Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

New malware?

Since a couple of days my iMac (Snow Leopard (10.6.8) would not start up when it is connected to the Internet. Blue

screen appears, and the desktop never appears. If I disconnect the Internet or turn off the modem, it loads

correctly and works as usual. If I turn on the modem while the computer is already on, it freezes or gets extremely

slow - impossible to open any application or turn it off in a normal way. I called my Internet provider, we reset

the modem, and I connected my old PC to test the modem with another computer. It works without problem. After the

reset I tried it with Mac again. The computer was able to start up, very slowly, and I managed to set up the

Internet connection again. But then a message appeared on the screen saying "Please type you computer password in

order for Dropbox to function properly". I clicked "cancel". After that the computer became incredibly slow again,

freezing each time I clicked the mouse.
I would like to run ClamXav or another antivirus software but can not do it because I need to get definitions from

Internet, and the computer becomes not usable as soon as it's connected to the Internet.

Does it look like a malware? The message that appears by itself proposing to enter the password for the computer

seems not to be normal.

I would really appreciate some advice!

iMac, Mac OS X (10.6.8)

Posted on Oct 23, 2012 2:27 PM

Reply
Question marked as Best reply

Posted on Oct 23, 2012 2:43 PM

Doesn't sound like malware yet.


One way to test is to Safe Boot from the HD, (holding Shift key down at bootup), run Disk Utility in Applications>Utilities, then highlight your drive, click on Repair Permissions, Test for problem in Safe Mode...


PS. Safe boot may stay on the gray radian for a long time, let it go, it's trying to repair the Hard Drive


Reboot, test again.


If it only does it in Regular Boot, then it could be some hardware problem like Video card, (Quartz is turned off in Safe Mode), or Airport, or some USB or Firewire device, or 3rd party add-on, Check System Preferences>Accounts>Login Items window to see if it or something relevant is listed.


Check the System Preferences>Other Row, for 3rd party Pref Panes.


Also look in these if they exist, some are invisible...


/private/var/run/StartupItems

/Library/StartupItems

/System/Library/StartupItems

/System/Library/LaunchDaemons

/Library/LaunchDaemons

57 replies

Oct 28, 2012 1:41 PM in response to WZZZ

I am learning a lot with you guys 🙂


I repeated the procedure, plugged in the Ethernet cable while the computer was already on, and leaved the console

message window opened. No messages appeared. I could still move the applications window if they were already opened, but any click inside any application window made it freeze - the rainbow wheel started turning. When it stopped turning I could click again and then it turned again for about 5 minutes.

I don't get any message saying that I need to restart.


If I am patient enough, and Safari manages to open, it doesn't connect to any website - but blue bar in the address

line goes half way and stops, the wheel turns for some minutes and stops but nothing happens, and the Safari window

stays white and blanc, named "Untitled". It took 5 minutes for it to respond to make a screenshot:


User uploaded file


Now, even if I unplug the Ethernet cable, it doesn't help - need to shut down with power button and restart with

cable unplugged to make it work again.



Looked in "Console>Library>Logs>Diagnostic Reports" as WZZZ suggested.


1) in "~Library/Logs":

- in Diagnostic Reports - nothing with the date of today and nothing that contains the word "panic";

- in CrashReporter --> CSConfigDotMacCert.log - messages from today saying that the password for my-email@me.com could not be obtained from the keychain. (I replaced my real email for "my-email" just not to display it here).


2) in "Library/Logs":

- in DiagnosticReports - some messages about WacomTabletDriver crash but the latest is 2 days ago (Wacom tablet is not connected now);

- in CrashReporter - the same.


I don't see anything called "Hang Reporter".

Oct 28, 2012 2:10 PM in response to SnowLeo777

I'd delete or move the com.adobe.versioncueCS4.plist & reboot for a test.


See if this helps...


Open Keychain Access in Utilities, use Keychain First Aid under the Keychain Menu item, then either check the Password under that item, change it, or delete it and start over.


Keychain Access asks for keychain "login" after changing login password...


http://support.apple.com/kb/HT1631


Resetting your keychain in Mac OS X...


If Keychain First Aid finds an issue that it cannot repair, or if you do not know your keychain password, you may need to reset your keychain.


http://support.apple.com/kb/TS1544

Oct 29, 2012 8:42 AM in response to MadMacs0

Yes, as soon as I plugged in the Ethernet cable, "System Preferences" immediately jumped to 20,1% of CPU usage in Activity Monitor. It stayed like that for 5 minutes and then was showing "0" again. Then I clicked on a Safari icon trying to open it. It didn't respond with the wheel turning, but there were no big changes in Activity Monitor - "Dock" was showing 1$% of CPU usage.

Oct 29, 2012 11:06 AM in response to SnowLeo777

SnowLeo777 wrote:


BDAqua,


com.adobe.versioncueCS4.plist us found in two locations:

1) Mac HD --> Library --> LaunchDaemons

2) Mac HD --> Library --> Preferences

??? The error message says it's in "/private/etc/mach_init_per_user.d/" and the error may indicate it just has not been updated for your OS X. If you can't find one there then the one in LaunchDaemons may be the candicate.

Oct 29, 2012 12:08 PM in response to MadMacs0

MadMacs0 wrote:


??? The error message says it's in "/private/etc/mach_init_per_user.d/" and the error may indicate it just has not been updated for your OS X. If you can't find one there then the one in LaunchDaemons may be the candicate.


I think there is a confusion. There were two error messages:


Sender: com.apple.launchctl.Aqua[104]

Message: launchctl: Please convert the following to launchd: /etc/mach_init_per_user.d/com.adobe.versioncueCS4.monitor.plist


Sender: com.apple.launchd.peruser.501[102]

Message: (0x100302d80.mach_init.VersionCueCS4monitor) Failed to check-in!


BDAqua suggested to delete "com.adobe.versioncueCS4.plist" which is found in 2 locations:

1) Mac HD --> Library --> LaunchDaemons

2) Mac HD --> Library --> Preferences


But the file "com.adobe.versioncueCS4.monitor.plist" shown in the error message is indeed found in the folder " /etc/mach_init_per_user.d/"


So which one I should delete?

Oct 29, 2012 12:21 PM in response to MadMacs0

MadMacs0 wrote:



Version Cue CS4

I don't use CS4, but this looks to be an update checker. Could be corrupt or perhaps is checking an old address.


Still think downloading and re-installing the latest version is in order.


I have several Adobe CS4 appications installed. Did you mean uninstalling these applications or only the Version Cue? I never installed it, it just appeared in the System Preferences after the installation of one of the CS4 applications. Version Cue is not listed in "Applications". What would be the correct way to uninstall it?

Oct 29, 2012 12:37 PM in response to SnowLeo777

For the moment, I just removed the Version Cue CS4 from the System Preferences panel. The same 2 errors were shown after reboot:


Sender: com.apple.launchctl.Aqua[104]

Message: launchctl: Please convert the following to launchd: /etc/mach_init_per_user.d/com.adobe.versioncueCS4.monitor.plist


Sender: com.apple.launchd.peruser.501[102]

Message: (0x100302d80.mach_init.VersionCueCS4monitor) Failed to check-in!


So now, which file shoul I try to remove: "com.adobe.versioncueCS4.monitor.plist" or

"com.adobe.versioncueCS4.plist"?

New malware?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.