閱讀878 返回首頁    go 人物


cleaning my Macbook

On my Macbook Pro, OS Sierra 10.12.6, I cannot remove malware from Piet2eix3l.

I tried Bitdefender and Adwaremedic.

It appears on Google, Youtube and so on.

Google shows some sites with solutions - always buy a malware cleaner - I don't trust these;

they all look like the same (made by Piet?)

Please help.

Thank you in advance.



Possible adware:

    Unknown file: /Library/LaunchDaemons/com.MyCouponize.agent.plist

    /Applications/MyCouponize/MyCouponize -guid 59664978352609663 -source picpm-1741 -brand MyCouponize -dt 1507806942 -home ~ -tracking_url http:/events.mycouponizemac.com

    Adware: /Library/LaunchDaemons/com.MyMacUpdater.agent.plist

    2 possible adware files found. [Remove/Report]

 

Clean up:

    /Library/LaunchDaemons/org.tcpdump.chmod_bpf.plist

        /usr/local/bin/chmod_bpf

        Executable not found!

    com.adobe.ARM.[...].plist

        /Applications/Adobe Reader.app/Contents/MacOS/Updater/Adobe Reader Updater Helper.app/Contents/MacOS/Adobe Reader Updater Helper semi-auto

        Executable not found!

    2 orphan files found. [Clean up]

 

Run the report again and click [Remove/Report] and [Clean up]. 



Please download and run EtreCheck, created by one of own helpers here in ASC. It is a diagnostic tool that's very useful to us in finding problems. Also it will give us further specs on your Mac. After it runs post the log file here. It will contain no personal information.



Here is the diagnostic report and I have seen some things to alter.

I am pleased with further help.

EtreCheck version: 3.4.6 (460)

Report generated 2017-10-20 15:29:02

Download EtreCheck from https://etrecheck.com

Runtime: 1:46

Performance: Excellent

 

Click the [Lookup] links for more information from Apple Support Communities.

Click the [Details] links for more information about that line.

Click the [Remove/Report] links to remove adware or update the whitelist of legitimate software.

Click the [Clean up] link to delete unused files.

 

Problem: Other problem

Description:

malware

 

Hardware Information:

    MacBook Pro (Retina, 15-inch, Late 2013)

    [Technical Specifications] - [User Guide] - [Warranty & Service]

    MacBook Pro - model: MacBookPro11,2

    1 2 GHz Intel Core i7 (i7-4750HQ) CPU: 4-core

    8 GB RAM Not upgradeable

        BANK 0/DIMM0

            4 GB DDR3 1600 MHz ok

        BANK 1/DIMM0

            4 GB DDR3 1600 MHz ok

    Handoff/Airdrop2: supported

    Wireless:  en0: 802.11 a/b/g/n/ac

    Battery: Health = Normal - Cycle count = 948

    iCloud Quota: 30.98 GB available

 

Video Information:

    Intel Iris Pro - VRAM: 1536 MB

        Color LCD 2880 x 1800

 

Disk Information:

    APPLE SSD SM0256F disk0: (251 GB) (Solid State - TRIM: Yes)

    [Show SMART report]

        EFI (disk0s1 - MS-DOS FAT32) <not mounted>  [EFI]: 210 MB

        (disk0s2) <not mounted>  [CoreStorage Container]: 250.14 GB

        Recovery HD (disk0s3 - Journaled HFS+) <not mounted>  [Recovery]: 650 MB

 

USB Information:

     USB30Bus

        Apple Inc. Apple Internal Keyboard / Trackpad

        Apple Inc. BRCM20702 Hub

            Apple Inc. Bluetooth USB Host Controller

 

Thunderbolt Information:

    Apple Inc. thunderbolt_bus

 

Virtual disks:

    Macintosh HD (disk1 - Journaled HFS+) /  [Startup]: 249.79 GB (105.80 GB free)

        Encrypted AES-XTS (Unlocked)

        Physical disk: disk0s2 250.14 GB Online

 

System Software:

    macOS Sierra  10.12.6 (16G29) - Time since boot: less than an hour

 

Gatekeeper:

    Mac App Store and identified developers

 

Possible adware:

    Unknown file: /Library/LaunchDaemons/com.MyCouponize.agent.plist

    /Applications/MyCouponize/MyCouponize -guid 59664978352609663 -source picpm-1741 -brand MyCouponize -dt 1507806942 -home ~ -tracking_url http:/events.mycouponizemac.com

    Adware: /Library/LaunchDaemons/com.MyMacUpdater.agent.plist

    2 possible adware files found. [Remove/Report]

 

Clean up:

    /Library/LaunchDaemons/org.tcpdump.chmod_bpf.plist

        /usr/local/bin/chmod_bpf

        Executable not found!

    com.adobe.ARM.[...].plist

        /Applications/Adobe Reader.app/Contents/MacOS/Updater/Adobe Reader Updater Helper.app/Contents/MacOS/Adobe Reader Updater Helper semi-auto

        Executable not found!

    2 orphan files found. [Clean up]

 

Kernel Extensions:

        /System/Library/Extensions

    [not loaded]    com.seagate.driver.PowSecDriverCore (5.1.1 (26439)) [Lookup]

 

        /System/Library/Extensions/Seagate Storage Driver.kext/Contents/PlugIns

    [not loaded]    com.seagate.driver.PowSecLeafDriver_10_4 (5.1.1 (26439)) [Lookup]

    [not loaded]    com.seagate.driver.PowSecLeafDriver_10_5 (5.1.1 (26439)) [Lookup]

    [not loaded]    com.seagate.driver.SeagateDriveIcons (5.1.1 (26439)) [Lookup]

 

System Launch Agents:

    [not loaded]    6 Apple tasks

    [loaded]    180 Apple tasks

    [running]    99 Apple tasks

 

System Launch Daemons:

    [not loaded]    42 Apple tasks

    [loaded]    178 Apple tasks

    [running]    99 Apple tasks

 

Launch Agents:

    [failed]    com.adobe.ARMDCHelper.cc24aef4a1b90ed56a725c38014c95072f92651fb65e1bf9c8e43c37a2 3d420d.plist (Adobe Systems, Inc. - installed 2017-01-12) [Lookup]

    [loaded]    com.google.keystone.agent.plist (Google, Inc. - installed 2017-09-28) [Lookup]

    [loaded]    com.oracle.java.Java-Updater.plist (? 4adb4daf 834cfa51 - installed 2016-08-07) [Lookup]

    [running]    com.seagate.SeagateStorageGauge.plist (? 502453cc 27724687 - installed 2015-03-11) [Lookup]

    [not loaded]    com.teamviewer.teamviewer.plist (TeamViewer GmbH - installed 2016-06-13) [Lookup]

    [not loaded]    com.teamviewer.teamviewer_desktop.plist (TeamViewer GmbH - installed 2016-05-02) [Lookup]

 

Launch Daemons:

    [running]    com.MyCouponize.agent.plist (Shell Script f9b1ab43 - installed 2017-10-12) [Lookup]

    [running]    com.MyMacUpdater.agent.plist (Shell Script b8cfac92 - installed 2017-10-12) Adware!  [Remove/Report]

        /Applications/MyMacUpdater/MyMacUpdater

    [loaded]    com.adobe.ARMDC.Communicator.plist (Adobe Systems, Inc. - installed 2017-01-12) [Lookup]

    [loaded]    com.adobe.ARMDC.SMJobBlessHelper.plist (Adobe Systems, Inc. - installed 2017-01-12) [Lookup]

    [loaded]    com.adobe.fpsaud.plist (? 2afb3af7 36f2fce - installed 2017-10-12) [Lookup]

    [loaded]    com.google.keystone.daemon.plist (Google, Inc. - installed 2017-10-13) [Lookup]

    [loaded]    com.malwarebytes.HelperTool.plist (Malwarebytes Corporation - installed 2017-03-26) [Lookup]

    [loaded]    com.oracle.java.Helper-Tool.plist (Shell Script e3fefdd2 - installed 2016-06-22) [Lookup]

    [loaded]    com.teamviewer.Helper.plist (TeamViewer GmbH - installed 2016-05-02) [Lookup]

    [not loaded]    com.teamviewer.teamviewer_service.plist (TeamViewer GmbH - installed 2016-06-13) [Lookup]

    [failed]    org.tcpdump.chmod_bpf.plist (? a9f8244f 0 - installed 2016-03-05) [Lookup] - /usr/local/bin/chmod_bpf: Executable not found!

 

User Launch Agents:

    [failed]    com.adobe.ARM.[...].plist (? 560d19c8 0 - installed 2015-02-13) [Lookup] - /Applications/Adobe Reader.app/Contents/MacOS/Updater/Adobe Reader Updater Helper.app/Contents/MacOS/Adobe Reader Updater Helper: Executable not found!

    [running]    com.spotify.webhelper.plist (Spotify - installed 2017-10-20) [Lookup]

 

User Login Items:

    iTunesHelper    Programma (Apple, Inc. - installed 2017-09-15)

        (/Applications/iTunes.app/Contents/MacOS/iTunesHelper.app)

    Spotify    Programma - Hidden

        (/Applications/Spotify.app)

    RealPlayer Downloader Agent    Programma

        (~/Library/Application Support/RealNetworks/RealPlayer Downloader Agent.app)

 

Internet Plug-ins:

    FlashPlayer-10.6: 27.0.0.170 (installed 2017-10-17) [Lookup]

    QuickTime Plugin: 7.7.3 (installed 2017-07-29)

    AdobePDFViewerNPAPI: 17.012.20098 (installed 2017-08-30) [Lookup]

    AdobePDFViewer: 17.012.20098 (installed 2017-08-30) [Lookup]

    Flash Player: 27.0.0.170 (installed 2017-10-17) [Lookup]

    o1dbrowserplugin: 5.41.3.0 (installed 2016-12-18) [Lookup]

    googletalkbrowserplugin: 5.41.3.0 (installed 2015-12-11) [Lookup]

    Silverlight: 5.1.50901.0 (installed 2017-05-05) [Lookup]

    JavaAppletPlugin: Java 8 Update 101 build 13 (installed 2016-08-07) Check version

 

User internet Plug-ins:

    RealPlayer Plugin: Unknown (installed 2014-07-12) [Lookup]

 

Safari Extensions:

    [enabled]    AdBlock - BetaFish, Inc. - https://getadblock.com (installed 2017-08-05)

    [enabled]    Google Analytics Opt-out Browser Add-on - Google, Inc. - https://tools.google.com/dlpage/gaoptout (installed 2016-06-02)

    [enabled]    racksearch - me (installed 2017-10-12)

 

3rd Party Preference Panes:

    Flash Player (installed 2017-10-12) [Lookup]

    Java (installed 2016-08-07) [Lookup]

 

Time Machine:

    Time Machine not configured!

 

Top Processes by CPU:

         9%   WindowServer

         1%   kernel_task

         0%   fontd

         0%   launchservicesd

         0%   python

 

Top Processes by Memory:

    713 MB    kernel_task

    214 MB    Finder

    155 MB    WindowServer

    128 MB    cfprefsd

    111 MB    mds_stores

 

Top Processes by Network Use:

    Input     Output    Process name

    47 KB     46 KB     apsd

    5 KB      22 KB     assistantd

    18 KB     5 KB      mDNSResponder

    522 B     354 B     netbiosd

    432 B     432 B     ntpd

 

Top Processes by Energy Use:

     10.40 WindowServer

      0.36 launchservicesd

      0.30 RealPlayer Downloader Agent

      0.20 python

 

Virtual Memory Information:

    4.71 GB   Available RAM

    1.84 GB   Free RAM

    3.29 GB   Used RAM

    2.88 GB   Cached files

    0 B       Swap Used

 

Software installs (last 30 days):

    Bitdefender Virus Scanner: 3.9 (installed 2017-09-24)

    Fotor Photo Editor: 3.4.0 (installed 2017-10-03)

    Bitdefender Virus Scanner: 3.10 (installed 2017-10-05)

    Repeatify: 0.17.9 (installed 2017-10-07)

    Adobe Flash Player:  (installed 2017-10-10)

    Paint 2: 5.6.0 (installed 2017-10-17)

    Adobe Flash Player:  (installed 2017-10-17)

 

    Install information may not be complete.

 

Diagnostics Events (last 3 days for minor events):

    2017-10-19 08:21:52    com.apple.WebKit.WebContent High CPU use [Open] [Details]



Possible adware:

    Unknown file: /Library/LaunchDaemons/com.MyCouponize.agent.plist

    /Applications/MyCouponize/MyCouponize -guid 59664978352609663 -source picpm-1741 -brand MyCouponize -dt 1507806942 -home ~ -tracking_url http:/events.mycouponizemac.com

    Adware: /Library/LaunchDaemons/com.MyMacUpdater.agent.plist

    2 possible adware files found. [Remove/Report]

 

Clean up:

    /Library/LaunchDaemons/org.tcpdump.chmod_bpf.plist

        /usr/local/bin/chmod_bpf

        Executable not found!

    com.adobe.ARM.[...].plist

        /Applications/Adobe Reader.app/Contents/MacOS/Updater/Adobe Reader Updater Helper.app/Contents/MacOS/Adobe Reader Updater Helper semi-auto

        Executable not found!

    2 orphan files found. [Clean up]

 

Run the report again and click [Remove/Report] and [Clean up]. 



Yes, you can remove the adware from within Etrecheck by clicking on the Remove links. I'd also advise removing Bitdefender as per the developer's instructions. No anti-virus or so-called "cleaning" apps are necessary or recommended. They can interfere with Mac's own built-in security. I'm surprised Malwarebytes didn't pick this up?



Thank you very much, this solved my problem and helped me!



I was surprised too, Malwarebytes didn't picked it up, that's why I asked it here; thank you very much!



You are welcome.



最後更新:2017-10-20 23:32:31

  上一篇:go My Mac is running slow Too many beachballs, Help
  下一篇:go How to expand the window to full screen using t...