Virus scan - Terminal

I used Terminal to check for virus and below is what I found:


gadgetllover - Pastebin.com


Please let me know what might be the problem.


Thank you!

MacBook Pro (Retina, 15-inch, Mid 2015), macOS High Sierra (10.13.6)

Posted on Aug 5, 2018 5:30 AM

Reply
Question marked as Top-ranking reply

Posted on Aug 5, 2018 12:04 PM

EtreCheck version: 4.3.6 (4D041)

Report generated: 2018-08-05 15:01:48

Download EtreCheck from https://etrecheck.com

Runtime: 4:04

Performance: Good


Problem: Computer is too slow


Major Issues:

Anything that appears on this list needs immediate attention.


No Time Machine backup - Time Machine backup not found.

Heavy CPU usage - Some processes are using an unusually high amount of CPU.

More than one antivirus app - This machine has multiple antivirus apps installed.


Minor Issues:

These issues do not need immediate attention but they may indicate future problems.


Heavy RAM usage - This machine is using a large amount of RAM.

High battery cycle count - Your battery may be losing capacity.

Clean up - There are orphan files that could be removed.

32-bit Apps - This machine has 32-bits apps that may have problems in the future.


Hardware Information:

MacBook Pro (Retina, 15-inch, Mid 2015)

MacBook Pro Model: MacBookPro11,5

1 2.8 GHz Intel Core i7 (i7-4980HQ) CPU: 4-core

16 GB RAM - Not upgradeable

BANK 0/DIMM0 - 8 GB DDR3 1600 ok

BANK 1/DIMM0 - 8 GB DDR3 1600 ok

Battery: Health = Replace Soon - Cycle count = 1684


Video Information:

AMD Radeon R9 M370X - VRAM: 2048 MB

Intel Iris Pro - VRAM: 1536 MB

Color LCD


Drives:

disk0 - APPLE SSD SM1024G 1.00 TB (Solid State - TRIM: Yes)

Internal PCI 8.0 GT/s x4 Serial ATA

disk0s1 - EFI (MS-DOS FAT32) [EFI] 210 MB

disk0s2 999.70 GB

disk1s1 - Macintosh HD (APFS) 999.70 GB (324.74 GB used)

disk1s2 - Preboot (APFS) [APFS Preboot] 999.70 GB (44 MB used)

disk1s3 - Recovery (APFS) [Recovery] 999.70 GB (1.04 GB used)

disk1s4 - VM (APFS) [APFS VM] 999.70 GB (5.37 GB used)


Mounted Volumes:

disk1s1 - Macintosh HD 999.70 GB (668.30 GB free)

APFS

Mount point: /

Encrypted


disk1s4 - VM [APFS VM] 999.70 GB (668.30 GB free)

APFS

Mount point: /private/var/vm


Network:

Interface en4: Thunderbolt Ethernet

One IPv4 address

3 IPv6 addresses

Interface en0: Wi-Fi


Interface en5: iPhone

Interface en3: Bluetooth PAN

Interface bridge0: Thunderbolt Bridge

iCloud Quota: 1.77 TB available


System Software:

macOS High Sierra 10.13.6 (17G65)

Time since boot: About 7 days

System Load: 3.25 (1 min ago) 3.64 (5 min ago) 3.83 (15 min ago)


Security:

SystemStatus
GatekeeperMac App Store and identified developers
System Integrity ProtectionEnabled


32-bit Applications:

8 32-bit apps


Kernel Extensions:

/Library/Extensions

[Loaded] MB_MBAM_Protection.kext (Malwarebytes Corporation, 3.3 - SDK 10.13)

[Loaded] SymXIPS.kext (Symantec, 8.1 - SDK 10.10)

[Loaded] SymInternetSecurity.kext (Symantec, 7.8.1 - SDK 10.11)

[Loaded] SymIPS.kext (Symantec, 7.8.1 - SDK 10.11)

[Loaded] NortonForMac.kext (Symantec, 7.8.1 - SDK 10.11)


System Launch Agents:

[Not Loaded] 8 Apple tasks
[Loaded] 154 Apple tasks
[Running] 131 Apple tasks
[Other] One Apple task


System Launch Daemons:

[Not Loaded] 37 Apple tasks
[Loaded] 168 Apple tasks
[Running] 131 Apple tasks


Launch Agents:

[Loaded] com.microsoft.update.agent.plist (Microsoft Corporation - installed 2018-07-10)
[Loaded] com.pharos.popup.plist (Pharos Systems International - installed 2017-09-03)
[Running] com.symantec.uiagent.application.NFM.plist (Symantec - installed 2017-11-10)
[Running] com.pharos.notify.plist (Pharos Systems International - installed 2017-09-03)
[Running] com.malwarebytes.mbam.frontend.agent.plist (Malwarebytes Corporation - installed 2018-05-22)


Launch Daemons:

[Loaded] com.microsoft.OneDriveUpdaterDaemon.plist (Microsoft Corporation - installed 2018-04-29)
[Running] com.symantec.symdaemon.NFM.plist (Symantec - installed 2018-07-17)
[Loaded] com.symantec.symqual.panicreporter.NFM.plist (Symantec - installed 2018-07-17)
[Running] com.malwarebytes.mbam.settings.daemon.plist (Malwarebytes Corporation - installed 2018-05-22)
[Loaded] com.microsoft.autoupdate.helper.plist (Microsoft Corporation - installed 2018-07-10)
[Loaded] com.vmware.VMMonHelper.plist (VMware, Inc. - installed 2018-06-30)
[Loaded] com.symantec.symqual.submit.NFM.plist (Symantec - installed 2018-07-17)
[Loaded] com.apple.installer.osmessagetracing.plist (Apple - installed 2018-07-04)
[Loaded] com.vmware.KextControlHelper.plist (VMware, Inc. - installed 2018-06-30)
[Running] com.malwarebytes.mbam.rtprotection.daemon.plist (Malwarebytes Corporation - installed 2018-05-22)
[Other] com.symantec.liveupdate.daemon.NFM.plist (Symantec - installed 2018-07-17)
[Running] com.pharos.psnotifyd.plist (Pharos Systems International - installed 2017-09-03)
[Loaded] com.symantec.nortonutilities.daemon.plist (Symantec - installed 2018-07-17)
[Loaded] com.symantec.symqual.detail.NFM.plist (Symantec - installed 2018-07-17)
[Loaded] com.symantec.UninstallerToolHelper.NFM.plist (Symantec - installed 2018-07-17)
[Loaded] com.symantec.SymLUHelper.NFM.plist (Symantec - installed 2018-07-17)
[Running] com.symantec.sharedsettings.NFM.plist (Symantec - installed 2018-07-17)
[Other] com.backblaze.bzserv.plist (? 317225a9 - installed 2018-04-29)
[Loaded] com.microsoft.office.licensingV2.helper.plist (Microsoft Corporation - installed 2018-04-10)
[Running] com.symantec.kexthelper.NFM.plist (Symantec - installed 2018-07-17)


User Launch Agents:

[Loaded] com.google.keystone.agent.plist (Google, Inc. - installed 2018-07-17)
[Running] com.hp.devicemonitor.plist (HP Inc. - installed 2018-08-04)
[Running] com.hp.productresearch.plist (HP Inc. - installed 2018-07-28)
[Other] com.backblaze.bzbmenu.plist (? 0 - installed 2018-05-14)


User Login Items:

Google Chrome Application (Google, Inc. - installed 2018-08-02)

(/Applications/Google Chrome.app)

iTunesHelper Application (Apple - installed 2018-07-10)

(/Applications/iTunes.app/Contents/MacOS/iTunesHelper.app)

Backup and Sync from Google Application (Google, Inc. - installed 2018-05-30)

(/Applications/Backup and Sync.app)

HP Product Research SMLoginItem (HP Inc. - installed 2018-04-29)

(/Library/Printers/hp/Utilities/HPPU Plugins/ProductImprovementStudy.hptask/Contents/Helpers/HP Product Research Manager.app/Contents/Library/LoginItems/HP Product Research.app)

HP Device Monitor SMLoginItem (HP Inc. - installed 2018-04-29)

(/Library/Printers/hp/Frameworks/HPDeviceMonitoring.framework/Versions/1.0/Help ers/HP Device Monitor Manager.app/Contents/Library/LoginItems/HP Device Monitor.app)


Internet Plug-ins:

QuickTime Plugin: (installed 2018-07-10)


3rd Party Preference Panes:

Backblaze Backup (installed 2018-04-29)


Time Machine:

Time Machine Not Configured!


Top Processes by CPU:

Process (count)Source% of CPULocation
Backup and SyncGoogle, Inc.102
Google Chrome Helper (44)Google, Inc.78
Google ChromeGoogle, Inc.14
WindowServerApple8
RTProtectionDaemonMalwarebytes Corporation4


Top Processes by Memory:

Process (count)SourceRAM usageLocation
Google Chrome Helper (45)Google, Inc.6.26 GB
kernel_taskApple1.70 GB
SymDaemonSymantec526 MB
Google ChromeGoogle, Inc.411 MB
MailApple269 MB


Top Processes by Network Use:

ProcessSourceInputOutputLocation
mDNSResponderApple41 MB4 MB
MailApple4 MB123 KB
netbiosdApple499 KB114 KB
usbmuxdApple252 KB192 KB
WhatsAppMac App Store94 KB49 KB


Top Processes by Energy Use:

Process (count)SourceEnergy (0-100)Location
Google Chrome Helper (45)Google, Inc.26
Backup and SyncGoogle, Inc.26
RTProtectionDaemonMalwarebytes Corporation12
SymDaemonSymantec11
WindowServerApple7


Virtual Memory Information:

Available RAM3.55 GB
Free RAM43 MB
Used RAM12.45 GB
Cached files3.51 GB
Swap Used3.70 GB


Software Installs (past 30 days):

NameVersionInstall Date
Microsoft AutoUpdate4.1.180705032018-07-10
iTunes12.82018-07-10
Microsoft PowerPoint for Mac16.15.180709022018-07-10
Microsoft OneNote for Mac16.15.180709022018-07-10
Microsoft Outlook for Mac16.15.180709022018-07-10
Microsoft Excel for Mac16.15.180709022018-07-10
Microsoft Word for Mac16.15.180709022018-07-10
WhatsApp0.3.332018-07-16
PassMaker2.0.12018-07-21
Norton for Mac.Universal7.8.0.34.02018-07-23
Microsoft Remote Desktop10.2.02018-07-27
Malwarebytes for Mac1.02018-07-28
Gatekeeper Configuration Data1492018-07-31


Clean up:

/Library/LaunchDaemons/com.backblaze.bzserv.plist

/Library/Backblaze.bzpkg/bzserv

Executable not found

~/Library/LaunchAgents/com.backblaze.bzbmenu.plist

/Library/Backblaze.bzpkg/bzbmenu.app/Contents/MacOS/bzbmenu

Executable not found


Diagnostics Information (past 7 days):

2018-08-04 15:49:02 HP Device Monitor.app Crash

/Library/Printers/hp/Frameworks/HPDeviceMonitoring.framework/Versions/1.0/Helper s/HP Device Monitor Manager.app/Contents/Library/LoginItems/HP Device Monitor.app

*** Terminating app due to uncaught exception 'NSGenericException', reason: '*** Collection <__NSArrayM: 0x7fd71363dd10> was mutated while being enumerated.'

terminating with uncaught exception of type NSException

abort() called


2018-08-03 23:52:16 Backup and Sync.app CPU (2 times)

/Applications/Backup and Sync.app



End of report

6 replies
Question marked as Top-ranking reply

Aug 5, 2018 12:04 PM in response to BobTheFisherman

EtreCheck version: 4.3.6 (4D041)

Report generated: 2018-08-05 15:01:48

Download EtreCheck from https://etrecheck.com

Runtime: 4:04

Performance: Good


Problem: Computer is too slow


Major Issues:

Anything that appears on this list needs immediate attention.


No Time Machine backup - Time Machine backup not found.

Heavy CPU usage - Some processes are using an unusually high amount of CPU.

More than one antivirus app - This machine has multiple antivirus apps installed.


Minor Issues:

These issues do not need immediate attention but they may indicate future problems.


Heavy RAM usage - This machine is using a large amount of RAM.

High battery cycle count - Your battery may be losing capacity.

Clean up - There are orphan files that could be removed.

32-bit Apps - This machine has 32-bits apps that may have problems in the future.


Hardware Information:

MacBook Pro (Retina, 15-inch, Mid 2015)

MacBook Pro Model: MacBookPro11,5

1 2.8 GHz Intel Core i7 (i7-4980HQ) CPU: 4-core

16 GB RAM - Not upgradeable

BANK 0/DIMM0 - 8 GB DDR3 1600 ok

BANK 1/DIMM0 - 8 GB DDR3 1600 ok

Battery: Health = Replace Soon - Cycle count = 1684


Video Information:

AMD Radeon R9 M370X - VRAM: 2048 MB

Intel Iris Pro - VRAM: 1536 MB

Color LCD


Drives:

disk0 - APPLE SSD SM1024G 1.00 TB (Solid State - TRIM: Yes)

Internal PCI 8.0 GT/s x4 Serial ATA

disk0s1 - EFI (MS-DOS FAT32) [EFI] 210 MB

disk0s2 999.70 GB

disk1s1 - Macintosh HD (APFS) 999.70 GB (324.74 GB used)

disk1s2 - Preboot (APFS) [APFS Preboot] 999.70 GB (44 MB used)

disk1s3 - Recovery (APFS) [Recovery] 999.70 GB (1.04 GB used)

disk1s4 - VM (APFS) [APFS VM] 999.70 GB (5.37 GB used)


Mounted Volumes:

disk1s1 - Macintosh HD 999.70 GB (668.30 GB free)

APFS

Mount point: /

Encrypted


disk1s4 - VM [APFS VM] 999.70 GB (668.30 GB free)

APFS

Mount point: /private/var/vm


Network:

Interface en4: Thunderbolt Ethernet

One IPv4 address

3 IPv6 addresses

Interface en0: Wi-Fi


Interface en5: iPhone

Interface en3: Bluetooth PAN

Interface bridge0: Thunderbolt Bridge

iCloud Quota: 1.77 TB available


System Software:

macOS High Sierra 10.13.6 (17G65)

Time since boot: About 7 days

System Load: 3.25 (1 min ago) 3.64 (5 min ago) 3.83 (15 min ago)


Security:

SystemStatus
GatekeeperMac App Store and identified developers
System Integrity ProtectionEnabled


32-bit Applications:

8 32-bit apps


Kernel Extensions:

/Library/Extensions

[Loaded] MB_MBAM_Protection.kext (Malwarebytes Corporation, 3.3 - SDK 10.13)

[Loaded] SymXIPS.kext (Symantec, 8.1 - SDK 10.10)

[Loaded] SymInternetSecurity.kext (Symantec, 7.8.1 - SDK 10.11)

[Loaded] SymIPS.kext (Symantec, 7.8.1 - SDK 10.11)

[Loaded] NortonForMac.kext (Symantec, 7.8.1 - SDK 10.11)


System Launch Agents:

[Not Loaded] 8 Apple tasks
[Loaded] 154 Apple tasks
[Running] 131 Apple tasks
[Other] One Apple task


System Launch Daemons:

[Not Loaded] 37 Apple tasks
[Loaded] 168 Apple tasks
[Running] 131 Apple tasks


Launch Agents:

[Loaded] com.microsoft.update.agent.plist (Microsoft Corporation - installed 2018-07-10)
[Loaded] com.pharos.popup.plist (Pharos Systems International - installed 2017-09-03)
[Running] com.symantec.uiagent.application.NFM.plist (Symantec - installed 2017-11-10)
[Running] com.pharos.notify.plist (Pharos Systems International - installed 2017-09-03)
[Running] com.malwarebytes.mbam.frontend.agent.plist (Malwarebytes Corporation - installed 2018-05-22)


Launch Daemons:

[Loaded] com.microsoft.OneDriveUpdaterDaemon.plist (Microsoft Corporation - installed 2018-04-29)
[Running] com.symantec.symdaemon.NFM.plist (Symantec - installed 2018-07-17)
[Loaded] com.symantec.symqual.panicreporter.NFM.plist (Symantec - installed 2018-07-17)
[Running] com.malwarebytes.mbam.settings.daemon.plist (Malwarebytes Corporation - installed 2018-05-22)
[Loaded] com.microsoft.autoupdate.helper.plist (Microsoft Corporation - installed 2018-07-10)
[Loaded] com.vmware.VMMonHelper.plist (VMware, Inc. - installed 2018-06-30)
[Loaded] com.symantec.symqual.submit.NFM.plist (Symantec - installed 2018-07-17)
[Loaded] com.apple.installer.osmessagetracing.plist (Apple - installed 2018-07-04)
[Loaded] com.vmware.KextControlHelper.plist (VMware, Inc. - installed 2018-06-30)
[Running] com.malwarebytes.mbam.rtprotection.daemon.plist (Malwarebytes Corporation - installed 2018-05-22)
[Other] com.symantec.liveupdate.daemon.NFM.plist (Symantec - installed 2018-07-17)
[Running] com.pharos.psnotifyd.plist (Pharos Systems International - installed 2017-09-03)
[Loaded] com.symantec.nortonutilities.daemon.plist (Symantec - installed 2018-07-17)
[Loaded] com.symantec.symqual.detail.NFM.plist (Symantec - installed 2018-07-17)
[Loaded] com.symantec.UninstallerToolHelper.NFM.plist (Symantec - installed 2018-07-17)
[Loaded] com.symantec.SymLUHelper.NFM.plist (Symantec - installed 2018-07-17)
[Running] com.symantec.sharedsettings.NFM.plist (Symantec - installed 2018-07-17)
[Other] com.backblaze.bzserv.plist (? 317225a9 - installed 2018-04-29)
[Loaded] com.microsoft.office.licensingV2.helper.plist (Microsoft Corporation - installed 2018-04-10)
[Running] com.symantec.kexthelper.NFM.plist (Symantec - installed 2018-07-17)


User Launch Agents:

[Loaded] com.google.keystone.agent.plist (Google, Inc. - installed 2018-07-17)
[Running] com.hp.devicemonitor.plist (HP Inc. - installed 2018-08-04)
[Running] com.hp.productresearch.plist (HP Inc. - installed 2018-07-28)
[Other] com.backblaze.bzbmenu.plist (? 0 - installed 2018-05-14)


User Login Items:

Google Chrome Application (Google, Inc. - installed 2018-08-02)

(/Applications/Google Chrome.app)

iTunesHelper Application (Apple - installed 2018-07-10)

(/Applications/iTunes.app/Contents/MacOS/iTunesHelper.app)

Backup and Sync from Google Application (Google, Inc. - installed 2018-05-30)

(/Applications/Backup and Sync.app)

HP Product Research SMLoginItem (HP Inc. - installed 2018-04-29)

(/Library/Printers/hp/Utilities/HPPU Plugins/ProductImprovementStudy.hptask/Contents/Helpers/HP Product Research Manager.app/Contents/Library/LoginItems/HP Product Research.app)

HP Device Monitor SMLoginItem (HP Inc. - installed 2018-04-29)

(/Library/Printers/hp/Frameworks/HPDeviceMonitoring.framework/Versions/1.0/Help ers/HP Device Monitor Manager.app/Contents/Library/LoginItems/HP Device Monitor.app)


Internet Plug-ins:

QuickTime Plugin: (installed 2018-07-10)


3rd Party Preference Panes:

Backblaze Backup (installed 2018-04-29)


Time Machine:

Time Machine Not Configured!


Top Processes by CPU:

Process (count)Source% of CPULocation
Backup and SyncGoogle, Inc.102
Google Chrome Helper (44)Google, Inc.78
Google ChromeGoogle, Inc.14
WindowServerApple8
RTProtectionDaemonMalwarebytes Corporation4


Top Processes by Memory:

Process (count)SourceRAM usageLocation
Google Chrome Helper (45)Google, Inc.6.26 GB
kernel_taskApple1.70 GB
SymDaemonSymantec526 MB
Google ChromeGoogle, Inc.411 MB
MailApple269 MB


Top Processes by Network Use:

ProcessSourceInputOutputLocation
mDNSResponderApple41 MB4 MB
MailApple4 MB123 KB
netbiosdApple499 KB114 KB
usbmuxdApple252 KB192 KB
WhatsAppMac App Store94 KB49 KB


Top Processes by Energy Use:

Process (count)SourceEnergy (0-100)Location
Google Chrome Helper (45)Google, Inc.26
Backup and SyncGoogle, Inc.26
RTProtectionDaemonMalwarebytes Corporation12
SymDaemonSymantec11
WindowServerApple7


Virtual Memory Information:

Available RAM3.55 GB
Free RAM43 MB
Used RAM12.45 GB
Cached files3.51 GB
Swap Used3.70 GB


Software Installs (past 30 days):

NameVersionInstall Date
Microsoft AutoUpdate4.1.180705032018-07-10
iTunes12.82018-07-10
Microsoft PowerPoint for Mac16.15.180709022018-07-10
Microsoft OneNote for Mac16.15.180709022018-07-10
Microsoft Outlook for Mac16.15.180709022018-07-10
Microsoft Excel for Mac16.15.180709022018-07-10
Microsoft Word for Mac16.15.180709022018-07-10
WhatsApp0.3.332018-07-16
PassMaker2.0.12018-07-21
Norton for Mac.Universal7.8.0.34.02018-07-23
Microsoft Remote Desktop10.2.02018-07-27
Malwarebytes for Mac1.02018-07-28
Gatekeeper Configuration Data1492018-07-31


Clean up:

/Library/LaunchDaemons/com.backblaze.bzserv.plist

/Library/Backblaze.bzpkg/bzserv

Executable not found

~/Library/LaunchAgents/com.backblaze.bzbmenu.plist

/Library/Backblaze.bzpkg/bzbmenu.app/Contents/MacOS/bzbmenu

Executable not found


Diagnostics Information (past 7 days):

2018-08-04 15:49:02 HP Device Monitor.app Crash

/Library/Printers/hp/Frameworks/HPDeviceMonitoring.framework/Versions/1.0/Helper s/HP Device Monitor Manager.app/Contents/Library/LoginItems/HP Device Monitor.app

*** Terminating app due to uncaught exception 'NSGenericException', reason: '*** Collection <__NSArrayM: 0x7fd71363dd10> was mutated while being enumerated.'

terminating with uncaught exception of type NSException

abort() called


2018-08-03 23:52:16 Backup and Sync.app CPU (2 times)

/Applications/Backup and Sync.app



End of report

Aug 5, 2018 6:24 PM in response to Bigboss1011

I work with very sensitive data so use it as a precaution.

From what we have seen in the forums, no 3rd party anti-virus has found anything on a Mac, but slowed down the Mac, interfered with network connections, quarantine essential software that ends up bricking the Mac.


The ONLY software that has proved to be useful is the free MalwareBytes, which was written by a long time forum contributor. And that ONLY needs to be run AFTER you have installed something, then you can uninstall MalwareBytes.


The reason you only need to run after installing something is that there are on self-propagating viruses for the Mac, so unless you are tricked into install the malware, it is not getting on your Mac. And you uninstall MalwareBytes and re-install a new copy after you have installed something, it is because MalwareBytes may have been updated with new trojans.


And be sensible about what you install, do not be tricked by phishing attacks from email or web browser pop-ups, and you will be good and your data safe.


Since you are using a Cloud backup, do you encrypt them before they leave the Mac and do you NOT allow that encryption key to leave your control? Because if someone else has the encryption key, then your sensitive data is not secure from anyone that has that key.


Besides multiple system resource draining anti-virus programs, you also are using Chrome with way too many tabs open

Google Chrome Helper (44) Google, Inc. 78
Google Chrome Google, Inc. 14

Swap Used 3.70 GB

Chrome is a resource hog on the Mac. And lots of tabs just aggravates the issue more.


You are using the swap area because you are over committing memory. This will slow down your Mac. And most likely Chrome is the offending party.

Aug 5, 2018 10:54 AM in response to Eric Root

Hey Eric,


Thanks for the response! Actually, my whole system is running slower than it should. I know many people say to not install any anti-virus but I work with very sensitive data so use it as a precaution.


Also, many times my computer shuts down even though there was about 50-80% battery percentage. I would have to turn it on as if I had shut it down properly, rather than it going into sleep mode.


Hope this clears things up.


Let me know if you have any inkling as to what the problem may be.


Thanks!

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Virus scan - Terminal

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.