Stubborn Virus

User uploaded file


I have often heard that MACs do not get viruses. I am not sure that is still true. I do have anti virus software installed on my MAC and for the last couple of days have been getting warnings about this 'virus infection' being blocked. I ran a scan and 9 infections were detected (the infections had a 'tr. The infections were moved to the quarantine chest and I deleted them. However, today as soon as I started up my MAC again, I kept getting the virus warnings again.


Could someone on here please shed some light onto this for me, what it could be and what I can do about it?


Thank you!

Mac mini, Mac OS X (10.6.4)

Posted on Jan 27, 2016 4:06 PM

Reply
12 replies

Jan 27, 2016 10:03 PM in response to Allan Eckert

Hi Allan,


Thank you for the tip and the link. Here you go:


EtreCheck version: 2.7.8 (238)

Report generated 2016-01-27 21:39:06

Download EtreCheck from http://etrecheck.com

Runtime 2:33

Performance: Excellent


Click the [Support] links for help with non-Apple products.

Click the [Details] links for more information about that line.

Click the [Remove] links to remove adware.

Click the [Check files] link for help with unknown files.


Problem: Other problem

Description:

Possible malware


Hardware Information:

Mac mini (Late 2012)

[Technical Specifications] - [User Guide] - [Warranty & Service]

Mac mini - model: Macmini6,2

1 2.3 GHz Intel Core i7 CPU: 4-core

16 GB RAM

BANK 0/DIMM0

8 GB DDR3 1600 MHz ok

BANK 1/DIMM0

8 GB DDR3 1600 MHz ok

Bluetooth: Good - Handoff/Airdrop2 supported

Wireless: en1: 802.11 a/b/g/n


Video Information:

Intel HD Graphics 4000 - VRAM: 768 MB

SMB2230H 1920 x 1080 @ 60 Hz


System Software:

OS X Mountain Lion 10.8.5 (12F45) - Time since boot: about one day


Disk Information:

APPLE HDD HTS541010A9E662 disk0 : (1 TB) (Rotational)

disk0s1 (disk0s1) <not mounted> : 210 MB

Macintosh HD (disk0s2) / : 999.35 GB (225.34 GB free)

Recovery HD (disk0s3) <not mounted> [Recovery]: 650 MB


USB Information:

Western Digital Ext HDD 1021 1 TB

disk1s1 (disk1s1) <not mounted> : 210 MB

EM Business (disk1s2) /Volumes/EM Business : 500.10 GB (497.22 GB free)

EM Personal (disk1s3) /Volumes/EM Personal 1 : 499.62 GB (42.56 GB free)

Apple Inc. Keyboard Hub

Apple Inc. Apple Keyboard

TOSHIBA STOR.E ALU 2S 500.11 GB

MINI PUNK (disk2s1) /Volumes/MINI PUNK : 500.11 GB (301.92 GB free)

PIXART USB OPTICAL MOUSE

Yamaha Corporation Steinberg UR22

Apple, Inc. IR Receiver

Apple Inc. BRCM20702 Hub

Apple Inc. Bluetooth USB Host Controller

Alesis Q49


Thunderbolt Information:

Apple Inc. thunderbolt_bus


Gatekeeper:

Anywhere


Unknown Files:

~/Library/LaunchAgents/com.pcv.hlpramcn.plist

~/Library/LaunchAgents/com.jdibackup.ZipCloud.backupstart.plist

~/Library/LaunchAgents/com.jdibackup.ZipCloud.notify.plist

~/Library/LaunchAgents/com.jdibackup.ZipCloud.autostart.plist

4 unknown files found. [Check files]


Kernel Extensions:

/Library/Application Support/Avast/components/fileshield/unsigned

[loaded] com.avast.AvastFileShield (2.1.0 - SDK 10.10) [Support]


/Library/Application Support/Avast/components/proxy/unsigned

[loaded] com.avast.PacketForwarder (2.0 - SDK 10.10) [Support]


/System/Library/Extensions

[loaded] com.avira.kext.FileAccessControl (1.0.0d1 - SDK 10.9) [Support]

[not loaded] com.caiaq.driver.NIUSBGuitarRigMobileDriver (2.6.0 - SDK 10.7) [Support]

[not loaded] com.caiaq.driver.NIUSBHardwareDriver (2.6.0 - SDK 10.7) [Support]

[loaded] com.movavi.driver.SoundGrabber (1.6.5 - SDK 10.6) [Support]

[loaded] jp.co.yamaha.driver.YamahaSteinbergUSBAudio (1.8.31 - SDK 10.6) [Support]


Launch Agents:

[running] com.avast.update-agent.plist [Support]

[loaded] com.avast.userinit.plist [Support]

[loaded] com.avira.antivirus.ipm.ui.plist [Support]

[loaded] com.avira.antivirus.notifications.agent.plist [Support]

[loaded] com.avira.antivirus.odscan.default.plist [Support]

[loaded] com.avira.antivirus.scheduler.agent.plist [Support]

[running] com.avira.antivirus.systray.plist [Support]

[loaded] com.avira.antivirus.telemetry.agent.plist [Support]

[loaded] com.avira.antivirus.update.default.plist [Support]

[running] com.epson.Epson_Low_Ink_Reminder.launcher.plist [Support]

[running] com.epson.eventmanager.agent.plist [Support]

[loaded] com.google.keystone.agent.plist [Support]


Launch Daemons:

[loaded] com.adobe.fpsaud.plist [Support]

[loaded] com.anchorfree.ajaxserver.plist [Support]

[loaded] com.avast.init.plist [Support]

[loaded] com.avast.uninstall.plist [Support]

[loaded] com.avast.update.plist [Support]

[loaded] com.avira.antivirus.dbcleaner.plist [Support]

[loaded] com.avira.antivirus.ipm.loader.plist [Support]

[running] com.avira.helper.watchdox.plist [Support]

[loaded] com.google.keystone.daemon.plist [Support]

[loaded] com.microsoft.office.licensing.helper.plist [Support]


User Launch Agents:

[loaded] com.BlueStacks.AppPlayer.LogRotator.plist [Support]

[loaded] com.BlueStacks.AppPlayer.Service.plist [Support]

[loaded] com.BlueStacks.AppPlayer.UninstallAgent.plist [Support]

[loaded] com.BlueStacks.AppPlayer.UpdaterAgent.plist [Support]

[loaded] com.adobe.ARM.[...].plist [Support]

[loaded] com.avast.home.userinit.plist [Support]

[loaded] com.citrixonline.GoToMeeting.G2MUpdate.plist [Support]

[loaded] com.jdibackup.ZipCloud.autostart.plist [Support]

[loaded] com.jdibackup.ZipCloud.backupstart.plist [Support]

[loaded] com.jdibackup.ZipCloud.notify.plist [Support]

[running] com.pcv.hlpramcn.plist [Support]

[running] com.spotify.webhelper.plist [Support]


User Login Items:

uHD-Agent Application (/Applications/BlueStacks.app/Contents/Runtime/uHD-Agent.app)

iTunesHelper Application (/Applications/iTunes.app/Contents/MacOS/iTunesHelper.app)

Hotspot Shield UNKNOWN (missing value)

NIHardwareAgent Application Hidden (/Library/Application Support/Native Instruments/Hardware/NIHardwareAgent.app)

Android File Transfer Agent Application (~/Library/Application Support/Google/Android File Transfer/Android File Transfer Agent.app)

Dropbox Application (/Applications/Dropbox.app)

Advanced Mac Cleaner UNKNOWN (missing value)

uTorrent UNKNOWN (missing value)


Other Apps:

[loaded] 0x7fa0c2106bd0.mach_init.Inspector

[running] [0x0-0x11011].com.BlueStacks.AppPlayer.Agent

[running] [0x0-0x15015].com.native-instruments.NIHardwareService

[running] [0x0-0x16016].com.google.android.mtpagent

[running] [0x0-0x223223].com.google.Chrome

[running] [0x0-0x2c62c6].com.jdibackup.ZipCloud

[running] [0x0-0x2e72e7].com.microsoft.Word

[running] [0x0-0x2ea2ea].com.microsoft.autoupdate.fba

[running] [0x0-0x30a30a].com.adobe.Reader

[running] [0x0-0x347347].com.microsoft.outlook.databasedaemon

[running] [0x0-0x3eb3eb].com.etresoft.EtreCheck

[loaded] com.avast.account

[loaded] com.avast.crashreport

[running] com.avast.daemon

[running] com.avast.fileshield

[running] com.avast.helper

[running] com.avast.proxy

[running] com.avast.service


Internet Plug-ins:

FlashPlayer-10.6: Version: 20.0.0.286 - SDK 10.6 [Support]

QuickTime Plugin: Version: 7.7.1

AdobePDFViewerNPAPI: Version: 10.1.4 [Support]

Flash Player: Version: 20.0.0.286 - SDK 10.6 [Support]

AdobePDFViewer: Version: 10.1.4 [Support]

SharePointBrowserPlugin: Version: 14.4.8 - SDK 10.6 [Support]

Silverlight: Version: 5.1.20913.0 - SDK 10.6 [Support]

JavaAppletPlugin: Version: 14.5.0 - SDK 10.8 Check version


User internet Plug-ins:

BlueStacks Install Detector: Version: 0.3.6 - SDK 10.7 [Support]

CitrixOnlineWebDeploymentPlugin: Version: 1.0.105 [Support]

Picasa: Version: 1.0 - SDK 10.6 [Support]


Safari Extensions:

Searchme Adware! [Remove]

Avast Online Security

Slick Savings Adware! [Remove]

Amazon Shopping Assistant Adware! [Remove]

Ebay Shopping Assistant Adware! [Remove]


Audio Plug-ins:

DVCPROHDAudio: Version: 1.3.2

EcammAudioLoader: Version: 1.0.4 - SDK 10.10 [Support]

CallRecorder: Version: v2.5.19 - SDK 10.10 [Support]


3rd Party Preference Panes:

Flash Player [Support]

Native Instruments USB Audio [Support]

Yamaha Steinberg USB [Support]


Time Machine:

Mobile backups: OFF

Auto backup: NO - Auto backup turned off

Destinations:

EM Business [Local]

Total size: 0 B

Total number of backups: 0

Oldest backup: -

Last backup: -

Size of backup disk: Excellent

Backup size 0 B > (Disk size 0 B X 3)


Top Processes by CPU:

90% Google Chrome Helper(9)

29% Google Chrome

4% WindowServer

3% Dock

3% diskmanagementd


Top Processes by Memory:

1.89 GB Google Chrome Helper(9)

410 MB savapi

377 MB Google Chrome

377 MB GarageBand

262 MB com.avast.daemon


Virtual Memory Information:

2.40 GB Free RAM

14.00 GB Used RAM

381 MB Swap Used


Diagnostics Information:

Jan 26, 2016, 04:19:27 PM ~/Library/Logs/DiagnosticReports/Logic Pro_2016-01-26-161927_[redacted].crash

com.apple.logic.pro - /Applications/Logic Pro.app/Contents/MacOS/Logic Pro

Jan 26, 2016, 04:19:02 PM ~/Library/Logs/DiagnosticReports/Avast_2016-01-26-161902_[redacted].crash

com.avast.AAFM - /Applications/Avast.app/Contents/MacOS/Avast

Jan 26, 2016, 03:40:04 PM ~/Library/Logs/DiagnosticReports/SystemUIServer_2016-01-26-154004_[redacted].cr ash

com.apple.systemuiserver - /System/Library/CoreServices/SystemUIServer.app/Contents/MacOS/SystemUIServer

Jan 26, 2016, 09:46:01 AM Self test - passed

Dec 31, 2015, 06:01:49 PM /Library/Logs/DiagnosticReports/Kernel_2015-12-31-180149_[redacted].panic [Details]

Jan 28, 2016 1:00 AM in response to michaelv03

- You have two anti-virus apps installed, Avast and Avari. Having one installed is bad enough but with two they tend to fightone another. I would uninstall both using the developer's unistalling instructions.

- I would also use other than Chrome since Chrome tends to us a lot of CPU like you are seeing

90% Google Chrome Helper(9)

- I would also remove these Safari extensions unless you rely want them

Searchme Adware! [Remove]

Slick Savings Adware! [Remove]

Amazon Shopping Assistant Adware! [Remove]

Ebay Shopping Assistant Adware! [Remove]

Jan 28, 2016 6:52 AM in response to michaelv03

Check with either of your virus software - and/or search the internet for the full name of the virus. If you have not cleaned up TOP sites in Safari - you may have sites refreshing that have a Windows virus/malware or a Linux virus/malware on them and that is what keeps getting cleaned out.


Tops sites can be a danger along with RSS feeds (that automatically refresh with email or safari (even if just a bookmark) where you saved the bookmark and it had an extension to default asp - had one site where the bookmark after 1 year went to a bogus site - removing default asp went to the correct one.


Macs can pass on other systems Malware.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Stubborn Virus

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.