Unknown app asking for permissions

My wife's MacBook Air running Big Sur 11.6.8 has these two suspicious apps (?) showing up in the Automation window in Security and Privacy - SEE ATTACHED SCREENSHOTS. The second one that's just a string of numbers and letters occasionally launches a pop-up window asking for various permissions. I've deleted what I can identify (various plists and things with 'Artemis' in the title) using 'Go to Folder' and I've also run Etrecheck which picked up a couple more things to delete, but those two things are still showing in Automation after a restart. Are they buried in Terminal? How can we find and get rid of them? Thanks!



MacBook Air

Posted on Sep 28, 2022 10:09 AM

Reply
Question marked as Top-ranking reply

Posted on Sep 29, 2022 3:23 AM

This stuff is adware and it's a good thing that the OS is preventing it from controlling system events.


Do NOT allow.


Then run Etrecheck and post its report.

It is possible that Etrecheck itself can remove this and, if not, we can direct you but we need to see the report in order to give exact instructions.

20 replies

Sep 29, 2022 10:32 AM in response to FlexibleHead

FlexibleHead wrote:

Thanks, but that doesn't seem to work. The items in the Automation list can not be selected or removed, even with the panel unlocked - at least as far as I can figure it out.

Sorry. There are several similar lists and they behave differently. The only way to remove items from this list is using the "tccutil" command in the Terminal.

Also: 'Don’t forget to remove the other malware files.' - which files would those be?

These files:


Unsigned Files:

Launchd: ~/Library/LaunchAgents/com.13699978372956373152.plist

Executable: ~/Library/Application Support/com.5102018893395745718/12386668529505365717 0E59F9FA-0276-5D8C-9CCC-276B197C958C 4238


Launchd: ~/Library/LaunchAgents/com.C3E1DB77.0D5C.4A33.9FDE.1B9A0A83DB5E.plist

Executable: /usr/bin/python '/Users/***/Library/Application Support/.2B460CC2-5890-4AE6-956D-0DA3DED726E9/.89E00556-B36D-429C-95C2-2446950572EC'


Launchd: ~/Library/LaunchAgents/com.18182571439639782993.11694573007.plist

Executable: ~/Library/Application Support/com.18358866630251488148/6532257702012041747 5D96AECF-C5EB-417F-A3B8-9D30722728D5 00930035-3D5C-4E56-9DB1-35D1E9937BF1


Launchd: ~/Library/LaunchAgents/com.2BD0429A.ED72.4DEF.B852.8FBCD6D3415F.plist

Executable: ~/Library/Application Support/.731F3950-DE78-4F3D-817E-1E43FF48FB2F/.DAAF845C-BFAC-4774-9503-C75F47FE0F6B h


The issue here is that I'm trying to remove malware but I don't know where to remove it from.

Use the Security page in your EtreCheck report to remove the files.

Sep 29, 2022 1:47 AM in response to FlexibleHead

Good work there on the trouble shooting thus far 👍


The more eyes on this Etrecheck Report - we maybe be able to point you in the right direction.


Post back the Full Report - copy and paste - using the Additional Text Icon ( 3rd Icon to last )


We can have a look at the report for possible issues and may have possible suggestions to resolve the issues

Sep 29, 2022 7:42 AM in response to FlexibleHead

Q -  Battery failure - Your battery is reporting that it needs to be serviced.

Q -  High battery cycle count - Your battery may be losing capacity.

Q - Battery: Health = Service Battery - Cycle count = 886

A - Batteries are considered Consumable Products. Over time it will degrade to a point where it needs to be replaced. The usage is normal as the capacity will go up and down all the time and never stay always at 100%. Apple Batteries are rated for 1000 Full Battery Cycles and / or 80% Capacity before needing Evaluation or replacement.


Q -  Unsigned files - There are unsigned software files installed that could be malicious and should be reviewed.

A - Self explanatory


Q -  Automatic updates disabled - Automatic updates are disabled. This computer is at risk of malware infection.

A - Personal Choice 


Q -  Security updates disabled - Security updates are disabled. This computer is at risk of malware infection

A - Personal Choice.


Q -  Apple security disabled - Apple security software is disabled. This computer is at risk of malware infection.

A - Personal Choice


Q - Obsolete hardware - This computer may be considered obsolete.

A - Self explanatory 


Q -  SSD too slow - SSD is showing poor performance.

A - Could be a sign of Failing Drive or Lack Of Empty Space on the drive. This will dovetail in later review below 


Q -  No Time Machine backup - Time Machine backup not found.

A -  Anything of the Personal Variety In the way of Data that can not Replaced or Reproduced is worth Protecting. Right now, the Personal Data is a high risk of being lost forever

A - Time Machine Backup  is very useful.


Q -  Low disk space - This computer is running low on free hard drive space.

A - Again this dovetails to later evidence the computer is about  cease to function as intended and if left unattended to - could Cease to Boot Up At All.     


Hardware Information:  MacBook Air (13-inch, 2013-2014)

Drives:


Q - disk0 - APPLE SSD SD0128F 121.33 GB (Solid State - TRIM: Yes)

 disk1s5s1 - Macintosh HD [APFS Snapshot]


        Filesystem: APFS


        Mount point: /


        Read-only: Yes


        Used: 22.21 GB


        Shared values


            Size: 121.12 GB


            Free: 28.90 GB


            Available: 29.63 GB


System Software:


Q -  macOS Big Sur 11.6.8 (20G730) 

A - Current stable version of Big Sur is 11.7 but you will need to do some Serious House Cleaning before attempting the update. Big Sur 11.7 needs space to download, then Expand and only then Install.


Q -  Unsigned Files:

A - All the below are beyond my Scope and Skill Set to assist with 


1 - Launchd: ~/Library/LaunchAgents/com.13699978372956373152.plist


2 - Launchd: ~/Library/LaunchAgents/com.C3E1DB77.0D5C.4A33.9FDE.1B9A0A83DB5E.plist


        Executable: /usr/bin/python '/Users/***/Library/Application Support/.2B460CC2-5890-4AE6-956D-0DA3DED726E9/.89E00556-B36D-429C-95C2-2446950572EC'


3 - Launchd: ~/Library/LaunchAgents/com.18182571439639782993.11694573007.plist


        Executable: ~/Library/Application Support/com.18358866630251488148/6532257702012041747 5D96AECF-C5EB-417F-A3B8-9D30722728D5 00930035-3D5C-4E56-9DB1-35D1E9937BF1


4 -  Launchd: ~/Library/LaunchAgents/com.2BD0429A.ED72.4DEF.B852.8FBCD6D3415F.plist


        Executable: ~/Library/Application Support/.731F3950-DE78-4F3D-817E-1E43FF48FB2F/.DAAF845C-BFAC-4774-9503-C75F47FE0F6B h


        Details: Executable file is hidden - possibly malware


 5 -   [Not Loaded] com.apple.installer.cleanupinstaller.plist (Not signed - installed 2020-12-17)


User Launch Agents:


6 -     [Not Loaded] com.13699978372956373152.plist (Not signed - installed 2022-09-28)


7 -    [Not Loaded] com.18182571439639782993.11694573007.plist (Not signed - installed 2020-12-17)


8 -    [Not Loaded] com.2BD0429A.ED72.4DEF.B852.8FBCD6D3415F.plist (Not signed - installed 2022-09-28)


9 -   [Not Loaded] com.C3E1DB77.0D5C.4A33.9FDE.1B9A0A83DB5E.plist (Not signed - installed 2020-11-17)


    

Sep 29, 2022 5:07 AM in response to FlexibleHead

Thank you for the Report.


WE, @ Luis S and Self ( I ) will dissect it, in detail. 


Will get back to you shortly


Though, suggest updating the Etrecheck Application to current version 6.7.1 and then run a New Report and post that specific report .


EtreCheck version: 5.7.2 (5247) as per supplied report


Further, this was nothing personal in an earlier posting but looking out for the Best Interests of the Computer

Sep 29, 2022 5:50 AM in response to Owl-53

My apologies to Luis for the snappy response. I appreciate the help, and I especially appreciate that you're neither of you is one of those Apple guys that starts a post with 'I understand' and then ignores every single thing you've written.


Etrecheck updated as recommended, which flagged up a new thing, which I've also now deleted. This has had the effect of removing the icon that looks like the Terminal from one of the results in Automation, but it's still showing up by name. There are other unsigned files coming up for review that are just strings of numbers, but I guess I shouldn't delete those without knowing what they are? Screenshot of Automation as it currently looks follows (with newly added Etrecheck!). New Etrecheck report attached.


Cheers again!



Sep 29, 2022 5:56 AM in response to FlexibleHead

Edit - I've removed the following, but Automation still appears as per the previous screenshot (after a restart):


~/Library/LaunchAgents/com.2BD0429A.ED72.4DEF.B852.8FBCD6D3415F.plist

Executable: ~/Library/Application Support/.731F3950-DE78-4F3D-817E-1E43FF48FB2F/.DAAF845C-BFAC-4774-9503-C75F47FE0F6B h

Details: Executable file is hidden - possibly malware

Sep 29, 2022 6:32 AM in response to etresoft

Thanks, but that doesn't seem to work. The items in the Automation list can not be selected or removed, even with the panel unlocked - at least as far as I can figure it out.


Also: 'Don’t forget to remove the other malware files.' - which files would those be? The issue here is that I'm trying to remove malware but I don't know where to remove it from. Have you actually read this thread?

Sep 29, 2022 7:57 AM in response to FlexibleHead

FlexibleHead wrote:

Thanks P, but I'm not sure what question you think you're answering.

All the questions included in the Now Up To Date version of Etrecheck and supplied Report Above .


There has been sufficient advise offered , from at least 3 different Contributors, for the User ( you ) to make an informed and educated choice what the next course of action is required for this computer.


The suggestions have been put forth on a volunteer basis, in good faith.


Shall not take up any more of your time


Good Luck with this computer issue


EDITED

Sep 29, 2022 8:35 AM in response to FlexibleHead

To answer directly, I don't know how you'd make them disappear from the list in System Preferences.

I do know that, since they have been removed, and, anyway, the box is unchecked, they will not be doing anything, anyway, so in that regard you seem to be safe.


On the other hand, suppose you go to the doctor for a splinter in your finger, and the doctor says "your blood pressure is dangerously high", would you tell the doctor "that's not what I came here for"?


The issues that were noted by P. Phillips are very relevant. A dead battery can swollen, cause erratic behavior, or worse. And if your wife's mac dies as a result, all her data will be lost, in the absence of a backup (it does not have to be Time Machine, but that is by far the easiest way to keep a backup up to date).

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Unknown app asking for permissions

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.