• A serious question for malware experts

    From David B.@David@hotmail.co.uk to alt.computer.workshop,uk.comp.sys.mac on Sun Jun 28 12:52:14 2026
    From Newsgroup: uk.comp.sys.mac

    On 28/06/2026 11:05, Brock McNuggets wrote:
    On Jun 28, 2026 at 2:43:26rC>AM MST, "David B." wrote <6a40ecbe$0$27$882e4bbb@reader.netnews.com>:

    On 28 Jun 2026 at 06:05:17 BST, "Brock McNuggets" <brock.mcnuggets@gmail.com>
    wrote:

    Not relevant. You are still spreading misinformation such as it somehow is not
    able to be scanned for malware because it does not show up in System
    Information >Installations as if malware has to register itself to be scanned.
    Do you realize how wrong that is?

    +

    The answer is you made a bunch of assumptions that are not just wrong but show
    a lack of understanding of basics.

    Brock,

    YourCOve completely misunderstood my point. I am well aware of how malware >> scanners and real-time security tools operate.

    My reference to 'System Information >Installations' wasn't about how a malware
    scanner physically detects a threat. I know perfectly well that scanners look
    at live memory, process behaviors, and persistence paths like LaunchAgents - >> they don't rely on an official installation receipt log.

    I am in reference to your comments:

    Most software downloaded onto a Mac is "installed", usually
    in Applications, and shows up in System Information >
    Installations.

    Once there, software can be scanned with an AV software
    package to check for malware.

    However, a popular tool often recommended by advisors on the
    Apple Support Communities forums (EtreCheck) cannot be
    checked in this manner.

    EtreCheck claims NOT to be "installed" - indeed, it does NOT
    show up in Applications or Installations - so just HOW can
    it be scanned by anti-malware software BEFORE being given
    free reign on an Apple computer?

    You were quite clear in questioning how it could be scanned without being listed there.

    My point to MacMost was about the provenance and visibility of software. I am
    used to seeing something "concrete" on my machine - a distinct application >> package that I can physically select, point a scanner at, and manually audit >> before it runs.

    The app icon.

    When a utility like EtreCheck bypasses the traditional installer process

    Most apps do. Again, you do not understand what is normal so you assume this is not.

    and
    doesn't leave an entry in the system's installation log,

    Nor should it.

    it lacks that
    familiar, visible audit trail. My question was simply focusing on how macOS >> handles the validation of those unlogged files before execution - which, as we
    know, happens via Gatekeeper, XProtect, and cryptographic notarization rather
    than a history log.

    Has nothing to do with that list.

    I understand the basics perfectly. You just misread the context of what I was
    driving at.

    No, you are showing no real understanding.

    =

    Gemini states:-

    Cryptographic Verification: macOS checks if the app is digitally signed with a
    valid Developer ID and, crucially, if it has been Notarized by Apple.

    The Apple Notary Service: To get notarized, the developer must submit the app
    to Apple's automated cloud servers before distribution. Apple runs behavioral
    analytics on it. If itrCOs a brand-new, unknown malware strain that evades >> automated detection, it might slip through and get notarized.

    The Verdict: If the unknown malware is not signed/notarized, macOS will
    flat-out block it from running, displaying an alert that it "cannot be opened
    because the developer cannot be verified." The user would have to explicitly >> override this in System Settings to run it.

    =

    John Daniel has now been under Apple's magnifying glass again for his
    relatively new product, Storeograph, so one just has to hope that Apple itself
    has satisfied itself that there really is no cause for concern.

    https://storeograph.ca/en/index.html

    Brock,

    You are still arguing about the phrasing of a casual YouTube comment
    rather than the actual technical point I just laid out.

    The mechanics of Gatekeeper, XProtect, and notarisation stand on their
    own, as does my preference for a visible audit trail. We can leave it at
    that.

    --
    David B.
    x-posted to uk.comp.sys.mac
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Brock McNuggets@brock.mcnuggets@gmail.com to alt.computer.workshop,uk.comp.sys.mac on Sun Jun 28 16:12:09 2026
    From Newsgroup: uk.comp.sys.mac

    On Jun 28, 2026 at 4:52:14rC>AM MST, ""David B."" wrote <nacg7eFdkidU1@mid.individual.net>:

    On 28/06/2026 11:05, Brock McNuggets wrote:
    On Jun 28, 2026 at 2:43:26rC>AM MST, "David B." wrote
    <6a40ecbe$0$27$882e4bbb@reader.netnews.com>:

    On 28 Jun 2026 at 06:05:17 BST, "Brock McNuggets" <brock.mcnuggets@gmail.com>
    wrote:

    Not relevant. You are still spreading misinformation such as it somehow is not
    able to be scanned for malware because it does not show up in System
    Information >Installations as if malware has to register itself to be scanned.
    Do you realize how wrong that is?

    +

    The answer is you made a bunch of assumptions that are not just wrong but show
    a lack of understanding of basics.

    Brock,

    YourCOve completely misunderstood my point. I am well aware of how malware >>> scanners and real-time security tools operate.

    My reference to 'System Information >Installations' wasn't about how a malware
    scanner physically detects a threat. I know perfectly well that scanners look
    at live memory, process behaviors, and persistence paths like LaunchAgents -
    they don't rely on an official installation receipt log.

    I am in reference to your comments:

    Most software downloaded onto a Mac is "installed", usually
    in Applications, and shows up in System Information >
    Installations.

    Once there, software can be scanned with an AV software
    package to check for malware.

    However, a popular tool often recommended by advisors on the
    Apple Support Communities forums (EtreCheck) cannot be
    checked in this manner.

    EtreCheck claims NOT to be "installed" - indeed, it does NOT
    show up in Applications or Installations - so just HOW can
    it be scanned by anti-malware software BEFORE being given
    free reign on an Apple computer?

    You were quite clear in questioning how it could be scanned without being
    listed there.

    My point to MacMost was about the provenance and visibility of software. I am
    used to seeing something "concrete" on my machine - a distinct application >>> package that I can physically select, point a scanner at, and manually audit
    before it runs.

    The app icon.

    When a utility like EtreCheck bypasses the traditional installer process

    Most apps do. Again, you do not understand what is normal so you assume this >> is not.

    and
    doesn't leave an entry in the system's installation log,

    Nor should it.

    it lacks that
    familiar, visible audit trail. My question was simply focusing on how macOS >>> handles the validation of those unlogged files before execution - which, as we
    know, happens via Gatekeeper, XProtect, and cryptographic notarization rather
    than a history log.

    Has nothing to do with that list.

    I understand the basics perfectly. You just misread the context of what I was
    driving at.

    No, you are showing no real understanding.

    =

    Gemini states:-

    Cryptographic Verification: macOS checks if the app is digitally signed with a
    valid Developer ID and, crucially, if it has been Notarized by Apple.

    The Apple Notary Service: To get notarized, the developer must submit the app
    to Apple's automated cloud servers before distribution. Apple runs behavioral
    analytics on it. If itrCOs a brand-new, unknown malware strain that evades >>> automated detection, it might slip through and get notarized.

    The Verdict: If the unknown malware is not signed/notarized, macOS will
    flat-out block it from running, displaying an alert that it "cannot be opened
    because the developer cannot be verified." The user would have to explicitly
    override this in System Settings to run it.

    =

    John Daniel has now been under Apple's magnifying glass again for his
    relatively new product, Storeograph, so one just has to hope that Apple itself
    has satisfied itself that there really is no cause for concern.

    https://storeograph.ca/en/index.html

    Brock,

    You are still arguing about the phrasing of a casual YouTube comment
    rather than the actual technical point I just laid out.

    No. Not the phrasing. The meaning.

    Most software downloaded onto a Mac is "installed", usually
    in Applications, and shows up in System Information >
    Installations.

    Once there, software can be scanned with an AV software
    package to check for malware.

    However, a popular tool often recommended by advisors on the
    Apple Support Communities forums (EtreCheck) cannot be
    checked in this manner.

    EtreCheck claims NOT to be "installed" - indeed, it does NOT
    show up in Applications or Installations - so just HOW can
    it be scanned by anti-malware software BEFORE being given
    free reign on an Apple computer?

    This is not at all accurate. It says a lot of very clearly deeply wrong
    things.

    The mechanics of Gatekeeper, XProtect, and notarisation stand on their
    own, as does my preference for a visible audit trail. We can leave it at that.

    --
    David B.
    x-posted to uk.comp.sys.mac
    --
    It's impossible for someone who is at war with themselves to be at peace with you.
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From David B.@David@hotmail.co.uk to alt.computer.workshop,uk.comp.sys.mac on Sun Jun 28 17:26:58 2026
    From Newsgroup: uk.comp.sys.mac

    On 28/06/2026 17:12, Brock McNuggets wrote:
    On Jun 28, 2026 at 4:52:14rC>AM MST, ""David B."" wrote <nacg7eFdkidU1@mid.individual.net>:

    On 28/06/2026 11:05, Brock McNuggets wrote:
    On Jun 28, 2026 at 2:43:26rC>AM MST, "David B." wrote
    <6a40ecbe$0$27$882e4bbb@reader.netnews.com>:

    On 28 Jun 2026 at 06:05:17 BST, "Brock McNuggets" <brock.mcnuggets@gmail.com>
    wrote:

    Not relevant. You are still spreading misinformation such as it somehow is not
    able to be scanned for malware because it does not show up in System >>>>> Information >Installations as if malware has to register itself to be scanned.
    Do you realize how wrong that is?

    +

    The answer is you made a bunch of assumptions that are not just wrong but show
    a lack of understanding of basics.

    Brock,

    YourCOve completely misunderstood my point. I am well aware of how malware >>>> scanners and real-time security tools operate.

    My reference to 'System Information >Installations' wasn't about how a malware
    scanner physically detects a threat. I know perfectly well that scanners look
    at live memory, process behaviors, and persistence paths like LaunchAgents -
    they don't rely on an official installation receipt log.

    I am in reference to your comments:

    Most software downloaded onto a Mac is "installed", usually
    in Applications, and shows up in System Information >
    Installations.

    Once there, software can be scanned with an AV software
    package to check for malware.

    However, a popular tool often recommended by advisors on the
    Apple Support Communities forums (EtreCheck) cannot be
    checked in this manner.

    EtreCheck claims NOT to be "installed" - indeed, it does NOT
    show up in Applications or Installations - so just HOW can
    it be scanned by anti-malware software BEFORE being given
    free reign on an Apple computer?

    You were quite clear in questioning how it could be scanned without being >>> listed there.

    My point to MacMost was about the provenance and visibility of software. I am
    used to seeing something "concrete" on my machine - a distinct application >>>> package that I can physically select, point a scanner at, and manually audit
    before it runs.

    The app icon.

    When a utility like EtreCheck bypasses the traditional installer process >>>
    Most apps do. Again, you do not understand what is normal so you assume this
    is not.

    and
    doesn't leave an entry in the system's installation log,

    Nor should it.

    it lacks that
    familiar, visible audit trail. My question was simply focusing on how macOS
    handles the validation of those unlogged files before execution - which, as we
    know, happens via Gatekeeper, XProtect, and cryptographic notarization rather
    than a history log.

    Has nothing to do with that list.

    I understand the basics perfectly. You just misread the context of what I was
    driving at.

    No, you are showing no real understanding.

    =

    Gemini states:-

    Cryptographic Verification: macOS checks if the app is digitally signed with a
    valid Developer ID and, crucially, if it has been Notarized by Apple.

    The Apple Notary Service: To get notarized, the developer must submit the app
    to Apple's automated cloud servers before distribution. Apple runs behavioral
    analytics on it. If itrCOs a brand-new, unknown malware strain that evades >>>> automated detection, it might slip through and get notarized.

    The Verdict: If the unknown malware is not signed/notarized, macOS will >>>> flat-out block it from running, displaying an alert that it "cannot be opened
    because the developer cannot be verified." The user would have to explicitly
    override this in System Settings to run it.

    =

    John Daniel has now been under Apple's magnifying glass again for his
    relatively new product, Storeograph, so one just has to hope that Apple itself
    has satisfied itself that there really is no cause for concern.

    https://storeograph.ca/en/index.html

    Brock,

    You are still arguing about the phrasing of a casual YouTube comment
    rather than the actual technical point I just laid out.

    No. Not the phrasing. The meaning.

    Most software downloaded onto a Mac is "installed", usually
    in Applications, and shows up in System Information >
    Installations.

    Once there, software can be scanned with an AV software
    package to check for malware.

    However, a popular tool often recommended by advisors on the
    Apple Support Communities forums (EtreCheck) cannot be
    checked in this manner.

    EtreCheck claims NOT to be "installed" - indeed, it does NOT
    show up in Applications or Installations - so just HOW can
    it be scanned by anti-malware software BEFORE being given
    free reign on an Apple computer?

    This is not at all accurate. It says a lot of very clearly deeply wrong things.

    <*SIGH*>

    The mechanics of Gatekeeper, XProtect, and notarisation stand on their
    own, as does my preference for a visible audit trail. We can leave it at
    that.
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Brock McNuggets@Brock.McNuggets@gmail.com to alt.computer.workshop,uk.comp.sys.mac on Sun Jun 28 17:23:26 2026
    From Newsgroup: uk.comp.sys.mac

    David B. <David@hotmail.co.uk> wrote:
    On 28/06/2026 17:12, Brock McNuggets wrote:
    On Jun 28, 2026 at 4:52:14rC>AM MST, ""David B."" wrote
    <nacg7eFdkidU1@mid.individual.net>:

    On 28/06/2026 11:05, Brock McNuggets wrote:
    On Jun 28, 2026 at 2:43:26rC>AM MST, "David B." wrote
    <6a40ecbe$0$27$882e4bbb@reader.netnews.com>:

    On 28 Jun 2026 at 06:05:17 BST, "Brock McNuggets" <brock.mcnuggets@gmail.com>
    wrote:

    Not relevant. You are still spreading misinformation such as it somehow is not
    able to be scanned for malware because it does not show up in System >>>>>> Information >Installations as if malware has to register itself to be scanned.
    Do you realize how wrong that is?

    +

    The answer is you made a bunch of assumptions that are not just wrong but show
    a lack of understanding of basics.

    Brock,

    YourCOve completely misunderstood my point. I am well aware of how malware
    scanners and real-time security tools operate.

    My reference to 'System Information >Installations' wasn't about how a malware
    scanner physically detects a threat. I know perfectly well that scanners look
    at live memory, process behaviors, and persistence paths like LaunchAgents -
    they don't rely on an official installation receipt log.

    I am in reference to your comments:

    Most software downloaded onto a Mac is "installed", usually
    in Applications, and shows up in System Information >
    Installations.

    Once there, software can be scanned with an AV software
    package to check for malware.

    However, a popular tool often recommended by advisors on the
    Apple Support Communities forums (EtreCheck) cannot be
    checked in this manner.

    EtreCheck claims NOT to be "installed" - indeed, it does NOT
    show up in Applications or Installations - so just HOW can
    it be scanned by anti-malware software BEFORE being given
    free reign on an Apple computer?

    You were quite clear in questioning how it could be scanned without being >>>> listed there.

    My point to MacMost was about the provenance and visibility of software. I am
    used to seeing something "concrete" on my machine - a distinct application
    package that I can physically select, point a scanner at, and manually audit
    before it runs.

    The app icon.

    When a utility like EtreCheck bypasses the traditional installer process >>>>
    Most apps do. Again, you do not understand what is normal so you assume this
    is not.

    and
    doesn't leave an entry in the system's installation log,

    Nor should it.

    it lacks that
    familiar, visible audit trail. My question was simply focusing on how macOS
    handles the validation of those unlogged files before execution - which, as we
    know, happens via Gatekeeper, XProtect, and cryptographic notarization rather
    than a history log.

    Has nothing to do with that list.

    I understand the basics perfectly. You just misread the context of what I was
    driving at.

    No, you are showing no real understanding.

    =

    Gemini states:-

    Cryptographic Verification: macOS checks if the app is digitally signed with a
    valid Developer ID and, crucially, if it has been Notarized by Apple. >>>>>
    The Apple Notary Service: To get notarized, the developer must submit the app
    to Apple's automated cloud servers before distribution. Apple runs behavioral
    analytics on it. If itrCOs a brand-new, unknown malware strain that evades
    automated detection, it might slip through and get notarized.

    The Verdict: If the unknown malware is not signed/notarized, macOS will >>>>> flat-out block it from running, displaying an alert that it "cannot be opened
    because the developer cannot be verified." The user would have to explicitly
    override this in System Settings to run it.

    =

    John Daniel has now been under Apple's magnifying glass again for his >>>>> relatively new product, Storeograph, so one just has to hope that Apple itself
    has satisfied itself that there really is no cause for concern.

    https://storeograph.ca/en/index.html

    Brock,

    You are still arguing about the phrasing of a casual YouTube comment
    rather than the actual technical point I just laid out.

    No. Not the phrasing. The meaning.

    Most software downloaded onto a Mac is "installed", usually
    in Applications, and shows up in System Information >
    Installations.

    Once there, software can be scanned with an AV software
    package to check for malware.

    However, a popular tool often recommended by advisors on the
    Apple Support Communities forums (EtreCheck) cannot be
    checked in this manner.

    EtreCheck claims NOT to be "installed" - indeed, it does NOT
    show up in Applications or Installations - so just HOW can
    it be scanned by anti-malware software BEFORE being given
    free reign on an Apple computer?

    This is not at all accurate. It says a lot of very clearly deeply wrong
    things.

    <*SIGH*>

    You asked if someone could answer your question. The answer is the question
    is filled with deeply flawed assumptions and thus no answer really works. Furthermore you are clearly starting with an agenda where you assume a
    specific product is doing something wrong but have no evidence. This is the exact wrong way to do a reasoned investigation or to find truth.

    The mechanics of Gatekeeper, XProtect, and notarisation stand on their
    own, as does my preference for a visible audit trail. We can leave it at >>> that.

    --
    Personal attacks from those who troll show their own insecurity. They
    cannot use reason to show the message to be wrong so they try to feel
    somehow superior by attacking the messenger.

    They cling to their attacks and ignore the message time and time again.
    --- Synchronet 3.22a-Linux NewsLink 1.2