Help Detecting Potential Malware

Hi,


I recently had what I believe to be a copy/paste issue in which text copied using a 'copy to clipboard' button (and confirmed to be copied!) resulted in pasted text that was not the same. Unfortunately, I made the mistake of not confirming the value, which led to a loss of funds.


Suspecting malware, I ran several tests using a variety of antivirus software, including Avast, ClamXAV, and CleanMyPC. These revealed no major infections.


Having done some research, I have also run EtreCheck, and it is here that I am requesting help. The log is attached.


Any advice for checking the (many) processes in the Activity Monitor would also be greatly appreciated.


Thank you!!





Posted on Sep 22, 2021 1:10 PM

Reply

Similar questions

10 replies

Sep 22, 2021 3:53 PM in response to coopere905

First, there is no reason to ever install or run any 3rd party "cleaning", "optimizing", "speed-up", anti-virus, VPN or security apps on your Mac.  This user tip describes what you need to know and do in order to protect your Mac: Effective defenses against malware and other threats - Apple Community.  


There are no known viruses, i.e. self propagating, for Macs.  There are, however, adware and malware which require the user to install although unwittingly most of the time thru sneaky links, etc.   


Anti Virus developers try to group all types as viruses into their ad campaigns of fear.  They do a poor job of the detecting and isolating the adware and malware.  Since there are no viruses these apps use up a lot of system resources searching for what is non-existent and adversely affect system and app performance.


There is one app, Malwarebytes, which was developed by a long time contributor to these forums and a highly respected member of the computer security community, that is desshoigned solely to seek out adware and known malware and remove it.  The free version is more than adequate for most users.  


Also, unless you're using a true VPN tunnel, such as between you and your employer's or bank's servers, they are useless from a privacy standpoint.  Read these two articles: Public VPN's are anything but private and Former Malware Distributor Kape Technologies Now Owns ExpressVPN, CyberGhost, Private Internet Access, Zenmate, and a Collection of VPN “Review” Websites. 


That being said uninstall Avast, ClamX and CleanMyMac according to the developer's instructions.


You can check to see if you've removed all of the supporting files by downloading and running the shareware app Find Any File to search for any files with the application's or the developer's name in the file name.  For the the mentioned software you'd do the following search(es): 


1 - Name contains cleanmymac

2 - Name contains macpaw

3 - Name contains avast

4 - Name contains clamx


Any files that are found can be dragged from the search results window to the Desktop or Trash bin in the Dock for deletion.


FAF can search areas that Spotlight can't like invisible folders, system folders and packages.  


Sep 22, 2021 2:11 PM in response to coopere905

There are no known Viruses in the wild that self replicate and affect macOS. There are Malware and Adware that does affect macOS and are often times downloaded as part of an Application from Third Party UnTrusted Site and get installed along with the Application. For this purpose - Suggest downloading from a Respected ASC Contributor the application Malwarebytes for Mac. It is free or paid for added features. Run the Application and it should remove the malware / adware. Once done, restart computer and test.


Any Third Party Applications that will interfere with the normal operation of the OS, alter, modify, remove or delete or attempt to do so is an invitation for disaster and may require a Reinstallation of the OS.


And CleanMyMac - over 600 hits all pointing to Remove ASAP as per Developers Instruction


Sep 22, 2021 1:33 PM in response to coopere905

Having done some research, I have also run EtreCheck, and it is here that I am requesting help. The log is attached.

You finally used the right tool and all it found was all the malware you installed to remove the suspected malware.

As already advised, remove all of the malware you installed to find what you think is some sort of other malware.

What symptoms are you having that makes you think you have some other malware installed?

Sep 22, 2021 1:26 PM in response to coopere905

using apps like Avast, ClamXAV, and CleanMyMac to remove malware is like trying to use gasoline to extinguish a fire. as already instructed, you should uninstall them first. then after that, we can begin to help you with the issue that caused you to install that junk ware in the first place.


to help us with that diagnosis, i'm thinking you should download and run the free version of EtreCheck so we can see if you have some software installed that is causing your issue. make sure you give "full disk access" to etrecheck. read how to use it by reading Using EtreCheck. if you need help interpreting the report, you can see how to post the report here by reading How to use the Add Text Feature When Posting Large Amounts of Text, i.e. an Etrecheck Report. and it automatically obscures sensitive things (like serial numbers) so you don't have to worry about sharing the report here.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Help Detecting Potential Malware

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.