Was almost scammed, and want to check if detritus was left behind. "Default Apps" in Settings—cannot be removed.

Running Sonoma 14.2 on a Retina 4k Mac 2019. Two concerns:


  1. Yesterday I was almost taken in by a scam and stupidly shared my desktop with the guy. I cut him off after 5 minutes, and am now trying to see if he left anything behind. I've removed the screen-sharing software he had me download, but have read in the community that: 1) anti-virus/malware scanners, like Malwarebytes, isn't that effective (I had it years ago and removed it), and 2) that anti-virus software, like Bitdefender, doesn't add further protection than what the Mac already provides. Is this true?


  1. In my Settings pane, there is something I don't recognize, "DefaultApps", and when I try to remove it by right-clicking, I get an alert that says "The file 'RCDefaultApp.prefPane" doesn't exist." (See screenshot.) What is this and how can I remove it?


Are there any steps I can take to see if the scammer left anything behind?


Thank you.


iMac 21.5″, 14.3

Posted on Feb 3, 2024 8:27 AM

Reply

Similar questions

6 replies

Feb 3, 2024 12:47 PM in response to gkgraphics

Safe mode - This computer is running in Safe Mode.


Don't run EtreCheck in Safe Mode. There's nothing wrong with Safe Mode, but potentially malicious apps or processes are not active in that mode. Restart your Mac normally, run it again, and post a new report.


Having said that, not even EtreCheck can provide absolute assurance of the absence of malware, Trojans, or various intrusions. Nothing can, so don't even look for something claiming that ability (such as the example you cited). The best EtreCheck or anything else might be able to accomplish is to identify the presence of something malicious — which might just exist as a distraction for something else more difficult to find.


This is the reason MrHoffman's recommendation is the only truly valid one:


Roll in your most recent backup from prior to the exploit, and change all your passwords including those associated with your password reset paths. Five minutes is a whole lot of time for a prepared attacker to upload sensitive data, if not also to install exploits.


👍

Feb 3, 2024 11:21 AM in response to gkgraphics

Nothing stands out from your EtreCheck report which is good. The major issue is shows is high CPU usage and the one that was identified was XProtectRemediatorWaterNet. This is an Apple process that will run in the background at times and is not unusual. As for the minor concerns, it does show some crashing/hanging issues that are identified as Safari. In that case, I would review any Extensions you have installed at Safari > Settings > Extensions. If there are some there that you do not need them remove them. By default there are no extensions installed on Safari. There are some orphan files which usually point to a file to launch, but the executable is missing. We can clean up some of those by following the steps below to post the screenshots of the file locations.


If you are no longer using the Transmit app, you can remove it from the Applications folder. It also contains a background process that will run when the computer is launched and if you do not use the app, then deleting it will also remove the background process.


Could you post a screenshot of these 5 locations by going to Finder > Go > Go to Folder and paste each one there. I normally would not ask for the preferencePane locations, but since your specific question deals with that I would include it. Normally those 2 preferencePane folders are empty by default, so if you have nothing in there then you do not need to include the screenshots of those.

/Library/LaunchDaemons

/Library/LaunchAgents

~/Library/LaunchAgents

/Library/PreferencePanes

~/Library/PreferencePanes

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Was almost scammed, and want to check if detritus was left behind. "Default Apps" in Settings—cannot be removed.

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.