{"id":42128,"date":"2024-02-15T16:09:25","date_gmt":"2024-02-15T21:09:25","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=42128"},"modified":"2024-02-15T16:09:25","modified_gmt":"2024-02-15T21:09:25","slug":"mac-app-launches-slowed-by-malware-scan","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2024\/02\/15\/mac-app-launches-slowed-by-malware-scan\/","title":{"rendered":"Mac App Launches Slowed by Malware Scan"},"content":{"rendered":"<p><a href=\"https:\/\/lapcatsoftware.com\/articles\/2024\/2\/3.html\">Jeff Johnson<\/a>:<\/p>\n<blockquote cite=\"https:\/\/lapcatsoftware.com\/articles\/2024\/2\/3.html\"><p>macOS is periodically scanning FileMerge for malware on launch, which causes very slow app launches. I don&rsquo;t know what the exact period is between scans, but rebooting the Mac seems to reset the cache[&#8230;]. I&rsquo;ve noticed the same <code>syspolicyd<\/code> malware scanning and consequent slow launches with some other apps such as Xcode itself, Google Chrome, and Wireshark. You can even see <code>syspolicyd<\/code> spinning up % CPU in Activity Monitor when the malware scan happens.<\/p><p>[&#8230;]<\/p><p>I also saw somewhat slow launching from another app bundled with Xcode, Accessibility Inspector. This app is larger than FileMerge, yet it launches much more quickly. I suspect the reason is that it links to fewer Xcode frameworks[&#8230;]<\/p><p>[&#8230;]<\/p><p>You may remember our friend <code>syspolicyd<\/code> as the process that <a href=\"https:\/\/lapcatsoftware.com\/articles\/catalina-executables.html\">phones home to Apple when running unsigned executables<\/a>. It was also the culprit in making <a href=\"https:\/\/lapcatsoftware.com\/articles\/xcrun.html\">Xcode tools slow after reboot<\/a>.<\/p><p>[&#8230;]<\/p><p>I&rsquo;ve now confirmed that disabling SIP does indeed eliminate the <code>syspolicyd<\/code> malware scan. Xcode launches so fast, it&rsquo;s beautiful.<\/p><\/blockquote>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2022\/08\/15\/xprotect-remediator\/\">XProtect Remediator<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2023\/07\/06\/how-ventura-checks-the-security-of-apps-and-tools\/\">How Ventura Checks the Security of Apps and Tools<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2020\/11\/13\/apple-server-outage-makes-mac-apps-hang-on-launch\/\">Apple Server Outage Makes Mac Apps Hang on Launch<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2020\/05\/22\/macos-10-15-slow-by-design\/\">macOS 10.15: Slow by Design<\/a><\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Jeff Johnson: macOS is periodically scanning FileMerge for malware on launch, which causes very slow app launches. I don&rsquo;t know what the exact period is between scans, but rebooting the Mac seems to reset the cache[&#8230;]. I&rsquo;ve noticed the same syspolicyd malware scanning and consequent slow launches with some other apps such as Xcode itself, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2024-02-15T21:09:28Z","apple_news_api_id":"e4eaeb32-9929-4d16-a498-e482f0473aed","apple_news_api_modified_at":"2024-02-15T21:09:28Z","apple_news_api_revision":"AAAAAAAAAAD\/\/\/\/\/\/\/\/\/\/w==","apple_news_api_share_url":"https:\/\/apple.news\/A5OrrMpkpTRakmOSC8Ec67Q","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[2556,30,2385,504,1235,226],"class_list":["post-42128","post","type-post","status-publish","format-standard","hentry","category-technology","tag-filemerge","tag-mac","tag-macos-14-sonoma","tag-malware","tag-system-integrity-protection","tag-xcode"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/42128","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=42128"}],"version-history":[{"count":1,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/42128\/revisions"}],"predecessor-version":[{"id":42129,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/42128\/revisions\/42129"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=42128"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=42128"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=42128"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}