sharona777

Q: My macbook pro 2012 has a virus or malware for sure. How can I scan it?

I can tell by the way my computer is behaving that there is a virus or malware on board. I am unable to download any virus scanners, it won't let me install. I can only use firefox browser. I am unable to open Chrome at all and In Safari I can only type in the search bar, unable to click on anything in the pages. Then tons of ads come up.

MacBook Pro with Retina display, iOS 9.2.1

Posted on Mar 21, 2016 10:55 PM

Close

Q: My macbook pro 2012 has a virus or malware for sure. How can I scan it?

  • All replies
  • Helpful answers

  • by Niel,Apple recommended

    Niel Niel Mar 21, 2016 10:58 PM in response to sharona777
    Level 10 (314,528 points)
    Mac OS X
    Mar 21, 2016 10:58 PM in response to sharona777

    Click here and follow the instructions, or if there’s a type of adware not covered by them on the computer, these ones. If you'd rather not remove it manually, you can instead run MalwareBytes for Mac.


    MalwareBytes is a removal tool and doesn't stop adware or other malware from getting onto the computer. It shouldn’t be relied on to prevent future incidents; instead, avoid downloading software from sources other than the Mac App Store or the developer websites.


    (140836)

  • by Allan Eckert,Helpful

    Allan Eckert Allan Eckert Mar 22, 2016 9:26 AM in response to sharona777
    Level 9 (54,090 points)
    Desktops
    Mar 22, 2016 9:26 AM in response to sharona777

    Please download and install EtreCheck from http://etrecheck.com/

     

    Run it and post the report here.

  • by Linc Davis,

    Linc Davis Linc Davis Mar 22, 2016 9:16 AM in response to sharona777
    Level 10 (208,037 points)
    Applications
    Mar 22, 2016 9:16 AM in response to sharona777

    You may have installed ad-injection malware ("adware").

    Don't use any kind of "anti-virus" or "anti-malware" product on a Mac. There is never a need for it, and relying on it for protection makes you more vulnerable to attack, not less.

    Back up all data first.

    Some of the most common types of adware can be removed by following Apple's instructions. But before you follow those instructions, you can attempt an automatic removal.

    If you're not already running the latest version of OS X ("El Capitan"), updating or upgrading in the App Store may cause the adware to be removed automatically. If you're already running the latest version of El Capitan, you can nevertheless download the current updater from the Apple Support Downloads page and run it. Again, some kinds of malware will be removed—not all. There is no such thing as automatic removal of all possible malware, either by OS X or by third-party software. That's why you can't rely on software to protect you.

    If the malware is removed in your case, you'll still need to make changes to the way you use the computer to protect yourself from further attacks. Ask if you need guidance.

    If the malware is not removed automatically, and you can't remove it yourself by following Apple's instructions, see below.

    This easy procedure will detect any kind of adware that I know of. Deactivating it is a separate, and even easier, procedure.

    Some legitimate software is ad-supported and may display ads in its own windows or in a web browser while it's running. That's not malware and it may not show up. Also, some websites carry intrusive popup ads that may be mistaken for adware.

    If none of your web browsers is working well enough to carry out these instructions, restart the computer in safe mode. That will disable the malware temporarily.

    Step 1

    Please triple-click the line below on this page to select it, then copy the text to the Clipboard by pressing the key combination command-C:

    ~/Library/LaunchAgents

    In the Finder, select

              Go Go to Folder...

    from the menu bar and paste into the box that opens by pressing command-V. Press return. Either a folder named "LaunchAgents" will open, or you'll get a notice that the folder can't be found. If the folder isn't found, go to the next step.

    If the folder does open, press the key combination command-2 to select list view, if it's not already selected. Please don't skip this step.

    There should be a column in the Finder window headed Date Modified. Click that heading twice to sort the contents by date with the newest at the top. If necessary, enlarge the window so that all of the contents are showing.

    Follow the instructions in this support article under the heading "Take a screenshot of a window." An image file with a name beginning in "Screen Shot" should be saved to the Desktop. Open the screenshot and make sure it's readable. If not, capture a smaller part of the screen showing only what needs to be shown.

    Start a reply to this message. Drag the image file into the editing window to upload it. You can also include text in the reply.

    Leave the folder open for now.

    Step 2

    Do as in Step 1 with this line:

    /Library/LaunchAgents

    The folder that may open will have the same name, but is not the same, as the one in Step 1. As in that step, the folder may not exist.

    Step 3

    Repeat with this line:

    /Library/LaunchDaemons

    This time the folder will be named "LaunchDaemons."

    Step 4

    Open the Safari preferences window and select the Extensions tab. If any extensions are listed, post a screenshot. If there are no extensions, or if you can't launch Safari, skip this step.

    Step 5

    If you use the Firefox or Chrome browser, open its extension list and do as in Step 4.

  • by sharona777,

    sharona777 sharona777 Mar 22, 2016 9:26 AM in response to Allan Eckert
    Level 1 (0 points)
    Mar 22, 2016 9:26 AM in response to Allan Eckert

    I ran Malware Bytes which found some but the one you suggested found even more. I had to restore my system to an old backup. Apple chat was no help, they actually made things worse. EtreCheck found a file it was unfamiliar with and I'm not sure if I should delete it.

     

    com.iOSinstaller.updd.plist

     

    Is this malware too?

     

    Sorry I didn't post the report, I forgot to do it prior to removing the adware it found.

  • by Allan Eckert,

    Allan Eckert Allan Eckert Mar 22, 2016 1:21 PM in response to sharona777
    Level 9 (54,090 points)
    Desktops
    Mar 22, 2016 1:21 PM in response to sharona777

    Please post the complete EtreCheck report here.

  • by sharona777,

    sharona777 sharona777 Mar 23, 2016 9:58 AM in response to Allan Eckert
    Level 1 (0 points)
    Mar 23, 2016 9:58 AM in response to Allan Eckert

    EtreCheck version: 2.9.10 (261)

    Report generated 2016-03-23 12:53:42

    Download EtreCheck from https://etrecheck.com

    Runtime 1:38

    Performance: Excellent

     

    Click the [Support] links for help with non-Apple products.

    Click the [Details] links for more information about that line.

    Click the [Check files] link for help with unknown files.

     

    Problem: No problem - just checking

     

    Hardware Information:

        MacBook Pro (Retina, Mid 2012)

        [Technical Specifications] - [User Guide] - [Warranty & Service]

        MacBook Pro - model: MacBookPro10,1

        1 2.6 GHz Intel Core i7 CPU: 4-core

        8 GB RAM Not upgradeable

            BANK 0/DIMM0

                4 GB DDR3 1600 MHz ok

            BANK 1/DIMM0

                4 GB DDR3 1600 MHz ok

        Bluetooth: Good - Handoff/Airdrop2 supported

        Wireless:  en0: 802.11 a/b/g/n

        Battery: Health = Normal - Cycle count = 299

     

    Video Information:

        Intel HD Graphics 4000

            Color LCD 2880 x 1800

        NVIDIA GeForce GT 650M - VRAM: 1024 MB

     

    System Software:

        OS X El Capitan 10.11.4 (15E65) - Time since boot: about one day

     

    Disk Information:

        APPLE SSD SM512E disk0 : (500.28 GB) (Solid State - TRIM: Yes)

            EFI (disk0s1) <not mounted> : 210 MB

            Macintosh HD (disk0s2) / : 499.42 GB (183.73 GB free)

            Recovery HD (disk0s3) <not mounted>  [Recovery]: 650 MB

     

    USB Information:

        Apple Inc. FaceTime HD Camera (Built-in)

        Apple Inc. Apple Internal Keyboard / Trackpad

        Apple Inc. BRCM20702 Hub

            Apple Inc. Bluetooth USB Host Controller

     

    Thunderbolt Information:

        Apple Inc. thunderbolt_bus

     

    Gatekeeper:

        Mac App Store and identified developers

     

    Unknown Files:

        /Library/LaunchDaemons/com.iOSinstaller.updd.plist

        One unknown file found. [Check files]

     

    Kernel Extensions:

            /Applications/Toast 10 Titanium/Toast Titanium.app

        [not loaded]    com.roxio.BluRaySupport (1.1.6 - 2011-11-28) [Support]

        [not loaded]    com.roxio.TDIXController (1.7 - 2011-11-28) [Support]

     

            /System/Library/Extensions

        [not loaded]    com.deepseasoftware.driver.CDSDAudioCaptureSupport (1.3 - 2016-03-22) [Support]

        [loaded]    com.logmein.driver.LogMeInSoundDriver (4.1.60f87 - 2016-03-22) [Support]

        [loaded]    com.rim.driver.BlackBerryUSBDriverInt (0.0.67 - 2016-03-22) [Support]

        [not loaded]    com.rim.driver.BlackBerryUSBDriverVSP (0.0.67 - 2016-03-22) [Support]

     

    System Launch Agents:

        [not loaded]    7 Apple tasks

        [loaded]    150 Apple tasks

        [running]    81 Apple tasks

     

    System Launch Daemons:

        [not loaded]    43 Apple tasks

        [loaded]    154 Apple tasks

        [running]    92 Apple tasks

     

    Launch Agents:

        [not loaded]    com.adobe.AAM.Updater-1.0.plist (2015-10-03) [Support]

        [failed]    com.adobe.AdobeCreativeCloud.plist (2015-07-12) [Support]

        [running]    com.brother.LOGINserver.plist (2014-05-08) [Support]

        [loaded]    com.google.keystone.agent.plist (2016-03-22) [Support]

        [failed]    com.logmein.LMILaunchAgentFixer.plist (2016-03-22) [Support]

        [running]    com.logmein.logmeingui.plist (2016-03-22) [Support]

        [running]    com.logmein.logmeinguiagent.plist (2016-03-22) [Support]

        [not loaded]    com.logmein.logmeinguiagentatlogin.plist (2016-03-22) [Support]

        [loaded]    com.oracle.java.Java-Updater.plist (2013-09-01) [Support]

        [running]    com.rim.BBLaunchAgent.plist (2011-08-24) [Support]

        [running]    com.teamviewer.teamviewer.plist (2016-03-22) [Support]

        [running]    com.teamviewer.teamviewer_desktop.plist (2016-03-22) [Support]

     

    Launch Daemons:

        [running]    com.adobe.adobeupdatedaemon.plist (2015-10-03) [Support]

        [loaded]    com.adobe.agsservice.plist (2015-10-03) [Support]

        [loaded]    com.adobe.fpsaud.plist (2016-03-07) [Support]

        [loaded]    com.apple.aelwriter.plist

        [loaded]    com.google.keystone.daemon.plist (2016-03-22) [Support]

        [not loaded]    com.iOSinstaller.updd.plist (2015-07-01) [Support]

        [running]    com.logmein.logmeinserver.plist (2016-03-22) [Support]

        [loaded]    com.logmein.raupdate.plist (2012-08-01) [Support]

        [loaded]    com.malwarebytes.MBAMHelperTool.plist (2016-03-22) [Support]

        [loaded]    com.microsoft.office.licensing.helper.plist (2012-04-02) [Support]

        [loaded]    com.oracle.java.Helper-Tool.plist (2013-09-01) [Support]

        [loaded]    com.oracle.java.JavaUpdateHelper.plist (2015-08-01) [Support]

        [running]    com.rim.BBDaemon.plist (2011-08-24) [Support]

        [loaded]    com.rogueamoeba.hermes.plist (2009-02-09) [Support]

        [running]    com.teamviewer.teamviewer_service.plist (2016-03-22) [Support]

        [loaded]    com.tunnelbear.mac.tbeard.plist (2015-07-02) [Support]

     

    User Launch Agents:

        [loaded]    com.adobe.AAM.Updater-1.0.plist (2015-07-12) [Support]

        [loaded]    com.adobe.ARM.[...].plist (2012-01-27) [Support]

        [running]    com.amazon.cloud-player.plist (2013-11-27) [Support]

        [failed]    com.apple.MobileMeSyncClientAgent.plist

        [loaded]    com.apple.SafariBookmarksSyncer.plist

        [running]    com.netputing.airprintactivator.plist (2012-02-05) [Support]

     

    User Login Items:

        uHD-Agent    UNKNOWN  (missing value)

        iTunesHelper    Application  (/Applications/iTunes.app/Contents/MacOS/iTunesHelper.app)

        AdobeResourceSynchronizer    Application Hidden (/Applications/Adobe Reader.app/Contents/Support/AdobeResourceSynchronizer.app)

        iPhone Explorer    UNKNOWN  (missing value)

        GetBackupAgent    Application  (/Applications/Toast 10 Titanium/Get Backup 2 RE.app/Contents/Resources/GetBackupAgent.app)

        Wondershare SafeEraser Helper    Application  (~/Library/Application Support/com.wondershare.SafeEraser/Wondershare SafeEraser Helper.app)

        BlackBerry Device Manager    Application Hidden (/Library/Application Support/BlackBerry/BlackBerry Device Manager.app)

        HP Scheduler    Application  (/Library/Application Support/Hewlett-Packard/Software Update/HP Scheduler.app)

     

    Other Apps:

        [running]    com.adobe.PDApp.AAMUpdatesNotifier.74912.5EB9F721-2A68-4E38-B7E8-2FEF4FB8D886

        [running]    com.brother.utility.NETserver.135072

        [running]    com.brother.utility.USBserver.134432

        [running]    com.etresoft.EtreCheck.182112

        [running]    com.iOSinstaller.updd

        [running]    com.wondershare.Wondershare-SafeEraser-Helper.132512

        [loaded]    397 Apple tasks

        [running]    219 Apple tasks

     

    Internet Plug-ins:

        AdobePDFViewerNPAPI: 10.1.15 (2015-07-25) [Support]

        Flash Player: 21.0.0.182 - SDK 10.6 (2016-03-22) Outdated! Update

        OfficeLiveBrowserPlugin: 12.3.2 (2012-01-26) [Support]

        AdobePDFViewer: 10.1.15 (2015-07-25) [Support]

        LogMeInSafari32: 1.0.660 (2012-03-20) [Support]

        Unity Web Player: UnityPlayer version 4.5.0f6 - SDK 10.6 (2014-06-06) [Support]

        googletalkbrowserplugin: 5.41.3.0 - SDK 10.8 (2015-12-11) [Support]

        iPhotoPhotocast: 7.0 (2010-03-30)

        DirectorShockwave: 11.0.0r465 (2008-08-01) [Support]

        QuickTime Plugin: 7.7.3 (2016-03-22)

        FlashPlayer-10.6: 21.0.0.182 - SDK 10.6 (2016-03-22) [Support]

        CitrixICAClientPlugIn: 11.0.0 (2012-02-16) [Support]

        AdobeAAMDetect: 3.0.0.0 - SDK 10.9 (2015-10-03) [Support]

        AmazonMP3DownloaderPlugin: AmazonMP3DownloaderPlugin 1.0.17 - SDK 10.4 (2012-04-13) [Support]

        GarminGpsControl: 2.9.2.0 Release (2010-03-25) [Support]

        LogMeInSafari64: 1.0.660 (2012-03-20) [Support]

        Silverlight: 5.1.30514.0 - SDK 10.6 (2014-10-31) [Support]

        CouponPrinter-FireFox_v2: 1.1.10 - SDK 10.5 (2013-08-05) [Support]

        LogMeIn: 1.0.660 (2012-06-03) [Support]

        CoolirisWebKitPlugin: Unknown (2009-07-12) [Support]

        Google Earth Web Plug-in: 6.1 (2011-10-17) [Support]

        Default Browser: 601 - SDK 10.11 (2016-03-22)

        Flip4Mac WMV Plugin: 2.3.4.1 (2010-06-15) [Support]

        o1dbrowserplugin: 5.41.3.0 - SDK 10.8 (2016-03-22) [Support]

        SharePointBrowserPlugin: 14.2.0 - SDK 10.6 (2012-07-17) [Support]

        JavaAppletPlugin: Java 8 Update 51 (2015-08-01) Check version

        AmazonMP3DownloaderPlugin101736: AmazonMP3DownloaderPlugin 1.0.17 - SDK 10.4 (2012-12-04) [Support]

     

    User internet Plug-ins:

        BlueStacks Install Detector: Unknown

        WebEx64: 1.0 - SDK 10.5 (2012-03-20) [Support]

        WebEx: 1.0 (2010-11-22) [Support]

     

    Safari Extensions:

        Ka-Block! (2016-03-22)

        Adblock Plus (2016-03-22)

        Wipr (2016-03-22)

        Keeper® Password Manager & Digital Vault (2015-08-21)

     

    3rd Party Preference Panes:

        Citrix online plug-in (2009-09-11) [Support]

        Flash Player (2016-03-07) [Support]

        Flip4Mac WMV (2010-06-15) [Support]

        Java (2015-08-01) [Support]

        Perian (2010-03-18) [Support]

     

    Time Machine:

        Skip System Files: NO

        Auto backup: YES

        Volumes being backed up:

            Macintosh HD: Disk size: 499.42 GB Disk used: 315.69 GB

        Destinations:

            G-DRIVE mobile [Local]

            Total size: 999.86 GB

            Total number of backups: 12

            Oldest backup: 7/21/12, 10:27 AM

            Last backup: 3/22/16, 2:33 PM

            Size of backup disk: Adequate

                Backup size 999.86 GB > (Disk used 315.69 GB X 3)

     

    Top Processes by CPU:

             4%    WindowServer

             2%    kernel_task

             2%    fontd

             1%    Messages

             0%    BBLaunchAgent

     

    Top Processes by Memory:

        873 MB    kernel_task

        328 MB    Safari

        229 MB    ocspd

        213 MB    mdworker(15)

        147 MB    Messages

     

    Virtual Memory Information:

        1.82 GB    Free RAM

        6.17 GB    Used RAM (1.53 GB Cached)

        743 MB    Swap Used

     

    Diagnostics Information:

        Mar 22, 2016, 01:56:22 PM    ~/Library/Logs/DiagnosticReports/Creative Cloud_2016-03-22-135622_[redacted].crash

            com.adobe.acc.AdobeCreativeCloud - /Applications/Utilities/Adobe Creative Cloud/*/Creative Cloud.app/Contents/MacOS/Creative Cloud

        Mar 22, 2016, 01:55:33 PM    Self test - passed

        Mar 22, 2016, 01:48:24 PM    ~/Library/Logs/DiagnosticReports/Finder_2016-03-22-134824_[redacted].crash

            com.apple.finder - /System/Library/CoreServices/Finder.app/Contents/MacOS/Finder

        Mar 22, 2016, 11:41:15 AM    ~/Library/Logs/DiagnosticReports/Creative Cloud_2016-03-22-114115_[redacted].crash

        Mar 22, 2016, 11:32:38 AM    ~/Library/Logs/DiagnosticReports/Creative Cloud_2016-03-22-113238_[redacted].crash

        Mar 22, 2016, 10:53:33 AM    ~/Library/Logs/DiagnosticReports/Creative Cloud_2016-03-22-105333_[redacted].crash

  • by thomas_r.,

    thomas_r. thomas_r. Mar 24, 2016 5:51 AM in response to sharona777
    Level 7 (30,944 points)
    Mac OS X
    Mar 24, 2016 5:51 AM in response to sharona777

    sharona777 wrote:

     

    com.iOSinstaller.updd.plist

     

    Is this malware too?

     

    That is part of Popcorn Time, which is designed to install apps from outside the App Store on iOS devices (ie, iPhones or iPads) without jailbreaking. It is often used to install pirated iOS software. It should not be used, and is probably a gateway to iOS malware (and possibly Mac malware), but is not in itself malware.