Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Papras Trojan?

I noticed recently that my computer seemed to be slowing down somewhat (taking much longer to boot up from switch on, getting the infamous spinning beach ball whilst opening applications, trying to complete tasks etc.) so decided to run a scan to check everything was ok. I have Sophos Anti-Virus software installed and it has never reported any issues up until now, so I must admit to only running occasional system scans (unlike my previous Windows PC where I ran a check every week!) However, this time it has detected the presence of "Troj/Papras-AZ".


The Sophos dialog box informed me that Automatic Cleanup was available, so I clicked this, but I'm now told Automatic Cleanup was not successful and a Manual Cleanup is required. Looking on the Sophos forums, the processes to do this look a little daunting to say the least!


Has anyone else had experience of the Papras Trojan infecting their Mac? And if so, how did you solve the problem?


I'm advised the original location on my computer was /Users/Owner/Library/Containers/com.apple.mail/Data/Library/Mail Downloads….


The path and filename is: /Volumes/Backup/Backups.backupdb/.… this is followed by the "name" of my computer and a succession of dates starting 21 May 2015. Sixteen entries in total. I presume these correspond to the dates this file was backed up (to an external hard drive using Time Machine).


Of course, this still may not be the reason for my computer running slow, but I have checked storage etc. and all seems ok (402gb free out of 500gb in total). But even if it's not the cause, I'm still anxious to get rid of it if it has the potential to cause harm to me, my system, or anyone else I come into contact with.


For info, I am running a 2012 Mac Mini, i5 processor, 4gb RAM, OS X 10.8.5 Mountain Lion.


Any help you can give would be much appreciated. Thank you.


Ambulancebloke.

Mac mini (Late 2012), OS X Mountain Lion (10.8.2)

Posted on Jul 15, 2015 5:16 AM

Reply
Question marked as Best reply

Posted on Jul 15, 2015 6:43 AM

I at one time also used Sophos and found it would give me false positives so I removed that program. Really not required on a Mac. I would guess your slow operation is from something else like some software. Try running EtreCheck app and post the results here. It may identify incompatible app. or other process slowing your Mac down.

5 replies
Question marked as Best reply

Jul 15, 2015 6:43 AM in response to Ambulancebloke

I at one time also used Sophos and found it would give me false positives so I removed that program. Really not required on a Mac. I would guess your slow operation is from something else like some software. Try running EtreCheck app and post the results here. It may identify incompatible app. or other process slowing your Mac down.

Jul 15, 2015 7:52 AM in response to Ambulancebloke

As tbirdvet mentioned, antivirus applications on OS X are unnecessary. There are no viruses for OS X however there is a VERY small amount of other malware which is easily avoided, I will explain how to avoid them below. I strongly recommend using the uninstall instructions Sophos provides. In addition to not needing antivirus apps, OS X does not need any cleaning, 3rd party maintenance utilities or the like. In most cases, if you leave OS X alone and follow the instructions below you will be rewarded with years of trouble free service.


How to avoid malware on OS X:


  • Never use a torrent to download anything.
  • If you receive an ad, pop-up, e-mail or phone call advising your computer has been compromised, this is a SCAM.
  • Keep OS X up-to-date.


It's really about that simple.

Jul 15, 2015 2:53 PM in response to tbirdvet

Thanks to all for your replies...


Tbirdvet - Ran EtreCheck as you suggested. This is the report:


Hardware Information: ℹ️

Mac mini (Late 2012) (Technical Specifications)

Mac mini - model: Macmini6,1

1 2.5 GHz Intel Core i5 CPU: 2-core

4 GB RAM

BANK 0/DIMM0

2 GB DDR3 1600 MHz ok

BANK 1/DIMM0

2 GB DDR3 1600 MHz ok

Bluetooth: Good - Handoff/Airdrop2 supported

Wireless: en1: 802.11 a/b/g/n


Video Information: ℹ️

Intel HD Graphics 4000 - VRAM: 512 MB

SyncMaster 1152 x 864 @ 75 Hz


System Software: ℹ️

OS X 10.8.5 (12F2542) - Time since boot: one day 2:46:31


Disk Information: ℹ️

APPLE HDD HTS545050A7E362 disk0 : (500.11 GB)

disk0s1 (disk0s1) <not mounted> : 210 MB

Macintosh HD (disk0s2) / : 499.25 GB (402.68 GB free)

Recovery HD (disk0s3) <not mounted> [Recovery]: 650 MB


USB Information: ℹ️

Seagate BUP Slim SL 500.11 GB

Backup (disk1s1) /Volumes/Backup : 500.10 GB (434.31 GB free)

USB USB Keykoard

Logitech USB Laser Mouse

Apple Inc. BRCM20702 Hub

Apple Inc. Bluetooth USB Host Controller

Apple, Inc. IR Receiver


Thunderbolt Information: ℹ️

Apple Inc. thunderbolt_bus


Gatekeeper: ℹ️

Mac App Store and identified developers


Kernel Extensions: ℹ️

/System/Library/Extensions

[loaded] com.Logitech.Control Center.HID Driver (3.7.0 - SDK 10.6) [Click for support]

[not loaded] com.Logitech.Unifying.HID Driver (1.3.0 - SDK 10.6) [Click for support]

[not loaded] com.motorola-mobility.driver.MotMobileUSB (1.2.2 - SDK 10.5) [Click for support]

[loaded] com.seagate.driver.PowSecDriverCore (5.2.6 - SDK 10.4) [Click for support]

[loaded] com.sophos.kext.sav (9.2.0 - SDK 10.8) [Click for support]

[loaded] com.sophos.nke.swi (9.2.0 - SDK 10.8) [Click for support]


/System/Library/Extensions/MotMobileUSB.kext/Contents/PlugIns

[not loaded] com.motorola-mobility.driver.MotMobileMS (1.0.0 - SDK 10.5) [Click for support]

[not loaded] com.motorola-mobility.driver.MotMobileMTP (1.2.2 - SDK 10.5) [Click for support]

[not loaded] com.motorola-mobility.driver.MotMobileUSBLAN (1.2.2 - SDK 10.5) [Click for support]

[not loaded] com.motorola-mobility.driver.MotMobileUSBLANMerge (1.2.2 - SDK 10.5) [Click for support]

[not loaded] com.motorola-mobility.driver.MotMobileUSBSwch (1.2.2 - SDK 10.5) [Click for support]


/System/Library/Extensions/Seagate Storage Driver.kext/Contents/PlugIns

[not loaded] com.seagate.driver.PowSecLeafDriver_10_4 (5.2.6 - SDK 10.4) [Click for support]

[loaded] com.seagate.driver.PowSecLeafDriver_10_5 (5.2.6 - SDK 10.5) [Click for support]

[not loaded] com.seagate.driver.SeagateDriveIcons (5.2.6 - SDK 10.4) [Click for support]


Problem System Launch Agents: ℹ️

[failed] com.apple.AirPlayUIAgent.plist

[failed] com.apple.coreservices.appleid.authentication.plist

[failed] com.apple.printtool.agent.plist [Click for details]


Problem System Launch Daemons: ℹ️

[failed] com.apple.wdhelper.plist

[running] com.seagate.TBDecorator.plist [Click for support]


Launch Agents: ℹ️

[running] com.Logitech.Control Center.Daemon.plist [Click for support]

[failed] com.motorola.MDMUpdater.plist [Click for support] [Click for details]

[running] com.motorola.motohelper.plist [Click for support]

[loaded] com.motorola.motohelperUpdater.plist [Click for support]

[running] com.sophos.uiserver.plist [Click for support]


Launch Daemons: ℹ️

[loaded] com.adobe.fpsaud.plist [Click for support]

[loaded] com.microsoft.office.licensing.helper.plist [Click for support]

[running] com.motorola-mobility.mmcfgd.plist [Click for support]

[loaded] com.rogueamoeba.instanton-agent.plist [Click for support]

[running] com.sophos.common.servicemanager.plist [Click for support]


User Launch Agents: ℹ️

[loaded] com.adobe.ARM.[...].plist [Click for support]

[running] com.spotify.webhelper.plist [Click for support]


User Login Items: ℹ️

iTunesHelper Application (/Applications/iTunes.app/Contents/MacOS/iTunesHelper.app)

AdobeResourceSynchronizer Application Hidden (/Applications/Adobe Reader.app/Contents/Support/AdobeResourceSynchronizer.app)

Dropbox Application (/Applications/Dropbox.app)

Spotify Application Hidden (/Applications/Spotify.app)


Internet Plug-ins: ℹ️

FlashPlayer-10.6: Version: 18.0.0.209 - SDK 10.6 [Click for support]

QuickTime Plugin: Version: 7.7.1

AdobePDFViewerNPAPI: Version: 11.0.11 - SDK 10.6 [Click for support]

Flash Player: Version: 18.0.0.209 - SDK 10.6 [Click for support]

AdobePDFViewer: Version: 11.0.11 - SDK 10.6 [Click for support]

SharePointBrowserPlugin: Version: 14.5.1 - SDK 10.6 [Click for support]

Silverlight: Version: 5.1.30514.0 - SDK 10.6 [Click for support]

JavaAppletPlugin: Version: 14.3.0 - SDK 10.8 Check version


Safari Extensions: ℹ️

donation reminder


3rd Party Preference Panes: ℹ️

Flash Player [Click for support]

Logitech Control Center [Click for support]

Paragon NTFS for Mac ® OS X [Click for support]

Seagate Dashboard for Mac OSX [Click for support]


Time Machine: ℹ️

Skip System Files: NO

Auto backup: YES

Volumes being backed up:

Macintosh HD: Disk size: 499.25 GB Disk used: 96.57 GB

Destinations:

Backup [Local]

Total size: 500.10 GB

Total number of backups: 51

Oldest backup: 2015-04-15 11:46:45 +0000

Last backup: 2015-07-15 21:40:56 +0000

Size of backup disk: Adequate

Backup size 500.10 GB > (Disk used 96.57 GB X 3)

/sbin excluded from backup!

/usr excluded from backup!

/System excluded from backup!

/bin excluded from backup!

/private excluded from backup!

/Library excluded from backup!

/Applications excluded from backup!


Top Processes by CPU: ℹ️

10% Spotify Helper(2)

3% AdobeReader

2% WindowServer

1% Dropbox

1% Microsoft Word


Top Processes by Memory: ℹ️

356 MB WebProcess

205 MB Safari

172 MB SophosScanD

160 MB Spotify Helper(2)

131 MB InterCheck


Virtual Memory Information: ℹ️

46 MB Free RAM

3.95 GB Used RAM

2.44 GB Swap Used


Diagnostics Information: ℹ️

Jul 14, 2015, 07:55:13 PM Self test - passed

Jul 15, 2015 3:06 PM in response to Ambulancebloke

This

https://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/T roj~Papras-AZ/detailed-analysis.aspx

says Troj/Papras-AZ

is a Windows executable and thus wouod ony be a convern to you if you ran Windows via BootCamp or a VM.


More memory will help with speed since 4 GB is not enough

Remove Sophos since it slows down the computer. I used to use it but it caused more mores and never found anything.

You can also add an SSD

Papras Trojan?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.