How do I remove Trovi after doing the obvious
I acquired Trovi about a week ago. It quickly infected Firefox, Chrome, and Safari. I ran Adware Medic which claimed to move the files to Trash and emptied the Trash. Still present. I then got Adware Doctor and MalwareBytes Anti-Malware, ran them with no fix. I went to Linc Davis's site and followed his advice, found no extensions in any of the browsers, found no obvious files in /Library/LaunchAgents, /Library/LaunchDaemons, or ~/Library/LaunchAgents. I did find one file installed as root and removed it. The file was
~/Library/Application\ Support/Firefox/Profiles/15den4ak.default-1450036030435/searchplugins/
with contents
<SearchPlugin xmlns="http://www.mozilla.org/2006/browser/search/">
<ShortName>Trovi</ShortName>
<Description>Trovi</Description>
<InputEncoding>UTF-8</InputEncoding>
<Image width="16" height="16">data:x-icon;base64,AAABAAEAEBAAAAAAIABoBAAAFgAAACgAAAAQAAAAIAAAAAEA IAAAAAAAQAQAAAAAAAAAAAAAAAAAAAAAAAD///8B////Af///wH///8B////Af///wH///8B////Af// /wH///8B////Af///wH///8B////Af///wH///8B////Af///wH///8B////Af///wH///8B////Af// /wH///8B////Af///wH///8B////Af///wH///8B////Af///wH///8B////AbuEtUWcTpWfjjWGu55U mI/Bj7wD////AapnpHuON4exqGOiieTO4Sf///8B////Af///wH///8B////AbN1rHmEKHvrgx94/5Eq gv+EGHj/rm6pa7V6r1eGHnz/jCeA/38adf+VQYzNv4q5Tf///wH///8BwIu6V4stgNNuAGP/fxRw/5wn g/+hMYP/njiA/69po/usZKD5mS58/6EuhP+aJ4P/dQNn/2wAYf+vbaefzaTIG61rpqdhAFT/gBh1/6Er h/+bLXn/lEtr/6FffP+pYpj/qWKX/6FffP+VSG3/miN3/6Axif98FnL/WgBM/6NXmrP///8BsXSrYZ41 ifuaH3r/k0pr/5ZTb/+aTYT/dwht/3sQcf+dVYb/kk5p/5ZIb/+eIX//kyqB+axxqZe9ibgp////Adai yCmWFHf/lSd1/5JNaf+lZYb/jDF9/3IAaf95C3H/jzZ9/55ae/+VT2z/lSF1/5sigPP///8B////Af// /wGxVJrVigBr/5w3fP+UTmr/nlh9/5I+f/93BnD/fA50/5RCfv+bVHn/lU9t/5Mgc/95AFT/u2qno/// /wH///8BwHeuW7NPn22rXI+tkEhk/5VIcv+TQnT/jjOB/481gP+WSHj/lUtz/4xAYP+uWpXLt2CjpcqM u33///8B////Af///wH///8Bsn6VQX0kS/+NPWb/k0R0/5VHdv+URnX/jjxt/4MsVv+DL1X/4svZKf// /wH///8B////Af///wH///8B////AbySo1OdWXnnuIece6Rhis2FK2H/gyde/72Lqausc4yvmVJ0/f7/ /Q3///8B////Af///wH///8B////Af///wHWuMYN07XDDf///wHPq8Ezhy5l/5NDdPX///8B////Acml tjHHo7QH////Af///wH///8B////Af///wH///8B////Af///wH///8B////AbF3mpnYvM5d////Af// /wH///8B////Af///wH///8B////Af///wH///8B////Af///wH///8B////Af///wH///8B////Af// /wH///8B////Af///wH///8B////Af///wH///8B////Af///wH///8B////Af///wH///8B////Af// /wH///8B////Af///wH///8B////Af///wH///8BAAD//wAA//8AAP//AAD//wAA//8AAP//AAD//wAA //8AAP//AAD//wAA//8AAP//AAD//wAA//8AAP//AAD//w==</Image>
<Url type="application/x-suggestions+json" method="GET" template="http://suggestqueries.google.com/complete/search?output=firefox&client=firef ox&qu={searchTerms}" />
<Url type="text/html" method="GET" template="http://www.trovi.com/">
<Param name="q" value="{searchTerms}" />
</Url>
<SearchForm>http%3A%2F%2Fwww.trovi.com%2FResults.aspx%3Fn%3DDP2791%26searchsource%3D58%26UM%3D8%26gd%3DSY1000250/</Sea rchForm>
</SearchPlugin>
Trove was still active. I remove Player x, Trovi was still active. Removed Firefox and Chrome in the hope that their infection was causing problems for Safari. Safari still has Trovi.
Symptoms in Safari. Trying to show extensions in the browser window yields an empty list. Setting the homepage to something other than trovi temporarily works, but after one or two restarts trovi reappear as the home page, If I set it so that the startup and new tab pages are empty after a bit the window will close and then reappear with trovi set as the home page and start and new tabs set to display the homepage. Turning off Javascript blocks its ads, but makes other things of course impossible and does nothing to avoid trovi becoming the home page.
I have also been having request on startup for the login keychain by
- Identityservicesd
- comm.apple.icloudHelper.xpc
- AddressBookSourceSync
- accountsd
- MessagesAgent
- and CommCenter
FWIW I have OS X El Capitain 10.11.4
EtreCheck reports
EtreCheck version: 2.9.12 (265)
Report generated 2016-05-13 22:29:08
Download EtreCheck from https://etrecheck.com
Runtime 1:33
Performance: Excellent
Click the [Support] links for help with non-Apple products.
Click the [Details] links for more information about that line.
Check Apple signatures: Enabled
Problem: Other problem
Hardware Information:ⓘ
MacBook Pro (Retina, 15-inch, Early 2013)
[Technical Specifications] - [User Guide] - [Warranty & Service]
MacBook Pro - model: MacBookPro10,1
1 2.4 GHz Intel Core i7 CPU: 4-core
8 GB RAM Not upgradeable
BANK 0/DIMM0
4 GB DDR3 1600 MHz ok
BANK 1/DIMM0
4 GB DDR3 1600 MHz ok
Bluetooth: Good - Handoff/Airdrop2 supported
Wireless: en0: 802.11 a/b/g/n
Battery: Health = Normal - Cycle count = 137
Video Information:ⓘ
Intel HD Graphics 4000
Color LCD 2880 x 1800
NVIDIA GeForce GT 650M - VRAM: 1024 MB
System Software:ⓘ
OS X El Capitan 10.11.4 (15E65) - Time since boot: about one hour
Disk Information:ⓘ
APPLE SSD SD256E disk0 : (251 GB) (Solid State - TRIM: Yes)
EFI (disk0s1) <not mounted> : 210 MB
Recovery HD (disk0s3) <not mounted> [Recovery]: 650 MB
Macintosh HD (disk1) / : 249.77 GB (29.73 GB free)
Core Storage: disk0s2 250.14 GB Online
USB Information:ⓘ
Apple Inc. FaceTime HD Camera (Built-in)
Apple Inc. Apple Internal Keyboard / Trackpad
Apple Inc. BRCM20702 Hub
Apple Inc. Bluetooth USB Host Controller
Thunderbolt Information:ⓘ
Apple Inc. thunderbolt_bus
Gatekeeper:ⓘ
Mac App Store and identified developers
Kernel Extensions:ⓘ
/Library/Extensions
[not loaded] com.BlackBerry.driver.USBCDCNCM (1.0.6 - SDK 10.7 - 2016-04-05) [Support]
[loaded] com.rim.driver.BlackBerryUSBDriverInt (2.2.7 - SDK 10.7 - 2016-04-05) [Support]
[loaded] com.rim.driver.BlackBerryVirtualPrivateNetwork (1.0.18 - SDK 10.8 - 2016-04-05) [Support]
Startup Items:ⓘ
daemonic-dbus: Path: /Library/StartupItems/daemonic-dbus
Startup items are obsolete in OS X Yosemite
System Launch Agents:ⓘ
[not loaded] 8 Apple tasks
[loaded] 154 Apple tasks
[running] 76 Apple tasks
System Launch Daemons:ⓘ
[not loaded] 44 Apple tasks
[loaded] 158 Apple tasks
[running] 88 Apple tasks
Launch Agents:ⓘ
[running] com.mozy.status.plist (2016-03-13) [Support]
[loaded] com.oracle.java.Java-Updater.plist (2014-01-01) [Support]
[running] com.rim.BBLaunchAgent.plist (2013-11-08) [Support]
[running] com.rim.PeerManager.plist (2013-11-08) [Support]
[running] com.rim.blackberrylink.BlackBerry-Link-Helper-Agent.plist (2013-11-08) [Support]
[loaded] org.macosforge.xquartz.startx.plist (2015-10-16) [Support]
Launch Daemons:ⓘ
[failed] com.adobe.fpsaud.plist (2016-04-15) [Support]
[not loaded] com.apple.nysgar.plist (2016-05-08) - Executable not found!
[loaded] com.barebones.authd.plist (2012-11-22) [Support]
[loaded] com.barebones.textwrangler.plist (2010-01-30) [Support]
[loaded] com.github.GitHub.GHInstallCLI.plist (2013-04-06) [Support]
[loaded] com.malwarebytes.MBAMHelperTool.plist (2016-05-09) [Support]
[loaded] com.microsoft.office.licensing.helper.plist (2012-04-02) [Support]
[running] com.mozy.backup.plist (2016-03-13) [Support]
[loaded] com.oracle.java.Helper-Tool.plist (2014-01-01) [Support]
[running] com.rim.BBDaemon.plist (2013-11-08) [Support]
[not loaded] com.rim.nkehelper.plist (2013-11-08) [Support]
[running] com.rim.tunmgr.plist (2013-11-08) [Support]
[loaded] org.macosforge.xquartz.privileged_startx.plist (2015-10-16) [Support]
User Launch Agents:ⓘ
[failed] com.adobe.ARM.[...].plist (2009-10-22) [Support]
[loaded] com.google.keystone.agent.plist (2016-05-11) [Support]
User Login Items:ⓘ
iSyncr Application (/Applications/iSyncr.app)
Skype Application (/Applications/Skype.app)
Other Apps:ⓘ
[running] com.JRTStudio.iSyncrWiFi.58272
[running] com.apple.nysgar
[running] com.etresoft.EtreCheck.268512
[loaded] com.excitedpixel.breaktimelauncher
[running] com.skype.skype.224352
[loaded] org.finkproject.dbus-session
[loaded] 410 Apple tasks
[running] 191 Apple tasks
Internet Plug-ins:ⓘ
Default Browser: 601 - SDK 10.11 (2016-03-22)
Flip4Mac WMV Plugin: 3.1.0.24 - SDK 10.8 (2013-04-06) [Support]
OfficeLiveBrowserPlugin: 12.3.6 (2013-03-20) [Support]
Silverlight: 5.1.10411.0 - SDK 10.6 (2013-04-06) [Support]
FlashPlayer-10.6: 21.0.0.226 - SDK 10.6 (2016-05-03) [Support]
QuickTime Plugin: 7.7.3 (2016-03-22)
Flash Player: 21.0.0.226 - SDK 10.6 (2016-05-03) Outdated! Update
Veoh Plugin: 3.0 (2008-04-15) [Support]
SharePointBrowserPlugin: 14.5.5 - SDK 10.6 (2015-09-12) [Support]
AdobePDFViewer: 9.5.4 (2013-02-22) [Support]
iPhotoPhotocast: 7.0 (2008-07-14)
JavaAppletPlugin: Java 8 Update 73 build 02 (2016-02-14) Check version
3rd Party Preference Panes:ⓘ
Flash Player (2016-04-15) [Support]
Flip4Mac WMV (2013-01-09) [Support]
Java (2016-02-14) [Support]
MozyHome (2016-05-12) [Support]
Perian (2011-07-23) [Support]
Spelling (2015-12-06) [Support]
TeXDistPrefPane (2015-12-06) [Support]
TotalAccess (2005-02-25) [Support]
Tuxera NTFS (2012-08-30) [Support]
Time Machine:ⓘ
Skip System Files: NO
Auto backup: YES
Volumes being backed up:
Macintosh HD: Disk size: 249.77 GB Disk used: 220.04 GB
Destinations:
Toshiba Mac+ [Local]
Total size: 999.86 GB
Total number of backups: 3
Oldest backup: 3/20/13, 11:47 PM
Last backup: 5/12/16, 9:44 PM
Size of backup disk: Excellent
Backup size 999.86 GB > (Disk size 249.77 GB X 3)
Top Processes by CPU:ⓘ
6% WindowServer
5% kernel_task
3% hidd
2% fontd
0% com.apple.WebKit.WebContent(4)
Top Processes by Memory:ⓘ
816 MB kernel_task
492 MB com.apple.WebKit.WebContent(4)
377 MB mds_stores
319 MB Finder
303 MB WindowServer
Virtual Memory Information:ⓘ
589 MB Free RAM
7.42 GB Used RAM (3.15 GB Cached)
0 B Swap Used
Diagnostics Information:ⓘ
May 13, 2016, 08:40:13 PM Self test - passed
May 13, 2016, 08:21:50 PM /Library/Logs/DiagnosticReports/MozyHomeBackup_2016-05-13-202150_[redacted].cpu _resource.diag [Details]
/Library/PreferencePanes/MozyHome.prefPane/Contents/Resources/MozyHomeBackup
May 13, 2016, 07:56:46 PM /Library/Logs/DiagnosticReports/MozyHomeBackup_2016-05-13-195646_[redacted].cpu _resource.diag [Details]
May 12, 2016, 11:35:57 PM /Library/Logs/DiagnosticReports/MozyHomeBackup_2016-05-12-233557_[redacted].cpu _resource.diag [Details]
May 12, 2016, 10:03:31 PM /Library/Logs/DiagnosticReports/MozyHomeBackup_2016-05-12-220331_[redacted].cra sh
May 12, 2016, 08:40:18 PM /Library/Logs/DiagnosticReports/backupd_2016-05-12-204018_[redacted].cpu_resour ce.diag [Details]
/System/Library/CoreServices/backupd.bundle/Contents/Resources/backupd
May 10, 2016, 11:36:03 PM ~/Library/Logs/DiagnosticReports/Finder_2016-05-10-233603_[redacted].crash
com.apple.finder - /System/Library/CoreServices/Finder.app/Contents/MacOS/Finder
May 10, 2016, 10:28:35 PM /Library/Logs/DiagnosticReports/BitMedic_2016-05-10-222835_[redacted].hang
/Applications/BitMedic.app/Contents/MacOS/BitMedic