Want to highlight a helpful answer? Upvote!

Did someone help you, or did an answer or User Tip resolve your issue? Upvote by selecting the upvote arrow. Your feedback helps others! Learn more about when to upvote >

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

How do I detect and get rid of Malware?

I used Avira virus detection this morning, and it detected 2 threats, and the program automatically got rid of them. I did my full virus scan recently and saw another threat, which Avira took care of. I spoke to a live agent and in which he said I have a lot of junk, and potential malware on my computer, which Avira did not detect or take care of. He came to this conclusion by downloading me downloading team viewer on my computer and allowing him to go to my console, and read. How would I detect the malware and get rid of it? Here is the console: http://tny.cz/bd58ed48

MacBook Pro, OS X Yosemite (10.10)

Posted on Apr 30, 2015 4:05 PM

Reply
11 replies

Apr 30, 2015 4:23 PM in response to FarhanQ96

Also I used etrecheck and found this:


Hardware Information: ℹ️

MacBook Pro (17-inch, Late 2011) (Verified)

MacBook Pro - model: MacBookPro8,3

1 2.4 GHz Intel Core i7 CPU: 4-core

8 GB RAM Upgradeable

BANK 0/DIMM0

4 GB DDR3 1333 MHz ok

BANK 1/DIMM0

4 GB DDR3 1333 MHz ok

Bluetooth: Old - Handoff/Airdrop2 not supported

Wireless: en1: 802.11 a/b/g/n

Battery: Health = Normal - Cycle count = 263 - SN = C01213301T8DGKMBJ


Video Information: ℹ️

Intel HD Graphics 3000 - VRAM: 512 MB

AMD Radeon HD 6770M - VRAM: 1024 MB

Color LCD 1920 x 1200


System Software: ℹ️

OS X 10.10 (14A389) - Time since boot: 9:46:39


Disk Information: ℹ️

APPLE HDD HTS727575A9E362 disk0 : (750.16 GB)

EFI (disk0s1) <not mounted> : 210 MB

Recovery HD (disk0s3) <not mounted> [Recovery]: 650 MB

Macintosh HD (disk1) / : 748.93 GB (465.94 GB free)

Core Storage: disk0s2 749.30 GB Online


MATSHITADVD-R UJ-8A8


USB Information: ℹ️

Apple Inc. FaceTime HD Camera (Built-in)

Apple Inc. BRCM2070 Hub

Apple Inc. Bluetooth USB Host Controller

Apple Inc. Apple Internal Keyboard / Trackpad

Razer Razer DeathAdder 2013

Apple Computer, Inc. IR Receiver


Thunderbolt Information: ℹ️

Apple Inc. thunderbolt_bus


Gatekeeper: ℹ️

Mac App Store and identified developers


Kernel Extensions: ℹ️

/Library/Application Support/Hotspot Shield

[not loaded] com.anchorfree.tun (1.1.1 - SDK 10.8) [Click for support]


/Library/Extensions

[not loaded] com.BlackBerry.driver.USBCDCNCM (1.0.10 - SDK 10.7) [Click for support]

[loaded] com.razer.common.razerhid (11.30 - SDK 10.9) [Click for support]

[loaded] com.rim.driver.BlackBerryUSBDriverInt (2.2.7 - SDK 10.7) [Click for support]

[loaded] com.rim.driver.BlackBerryVirtualPrivateNetwork (1.0.18 - SDK 10.8) [Click for support]


/System/Library/Extensions

[loaded] com.LivestreamProcaster.driver.ProcasterAudioRedirector (2.0.0 - SDK 10.0) [Click for support]

[loaded] com.avira.kext.FileAccessControl (1.0.0d1 - SDK 10.9) [Click for support]


Launch Agents: ℹ️

[not loaded] com.adobe.AAM.Updater-1.0.plist [Click for support]

[loaded] com.avira.antivirus.general.agent.plist [Click for support]

[loaded] com.avira.antivirus.ipm.ui.plist [Click for support]

[loaded] com.avira.antivirus.notifications.agent.plist [Click for support]

[loaded] com.avira.antivirus.scheduler.agent.plist [Click for support]

[running] com.avira.antivirus.systray.plist [Click for support]

[loaded] com.avira.antivirus.telemetry.agent.plist [Click for support]

[failed] com.avira.antivirus.update.default.plist [Click for support] [Click for details]

[loaded] com.oracle.java.Java-Updater.plist [Click for support]

[running] com.razer.rzupdater.plist [Click for support]

[running] com.razerzone.rzdeviceengine.plist [Click for support]

[running] com.rim.BBLaunchAgent.plist [Click for support]

[running] com.rim.blackberrylink.BlackBerry-Link-Helper-Agent.plist [Click for support]

[running] com.rim.PeerManager.plist [Click for support]


Launch Daemons: ℹ️

[loaded] com.adobe.fpsaud.plist [Click for support]

[loaded] com.adobe.SwitchBoard.plist [Click for support]

[loaded] com.anchorfree.ajaxserver.plist [Click for support]

[loaded] com.avira.antivirus.dbcleaner.plist [Click for support]

[loaded] com.avira.antivirus.ipm.loader.plist [Click for support]

[running] com.avira.helper.watchdox.plist [Click for support]

[loaded] com.microsoft.office.licensing.helper.plist [Click for support]

[loaded] com.oracle.java.Helper-Tool.plist [Click for support]

[running] com.rim.BBDaemon.plist [Click for support]

[not loaded] com.rim.nkehelper.plist [Click for support]

[running] com.rim.tunmgr.plist [Click for support]

[loaded] com.skype.skypeinstaller.plist [Click for support]

[loaded] com.tunnelbear.mac.tbeard.plist [Click for support]


User Launch Agents: ℹ️

[loaded] com.google.keystone.agent.plist [Click for support]

[running] com.spotify.webhelper.plist [Click for support]

[loaded] com.valvesoftware.steamclean.plist [Click for support]


User Login Items: ℹ️

iTunesHelper Application (/Applications/iTunes.app/Contents/MacOS/iTunesHelper.app)

Caffeine Application (/Applications/Caffeine.app)

Spotify Application Hidden (/Applications/Spotify.app)

Hotspot Shield UNKNOWN (missing value)

Google Chrome Application Hidden (/Applications/Google Chrome.app)


Internet Plug-ins: ℹ️

FlashPlayer-10.6: Version: 17.0.0.169 - SDK 10.6 [Click for support]

QuickTime Plugin: Version: 7.7.3

Flash Player: Version: 17.0.0.169 - SDK 10.6 [Click for support]

Default Browser: Version: 600 - SDK 10.10

SharePointBrowserPlugin: Version: 14.0.0 [Click for support]

Silverlight: Version: 5.1.30514.0 - SDK 10.6 [Click for support]

JavaAppletPlugin: Version: Java 8 Update 31 Check version


Safari Extensions: ℹ️

Adblock Plus

Searchme Adware! [Click to remove]


3rd Party Preference Panes: ℹ️

Flash Player [Click for support]

Java [Click for support]


Time Machine: ℹ️

Time Machine not configured!


Top Processes by CPU: ℹ️

82% java

7% WindowServer

2% coreaudiod

1% fontd

1% mdworker(7)


Top Processes by Memory: ℹ️

1.62 GB com.apple.WebKit.WebContent(6)

614 MB kernel_task

573 MB java

459 MB Safari

377 MB savapi


Virtual Memory Information: ℹ️

41 MB Free RAM

7.95 GB Used RAM

1 MB Swap Used


Diagnostics Information: ℹ️

Apr 30, 2015, 09:33:17 AM Self test - passed

Apr 29, 2015, 11:17:45 PM /Library/Logs/DiagnosticReports/Activity Monitor_2015-04-29-231745_[redacted].crash

Apr 27, 2015, 11:51:45 PM /Users/[redacted]/Library/Logs/DiagnosticReports/UserKernel_2015-04-27-235145_[ redacted].crash

Apr 30, 2015 6:14 PM in response to FarhanQ96

Hello FarhanQ96,

Unfortunately it is quite common to see both antivirus and adware installed. Most antivirus only checks for Windows malware and ignores the growing adware epidemic on Macs.


I suggest you click on the "[Click to remove]" link in your EtreCheck report. That will give you a link where you can download the popular AdwareMedic tool (http://www.adwaremedic.com/index.php) that will remove your adware.

Apr 30, 2015 6:47 PM in response to FarhanQ96

Fat lot of good Avira has done for you. Follow its uninstallation instructions. The following files and folders will remain and require manual removal:


~/Library/Application Support/Avira

/Library/Application Support/Avira

~/Library/Saved Application State/com.avira.uninstall.savedState

~/Library/Saved Application State/com.avira.controlcenter.savedState

/var/log/com.avira.helper.watchdox.log


Never use any "cleaner" or "zapper" type programs to delete programs or their files.


In addition, "Adblock Plus" permits certain advertisers to bypass its restrictions and is therefore of limited utility. As an alternative, I suggest you research the completely unrelated Adblock: https://betafishinc.com/


Uninstall the RIM software, unless you are one of the elite few "Blackberry" users remaining on Earth.


Update OS X. Version 10.10.3 is the current release.


Remove "Hotspot Shield" also. Read below.


  1. Back up your Mac if you have not done so already. To learn how to use Time Machine read Mac Basics: Time Machine backs up your Mac - Apple Support.
  2. Delete the "Hotspot Shield" program from Applications if you did not already do that.
  3. Select the entire line that follows (triple-click to select it), then control-click, and from the contextual menu that appears, select Services > Open:


/Library/LaunchDaemons/

Locate the file containing the word "anchorfree". Drag it to the Trash.

Repeat the above instructions with the following:


/Library/Application Support/


Locate the folder named "Hotspot Shield" and drag it to the Trash.


Repeat the above instructions with the following:


~/Library/Preferences

and

/Library/Preferences


Locate any files containing the words "anchorfree" and drag them to the Trash.


Open System Preferences > Users & Groups. Click Login Items. If you find an item named Hotspot Shield, select it and delete it with the [—] (minus) button.


Log out or restart your Mac.


For a description of how this may have occurred, how to avoid it in the future, and for Apple's recommended actions read How to install adware. Apple's instructions are linked in the Recovery Procedure near the end of that document. Read and follow them carefully. Pay particular attention to the easily overlooked passages directing you to restart your Mac when required.


Review your Gatekeeper settings: OS X : About Gatekeeper - Apple Support. Gatekeeper is designed to help prevent you from inadvertently installing garbage software.

May 1, 2015 4:13 AM in response to FarhanQ96

In addition to what everyone else mentioned, I'm a little concerned by one thing that you said:


I spoke to a live agent and in which he said I have a lot of junk, and potential malware on my computer, which Avira did not detect or take care of.


Who was this "live agent?" Did you call an Avira support number? Did you see a pop-up in your web browser telling you that you had a virus, and did you then call the phone number provided? Did you Google "Apple support" and call a number found there?


The reason I ask is that I'm concerned you may have called the wrong folks and gotten scammed. So please let us know who you called so we can give you further guidance.

May 1, 2015 5:22 AM in response to thomas_r.

On the Avira website was this side panel which had live agents working to help customers or people with questions. So I clicked on one of the people that was online and free, and a chat box appeared, so I asked the same question I asked here, and they asked for my phone number and my name incase we got disconnected. I provided them with the information, and he made me download teamviewer for him to gain access to my computer, so he can see the issue. He went to the console on my computer and scrolled through it, and said that I had, "junk, and malware on my computer" and, suggested I make an appointment with an Avira technician to help me get rid of this junk and malware for $59.99.

May 1, 2015 6:00 AM in response to FarhanQ96

Avira is listed on the AppStore, which really shouldn't be necessary unless it's checking for windows malware. Before paying for a "tech call, I'd suggest buying Virex or another well known commercial anti-virus / malware app. To avoid inadvertently adding malware to you computer, decline any alerts to update Flash or JAVA. Instead, dismiss the alert & then go to Adobe.com or JAVA.com from your browser yourself. The maleware Genio is now pretending to be a Flash update & asks permission to instal itself… yes, I regret having fallen for that. Malware is an app & can only be installed if you give it permission usually by pressing Ok & entering your password. Always be certain that you wanted to download & install an app before giving your permission.

Cheers

May 1, 2015 9:29 AM in response to FarhanQ96

Since you initiated this from the Avira site, that should be okay. However, note that the Avira tech overstated his case to try to upsell you. You do not appear to have any actual malware installed, just a single adware Safari extension (Searchme), which you can remove by yourself very easily. (There may be similar extensions in Chrome and/or Firefox, if you have those installed.) Not to mention, of course, that you should have some serious questions about paying them to remove "malware" that you installed Avira to prevent. 😁


As for junk, yes, you may have some of that installed... Avira is included in that, though. In addition, remove the Blackberry and Razer software if you are no longer in need of it.

How do I detect and get rid of Malware?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.