Virus? in startup running in background

I noticed 2 unrecognized Items in the bottom of the list, in Settings>General>Login Items, allow in the Background, (TNT-why join the navy if you can be a pirate) (Vesa Heikkila) I have turned them both of, but the TNT one randomly tuns back on... I want to Permanently remove them... I’ve tried running, Bitdefender , but no viruses found, Any one had similar problems? any help please....

Posted on Dec 20, 2022 9:09 AM

Reply

Similar questions

8 replies

Dec 20, 2022 11:11 AM in response to nickobee53

Do not start by deleting things through the terminal if you don't know what you're doing.


I would recommend the following:

  1. Get rid of CleanMyMac. It's pretty close to malware and can cause all sorts of problems.
  2. Download and run Etrecheck. It will generate a report with no personally identifying data that you can post here. It will let other people here in the forums see what's going on.


https://www.etrecheck.com/en/index.html




Dec 20, 2022 11:39 AM in response to Old Toad

Old Toad wrote:

Vesa Heikkila is the software developer for the IriunVR app. Apple, for some screwy reason, is not using developer's names in that settings pane instead of the app name.

Apple definitely uses developer names in the settings pane. In this case, the developer is using their personal developer account under their own name. Technically speaking, there's nothing wrong with that as long as you can verify that the app is genuine and not malware. In this case, that is really only possible through dumb luck and piecing together various bits and icons from various web sites.


The "TNT - why join the navy if you can be a pirate" item is more interesting. That's obviously a cracked/pirated/stolen Mac app. Just Google it. Such things often contain malware. What's more interesting is why it shows up that way in the list. It looks like Apple is using more than just the developer names in this settings pane. I guess that makes sense since "Rogue Amoeba Audio Capture Engine (ACE)" obviously isn't a developer name. In typical Apple fashion, none of this documented. We just have to guess at what it all means.

Dec 20, 2022 11:18 AM in response to nickobee53

Vesa Heikkila is the software developer for the IriunVR app. Apple, for some screwy reason, is not using developer's names in that settings pane instead of the app name.


Effective defenses against malware and other threats - Apple Community and Recognize and avoid phishing messages, phony support calls, and other scams - Apple Support.  


There are no known viruses, i.e. self propagating, for Macs.  There are, however, adware and malware which require the user to install although unwittingly most of the time thru sneaky links, etc.   


Anti Virus developers try to group all types as viruses into their ad campaigns of fear.  They do a poor job of the detecting and isolating the adware and malware.  Since there are no viruses these apps use up a lot of system resources searching for what is non-existent and adversely affect system and app performance.


There is one app, Malwarebytes, which was developed by a long time contributor to these forums and a highly respected member of the computer security community, that is designed solely to seek out adware and known malware and remove it.  The free version is more than adequate for most users.  


Don't worry about strange names in that settings pane.



[Edited by Moderator]

Dec 20, 2022 2:29 PM in response to nickobee53

Personally would be more concerned about two Applications installed and used on his computer.


Any Third Party Applications that will interfere with the normal operation of the OS,  is an invitation for disaster and comprise the Operating System


Certain Applications maybe available on the Apple Apps Store - this only means the Developer is prepared to pay Apple a portion on each sale. What the Application may do to the computer is up to the User to check this out before purchase


Any of the below should be removed as per Developers Instructions 


This will include CleanMyMac , This will include BitDefender


The Two above are on My List of the Top Two Applications to be removed


Read some of the posting and arrive at your own conclusions.


The The Built in Security  is all that is required.



Specific to CMM, MacKeeper and Dr Cleaner Pro Plus 


Some Contributors suggest restarting in Recovery Mode and choosing to Reinstall the Operating System over  the existing installation. 


This may or may not replace elements of the Entire Operating System including the Home Folder ( User Account )  and replace any corrupted or removed elements of the Operating System and make thing right.


Then there are Other Contributors ( like myself ) would suggest  from this link Use Disk Utility to erase a Mac with Apple silicon.


Thereafter to start from scratch and install all Required Application directly from the Apple Apps Store or Directly from the Developer.


If going this route - I suggest Not using Startup Assist to migrate things back as this will probably Re-Introduce the existing  issue that existed when the TM Backup was made 


EDITED - Spelling

Dec 20, 2022 2:01 PM in response to Old Toad

Old Toad wrote:

If they wanted to stay under the radar they wouldn't have signed it that way but egos do get in the way of reason at times.

Why would they want to stay under the radar? Did you think I was talking about some dark web site? LOL!


This is mainstream stuff. I've redacted the actual name to please the Apple moderators, but here is a screenshot of the site and their secure certificate:


Look closely at that certificate name. I left enough unreacted to see that it is a wildcard certificate. Those are expensive. I can't afford them.


I can assure you that there is absolutely no need to stay "under the radar" when you're committing crime on the internet. It's wide open. Of course, there are a handful of internet topics that would see you get yourself arrested, but really only 2 or 3. And even that would take years. For something like software piracy? No need to worry at all.

Dec 22, 2022 5:47 AM in response to Dogcow-Moof

Dogcow-Moof wrote:

The Rogue Amoeba listing is brilliant - it lets you know why it's there where if it just said Rogue Amoeba you'd wonder as a user which of their several apps installed something (I have four.)

I don’t think that they should necessarily get any credit for that. It’s just dumb luck.


It would be nice if Apple would document exactly how Ventura is displaying these things. It isn’t really fair to run a technology out of a hidden directory for 20 years and then one day make it presentable to the user. Apple isn’t displaying keywords like the label that one would use to control these items from the command line. In some cases, Apple only displays the Developer ID signature which is otherwise completely hidden from the user. It would have been really easy to define a new description field for the plist. That is standard procedure for Apple in many other areas when they want something shown to the user. But not in this case.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Virus? in startup running in background

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.