How to prevent transfer of malware when transferring content

I have an old MacBook Pro that I am 99% certain has been infected with malware. I have purchased a new iMac and want to transfer working files, such as documents, music, image files, videos, etc. How do I ensure that I am not transferring any unknown program or script files that may be part of the malware infection?

iMac (Retina 5K, 27-inch, 2017), iOS 11.2.5

Posted on Feb 1, 2018 6:20 PM

Reply
3 replies

Feb 1, 2018 6:33 PM in response to Ken_Howard

Why don't you run the following diagnostic program on the old Macbook Pro - it should find anything that shouldn't be there. Copy and then paste the entire report here so we can have a look.


http://etrecheck.com


You can then also run Malwarebytes which would find and remove such stuff.


Malwarebytes | Malwarebytes for Mac


And no, as far as I know, there is no way to ensure that you're not transferring malware unless you do not transfer anything, erase your hard drive and do a fresh factory install via recovery.

Feb 2, 2018 8:15 PM in response to Ken_Howard

OK. I did the EtreCheck. I see for one thing that that ****** CleanMyMac program is still on there - even though I had the Genius Bar supposedly remove that a couple of years ago. I also need to take off the old Parallels program as that doesn't work with current OS and I don't need anyway.


EtreCheck version: 3.4.6 (460)

Report generated 2018-02-02 21:55:41

Download EtreCheck from https://etrecheck.com

Runtime: 8:03

Performance: Below Average


Click the [Lookup] links for more information from Apple Support Communities.

Click the [Details] links for more information about that line.


Problem: Computer is too slow

Description:

Everything takes at least dozens of seconds to execute. Even simple acts like opening a file on the computer that has no Internet functions creates beach balling for 20-30 seconds and the Activity Monitor shows that the computer is pinging an IP address during that time. I suspect a malware infection of some type.


Hardware Information: ⓘ

MacBook Pro (15-inch, Mid 2010)

[Technical Specifications] - [User Guide] - [Warranty & Service]

MacBook Pro - model: MacBookPro6,2

1 2.53 GHz Intel Core i5 (i5) CPU: 2-core

4 GB RAM Upgradeable - [Instructions]

BANK 0/DIMM0

2 GB DDR3 1067 MHz ok

BANK 1/DIMM0

2 GB DDR3 1067 MHz ok

Handoff/Airdrop2: not supported

Wireless: en1: 802.11 a/b/g/n

Battery: Health = Normal - Cycle count = 1


Video Information: ⓘ

Intel HD Graphics - VRAM: 288 MB

NVIDIA GeForce GT 330M - VRAM: 256 MB

Color LCD 1680 x 1050

SyncMaster 1920 x 1080 @ 60 Hz


Disk Information: ⓘ

Hitachi HTS725050A9A362 disk0: (500.11 GB) (Rotational)

[Show SMART report]

(disk0s1) <not mounted> [EFI]: 210 MB

Macintosh HD (disk0s2 - Journaled HFS+) / [Startup]: 478.49 GB (126.71 GB free)

(disk0s3) <not mounted> [Recovery]: 650 MB

BOOTCAMP (disk0s4 - MS-DOS FAT32) /Volumes/BOOTCAMP : 20.76 GB (20.75 GB free)


MATSHITADVD-R UJ-898 ()


USB Information: ⓘ

USB20Bus

hub_device

Seagate FreeAgent GoFlex

Apple Card Reader

Apple Inc. Apple Internal Keyboard / Trackpad

Apple Inc. BRCM2070 Hub

Apple Inc. Bluetooth USB Host Controller

USB20Bus

hub_device

VIA Labs, Inc. USB2.0 Hub

Apple, Inc. Keyboard Hub

Apple, Inc Apple Keyboard

Logitech USB Receiver

HD Webcam C615

Apple Computer, Inc. IR Receiver

Apple Inc. Built-in iSight


Virtual disks: ⓘ

FreeAgent GoFlex Drive (disk1s2 - Case-sensitive Journaled HFS+) /Volumes/FreeAgent GoFlex Drive : 499.76 GB (80.71 GB free)

Physical disk: FreeAgent GoFlex 499.76 GB (80.71 GB free)


System Software: ⓘ

OS X El Capitan 10.11.6 (15G1611) - Time since boot: about 5 hours


Configuration files: ⓘ

/etc/sudoers, File size 1383 but expected 2299


Gatekeeper: ⓘ

Mac App Store and identified developers


Kernel Extensions: ⓘ

/Library/Extensions

[loaded] com.Logitech.Control Center.HID Driver (3.9.1 - SDK 10.8) [Lookup]

[loaded] com.avira.kext.FileAccessControl (1.2.5 - SDK 10.9) [Lookup]


/System/Library/Extensions

[loaded] com.Logitech.Unifying.HID Driver (1.3.0 - SDK 10.6) [Lookup]

[not loaded] com.lge.driver.LGEADMobilSolutionFamily (1.6.0.0604) [Lookup]

[loaded] com.rim.driver.BlackBerryUSBDriverInt (0.0.68) [Lookup]

[not loaded] com.rim.driver.BlackBerryUSBDriverVSP (0.0.68) [Lookup]

[not loaded] com.sierrawireless.driver.SierraDIPSupport (1.0.0.7) [Lookup]

[not loaded] com.sierrawireless.driver.SierraFSRSupport (3.0.0.3 - SDK 10.6) [Lookup]

[not loaded] com.sierrawireless.driver.SierraHSRSupport (3.0.0.18 - SDK 10.6) [Lookup]

[not loaded] com.sierrawireless.driver.SierraIPDirect (1.1.5) [Lookup]

[loaded] com.webroot.driver.WebrootSecureAnywhere (8.0.4 - SDK 10.7) [Lookup]


/System/Library/Extensions/LGEADMobileSolutionFamily.kext/Contents/PlugIns

[not loaded] com.lge.driver.LGELTEADBus (1.6.0.0604) [Lookup]

[not loaded] com.lge.driver.LGELTEADMdmControl (1.6.0.0604) [Lookup]

[not loaded] com.lge.driver.LGELTEADMdmData (1.6.0.0604) [Lookup]

[not loaded] com.lge.driver.LGELTEADMsc (1.6.0.0604) [Lookup]

[not loaded] com.lge.driver.LGELTEADNicControl (1.6.0.0604) [Lookup]

[not loaded] com.lge.driver.LGELTEADNicData (1.6.0.0604) [Lookup]


Startup Items: ⓘ

ParallelsDesktopTransporter: Path: /Library/StartupItems/ParallelsDesktopTransporter

Startup items no longer function in OS X Yosemite or later


System Launch Agents: ⓘ

[not loaded] 9 Apple tasks

[loaded] 161 Apple tasks

[running] 48 Apple tasks

[killed] 21 Apple tasks

21 processes killed due to insufficient RAM


System Launch Daemons: ⓘ

[not loaded] 44 Apple tasks

[loaded] 161 Apple tasks

[running] 74 Apple tasks

[killed] 11 Apple tasks

11 processes killed due to insufficient RAM


Launch Agents: ⓘ

[running] com.AT&T.attcm_AppStart.plist (? 7352b384 5294abbf - installed 2015-08-22) [Lookup]

[running] com.Logitech.Control Center.Daemon.plist (Logitech Inc. - installed 2015-08-22) [Lookup]

[failed] com.adobe.ARMDCHelper.cc24aef4a1b90ed56a725c38014c95072f92651fb65e1bf9c8e43c37a 23d420d.plist (Adobe Systems, Inc. - installed 2017-01-13) [Lookup]

[running] com.avast.osx.secureline.update-agent.plist (AVAST Software a.s. - installed 2017-10-24) [Lookup]

[loaded] com.avast.osx.secureline.userinit.plist (Shell Script 2fc1004f - installed 2017-10-24) [Lookup]

[loaded] com.avira.antivirus.general.agent.plist (? 94ca9a28 6432bf62 - installed 2018-02-02) [Lookup]

[loaded] com.avira.antivirus.gjallarhorn.plist (Avira Operations GmbH & Co. KG - installed 2017-12-21) [Lookup]

[not loaded] com.avira.antivirus.iris.plist (Avira Operations GmbH & Co. KG - installed 2017-12-13) [Lookup]

[loaded] com.avira.antivirus.notifications.agent.plist (? 8b13021d 6432bf62 - installed 2018-02-02) [Lookup]

[loaded] com.avira.antivirus.odscan.default.plist (? 29513e6b 6432bf62 - installed 2018-02-02) [Lookup]

[loaded] com.avira.antivirus.scheduler.agent.plist (? 4b765eec 6432bf62 - installed 2018-02-02) [Lookup]

[running] com.avira.antivirus.systray.plist (? 9bf80dc3 fd30d462 - installed 2018-02-02) [Lookup]

[loaded] com.avira.antivirus.telemetry.agent.plist (? a4625078 6432bf62 - installed 2018-02-02) [Lookup]

[loaded] com.avira.antivirus.update.default.plist (? 7dca32a5 6432bf62 - installed 2018-02-02) [Lookup]

[running] com.avira.helper.avstats.plist (? cf66ea88 a28384e2 - installed 2017-12-21) [Lookup]

[loaded] com.avira.servicehub.license.plist (Avira Operations GmbH & Co. KG - installed 2017-12-22) [Lookup]

[loaded] com.avira.servicehub.license.poll.plist (Avira Operations GmbH & Co. KG - installed 2017-12-22) [Lookup]

[loaded] com.google.keystone.agent.plist (Google, Inc. - installed 2017-09-27) [Lookup]

[running] com.hp.productresearch.plist (? 86e3d2b 93f36112 - installed 2013-08-11) [Lookup]

[loaded] com.oracle.java.Java-Updater.plist (? 3e0658c9 72ac4dde - installed 2017-10-01) [Lookup]

[running] com.parallels.mobile.prl_deskctl_agent.launchagent.plist (Parallels, Inc. - installed 2017-05-05) [Lookup]

[running] com.rosettastone.rosettastonedaemon.plist (Rosetta Stone Ltd. - installed 2016-09-23) [Lookup]

[running] com.sierrawireless.SwitchTool.plist (? f4fe8c02 a6f391e6 - installed 2012-02-02) [Lookup]

[running] com.webroot.WRMacBackNSync.plist (? 5d873754 c1efcaec - installed 2014-10-29) [Lookup]

[loaded] org.macosforge.xquartz.startx.plist (Apple Inc. - XQuartz - installed 2012-09-27) [Lookup]


Launch Daemons: ⓘ

[loaded] com.adobe.ARMDC.Communicator.plist (Adobe Systems, Inc. - installed 2017-01-13) [Lookup]

[loaded] com.adobe.ARMDC.SMJobBlessHelper.plist (Adobe Systems, Inc. - installed 2017-01-13) [Lookup]

[loaded] com.adobe.fpsaud.plist (Adobe Systems, Inc. - installed 2017-12-14) [Lookup]

[loaded] com.avast.osx.secureline.init.plist (Shell Script 1bda83b1 - installed 2017-10-24) [Lookup]

[loaded] com.avast.osx.secureline.uninstall.plist (Shell Script ba7a0061 - installed 2017-10-24) [Lookup]

[loaded] com.avast.osx.secureline.update.plist (Shell Script f50a649c - installed 2017-10-24) [Lookup]

[loaded] com.avira.antivirus.dbcleaner.plist (? 223cb974 36910734 - installed 2018-02-02) [Lookup]

[running] com.avira.helper.watchdox.plist (? e7e538d1 e163ec4c - installed 2018-02-02) [Lookup]

[loaded] com.google.keystone.daemon.plist (Google, Inc. - installed 2017-10-12) [Lookup]

[loaded] com.macpaw.CleanMyMac2.Agent.plist (MacPaw Inc. - installed 2014-12-14) [Lookup]

[loaded] com.malwarebytes.HelperTool.plist (Malwarebytes Corporation - installed 2016-09-30) [Lookup]

[loaded] com.microsoft.autoupdate.helper.plist (Microsoft Corporation - installed 2017-04-15) [Lookup]

[loaded] com.microsoft.office.licensing.helper.plist (? 6d8cb30e 442fdde9 - installed 2011-03-10) [Lookup]

[loaded] com.microsoft.office.licensingV2.helper.plist (Microsoft Corporation - installed 2015-10-08) [Lookup]

[loaded] com.oracle.java.Helper-Tool.plist (Shell Script e3fefdd2 - installed 2017-07-22) [Lookup]

[running] com.parallels.mobile.dispatcher.launchdaemon.plist (Parallels, Inc. - installed 2017-05-05) [Lookup]

[loaded] com.parallels.mobile.kextloader.launchdaemon.plist (Apple, Inc. - installed 2017-05-05)

[loaded] com.sharpcast.xfsmond.plist (? 72832b94 0 - installed 2013-05-08) [Lookup]

[running] com.webroot.security.mac.plist (Webroot Software, Inc. - installed 2014-10-29) [Lookup]

[running] com.webroot.webfilter.mac.plist (Webroot Software, Inc. - installed 2014-10-29) [Lookup]

[loaded] org.macosforge.xquartz.privileged_startx.plist (Apple Inc. - XQuartz - installed 2012-09-27) [Lookup]


User Launch Agents: ⓘ

[loaded] com.adobe.ARM.[...].plist (? 56ebbe7d b8887e79 - installed 2013-05-19) [Lookup]

[loaded] com.avast.osx.secureline.home.userinit.plist (Shell Script 627a0783 - installed 2017-10-24) [Lookup]

[loaded] com.citrixonline.GoToMeeting.G2MUpdate.plist (Citrix Online LLC - installed 2016-04-06) [Lookup]

[loaded] com.facebook.videochat.[redacted].plist (Apple, Inc. - installed 2015-10-28)

[loaded] com.macpaw.CleanMyMac2Helper.diskSpaceWatcher.plist (MacPaw Inc. - installed 2015-08-22) [Lookup]

[loaded] com.macpaw.CleanMyMac2Helper.scheduledScan.plist (MacPaw Inc. - installed 2015-08-22) [Lookup]

[loaded] com.macpaw.CleanMyMac2Helper.trashWatcher.plist (MacPaw Inc. - installed 2015-08-22) [Lookup]

[loaded] com.parallels.mobile.startgui.launchagent.plist (Parallels, Inc. - installed 2017-05-07) [Lookup]


User Login Items: ⓘ

iTunesHelper Application (Apple, Inc. - installed 2017-07-28)

(/Applications/iTunes.app/Contents/MacOS/iTunesHelper.app)

Firefox Application

(/Applications/Firefox.app)

HP Device Monitor SMLoginItem - Hidden (? 0 - installed 2015-07-05)

(/Library/Printers/hp/Utilities/HP Utility.app/Contents/Library/LoginItems/HP Device Monitor.app/Contents/Library/LoginItems/HP Device Monitor.app)

HP Device Monitor SMLoginItem - Hidden (? 0 - installed 2015-07-05)

(/Library/Printers/hp/Utilities/HP Utility.app/Contents/Library/LoginItems/HP Device Monitor.app)

6H4HRTU5E3.com.avast.osx.secureline.avastsecurelinehelper SMLoginItem - Hidden (AVAST Software a.s. - installed 2017-10-20)

(/Applications/AvastSecureLine.app/Contents/Library/LoginItems/6H4HRTU5E3.com.a vast.osx.secureline.avastsecurelinehelper.app)


Internet Plug-ins: ⓘ

Default Browser: 601 (installed 2016-10-10)

Flip4Mac WMV Plugin: 3.3.7.2 (installed 2015-12-28) [Lookup]

OfficeLiveBrowserPlugin: 12.3.2 (installed 2011-12-19) [Lookup]

npwebroot: 2.0.15 (installed 2014-10-29) [Lookup]

AdobePDFViewerNPAPI: 17.012.20098 (installed 2017-12-02) [Lookup]

FlashPlayer-10.6: 28.0.0.137 (installed 2018-01-09) [Lookup]

Silverlight: 5.1.41212.0 (installed 2016-03-02) [Lookup]

QuickTime Plugin: 7.7.3 (installed 2017-07-28)

Flash Player: 28.0.0.137 (installed 2018-01-09) [Lookup]

iPhotoPhotocast: 7.0 (installed 2010-07-30)

SharePointBrowserPlugin: 14.7.3 (installed 2017-04-15) [Lookup]

AdobePDFViewer: 18.009.20050 (installed 2017-12-02) [Lookup]

JavaAppletPlugin: Java 8 Update 144 build 01 (installed 2017-10-01) Check version


User internet Plug-ins: ⓘ

CitrixOnlineWebDeploymentPlugin: 1.0.105 (installed 2013-04-25) [Lookup]

WebEx64: 1.0 (installed 2015-08-11) [Lookup]


Safari Extensions: ⓘ

[disabled] Password Management - Webroot - http://webroot.com (installed 2013-10-09)

[disabled] Open in Internet Explorer - Parallels - http://www.parallels.com (installed 2014-02-17)

[disabled] DivX Plus Web Player HTML5 <video> - DivX, Inc. - http://www.divx.com/en/software/divx-plus/web-player/ (installed 2011-04-15)

[disabled] DivX HiQ - DivX, Inc. - http://www.divx.com/en/software/divx-plus/web-player/ (installed 2011-04-15)

[disabled] Avast Online Security - AVAST Software - http://www.avast.com (installed 2015-03-04)


3rd Party Preference Panes: ⓘ

Flash Player (installed 2017-12-14) [Lookup]

Flip4Mac WMV (installed 2015-12-28) [Lookup]

Java (installed 2017-10-01) [Lookup]

Logitech Control Center (installed 2015-08-22) [Lookup]

MacFUSE (installed 2010-09-16) [Lookup]


Time Machine: ⓘ

Skip System Files: NO

Mobile backups: ON

Auto backup: YES

Volumes being backed up:

Macintosh HD: Disk size: 478.49 GB Disk used: 351.77 GB

Destinations:

FreeAgent GoFlex Drive [Local]

Total size: 499.76 GB

Total number of backups: 9

Oldest backup: 10/25/15, 8:48 PM

Last backup: 2/2/18, 9:40 PM

Size of backup disk: Too small

Backup size 499.76 GB < (Disk used 351.77 GB X 3)


Top Processes by CPU: ⓘ

7% WindowServer

7% firefox

6% kernel_task

5% Microsoft Excel

3% com.hp.devicemonitor


Top Processes by Memory: ⓘ

509 MB kernel_task

175 MB firefox

137 MB plugin-container

77 MB Finder

39 MB savapi


Top Processes by Energy Use: ⓘ

10.10 WindowServer

9.10 firefox

8.94 Microsoft Excel

5.02 com.hp.devicemonitor


Virtual Memory Information: ⓘ

1.19 GB Available RAM

47 MB Free RAM

2.81 GB Used RAM

1.14 GB Cached files

39 MB Swap Used


Software installs (last 30 days): ⓘ

Adobe Flash Player: (installed 2018-01-09)


Install information may not be complete.


Diagnostics Events (last 3 days for minor events): ⓘ

2018-02-02 15:39:40 Finder.app Crash [Open]

2018-01-31 15:20:06 Firefox.app Hang [Open]

Feb 2, 2018 9:33 PM in response to Ken_Howard

1. You are running a newer OS on only the very minimum 4 GB RAM and you have a very slow 5400 rpm hard drive, both of which will contribute to the slowness.


2. You should really uninstall CleanMyMac (go to their website and look for uninstall instructions) and all the AV software you've got (Avira and Avast).


3. Delete all the apps in your Login items - there is no need for all of them to launch at the same time; they'll launch when you need them.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

How to prevent transfer of malware when transferring content

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.