Possible Trojan. Help!

Ok I understand that utility programs aren't routinely necessary for MacBook Pro but I've seen a slowing recently so I'm wondering if I've already picked up a trojan and have no idea how I did. Also I live rural so no access to a Apple Store so I'd have to send it in. Anything out there to help this problem?

MacBook Pro (13-inch Mid 2009), OS X Mavericks (10.9.2)

Posted on Mar 17, 2014 10:22 AM

Reply
8 replies

Mar 17, 2014 11:22 AM in response to chattphotos

I 'll be working either on the internet, word processing, spreadsheet, or so on and either the the laptop is slow to respond (won't swich programs keyboard/touchpad will not respond, program will not close if not resonding) or the multi-color wheel shows up sometimes requiring a hard reset to continue to keep working.


Yes I have repaired disk permissions and disabled the Garmin update at startup. The only programs running at startup are the iTunesHelper and my Cannon Network Scanner utility. It did say that the iTunesHelper could not be found???


Thanks for responding.

Mar 17, 2014 11:35 AM in response to Chris-Woody

Boot to recovery and repair the disk (hold cmd+R at startup). Open Activity Monitor from the Applications>Utilities folder. Make sure All Processes are showing and not just My Processes. Select the CPU tab and order the percent column in descending order. See what is using a lot of CPU and report back.


Also, it would help us help you if you download and run etrecheck and post the report it creates here.

Mar 17, 2014 11:54 AM in response to Chris-Woody

Launch the Console application in any of the following ways:


☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)


☞ In the Finder, select Go Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.


☞ Open LaunchPad. Click Utilities, then Console in the icon grid.


Make sure the title of the Console window is All Messages. If it isn't, select All Messages from the SYSTEM LOG QUERIES menu on the left. If you don't see that menu, select

View Show Log List

from the menu bar.


Click the Clear Display icon in the toolbar. Then try the action that you're having trouble with again. Select any messages that appear in the Console window. Copy them to the Clipboard by pressing the key combination command-C. Paste into a reply to this message (command-V).

When posting a log extract, be selective. In most cases, a few dozen lines are more than enough.

Please do not indiscriminately dump thousands of lines from the log into this discussion.

Important: Some private information, such as your name, may appear in the log. Anonymize before posting.

Mar 17, 2014 3:01 PM in response to cbs20

I have included a copy of the activity monitor and the etRecheck report. A lot to look at again, thank you.




kernel_task1.926.207619,9960root0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
launchd0.01.79321root0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
WindowServer19.91:07.2462,135102_windowserver0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
hidd1.710.97410446root0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
sysmond0.31.3236123root0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
launchservicesd0.01.016453root0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
loginwindow0.00.552840cwoodward0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
com.apple.internetaccounts0.00.7935214cwoodward0 bytes0 bytes0 bytes64 bitYesYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
ShareKitHelper0.00.3336212cwoodward0 bytes0 bytes0 bytes64 bitYesYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
FlipShareServer0.00.39725365root0 bytes0 bytes0 bytes32 BitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
configd0.01.1381456root0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
appleeventsd0.00.074254_appleevents0 bytes0 bytes0 bytes64 bitNoYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
powerd0.00.292530root0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
locationd0.00.267442_locationd0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
pacemaker0.00.16337119root0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
UserEventAgent0.00.376711root0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
CVMServer0.00.0534125root0 bytes0 bytes0 bytes64 bitNoYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
cfprefsd0.00.514774root0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
mDNSResponder0.00.6153737_mdnsresponder0 bytes0 bytes0 bytes64 bitYesYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
notifyd0.00.493215root0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
mds0.04.9843736root0 bytes0 bytes0 bytes64 bitNoYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
networkd0.00.2924111_networkd0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
coreservicesd0.01.034868root0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
syslogd0.00.214322root0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
fseventsd0.00.7484847root0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
mds_stores0.04.21211112root0 bytes0 bytes0 bytes64 bitNoYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
filecoordinationd0.00.0421206root0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
launchd0.00.4020151cwoodward0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
Activity Monitor4.74.17510289cwoodward0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
Dock1.84.67591162cwoodward0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
com.apple.dock.extra0.00.2336234cwoodward0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
Finder0.38.42435165cwoodward0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
Notification Center0.10.7848181cwoodward0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
distnoted0.10.3555157cwoodward0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
Canon IJ Network Scanner Selector0.10.67546207cwoodward0 bytes0 bytes0 bytes32 BitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
SystemUIServer0.01.0047164cwoodward0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
FlipShareAutoRun0.00.2133203cwoodward0 bytes0 bytes0 bytes32 BitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
UserEventAgent0.00.8256156cwoodward0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
AirPlayUIAgent0.00.1136236cwoodward0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
cookied0.01.2522209cwoodward0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
pbs0.00.1121269cwoodward0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
fontd0.02.1523178cwoodward0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
imagent0.00.1122195cwoodward0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
ubd0.00.60101177cwoodward0 bytes0 bytes0 bytes64 bitNoYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
storeagent0.00.2723241cwoodward0 bytes0 bytes0 bytes64 bitYesYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
SocialPushAgent0.00.2731186cwoodward0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
AppleSpell.service0.00.5621280cwoodward0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
secd0.00.1322208cwoodward0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
helpd0.00.0221197cwoodward0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
WiFiKeychainProxy0.00.0321189cwoodward0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
CalendarAgent0.01.1341184cwoodward0 bytes0 bytes0 bytes64 bitNoYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
identityservicesd0.00.7441196cwoodward0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
accountsd0.00.2722188cwoodward0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
AirPort Base Station Agent0.00.0240226cwoodward0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
tccd0.00.2523161cwoodward0 bytes0 bytes0 bytes64 bitYesYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
usernoted0.00.2820180cwoodward0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
AppleIDAuthAgent0.00.0130199cwoodward0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
mdflagwriter0.00.0120283cwoodward0 bytes0 bytes0 bytes64 bitYesYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
librariand0.00.1620176cwoodward0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
spindump_agent0.00.0120253cwoodward0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
CVMCompiler0.00.9320288cwoodward0 bytes0 bytes0 bytes64 bitNoYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
sharingd0.00.1931174cwoodward0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
recentsd0.00.1020279cwoodward0 bytes0 bytes0 bytes64 bitYesYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
pboard0.00.0110172cwoodward0 bytes0 bytes0 bytes64 bitYesYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
lsboxd0.00.0522193cwoodward0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
CloudKeychainProxy0.00.0220221cwoodward0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
warmd0.00.083219root0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
opendirectoryd0.01.6861133root0 bytes0 bytes0 bytes64 bitNoYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
diskarbitrationd0.00.112216root0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
airportd0.00.443163root0 bytes0 bytes0 bytes64 bitYesYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
com.apple.iCloudHelper0.00.9755210cwoodward0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
coreaudiod0.00.5441166_coreaudiod0 bytes0 bytes0 bytes64 bitNoYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
com.apple.audio.DriverHelper0.00.0620215_coreaudiod0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
blued0.00.163158root0 bytes0 bytes0 bytes64 bitYesYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
kextd0.00.802212root0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
apsd0.00.354261root0 bytes0 bytes0 bytes64 bitNoYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
autofsd0.00.012160root0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
usbmuxd0.00.033120_usbmuxd0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
stackshot0.00.013124root0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
ocspd0.01.035490root0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
aosnotifyd0.00.264262root0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
softwareupdated0.00.2522231_softwareupdate0 bytes0 bytes0 bytes64 bitYesYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
suhelperd0.00.0321235root0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
usbd0.00.1121116root0 bytes0 bytes0 bytes64 bitNoYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
xpcd0.00.3923169cwoodward0 bytes0 bytes0 bytes64 bitYesYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
com.apple.IconServicesAgent0.00.9520223cwoodward0 bytes0 bytes0 bytes64 bitYesYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
ntpd0.00.0220117root0 bytes0 bytes0 bytes64 bitYesYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
taskgated0.00.832213root0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
securityd0.00.594114root0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
dynamic_pager0.00.011049root0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
xpcd0.00.0220233_softwareupdate0 bytes0 bytes0 bytes64 bitYesYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
com.apple.InputMethodKit.UserDictionary0.00.0920282cwoodward0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
securityd_service0.00.1420154root0 bytes0 bytes0 bytes64 bitYesYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
com.apple.NotesMigratorService0.00.0520238cwoodward0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
distnoted0.00.102166root0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
authd0.00.224073root0 bytes0 bytes0 bytes64 bitNoYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
com.apple.CodeSigningHelper0.00.0721136root0 bytes0 bytes0 bytes64 bitYesYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
xpcd0.00.0220171_coreaudiod0 bytes0 bytes0 bytes64 bitYesYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
revisiond0.00.044029root0 bytes0 bytes0 bytes64 bitNoYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
KernelEventAgent0.00.013043root0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
rooksd0.00.053064root0 bytes0 bytes0 bytes32 BitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
launchd0.00.0220255_spotlight0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
distnoted0.00.0121258_spotlight0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
networkd_privileged0.00.0221113root0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
SleepServicesD0.00.012027root0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
IMDPersistenceAgent0.00.0430211cwoodward0 bytes0 bytes0 bytes64 bitYesNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
logind0.00.022041root0 bytes0 bytes0 bytes64 bitNoNoNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
xpcd0.00.0120218_appleevents0 bytes0 bytes0 bytes64 bitYesYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
xpcd0.00.052069root0 bytes0 bytes0 bytes64 bitYesYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
wdhelper0.00.022018root0 bytes0 bytes0 bytes64 bitYesYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
netbiosd0.00.0220230_netbios0 bytes0 bytes0 bytes64 bitYesYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
systemstatsd0.00.0620277root0 bytes0 bytes0 bytes64 bitYesYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes
tccd0.00.0120170root0 bytes0 bytes0 bytes64 bitYesYesNo0 bytes0 bytes00-0 bytes0 bytes0 bytes0 bytes





Hardware Information:

MacBook Pro (13-inch, Mid 2009)

MacBook Pro - model: MacBookPro5,5

1 2.53 GHz Intel Core 2 Duo CPU: 2 cores

4 GB RAM


Video Information:

NVIDIA GeForce 9400M - VRAM: 256 MB


System Software:

OS X 10.9.2 (13C64) - Uptime: 0 days 0:25:21


Disk Information:

FUJITSU MJA2320BH FFS G1 disk0 : (320.07 GB)

EFI (disk0s1) <not mounted>: 209.7 MB

Macintosh HD (disk0s2) / [Startup]: 319.21 GB (291.8 GB free)

Recovery HD (disk0s3) <not mounted>: 650 MB


HL-DT-ST DVDRW GS23N


USB Information:

Apple Internal Memory Card Reader


Apple Inc. Built-in iSight


Apple Inc. BRCM2046 Hub

Apple Inc. Bluetooth USB Host Controller


Apple Inc. Apple Internal Keyboard / Trackpad


Apple Computer, Inc. IR Receiver


FireWire Information:


Thunderbolt Information:


Launch Daemons:

[System] com.adobe.fpsaud.plist 3rd-Party support link

[System] com.flipvideo.FlipShareServer.launchd.plist 3rd-Party support link

[System] com.google.keystone.daemon.plist 3rd-Party support link

[System] com.oracle.java.Helper-Tool.plist 3rd-Party support link

[System] com.oracle.java.JavaUpdateHelper.plist 3rd-Party support link

[System] com.trusteer.rooks.rooksd.plist 3rd-Party support link


Launch Agents:

[System] com.flipvideo.FlipShare.AutoRun.plist 3rd-Party support link

[System] com.google.keystone.agent.plist 3rd-Party support link

[System] com.oracle.java.Java-Updater.plist 3rd-Party support link


User Launch Agents:

[not loaded] com.google.GoogleContactSyncAgent.plist 3rd-Party support link


User Login Items:

iTunesHelper

Canon IJ Network Scanner Selector2


Internet Plug-ins:

o1dbrowserplugin: Version: 5.1.7.17873 3rd-Party support link

Default Browser: Version: 537 - SDK 10.9

Flip4Mac WMV Plugin: Version: 2.4.1.4 3rd-Party support link

OfficeLiveBrowserPlugin: Version: 12.3.6 3rd-Party support link

SlingPlayer: Version: (null) - SDK 10.6 3rd-Party support link

Silverlight: Version: 5.1.20513.0 - SDK 10.6 3rd-Party support link

FlashPlayer-10.6: Version: 12.0.0.77 - SDK 10.6 3rd-Party support link

Flash Player: Version: 12.0.0.77 - SDK 10.6 3rd-Party support link

QuickTime Plugin: Version: 7.7.3

googletalkbrowserplugin: Version: 5.1.7.17873 3rd-Party support link

npgtpo3dautoplugin: Version: 0.1.44.29 - SDK 10.5 3rd-Party support link

GarminGpsControl: Version: 4.0.4.0 Release - SDK 10.6 3rd-Party support link

iPhotoPhotocast: Version: 7.0

JavaAppletPlugin: Version: Java 7 Update 51 3rd-Party support link


Safari Extensions:

Amazon Shopping Assistant: Version: 1.1

Searchme: Version: 1.2

Ebay Shopping Assistant: Version: 1.1

Slick Savings: Version: 1.0


Audio Plug-ins:

BluetoothAudioPlugIn: Version: 1.0 - SDK 10.9

AirPlay: Version: 2.0 - SDK 10.9

AppleAVBAudio: Version: 203.2 - SDK 10.9

iSightAudio: Version: 7.7.3 - SDK 10.9


iTunes Plug-ins:

Quartz Composer Visualizer: Version: 1.4 - SDK 10.9


3rd Party Preference Panes:

3ivx MPEG-4 3rd-Party support link

Flash Player 3rd-Party support link

Flip4Mac WMV 3rd-Party support link

Java 3rd-Party support link

Rapport 3rd-Party support link


Old Applications:

Microsoft AutoUpdate: Version: 2.3.6 - SDK 10.4 3rd-Party support link

/Library/Application Support/Microsoft/MAU2.0/Microsoft AutoUpdate.app

/Library/Application Support/Microsoft/MERP2.0

Microsoft Error Reporting: Version: 2.2.9 - SDK 10.4 3rd-Party support link

Microsoft Ship Asserts: Version: 1.1.4 - SDK 10.4 3rd-Party support link

SLLauncher: Version: 1.0 - SDK 10.5 3rd-Party support link

/Library/Application Support/Microsoft/Silverlight/OutOfBrowser/SLLauncher.app

Garmin Lifetime Map Updater: Version: 2.2 - SDK 10.5 3rd-Party support link


Time Machine:

Time Machine not configured!


Top Processes by CPU:

12% PluginProcess

3% WindowServer

2% EtreCheck

0% coreservicesd

0% Canon IJ Network Scanner Selector2


Top Processes by Memory:

98 MB ocspd

86 MB Finder

86 MB mds_stores

66 MB WindowServer

61 MB Mail


Virtual Memory Information:

1.86 GB Free RAM

1.19 GB Active RAM

182 MB Inactive RAM

531 MB Wired RAM

287 MB Page-ins

0 B Page-outs

Mar 17, 2014 3:20 PM in response to Chris-Woody

1. This procedure is a diagnostic test. It changes nothing, for better or worse, and therefore will not, in itself, solve the problem.

2. If you don't already have a current backup, back up all data before doing anything else. The backup is necessary on general principle, not because of anything in the test procedure. There are ways to back up a computer that isn't fully functional. Ask if you need guidance.

3. Below are instructions to run a UNIX shell script, a type of program. All it does is to collect information about the state of the computer. That information goes nowhere unless you choose to share it. However, you should be cautious about running any kind of program (not just a shell script) at the request of a stranger on a public message board. If you have doubts, search this site for other discussions in which this procedure has been followed without any report of ill effects. If you can't satisfy yourself that the instructions are safe, don't follow them. Ask for other options.

Here's a summary of what you need to do, if you choose to proceed: Copy a line of text from this web page into the window of another application. Wait for the script to run. It usually takes a few minutes. Then paste the results, which will have been copied automatically, back into a reply on this page. The sequence is: copy, paste, wait, paste again. Details follow.

4. You may have started the computer in "safe" mode. Preferably, these steps should be taken in “normal” mode. If the system is now in safe mode and works well enough in normal mode to run the test, restart as usual. If you can only test in safe mode, do that.

5. If you have more than one user, and the one affected by the problem is not an administrator, then please run the test twice: once while logged in as the affected user, and once as an administrator. The results may be different. The user that is created automatically on a new computer when you start it for the first time is an administrator. If you can't log in as an administrator, test as the affected user. Most personal Macs have only one user, and in that case this section doesn’t apply. Don't log in as root.

6. The script is a single long line, all of which must be selected. You can accomplish this easily by triple-clicking anywhere in the line. The whole line will highlight, though you may not see all of it in the browser window, and you can then copy it. If you try to select the line by dragging across the part you can see, you won't get all of it.

Triple-click anywhere in the line of text below on this page to select it:

PATH=/usr/bin:/bin:/usr/sbin:/sbin; clear; Fb='%s\n\t(%s)\n'; Fm='\n%s\n\n%s\n'; Fr='\nRAM details\n%s\n'; Fs='\n%s: %s\n'; Fu='user %s%%, system %s%%'; AC="com.autodesk.AutoCAD com.google.GoogleDrive"; H='^[[:space:]]*((127\.0\.0\.1|::1|fe80::1%lo0)[[:space:]]+local|(255\.){3}255[[:space:]]*broadcast)host[[:space:]]*$'; NS=networksetup; PB="/usr/libexec/PlistBuddy -c Print"; A () { [[ a -eq 0 ]]; }; M () { find -L "$d" -type f | while read f; do file -b "$f" | egrep -lq XML\|exec && echo $f; done; }; AT () { o=`file -b "$1" | egrep -v '^(A.{16}t$|cann)'`; Ps "${1##*/} format"; }; Pc () { o=`grep -v '^ *#' "$2"`; l=`wc -l <<< "$o"`; [[ l -gt 25 ]] && o=`head -n25 <<< "$o"`$'\n'"[$((l-25)) more line(s)]"; Pm "$1"; AT "$1"; }; Pm () { [[ "$o" ]] && o=`sed -E '/^ *$/d; s/^ */ /;s/[-0-9A-Fa-f]{22,}/UUID/g;s/(ochat)\.[^.]+(\..+)/\1\2/' <<< "$o"` && printf "$Fm" "$1" "$o"; }; Pp () { o=`$PB "$2" | awk -F'= ' \/$3'/{print $2}'`; Pm "$1"; }; Ps () { o=`echo $o`; [[ ! "$o" =~ ^0?$ ]] && printf "$Fs" "$1" "$o"; }; R () { o=; [[ r -eq 0 ]]; }; SP () { system_profiler SP${1}DataType; }; id -G | grep -qw 80; a=$?; A && sudo true; r=$?; t=`date +%s`; clear; { A || echo $'No admin access\n'; A && ! R && echo $'No root access\n'; SP Software | sed -n 's/^ *//;5p;6p;8p'; h=(`SP Hardware | awk '/ Id/{print $3}; /Mem/{print $2}'`); o=$h; Ps "Model"; o=$((h[1]<4?h[1]:0)); Ps "Total RAM (GB)"; o=`SP Memory | sed '1,5d;/[my].*:/d'`; [[ "$o" =~ s:\ [^O]|x([^08]|0[^2]|8[^0]) ]] && printf "$Fr" "$o"; o=`SP Diagnostics | sed '5,6!d'`; [[ "$o" =~ Pass ]] || Pm "POST"; p=`SP Power`; o=`awk '/Cy/{print $NF}' <<< "$p"`; o=$((o>=300?o:0)); Ps "Battery cycles"; o=`sed -n '/Cond.*: [^N]/{s/^.*://p;}' <<< "$p"`; Ps "Battery condition"; for b in FireWire Thunderbolt USB; do o=`SP $b | sed -En '1d;/:$/{s/ *:$//;x;s/\n//p;};/^ *(V.+ [0N]|Man).+ /{s/ 0x.... //;s/[()]//g;s/(.+: )(.+)/ \(\2\)/;H;};/Apple|Genesy|Intel|SMSC/{s/.//g;h;}' | egrep -v '^ *[(]'`; Pm $b; done; o=`pmset -g therm | sed 's/^.*C/C/'`; [[ "$o" =~ No\ th|pms ]] && o=; Pm "Thermal conditions"; o=`pmset -g sysload | grep -v :`; [[ "$o" =~ =\ [^GO] ]] || o=; Pm "System load advisory"; o=`nvram boot-args | awk '{$1=""; print}'`; Ps "boot-args"; a=(/ ""); A=(System User); for i in 0 1; do o=`cd ${a[$i]}L*/Lo*/Diag* || continue; for f in *.{cr,h,pa,s}*; do [[ -f "$f" ]] || continue; d=$(stat -f%Sc -t%F "$f"); [[ "$f" =~ h$ ]] && grep -lq "^Thread c" "$f" && f="$f *"; echo "$d ${f%%_2*} ${f##*.}"; done | sort | tail`; Pm "${A[$i]} diagnostics"; done; grep -lq '*$' <<< "$o" && printf $'\n\t* Code injection\n'; o=`syslog -F bsd -k Sender kernel -k Message CReq 'caug|GPU |hfs: Ru|last value [1-9]|n Cause: -|NVDA\(|pagin|proc: t|Roamed|rror|ssert|Thrott|timed? ?o|WARN' -k Message Ane 'SMC:' | tail -n25 | awk '/:/{$4=""; $5=""};1'`; Pm "Kernel messages"; o=`df -m / | awk 'NR==2 {print $4}'`; o=$((o<5120?o:0)); Ps "Free space (MiB)"; o=$(($(vm_stat | awk '/eo/{sub("\\.",""); print $2}')/256)); o=$((o>=1024?o:0)); Ps "Pageouts (MiB)"; s=( `sar -u 1 10 | sed '$!d'` ); [[ s[4] -lt 85 ]] && o=`printf "$Fu" ${s[1]} ${s[3]}` || o=; Ps "Total CPU usage" && { s=(`ps acrx -o comm,ruid,%cpu | sed '2!d'`); n=$((${#s[*]}-1)); c="${s[*]}"; o=${s[$n]}%; Ps "CPU usage by process \"${c% ${s[$((n-1))]}*}\" with UID ${s[$((n-1))]}"; }; s=(`top -R -l1 -n1 -o prt -stats command,uid,prt | sed '$!d'`); n=$((${#s[*]}-1)); s[$n]=${s[$n]%[+-]}; c="${s[*]}"; o=$((s[$n]>=25000?s[$n]:0)); Ps "Mach ports used by process \"${c% ${s[$((n-1))]}*}\" with UID ${s[$((n-1))]}"; o=`kextstat -kl | grep -v com\\.apple | cut -c53- | cut -d\< -f1`; Pm "Loaded extrinsic kernel extensions"; R && o=`sudo launchctl list | awk 'NR>1 && !/0x|com\.(apple|openssh|vix\.cron)|org\.(amav|apac|calendarse|cups|dove|isc|ntp|openld|post[fg]|x)/{print $3}'`; Pm "Extrinsic daemons"; o=`launchctl list | awk 'NR>1 && !/0x|com\.apple|org\.(x|openbsd)|\.[0-9]+$/{print $3}'`; Pm "Extrinsic agents"; o=`for d in {/,}L*/Lau*; do M; done | egrep -v 'com\.apple\.(CSConfig|server)' | while read f; do ID=$($PB\ :Label "$f") || ID="No job label"; printf "$Fb" "$f" "$ID"; done`; Pm "launchd items"; o=`for d in /{S*/,}L*/StartupItems; do M; done`; Pm "Startup items"; sys=`pkgutil --regexp --only-files --files com.apple.pkg.* | sort | uniq | sed 's:^:/:'`; b=`sed -E '/^.+Lib.+\/Contents\/Info.plist$/!d;s/\/Info.plist$//;/Contents\/./d' <<< "$sys"`; l=`egrep '^/usr/lib/.+dylib$' <<< "$sys"`; [[ "$b" && "$l" ]] && { o=`find -L /S*/L*/{C*/Sec*A,E}* {/,}L*/{A*d,Compon,Ex,In,iTu,Keyb,Mail/B,P*P,Qu*T,Scripti,Sec,Servi,Spo}* -type d -name Contents -prune | grep -Fv "$b" | while read d; do test -f "$d/Info.plist" || continue; ID=$($PB\ :CFBundleIdentifier "$_") || ID="No bundle ID"; printf "$Fb" "${d%/Contents}" "$ID"; done`; Pm "Extrinsic loadable bundles"; o=`find /usr/lib -type f -name *.dylib | grep -Fv "$l"`; Pm "Extrinsic shared libraries"; :; } || echo $'\nReceipts missing'; o=`for e in INSERT_LIBRARIES LIBRARY_PATH; do launchctl getenv DYLD_$e; done`; Pm "Environment"; o=`find -L {,/u*/lo*}/e*/periodic -type f -mtime -10d`; Pm "Modified periodic scripts"; o=`scutil --proxy | grep Prox`; Pm "Proxies"; o=`scutil --dns | awk '/r\[0\] /{if ($NF !~ /^1(0|72\.(1[6-9]|2[0-9]|3[0-1])|92\.168)\./) print $NF; exit}'`; i=`route -n get default | awk '/e:/{print $2}'`; I=`$NS -listnetworkserviceorder | sed -En '/ '$i'\)$/{x;s/^\(.+\) //p;q;};x'`; n=`$NS -getdnsservers "$I" | awk '!/^T/{print "not "}'`; Ps "DNS (${n}from DHCP)"; o=`$NS -getinfo "$I" | awk '/k:/{if ($3 !~ "(255\.){3}0") print $3}'`; Ps "Netmask"; R && o=`sudo profiles -P | grep : | wc -l`; Ps "Profiles"; f=auto_master; [[ `md5 -q /etc/$f` =~ ^b166 ]] || Pc $f /etc/$f; for f in fstab sysctl.conf crontab launchd.conf; do Pc $f /etc/$f; done; f=/etc/hosts; Pc "hosts" <(egrep -v "$H" $f ); AT $f; Pc "User launchd" ~/.launchd*; R && Pc "Root crontab" <(sudo crontab -l); Pc "User crontab" <(crontab -l | sed -E 's:/Users/[^/]+/:/Users/USER/:g'); R && o=`sudo defaults read com.apple.loginwindow LoginHook`; Pm "Login hook"; LD="$(`find /S*/*/F* -type f -name lsregister | head -n1` -dump)"; o=`for ID in $AC; do [[ "$LD" =~ $ID ]] && echo $ID; done`; Pm "Application check"; Pp "Global login items" /L*/P*/loginw* Path; Pp "User login items" L*/P*/*loginit* Name; Pp "Safari extensions" L*/Saf*/*/E*.plist Bundle | sed -E 's/(\..*$|-[1-9])//g'; o=`find ~ $TMPDIR.. \( -flags +sappnd,schg,uappnd,uchg -o ! -user $UID -o ! -perm -600 \) | wc -l`; Ps "Restricted user files"; cd; o=`SP Fonts | egrep 'id: N|te: Y' | wc -l`; Ps "Font problems"; o=`find L*/{Con,Pref}* -type f ! -size 0 -name *.plist | while read f; do plutil -s "$f" >&- || echo $f; done`; Pm "Bad plists"; d=(Desktop L*/Keyc*); n=(20 7); for i in 0 1; do o=`find "${d[$i]}" -type f -maxdepth 1 | wc -l`; o=$((o<=n[$i]?0:o)); Ps "${d[$i]##*/} file count"; done; o=; [[ UID -eq 0 ]] && o=root; Ps "UID"; o=$((`date +%s`-t)); Ps "Elapsed time (s)"; } 2>/dev/null | pbcopy; exit 2>&-

Copy the selected text to the Clipboard by pressing the key combination command-C.

7. Launch the built-in Terminal application in any of the following ways:

☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)

☞ In the Finder, select Go ▹ Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.

☞ Open LaunchPad. Click Utilities, then Terminal in the icon grid.

Click anywhere in the Terminal window and paste (command-V). The text you pasted should vanish immediately. If it doesn't, press the return key.

8. If you see an error message in the Terminal window such as "syntax error," enter

exec bash

and press return. Then paste the script again.

9. If you're logged in as an administrator, you'll be prompted for your login password. Nothing will be displayed when you type it. You will not see the usual dots in place of typed characters. Make sure caps lock is off. Type carefully and then press return. You may get a one-time warning to be careful. If you make three failed attempts to enter the password, the test will run anyway, but it will produce less information. In most cases, the difference is not important. If you don't know the password, or if you prefer not to enter it, press the key combination control-C or just press return three times at the password prompt. Again, the script will still run.

If you're not logged in as an administrator, you won't be prompted for a password. The test will still run. It just won't do anything that requires administrator privileges.

10. The test may take a few minutes to run, depending on how many files you have and the speed of the computer. A computer that's abnormally slow may take longer to run the test. While it's running, there will be nothing in the Terminal window and no indication of progress. Wait for the line

[Process completed]

to appear. If you don't see it within half an hour or so, the test probably won't complete in a reasonable time. In that case, close the Terminal window and report the results. No harm will be done.

11. When the test is complete, quit Terminal. The results will have been copied to the Clipboard automatically. They are not shown in the Terminal window. Please don't copy anything from there. All you have to do is start a reply to this comment and then paste by pressing command-V again.

If any private information, such as your name or email address, appears in the results, anonymize it before posting. Usually that won't be necessary.

12. When you post the results, you might see the message, "You have included content in your post that is not permitted." It means that the forum software has misidentified something in the post as a violation of the rules. If that happens, please post the test results on Pastebin, then post a link here to the page you created.

Note: This is a public forum, and others may give you advice based on the results of the test. They speak only for themselves, and I don't necessarily agree with them.


________________________________

Copyright © 2014 by Linc Davis. As the sole author of this work, I reserve all rights to it except as provided in the Terms of Use of the Apple Support Communities website ("ASC"). Readers of ASC may copy it for their own personal use. Neither the whole nor any part may be redistributed.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Possible Trojan. Help!

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.