Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Worried about a virus

So, as some of you may know... There is a third party app called Popcorn Time, that promises to deliver netflix like movies for free. I know I made a mistake downloading this. But they came out with an iOS version that does not need to be jail broken. It requires an installer that i installed on my mac, and then it prompts you through a number of instructions. You then have to connect your iOS device to your computer via usb. When i connected it to my iPad mini my iPad mini began restoring itself and it said "restore" and then the app was on there. When i went to click the app it never opened. I quickly deleted it off my iPad. And i deleted the iOS installer off my mac. Do i have a virus? I feel so stupid. Here's a link on an article for more info on what it is:

<Link Edited by Host>

MacBook Pro with Retina display, null

Posted on May 9, 2015 6:32 AM

Reply
27 replies

May 9, 2015 6:54 AM in response to Al7RIAN

There are no viruses for OS X, none so you don't have any viruses. However you may have installed some malware or adware. First download and run AdWare Medic and let it remove any adware. Then post an EtreCheck report of your computer and we can look for any other obvious issues.


Finally avoiding malware takes a little common sense:


  • Never use a torrent to download anything
  • If you receive an e-mail, popup ad or phone call telling you the computer has been compromised, that is a SCAM!!!!!
  • Finally keep your iMac's version of OS X up-to-date

May 9, 2015 5:44 PM in response to rkaufmann87

EtreCheck version: 2.2 (132)

Report generated 5/9/15, 8:40 PM

Download EtreCheck from http://etresoft.com/etrecheck


Click the [Click for support] links for help with non-Apple products.

Click the [Click for details] links for more information about that line.


Hardware Information: ℹ️

MacBook Pro (Retina, 15-inch, Late 2013) (Verified)

MacBook Pro - model: MacBookPro11,3

1 2.3 GHz Intel Core i7 CPU: 4-core

16 GB RAM Not upgradeable

BANK 0/DIMM0

8 GB DDR3 1600 MHz ok

BANK 1/DIMM0

8 GB DDR3 1600 MHz ok

Bluetooth: Good - Handoff/Airdrop2 supported

Wireless: en0: 802.11 a/b/g/n/ac

Battery: Health = Normal - Cycle count = 255 - SN = D864166Y27UF9CPA4


Video Information: ℹ️

Intel Iris Pro

Color LCD 2880 x 1800

NVIDIA GeForce GT 750M - VRAM: 2048 MB


System Software: ℹ️

OS X 10.10 (14A389) - Time since boot: one day 6:42:11


Disk Information: ℹ️

APPLE SSD SM0512F disk0 : (500.28 GB)

EFI (disk0s1) <not mounted> : 210 MB

Recovery HD (disk0s3) <not mounted> [Recovery]: 650 MB

Macintosh HD (disk1) / : 499.06 GB (124.89 GB free)

Encrypted AES-XTS Unlocked

Core Storage: disk0s2 499.42 GB Online


USB Information: ℹ️

Apple Internal Memory Card Reader

Microsoft Microsoft Notebook Receiver v2.0

Apple Inc. Apple Internal Keyboard / Trackpad

Apple Inc. BRCM20702 Hub

Apple Inc. Bluetooth USB Host Controller


Thunderbolt Information: ℹ️

Apple Inc. thunderbolt_bus


Gatekeeper: ℹ️

Mac App Store and identified developers


Startup Items: ℹ️

TuxeraNTFSUnmountHelper: Path: /Library/StartupItems/TuxeraNTFSUnmountHelper

Startup items are obsolete in OS X Yosemite


Launch Agents: ℹ️

[loaded] com.oracle.java.Java-Updater.plist [Click for support]


Launch Daemons: ℹ️

[loaded] com.adobe.fpsaud.plist [Click for support]

[unknown] com.iOSinstaller.updd.plist [Click for support]

[loaded] com.oracle.java.Helper-Tool.plist [Click for support]

[not loaded] org.eyebeam.SelfControl.plist [Click for support]


User Launch Agents: ℹ️

[loaded] com.google.keystone.agent.plist [Click for support]

[loaded] com.valvesoftware.steamclean.plist [Click for support]


User Login Items: ℹ️

Steam Application (/Applications/Steam.app)

iTunesHelper Application (/Applications/iTunes.app/Contents/MacOS/iTunesHelper.app)

uTorrent Application (/Applications/uTorrent.app)

pCloud Drive UNKNOWN (missing value)


Internet Plug-ins: ℹ️

FlashPlayer-10.6: Version: 14.0.0.145 - SDK 10.6 [Click for support]

Flash Player: Version: 14.0.0.145 - SDK 10.6 Outdated! Update

QuickTime Plugin: Version: 7.7.3

JavaAppletPlugin: Version: Java 8 Update 25 Check version

Default Browser: Version: 600 - SDK 10.10


3rd Party Preference Panes: ℹ️

Flash Player [Click for support]

Java [Click for support]

MacFUSE [Click for support]

NTFS-3G [Click for support]

Tuxera NTFS [Click for support]


Time Machine: ℹ️

Time Machine not configured!


Top Processes by CPU: ℹ️

3% launchd

2% fontd

2% WindowServer

1% com.apple.WebKit.WebContent(5)

0% Safari


Top Processes by Memory: ℹ️

1.15 GB kernel_task

934 MB Numbers(4)

836 MB com.apple.MediaLibraryService(5)

754 MB com.apple.WebKit.WebContent(5)

442 MB softwareupdated


Virtual Memory Information: ℹ️

5.65 GB Free RAM

10.00 GB Used RAM

0 B Swap Used


Diagnostics Information: ℹ️

May 8, 2015, 05:36:42 PM /Users/[redacted]/Library/Logs/DiagnosticReports/Call of Duty 4 Multiplayer_2015-05-08-173642_[redacted].crash

May 8, 2015, 04:57:34 PM /Users/[redacted]/Library/Logs/DiagnosticReports/UserKernel_2015-05-08-165734_[ redacted].crash

May 8, 2015, 04:51:24 PM /Users/[redacted]/Library/Logs/DiagnosticReports/UserKernel_2015-05-08-165124_[ redacted].crash

May 8, 2015, 01:58:06 PM Self test - passed

May 8, 2015, 01:53:29 PM /Users/[redacted]/Library/Logs/DiagnosticReports/node-webkit Helper_2015-05-08-135329_[redacted].crash

May 8, 2015, 12:01:22 AM /Users/[redacted]/Library/Logs/DiagnosticReports/LeagueofLegends_2015-05-08-000 122_[redacted].crash

May 7, 2015, 11:30:43 PM /Users/[redacted]/Library/Logs/DiagnosticReports/LoLPatcher_2015-05-07-233043_[ redacted].crash

May 7, 2015, 12:21:10 AM /Users/[redacted]/Library/Logs/DiagnosticReports/UserKernel_2015-05-07-002110_[ redacted].crash

May 7, 2015, 12:20:32 AM /Users/[redacted]/Library/Logs/DiagnosticReports/UserKernel_2015-05-07-002032_[ redacted].crash

May 6, 2015, 08:56:27 PM /Library/Logs/DiagnosticReports/Call of Duty 4 Multiplayer_2015-05-06-205627_[redacted].cpu_resource.diag [Click for details]

This is the report I received. There is a launch daemon that matched the program i used: [unknown] com.iOSinstaller.updd.plist [Click for support]

What could this be?

May 9, 2015 6:27 PM in response to Al7RIAN

I downloaded what I assume is the same "Popcorn Time" for iOS, and it is an exploit. Your phone is unsafe to use until it has been reset in DFU mode according to these instructions:


If your iPhone, iPad, or iPod touch doesn't respond or doesn't turn on - Apple Support


If you're in any doubt about what to do, make a "Genius" appointment at an Apple Store.

May 9, 2015 6:35 PM in response to Al7RIAN

I'm guessing I have to restore my iPad mini?

Yes.

what do I do about my mac?

1. This procedure is a diagnostic test. It changes nothing, for better or worse, and therefore will not, in itself, solve the problem. But with the aid of the test results, the solution may take a few minutes, instead of hours or days.

The test works on OS X 10.7 ("Lion") and later. I don't recommend running it on older versions of OS X. It will do no harm, but it won't do much good either.

Don't be put off by the complexity of these instructions. The process is much less complicated than the description. You do harder tasks with the computer all the time.

2. If you don't already have a current backup, back up all data before doing anything else. The backup is necessary on general principle, not because of anything in the test procedure. Backup is always a must, and when you're having any kind of trouble with the computer, you may be at higher than usual risk of losing data, whether you follow these instructions or not.

There are ways to back up a computer that isn't fully functional. Ask if you need guidance.

3. Below are instructions to run a UNIX shell script, a type of program. As I wrote above, it changes nothing. It doesn't send or receive any data on the network. All it does is to generate a human-readable report on the state of the computer. That report goes nowhere unless you choose to share it. If you prefer, you can act on it yourself without disclosing the contents to me or anyone else.

You should be wondering whether you can believe me, and whether it's safe to run a program at the behest of a stranger. In general, no, it's not safe and I don't encourage it.

In this case, however, there are a couple of ways for you to decide whether the program is safe without having to trust me. First, you can read it. Unlike an application that you download and click to run, it's transparent, so anyone with the necessary skill can verify what it does.

You may not be able to understand the script yourself. But variations of it have been posted on this website thousands of times over a period of years. The site is hosted by Apple, which does not allow it to be used to distribute harmful software. Any one of the millions of registered users could have read the script and raised the alarm if it was harmful. Then I would not be here now and you would not be reading this message. See, for example, this discussion.

Another indication that the test is safe can be found in this thread, and this one, for example, where the comment in which I suggested it was recommended by one of the Apple Community Specialists, as explained here.

Nevertheless, if you can't satisfy yourself that these instructions are safe, don't follow them. Ask for other options.

4. Here's a general summary of what you need to do, if you choose to proceed:

☞ Copy a particular line of text to the Clipboard.

☞ Paste into the window of another application.

☞ Wait for the test to run. It usually takes a few minutes.

☞ Paste the results, which will have been copied automatically, back into a reply on this page.

These are not specific instructions; just an overview. The details are in parts 7 and 8 of this comment. The sequence is: copy, paste, wait, paste again. You don't need to copy a second time.

5. Try to test under conditions that reproduce the problem, as far as possible. For example, if the computer is sometimes, but not always, slow, run the test during a slowdown.

You may have started up in safe mode. If the system is now in safe mode and works well enough in normal mode to run the test, restart as usual. If you can only test in safe mode, do that.

6. If you have more than one user, and the one affected by the problem is not an administrator, then please run the test twice: once while logged in as the affected user, and once as an administrator. The results may be different. The user that is created automatically on a new computer when you start it for the first time is an administrator. If you can't log in as an administrator, test as the affected user. Most personal Macs have only one user, and in that case this section doesn’t apply. Don't log in as root.

7. Load this linked web page (on the website "Pastebin.") The title of the page is "Diagnostic Test." Below the title is a text box headed by three small icons. The one on the right represents a clipboard. Click that icon to select the text, then copy it to the Clipboard on your computer by pressing the key combination command-C.

If the text doesn't highlight when you click the icon, select it by triple-clicking anywhere inside the box. Don't select the whole page, just the text in the box.

8. Launch the built-in Terminal application in any of the following ways:

☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)

☞ In the Finder, select Go ▹ Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.

☞ Open LaunchPad and start typing the name.

Click anywhere in the Terminal window to activate it. Paste from the Clipboard into the window by pressing command-V, then press return. The text you pasted should vanish immediately.

9. If you see an error message in the Terminal window such as "Syntax error" or "Event not found," enter

exec bash

and press return. Then paste the script again.

10. If you're logged in as an administrator, you'll be prompted for your login password. Nothing will be displayed when you type it. You will not see the usual dots in place of typed characters. Make sure caps lock is off. Type carefully and then press return. You may get a one-time warning to be careful. If you make three failed attempts to enter the password, the test will run anyway, but it will produce less information. If you don't know the password, or if you prefer not to enter it, just press return three times at the password prompt. Again, the script will still run.

If you're not logged in as an administrator, you won't be prompted for a password. The test will still run. It just won't do anything that requires administrator privileges.

11. The test may take a few minutes to run, depending on how many files you have and the speed of the computer. A computer that's abnormally slow may take longer to run the test. While it's running, a series of lines will appear in the Terminal window like this:

[Process started]

Part 1 of 8 done at … sec

Part 8 of 8 done at … sec

The test results are on the Clipboard.

Please close this window.

[Process completed]

The intervals between parts won't be exactly equal, but they give a rough indication of progress. The total number of parts may be different from what's shown here.

Wait for the final message "Process completed" to appear. If you don't see it within about ten minutes, the test probably won't complete in a reasonable time. In that case, press the key combination control-C or command-period to stop it and go to the next step. You'll have incomplete results, but still something.

12. When the test is complete, or if you stopped it because it was taking too long, quit Terminal. The results will have been copied to the Clipboard automatically. They are not shown in the Terminal window. Please don't copy anything from there. All you have to do is start a reply to this comment and then paste by pressing command-V again.

At the top of the results, there will be a line that begins with the words "Start time." If you don't see that, but instead see a mass of gibberish, you didn't wait for the "Process completed" message to appear in the Terminal window. Please wait for it and try again.

If any private information, such as your name or email address, appears in the results, anonymize it before posting. Usually that won't be necessary.

13. When you post the results, you might see an error message on the web page: "You have included content in your post that is not permitted," or "The message contains invalid characters." That's a bug in the forum software. Please post the test results on Pastebin, then post a link here to the page you created.

14. This is a public forum, and others may give you advice based on the results of the test. They speak for themselves, not for me. The test itself is harmless, but whatever else you're told to do may not be. For others who choose to run it, I don't recommend that you post the test results on this website unless I asked you to.

______________________________________________________________

Copyright © 2014, 2015 by Linc Davis. As the sole author of this work (including the referenced "Diagnostic Test"), I reserve all rights to it except as provided in the Use Agreement for the Apple Support Communities website ("ASC"). Readers of ASC may copy it for their own personal use. Neither the whole nor any part may be redistributed.

May 9, 2015 8:33 PM in response to Al7RIAN

That's the longest report I've ever seen from the test by a factor of ten. Most of it is a list of "Steam" mods.


You don't have any recognizable malware. Just restart to get rid of that entry in the process table. Your "Steam" games are crashing even more than they usually do because of all the mods, but that wasn't the question.

May 9, 2015 8:37 PM in response to Linc Davis

Hey Linc... Thank you so much for you're patience. I have tried restarting it and it doesn't do the trick.. And also, the iOSinstaller that shows up in the results.. what is that? I know that it has ties to popcorn time because that is what was used to install to iOS. it is a malicious thing? How else could i get rid of it?

Worried about a virus

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.