Do I have a Virus or Malware?

I have had trouble with huge downloads occurring on my adsl account, I changed my password on my internet service provider but it still continues. 15 gigabits in one day & I wasn't even home. I found numerous entries in my Keychain named spark & imessage protection keys. I searched my computer & found a few Spark emails with the following attachment - x00_22569.olk14Message. I have deleted them all. I have a lot of entries in Keychain which I don't recognize & they have no password. Has anyone heard of "Spark" or know how to identify everything in Keychain? I think something like a virus or malware is using my internet connection. I don't do anything intensive when on the internet but I've used 100gig in 2 weeks. Please help.

MacBook Pro with Retina display, OS X El Capitan (10.11.6)

Posted on Apr 8, 2017 3:55 AM

Reply
20 replies

Sep 7, 2017 6:02 PM in response to printworks1

I removed AVG, Tunnelbear and GPGsuite. But I'm not sure I fixed the problem


EtreCheck version: 3.4.4 (448)

Report generated 2017-09-07 20:45:07

Download EtreCheck from https://etrecheck.com

Runtime: 2:10

Performance: Excellent


Click the [Lookup] links for more information from Apple Support Communities.

Click the [Details] links for more information about that line.

Click the [Clean up] link to delete unused files.


Problem: Other problem


Hardware Information:

MacBook Air (13-inch, Early 2014)

[Technical Specifications] - [User Guide] - [Warranty & Service]

MacBook Air - model: MacBookAir6,2

1 1.4 GHz Intel Core i5 (i5-4260U) CPU: 2-core

4 GB RAM Not upgradeable

BANK 0/DIMM0

2 GB DDR3 1600 MHz ok

BANK 1/DIMM0

2 GB DDR3 1600 MHz ok

Handoff/Airdrop2: supported

Wireless: en0: 802.11 a/b/g/n/ac

Battery: Health = Normal - Cycle count = 1049


Video Information:

Intel HD Graphics 5000 - VRAM: 1536 MB

Color LCD 1440 x 900


Disk Information:

APPLE SSD SD0256F disk0: (251 GB) (Solid State - TRIM: Yes)

[Show SMART report]

(disk0s1) <not mounted> [EFI]: 210 MB

(disk0s2) <not mounted> [CoreStorage Container]: 250.14 GB

(disk0s3) <not mounted> [Recovery]: 650 MB


USB Information:

XHCI Root Hub SS Simulation

Apple Internal Memory Card Reader

XHCI Root Hub USB 2.0 Simulation

Apple Inc. iPhone

Apple Inc. BRCM20702 Hub

Apple Inc. Bluetooth USB Host Controller


Thunderbolt Information:

Apple Inc. thunderbolt_bus


Virtual disks:

Macintosh HD (disk1 - Journaled HFS+) / [Startup]: 249.79 GB (98.86 GB free)

Physical disk: disk0s2 250.14 GB Online


System Software:

OS X Yosemite 10.10.5 (14F2109) - Time since boot: about 5 days


Configuration files:

/etc/sysctl.conf - File exists but not expected


Gatekeeper:

Mac App Store and identified developers


Clean up:

/Library/LaunchAgents/org.gpgtools.gpgmail.enable-bundles.plist

/Library/Application Support/GPGTools/uuid-patcher enable-bundles

Executable not found!

/Library/LaunchAgents/org.gpgtools.gpgmail.updater.plist

/usr/local/MacGPG2/libexec/MacGPG2_Updater.app/Contents/MacOS/MacGPG2_Updater /Library/Application Support/GPGTools/GPGMail_Updater.app/Contents/MacOS/GPGMail_Updater

Executable not found!

2 orphan files found. [Clean up]


System Launch Agents:

[not loaded] 6 Apple tasks

[loaded] 139 Apple tasks

[running] 58 Apple tasks

[killed] 9 Apple tasks

9 processes killed due to insufficient RAM


System Launch Daemons:

[not loaded] 47 Apple tasks

[loaded] 130 Apple tasks

[running] 76 Apple tasks

[killed] 8 Apple tasks

8 processes killed due to insufficient RAM


Launch Agents:

[loaded] com.google.keystone.agent.plist (Google, Inc. - installed 2017-07-10) [Lookup]

[loaded] org.gpgtools.gpgmail.enable-bundles.plist (? d032aea 0 - installed 2015-02-07) [Lookup] - /Library/Application Support/GPGTools/uuid-patcher: Executable not found!

[loaded] org.gpgtools.gpgmail.updater.plist (? 6ece8d61 0 - installed 2015-02-07) [Lookup] - /usr/local/MacGPG2/libexec/MacGPG2_Updater.app/Contents/MacOS/MacGPG2_Updater: Executable not found!


Launch Daemons:

[loaded] com.adobe.fpsaud.plist (? 2afb3af7 85012398 - installed 2017-07-24) [Lookup]

[running] com.fitbit.galileod.plist (? 7ad1c5c 186e99a1 - installed 2014-05-19) [Lookup]

[loaded] com.google.keystone.daemon.plist (Google, Inc. - installed 2017-07-27) [Lookup]

[loaded] com.microsoft.office.licensing.helper.plist (? 6d8cb30e afb3bef0 - installed 2010-08-25) [Lookup]

[loaded] com.tunnelbear.mac.tbeard.plist (TunnelBear, Inc./ - installed 2015-04-07) [Lookup]


User Launch Agents:

[running] com.spotify.webhelper.plist (Spotify - installed 2017-09-04) [Lookup]


User Login Items:

Fitbit Connect Menubar Helper Application (Fitbit, Inc. - installed 2014-09-15)

(/Applications/Fitbit Connect.app/Contents/MacOS/Fitbit Connect Menubar Helper.app)

iTunesHelper Application (? 0 - installed 2017-03-04)

(/Applications/iTunes.app/Contents/MacOS/iTunesHelper.app)

Spotify Application - Hidden

(/Applications/Spotify.app)

Google Chrome Application - Hidden

(/Applications/Google Chrome.app)

Photo Stream URL SMLoginItem - Hidden (Apple, Inc. - installed 2014-06-28)

(/Applications/iPhoto.app/Contents/Library/LoginItems/PhotoStreamAgent.app)


Internet Plug-ins:

FlashPlayer-10.6: 26.0.0.151 (installed 2017-08-08) [Lookup]

QuickTime Plugin: 7.7.3 (installed 2017-03-04)

AdobePDFViewerNPAPI: 11.0.07 (installed 2014-05-08) [Lookup]

AdobePDFViewer: 11.0.07 (installed 2014-05-08) [Lookup]

Flash Player: 26.0.0.151 (installed 2017-08-08) [Lookup]

Default Browser: 600 (installed 2015-09-20)

o1dbrowserplugin: 5.41.3.0 (installed 2015-12-16) [Lookup]

SharePointBrowserPlugin: 14.0.0 (installed 2010-08-25) [Lookup]

googletalkbrowserplugin: 5.41.3.0 (installed 2015-12-11) [Lookup]

Silverlight: 5.1.30514.0 (installed 2014-12-19) [Lookup]


Safari Extensions:

Pin It Button - Pinterest, Inc. - http://www.pinterest.com/ (installed 2015-07-04)

Save to Pocket - Read It Later, Inc. - http://getpocket.com/ (installed 2015-11-10)

Grammarly for Safari - Grammarly - https://www.grammarly.com (installed 2017-08-14)


3rd Party Preference Panes:

Flash Player (installed 2017-07-24) [Lookup]


Time Machine:

Time Machine not configured!


Top Processes by CPU:

106% Safari

51% mdworker

50% mdworker

46% syncdefaultsd

37% Google Chrome Helper


Top Processes by Memory:

574 MB kernel_task

256 MB Safari

182 MB Google Chrome Helper

162 MB Google Chrome

148 MB Google Chrome Helper


Top Processes by Energy Use:

38.28 com.apple.WebKit.WebContent

34.14 com.apple.WebKit.WebContent

26.06 com.apple.WebKit.Networking

11.86 Safari

7.66 WindowServer


Virtual Memory Information:

895 MB Available RAM

80 MB Free RAM

3.13 GB Used RAM

814 MB Cached files

162 MB Swap Used



Diagnostics Information:

2017-09-07 20:33:26 quicklookd.app Crash [Open]

Cause: qlmanage --diag 6571367.8521628 6571367.8354419 6571367.8522581

last generator in main thread: com.apple.qlgenerator.office

last threaded generator: com.apple.qlgenerator.image

2017-09-07 20:21:11 SecurityAgent Crash [Open]

Cause: objc_msgSend() selector name: setContextValue:flags:forKey:

Performing @selector(changeClicked:) from sender NSButton 0x7ffb1ad120a0

Sep 7, 2017 6:23 PM in response to seliwe

There are orphaned GPG tools launch agents to remove. You can see those under the Clean Up section. Run EtreCheck again and click the [Clean up] link to remove them.


Don't know what's going on with Safari's heavy use of system resources. That isn't normal, though a restart should clear it.


Google is killing your system. Besides Chrome itself, it is running four other processes for itself. That google.keystone.agent? That's Google collecting marketing data on your computer usage the entire time your Mac is running. It does that whether Chrome itself is running or not. Seriously, remove anything to do with Google from your Mac. Delete Chrome, then go to the LaunchServices and LaunchDaemons folders in your account and the main Library folders. Delete every Google agent or daemon file you see in the report. There's also a GoogleTalk browser extension. Probably in Safari. Kill it.


A tunnelbear agent is still running. You'll find that in one of the LaunchDaemons folder, too. Remove it.


Restart after putting all of these agents and daemons in the trash.


This will help a lot, but your main problem is still mainly lack of RAM. 4GB simply isn't sufficient. Unfortunately, you also can't upgrade the RAM in a MacBook Air. All you can really do is keep installed software as lean as possible.

Sep 8, 2017 8:12 AM in response to seliwe

Safari/Preferences/Advanced - enable the Develop menu, then go there and Empty Caches. Quit/reopen Safari and test. Then try Safari/History/Show History and delete all history items. Quit/reopen Safari and test. You can also try try Safari/Clear History…. The down side is it clears all cookies. Doing this may cause some sites to no longer recognize your computer as one that has visited the web site. Go to Finder and select your user/home folder. With that Finder window as the front window, either select Finder/View/Show View options or go command - J. When the View options opens, check ’Show Library Folder’. That should make your user library folder visible in your user/home folder. Select Library/Caches/com.apple.Safari/Cache.db and move it to the trash.


Go to Safari Preferences/Extensions and turn all extensions off. Test. If okay, turn the extensions on one by one until you figure out what extension is causing the problem.


Safari Corruption See post by Linc Davis


Safari Reset

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Do I have a Virus or Malware?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.