ChrisHorlacher

Q: Mac Running Slow - EtreCheck Not Validating

My Mac has been running very slow as of late and I'm using EtreCheck to try and identify any issues. It discovered some Adware on my machine but I've been unable to remove it due to an EtreCheck error.

Screen Shot 2016-06-23 at 4.45.13 PM.png

I don't have a firewall so I'm not sure why this isn't working. I'd really like to see how things run after I clean out the adware.

 

Below is the full EtreCheck report:

 

EtreCheck version: 2.9.12 (265)

Report generated 2016-06-23 16:34:43

Download EtreCheck from https://etrecheck.com

Runtime 3:10

Performance: Good

 

Click the [Support] links for help with non-Apple products.

Click the [Details] links for more information about that line.

Click the [Remove] links to remove adware.

 

Problem: Computer is too slow

 

Hardware Information:

    Mac mini (Late 2012)

    [Technical Specifications] - [User Guide] - [Warranty & Service]

    Mac mini - model: Macmini6,2

    1 2.3 GHz Intel Core i7 CPU: 4-core

    4 GB RAM Upgradeable - [Instructions]

        BANK 0/DIMM0

            2 GB DDR3 1600 MHz ok

        BANK 1/DIMM0

            2 GB DDR3 1600 MHz ok

    Bluetooth: Good - Handoff/Airdrop2 supported

    Wireless:  en1: 802.11 a/b/g/n

 

Video Information:

    Intel HD Graphics 4000

        PIONEER-M 1920 x 1080

 

System Software:

    OS X Mavericks 10.9.5 (13F1808) - Time since boot: about 23 days

 

Disk Information:

    APPLE HDD HTS541010A9E662 disk0 : (1 TB) (Rotational)

        EFI (disk0s1) <not mounted> : 210 MB

        Macintosh HD (disk0s2) / : 999.35 GB (327.11 GB free)

        Recovery HD (disk0s3) <not mounted>  [Recovery]: 650 MB

 

USB Information:

    Apple, Inc. IR Receiver

    Apple Inc. BRCM20702 Hub

        Apple Inc. Bluetooth USB Host Controller

 

Thunderbolt Information:

    Apple Inc. thunderbolt_bus

 

Configuration files:

    /etc/sysctl.conf - File exists but not expected

 

Gatekeeper:

    Mac App Store and identified developers

 

Adware:

    ~/Library/LaunchAgents/com.jdibackup.ZipCloud.autostart.plist

    ~/Library/LaunchAgents/com.jdibackup.ZipCloud.notify.plist

    2 adware files found. [Remove]

 

Kernel Extensions:

        /Applications/AVG AntiVirus.app

    [loaded]    com.avg.Antivirus.OnAccess.kext (4791 - SDK 10.8 - 2016-06-23) [Support]

 

        /Library/Application Support/Roxio

    [not loaded]    com.roxio.TDIXController (1.7 - 2014-09-06) [Support]

 

        /System/Library/Extensions

    [not loaded]    com.FTDI.driver.FTDIUSBSerialDriver (2.2.14 - 2016-06-04) [Support]

 

System Launch Agents:

    [not loaded]    6 Apple tasks

    [loaded]    142 Apple tasks

    [running]    36 Apple tasks

 

System Launch Daemons:

    [failed]    com.apple.AOSNotificationOSX.plist

    [not loaded]    51 Apple tasks

    [loaded]    140 Apple tasks

    [running]    56 Apple tasks

 

Launch Agents:

    [running]    com.avg.Antivirus.gui.plist (2016-03-20) [Support]

    [failed]    com.brother.LOGINserver.plist (2010-09-09) [Support]

    [loaded]    com.divx.dms.agent.plist (2016-05-31) [Support]

    [loaded]    com.divx.update.agent.plist (2016-04-13) [Support]

    [loaded]    com.google.keystone.agent.plist (2016-03-01) [Support]

 

Launch Daemons:

    [failed]    com.adobe.fpsaud.plist (2016-04-15) [Support]

    [loaded]    com.avg.Antivirus.crashpad.plist (2016-03-20) [Support]

    [running]    com.avg.Antivirus.infosd.plist (2016-03-20) [Support]

    [running]    com.avg.Antivirus.services.plist (2016-03-20) [Support]

    [loaded]    com.google.keystone.daemon.plist (2016-03-01) [Support]

 

User Launch Agents:

    [running]    com.iobit.MacBoosterMini.plist (2015-07-13) [Support]

    [failed]    com.jdibackup.ZipCloud.autostart.plist (2015-09-20) Adware!  [Remove]

    [failed]    com.jdibackup.ZipCloud.notify.plist (2015-09-20) Adware!  [Remove]

 

 

Other Apps:

    [running]    [0x0-0x24024].org.m0k.transmission

    [running]    [0x0-0x689689].com.etresoft.EtreCheck

    [running]    com.google.Chrome.76944

    [loaded]    org.m0k.transmission.12000

    [running]    org.videolan.vlc.11648

    [loaded]    446 Apple tasks

    [running]    294 Apple tasks

 

Internet Plug-ins:

    DirectorShockwave: 12.1.8r158 - SDK 10.6 (2015-04-16) [Support]

    OVSHelper: 1.1 (2016-06-09) [Support]

    Default Browser: 537 - SDK 10.9 (2014-09-25)

    OfficeLiveBrowserPlugin: 12.3.6 (2013-05-27) [Support]

    Google Earth Web Plug-in: 7.1 (2013-10-07) [Support]

    Silverlight: 5.1.30317.0 - SDK 10.6 (2014-05-30) [Support]

    FlashPlayer-10.6: 21.0.0.226 - SDK 10.6 (2016-04-22) [Support]

    DivX Web Player: 3.6.0.4 - SDK 10.10 (2016-05-31) [Support]

    QuickTime Plugin: 7.7.3 (2016-05-17)

    Flash Player: 21.0.0.226 - SDK 10.6 (2016-04-22) Outdated! Update

    iPhotoPhotocast: 7.0 (2008-11-22)

    GarminGpsControl: 2.6.2.0 Release (2008-09-22) [Support]

    JavaAppletPlugin: 14.9.0 - SDK 10.7 (2015-01-06) Check version

 

User internet Plug-ins:

    fbplugin_1_0_3: Unknown (2010-02-26) [Support]

    WebEx: 1.0 (2011-04-07) [Support]

 

3rd Party Preference Panes:

    Flash Player (2016-04-15) [Support]

 

Time Machine:

    Skip System Files: YES - System files not being backed up

    Auto backup: NO - Auto backup turned off

    Destinations:

        Macintosh HD [Local]

        Total size: 0 B

        Total number of backups: 0

        Oldest backup: -

        Last backup: -

        Size of backup disk: Excellent

            Backup size 0 B > (Disk size 0 B X 3)

 

Top Processes by CPU:

        36%    mdworker(8)

         4%    kernel_task

         3%    WindowServer

         3%    Google Chrome Helper(3)

         1%    fontd

 

Top Processes by Memory:

    574 MB    kernel_task

    438 MB    Google Chrome Helper(3)

    184 MB    Google Chrome

    74 MB    avgscand

    66 MB    Mail

 

Virtual Memory Information:

    130 MB    Free RAM

    2.58 GB    Used RAM (581 MB Cached)

    1.78 GB    Swap Used

Posted on Jun 23, 2016 1:54 PM

Close

Q: Mac Running Slow - EtreCheck Not Validating

  • All replies
  • Helpful answers

  • by macjack,

    macjack macjack Jun 23, 2016 2:02 PM in response to ChrisHorlacher
    Level 9 (55,709 points)
    Mac OS X
    Jun 23, 2016 2:02 PM in response to ChrisHorlacher

    Also uninstall the Anti-virus software. There are no viruses that can attack Mac.OS X. So, anti-virus programs are selling a cure for a disease that doesn't exist. And they are renowned for borking Mac systems. Check for an uninstaller or visit their site for uninstall instructions.

    Not sure about the message, try starting in Safe Mode and see if it works in Safe Mode.

    Restart holding the "shift" key.

    (Expect it to take longer to start this way because it runs a directory check first.)

  • by Esquared,

    Esquared Esquared Jun 23, 2016 2:04 PM in response to ChrisHorlacher
    Level 6 (8,538 points)
    Mac OS X
    Jun 23, 2016 2:04 PM in response to ChrisHorlacher

    That Etrecheck screen looks very fishy to me...

  • by Linc Davis,

    Linc Davis Linc Davis Jun 23, 2016 2:07 PM in response to ChrisHorlacher
    Level 10 (208,044 points)
    Applications
    Jun 23, 2016 2:07 PM in response to ChrisHorlacher

    1. This procedure is a diagnostic test. It changes nothing, for better or worse, and therefore will not, in itself, solve the problem. But with the aid of the test results, the solution may take a few minutes, instead of hours or days.

    The test works on OS X 10.8 ("Mountain Lion") and later. I don't recommend running it on older versions of OS X. It will do no harm, but it won't do much good either.

    Don't be put off by the complexity of these instructions. The procedure is easy to do right, but it's also easy to do wrong, so I've made the instructions very detailed. You do harder tasks with the computer all the time.

    2. If you don't already have a current backup, please back up all data before doing anything else. The backup is necessary on general principle, not because of anything in the test procedure. Backup is always a must, and when you're having any kind of trouble with the computer, you may be at higher than usual risk of losing data, whether you follow these instructions or not.

    There are ways to back up a computer that isn't fully functional. Ask if you need guidance.

    3. Below are instructions to run a UNIX shell script, a type of program. As I wrote above, it changes nothing. It doesn't send or receive any data on the network. All it does is to generate a human-readable report on the state of the computer. That report goes nowhere unless you choose to share it. If you prefer, you can act on it yourself without disclosing the contents to me or anyone else.

    You should be wondering whether you can believe me, and whether it's safe to run a program at the behest of a stranger. In general, no, it's not safe and I don't encourage it.

    In this case, however, there are ways for you to decide whether the program is safe without having to trust me. First, you can read it. Unlike an application that you download and click to run, it's transparent, so anyone who understands the code can verify what it does.

    You may not be able to understand the script yourself. But variations of it have been posted on this website many times over a period of years. Any one of the millions of registered users could have read the script and raised the alarm if it was harmful. Then I would not be here now and you would not be reading this message. See, for example, this discussion.

    Nevertheless, if you can't satisfy yourself that these instructions are safe, don't follow them. Ask for other options.

    4. Here's a general summary of what you need to do, if you choose to proceed:

    ☞ Copy the text of a particular web page (not this one) to the Clipboard.

    ☞ Paste into the window of another application.

    ☞ Wait for the test to run. It usually takes a few minutes.

    ☞ Paste the results, which will have been copied automatically, back into a reply on this page.

    These are not specific instructions; just an overview. The details are in parts 7 and 8 of this comment. The sequence is: copy, paste, wait, paste again. You don't need to copy a second time.

    5. Try to test under conditions that reproduce the problem, as far as possible. For example, if the computer is intermittently slow, run the test during a slowdown.

    You may have started up in safe mode. If the system is now in safe mode and works well enough in normal mode to run the test, restart as usual before running it. If you can only test in safe mode, do that.

    6. If you have more than one user, and only one user is affected by the problem,, and the affected user is not an administrator, then please run the test twice: once while logged in as the affected user, and once as an administrator. The results may be different. The user that is created automatically on a new computer when you start it for the first time is an administrator. If you can't log in as an administrator, test as the affected user. Most personal Macs have only one user, and in that case this section doesn’t apply. Don't log in as root.

    7. Load this linked web page (on the website "Pastebin") in Safari. Press the key combination command-A to select all the text, then copy it to the Clipboard by pressing command-C.

    8. Launch the built-in Terminal application in any one of the following ways:

    ☞ Enter the first few letters of its name ("Terminal") into a Spotlight search. Select it in the results (it should be at the top.)

    ☞ In the Finder, select Go ▹ Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.

    ☞ Open LaunchPad and start typing the name.

    Click anywhere in the Terminal window to activate it. Paste from the Clipboard into the window by pressing command-V, then press return. The text you pasted should vanish immediately.

    9. If you're logged in as an administrator, you'll be prompted for your login password. Nothing will be displayed when you type it. You will not see the usual dots in place of typed characters. Make sure caps lock is off. Type carefully and then press return. You may get a one-time warning to be careful. If you make three failed attempts to enter the password, the test will run anyway, but it will produce less information. If you don't know the password, or if you prefer not to enter it, just press return three times at the password prompt. Again, the script will still run.

    If the test is taking much longer than usual to run because the computer is very slow, you might be prompted for your password a second time. The authorization that you grant by entering it expires automatically after five minutes.

    If you're not logged in as an administrator, you won't be prompted for a password. The test will still run. It just won't do anything that requires administrator privileges.

    10. The test may take a few minutes to run, depending on how many files you have and the speed of the computer. A computer that's abnormally slow may take longer to run the test. While it's running, a series of lines will appear in the Terminal window like this:

        Test started
            Part 1 of 4 done at: … sec
            …
            Part 4 of 4 done at: … sec
        The test results are on the Clipboard.
        Please close this window.

    The intervals between parts won't be exactly equal, but they give a rough indication of progress.

    Wait for the final message "Please close this window" to appear—again, usually within a few minutes. If you don't see that message within about 30 minutes, the test probably won't complete in a reasonable time. In that case, press the key combination control-C or command-period to stop it. Then go to the next step. You'll have incomplete results, but still something.

    In order to get results, the test must either be allowed to complete or else manually stopped as above. If you close the Terminal window while the test is still running, the partial results won't be saved.

    11. When the test is complete, or if you stopped it manually, quit Terminal. The results will have been saved to the Clipboard automatically. They are not shown in the Terminal window. Please don't copy anything from there. All you have to do is start a reply to this comment and then paste by pressing command-V again.

    At the top of the results, there will be a line that begins with the words "Start time." If you don't see that, but instead see a mass of gibberish, you didn't wait for the "close this window" message. Please wait for it and try again.

    If any private information, such as your name or email address, appears in the results, anonymize it before posting. Usually that won't be necessary.

    12. When you post the results, you might see an error message on the web page: "You have included content in your post that is not permitted," or "The message contains invalid characters." That's a bug in the software that runs this website. Please post the test results on Pastebin, then post a link here to the page you created.

    If you have an account on Pastebin, please don't select Private from the Paste Exposure menu on the page, because then no one but you will be able to see it.

    13. When you're done with the test, it's gone. There is nothing to uninstall or clean up.

    14. This is a public forum, and others may give you advice based on the results of the test. They speak for themselves, not for me. The test itself is harmless, but whatever else you do may not be. For others who choose to run it, I don't recommend that you post the test results on this website unless I asked you to.

    15. The linked UNIX shell script bears a notice of copyright. Readers of ASC may copy it for their own personal use. Neither the whole nor any part may be redistributed.

  • by ChrisHorlacher,

    ChrisHorlacher ChrisHorlacher Jun 23, 2016 2:07 PM in response to Esquared
    Level 1 (4 points)
    Desktops
    Jun 23, 2016 2:07 PM in response to Esquared

    I downloaded from the official website so I'm pretty confident it's not a hacked version.

  • by lllaass,Solvedanswer

    lllaass lllaass Jun 24, 2016 2:35 PM in response to ChrisHorlacher
    Level 10 (190,886 points)
    Apple Watch
    Jun 24, 2016 2:35 PM in response to ChrisHorlacher

    mdworker is using a lot of CPU and it is associate with indexing for Spotlight search.

    I would reindex the storage devices

    Rebuild the Spotlight index on your Mac - Apple Support

     

    uninstall AVG antivirus since it really does no good and frequently causes problems like slowness

    https://support.avg.com/SupportArticleView?l=en_US&urlName=How-to-uninstall-AVG- AntiVirus-for-Mac

     

    remove this since it is not even loaded:

    [failed]    com.jdibackup.ZipCloud.autostart.plist (2015-09-20) Adware!  [Remove]

        [failed]    com.jdibackup.ZipCloud.notify.plist (2015-09-20) Adware!  [Remove]

  • by etresoft,

    etresoft etresoft Jun 23, 2016 10:48 PM in response to ChrisHorlacher
    Level 7 (29,380 points)
    Jun 23, 2016 10:48 PM in response to ChrisHorlacher

    Hello Chris,

    That is a legitimate EtreCheck error message - typo and all. For some reason, EtreCheck could not contact the server to download the latest adware and whitelist updates. This is one of a number of failsafes for EtreCheck's adware removal feature. I never wanted to add that feature to begin with but adware was just out of control and is getting worse. I think if you try it again later, and/or remove your 3rd party antivirus software, it may work.

     

    As lllaass says, the files in question are not loaded so they aren't doing any harm. In this case, they aren't even technically adware. They are adware bait. I have started to classify as adware any software that is closely associated with adware and has no uninstaller, no uninstallation procedure, or misleading uninstallation procedures. In this case, you may have gone to the ZipCloud web site and followed their uninstallation procedures. This is the result. It doesn't hurt anything, but it is irresponsible and it annoys me. For that, I put them on my naughty list.

     

    My suggestion would be to remove the anti-virus software, install more RAM and an SSD, and upgrade to the latest operating system.

  • by Esquared,

    Esquared Esquared Jun 24, 2016 7:30 AM in response to etresoft
    Level 6 (8,538 points)
    Mac OS X
    Jun 24, 2016 7:30 AM in response to etresoft

    FWIW: that typo was what made it look fishy to me. Especially in this kind of software it is important to avoid them (typos I mean).