Greeapp1

Q: Process "orlean"

Can anyone tell me if the following processes are part of OS X?

"orlean"

"nevermore"

"autoinfusion"

"spondulics"

 

I deleted them because they were part of some other user that changed names everytime I restarted the computer. And apparently were adware. But I'm not sure.

MacBook Pro (13-inch Mid 2012), OS X Yosemite (10.10.5), null

Posted on Jun 9, 2016 10:40 PM

Close

Q: Process "orlean"

  • All replies
  • Helpful answers

  • by JimmyCMPIT,Apple recommended

    JimmyCMPIT JimmyCMPIT Jun 12, 2016 10:33 AM in response to Greeapp1
    Level 6 (8,538 points)
    Mac OS X
    Jun 12, 2016 10:33 AM in response to Greeapp1

    I don't recognize them and most of them lead back to this post in a web search so they may be alien to OS X, they are not appearing in my activity monitor and I don't recognize them as something that once did.

    if they are adware just removing the processes might not completly remove the payload.

    Many of us here have used Malwarebytes for mac (free) to remove adware on the mac and had great success.

    While this is not the only way to remove malware others may feel they have methods which better address the removal of those things. While MWB is fairly new in the Mac arena it has been around for ages in the Windows side and I was introduced to in corporate IT Work so it was something being used by companies and freelance IT securities people for this task for years. However; any software solution (or manual solution) regardless of who it came from should be approached with discretion, that being said the link is here

    https://www.malwarebytes.org

  • by Eric Root,Helpful

    Eric Root Eric Root Jun 12, 2016 10:34 AM in response to Greeapp1
    Level 9 (74,293 points)
    iTunes
    Jun 12, 2016 10:34 AM in response to Greeapp1

    Try running this program and then copy and paste the output in a reply. The program was created by Etresoft, a frequent contributor.  Please use copy and paste as screen shots can be hard to read. This will show what is running on your computer. No personal information is shown.
      

    Etrecheck – System Information

  • by Greeapp1,

    Greeapp1 Greeapp1 Jun 10, 2016 9:29 AM in response to JimmyCMPIT
    Level 1 (12 points)
    Mac OS X
    Jun 10, 2016 9:29 AM in response to JimmyCMPIT

    Thank you! The program found quite a lot of files that were adware, guess I should be more careful on the web... Unfortunately now I have the same processes named differently used by another user. Now being "TheBaid" used by "paratrooper".

  • by Greeapp1,

    Greeapp1 Greeapp1 Jun 10, 2016 9:35 AM in response to Eric Root
    Level 1 (12 points)
    Mac OS X
    Jun 10, 2016 9:35 AM in response to Eric Root

    EtreCheck version: 2.9.12 (265)

    Report generated 2016-06-10 11:26:50

    Download EtreCheck from https://etrecheck.com

    Runtime 5:34

    Performance: Below Average

     

    Click the [Support] links for help with non-Apple products.

    Click the [Details] links for more information about that line.

    Click the [Remove] links to remove adware.

    Click the [Check files] link for help with unknown files.

     

    Problem: Other problem

    Description:

    Orlean Adware

     

    Hardware Information:

        MacBook Pro (13-inch, Mid 2012)

        [Technical Specifications] - [User Guide] - [Warranty & Service]

        MacBook Pro - model: MacBookPro9,2

        1 2.5 GHz Intel Core i5 CPU: 2-core

        16 GB RAM Upgradeable - [Instructions]

            BANK 0/DIMM0

                8 GB DDR3 1600 MHz ok

            BANK 1/DIMM0

                8 GB DDR3 1600 MHz ok

        Bluetooth: Good - Handoff/Airdrop2 supported

        Wireless:  en1: 802.11 a/b/g/n

        Battery: Health = Normal - Cycle count = 1318

     

    Video Information:

        Intel HD Graphics 4000

            Color LCD 1280 x 800

     

    System Software:

        OS X Yosemite 10.10.5 (14F1808) - Time since boot: less than an hour

     

    Disk Information:

        APPLE HDD HTS547550A9E384 disk0 : (500.11 GB) (Rotational)

            EFI (disk0s1) <not mounted> : 210 MB

            Macintosh HD (disk0s2) / : 341.25 GB (124.18 GB free)

            Recovery HD (disk0s3) <not mounted>  [Recovery]: 650 MB

            BOOTCAMP (disk0s4) /Volumes/BOOTCAMP : 158.00 GB (5.87 GB free)

     

        MATSHITADVD-R   UJ-8A8   ()

     

    USB Information:

        Apple Inc. FaceTime HD Camera (Built-in)

        Apple Computer, Inc. IR Receiver

        Apple Inc. BRCM20702 Hub

            Apple Inc. Bluetooth USB Host Controller

        Apple Inc. Apple Internal Keyboard / Trackpad

     

    Thunderbolt Information:

        Apple Inc. thunderbolt_bus

     

    Configuration files:

        /etc/hosts - Count: 1 - Corrupt!

     

    Gatekeeper:

        Mac App Store and identified developers

     

    Adware:

        /Library/LaunchDaemons/com.SiphonophoraUpd.plist

        /Library/LaunchDaemons/com.TaeniadaUpd.plist

        2 adware files found. [Remove]

     

    Unknown Files:

        /Library/LaunchDaemons/com.Thebaid.plist

            /etc/Thebaid.sh

        /Library/LaunchDaemons/com.malwarebytes.HelperTool.plist

            /Library/PrivilegedHelperTools/com.malwarebytes.HelperTool /Library/PrivilegedHelperTools/com.malwarebytes.HelperTool

        /Library/LaunchDaemons/com.urothl.plist

        3 unknown files found. [Check files]

     

    Kernel Extensions:

            /Applications/Private Eye.app

        [loaded]    com.radiosilenceapp.nke.PrivateEye (1.0 - SDK 10.7 - 2016-06-10) [Support]

     

            /Applications/duet.app

        [loaded]    com.kairos.driver.DuetDisplay (1.2.0 - SDK 10.11 - 2016-05-04) [Support]

     

            /Library/Application Support/Hotspot Shield

        [not loaded]    com.anchorfree.tun (1.0.1 - 2014-10-17) [Support]

     

            /System/Library/Extensions

        [loaded]    com.corel.painter.PainterAudioDriver (1.0 - SDK 10.9 - 2016-06-09) [Support]

        [not loaded]    com.eltima.ElmediaPlayer.kext (1.58 - SDK 10.4 - 2016-06-09) [Support]

        [not loaded]    com.marvell.kext.USBGenericPrinterClass (1.0.0 - 2016-06-09) [Support]

        [not loaded]    com.mice.driver.Wireless360Controller (1.0.0d12 - SDK 10.8 - 2016-06-09) [Support]

        [not loaded]    com.mice.driver.WirelessGamingReceiver (1.0.0d12 - SDK 10.8 - 2016-06-09) [Support]

        [not loaded]    com.mice.driver.Xbox360Controller (1.0.0d12 - SDK 10.8 - 2016-06-09) [Support]

        [not loaded]    com.microsoft.driver.MicrosoftKeyboard (8.2 - 2016-06-09) [Support]

        [not loaded]    com.microsoft.driver.MicrosoftMouse (8.2 - 2016-06-09) [Support]

        [not loaded]    com.nvidia.CUDA (1.1.0 - 2016-06-09) [Support]

        [not loaded]    com.paceap.kext.pacesupport.master (5.9.1 - SDK 10.6 - 2016-06-09) [Support]

        [not loaded]    com.wacom.kext.pentablet (Pen Tablet 5.3.6-6 - SDK 10.9 - 2016-06-09) [Support]

        [loaded]    net.telestream.driver.TelestreamAudio (1.1.0 - SDK 10.8 - 2016-06-09) [Support]

     

            /System/Library/Extensions/MicrosoftKeyboard.kext/Contents/PlugIns

        [not loaded]    com.microsoft.driver.MicrosoftKeyboardBluetooth (8.2 - 2011-07-27) [Support]

        [not loaded]    com.microsoft.driver.MicrosoftKeyboardUSB (8.2 - 2011-07-27) [Support]

     

            /System/Library/Extensions/MicrosoftMouse.kext/Contents/PlugIns

        [not loaded]    com.microsoft.driver.MicrosoftMouseBluetooth (8.2 - 2014-05-13) [Support]

        [not loaded]    com.microsoft.driver.MicrosoftMouseUSB (8.2 - 2014-05-13) [Support]

     

            /System/Library/Extensions/PACESupportFamily.kext/Contents/PlugIns

        [not loaded]    com.paceap.kext.pacesupport.leopard (5.9.1 - SDK 10.4 - 2014-08-02) [Support]

        [not loaded]    com.paceap.kext.pacesupport.panther (5.9.1 - SDK 10.-1 - 2014-08-02) [Support]

        [not loaded]    com.paceap.kext.pacesupport.snowleopard (5.9.1 - SDK 10.6 - 2014-08-02) [Support]

        [not loaded]    com.paceap.kext.pacesupport.tiger (5.9.1 - SDK 10.4 - 2014-08-02) [Support]

     

    Startup Items:

        CUDA: Path: /System/Library/StartupItems/CUDA

        DigidesignLoader: Path: /Library/StartupItems/DigidesignLoader

        Startup items are obsolete in OS X Yosemite

     

    System Launch Agents:

        [not loaded]    5 Apple tasks

        [loaded]    147 Apple tasks

        [running]    60 Apple tasks

     

    System Launch Daemons:

        [not loaded]    47 Apple tasks

        [loaded]    141 Apple tasks

        [running]    76 Apple tasks

     

    Launch Agents:

        [not loaded]    com.adobe.AAM.Updater-1.0.plist (2016-06-03) [Support]

        [failed]    com.adobe.ARMDCHelper.cc24aef4a1b90ed56a...plist (2016-05-11) [Support]

        [loaded]    com.adobe.AdobeCreativeCloud.plist (2015-11-14) [Support]

        [loaded]    com.google.keystone.agent.plist (2016-03-02) [Support]

        [loaded]    com.oracle.java.Java-Updater.plist (2014-06-03) [Support]

        [running]    com.wacom.pentablet.plist (2014-12-23) [Support]

     

    Launch Daemons:

        [not loaded]    com.SiphonophoraUpd.plist (2016-06-03) Adware!  [Remove]

        [not loaded]    com.TaeniadaUpd.plist (2016-04-26) Adware!  [Remove]

        [running]    com.Thebaid.plist (2016-06-10) [Support]

        [loaded]    com.adobe.ARMDC.Communicator.plist (2016-05-11) [Support]

        [loaded]    com.adobe.ARMDC.SMJobBlessHelper.plist (2016-05-11) [Support]

        [loaded]    com.adobe.SwitchBoard.plist (2015-02-25) [Support]

        [running]    com.adobe.adobeupdatedaemon.plist (2016-02-16) [Support]

        [loaded]    com.adobe.agsservice.plist (2015-09-13) [Support]

        [loaded]    com.adobe.fpsaud.plist (2016-05-09) [Support]

        [loaded]    com.anchorfree.ajaxserver.plist (2013-02-20) [Support]

        [not loaded]    com.apple.panur.plist (2016-05-27) - Executable not found!

        [running]    com.autodesk.backburner_manager.plist (2012-02-02) [Support]

        [running]    com.autodesk.backburner_server.plist (2012-02-02) [Support]

        [loaded]    com.autodesk.backburner_start.plist (2012-02-02) [Support]

        [loaded]    com.google.keystone.daemon.plist (2016-03-02) [Support]

        [loaded]    com.macpaw.CleanMyMac2.Agent.plist (2014-10-26) [Support]

        [loaded]    com.macpaw.CleanMyMac3.Agent.plist (2016-06-10) [Support]

        [loaded]    com.malwarebytes.HelperTool.plist (2016-06-10) [Support]

        [loaded]    com.oracle.java.Helper-Tool.plist (2014-06-03) [Support]

        [running]    com.paceap.eden.licensed.plist (2014-01-15) [Support]

        [loaded]    com.radiosilenceapp.nke.PrivateEye.plist (2011-10-06) [Support]

        [not loaded]    com.urothl.plist (2016-05-09) [Support]

        [loaded]    org.macosforge.xquartz.privileged_startx.plist (2013-11-10) [Support]

     

    User Launch Agents:

        [running]    com.apple.FolderActions.enabled.plist

        [loaded]    com.apple.FolderActions.folders.plist

        [running]    com.hp.printerAgent.plist (2011-08-30) [Support]

        [loaded]    com.macpaw.CleanMyMac3.Scheduler.plist (2016-06-10) [Support]

        [running]    com.spotify.webhelper.plist (2016-05-07) [Support]

        [loaded]    uk.co.canimaansoftware.clamxav.freshclam.plist (2016-06-09) [Support]

     

    User Login Items:

        iTunesHelper    Aplicación  (/Applications/iTunes.app/Contents/MacOS/iTunesHelper.app)

        CleanMyMac 3 Menu    Aplicación  (/Applications/CleanMyMac 3.app/Contents/MacOS/CleanMyMac 3 Menu.app)

        BambooCore    Aplicación  (/Library/Application Support/Wacom/BambooCore.app)

     

    Other Apps:

        [running]    /Library/urothl/urothl.app/Contents/MacOS/urothl

        [loaded]    SiphonophoraUpd.plist

        [failed]    com.5e275556e95e3ba9.config

        [running]    com.adobe.CCXProcess.242284

        [running]    com.adobe.acc.AdobeDesktopService.192868.C10349AE-BAFD-4A6F-BC34-CB72BD0D1BBE

        [running]    com.adobe.accmac.196560

        [running]    com.macpaw.CleanMyMac3.Menu.3156

        [running]    com.wacom.BambooCore.46324

        [running]    com.wacom.ConsumerTouchDriver.50584

        [running]    com.wacom.TabletDriver.53140

        [loaded]    386 Apple tasks

        [running]    169 Apple tasks

     

    Internet Plug-ins:

        FlashPlayer-10.6: 21.0.0.242 - SDK 10.6 (2016-05-13) [Support]

        QuickTime Plugin: 7.7.3 (2016-06-09)

        AdobePDFViewerNPAPI: 15.016.20045 - SDK 10.11 (2016-06-03) [Support]

        AdobePDFViewer: 15.016.20045 - SDK 10.11 (2016-06-03) [Support]

        Flash Player: 21.0.0.242 - SDK 10.6 (2016-05-13) [Support]

        Default Browser: 600 - SDK 10.10 (2015-08-15)

        o1dbrowserplugin: 5.41.3.0 - SDK 10.8 (2015-12-11) [Support]

        googletalkbrowserplugin: 5.41.3.0 - SDK 10.8 (2015-12-11) [Support]

        Silverlight: 5.1.30514.0 - SDK 10.6 (2014-08-23) [Support]

        Unity Web Player: UnityPlayer version 5.3.4f1 - SDK 10.6 (2016-03-30) [Support]

        JavaAppletPlugin: Java 8 Update 91 build 14 (2016-05-08) Check version

     

    Safari Extensions:

        Adblock Plus - Eyeo GmbH - https://adblockplus.org/ (2016-06-03)

     

    Audio Plug-ins:

        Avid CoreAudio: 10.3.3.106 - SDK 10.6 (2012-12-15) [Support]

     

    3rd Party Preference Panes:

        Flash Player (2016-05-09) [Support]

        Java (2016-05-08) [Support]

        Microsoft Mouse (2014-05-13) [Support]

        PenTablet (2016-03-23) [Support]

     

    Time Machine:

        Skip System Files: NO

        Mobile backups: OFF

        Auto backup: YES

        Volumes being backed up:

            Macintosh HD: Disk size: 341.25 GB Disk used: 217.07 GB

        Destinations:

            Data [Network]

            Total size: 2.00 TB

            Total number of backups: 92

            Oldest backup: 22/04/14 21:52

            Last backup: 09/06/16 20:48

            Size of backup disk: Excellent

                Backup size 2.00 TB > (Disk size 341.25 GB X 3)

     

    Top Processes by CPU:

            13%    Activity Monitor

             9%    WindowServer

             4%    sysmond

             4%    hidd

             4%    kernel_task

     

    Top Processes by Memory:

        1011 MB    kernel_task

        557 MB    com.apple.WebKit.WebContent(2)

        295 MB    Safari

        98 MB    cfprefsd(2)

        82 MB    garcon

     

    Virtual Memory Information:

        11.00 GB    Free RAM

        4.73 GB    Used RAM (1.51 GB Cached)

        0 B    Swap Used

     

    Diagnostics Information:

        Jun 10, 2016, 11:14:01 AM    Self test - passed

        Jun 10, 2016, 03:21:25 AM    /Library/Logs/DiagnosticReports/com.apple.WebKit.WebContent_2016-06-10-032125_[ redacted].cpu_resource.diag [Details]

            /System/Library/StagedFrameworks/Safari/WebKit.framework/Versions/A/XPCServices /com.apple.WebKit.WebContent.xpc/Contents/MacOS/com.apple.WebKit.WebContent

        Jun 10, 2016, 12:18:04 AM    /Library/Logs/DiagnosticReports/com.apple.WebKit.WebContent_2016-06-10-001804_[ redacted].cpu_resource.diag [Details]

        Jun 10, 2016, 12:14:23 AM    /Library/Logs/DiagnosticReports/com.apple.WebKit.WebContent_2016-06-10-001423_[ redacted].cpu_resource.diag [Details]

        Jun 10, 2016, 12:14:04 AM    /Library/Logs/DiagnosticReports/com.apple.WebKit.WebContent_2016-06-10-001404_[ redacted].cpu_resource.diag [Details]

        Jun 9, 2016, 09:04:38 AM    /Library/Logs/DiagnosticReports/Safari_2016-06-09-090438_[redacted].hang

            /Applications/Safari.app/Contents/MacOS/Safari

        Jun 9, 2016, 08:46:44 AM    /Library/Logs/DiagnosticReports/CleanMyMac 3_2016-06-09-084644_[redacted].cpu_resource.diag [Details]

            /Applications/CleanMyMac 3.app/Contents/MacOS/CleanMyMac 3

        Jun 9, 2016, 08:41:13 AM    /Library/Logs/DiagnosticReports/com.apple.WebKit.WebContent_2016-06-09-084113_[ redacted].cpu_resource.diag [Details]

        Jun 9, 2016, 08:34:36 AM    /Library/Logs/DiagnosticReports/CleanMyMac 3_2016-06-09-083436_[redacted].cpu_resource.diag [Details]

        Jun 9, 2016, 08:05:35 AM    /Library/Logs/DiagnosticReports/PenTabletDriver_2016-06-09-080535_[redacted].cr ash

            /Library/Application Support/Tablet/PenTabletDriver.app/Contents/MacOS/PenTabletDriver

        Jun 9, 2016, 01:59:52 AM    /Library/Logs/DiagnosticReports/com.apple.WebKit.WebContent_2016-06-09-015952_[ redacted].cpu_resource.diag [Details]

        Jun 9, 2016, 01:54:03 AM    /Library/Logs/DiagnosticReports/com.apple.WebKit.WebContent_2016-06-09-015403_[ redacted].cpu_resource.diag [Details]

        Jun 9, 2016, 01:04:08 AM    /Library/Logs/DiagnosticReports/com.apple.WebKit.WebContent_2016-06-09-010408_[ redacted].cpu_resource.diag [Details]

     

    I hope this helps.

  • by Greeapp1,

    Greeapp1 Greeapp1 Jun 10, 2016 10:19 AM in response to Greeapp1
    Level 1 (12 points)
    Mac OS X
    Jun 10, 2016 10:19 AM in response to Greeapp1

    Thank you both for the recommendations! Simply removing the files through each of those programs seemed to solve my problem. Though, I will continue monitoring the system if I missed anything else. Later today I will post a complete report on this issue.

  • by Eric Root,Apple recommended

    Eric Root Eric Root Jun 11, 2016 10:24 AM in response to Greeapp1
    Level 9 (74,293 points)
    iTunes
    Jun 11, 2016 10:24 AM in response to Greeapp1

    You have adware installed. Run the report again and where you see the red Adware, click Remove. Once complete, run the report again and post a copy into a new reply.

     

    /etc/hosts file - Fixing a hacked


    Most people advise not to use cleaning programs. They can destroy your computer operation as they may already have done.

     

    CleanMyMac2 Un-install

     

    CleanMyMac 3 Uninstall

     

    After un-installing, use this program to make sure you got all the pieces.

    EasyFind – Spotlight Replacement

  • by Greeapp1,

    Greeapp1 Greeapp1 Jun 12, 2016 10:53 AM in response to Eric Root
    Level 1 (12 points)
    Mac OS X
    Jun 12, 2016 10:53 AM in response to Eric Root

    EtreCheck version: 2.9.12 (265)

    Report generated 2016-06-12 12:44:40

    Download EtreCheck from https://etrecheck.com

    Runtime 7:30

    Performance: Below Average

     

    Click the [Support] links for help with non-Apple products.

    Click the [Details] links for more information about that line.

     

    Problem: Other problem

    Description:

    Adware

     

    Hardware Information:

        MacBook Pro (13-inch, Mid 2012)

        [Technical Specifications] - [User Guide] - [Warranty & Service]

        MacBook Pro - model: MacBookPro9,2

        1 2.5 GHz Intel Core i5 CPU: 2-core

        16 GB RAM Upgradeable - [Instructions]

            BANK 0/DIMM0

                8 GB DDR3 1600 MHz ok

            BANK 1/DIMM0

                8 GB DDR3 1600 MHz ok

        Bluetooth: Good - Handoff/Airdrop2 supported

        Wireless:  en1: 802.11 a/b/g/n

        Battery: Health = Normal - Cycle count = 1320

     

    Video Information:

        Intel HD Graphics 4000

            Color LCD 1280 x 800

     

    System Software:

        OS X Yosemite 10.10.5 (14F1808) - Time since boot: about 2 days

     

    Disk Information:

        APPLE HDD HTS547550A9E384 disk0 : (500.11 GB) (Rotational)

            EFI (disk0s1) <not mounted> : 210 MB

            Macintosh HD (disk0s2) / : 341.25 GB (123.57 GB free)

            Recovery HD (disk0s3) <not mounted>  [Recovery]: 650 MB

            BOOTCAMP (disk0s4) /Volumes/BOOTCAMP : 158.00 GB (5.87 GB free)

     

        MATSHITADVD-R   UJ-8A8   ()

     

    USB Information:

        Apple Inc. FaceTime HD Camera (Built-in)

        Apple Inc. Apple Internal Keyboard / Trackpad

        Apple Computer, Inc. IR Receiver

        Apple Inc. BRCM20702 Hub

            Apple Inc. Bluetooth USB Host Controller

     

    Thunderbolt Information:

        Apple Inc. thunderbolt_bus

     

    Configuration files:

        /etc/hosts - Corrupt!

     

    Gatekeeper:

        Mac App Store and identified developers

     

    Kernel Extensions:

            /Applications/Private Eye.app

        [loaded]    com.radiosilenceapp.nke.PrivateEye (1.0 - SDK 10.7 - 2016-06-10) [Support]

     

            /Applications/duet.app

        [loaded]    com.kairos.driver.DuetDisplay (1.2.0 - SDK 10.11 - 2016-05-04) [Support]

     

            /Library/Application Support/Hotspot Shield

        [not loaded]    com.anchorfree.tun (1.0.1 - 2014-10-17) [Support]

     

            /System/Library/Extensions

        [loaded]    com.corel.painter.PainterAudioDriver (1.0 - SDK 10.9 - 2016-06-09) [Support]

        [not loaded]    com.eltima.ElmediaPlayer.kext (1.58 - SDK 10.4 - 2016-06-09) [Support]

        [not loaded]    com.marvell.kext.USBGenericPrinterClass (1.0.0 - 2016-06-09) [Support]

        [not loaded]    com.mice.driver.Wireless360Controller (1.0.0d12 - SDK 10.8 - 2016-06-09) [Support]

        [not loaded]    com.mice.driver.WirelessGamingReceiver (1.0.0d12 - SDK 10.8 - 2016-06-09) [Support]

        [not loaded]    com.mice.driver.Xbox360Controller (1.0.0d12 - SDK 10.8 - 2016-06-09) [Support]

        [not loaded]    com.microsoft.driver.MicrosoftKeyboard (8.2 - 2016-06-09) [Support]

        [not loaded]    com.microsoft.driver.MicrosoftMouse (8.2 - 2016-06-09) [Support]

        [not loaded]    com.nvidia.CUDA (1.1.0 - 2016-06-09) [Support]

        [not loaded]    com.paceap.kext.pacesupport.master (5.9.1 - SDK 10.6 - 2016-06-09) [Support]

        [not loaded]    com.wacom.kext.pentablet (Pen Tablet 5.3.6-6 - SDK 10.9 - 2016-06-09) [Support]

        [loaded]    net.telestream.driver.TelestreamAudio (1.1.0 - SDK 10.8 - 2016-06-09) [Support]

     

            /System/Library/Extensions/MicrosoftKeyboard.kext/Contents/PlugIns

        [not loaded]    com.microsoft.driver.MicrosoftKeyboardBluetooth (8.2 - 2011-07-27) [Support]

        [not loaded]    com.microsoft.driver.MicrosoftKeyboardUSB (8.2 - 2011-07-27) [Support]

     

            /System/Library/Extensions/MicrosoftMouse.kext/Contents/PlugIns

        [not loaded]    com.microsoft.driver.MicrosoftMouseBluetooth (8.2 - 2014-05-13) [Support]

        [not loaded]    com.microsoft.driver.MicrosoftMouseUSB (8.2 - 2014-05-13) [Support]

     

            /System/Library/Extensions/PACESupportFamily.kext/Contents/PlugIns

        [not loaded]    com.paceap.kext.pacesupport.leopard (5.9.1 - SDK 10.4 - 2014-08-02) [Support]

        [not loaded]    com.paceap.kext.pacesupport.panther (5.9.1 - SDK 10.-1 - 2014-08-02) [Support]

        [not loaded]    com.paceap.kext.pacesupport.snowleopard (5.9.1 - SDK 10.6 - 2014-08-02) [Support]

        [not loaded]    com.paceap.kext.pacesupport.tiger (5.9.1 - SDK 10.4 - 2014-08-02) [Support]

     

    System Launch Agents:

        [not loaded]    5 Apple tasks

        [loaded]    134 Apple tasks

        [running]    73 Apple tasks

     

    System Launch Daemons:

        [not loaded]    46 Apple tasks

        [loaded]    132 Apple tasks

        [running]    86 Apple tasks

     

    Launch Agents:

        [not loaded]    com.adobe.AAM.Updater-1.0.plist (2016-06-03) [Support]

        [failed]    com.adobe.ARMDCHelper.cc24aef4a1b90ed56a...plist (2016-05-11) [Support]

        [loaded]    com.adobe.AdobeCreativeCloud.plist (2015-11-14) [Support]

        [loaded]    com.google.keystone.agent.plist (2016-03-02) [Support]

        [loaded]    com.oracle.java.Java-Updater.plist (2014-06-03) [Support]

        [running]    com.wacom.pentablet.plist (2014-12-23) [Support]

     

    Launch Daemons:

        [failed]    com.apple.panur.plist

        [running]    com.macpaw.CleanMyMac3.Agent.plist (2016-06-12) [Support]

        [not loaded]    com.radiosilenceapp.nke.PrivateEye.plist (2011-10-06) [Support]

     

    User Launch Agents:

        [running]    com.apple.FolderActions.enabled.plist

        [loaded]    com.apple.FolderActions.folders.plist

        [running]    com.hp.printerAgent.plist (2011-08-30) [Support]

        [running]    com.spotify.webhelper.plist (2016-06-10) [Support]

        [loaded]    uk.co.canimaansoftware.clamxav.freshclam.plist (2016-06-09) [Support]

     

    User Login Items:

        iTunesHelper    Aplicación  (/Applications/iTunes.app/Contents/MacOS/iTunesHelper.app)

        BambooCore    Aplicación  (/Library/Application Support/Wacom/BambooCore.app)

     

    Other Apps:

        [running]    com.adobe.CCXProcess.242284

        [running]    com.adobe.acc.AdobeDesktopService.192868.33E58EFC-1817-438F-935D-1569EB159748

        [running]    com.adobe.accmac.196560

        [running]    com.etresoft.EtreCheck.257620

        [running]    com.wacom.BambooCore.46324

        [running]    com.wacom.ConsumerTouchDriver.50584

        [running]    com.wacom.TabletDriver.53140

        [loaded]    353 Apple tasks

        [running]    190 Apple tasks

     

    Internet Plug-ins:

        FlashPlayer-10.6: 21.0.0.242 - SDK 10.6 (2016-05-13) [Support]

        QuickTime Plugin: 7.7.3 (2016-06-09)

        AdobePDFViewerNPAPI: 15.016.20045 - SDK 10.11 (2016-06-03) [Support]

        AdobePDFViewer: 15.016.20045 - SDK 10.11 (2016-06-03) [Support]

        Flash Player: 21.0.0.242 - SDK 10.6 (2016-05-13) [Support]

        Default Browser: 600 - SDK 10.10 (2015-08-15)

        o1dbrowserplugin: 5.41.3.0 - SDK 10.8 (2015-12-11) [Support]

        googletalkbrowserplugin: 5.41.3.0 - SDK 10.8 (2015-12-11) [Support]

        Silverlight: 5.1.30514.0 - SDK 10.6 (2014-08-23) [Support]

        Unity Web Player: UnityPlayer version 5.3.4f1 - SDK 10.6 (2016-03-30) [Support]

        JavaAppletPlugin: Java 8 Update 91 build 14 (2016-05-08) Check version

     

    Safari Extensions:

        Adblock Plus - Eyeo GmbH - https://adblockplus.org/ (2016-06-03)

     

    Audio Plug-ins:

        Avid CoreAudio: 10.3.3.106 - SDK 10.6 (2012-12-15) [Support]

     

    3rd Party Preference Panes:

        Flash Player (2016-05-09) [Support]

        Java (2016-05-08) [Support]

        Microsoft Mouse (2014-05-13) [Support]

        PenTablet (2016-03-23) [Support]

     

    Time Machine:

        Skip System Files: NO

        Mobile backups: OFF

        Auto backup: YES

        Volumes being backed up:

            Macintosh HD: Disk size: 341.25 GB Disk used: 217.68 GB

        Destinations:

            Data [Network]

            Total size: 2.00 TB

            Total number of backups: 91

            Oldest backup: 22/04/14 21:52

            Last backup: 11/06/16 1:30

            Size of backup disk: Excellent

                Backup size 2.00 TB > (Disk size 341.25 GB X 3)

     

    Top Processes by CPU:

            36%    com.apple.WebKit.WebContent(7)

            23%    kernel_task

            19%    Safari

            10%    WindowServer

             3%    diskimages-helper

     

    Top Processes by Memory:

        1.81 GB    com.apple.WebKit.WebContent(7)

        1.24 GB    kernel_task

        459 MB    softwareupdated

        311 MB    Safari

        131 MB    mds_stores

     

    Virtual Memory Information:

        7.98 GB    Free RAM

        8.02 GB    Used RAM (1.51 GB Cached)

        0 B    Swap Used

     

    Diagnostics Information:

        Jun 10, 2016, 02:41:55 PM    Self test - passed

        Jun 10, 2016, 02:00:49 PM    /Library/Logs/DiagnosticReports/com.apple.WebKit.WebContent_2016-06-10-140049_[ redacted].cpu_resource.diag [Details]

            /System/Library/StagedFrameworks/Safari/WebKit.framework/Versions/A/XPCServices /com.apple.WebKit.WebContent.xpc/Contents/MacOS/com.apple.WebKit.WebContent

        Jun 10, 2016, 03:21:25 AM    /Library/Logs/DiagnosticReports/com.apple.WebKit.WebContent_2016-06-10-032125_[ redacted].cpu_resource.diag [Details]

        Jun 10, 2016, 12:18:04 AM    /Library/Logs/DiagnosticReports/com.apple.WebKit.WebContent_2016-06-10-001804_[ redacted].cpu_resource.diag [Details]

        Jun 10, 2016, 12:14:23 AM    /Library/Logs/DiagnosticReports/com.apple.WebKit.WebContent_2016-06-10-001423_[ redacted].cpu_resource.diag [Details]

        Jun 10, 2016, 12:14:04 AM    /Library/Logs/DiagnosticReports/com.apple.WebKit.WebContent_2016-06-10-001404_[ redacted].cpu_resource.diag [Details]

  • by Eric Root,

    Eric Root Eric Root Jun 13, 2016 11:45 AM in response to Greeapp1
    Level 9 (74,293 points)
    iTunes
    Jun 13, 2016 11:45 AM in response to Greeapp1

    The adware is gone.

     

    Parts of CleanMyMac 3 are still installed. See if you can find them with Easy Find (link in last post).

     

    Also try the link below.

     

    /etc/hosts file - Fixing a hacked

  • by Greeapp1,

    Greeapp1 Greeapp1 Jun 14, 2016 11:06 AM in response to Eric Root
    Level 1 (12 points)
    Mac OS X
    Jun 14, 2016 11:06 AM in response to Eric Root

    Thanks, the fix worked and CleanMyMac is completely uninstalled. Do you recommend any software or extension that monitors or blocks adware in the computer?, that would be helpful for future reference.

  • by Eric Root,

    Eric Root Eric Root Jun 15, 2016 9:11 AM in response to Greeapp1
    Level 9 (74,293 points)
    iTunes
    Jun 15, 2016 9:11 AM in response to Greeapp1

    You are welcome. I don't use any such software or extensions, but based on discussions I've read, the 2 extensions that seem to be installed the most are AdBlock and AdBlock Plus, which are available at Safari/Safari Extensions........