Found a ton of Malware and Adware on my MacBook Pro- When I try to delete it, it just comes back into the folders I found it in, someone please help!

I have found a TON of malware and adware to the point of where the downloaded programs I had on my computer were basically masked, and used by his operating system or coding etc. I have found a lot of these to the point where I stopped looking. I reset my computer and wiped it, but whoever this is decided to get all their programs on my Mac OS system and it was basically full. There was about 30 GB left and I was unable to erase it because it was grayed out. I can't even update to the newest version of the Mac software because I either get an error or I have my screen turn grey and then goes back to the homepage of where I left off on all my applications that were opened. I believe this happened by him accessing my next work a few times through all the smart appliances I use (smart lightbulbs, google home, wireless printers, smart extension cords and google home etc. I do remember seeing a pop up after updating my VPN saying it would like me to add in a "HelperTool" which I stupidly did and this was not the first time I did this for a program as I thought back about it. I did an etrecheck report and it stated I had both adware and malware. After resetting and deleting everything is my Disk Utility where I wiped my Macintosh HD clean, reinstalled the latest version of software, and now I did erecheck again and this popped up: I have to many characters so ill post it in the answers tab- Notice: THIS has NO FULL DISK ENCRYPTION ON THIS ETRECHECK.



MacBook Pro 15”, macOS 10.13

Posted on Apr 12, 2020 8:06 PM

Reply
Question marked as Top-ranking reply

Posted on Apr 14, 2020 9:17 AM

Hi AlwayHacked247,


first of all thanks for posting.


My advice? I would collect all my valuable data and store it in iCloud so no valuable data is ever gone (unless you delete it yourself ;-) )


Then I would clean install your entire Mac so you don't have to worry about leftovers of possible ad- or malware.

To do so (after backing up all the important data like documents and licenses of software) follow the following instructions on https://support.apple.com/en-us/HT204904


In your case I would include step 2 (Learn more about when and how to erase) and erase the whole disk to be sure there is nothing left of the ad- and malware.


As my colleague-support people advised: try not to install 3rd party application who claim to "Clean Up your Mac". The coders at Apple do a fine job protecting your system as it is.


If you don't browse the darker side of the web, and you don't do anything illegal online like piracy and stuff, don't be afraid to just surf around and do your business. I tend to believe that when you don't do anything wrong, you're not watched by anyone who would do you any harm.


If you need any further assistance just reply and we'll try to help you further.


Stay healthy and save the summer!



Similar questions

17 replies
Question marked as Top-ranking reply

Apr 14, 2020 9:17 AM in response to AlwaysHacked247

Hi AlwayHacked247,


first of all thanks for posting.


My advice? I would collect all my valuable data and store it in iCloud so no valuable data is ever gone (unless you delete it yourself ;-) )


Then I would clean install your entire Mac so you don't have to worry about leftovers of possible ad- or malware.

To do so (after backing up all the important data like documents and licenses of software) follow the following instructions on https://support.apple.com/en-us/HT204904


In your case I would include step 2 (Learn more about when and how to erase) and erase the whole disk to be sure there is nothing left of the ad- and malware.


As my colleague-support people advised: try not to install 3rd party application who claim to "Clean Up your Mac". The coders at Apple do a fine job protecting your system as it is.


If you don't browse the darker side of the web, and you don't do anything illegal online like piracy and stuff, don't be afraid to just surf around and do your business. I tend to believe that when you don't do anything wrong, you're not watched by anyone who would do you any harm.


If you need any further assistance just reply and we'll try to help you further.


Stay healthy and save the summer!



Apr 13, 2020 6:11 AM in response to AlwaysHacked247

Hi Jeff


We've been down this road before. You received a ton of valuable advice:


I found something interesting in my Cache Dameons folder ...

I feel as if I am being watched ...

I am Constantly getting hacked ...


You need to act upon that advice.


You're going well off into the weeds pursuing junk like "CleanMyMac" and its ilk. The problems you're having are almost certainly the result of unauthorized use of your Mac, your network, your home, your office, your appliances, your smart extension cords, your Google, or all of the above. All of those surroundings including the equipment they contain needs to be be physically secure from unauthorized intrusion.

Apr 13, 2020 4:00 PM in response to AlwaysHacked247

Thank you for retrospection of how things had happened AlwaysHacked247.

This was very helpful for me to get better understanding on what was going on.

Thank you for showing appreciation of my personal time I had spent writing to you.


I find concerns for your privacy very reasonable. Let see what might be done to improve security of your Macintosh.


"What do you think I can do to repair it, because this is the second time its happened in 4 years and I am always safe using the internet with a VPN, CleanmyMacX, App cleaner, and now it just started happening":


It is possible that you core network device and DNS resolvers it uses had been hacked.

Look for WikiLeaks "Cherry Blossom" CIA project.

https://thehackernews.com/2017/06/cia-wireless-router-hacking-tool.html

If your security had been compromised by this way, you will not be able to find any clue on your Laptop, but particular addresses your OperationSystem/Software trust - will be routed to the "black" servers imitating all functions that your software used to trust to. That is why you suddenly discovered that software updates that supposedly come form Apple - do things you had not expected - CIA imitates Apple update servers - and delivers to you software that looks like Apple software but is something else.


To get over this:

  1. Immediately drop all network delivering devices you might have at home
  2. Immediately replace your current Internet provider network delivery device:
  • Took off your Internet provider device
  • Go to random office of your network provider / not office you had visited before
  • Request your device to be replaced with new one
  • ! auto update function for the firmware to be disabled !
  • ! WiFi to be disabled !
  • Once you return home initiate network recovery for your Laptop
  • Link the laptop via LAN cable to the Internet Provider device
  • Perform the network OS recovery
  • Do not login with Apple account
  • Do not agree to use iCloud, Be sure to disable any iCloud Application data off-loads, Documents offload, Picture offloads etc.
  • Disable Automatic MacOS updates/checks for updates,


From this point you will have clean system to start with.


Apr 12, 2020 8:10 PM in response to AlwaysHacked247

EtreCheck version: 5.5.4 (5106)

Report generated: 2020-04-12 21:53:27

Download EtreCheck from https://etrecheck.com

Runtime: 1:34

Performance: Excellent

Sandbox: Enabled

Full drive access: Disabled

Problem: Other problem

Description: 

Hacked

Major Issues:

    Anything that appears on this list needs immediate attention. 

 No Time Machine backup - Time Machine backup not found.

Minor Issues:

    These issues do not need immediate attention but they may indicate future problems or opportunities for improvement. 

32-bit Apps - This machine has 32-bits apps will not work on macOS 10.15 "Catalina".

Limited drive access - More information may be available with Full Drive Access.

Kernel extensions present - This machine has kernel extensions that may not work in the future.

Hardware Information:

    MacBook Pro (15-inch, 2018-2019)

 MacBook Pro Model: MacBookPro15,1

    2.2 GHz Intel Core i7 (i7-8750H) CPU: 6-core

    16 GB RAM - Not upgradeable

        BANK 0/ChannelA-DIMM0 - 8 GB DDR4 2400 

        BANK 2/ChannelB-DIMM0 - 8 GB DDR4 2400 

Battery: Health = Normal - Cycle count = 235

Video Information:

  Intel UHD Graphics 630 - VRAM: 1536 MB

  Color LCD (built-in) 3360 x 2100

  Radeon Pro 555X - VRAM: 4096 MB


Drives:

disk0 - APPLE SSD AP0256M 251.00 GB (Solid State - TRIM: Yes)

    Internal PCI-Express 8.0 GT/s x4 NVM Express

        disk0s1 - EFI [EFI] 315 MB

        disk0s2 [APFS Container] 250.69 GB

            disk1 [APFS Virtual drive] 250.69 GB (Shared by 4 volumes)

                disk1s1 - Macintosh HD (APFS) (Shared - 26.96 GB used)

                disk1s2 - Preboot (APFS) [APFS Preboot] (Shared)

                disk1s3 - Recovery (APFS) [Recovery] (Shared)

                disk1s4 - VM (APFS) [APFS VM] (Shared - 1.07 GB used)


Mounted Volumes:

    disk1s1 - Macintosh HD

        250.69 GB (Shared - 26.96 GB used, 222.10 GB available, 221.98 GB free)

        APFS

        Mount point: /

        Encrypted

 disk1s4 - VM [APFS VM]

        250.69 GB (Shared - 1.07 GB used, 221.98 GB free)

        APFS

        Mount point: /private/var/vm

        Encrypted


Network:

    Interface en0: Wi-Fi

        802.11 a/b/g/n/ac

    Interface en6: Bluetooth PAN

    Interface bridge0: Thunderbolt Bridge

System Software:

    macOS High Sierra 10.13.6 (17G12034) 

    Time since boot: Less than an hour

Notifications:

    Notifications not available without Full Drive Access.


Security:

    Gatekeeper: Enabled

    System Integrity Protection: Enabled


    Antivirus software: Apple

32-bit Applications:

    3 32-bit apps

Kernel Extensions:

    /Library/Application Support/Malwarebytes/MBAM/Kext

        MB_MBAM_Protection.kext (Malwarebytes Corporation, 4.3 - SDK 10.11)

System Launch Agents:

    [Not Loaded] 14 Apple tasks

    [Loaded] 170 Apple tasks

    [Running] 110 Apple tasks


System Launch Daemons:

    [Not Loaded] 39 Apple tasks

    [Loaded] 172 Apple tasks

    [Running] 124 Apple tasks


Launch Daemons:

    [Loaded] com.apple.installer.osmessagetracing.plist (Apple - installed 2020-03-18)

Apr 12, 2020 8:11 PM in response to AlwaysHacked247

User Internet Plug-ins:

    User Internet Plug-ins need Full Drive Access


Audio Plug-ins:

    AppleTimeSyncAudioClock: 1.0 (Apple - installed 2020-04-12)

    BluetoothAudioPlugIn: 6.0.7 (Apple - installed 2020-04-12)

    AirPlay: 2.0 (Apple - installed 2020-04-12)

    AppleAVBAudio: 683.1 (Apple - installed 2020-04-12)

    BridgeAudioSP: 4.69.2 (Apple - installed 2020-04-12)

    iSightAudio: 7.7.3 (Apple - installed 2020-04-12)

User Audio Plug-ins:

    User Audio Plug-ins need Full Drive Access

User iTunes Plug-ins:

    User iTunes Plug-ins need Full Drive Access

Time Machine:

    Time Machine Not Configured!


Performance:

    System Load: 2.26 (1 min ago) 2.69 (5 min ago) 1.33 (15 min ago)

    Nominal I/O speed: 13.92 MB/s

    File system: 20.21 seconds

    Write speed: 1327 MB/s

    Read speed: 2855 MB/s


CPU Usage Snapshot:

    Type Overall

    System: 4 %

    User: 7 %

    Idle: 90 %

Top Processes Snapshot by CPU:

    Process (count) CPU (Source - Location)

    Other processes 78.76 % (?)

    Console 34.55 % (Apple)

    EtreCheck 5.91 % (App Store)

    trustd 5.18 % (Apple)

    CoreServicesUIAgent 0.19 % (Apple)

Top Processes Snapshot by Memory:

    Process (count) RAM usage (Source - Location)

    EtreCheck 488 MB (App Store)

    Console 197 MB (Apple)

    osinstallersetupd 192 MB (Apple)

    App Store 109 MB (Apple)

    InstallAssistant_springboard 98 MB (App Store)

Top Processes Snapshot by Network Use:


    Process Input / Output (Source - Location)


    Other processes 18 MB / 3 MB (?)


    IMRemoteURLConnectionAgent 18 KB / 703 B (Apple)


    SystemUIServer 0 B / 64 B (Apple)


    spindump_agent 0 B / 0 B (Apple)


    backgroundtaskmanagementagent 0 B / 0 B (Apple)


Virtual Memory Information:


    Physical RAM: 16 GB


    Free RAM: 7.35 GB


    Used RAM: 5.41 GB


    Cached files: 3.24 GB




    Available RAM: 10.59 GB


    Swap Used: 0 B


Software Installs (past 30 days):


    Install Date Name (Version)


    2020-04-12 SU_TITLE (10.13.6.1.1.1532145923)


    2020-04-12 Malwarebytes for Mac


    2020-04-12 iTunes Device Support Update ( )


    2020-04-12 Safari (13.1)


    2020-04-12 iTunes (12.8.2)


    2020-04-12 CompatibilityNotificationData (1.0.5)


    2020-04-12 macOS Installer Notification (2.0)


    2020-04-12 Gatekeeper Configuration Data (181)


    2020-04-12 XProtectPlistConfigData (2118)


    2020-04-12 MRTConfigData (1.58)


    2020-04-12 Security Update 2020-002 (10.13.6)


    2020-04-12 macOS Catalina (15.4.01)


    2020-04-12 EtreCheck (5.5.4)




Diagnostics Information (past 7-30 days):


    Directory /Library/Logs/DiagnosticReports is not accessible.


    Enable Full Drive Access to see more information.


End of report

AND also this picture popped up and yet I did NOTHING after resetting my Mac to default except use etrecheck. Here is the folder from my Privacy settings.

Apr 12, 2020 8:12 PM in response to AlwaysHacked247

AND also this picture popped up and yet I did NOTHING after resetting my Mac to default except use etrecheck. Here is the folder from my Privacy settings.




It's missing full disk encryption and many other options. I can put some items of the coding on here as well but I have no idea what to do, can someone please offer some advice on what to do in order to fix this? I can't find anyone around my area who fixes Mac's, so it would be much appreciated!! 




Thanks everyone.


Apr 13, 2020 2:30 AM in response to Lambry

I will lay It out for you in simple terms from about 2 weeks ago to now in a timeline. I downloaded and bought a 3 year subscription for my VPN service NordVPN. I had an update 2 weeks ago and I updated it, but afterwards I received a pop stating they need to install a Nord.VPNHelperTool and of course I did it. I believe this also happened on another program that I bought which was CleanMyMacX. Then about 7-10 days later I noticed my Mac was taking forever to turn on, was freezing every once in awhile. So I started looking into things and I saw a lot of coding which was stating things like voice recordings plists and then I also found another Machintosh Drive in another folder where all the coding was written, which included photos of all my applications which I finally found out he made a switch and was basically keeping all the information on those applications in a folder, usually things I use most.


So after that I ran etrecheck from App Store (this was the 1st time) and it said I was at high risk and said I have adware and malware on my machine. It also said my data was corrupted and that I needed to take action immediately and gave me some tips, it also said a lot about my Drives because I don't do any partitioning at all and there was a lot going on, especially since the Mac OS System Storage- where all Apple coding is, was full to almost the max, which was not normal. So I wiped my Machintosh HD, but it would let me doing anything to remove, first aid or anything to the OS system. Now I just discovered this virus made another Machintosh HD when I was trying to download new updates. Every time I try to update my computer, theres an error and it won't let me.


The second time, the one your asking about, was after I deleted all my personal files to try and start from scratch, but that didn't work since it was in the Mac OS system storage (idk the exact name I just remember the Mac OS Storage. And when I said hacked I mean't to say constant malware and adware being added daily to the point where it will key log me sooner than later. They hd folders of coding that said put messaging and store them in this location or voice recordings and store them in this location etc. I was trying to get etrecheck in full disk access but thats not even ON MY PRIVACY SETTINGS ANYMORE!


Yes everything is encrypted, but I had to make sure when I rebooted my Mac to put those settings into place again. I was told on some things I read I could shut down my Mac, using power buttoned shift, control option, release the keys and then press the power button OR use the Internet Recovery Partition and start over since I have an external Hardrive but I have NO IDEA how to do that.


The someone suggested to partition the drive using the internet recovery and install the new Mac OS software on the new partition by doing it on the computer and use finder, Machintosh HD, copy any files I wanna keep, under devices locate my Machintosh HD (new) and install the latest version of software on it..


I also don't get that I bought CleanMyMAc for Malware and basically an all in one machine and it never once found anything wrong with my computer.


What do you think I can do to repair it, because this is the second time its happened in 4 years and I am always safe using the internet with a VPN, CleanmyMacX, App cleaner, and now it just started happening. Idk what to do because I just bought a brand new iMac 2 months ago and thats also infected but I barley used it since we are moving and packing.


Lastly that you for your help and reply, I wish there were a lot more of you out there then people who say "your crazy you can get a virus unless they have your computer in their hands" so thank thank thank !!!

Apr 14, 2020 5:25 AM in response to Lambry

When you say request your device to be replaced with a new one do you mean I have to get a new iPhone and new iPads, iMac and MacBook Pro or are you saying I just need to get a new router, then for the sake of explaining, reset my phone tablets and other devices?


what about having all of my smart lights? I have google Chromecast, 3 active smart lightbulbs, 2 active smart extension cords a Wemo smart plug for tv voice control, PS4 TVs etc all connected to the internet.


Lastly I am moving to another state in 2 weeks. What would your recommendations be for this since I’m leaving the state. I have a place to go, my girlfriends but I’ve been there before so basically I just can’t use any of my personal stuff to connect to her internet.


why would the CIA so this or is that just a name of a group that’s hacking people? Thanks for your advice, but this seems super complex so I may have a few more questions afterwards but thank you for everything!

Apr 14, 2020 6:38 AM in response to etresoft

Etresoft thank you for your reply.


so when I tried to update my Mac to the new Catalina update i got an error and then my screen turned gray then went back to the pages I was currently on. At first I wiped my computer, but when I went back to reinstall the software i went into disk utility first and the Mac OS Base System was almost 3/4s full, is that normal?


To answer your question, yes I have an External hard drive as my time machine. I also did have almost a full hard drive because I have a lot of Videos for learning magic as I am a magician. I would say just in videos on the Mac I had probably 200-300 videos all in the range of being an hour or longer, some only 30 minutes but also had documents and PDFs as long as 300 pages(25 atleast of those). As of now my computer has a question mark in a box so I cant use it at all right now until I bring it into a Mac store I believe unless you know how to install it without going into a Apple store. Do you think I need to reset my phone and iPads as well or do you think this is just something on my computer and not a wide problem throughout the network everyone uses? Thanks again for your help!

Apr 14, 2020 8:19 AM in response to Barney-15E

what I mean by wiping it is selecting the Machintosh HD drive and erased it and then I tried deleting other disks that were under it like disks1 or something similar to that name- there were about 7 of those and when I tried to erase it the erase button was greyed out. I’m not sure how to delete the drive unless it was trying to delete everything on the disk utility- I tried to even erase some of the OS base system but that was also greyed out. I will try and reset it with what you gave me above. I really appreciate everyone’s opinions on this because it’s been really stressful so thank you !

Apr 13, 2020 12:09 AM in response to AlwaysHacked247

Dear AlwaysHacked247,


I am so sorry about the security issue You had experienced with you Macintosh.


First of all congratulation for the fine choice of MacBook Pro model - it seems modern and powerful enough.

Second, good job on rescuing it by your own and recovering / resetting MacOS.


Let me try to understand - recently you had installed a "free" less known application called "EtreCheck", that had told you that your MacBook Pro laptop is "hacked"?


Based on statement from "EtreCheck" you had panicked and had performed system recovery returning the original 2018 image "HighSierra" MacOS version?


About "full disk encryption" - on all Macintosh systems this is provided by "FileVault" which I can see is visible on your "Security&Privacy" windows under the Tab "FileVault". Also "EtreCheck" report shows you that particular drives are "Encrypted", correct ?


Apr 14, 2020 6:21 AM in response to AlwaysHacked247

Don’t worry. I can guarantee that the CIA isn’t hacking you.


Here is what seems like actually happened...


You updated NordVPN and then CleanMyMac. No problem there. While NordVPN can use built-in VPN protocols, it also has more powerful versions with extra features. These more powerful VPN protocols may need extra software or “helpers’. This is all perfectly normal.


Even though CleanMyMac advertises itself as an antivirus app, there is no guarantee that it will do a good job at that. This is true about all antivirus apps. In many cases, they cause more problems than they solve.


At some point you ran EtreCheck and it found some adware and/or malware. Unfortunately, this is also normal. Since the COVID, there seems to have been a massive spike in adware and malware due to people trying to work from home. While EtreCheck will help you remove adware and malware, the idea is for you to post the report here in Apple Support Communities so people can help you resolve these problems.


At some point, you also seem to have installed the latest version of macOS, “Catalina”. This adds some extra layers of complexity, including splitting your hard drive into 2 parts. This frequently confuses people, but is entirely normal.


Also, it seems like your hard drive was full. To repeat the phrase yet again - all perfectly normal.


You may have restored your computer to a previous operating system that does not have some of the newer settings for privacy in System Preferences. Check which version you have in About this Mac, or, even better, post your EtreCheck report. You may need to upgrade your system back to Catalina.


You mentioned an external drive. Were you using Time Machine? If so, then all you need to do is restore your files. You can use “Migration Assistant” to do that. Since you had lots of adware and malware installed, you will need to be careful about restoring. You can’t restore the entire system as that would restore the malware too. Just restore “User Accounts” only. Then reinstall any apps that you need. It is possible that this will restore some adware and malware, but you can use EtreCheck to remove those. And this time, please post your report here in the forums so we can help.



Apr 14, 2020 7:07 AM in response to AlwaysHacked247

Mac OS Base System is the Recovery "OS", so yes, it is normal.


The question mark means it cannot find the startup drive. Try an NVRAM reset or boot into Recovery and set the Startup Disk (Apple menu). If your Mac stops or delays while starting up - Apple Support


At first I wiped my computer

How, exactly, did you go about doing that?

Did you just erase Macintosh HD volume or did you erase the drive itself?

Apr 14, 2020 7:41 AM in response to AlwaysHacked247

As Barney says, that's normal.


It sounds like all you need to do is restore the operating system. Here are instructions from Apple: How to reinstall macOS from macOS Recovery - Apple Support


After that, you can carefully restore using Migration Assistant, as described here: Restore your Mac from a backup - Apple Support


The only tricky part is when you get to "Select the Information to Transfer". You want to limit that to just your user account to avoid reinstalling your adware and malware. As I mentioned before, sometimes that stuff gets installed inside your user account, so you might have it after reinstallation. You can just run EtreCheck again and use EtreCheck's free "Security" page to remove it.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Found a ton of Malware and Adware on my MacBook Pro- When I try to delete it, it just comes back into the folders I found it in, someone please help!

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.