Backdoor Virus attack

I use the stock market feature on the MAC-OS Hi-Sierra menu bar and a few minutes ago I clicked to see how the market was doing, and I clicked on the symbol for JM Smucker (on my list of interested stocks) and when you do that, Yahoo! brings up the days quote and other info in safari. Looking at this, all of a sudden I get two warning messages on top of each other, one about a backdoor virus (don't ignore or something like that) and I don't remember, and then my screen starts to fill up with small icons appearing right to left, top to bottom and pushing my HD icon to the left but not other icons I leave on the desktop, and I immediately hit the computer switch to shut down. I did not know what was happening and I wasn't going to wait as this did not look ok. When I restarted the dialog box that came up asked if I wanted to reopen the program that was open (Safari) and I clicked no. The desktop had some 90 of these icons, 2 bytes and all were trashed and emptied. It appears that everything is OK, software works, nothing in my download folder.


I do not believe I clicked on anything while I moved my pointer about the Yahoo! page. But maybe this is some trick when passing over something. Things went so fast I have myself programed to abort at trouble and so don't have recall on all that I saw. Anyone in the community have any insight to this situation? A harmless elaborate ad that I did not let finish or something mean?

iMac, macOS High Sierra (10.13.5), 8GB on 27" 2GB on 17"

Posted on Jun 11, 2018 11:54 AM

Reply
Question marked as Top-ranking reply

Posted on Jun 11, 2018 9:45 PM

First of all, disable pop-ups in Safari: Preferences (for Safari) -> Security -> tick "Block pop-up windows". Secondly, these warnings are scams designed to trick you into installing malware (usually adware). Simply close those browser windows / tabs or force quit Safari if it happens again and check for adware (e.g. by using a free tool by Malwarebytes). There are more extensive user tips on such "warnings" and how to deal with them if you search support communities.

Similar questions

7 replies
Question marked as Top-ranking reply

Jun 11, 2018 9:45 PM in response to Charles Palenz

First of all, disable pop-ups in Safari: Preferences (for Safari) -> Security -> tick "Block pop-up windows". Secondly, these warnings are scams designed to trick you into installing malware (usually adware). Simply close those browser windows / tabs or force quit Safari if it happens again and check for adware (e.g. by using a free tool by Malwarebytes). There are more extensive user tips on such "warnings" and how to deal with them if you search support communities.

Jun 11, 2018 9:53 PM in response to Charles Palenz

Also hold down the Shift key the next time you launch Safari.


To check to see if there were any malware/adware installed download and run Etrecheck. Copy and paste the results into your reply. Etrecheck is a diagnostic tool that was developed by one of the most respected users here in the ASC and recommended by Apple Support to provide a snapshot of the system and help identify the more obvious culprits that can adversely affect a Mac's performance.


User uploaded file

Jun 12, 2018 6:35 AM in response to Old Toad

Ran Etrecheck and results below.

Looks like I'm clean of malware. Two crashing software, one is "SmartwareDriveService" a .exe file which I suppose should be deleted (I think its installed when I acquired one of my Western Digital HDs) and the other "SIMBL Agent.app" is from 2011, don't know what that is and maybe can be deleted too (its in the library, scripting). Stuffit version I have no longer runs under High Sierra (incompatible and I haven't deleted). The section labeled "user login items" in the report the only one I use is audio-hijack and the others are not. So I'm not sure what they are doing if anything.


Appreciate any suggestions.


Thank you OT


EtreCheck version: 4.3.2 (4D034)

Report generated: 2018-06-12 08:53:47

Download EtreCheck from https://etrecheck.com

Runtime: 3:50

Performance: Good

Problem: No problem - just checking

Major Issues: None

Minor Issues:

These issues do not need immediate attention but they may indicate future problem

Apps crashing - There have been numerous app crashes.

Clean up - There are orphan files that could be removed.

Small backup drive - Time Machine backup drive is too small.

Unsigned files - There is unsigned software installed. They appear to be legitimate

Vintage hardware - This machine may be considered vintage.

32-bit Apps - This machine has 32-bits apps that may have problems in the future.

Hardware Information:

iMac (27-inch, Mid 2010) - Vintage!

iMac Model: iMac11,3

1 2.93 GHz Intel Core i7 (i7) CPU: 4-core

8 GB RAM - Upgradeable

BANK 0/DIMM0 - 2 GB DDR3 1333 ok

BANK 1/DIMM0 - 2 GB DDR3 1333 ok

BANK 0/DIMM1 - 2 GB DDR3 1333 ok

BANK 1/DIMM1 - 2 GB DDR3 1333 ok

Video Information:

ATI Radeon HD 5750 - VRAM: 1024 MB

iMac 2560 x 1440

Drives:

disk0 - Hitachi HDS722020ALA330 2.00 TB (Mechanical)

Internal SATA 3 Gigabit Serial ATA

disk0s1 - EFI (MS-DOS FAT32) [EFI] 210 MB

disk0s2 - Macintosh HD (Journaled HFS+) 2.00 TB

disk0s3 - Recovery HD (Journaled HFS+) [Recovery] 650 MB

disk1 - Western Digital My Book 1.00 TB

External USB 480 Mbit/s

disk1s1 [Partition Map] 32 KB

disk1s3 - P*******0 (HFS+) 1.00 TB

disk2 - WD 2.00 TB

External FireWire

disk2s1 [Partition Map] 32 KB

disk2s3 - P********B (Journaled HFS+) 2.00 TB

Mounted Volumes:

disk0s2 - Macintosh HD 2.00 TB (931.91 GB free)

Journaled HFS+

Mount point: /

disk1s3 - P*******0 1.00 TB (458.72 GB free)

HFS+

Mount point: /Volumes/P*******0

disk2s3 - P********B 2.00 TB (2.25 GB free)

Journaled HFS+

Mount point: /Volumes/P********B

Network:

Interface en0: Ethernet

Interface en3: iPhone

Interface fw0: FireWire

Interface en1: AirPort

802.11 a/b/g/n

One IPv4 address

Interface en2: Bluetooth PAN

System Software:

macOS High Sierra 10.13.5 (17F77)

Time since boot: Less than an hour

System Load: 1.49 (1 min ago) 1.40 (5 min ago) 0.98 (15 min ago)

Security:

System Status

Gatekeeper Mac App Store and identified developers

System Integrity Protection Enabled

Unsigned Files:

Launchd: /Library/LaunchDaemons/com.westerndigital.WD-Drive-Manager-Installer

Executable: /Library/PrivilegedHelperTools/com.westerndigital.WD-Drive-Manager

Details: Exact match found in the whitelist - probably OK

Launchd: ~/Library/LaunchAgents/com.citrixonline.GoToMeeting.G2MUpdate.plist

Executable: ~/Library/Application Support/CitrixOnline/GoToMeeting/G2MUpdate

Details: Exact match found in the whitelist - probably OK

Launchd: /Library/LaunchDaemons/com.wdc.SmartwareDriveService.plist

Executable: /Library/Application Support/WD SmartWare Services/SmartwareDriv

Details: Exact match found in the whitelist - probably OK

Launchd: /Library/LaunchDaemons/com.microsoft.office.licensing.helper.plist

Executable: /Library/PrivilegedHelperTools/com.microsoft.office.licensing.helper

Details: Exact match found in the whitelist - probably OK

Launchd: /Library/LaunchAgents/com.brother.LOGINserver.plist

Executable: /Library/Printers/Brother/Utilities/Server/LOGINserver.app/Contents/M

Details: Exact match found in the whitelist - probably OK

Launchd: /Library/LaunchDaemons/com.wdc.WDSmartWareService.plist

Executable: /Library/Application Support/WD SmartWare Services/SmartwareServ

SmartwareServiceApp

Details: Exact match found in the whitelist - probably OK

Launchd: /Library/LaunchAgents/net.culater.SIMBL.Agent.plist

Executable: /Library/ScriptingAdditions/SIMBL.osax/Contents/Resources/SIMBL A

SIMBL Agent

Details: Exact match found in the whitelist - probably OK

Launchd: ~/Library/LaunchAgents/com.apple.SafariBookmarksSyncer.plist

Executable: /Applications/Safari.app/Contents/SafariSyncClient.app/Contents/Mac

com.apple.Safari --entitynames com.apple.bookmarks.Bookmark,com.apple.bookmarks

Details: Exact match found in the whitelist - probably OK

Launchd: /Library/LaunchDaemons/com.macromates.auth_server.plist

Executable: /Library/PrivilegedHelperTools/com.macromates.auth_server

Details: Exact match found in the whitelist - probably OK

Launchd: /Library/LaunchDaemons/com.wdc.WDPrivilegedHelper.plist

Executable: /Library/PrivilegedHelperTools/com.wdc.WDPrivilegedHelper

Details: Exact match found in the whitelist - probably OK

32-bit Applications:

168 32-bit apps

Kernel Extensions:

/Library/Application Support/Roxio

[Not Loaded] TDIXController.kext (2.0)

/System/Library/Extensions

[Not Loaded] CDSDAudioCaptureSupport.kext (1.5)

[Not Loaded] HotSync Classic Seize.kext (3.2.1)

[Not Loaded] Seagate Storage Driver.kext (5.0.1)

/System/Library/Extensions/Seagate Storage Driver.kext/Contents/PlugIns

[Not Loaded] SeagateLeafPowSecDriver_10_4.kext (5.0.1)

[Not Loaded] SeagateLeafPowSecDriver_10_5.kext (5.0.1)

[Not Loaded] SeagateDriveIcons.kext (5.0.1)

System Launch Agents:

[Not Loaded] 8 Apple tasks

[Loaded] 170 Apple tasks

[Running] 114 Apple tasks

[Other] One Apple task

System Launch Daemons:

[Not Loaded] 36 Apple tasks

[Loaded] 185 Apple tasks

[Running] 114 Apple tasks

[Other] One Apple task

Launch Agents:

[Loaded] com.microsoft.update.agent.plist (Microsoft Corporation - installed 2

[Other] com.seagate.SeagateStorageGauge.plist (? 502453cc - installed 20

[Loaded] com.google.keystone.agent.plist (Google, Inc. - installed 2018-02-03

[Running] com.brother.LOGINserver.plist (? a1772de2 - installed 2015-11-09)

[Not Loaded] net.culater.SIMBL.Agent.plist (? 850e6250 - installed 2011-08-25)

Launch Daemons:

[Loaded] com.apple.aelwriter.plist (Apple - installed 2010-08-17)

[Loaded] com.microsoft.autoupdate.helper.plist (Microsoft Corporation - installed

[Loaded] com.bombich.ccchelper.plist (Bombich Software, Inc. - installed 2017-0

[Loaded] com.macromates.auth_server.plist (? 65a04e5e - installed 2015-05-05)

[Loaded] com.wdc.WDPrivilegedHelper.plist (? 9f7f4405 - installed 2017-12-27)

[Loaded] com.bombich.ccc.plist (? 41245744 - installed 2015-01-05)

[Loaded] com.wdc.SmartwareDriveService.plist (? b71286b - installed 2013-11-1

[Loaded] com.malwarebytes.HelperTool.plist (Malwarebytes Corporation - installe

[Loaded] com.westerndigital.WD-Drive-Manager-Installer.plist (? b8f7fa94 - insta

[Running] com.wdc.WDSmartWareService.plist (? dbb7e753 - installed 2013-11-1

[Loaded] com.adobe.fpsaud.plist (Adobe Systems, Inc. - installed 2018-06-01)

[Loaded] com.microsoft.office.licensing.helper.plist (? 6d8cb30e - installed 2010-

[Loaded] com.google.keystone.daemon.plist (Google, Inc. - installed 2018-03-05

[Loaded] com.rogueamoeba.instanton-agent.plist (Rogue Amoeba Software, LLC

User Launch Agents:

[Running] com.hp.devicemonitor.plist (HP Inc. - installed 2018-06-12)

[Loaded] com.citrixonline.GoToMeeting.G2MUpdate.plist (? 0 - installed

2014-10-17)

[Loaded] com.macpaw.CleanMyMac3.Scheduler.plist (? 0 - installed 2017-01-18

[Running] com.apple.SafariBookmarksSyncer.plist (? 0 - installed 2010-08-28)

User Login Items:

StuffItAVRDaemon Application (? - installed 2010-09-02)

(/Library/PreferencePanes/StuffIt AVR.prefPane/Contents/Resources/StuffItAVR

GetBackupAgent Application (? - installed 2011-01-02)

(/Users/***/Library/Application Support/BeLight Software/Get Backup 2/GetBack

SIMBL Agent Application (? - installed 2011-08-25)

(/Library/ScriptingAdditions/SIMBL.osax/Contents/Resources/SIMBL Agent.app)

Audio Hijack 3 Schedule Helper Application (Rogue Amoeba Software, LLC - installe

(/Library/Application Support/Audio Hijack/Audio Hijack 3 Schedule Helper.app)

Internet Plug-ins:

JavaAppletPlugin: 15.0.1 (installed 2015-01-24)

FlashPlayer-10.6: 30.0.0.113 (installed 2018-06-09)

QuickTime Plugin: 7.7.3 (installed 2018-06-11)

Flash Player: 30.0.0.113 (installed 2018-06-09)

AdobePDFViewer: 10.1.0 (installed 2011-08-16)

EPPEX Plugin: 3.0.5.0 (installed 2009-07-30)

o1dbrowserplugin: 5.41.3.0 (installed 2015-12-11)

SharePointBrowserPlugin: 14.7.7 (installed 2018-03-06)

googletalkbrowserplugin: 5.41.3.0 (installed 2015-12-11)

iPhotoPhotocast: 7.0 (installed 2012-04-07)

User Internet Plug-ins:

CitrixOnlineWebDeploymentPlugin: 1.0.105 (installed 2013-04-25)

3rd Party Preference Panes:

Flash Player (installed 2018-06-01)

Perian (installed 2011-07-23)

StuffIt AVR (installed 2010-09-02)

Time Machine:

Skip System Files: No

Mobile backups: No

Auto backup: Yes

Volumes being backed up:

Macintosh HD: Disk size: 2.00 TB - Disk used: 1.07 TB

Destinations:

P********B [Local] (Last used)

Total size: 2.00 TB

Total number of backups: 305

Oldest backup: 2012-02-08 11:27:11

Last backup: 2018-06-11 20:08:07

Top Processes by CPU:

Process (count) Source % of CPU Location

mdworker (25) Apple 9

mds_stores Apple 7

backupd Apple 5

WindowServer Apple 3

kernel_task Apple 2

Top Processes by Memory:

Process (count) Source RAM usage Location

kernel_task Apple 695 MB

mdworker (25) Apple 535 MB

mds_stores Apple 384 MB

com.apple.WebKit.WebContent

(4) Apple 325 MB

Mail Apple 131 MB

Top Processes by Network Use:

Process Source Input Output Location

Mail Apple 183 KB 8 KB

mDNSResponde

r Apple 47 KB 40 KB

apsd Apple 8 KB 9 KB

netbiosd Apple 1 KB 912 B

ocspd Apple 832 B 180 B

Top Processes by Energy Use:

Process (count) Source Energy (0-100) Location

backupd Apple 8

mds_stores Apple 6

mdworker (25) Apple 4

WindowServer Apple 3

HP Device

Monitor HP Inc. 1

Virtual Memory Information:

Available RAM 4.35

GB

Free RAM 167 MB

Used RAM 3.65

GB

Cached files 4.19

GB

Swap Used 0 B

Software Installs (past 30 days):

Name Version Install

Date

iTunes 12.7.5 2018-05-31

Gatekeeper Configuration Data 140 2018-06-03

Adobe Flash Player 30.0.0.11

3 2018-06-09

Clean up:

/Library/LaunchAgents/com.seagate.SeagateStorageGauge.plist

/Library/Application Support/Seagate/Seagate Storage Gauge.app/Contents/Ma

Executable not found

Diagnostics Information (past 7 days):

2018-06-12 08:48:46 SmartwareDriveService Crash

/Library/Application Support/WD SmartWare Services/SmartwareDriveService

2018-06-12 08:37:52 SIMBL Agent.app Crash (20 times)

/Library/ScriptingAdditions/SIMBL.osax/Contents/Resources/SIMBL Agent.app

dyld: launch, running initializers

/usr/lib/libSystem.B.dylib

End of report

Jun 12, 2018 11:38 AM in response to Charles Palenz

You've installed one of the worst offenders of Macs: CleanMyMac3.


It is a known problem and is considered akin to malware by most of us here. Uninstall it according to the developer's instructions: How to uninstall CleanMyMac 3. Knowledge Base - MacPaw


Also you have WD and Seagate drive software. Neither are needed and only hinder the macOSX's ability to manage hard drives. Uninstall all of the WD and Seagate drive software.


Rerun Etrecheck when done to verify that you've gotten all of the supporting files removed.


SIMBL is a system hack used by many apps to change the appearance of the GUI, i.e. buttons, dock color, etc. If you didn't install an app that uses it, like XtraFinder, then remove all of the SIMBL files.


You can check to see if you've removed all of the files by downloading and running Find Any File to search for any files with the application's name and/or the developer's name in the file name. For example for CleanMyMac you'd do two searches:


1 - Name contains cleanmymac

2 - Name contains macpaw


Any files that are found can be dragged from the search results window to the Desktop for deletion.


FAF can search areas that Spotlight can't like invisible folders, system folders and packages.

Jun 12, 2018 11:38 AM in response to Old Toad

Thank you. I tried CleanMyMac last year and did not like it and deleted the program a few days later, manually, only the application to trash. So using Find-any-file I found all the supporting files and deleted those. The SIMBL seems to crash every time the computer is turned on and all in the background. BBedit has files with SIMBL in the name. I don't know why it runs and crashes and generates a report which until now was unaware.

Jun 12, 2018 2:18 PM in response to Charles Palenz

FWIW I have SIMBL installed for XtraFinder and other apps and this is where I find different supporting files:

User uploaded file

You can look in similar locations to see if there are any. I don't see any associated with BBEdit. I'd remove all of the SIMBL files and see if you continue to get the crashes. If not then launch BBEdit and see if it works OK. Then reboot to see if BBEdit installed any SIMBL files that crash.k

Jun 13, 2018 2:05 PM in response to Old Toad

I'm unsure about total deleting SIMBL since the many locations. Are we suggesting I remove the SIMBL Agent.app and see if the crashes stop and nothing else is impacted? There's two daily crashes, one is labeled BBedit text document and the other is just Crash report. I suppose there is a trigger, just don't know what it might be. And I did not notice if older reports delete or if they started May 24th. Ran Malware and is clean. No Apple updates then either. Anything else I do not recall. All my old incompatible software is now deleted. I seldom run BBedit.


Using EtreCheck going to the Software and to the user Login items I found a number of login items with yellow triangles and I deleted those. I did not delete SIMBL agent since I'm uncertain that alone is the crash source trigger.

User uploaded file


User uploaded file

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Backdoor Virus attack

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.