Ok here's the report from EtreCheck as below:
EtreCheck version:4.3.6 (4D041)
Report generated:2018-09-17 20:57:51
Download EtreCheck from https://etrecheck.com
Runtime:5:04
Performance:Below Average
Problem:Other problem
Description:
maleware apple ad-pop up
Major Issues:
Anything that appears on this list needs immediate attention.
No Time Machine backup- Time Machine backup not found.
Minor Issues:
These issues do not need immediate attention but they may indicate future problems.
Heavy RAM usage- This machine is using a large amount of RAM.
Apps crashing- There have been numerous app crashes.
Clean up- There are orphan files that could be removed.
Unsigned files- There are unsigned software file installed. They appear to be legitimate but should be reviewed.
System modifications- There are a large number of system modifications running in the background.
Low performance- EtreCheck report took over 5 minutes to run. This is unusual.
32-bit Apps- This machine has 32-bits apps that may have problems in the future.
Abnormal shutdown- Your machine shut down abnormally.
Hardware Information:
iMac (27-inch, Mid 2011)
iMac Model: iMac12,2
1 3.1 GHz Intel Core i5 (i5-2400) CPU: 4-core
16 GB RAM -At maximum
BANK 0/DIMM0 - 4 GB DDR3 1333 ok
BANK 1/DIMM0 - 4 GB DDR3 1333 ok
BANK 0/DIMM1 - 4 GB DDR3 1333 ok
BANK 1/DIMM1 - 4 GB DDR3 1333 ok
Video Information:
AMD Radeon HD 6970M - VRAM: 1024 MB
iMac 2560 x 1440
Drives:
disk0 - ST31000528AS 1.00 TB (Mechanical)
Internal SATA 3 Gigabit Serial ATA
disk0s1 - EFI (MS-DOS FAT32) [EFI] 210 MB
disk0s2 - S********c (Journaled HFS+) 999.35 GB
disk0s3 - Recovery HD (Journaled HFS+) [Recovery] 650 MB
disk1 - Disk Image 24 MB (Disk Image)
External Disk Image
disk1s1 [Partition Map] 32 KB
disk1s2 - Flash Player (HFS+) 24 MB
disk2 - Ext HDD 1021 1.50 TB
External USB
disk4 - Disk Image 24 MB (Disk Image)
External Disk Image
disk4s1 [Partition Map] 32 KB
disk4s2 - Flash Player (HFS+) 24 MB
disk5 - Verbatim Portable USB 3.0 Drive 2.00 TB
External USB 480 Mbit/s
disk5s1 - EFI (MS-DOS FAT32) [EFI] 210 MB
disk5s2 - E*******N (UFSD_NTFS) 2.00 TB
disk6 - Western Digital Ext HDD 1021 1.50 TB
External USB 480 Mbit/s
disk6s1 - S*******B (MS-DOS FAT32) 1.50 TB
Mounted Volumes:
disk0s2 - S********c 999.35 GB (599.10 GB free)
Journaled HFS+
Mount point: /
disk5s2 - E*******N 2.00 TB (41.11 GB free)
UFSD_NTFS
Mount point: /Volumes/E*******N
disk6s1 - S*******B 1.50 TB (78.84 GB free)
MS-DOS FAT32
Mount point: /Volumes/S*******B
Network:
Interface usbmodemFD1340: ALCATEL 2045
Interface usbmodemFD1342: ALCATEL 2046
Interface en0: Ethernet
Interface en6: iPad
Interface en5: iPhone
Interface fw0: FireWire
Interface en1: Wi-Fi
802.11 a/b/g/n
One IPv4 address
Interface en4: Bluetooth PAN
Interface bridge0: Thunderbolt Bridge
System Software:
macOS High Sierra 10.13.6 (17G65)
Time since boot: About 6 days
System Load: 2.46 (1 min ago) 2.39 (5 min ago) 2.22 (15 min ago)
Configuration Files:
/etc/hosts - Count: 17
Security:
| System | Status |
|---|
| Gatekeeper | Mac App Store and identified developers |
| System Integrity Protection | Enabled |
Unsigned Files:
Launchd: /Library/LaunchAgents/com.divx.dms.agent.plist
Executable: /Library/Application Support/DivX/DivXMediaServer.app/Contents/MacOS/DivXMediaServer
Details: Exact match found in the whitelist - probably OK
Launchd: /Library/LaunchAgents/com.paragon-software.facebook.agent.plist
Executable: /Library/Application Support/Paragon Software/Paragon Software Facebook Agent.app/Contents/MacOS/Paragon Software Facebook Agent
Details: Exact match found in the whitelist - probably OK
Launchd: /Library/LaunchDaemons/com.microsoft.office.licensing.helper.plist
Executable: /Library/PrivilegedHelperTools/com.microsoft.office.licensing.helper
Details: Exact match found in the whitelist - probably OK
Launchd: /Library/LaunchDaemons/com.microsoft.office.licensingV2.helper.plist
Executable: /Library/PrivilegedHelperTools/com.microsoft.office.licensingV2.helper
Details: Exact match found in the whitelist - probably OK
Launchd: /Library/LaunchAgents/com.divx.uninstall.preferences.plist
Executable: /bin/bash -c 'if [[ ! -e "/Applications/DivX/DivX Preferences.app" ]] ; then open "/Library/Application Support/DivX/Uninstall DivX for Mac.app"; fi'
Details: Exact match found in the whitelist - probably OK
Launchd: /Library/LaunchAgents/com.divx.uninstall.converter.plist
Executable: /bin/bash -c 'if [[ ! -e "/Applications/DivX Converter.app" ]] ; then open "/Library/Application Support/DivX/Uninstall DivX for Mac.app"; fi'
Details: Exact match found in the whitelist - probably OK
Launchd: /Library/LaunchAgents/com.divx.uninstall.player.plist
Executable: /bin/bash -c 'if [[ ! -e "/Applications/DivX Player.app" ]] ; then open "/Library/Application Support/DivX/Uninstall DivX for Mac.app"; fi'
Details: Exact match found in the whitelist - probably OK
Launchd: /Library/LaunchDaemons/net.tunnelblick.tunnelblick.tunnelblickd.plist
Executable: /Applications/Tunnelblick.app/Contents/Resources/tunnelblickd
Details: Exact match found in the whitelist - probably OK
32-bit Applications:
46 32-bit apps
Kernel Extensions:
/Library/Extensions
[Loaded] ufsd_NTFS.kext (Paragon Software GmbH, 15.2.319 - SDK 10.10)
System Launch Agents:
| [Not Loaded] | 8 Apple tasks |
| [Loaded] | 164 Apple tasks |
| [Running] | 121 Apple tasks |
| [Other] | One Apple task |
System Launch Daemons:
| [Not Loaded] | 33 Apple tasks |
| [Loaded] | 172 Apple tasks |
| [Running] | 128 Apple tasks |
| [Other] | 3 Apple tasks |
Launch Agents:
| [Running] | com.adobe.AdobeCreativeCloud.plist (Adobe Systems, Inc. - installed 2017-06-08) |
| [Loaded] | com.divx.dms.agent.plist (? bf9bdaf7 - installed 2017-11-18) |
| [Not Loaded] | com.adobe.AAM.Updater-1.0.plist (? ffb65062 - installed 2018-02-24) |
| [Loaded] | com.divx.update.agent.plist (DivX, LLC - installed 2017-08-02) |
| [Loaded] | com.divx.uninstall.converter.plist (? 9e90dee7 - installed 2018-01-18) |
| [Loaded] | com.paragon.updater.plist (Paragon Software GmbH - installed 2016-11-29) |
| [Loaded] | com.divx.uninstall.preferences.plist (? 1cd1d81c - installed 2018-01-18) |
| [Loaded] | com.divx.uninstall.player.plist (? 664f994d - installed 2018-01-18) |
| [Not Loaded] | com.adobe.GC.Invoker-1.0.plist (Adobe Systems, Inc. - installed 2018-06-02) |
| [Running] | com.paragon-software.ntfs.notification-agent.plist (Paragon Software GmbH - installed 2018-04-21) |
| [Other] | com.adobe.ARMDCHelper.cc24aef4a1b90ed56a725c38014c95072f92651fb65e1bf9c8e43c37a2 3d420d.plist (Adobe Systems, Inc. - installed 2018-02-16) |
| [Running] | com.malwarebytes.mbam.frontend.agent.plist (Malwarebytes Corporation - installed 2018-08-06) |
| [Loaded] | com.paragon-software.facebook.agent.plist (? 95fb0bd4 - installed 2016-11-29) |
Launch Daemons:
| [Loaded] | com.adobe.ARMDC.SMJobBlessHelper.plist (Adobe Systems, Inc. - installed 2018-02-16) |
| [Running] | com.malwarebytes.mbam.settings.daemon.plist (Malwarebytes Corporation - installed 2018-08-06) |
| [Loaded] | com.microsoft.autoupdate.helper.plist (Microsoft Corporation - installed 2017-04-24) |
| [Other] | com.expressvpn.tap.plist (Apple - installed 2018-07-04) |
| [Running] | com.adobe.adobeupdatedaemon.plist (Adobe Systems, Inc. - installed 2017-06-08) |
| [Loaded] | com.apple.installer.osmessagetracing.plist (Apple - installed 2018-07-04) |
| [Running] | com.malwarebytes.mbam.rtprotection.daemon.plist (Malwarebytes Corporation - installed 2018-08-06) |
| [Loaded] | com.adobe.fpsaud.plist (Adobe Systems, Inc. - installed 2018-08-28) |
| [Loaded] | com.microsoft.office.licensing.helper.plist (? 6d8cb30e - installed 2012-04-02) |
| [Loaded] | com.BlueStacks.AppPlayer.bstservice_helper.plist (BlueStack Systems, Inc. - installed 2018-05-03) |
| [Loaded] | com.adobe.agsservice.plist (Adobe Systems, Inc. - installed 2018-06-02) |
| [Loaded] | com.adobe.ARMDC.Communicator.plist (Adobe Systems, Inc. - installed 2018-02-16) |
| [Running] | com.paragon-software.ntfsd.plist (Paragon Software GmbH - installed 2018-04-21) |
| [Running] | com.adobe.agmservice.plist (Adobe Systems, Inc. - installed 2018-06-02) |
| [Loaded] | com.paragon-software.ntfs.loader.plist (Apple - installed 2018-07-04) |
| [Other] | com.expressvpn.tun.plist (Apple - installed 2018-07-04) |
| [Running] | com.paragon-software.installer.plist (Paragon Software GmbH - installed 2018-01-19) |
| [Loaded] | com.microsoft.office.licensingV2.helper.plist (? 689758eb - installed 2015-07-01) |
| [Loaded] | net.tunnelblick.tunnelblick.tunnelblickd.plist (? 606fa614 - installed 2016-05-01) |
User Launch Agents:
| [Loaded] | com.dropbox.DropboxMacUpdate.agent.plist (Dropbox, Inc. - installed 2018-09-06) |
| [Running] | com.wondershare.AnjoyTunesHelper.plist (? 0 - installed 2016-03-10) |
| [Not Loaded] | com.adobe.GC.Invoker-1.0.plist (Adobe Systems, Inc. - installed 2018-06-02) |
| [Other] | net.tunnelblick.tunnelblick.LaunchAtLogin.plist (? 0 - installed 2016-04-24) |
| [Running] | com.expressvpn.ExpressVPN.agent.plist (ExprsVPN LLC - installed 2018-08-07) |
| [Loaded] | com.bittorrent.uTorrent.plist (BitTorrent, Inc - installed 2016-03-18) |
User Login Items:
Dropbox Application (Dropbox, Inc. - installed 2018-09-12)
(/Applications/Dropbox.app)
AdobeResourceSynchronizer Application (Adobe Systems, Inc. - installed 2018-02-24)
(/Applications/Adobe Acrobat DC/Adobe Acrobat.app/Contents/Helpers/AdobeResourceSynchronizer.app)
ExpressVPN Launcher Application (ExprsVPN LLC - installed 2018-08-07)
(/Applications/ExpressVPN.app/Contents/Library/LoginItems/ExpressVPN Launcher.app)
uTorrent Application (BitTorrent, Inc - installed 2016-03-18)
(/Applications/uTorrent.app)
Wondershare TunesGo Helper Application (? - installed 2016-01-28)
(~/Library/Application Support/wondershare_TunesGo/Wondershare TunesGo Helper.app)
Internet Plug-ins:
AdobeAAMDetect: (installed 2017-06-08)
FlashPlayer-10.6: (installed 2018-09-12)
QuickTime Plugin: (installed 2018-07-23)
AdobePDFViewerNPAPI: (installed 2018-02-24)
AdobePDFViewer: (installed 2018-02-24)
DivX Web Player: (installed 2018-01-18)
Flash Player: (installed 2018-09-12)
SharePointBrowserPlugin: (installed 2017-04-24)
PepperFlashPlayer: (installed 2018-09-12)
Silverlight: (installed 2016-06-28)
3rd Party Preference Panes:
Flash Player (installed 2018-08-28)
NTFS (installed 2018-04-21)
Time Machine:
Time Machine Not Configured!
Top Processes by CPU:
| Process (count) | Source | % of CPU | Location |
| plugin-container (5) | Mozilla Corporation | 20 |
| VLC | VideoLAN | 6 |
| uTorrent | BitTorrent, Inc | 5 |
| kernel_task | Apple | 4 |
| WindowServer | Apple | 2 |
Top Processes by Memory:
| Process (count) | Source | RAM usage | Location |
| plugin-container (5) | Mozilla Corporation | 3.66 GB |
| kernel_task | Apple | 1.33 GB |
| firefox | Mozilla Corporation | 1.13 GB |
| WhatsApp Helper (2) | Mac App Store | 310 MB |
| mdworker (7) | Apple | 255 MB |
Top Processes by Network Use:
| Process | Source | Input | Output | Location |
| uTorrent | BitTorrent, Inc | 11.06 GB | 107.63 GB |
| mDNSResponder | Apple | 18 MB | 2 MB |
| Dropbox | Dropbox, Inc. | 3 MB | 2 MB |
| firefox | Mozilla Corporation | 3 MB | 2 MB |
| netbiosd | Apple | 491 KB | 198 KB |
Top Processes by Energy Use:
| Process (count) | Source | Energy (0-100) | Location |
| plugin-container (5) | Mozilla Corporation | 10 |
| VLC | VideoLAN | 4 |
| WindowServer | Apple | 2 |
| coreaudiod | Apple | 1 |
| bluetoothaudiod | Apple | 1 |
Virtual Memory Information:
| Available RAM | 3.87 GB |
| Free RAM | 36 MB |
| Used RAM | 12.13 GB |
| Cached files | 3.84 GB |
| Swap Used | 26 MB |
Software Installs (past 30 days):
| Name | Version | Install Date |
| Gatekeeper Configuration Data | 154 | 2018-09-06 |
| Adobe Acrobat DC (18.011.20058) | 18.011.20058 | 2018-09-06 |
| Vimeo | 1.2.1 | 2018-09-09 |
| WhatsApp | 0.3.419 | 2018-09-09 |
| Adobe Flash Player | 31.0.0.108 | 2018-09-12 |
| Adobe Pepper Flash Player | 31.0.0.108 | 2018-09-12 |
Clean up:
~/Library/LaunchAgents/net.tunnelblick.tunnelblick.LaunchAtLogin.plist
/Applications/Tunnelblick.app/Contents/Resources/launchAtLogin.sh
Executable not found
Diagnostics Information (past 7 days):
2018-09-15 12:49:49 Firefox.app Crash (3 times)
/Users/***/Desktop/*/Firefox.app
2018-09-12 20:03:24 plugin-container.app Crash (8 times)
/Applications/Firefox.app/Contents/MacOS/plugin-container.app
2018-09-11 18:23:54 Last Shutdown Cause: 3 - Hard shutdown
2018-09-10 23:12:39 Finder.app Crash
/System/Library/CoreServices/Finder.app
objc_msgSend() selector name: screen ViewBridge hint(s): ( "<NSRemoteView 0x60c00013e960> com.apple.LookupViewService LookupViewService" ) |