Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Stubborn Virus

User uploaded file


I have often heard that MACs do not get viruses. I am not sure that is still true. I do have anti virus software installed on my MAC and for the last couple of days have been getting warnings about this 'virus infection' being blocked. I ran a scan and 9 infections were detected (the infections had a 'tr. The infections were moved to the quarantine chest and I deleted them. However, today as soon as I started up my MAC again, I kept getting the virus warnings again.


Could someone on here please shed some light onto this for me, what it could be and what I can do about it?


Thank you!

Mac mini, Mac OS X (10.6.4)

Posted on Jan 27, 2016 4:06 PM

Reply
Question marked as Best reply

Posted on Jan 27, 2016 5:07 PM

You do not have a virus....No Mac running OS X has been affected by a documented virus. Malware, occasionally if one visits odd sites or downloads from unknown sources.


First, get rid of the A/V software. Most of that stuff causes harm - in varying degrees - to Macs. After you uninstall that junk, I would reinstall OS X from your recovery disk.


Barry

12 replies
Question marked as Best reply

Jan 27, 2016 5:07 PM in response to michaelv03

You do not have a virus....No Mac running OS X has been affected by a documented virus. Malware, occasionally if one visits odd sites or downloads from unknown sources.


First, get rid of the A/V software. Most of that stuff causes harm - in varying degrees - to Macs. After you uninstall that junk, I would reinstall OS X from your recovery disk.


Barry

Jan 27, 2016 10:03 PM in response to Allan Eckert

Hi Allan,


Thank you for the tip and the link. Here you go:


EtreCheck version: 2.7.8 (238)

Report generated 2016-01-27 21:39:06

Download EtreCheck from http://etrecheck.com

Runtime 2:33

Performance: Excellent


Click the [Support] links for help with non-Apple products.

Click the [Details] links for more information about that line.

Click the [Remove] links to remove adware.

Click the [Check files] link for help with unknown files.


Problem: Other problem

Description:

Possible malware


Hardware Information:

Mac mini (Late 2012)

[Technical Specifications] - [User Guide] - [Warranty & Service]

Mac mini - model: Macmini6,2

1 2.3 GHz Intel Core i7 CPU: 4-core

16 GB RAM

BANK 0/DIMM0

8 GB DDR3 1600 MHz ok

BANK 1/DIMM0

8 GB DDR3 1600 MHz ok

Bluetooth: Good - Handoff/Airdrop2 supported

Wireless: en1: 802.11 a/b/g/n


Video Information:

Intel HD Graphics 4000 - VRAM: 768 MB

SMB2230H 1920 x 1080 @ 60 Hz


System Software:

OS X Mountain Lion 10.8.5 (12F45) - Time since boot: about one day


Disk Information:

APPLE HDD HTS541010A9E662 disk0 : (1 TB) (Rotational)

disk0s1 (disk0s1) <not mounted> : 210 MB

Macintosh HD (disk0s2) / : 999.35 GB (225.34 GB free)

Recovery HD (disk0s3) <not mounted> [Recovery]: 650 MB


USB Information:

Western Digital Ext HDD 1021 1 TB

disk1s1 (disk1s1) <not mounted> : 210 MB

EM Business (disk1s2) /Volumes/EM Business : 500.10 GB (497.22 GB free)

EM Personal (disk1s3) /Volumes/EM Personal 1 : 499.62 GB (42.56 GB free)

Apple Inc. Keyboard Hub

Apple Inc. Apple Keyboard

TOSHIBA STOR.E ALU 2S 500.11 GB

MINI PUNK (disk2s1) /Volumes/MINI PUNK : 500.11 GB (301.92 GB free)

PIXART USB OPTICAL MOUSE

Yamaha Corporation Steinberg UR22

Apple, Inc. IR Receiver

Apple Inc. BRCM20702 Hub

Apple Inc. Bluetooth USB Host Controller

Alesis Q49


Thunderbolt Information:

Apple Inc. thunderbolt_bus


Gatekeeper:

Anywhere


Unknown Files:

~/Library/LaunchAgents/com.pcv.hlpramcn.plist

~/Library/LaunchAgents/com.jdibackup.ZipCloud.backupstart.plist

~/Library/LaunchAgents/com.jdibackup.ZipCloud.notify.plist

~/Library/LaunchAgents/com.jdibackup.ZipCloud.autostart.plist

4 unknown files found. [Check files]


Kernel Extensions:

/Library/Application Support/Avast/components/fileshield/unsigned

[loaded] com.avast.AvastFileShield (2.1.0 - SDK 10.10) [Support]


/Library/Application Support/Avast/components/proxy/unsigned

[loaded] com.avast.PacketForwarder (2.0 - SDK 10.10) [Support]


/System/Library/Extensions

[loaded] com.avira.kext.FileAccessControl (1.0.0d1 - SDK 10.9) [Support]

[not loaded] com.caiaq.driver.NIUSBGuitarRigMobileDriver (2.6.0 - SDK 10.7) [Support]

[not loaded] com.caiaq.driver.NIUSBHardwareDriver (2.6.0 - SDK 10.7) [Support]

[loaded] com.movavi.driver.SoundGrabber (1.6.5 - SDK 10.6) [Support]

[loaded] jp.co.yamaha.driver.YamahaSteinbergUSBAudio (1.8.31 - SDK 10.6) [Support]


Launch Agents:

[running] com.avast.update-agent.plist [Support]

[loaded] com.avast.userinit.plist [Support]

[loaded] com.avira.antivirus.ipm.ui.plist [Support]

[loaded] com.avira.antivirus.notifications.agent.plist [Support]

[loaded] com.avira.antivirus.odscan.default.plist [Support]

[loaded] com.avira.antivirus.scheduler.agent.plist [Support]

[running] com.avira.antivirus.systray.plist [Support]

[loaded] com.avira.antivirus.telemetry.agent.plist [Support]

[loaded] com.avira.antivirus.update.default.plist [Support]

[running] com.epson.Epson_Low_Ink_Reminder.launcher.plist [Support]

[running] com.epson.eventmanager.agent.plist [Support]

[loaded] com.google.keystone.agent.plist [Support]


Launch Daemons:

[loaded] com.adobe.fpsaud.plist [Support]

[loaded] com.anchorfree.ajaxserver.plist [Support]

[loaded] com.avast.init.plist [Support]

[loaded] com.avast.uninstall.plist [Support]

[loaded] com.avast.update.plist [Support]

[loaded] com.avira.antivirus.dbcleaner.plist [Support]

[loaded] com.avira.antivirus.ipm.loader.plist [Support]

[running] com.avira.helper.watchdox.plist [Support]

[loaded] com.google.keystone.daemon.plist [Support]

[loaded] com.microsoft.office.licensing.helper.plist [Support]


User Launch Agents:

[loaded] com.BlueStacks.AppPlayer.LogRotator.plist [Support]

[loaded] com.BlueStacks.AppPlayer.Service.plist [Support]

[loaded] com.BlueStacks.AppPlayer.UninstallAgent.plist [Support]

[loaded] com.BlueStacks.AppPlayer.UpdaterAgent.plist [Support]

[loaded] com.adobe.ARM.[...].plist [Support]

[loaded] com.avast.home.userinit.plist [Support]

[loaded] com.citrixonline.GoToMeeting.G2MUpdate.plist [Support]

[loaded] com.jdibackup.ZipCloud.autostart.plist [Support]

[loaded] com.jdibackup.ZipCloud.backupstart.plist [Support]

[loaded] com.jdibackup.ZipCloud.notify.plist [Support]

[running] com.pcv.hlpramcn.plist [Support]

[running] com.spotify.webhelper.plist [Support]


User Login Items:

uHD-Agent Application (/Applications/BlueStacks.app/Contents/Runtime/uHD-Agent.app)

iTunesHelper Application (/Applications/iTunes.app/Contents/MacOS/iTunesHelper.app)

Hotspot Shield UNKNOWN (missing value)

NIHardwareAgent Application Hidden (/Library/Application Support/Native Instruments/Hardware/NIHardwareAgent.app)

Android File Transfer Agent Application (~/Library/Application Support/Google/Android File Transfer/Android File Transfer Agent.app)

Dropbox Application (/Applications/Dropbox.app)

Advanced Mac Cleaner UNKNOWN (missing value)

uTorrent UNKNOWN (missing value)


Other Apps:

[loaded] 0x7fa0c2106bd0.mach_init.Inspector

[running] [0x0-0x11011].com.BlueStacks.AppPlayer.Agent

[running] [0x0-0x15015].com.native-instruments.NIHardwareService

[running] [0x0-0x16016].com.google.android.mtpagent

[running] [0x0-0x223223].com.google.Chrome

[running] [0x0-0x2c62c6].com.jdibackup.ZipCloud

[running] [0x0-0x2e72e7].com.microsoft.Word

[running] [0x0-0x2ea2ea].com.microsoft.autoupdate.fba

[running] [0x0-0x30a30a].com.adobe.Reader

[running] [0x0-0x347347].com.microsoft.outlook.databasedaemon

[running] [0x0-0x3eb3eb].com.etresoft.EtreCheck

[loaded] com.avast.account

[loaded] com.avast.crashreport

[running] com.avast.daemon

[running] com.avast.fileshield

[running] com.avast.helper

[running] com.avast.proxy

[running] com.avast.service


Internet Plug-ins:

FlashPlayer-10.6: Version: 20.0.0.286 - SDK 10.6 [Support]

QuickTime Plugin: Version: 7.7.1

AdobePDFViewerNPAPI: Version: 10.1.4 [Support]

Flash Player: Version: 20.0.0.286 - SDK 10.6 [Support]

AdobePDFViewer: Version: 10.1.4 [Support]

SharePointBrowserPlugin: Version: 14.4.8 - SDK 10.6 [Support]

Silverlight: Version: 5.1.20913.0 - SDK 10.6 [Support]

JavaAppletPlugin: Version: 14.5.0 - SDK 10.8 Check version


User internet Plug-ins:

BlueStacks Install Detector: Version: 0.3.6 - SDK 10.7 [Support]

CitrixOnlineWebDeploymentPlugin: Version: 1.0.105 [Support]

Picasa: Version: 1.0 - SDK 10.6 [Support]


Safari Extensions:

Searchme Adware! [Remove]

Avast Online Security

Slick Savings Adware! [Remove]

Amazon Shopping Assistant Adware! [Remove]

Ebay Shopping Assistant Adware! [Remove]


Audio Plug-ins:

DVCPROHDAudio: Version: 1.3.2

EcammAudioLoader: Version: 1.0.4 - SDK 10.10 [Support]

CallRecorder: Version: v2.5.19 - SDK 10.10 [Support]


3rd Party Preference Panes:

Flash Player [Support]

Native Instruments USB Audio [Support]

Yamaha Steinberg USB [Support]


Time Machine:

Mobile backups: OFF

Auto backup: NO - Auto backup turned off

Destinations:

EM Business [Local]

Total size: 0 B

Total number of backups: 0

Oldest backup: -

Last backup: -

Size of backup disk: Excellent

Backup size 0 B > (Disk size 0 B X 3)


Top Processes by CPU:

90% Google Chrome Helper(9)

29% Google Chrome

4% WindowServer

3% Dock

3% diskmanagementd


Top Processes by Memory:

1.89 GB Google Chrome Helper(9)

410 MB savapi

377 MB Google Chrome

377 MB GarageBand

262 MB com.avast.daemon


Virtual Memory Information:

2.40 GB Free RAM

14.00 GB Used RAM

381 MB Swap Used


Diagnostics Information:

Jan 26, 2016, 04:19:27 PM ~/Library/Logs/DiagnosticReports/Logic Pro_2016-01-26-161927_[redacted].crash

com.apple.logic.pro - /Applications/Logic Pro.app/Contents/MacOS/Logic Pro

Jan 26, 2016, 04:19:02 PM ~/Library/Logs/DiagnosticReports/Avast_2016-01-26-161902_[redacted].crash

com.avast.AAFM - /Applications/Avast.app/Contents/MacOS/Avast

Jan 26, 2016, 03:40:04 PM ~/Library/Logs/DiagnosticReports/SystemUIServer_2016-01-26-154004_[redacted].cr ash

com.apple.systemuiserver - /System/Library/CoreServices/SystemUIServer.app/Contents/MacOS/SystemUIServer

Jan 26, 2016, 09:46:01 AM Self test - passed

Dec 31, 2015, 06:01:49 PM /Library/Logs/DiagnosticReports/Kernel_2015-12-31-180149_[redacted].panic [Details]

Jan 28, 2016 1:00 AM in response to michaelv03

- You have two anti-virus apps installed, Avast and Avari. Having one installed is bad enough but with two they tend to fightone another. I would uninstall both using the developer's unistalling instructions.

- I would also use other than Chrome since Chrome tends to us a lot of CPU like you are seeing

90% Google Chrome Helper(9)

- I would also remove these Safari extensions unless you rely want them

Searchme Adware! [Remove]

Slick Savings Adware! [Remove]

Amazon Shopping Assistant Adware! [Remove]

Ebay Shopping Assistant Adware! [Remove]

Jan 28, 2016 6:52 AM in response to michaelv03

Check with either of your virus software - and/or search the internet for the full name of the virus. If you have not cleaned up TOP sites in Safari - you may have sites refreshing that have a Windows virus/malware or a Linux virus/malware on them and that is what keeps getting cleaned out.


Tops sites can be a danger along with RSS feeds (that automatically refresh with email or safari (even if just a bookmark) where you saved the bookmark and it had an extension to default asp - had one site where the bookmark after 1 year went to a bogus site - removing default asp went to the correct one.


Macs can pass on other systems Malware.

Stubborn Virus

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.