Apple Event: May 7th at 7 am PT

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

10.9.5 Virus vs NotSigned Applications, Frameworks, Extensions

Hello World,

I’m a bit frustrated, so your comments are really appreciated.


1. I performed Fresh-Clean install of OSx 10.9.5 (on erased SSD).

2. Then downloaded 5 core programs from AppStore:

Final Cut

Compressor

Motion

Logic Pro X

iPhoto

3. Than maintained suggested updates.

User uploaded file


Now i can see some unknown applications, frameworks and extensions reported by “About this Mac/More Info”:


Unknown Applications:

User uploaded file


/System/Library/CoreServices/Feedback Assistant.app


/Library/Application Support/Script Editor/Templates/Cocoa-AppleScript Applet.app

/Library/Application Support/Script Editor/Templates/Droplets/Droplet with Settable Properties.app

/Library/Application Support/Script Editor/Templates/Droplets/Recursive File Processing Droplet.app

/Library/Application Support/Script Editor/Templates/Droplets/Recursive image File Processing Droplet.app



Unknown Frameworks:

User uploaded file

/System/Library/Frameworks/System.framework

/System/Library/Frameworks/Automator.framework/Frameworks/MediaBrowser.framework


/System/Library/PrivateFrameworks/AirPortDevices.framework

/System/Library/PrivateFrameworks/FaceCoreLight.framework

/System/Library/PrivateFrameworks/GPUSupport.framework

/System/Library/PrivateFrameworks/VCXMPP.framework/Frameworks/libxml.framework



Unknown Extensions:

User uploaded file

Unknown:

/System/Library/Extensions/IOAHCIFamily.kext/Contents/PlugIns/IOAHCIBlockStorage .kex (loaded)


Not Signed:

/System/Library/Extensions/Accusys6xxxx.kext

/System/Library/Extensions/ATTOCelerityFC.kext

/System/Library/Extensions/ATTOExpressPCI4.kext

/System/Library/Extensions/ATTOExpressSASHBA.kext

/System/Library/Extensions/ATTOExpressSASHBA3.kext

/System/Library/Extensions/ATTOExpressSASRAID.kext

/System/Library/Extensions/JMicronATA.kext




Let me stress: this is fresh-clean install on erased Samsung SSD and everything came from AppStore.

I do really appreciate your comments,

Thanks.

MacBook Pro, OS X Mavericks (10.9.5), null

Posted on Apr 7, 2015 5:15 AM

Reply
5 replies

Apr 9, 2015 10:46 AM in response to WilliamCooper

These drivers are years old and they are root drivers!

So? Let's try this again.


These are all normal files.


Kernel extensions are completely normal. Any device that requires a driver in order for the OS to recognize and use it correctly has one. Yes, they are secure. They have to be validated by Unix to use them. If you manually copy a .kext file into the System Folder, even with Admin privileges, on every startup or restart the OS will tell you the file was improperly installed and will not be used.


The age of the files means nothing. Repeat - nothing. There's no reason for Apple to update a driver that doesn't need updating, so it naturally carries its last creation date.


But hey, keep digging for and deleting items you have no idea what they're for, and you'll have the grand opportunity to reinstall the OS when your Mac stops working.

Apr 9, 2015 12:08 PM in response to WilliamCooper

WilliamCooper wrote:


Nop, this is completely abnormal.


On what do you base this statement?


As an example, see the following list of apps obtained from "Unknown" from a mostly clean test system I have. (The only thing that has been done to it since the OS was installed was the addition of Chrome and Firefox.)


User uploaded file


This is the way it is for all recent versions of Mac OS X, the expected behavior, the very definition of normal. If you would like to debate whether or not this should be normal, feel free, but that is not the same as debating whether or not it currently is normal.


This absolutely, 100% is NOT the work of a virus.

10.9.5 Virus vs NotSigned Applications, Frameworks, Extensions

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.