may help me track this originating file down as I really don’t want to have to format the drive and start over!


Thanks!



MacBook Pro 16″, macOS 12.2

Posted on Feb 23, 2022 1:43 PM

Reply
8 replies

Feb 23, 2022 2:07 PM in response to paulafrompekin

Do they all have the same title?

Are you downloading things before they occur?


Download and run this app so we can find more information about your installation.

https://etrecheck.com/upgrade

It shows what is launched and other information and is very useful in finding causes of problems. After you first launch the app make sure you check Enable full disk access in the box in lower left.


After running the app use the app's feature to paste to clipboard. Then paste it in the text box for a reply in this forum click on the addition text icon. This is because the normal reply text box limits how much you can type.

No personal identifiable information is contained if the app output. The app was written for a person who is contributor to these Apple Support Communities

Feb 23, 2022 3:36 PM in response to paulafrompekin

Finding: More than one antivirus app - This computer has multiple antivirus apps installed.

CleanMyMac, Symantec, Apple, and Malwarebytes

System Extensions:

[Running] Avast Antivirus System Extension - version 4.1.103 (AVAST Software a.s. - 2022-02-21)

Application: /Applications/Avast.app - version 4.1.103

Action: Uninstall CleanMyMac and Symantec using using instructions provided by the developers. MalwareBytes is OK but only ru it manually. Have on extra antivirus app is bad enough two is asking for problems.


Finding: Unsigned Files:

Launchd: ~/Library/LaunchAgents/com.wqmyugdlgzqedafpoqrjbyenhxousi.plist.plist

Executable: /bin/bash -c 'sudo /tmp/LjJAsTQYXB1K pkgsh && rm /tmp/LjJAsTQYXB1K && /bin/launchctl bootout gui/501/com.wqmyugdlgzqedafpoqrjbyenhxousi.plist'

Details: Domain name invalid - possibly adware

Launchd: ~/Library/LaunchAgents/com.mgtdxwjjjgedfbvtxpajrnonbhcorf.plist.plist

Executable: /bin/bash -c 'sudo /tmp/bbt9xMGsY9zd pkgsh && rm /tmp/bbt9xMGsY9zd && /bin/launchctl bootout gui/501/com.mgtdxwjjjgedfbvtxpajrnonbhcorf.plist'

Details: Domain name invalid - possibly adware

Launchd: ~/Library/LaunchAgents/com.vtzyrrmjriroqinjxarkytxrbalbzc.plist.plist

Executable: /bin/bash -c 'sudo /tmp/taFZrJCclOPz pkgsh && rm /tmp/taFZrJCclOPz && /bin/launchctl bootout gui/501/com.vtzyrrmjriroqinjxarkytxrbalbzc.plist'

Details: Domain name invalid - possibly adware

Launchd: ~/Library/LaunchAgents/com.bkxghlwalclgunnsjwjpxjtezqbeqd.plist.plist

Executable: /bin/bash -c 'sudo /tmp/RMf94Q5boRCg pkgsh && rm /tmp/RMf94Q5boRCg && /bin/launchctl bootout gui/501/com.bkxghlwalclgunnsjwjpxjtezqbeqd.plist'

Details: Domain name invalid - possibly adware

Action: Remove these items. I think EtreCheck says how to do this.


Feb 23, 2022 4:41 PM in response to paulafrompekin

Well, that's the nature of malware. It doesn't want to give up so easily. Just keep going. When you've deleted all you can delete, restart your Mac, generate a new EtreCheck report, and do it all over again. Hopefully you get to a point where they are all gone.


You have a couple of malware files that weren't mentioned above. Here are then files you need to delete:


Unsigned Files:

Launchd: ~/Library/LaunchAgents/com.wqmyugdlgzqedafpoqrjbyenhxousi.plist.plist


Launchd: ~/Library/LaunchAgents/com.mgtdxwjjjgedfbvtxpajrnonbhcorf.plist.plist


Launchd: /Library/LaunchDaemons/com.buffer.system.plist

Executable: /Library/Application Support/System/SystemBuffer


Launchd: ~/Library/LaunchAgents/com.epxlxsggsygaerbzxgylfnvxtsudyd.plist.plist


Launchd: ~/Library/LaunchAgents/com.vtzyrrmjriroqinjxarkytxrbalbzc.plist.plist


Launchd: ~/Library/LaunchAgents/com.bkxghlwalclgunnsjwjpxjtezqbeqd.plist.plist


These are unusual files. I haven't seen any like most of these before. That explains why EtreCheck is a bit confused about them.


Please do NOT attempt to use EtreCheck to remove your antivirus apps. Clearly, they aren't protecting you from this malware. But they will be much more difficult to remove.


The only way to remove these files is with official uninstallers or uninstallation instructions provided directly by the developer. Never use an “app zapper” or “clean up” tool to uninstall software. Never try to manually delete files in these hidden directories by hand. Do not use EtreCheck’s “Remove” buttons either. Those are only designed for adware and malware.


I am NOT kidding about this. It looks like you've already attempted to uninstall Avast and left if running an undefined state. There wasn't enough of it left for EtreCheck to recognize as an Antivirus. You will need to reinstall Avast and then uninstall it using the proper procedure.

Feb 24, 2022 7:22 AM in response to etresoft

Thanks for all of your help. I have ultimately deleted and am reinstalling everything…thank goodness I backup with Time Machine. I have deleted the partition and reinstalled Monterey. Before I reinstall any data, I am waiting to see if this malware tries to install again. Next, I will probably just reinstall the apps I use regularly (not restore), then only restore data files I am sure I still need.

I have been working on this for several weeks and I think this is the best route at this time. Thanks, again!

Feb 24, 2022 8:03 AM in response to paulafrompekin

Sorry, but you probably should have checked first. Time Machine is probably not going to help you. It backs up all data, including malware, and reinstalls it.


If you haven't reinstalled any data yet, then you don't have to worry about the malware reinstalling itself. Malware never installs itself. Malware gets installed by tricking the user into installing it.


Unless you manually drag your documents over from your backup, you have a very good chance of reinstalling the malware. However, malware is relatively easy to remove. Just use the list of files I posted above. If you get any new ones, EtreCheck will usually identify them as "probably adware".


I wouldn't really recommend a manual reinstall like this. It's a lot of work. But if you've already erased, it is at least an easy way to remove the antivirus apps that weren't working. Those are much more difficult to remove than malware. Funny that.


PS: Thanks for posting your EtreCheck report. Your malware files are quite unusual. I'm going to make some changes to try to better handle these kinds of things.

Feb 24, 2022 8:58 AM in response to etresoft

Thanks...I haven't reinstalled any data...yet, but I do have to reinstall some of my documents as they are "work" types of files. Will see how it goes, and yes, I was planning on dragging them over individually.


I appreciate you help with this. Installing my required software now (MS Office, Quicken, etc.) and then onto the data. As a retired IT Specialist, I have years and years of experience with Windows, but am pretty new to Mac OS...since my retirement, actually. This only helps me learn more about the beast!


Thanks, again!

Install files randomly created on MacBook Pro 16”, 2019

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.