Thank you very much for your help! I still see the malware on my Chrome, although when I delete the other search engines and just keep google.com on there it seems to be ok. But, if I close the app and/or restart my mac the malware is still effecting Chrome.
Here is the report from Etrecheck, thanks again for your help!
EtreCheck version:5.0.3 (5018)
Report generated:2018-11-29 16:19:00
Download EtreCheck from https://etrecheck.com
Runtime:3:33
Performance:Good
Sandbox:Enabled
Full drive access:Disabled
Problem:Other problem
Description:
How to remove Application.MAC.InstallMiez.BPY & Adware.MAC.Generic.9529
Major Issues:
Anything that appears on this list needs immediate attention.
More than one antivirus app- This machine has multiple antivirus apps installed.
Minor Issues:
These issues do not need immediate attention but they may indicate future problems.
Clean up- There are orphan files that could be removed.
Unsigned files- There are unsigned software files installed. They appear to be legitimate but should be reviewed.
32-bit Apps- This machine has 32-bits apps that may have problems in the future.
Limited drive access- More information may be available with Full Drive Access.
Hardware Information:
MacBook Air (13-inch, Early 2015)
MacBook Air Model: MacBookAir7,2
1 2.2 GHz Intel Core i7 (i7-5650U) CPU: 2-core
8 GB RAM -Not upgradeable
BANK 0/DIMM0 - 4 GB DDR3 1600 ok
BANK 1/DIMM0 - 4 GB DDR3 1600 ok
Battery: Health = Normal - Cycle count = 100
Video Information:
Intel HD Graphics 6000 - VRAM: 1536 MB
Color LCD 1440 x 900
Drives:
disk0 - APPLE SSD SM0512G 500.28 GB (Solid State - TRIM: Yes)
Internal PCI 5.0 GT/s x4 Serial ATA
disk0s1 - EFI (MS-DOS FAT32) [EFI] 210 MB
disk0s2 [APFS Container] 500.07 GB
disk1 [APFS Virtual drive] 500.07 GB (Shared by 4 volumes)
disk1s1 - Macintosh HD (APFS) (Shared - 208.42 GB used)
disk1s2 - Preboot (APFS) [APFS Preboot] (Shared)
disk1s3 - Recovery (APFS) [Recovery] (Shared)
disk1s4 - VM (APFS) [APFS VM] (Shared - 3.22 GB used)
Mounted Volumes:
disk1s1 - Macintosh HD 500.07 GB (287.73 GB free)
APFS
Mount point: /
Encrypted
disk1s4 - VM [APFS VM] (Shared - 3.22 GB used)
APFS
Mount point: /private/var/vm
Network:
Interface en3: iPhone
Interface en0: Wi-Fi
802.11 a/b/g/n/ac
Interface en2: Bluetooth PAN
Interface bridge0: Thunderbolt Bridge
System Software:
macOS High Sierra 10.13.6 (17G3025)
Time since boot: About 16 hours
Security:
| System | Status |
|---|
| Gatekeeper | Enabled |
| System Integrity Protection | Enabled |
Unsigned Files:
Launchd: /Library/LaunchDaemons/com.avast.init.plist
Executable: /Applications/Avast.app/Contents/Backend/hub/init.sh
Details: Exact match found in the whitelist - probably OK
Launchd: ~/Library/LaunchAgents/com.google.keystone.agent.plist
Executable: ~/Library/Google/GoogleSoftwareUpdate/GoogleSoftwareUpdate.bundle/Contents/Reso urces/GoogleSoftwareUpdateAgent.app/Contents/MacOS/GoogleSoftwareUpdateAgent -runMode ifneeded
Details: Exact match found in the whitelist - probably OK
Launchd: /Library/LaunchDaemons/com.avast.uninstall.plist
Executable: /Library/Application Support/Avast/autouninstall/autouninstall.sh
Details: Exact match found in the whitelist - probably OK
Launchd: /Library/LaunchDaemons/com.avast.update.plist
Executable: /Applications/Avast.app/Contents/Backend/scripts/update/update.sh
Details: Exact match found in the whitelist - probably OK
Launchd: /Library/LaunchAgents/com.avast.userinit.plist
Executable: /Applications/Avast.app/Contents/Backend/hub/userinit.sh
Details: Exact match found in the whitelist - probably OK
32-bit Applications:
5 32-bit apps
Kernel Extensions:
/Applications/Avast.app
AvastFileShield.kext (AVAST Software a.s., 4.0.0 - SDK 10.12)
AvastPacketForwarder.kext (AVAST Software a.s., 2.1 - SDK 10.12)
/Library/Application Support/Malwarebytes/MBAM/Kext
MB_MBAM_Protection.kext (Malwarebytes Corporation, 3.5 - SDK 10.13)
System Launch Agents:
| [Not Loaded] | 16 Apple tasks |
| [Loaded] | 164 Apple tasks |
| [Running] | 114 Apple tasks |
System Launch Daemons:
| [Not Loaded] | 38 Apple tasks |
| [Loaded] | 180 Apple tasks |
| [Running] | 117 Apple tasks |
Launch Agents:
| [Running] | com.epson.scannermonitor.plist (Seiko Epson Corporation - installed 2018-02-21) |
| [Loaded] | com.avast.userinit.plist (? 4b9d47d7 - installed 2018-11-27) |
| [Loaded] | com.epson.esua.launcher.plist (Seiko Epson Corporation - installed 2018-08-02) |
| [Other] | com.adobe.ARMDCHelper.cc24aef4a1b90ed56a725c38014c95072f92651fb65e1bf9c8e43c37a2 3d420d.plist (Adobe Systems, Inc. - installed 2018-07-30) |
| [Running] | com.malwarebytes.mbam.frontend.agent.plist (Malwarebytes Corporation - installed 2018-11-09) |
| [Running] | com.epson.Epson_Low_Ink_Reminder.launcher.plist (Seiko Epson Corporation - installed 2018-02-07) |
| [Running] | com.epson.eventmanager.agent.plist (Seiko Epson Corporation - installed 2018-02-22) |
| [Running] | com.epson.ecrp.launcher.plist (Seiko Epson Corporation - installed 2018-08-02) |
Launch Daemons:
| [Running] | com.malwarebytes.mbam.rtprotection.daemon.plist (Malwarebytes Corporation - installed 2018-11-28) |
| [Running] | com.malwarebytes.mbam.settings.daemon.plist (Malwarebytes Corporation - installed 2018-11-09) |
| [Loaded] | com.adobe.ARMDC.Communicator.plist (Adobe Systems, Inc. - installed 2018-07-30) |
| [Loaded] | com.avast.init.plist (? fe750b9b - installed 2018-11-27) |
| [Loaded] | com.avast.update.plist (? f4a2548f - installed 2018-11-27) |
| [Loaded] | com.apple.installer.osmessagetracing.plist (Apple - installed 2018-10-26) |
| [Loaded] | com.avast.uninstall.plist (? 1d68eef4 - installed 2018-11-27) |
| [Loaded] | com.adobe.ARMDC.SMJobBlessHelper.plist (Adobe Systems, Inc. - installed 2018-07-30) |
User Launch Agents:
| [Loaded] | com.google.keystone.agent.plist (? 0 - installed 2018-10-06) |
User Login Items:
iTunesHelper.app (Apple - installed 2018-08-03)
(/Applications/iTunes.app/Contents/MacOS/iTunesHelper.app)
Internet Plug-ins:
AdobePDFViewerNPAPI: 17.012.20098 (installed 2018-06-29)
QuickTime Plugin: 7.7.3 (installed 2018-11-22)
AdobePDFViewer: 18.011.20055 (installed 2018-06-29)
Time Machine:
Time Machine information not available without Full Drive Access.
Performance:
System Load: 1.79 (1 min ago) 1.70 (5 min ago) 1.68 (15 min ago)
Nominal I/O speed: 0.96 MB/s
File system: 106.57 seconds
Write speed: 1156 MB/s
Read speed: 1199 MB/s
CPU Usage:
| Type | Overall | Individual cores |
| System | 7 % | 13 % | 3 % | 8 % | 3 % |
| User | 11 % | 17 % | 5 % | 15 % | 6 % |
| Idle | 83 % | 70 % | 92 % | 77 % | 91 % |
Top Processes by CPU:
| Process (count) | Source | CPU | Location |
| Other processes | ? | 38.76 % |
| Finder | Apple | 9.35 % |
| plugin-container (4) | Mozilla Corporation | 5.77 % |
| Google Chrome | Google, Inc. | 4.96 % |
| EtreCheck | App Store | 4.07 % |
Top Processes by Memory:
| Process (count) | Source | RAM usage | Location |
| EtreCheck | App Store | 403 MB |
| plugin-container (4) | Mozilla Corporation | 354 MB |
| firefox | Mozilla Corporation | 293 MB |
| Google Chrome | Google, Inc. | 103 MB |
| Safari | Apple | 64 MB |
Top Processes by Network Use:
| Process | Source | Input | Output | Location |
| com.avast.proxy | AVAST Software a.s. | 2 MB | 1 MB |
| mDNSResponder | Apple | 439 KB | 148 KB |
| apsd | Apple | 4 KB | 6 KB |
| netbiosd | Apple | 6 KB | 3 KB |
| RTProtectionDaemon | Malwarebytes Corporation | 4 KB | 1 KB |
Virtual Memory Information:
| Available RAM | 1.48 GB |
| Free RAM | 176 MB |
| Used RAM | 6.52 GB |
| Cached files | 1.30 GB |
| Swap Used | 770 MB |
Software Installs (past 30 days):
| Name | Version | Install Date |
| Gatekeeper Configuration Data | 156 | 2018-10-31 |
| Safari | 12.0.1 | 2018-10-31 |
| Pages | 7.0 | 2018-11-12 |
| Numbers | 5.0 | 2018-11-12 |
| WeChat | 2.3.20 | 2018-11-16 |
| Zoolz | 2018-11-19 |
| Security Update 2018-002 | 10.13.6 | 2018-11-22 |
| Avast Security | 13.11 | 2018-11-27 |
| Malwarebytes for Mac | 2018-11-28 |
| EtreCheck | 5.0.3 | 2018-11-29 |
Clean up:
/Applications/Avast.app/Contents/Backend/launch/com.avast.account-sync.plist
@AV_BASE_DIR/utils/com.avast.account-sync
Executable not found
Diagnostics Information (past 7 days):
Directory /Library/Logs/DiagnosticReports is not accessible without Full Drive Access.
End of report