Apple’s Worldwide Developers Conference to kick off June 10 at 10 a.m. PDT with Keynote address

The Keynote will be available to stream on apple.com, the Apple Developer app, the Apple TV app, and the Apple YouTube channel. On-demand playback will be available after the conclusion of the stream.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Is there any malware?

My question is are any of these files suspicious or malware?

iMac 21.5″, macOS 11.7

Posted on Jan 2, 2023 7:56 PM

Reply
Question marked as Best reply

Posted on Jan 2, 2023 10:18 PM

kang1st Said:

"Is there any malware?: My question is are any of these files suspicious or malware?"

-------


Thank you for the screenshot.


To browse for Malware on a Mac...


Use of MalwareBytes for Mac

This is software that searches for malware/adware. So, scan with it and then remove what is found. Once removed, uninstall MalwareBytes for Mac. Then restart the Mac. This software has been created by Long Time Users of these Forums. So, that makes it reliable for Macs.

Downloads:

  1. Malwarebytes Anti-Malware for Mac
  2. Malwarebytes uninstaller
3 replies
Question marked as Best reply

Jan 2, 2023 10:18 PM in response to kang1st

kang1st Said:

"Is there any malware?: My question is are any of these files suspicious or malware?"

-------


Thank you for the screenshot.


To browse for Malware on a Mac...


Use of MalwareBytes for Mac

This is software that searches for malware/adware. So, scan with it and then remove what is found. Once removed, uninstall MalwareBytes for Mac. Then restart the Mac. This software has been created by Long Time Users of these Forums. So, that makes it reliable for Macs.

Downloads:

  1. Malwarebytes Anti-Malware for Mac
  2. Malwarebytes uninstaller

Jan 2, 2023 10:19 PM in response to kang1st

Start here: Personal Safety User Guide - Apple Support


Consider an upgrade to current macOS, particularly if you’re concerned about security.


As for posting effectively random screenshots of property list files, or log dumps or analytics as others have done, that serves no viable diagnostic purpose. Nobody can answer your question with any certainty.


The build-in security does well against malware, but (again) you are on an older macOS version, with older security features.


Very likely not associated with malware, but… these are screenshots of who-knows-what contents. Almost certainly benign, but nobody here can know with certainty.

Jan 3, 2023 12:21 PM in response to kang1st

kang1st wrote:
My question is are any of these files suspicious or malware?


Yes, certainly. Some if not all of the suspicious files in your first screenshot were probably installed as a consequence of downloading a non-Apple "media player" product from a dubious website. Don't do that. To avoid making that sort of mistake again, read Effective defenses against malware and other threats - Apple Community.


To fix it follow the instructions below. You don't need to download or install anything to fix it.



First, ensure you have a reliable backup of your Mac, in case something should go wrong with continued troubleshooting. To learn how to do that, please read Back up your Mac with Time Machine.


  • A backup is a fundamental prerequisite regardless of whatever method you may choose uninstall adware, and would apply even if your Mac were running perfectly well. Do not overlook this fundamental requirement. It's important.


Next: This step will prevent the scam products from loading so that they can be removed while they are inactive. Restart in "Safe Mode", and log in: How to use safe mode on your Mac. Starting in Safe Mode takes longer than usual so let it finish. The rogue processes affecting that Mac are inoperative in "Safe Mode".


The following files and / or folders need to be deleted while using your Mac in "Safe Mode":


First screenshot:



Drag that selection of files to the Trash. You may be asked to authenticate. Confirm they are no longer present in that folder. Leave all the others alone for now.


The files in the other two screenshots are ok.


Next: open Safari and select the Safari menu > Preferences... > Extensions. If you see any Safari Extensions that you do not recognize or understand, simply click the Uninstall button and they will be gone. No Safari Extensions are required for normal operation. Then, select the General pane and review your Homepage selection. Repeat those equivalent actions for any other browser you may use (Brave, Firefox, or Opera for example).


There may also be adware-associated app icons in your Mac's Applications folder. Open it and examine its contents. Any unwanted or mysterious app icons should be obvious to you, but again please don't remove anything if you are uncertain—ask first. Identify any suspicious apps by name, or post another screenshot.


Next: In an abundance of caution, examine System Preferences > Extensions. Determine if there are any System Extensions that may have been installed without your knowledge. Ask if you're uncertain.


Remaining in System Preferences, check for the presence of any Profiles. Profiles are installed by organizations with a need to manage Macs deployed in institutional corporate or educational environments (for example), but have also been exploited by adware creators and similar malcontents. If any Profiles are installed on your Mac an icon like this will appear in System Preferences:



If you see that icon in System Preferences, select it. To remove a Profile, select it, then click the [—] (minus) button and authenticate.


Remaining in System Preferences, open Users & Groups. Select your User Account's Login Items. You may or may not find those Applications in its list. If you do, select them then click the [—] (minus) button to remove them from Login Items.


You can then restart your Mac and log in as usual. Evaluate its operation and ensure everything is working as you expect it should.


Next: if you want to eradicate all remaining adware remnants post a screenshot of the following folder, in the same manner as you did earlier:


~/Library/Application Support


It is normal for that folder to contain many items, but anything associated with the above adware may contain identical names. If you find a folder or folders bearing those names, drag those folders to the Trash. Without the files you already removed or the reintroduction of similar malware, they can do nothing but occupy space. These can be removed if you wish, but again don't remove anything if you are uncertain.


Finally: If any of the above actions result in abnormal operation or if something else stops working, the easiest way to recover would be to restore the Time Machine backup you created as a prerequisite, so the importance of that fundamental step cannot be overemphasized.

Is there any malware?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.