suspect folder named 73UVK6498D

This is the 1st folder in my library>containers directory and has countless desktop & download files and links to keychains, address book data and many others. I am suspicious.


Earlier today I found and deleted a folder with"ru.keepcoder" in the file name, which is a known Malware and was the very last folder in the same directory. I found and deleted several more with the same name. They had similar data. Neither MalwareBytes nor BitDefender had picked these up.


Does anybody recognise 73UVK6498D please?


Running High Sierra.

Posted on Jul 1, 2024 12:28 PM

Reply
Question marked as Top-ranking reply

Posted on Jul 1, 2024 3:06 PM

Sorry, but all I can confirm is that folder is not on my system. It appears you are able to read some of the information provided in the plist file. I do wonder where it came from as you do. Have you used any of those third party app stores such as SetApp or iBoostUp!?


If it were me, I would check the folders on my computer that do actually launch files when it starts up to make sure there is nothing there that I do not recognize. You can go to Finder > Go > Go to Folder, and paste each of these locations there to review. Don't forget the "~" character in the second one.

/Library/LaunchDaemons

~/Library/LaunchAgents

/Library/LaunchAgents


If there are files that you are uncertain about, I would ask before deleting.

Similar questions

15 replies
Question marked as Top-ranking reply

Jul 1, 2024 3:06 PM in response to ontravel2

Sorry, but all I can confirm is that folder is not on my system. It appears you are able to read some of the information provided in the plist file. I do wonder where it came from as you do. Have you used any of those third party app stores such as SetApp or iBoostUp!?


If it were me, I would check the folders on my computer that do actually launch files when it starts up to make sure there is nothing there that I do not recognize. You can go to Finder > Go > Go to Folder, and paste each of these locations there to review. Don't forget the "~" character in the second one.

/Library/LaunchDaemons

~/Library/LaunchAgents

/Library/LaunchAgents


If there are files that you are uncertain about, I would ask before deleting.

Jul 2, 2024 6:16 AM in response to Mac Jim ID

Thanks, I had forgotten that location.


The clear answer is "File List Export" (listed on App Store as "Files List Export") which I apparently installed 1 Feb and which was updated 9 Feb. I might indeed have been looking for such a tool. I have just contacted the developer to ask about the folder name. Maybe it's all harmless.


Strange that the App Store didn't show the purchase. I need to check my credit card to see how I paid for it.


I see that many original Apple folders have a similar structure, basically showing the system directories, some files and many links to files. Perhaps I was overreacting after finding and deleting the "ru.keepcoder.Telegram" folder.


Jul 2, 2024 5:43 AM in response to ontravel2

ontravel2 wrote:

Where could I find a list of other Apps recently installed please? I have certainly installed apps since 9 Feb. (incl. Proton VPN and BitDefender), which did not come from the app store. I don't just remember which. However, as the plist was last opened 9 Feb, that seems to be a magical date, although a very unlikely one as I was travelling.

Here you go:

 > System Settings > General > About > System Report. Check Installations under the Software tab and you can then sort it by Date. Please update if you find anything.


Proton VPN and BitDefender would concern me, even if not related to the issue at hand. I stick with the golden rule on the Mac:

  • No Cleaners
  • No Optimizers
  • No AntiVirus
  • No VPN


I do understand there are specific use cases for VPN software, but there are many issues with them as well including selling your web traffic data. Since you use EtreCheck, you should have a good idea of the Extensions that are installed and some of them are difficult to remove.

Jul 1, 2024 5:33 PM in response to ontravel2

First, I think the action you are proposing to remove the folder is right on and I am aware of the Telegram Malware that you are referring to.


The contents of the plist file does reveal some clues. The process "storedownloadd" is a standard Apple process that appears when apps are updated and downloaded from the App Store. The extra "d" on the end is normal and stands for daemon, because it is a process that runs in the background and will check for updates in the App Store. It will also be called upon to download those apps. The app was also installed in your Applications folder. Something I would check is your purchase history by using the link to see if there were any apps installed on 2/9/24 from the App Store.

View your purchase history for the App Store and other Apple media services - Apple Support


Good to hear that you are not using other sites to download apps such as SetApp. These sites contain many apps available for download and some of those are less than legitimate containing Malware.

Jul 1, 2024 1:08 PM in response to Mac Jim ID

Indeed, the "ru.keepcoder" files were infact "ru.keepcoder.Telegram" although I do not have Telegram installed and have never used it.


I just did a local search for 73UVK6498D and found several occurrences:



Apparently the irregular location was the reason that the ru.keepcoder malware evaded detection. It might have been placed there hoping that I would use Telegram at some time.


I just did a complete disk search (not just user based) and found 2 additional files:



Do you believe the files 73UVK6498D might be needed elsewhere or can I just delete the folder?


Jul 1, 2024 5:01 PM in response to Mac Jim ID

I didn't know about other app stores, but would not use them anyway. I do have some apps from legit companies, but not installed since 9 Feb 2024 afaik.


The folders you kindly pointed to were clean and I also just deleted zoom which I hate and avoid. I regularly use EtreCheck, which normally picks up such things.


The plist screenshot shows "storedownloadd" which is misspelt with an extra d.


There are just so many shortcuts within the folder, incl. to my contacts (whom I do not want to compromise) and also to my favorite locations, which naturally is all very important data.


I was travelling, so I will make an immediate TM backup (which is normally on all the time when I am at base) and then delete the whole folder. It just sounds too risky!


Time will tell whether it is important, but I imagine not so, as you didn't find it on your system. It appears to fit into the category of the Telegram malware mentioned above, which just waits to be activated if certain circumstances arise. That incidentally bundles everything into a zip file and uploads it somewhere.


I prefer not to wait though ;-)


Thanks for your help.


Jul 2, 2024 4:42 AM in response to ontravel2

Where could I find a list of other Apps recently installed please? I have certainly installed apps since 9 Feb. (incl. Proton VPN and BitDefender), which did not come from the app store. I don't just remember which. However, as the plist was last opened 9 Feb, that seems to be a magical date, although a very unlikely one as I was travelling.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

suspect folder named 73UVK6498D

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.