malware or virus?

EtreCheck version: 2.9.12 (265)

Report generated 2016-05-08 21:55:47

Download EtreCheck from https://etrecheck.com

Runtime 3:49

Performance: Good


Click the [Support] links for help with non-Apple products.

Click the [Details] links for more information about that line.

Click the [Remove] links to remove adware.

Click the [Check files] link for help with unknown files.


Problem: No problem - just checking


Hardware Information:

MacBook Pro (17-inch, Mid 2010)

[Technical Specifications] - [User Guide] - [Warranty & Service]

MacBook Pro - model: MacBookPro6,1

1 2.66 GHz Intel Core i7 CPU: 2-core

8 GB RAM Upgradeable - [Instructions]

BANK 0/DIMM0

4 GB DDR3 1067 MHz ok

BANK 1/DIMM0

4 GB DDR3 1067 MHz ok

Bluetooth: Old - Handoff/Airdrop2 not supported

Wireless: en1: 802.11 a/b/g/n

Battery: Health = Replace Soon - Cycle count = 1317


Video Information:

Intel HD Graphics

NVIDIA GeForce GT 330M - VRAM: 512 MB

Color LCD 1920 x 1200


System Software:

OS X Yosemite 10.10.5 (14F27) - Time since boot: about 2 days


Disk Information:

Hitachi HTS545050B9SA02 disk0 : (500.11 GB) (Rotational)

EFI (disk0s1) <not mounted> : 210 MB

Recovery HD (disk0s3) <not mounted> [Recovery]: 650 MB

HD (disk1) / : 498.88 GB (67.81 GB free)

Core Storage: disk0s2 499.25 GB Online


MATSHITADVD-R UJ-898 ()


USB Information:

Apple Inc. BRCM2070 Hub

Apple Inc. Bluetooth USB Host Controller

Apple Inc. Apple Internal Keyboard / Trackpad

Apple Inc. iPhone

Apple Inc. Built-in iSight

Apple Computer, Inc. IR Receiver


Configuration files:

/etc/launchd.conf - File exists but not expected

/etc/hosts - Count: 15


Gatekeeper:

Mac App Store and identified developers


Adware:

/Applications/InstallMac

/Library/LaunchAgents/com.EasyShopper.agent.plist

/Library/LaunchAgents/com.SoftwareUpdater.agent.plist

/Library/LaunchAgents/com.genieo.engine.plist

/Library/LaunchDaemons/com.droopingly.net-preferences.plist

/Library/LaunchDaemons/com.potwhiskyUpd.plist

~/Library/LaunchAgents/InstallMac.download.plist

~/Library/LaunchAgents/InstallMac.ltvbit.plist

~/Library/LaunchAgents/InstallMac.update.plist

~/Library/LaunchAgents/com.EasyShopper.agent.plist

~/Library/LaunchAgents/com.SoftwareUpdater.agent.plist

~/Library/LaunchAgents/com.codecm.uploader.plist

/private/etc/launchd.conf

/usr/lib/libgenkit.dylib

/usr/lib/libgenkitsa.dylib

15 adware files found. [Remove]


Unknown Files:

/Library/LaunchDaemons/com.vigimac.plist

/bin/sh /Library/VigiMac/trace.sh

One unknown file found. [Check files]


Kernel Extensions:

/Applications/Toast 10 Titanium/Toast Titanium.app

[not loaded] com.roxio.BluRaySupport (1.1.6 - 2015-08-21) [Support]


/Library/Application Support/Hideman/daemon

[not loaded] net.tunnelblick.tap (20111101 (Tunnelblick build 2891.2917) - 2012-11-07) [Support]

[not loaded] net.tunnelblick.tun (20111101 (Tunnelblick build 2891.2917) - 2012-11-07) [Support]


/Library/Extensions

[loaded] com.avira.kext.FileAccessControl (1.2.2 - SDK 10.9 - 2016-05-07) [Support]


/System/Library/Extensions

[loaded] com.Cycling74.driver.Soundflower (1.6.6 - SDK 10.6 - 2016-05-07) [Support]

[not loaded] com.echofx.videoglide.kext (1.4.8 - 2016-05-07) [Support]

[not loaded] com.hzsystems.driver.CDSDAudioCaptureSupport (1.5 - 2016-05-07) [Support]

[not loaded] com.paceap.kext.PACESupport (5.7.2b8 - 2016-05-07) [Support]

[not loaded] com.paceap.kext.PACESupport2 (5.7.2b8 - 2016-05-07) [Support]

[not loaded] com.paceap.kext.pacesupport.master (5.7.2b8 - 2016-05-07) [Support]

[not loaded] com.pctools.iantivirus.kfs (1.0.1 - 2016-05-07) [Support]

[not loaded] com.red.driver.redrocket (2.1.23 - 2016-05-07) [Support]

[not loaded] com.sony.driver.sxsexpressdrivers (1.0.2d006 - SDK 10.6 - 2016-05-07) [Support]

[not loaded] com.sony.driver.sxsus10drivers (1.0.2d006 - SDK 10.6 - 2016-05-07) [Support]

[not loaded] com.sony.filesystems.sxsudf_fs (1.0.2d006 - SDK 10.6 - 2016-05-07) [Support]


/System/Library/Extensions/PACESupportFamily.kext/Contents/PlugIns

[not loaded] com.paceap.kext.pacesupport.leopard (5.7.2b8 - 2009-07-15) [Support]

[not loaded] com.paceap.kext.pacesupport.panther (5.7.2b8 - 2009-07-15) [Support]

[loaded] com.paceap.kext.pacesupport.snowleopard (5.7.2b8 - 2009-07-15) [Support]

[not loaded] com.paceap.kext.pacesupport.tiger (5.7.2b8 - 2009-07-15) [Support]


/System/Library/Extensions/VideoGlide.kext/Contents/PlugIns

[not loaded] com.echofx.videoglide.kext.audio (1.4.8 - 2011-06-09) [Support]

[not loaded] com.echofx.videoglide.kext.noseize.appleusbaudio (1.4.8 - 2011-06-09) [Support]

[not loaded] com.echofx.videoglide.kext.noseize.classic (1.4.8 - 2011-06-09) [Support]


~/Library/Services/ToastIt.service/Contents/MacOS

[not loaded] com.roxio.TDIXController (2.0 - 2011-04-02) [Support]


Startup Items:

PACESupport: Path: /Library/StartupItems/PACESupport

Sudochmod: Path: /Library/StartupItems/Sudochmod

VideoGlide Startup: Path: /Library/StartupItems/VideoGlide Startup

Startup items are obsolete in OS X Yosemite


System Launch Agents:

[not loaded] 5 Apple tasks

[loaded] 145 Apple tasks

[running] 61 Apple tasks


System Launch Daemons:

[not loaded] 46 Apple tasks

[loaded] 130 Apple tasks

[running] 87 Apple tasks


Launch Agents:

[running] com.EasyShopper.agent.plist (2016-04-29) Adware! [Remove]

/Applications/EasyShopper/EasyShopper

[loaded] com.SoftwareUpdater.agent.plist (2016-04-29) Adware! [Remove]

/Applications/SoftwareUpdater/SoftwareUpdater

[not loaded] com.adobe.AAM.Updater-1.0.plist (2012-10-27) [Support]

[loaded] com.avira.antivirus.general.agent.plist (2016-01-21) [Support]

[loaded] com.avira.antivirus.ipm.ui.plist (2016-01-21) [Support]

[loaded] com.avira.antivirus.notifications.agent.plist (2016-01-21) [Support]

[loaded] com.avira.antivirus.odscan.default.plist (2016-05-07) [Support]

[loaded] com.avira.antivirus.scheduler.agent.plist (2016-01-21) [Support]

[running] com.avira.antivirus.systray.plist (2016-01-21) [Support]

[loaded] com.avira.antivirus.telemetry.agent.plist (2016-01-21) [Support]

[loaded] com.avira.antivirus.update.default.plist (2016-01-21) [Support]

[running] com.avira.helper.avstats.plist (2016-01-21) [Support]

[running] com.canon.SPPHelper.plist (2012-01-23) [Support]

[loaded] com.divx.dms.agent.plist (2015-09-04) [Support]

[loaded] com.divx.update.agent.plist (2015-06-15) [Support]

[failed] com.genieo.engine.plist (2012-07-20) Adware! [Remove]

[loaded] com.google.keystone.agent.plist (2016-03-03) [Support]

[not loaded] com.teamviewer.teamviewer.plist (2014-08-08) [Support]

[not loaded] com.teamviewer.teamviewer_desktop.plist (2014-08-22) [Support]

[running] jp.co.canon.SELPHYCP.BG.plist (2013-11-21) [Support]


Launch Daemons:

[loaded] PACESupport.plist (2009-07-14) [Support]

[loaded] com.adobe.SwitchBoard.plist (2012-04-19) [Support]

[failed] com.adobe.fpsaud.plist (2016-04-16) [Support]

[loaded] com.adobe.versioncueCS3.plist (2010-09-06) [Support]

[loaded] com.apple.aelwriter.plist

[running] com.apple.qmaster.qmasterd.plist

[not loaded] com.apple.quoroden.plist (2016-04-29) - Executable not found!

[loaded] com.autodesk.adlm.plist (2010-11-22) [Support]

[failed] com.autodesk.backburner_manager.plist (2010-03-25) [Support]

[running] com.autodesk.backburner_server.plist (2010-03-25) [Support]

[loaded] com.autodesk.backburner_start.plist (2010-03-25) [Support]

[running] com.autodesk.dl_mpd.plist (2010-11-22) [Support]

[running] com.autodesk.sw_bwmgr.plist (2010-11-23) [Support]

[running] com.autodesk.sw_dbd.plist (2010-11-23) [Support]

[running] com.autodesk.sw_ifffs.plist (2010-12-07) [Support]

[running] com.autodesk.sw_probed.plist (2010-11-23) [Support]

[failed] com.autodesk.sw_server.plist (2010-11-23) [Support]

[loaded] com.autodesk.sw_start.plist (2010-11-23) [Support]

[failed] com.autodesk.wiretapgateway.plist (2010-11-23) [Support]

[loaded] com.avid.AMCUninstaller.plist (2012-03-14) [Support]

[loaded] com.avira.antivirus.dbcleaner.plist (2016-01-21) [Support]

[loaded] com.avira.antivirus.ipm.loader.plist (2016-01-21) [Support]

[running] com.avira.helper.watchdox.plist (2016-01-21) [Support]

[running] com.droopingly.net-preferences.plist (2016-04-29) Adware! [Remove]

/etc/change_net_settings.sh

[loaded] com.google.keystone.daemon.plist (2016-03-03) [Support]

[loaded] com.microsoft.office.licensing.helper.plist (2010-08-25) [Support]

[loaded] com.noiseindustries.FxFactory.AE.plist (2012-04-29) [Support]

[loaded] com.potwhiskyUpd.plist (2016-04-29) Adware! [Remove]

/etc/st-up.sh

[not loaded] com.teamviewer.teamviewer_service.plist (2014-08-08) [Support]

[loaded] com.torch.update.agent.plist (2014-07-10) [Support]

[loaded] com.vigimac.plist (2008-06-21) [Support]

[loaded] org.tcpdump.chmod_bpf.plist (2008-06-05) [Support]


User Launch Agents:

[loaded] InstallMac.download.plist (2015-06-14) Adware! [Remove]

[failed] InstallMac.ltvbit.plist (2015-06-14) Adware! [Remove]

[running] InstallMac.update.plist (2015-06-14) Adware! [Remove]

[running] com.EasyShopper.agent.plist (2016-04-29) Adware! [Remove]

/Applications/EasyShopper/EasyShopper

[loaded] com.SoftwareUpdater.agent.plist (2016-04-29) Adware! [Remove]

/Applications/SoftwareUpdater/SoftwareUpdater

[loaded] com.adobe.AAM.Updater-1.0.plist (2012-04-24) [Support]

[loaded] com.adobe.ARM.[...].plist (2015-08-24) [Support]

[loaded] com.adobe.ARM.[...].plist (2016-01-03) [Support]

[loaded] com.apple.FolderActions.folders.plist

[failed] com.codecm.uploader.plist (2012-04-22) Adware! [Remove]

[loaded] com.digitalrebellion.PreferenceManagerAutoSave.plist (2013-07-29) [Support]

[loaded] com.digitalrebellion.SoftwareUpdateAutoCheck.plist (2013-07-29) [Support]

[loaded] com.macpaw.CleanMyMac.helperTool.plist (2011-04-02) [Support]

[running] com.microsoft.LaunchAgent.SyncServicesAgent.plist (2015-06-15) [Support]

[running] com.nchsoftware.expressinvoice.agent.plist (2012-04-03) [Support]


User Login Items:

RED Watchdog Application (/Applications/REDCINE-X Professional/Utilities/RED Watchdog.app)

RealPlayer Downloader Agent Application (~/Library/Application Support/RealNetworks/RealPlayer Downloader Agent.app)

SPanel Application (/Library/Printers/SPanel/Samsung/SPanel.app)


Other Apps:

[running] com.Samsung.SPanel.93468

[running] com.adobe.PDApp.AAMUpdatesNotifier.99148.4954E88C-F6AA-4A04-AA5E-5380765E86F7

[running] com.microsoft.outlook.database_daemon.67340

[running] com.realnetworks.realplayerdownloaderagent.82392

[running] com.red.RED-Watchdog.76712

[running] jp.co.canon.cijscannerregister.98296

[loaded] 391 Apple tasks

[running] 195 Apple tasks


Internet Plug-ins:

DirectorShockwave: 11.6.8r638 (2012-10-04) [Support]

Google Earth Web Plug-in: 6.0 (2011-05-18) [Support]

Default Browser: 600 - SDK 10.10 (2015-07-17)

Flip4Mac WMV Plugin: 2.4.4.2 (2012-08-28) [Support]

OVSHelper: 1.1 (2015-12-05) [Support]

RealPlayer Plugin: Unknown (2013-07-05) [Support]

AdobePDFViewerNPAPI: 11.0.12 - SDK 10.6 (2015-09-17) [Support]

FlashPlayer-10.6: 21.0.0.226 - SDK 10.6 (2016-04-29) [Support]

DivX Web Player: 3.4.1.14 - SDK 10.10 (2015-11-05) [Support]

Silverlight: 5.1.20913.0 - SDK 10.6 (2013-11-10) [Support]

Flash Player: 21.0.0.226 - SDK 10.6 (2016-04-29) [Support]

iPhotoPhotocast: 7.0 (2010-09-13)

QuickTime Plugin: 7.7.3 (2015-08-15)

SharePointBrowserPlugin: 14.0.0 (2010-08-25) [Support]

AdobePDFViewer: 11.0.12 - SDK 10.6 (2015-09-17) [Support]

SiteAdvisor: 2.0 - SDK 10.1 (2013-10-08) [Support]

Unity Web Player: UnityPlayer version 4.5.4f1 - SDK 10.6 (2014-09-13) [Support]

JavaAppletPlugin: 15.0.1 - SDK 10.7 (2015-08-25) Check version


Safari Extensions:

Facebook Cleaner - Sonny Fazio - http://sonstermedia.com (2012-01-18)

Better Facebook - Matt Kruse - http://BetterFacebook.net (2012-01-18)

SiteAdvisor - McAfee - http://www.siteadvisor.com (2013-10-17)

iTube Studio - iSkysoft Studio - http://www.iskysoft.com (2013-07-02)

clea.nr Videos - A Cleaner Internet - http://clea.nr/ (2012-01-18)

Turn Off the Lights - Stefan vd - http://www.stefanvd.net (2012-01-18)

AdBlock - Michael Gundlach - http://safariadblock.com (2012-01-18)

Adblock Plus - Eyeo GmbH - https://adblockplus.org/ (2015-06-15)


Audio Plug-ins:

DVCPROHDAudio: 1.3.2 (2012-06-23)


3rd Party Preference Panes:

Adobe Version Cue CS3 (2010-09-06) [Support]

Flash Player (2016-04-16) [Support]

Flip4Mac WMV (2012-05-16) [Support]

Growl (2014-06-25) [Support]

MacFUSE (2008-12-19) [Support]

Perian (2011-07-24) [Support]

REDcode (2015-08-17) [Support]


Time Machine:

Skip System Files: NO

Mobile backups: ON

Auto backup: YES

Volumes being backed up:

HD: Disk size: 498.88 GB Disk used: 431.06 GB

Destinations:

Time Machine Backups [Local]

Total size: 999.12 GB

Total number of backups: 3

Oldest backup: 8/30/15, 9:19 AM

Last backup: 2/5/16, 3:50 AM

Size of backup disk: Too small

Backup size 999.12 GB < (Disk used 431.06 GB X 3)


Top Processes by CPU:

30% WindowServer

15% osascript

4% kernel_task

4% Dock

3% hidd


Top Processes by Memory:

730 MB kernel_task

426 MB savapi

426 MB com.apple.WebKit.WebContent(2)

131 MB WindowServer

115 MB Safari


Virtual Memory Information:

1.84 GB Free RAM

6.16 GB Used RAM (2.49 GB Cached)

11 MB Swap Used


Diagnostics Information:

May 8, 2016, 03:15:56 AM /Library/Logs/DiagnosticReports/wiretapgateway_2016-05-08-031556_[redacted].cra sh

/usr/discreet/wiretapgateway/wiretapgateway

May 8, 2016, 03:15:41 AM /Library/Logs/DiagnosticReports/backburnerManager_2016-05-08-031541_[redacted]. crash

/usr/discreet/backburner/backburnerManager

May 7, 2016, 01:51:39 AM /Library/Logs/DiagnosticReports/lmgrd_2016-05-07-015139_[redacted].crash

/usr/local/flexnetserver/lmgrd

May 7, 2016, 01:50:40 AM Self test - passed

May 7, 2016, 01:49:13 AM ~/Library/Logs/DiagnosticReports/com.apple.WebKit.Plugin.64_2016-05-07-014913_[ redacted].crash

/System/Library/Frameworks/WebKit.framework/Versions/A/XPCServices/com.apple.We bKit.Plugin.64.xpc/Contents/MacOS/com.apple.WebKit.Plugin.64

May 5, 2016, 10:26:21 PM /Library/Logs/DiagnosticReports/AdobeAcrobat_2016-05-05-222621_[redacted].hang

/Applications/Adobe Acrobat X Pro/Adobe Acrobat Pro.app/Contents/MacOS/AdobeAcrobat

Posted on May 8, 2016 12:01 PM

Reply
3 replies

May 8, 2016 6:47 PM in response to petibozo

Yes, you have lots of adware! Uninstall Avira AV you don't need any AV software and it does you more harm than good. Use the "remove" to get rid of the adware.

You may want to follow up with MalwareBytes. MalwareBytes is used by Apple Geniuses at Apple Store Genius Bars. It is also recommended by Apple Community Hosts here in the forums, as well as by Apple Telephone Support agents.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

malware or virus?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.