Trojan Horse Generic 11.PWW in my AIR download!

Last week I downloaded and installed the latest version of
Adobe (vers. 9) from the Adobe.com site. However, it wouldn't run
and gave me a message that ran along the lines "Your software has
been successfully installed. However, it might run slower than
normal because your disc needs defragmenting," plus some advice to
defrag the disc then run the program again. Well my disc was fine
as I'd run a defrag a day earlier. All the same I defragged it
again then re-tried the new Adobe program. Same message. So I
uninstalled the whole thing and did a new d/load and install. Same
problem still. Finally I gave up on it and uninstalled it. What's
the point of having it if I can't use it?
Well today I ran my anti-virus program (AVG 8) and it found
this:
Infection Trojan horse Generic11.PWW
And the path:
C:\Documents and Settings\Owner\Local Settings\Application
Data\Adobe\Reader 9.0\Setup Files\AIR\Adobe AIR Installer.exe
This Trojan is now locked away in the AVG virus vault. What
beats me is how this is still hanging around on my comp after I'd
uninstalled, run CCleaner etc. I'm not a geek though so if anyone
can advise then I'd be glad for it.
Also, having browsed some recent AIR topics and seeing the
problems people have been having, I'd like to know if anyone else
has picked up a trojan in AIR in their virus scans. I'd appreciate
any feedback, because until I can be sure this problem is fixed I'm
not d/loading any new versions of the main Adobe s/ware.
Many thanks,
Mike

Hi Luis,
I downloaded the Adobe Reader v.9 s/ware again to see if
things were now different, but the problems persist. Because it
might be helpful to you I took screen shots of the following, which
in respect of issues tell the story well enough:
the download confirmation (while on the Adobe.com download
page),
the Run query box prior to running it that confirms it's
ready to be run,
the Setup Successful box with its confirm of a successful
install but an advisory that the program might not launch as
quickly as possible as my disk needs defragmenting,
the defragment disk report which shows my disk doesn't need
defragmenting,
the download page of an official govt. site where I wished to
download some .pdf format application forms,
the Mozilla Crash Report that I got as soon as I clicked on
the download link in the above page, and
the "Adobe Reader 9.0 has encountered a problem and needs to
close" box that I got when I tried to read one of the same .pdf
files (downloaded via another comp that doesn't have Adobe 9.0).
Please note that same .pdf file reads fine on my PC which runs
Adobe v 7.
Summary: the newly installed Adobe v. 9.0 wrongly says that
my disk needs defragmenting; it crashes my Mozilla v.3 browser as
soon as I try to download a .pdf file from a safe (Capital City
Govt. Dept) website; it cannot read .pdf documents but has to close
- even though those documents clearly show with the usual "Adobe"
icon, showing that Adobe reader is installed on the laptop.
I have uploaded all of those screen shots to a photobucket
site and am sending you a private message with the link. I hope
this will help. Meanwhile, because I never had a Mozilla crash
prior to installing Adobe v 9.0, I am uninstalling this software
again to avoid any more possible crashes. I have also used the
Mozilla Crash Report facility to advise them that I had installed
Adobe 9.0 only minutes prior to the crash and would uninstall the
new s/ware and see if that fixes the problem. (Because the fact is
that there may be another issue involved.)
Meanwhile if there is any way to download an older version of
Adobe reader I'd like to have it. My Adobe 8 was excellent.
Many thanks for taking the time to review this for us. (As
I'm surely not the only one.) I understand that as it's freeware,
Adobe has no liability or onus to do anything so your helpful
approach is brilliant.
EDIT to add: On second thoughts I'll leave the new Adobe 9.0
installed. Makes more sense as there's no way to try any fixes if I
uninstall it :)

Similar Messages

  • Trojan Horse Generic 11.BEOG in Reader 9 Installer?

    Hi Folks-
    AVG8 Free Version found this Trojan in the Adobe Reader Installer\Reader9\Setup.exe on 10/17/08, 3 days after I upped from R8 to R9.
    Anything to this or just another False Positive? I have notified AVG and have not deleted it, just in case. Thanks.

    I wouldn't mess with it for the moment.
    AVG seems to be finding false positives with the latest update.
    http://securityandthe.net/2008/11/10/avg-virus-scanner-removes-critical-windows-file/

  • Trojan Horse Generic 32.IPG

    this virus has been located three times upon attempt to update current Reader during installation.
    Function of reader was irregular, so I attempted to update.  Please advise how to proceed.
    AVG has removed threat successfully each time. Prior scans detected no virus' in whole computer.

    Thank you.  I ran a full scan again on computer and it came up clean again.
    I tried to report to Adobe but could only access discussion forums.
    Thank you very much for your help. I appreciate it very much. This was my
    first time utilizing the forums for assistance.
    Best regards
    On Sun, Mar 17, 2013 at 2:32 PM, Test Screen Name

  • Trojan Horse on download

    Everytime I start to download from the official site, I get a notification from Kaspersky that a Trojan Horse has been detected.  I don't know if it's in the software or not.  Consequently, I haven't completed a download.  Help! Thanks
    1/26/2011 9:46:03 PM Suspicious legal software that can be used by criminals for damaging your computer or personal data PDM.Trojan.generic C:\DOCUMENTS AND SETTINGS\HP_ADMINISTRATOR\LOCAL SETTINGS\TEMP\ICD1.TMP\GETPLUSPLUS_ADOBE_REG.EXE High

    If you want to download the Reader installer without download manager, get it from http://get.adobe.com/reader/enterprise/

  • How do i enable the e drive? something has happened to it. this system was full of trojan horses

    My E drive has been disabled by the trojan horse virises. What do I do?

    Thanks for the reply. I was able to save the data on the Macbook Air whose HD got corrupted by using File Sharing (ethernet connecting two Macbook Airs).
    I am also going to make a disk image of the HD using Disk Utility and mount that Disk Image onto an external hard drive. That way I can save the hard drive contents.

  • My computer has been infected with a Trojan Horse.  It has completely taken over my Mac email account and was sending out malicious email to everyone in my address book.  At the same time it infected my iPhone---I am no longer able to receive or send emai

    My computer has been infected by a Trojan Horse.  It has taken over my Mac email account and began sending out malicious emails to everyone in my address book.  I cleared out my MAC address book and began using my AOL email account. It took a few days and then my AOL email account was infected and has now been send out malicious email to all my contacts for over a month.  It has also infected my iPhone--I am no longer able to send or receive emails on my iPhone.  Also, once the Trojan Horse began using my AOL email it completely blocked me from using my MAC account by sending never ending popups asking for my email password to access my MAC email account, but it never accepts my pass word.  The TH has also slowed down everything on my computer.  It's like I am working on an old PC with dial up connection instead of the high speed digital connection that I have.  The little color wheel spins constantly as I wait for sometimes over a minute for a page to pull up.  If it pulls up at all.  I have tried to use the 2 disks that came with my computer to completely remove everything on my computer and then reinstall all the programs, but I am not allowed to sweep my computer clean.  I thought maybe my disks that came with my computer were defective so I called Apple and they sent me 2 new disks.  I am not able able to clear my computer with the 2 new disks either.  I have done this before successfully so it's not something new to me.  I do remember when I believe my computer became infected:  I had googled an unusual sewing term, and I was opening what appeared to be legitimate sites, when all of a sudden a pop up appeared that said that my computer had been infected.  I immediately shut my computer off, but it was too late.  I downloaded a virus program for Mac, and it has never found a virus or problem at all.  I think it is part of this Trojan Horse, but I am unable to delete it from my computer.  It refuses to uninstall.  The Mac Trojan Horse is real and it is terrible.  If anyone has any suggestions for me I would be very appreciative,
    Beth
    vu

    Install ClamXav and run a scan with that. It should pick up any trojans.   
    17" 2.2GHz i7 Quad-Core MacBook Pro  8G RAM  750G HD + OCZ Vertex 3 SSD Boot HD 
    Got problems with your Apple iDevice-like iPhone, iPad or iPod touch? Try Troubleshooting 101

  • Hey, im experiencing problems with itunes. i downloaded the recent itunes update yesterday and today i plugged my iphone in and my computer said there was a trojan horse and now itunes wont open. Help please??

    Hey guys, Im expierencing problems with itunes after the latest update yesterday(1/22) and the problem im having is when i plugged my iphone into my PC today a virus detection came up and said a trojan horse was present. I also cant open itunes at all. Im confused and dont know what to do. thanks in advance

    Place the device in DFU mode (google it) and restore.

  • I think I have  some Malware/Trojan Horse on MacBook Pro. How to get rid of it?

    My MacBook Pro has worked perfect for the last 2 years, but over the last 2 days when I am on Chrome it has started clicking onto random websites when I click other links, and showing certain words as underlined and as hotlinks. I think I recognise that from having a PC as Malware or Trojan Horse? What is the best way to remove this as I have read through a few threads on here and they advise not downloading any anti virus software as it slows down your Mac instead of helping.
    <Post Edited By Host>

    You installed the "VSearch" trojan, perhaps under a different name. Remove it as follows.
    Malware is constantly changing to get around the defenses against it. The instructions in this comment are valid as of now, as far as I know. They won't necessarily be valid in the future. Anyone finding this comment a few days or more after it was posted should look for more recent discussions or start a new one.
    Back up all data before proceeding.
    Triple-click anywhere in the line below on this page to select it:
    /Library/LaunchAgents/com.vsearch.agent.plist
    Right-click or control-click the line and select
              Services ▹ Reveal in Finder (or just Reveal)
    from the contextual menu.* A folder should open with an item named "com.vsearch.agent.plist" selected. Drag the selected item to the Trash. You may be prompted for your administrator login password.
    Repeat with each of these lines:
    /Library/LaunchDaemons/com.vsearch.daemon.plist
    /Library/LaunchDaemons/com.vsearch.helper.plist
    /Library/LaunchDaemons/Jack.plist
    Restart the computer and empty the Trash. Then delete the following items in the same way:
    /Library/Application Support/VSearch
    /Library/PrivilegedHelperTools/Jack
    /System/Library/Frameworks/VSearch.framework
    ~/Library/Internet Plug-Ins/ConduitNPAPIPlugin.plugin
    Some of these items may be absent, in which case you'll get a message that the file can't be found. Skip that item and go on to the next one.
    From the Safari menu bar, select
              Safari ▹ Preferences... ▹ Extensions
    Uninstall any extensions you don't know you need, including any that have the word "Spigot," "Trovi," or "Conduit" in the description. If in doubt, uninstall all extensions. Do the equivalent for the Firefox and Chrome browsers, if you use either of those.
    Reset the home page and default search engine in all the browsers, if it was changed.
    This trojan is distributed on illegal websites that traffic in pirated content. If you, or anyone else who uses the computer, visit such sites and follow prompts to install software, you can expect much worse to happen in the future.
    You may be wondering why you didn't get a warning from Gatekeeper about installing software from an unknown developer, as you should have. The reason is that this Internet criminal has a codesigning certificate issued by Apple, which causes Gatekeeper to give the installer a pass. Apple could revoke the certificate, but as of this writing, has not done so, even though it's aware of the problem. This failure of oversight has compromised both Gatekeeper and the Developer ID program. You can't rely on Gatekeeper alone to protect you from harmful software.
    *If you don't see the contextual menu item, copy the selected text to the Clipboard by pressing the key combination  command-C. In the Finder, select
              Go ▹ Go to Folder...
    from the menu bar and paste into the box that opens by pressing command-V. You won't see what you pasted because a line break is included. Press return.

  • I have received an email from a friend with a link which I clicked. It directed me to the google home page and I am now suspicious that it is a virus  or a Trojan horse. I would know what to do on my PC but am new to Ipad. How can I check?

    I have received an email from a friend with a link which I clicked. It took me to the google home page. I am now suspicious that my friend's email account has been hijacked and the link contained a virus or a Trojan horse. I would know what to do on my PC but am new to the IPad. Can any form of Trojan horse be planted on IOS 6 or am I worrying unnecessarily? Reassurance would be most welcome as I do use the IPad for checking bank details and web purchases. Thanks for any help.

    PC virus won't run on iPad.

  • Can't find file for Trojan Horse on my MacBook

    Anyone seen this before?
    I have the Norton Antivirus Program installed on my MacBook.
    I believe an attack occurred while I was looking through the Apple Support Forums for help with a QuickTime problem and accidentally clicked on the following link: http:www.smacktalkpaintball.com/video/
    The Norton Warning came up and I hit the delete option and then set Norton to scan manually.
    The following came up at the end of the scan:
    Virus "bof.jar-51a4bd07-3d4b399d.zip" detected, Today at 7:24 AM. Repair failed.
    /Users/Owner/Li...bd07-3d4b399d.zip Trojan Horse infected
    I was not able to locate either of these files anywhere on my computer.
    I have two external hard drives that I use to back-up data, but neither of them were connected at the time of the attack, and nothing else was connected when I ran the virus scan.
    I do not have Windows installed on this MacBook - Mac OS X, Version 10.5.8,

    Norton was able to detect the Trojan whereas MacScan was not, but Norton was not able to remove it
    That sounds an unlikely outcome on both counts. Norton anti-virus is just that: anti-virus, and I would not trust it to deal with trojans.
    Are you sure you actually installed a Trojan?
    If you allow a Trojan to be installed, the user's DNS records can be modified, redirecting incoming internet traffic through the attacker's servers, where it can be hijacked and injected with malicious websites and pornographic advertisements. The trojan also installs a watchdog process that ensures the victim's (that's you!) DNS records stay modified on a minute-by-minute basis.
    You can read more about how, for example, the OSX/DNSChanger Trojan works here:
    http://www.f-secure.com/v-descs/trojanosxdnschanger.shtml
    SecureMac has introduced a free Trojan Detection Tool for Mac OS X. It's available here:
    http://macscan.securemac.com/
    The DNSChanger Removal Tool detects and removes spyware targeting Mac OS X and allows users to check to see if the trojan has been installed on their computer; if it has, the software helps to identify and remove the offending file. After a system reboot, the users' DNS records will be repaired.
    (Note that a 30 day trial version of MacScan can be downloaded free of charge from:
    http://macscan.securemac.com/buy/
    and this can perform a complete scan of your entire hard disk. After 30 days free trial the cost is $29.99. The full version permits you to scan selected files and folders only, as well as the entire hard disk. It will detect (and delete if you ask it to) all 'tracker cookies' that switch you to web sites you did not want to go to.)

  • Acrobat 9.5.4 update introduced Trojan Horse Generic31.COFB

    I allowed Acrobat 9 to update to 9.5.4 this morning.  During the process AVG identified Trojan Horse Generic31.COFB in the file JP2KLib.dll.  Is this a false positive or is this file truley infected right from Adobe?

    I contacted AVG technical support and verified this is a false positive from a virus definition update they pushed out overnight.  They will be sending out an updated virus definition update that will resolve this from being falsely detected.  Thanks.

  • I think I have a trojan horse, what to do?

    First off, I'm going to start by admitting that this is my fault.
    Last month I was ***** and cruising around looking at internet **** on my brand new 21.5 iMac. I think I tried to view a video on one of the sites and was prompted to download a required plugin, which I did. I believe that's how the trojan was allowed onto my machine.
    There was one site I decided to join for $19.99/month (one month only) and I filled out the online form including my cc information. The next day or so I received a phone call from the people who monitor my cc. They said there had been some unusual activity on my account. After reviewing, I found that about $800 in charges were made to my card by someone else. The card was cancelled and now, a couple weeks later, I have a brand new card.
    Fast forward a couple weeks to this last Sunday. I decided to buy some new floor mats for my wifes car ($117)and went online with the same computer to a web site for a well known company and this time I used my Paypal account to purchase the floor mats. The next morning I got an email from Paypal telling me that I had sent $20 to a company called Garena Online Private Limited. I contacted Paypal and started the process to dispute the charge and also changed my password.
    So, that's the background but now what should I do to get rid of the trojan horse? Is there some kind of virus protection software I need to run? I've been a Mac user since 1992 and this is the first time this has happened. TIA.

    http://discussions.apple.com/thread.jspa?threadID=1764179&tstart=0
    Tho seemingly from 2008 and archived, some info is old, but some was updated Oct 2010. Also use openDNS per http://discussions.apple.com/thread.jspa?messageID=13268959
    Wipe out the hard drive and Reinstall everything from scratch. If you don't have an external drive, you could use the Partition tab in Disk Utilty to shrink existing volume, and create a new empty 2nd volume. I would not use any backup software first (as it might include the trojan), but just manually copy your files by drag and drop in the Finder.
    For good overview of how to prevent it in future...
    http://www.macforensicslab.com/ProductsAndServices/index.php?mainpage=document_general_info&cPath=11&productsid=174

  • SPY script/ Trojan Horse active on my MAC BOOK PRO

    Hello, Since two days I have noticed a small pop up every other minute when I am connected to the internet (which I do wireless) in the left top corner. It is a small window that pops and disappears very fast, impossible to read what it says. Does anyone can help me with this? How do I find out what it is and even more important how can I delete/ remove it

    Just in case we actually are confronted by a Trojan, read this:
    From MacWorld, January 10, 2008:
    SecureMac has introduced a free Trojan Detection Tool for Mac OS X. It's available here:
    http://www.securemac.com/
    The DNSChanger Removal Tool detects and removes spyware targeting Mac OS X. Called DNSChanger Trojan and also known as OSX.RSPlug.A Trojan Horse the software attacks users attempting to play a fake video file.
    Upon attempting to play the video, the victim receives the following message:
    “Quicktime Player is unable to play movie file.
Please click here to download new version of codec.”
    Upon running the installer, the user's DNS records are modified, redirecting incoming internet traffic through the attacker's servers, where it can be hijacked and injected with malicious websites and pornographic advertisements. The trojan also installs a watchdog process that ensures the victim's DNS records stay modified on a minute-by-minute basis.
    SecureMac's DNSChanger Removal Tool allows users to check to see if the trojan has been installed on their computer; if it has, the software helps to identify and remove the offending file. After a system reboot, the users' DNS records will be repaired.

  • Trojan Horse pakes?

    I have some sort of Trojan horse on my iMAC (running Mavericks 10.9.5). When I check the console, there are 1000s of processes going on per second and they repetitively say:
    "10/13/14 7:51:53.579 AM proxyhost[22202]: 67.198.140.250:2122 - - [13/Oct/2014:07:51:53 -0700] "GET http://us-u.openx.net/w/1.0/sd?id=537073142&val=RUIDdzr1pcqq7bm659gajgpbbd5mgaxr 8t4yzbrfwht3uyidafrw9hqy==== HTTP/1.1" 302 401 895"
    10/13/14 7:51:53.505 AM proxyhost[22200]: Made direct (non-proxy) connection to syndication.exoclick.com:80
    10/13/14 7:51:53.000 AM kernel[0]: proc: table is full
    for example. The websites keep changing.
    I've scanned for malware with ClamXV and MacScan and found nothing. I have been blocked from my network. They said I have a trojan horse "pakes".
    Here is the etrecheck report (I'm no longer connected to the ethernet so the processes have stopped. I'm not sure if this matters for what people want to see):
    EtreCheck version: 1.9.15 (52)
    Report generated October 13, 2014 at 7:52:18 AM PDT
    Hardware Information: ?
      iMac (27-inch, Mid 2011) (Verified)
      iMac - model: iMac12,2
      1 3.4 GHz Intel Core i7 CPU: 4 cores
      8 GB RAM
    Video Information: ?
      AMD Radeon HD 6970M - VRAM: 1024 MB
      iMac 2560 x 1440
    System Software: ?
      OS X 10.9.5 (13F34) - Uptime: 2 days 19:28:14
    Disk Information: ?
      Hitachi HDS722020ALA330 disk0 : (2 TB)
      S.M.A.R.T. Status: Verified
      EFI (disk0s1) <not mounted>: 209.7 MB
      Macintosh HD (disk0s2) / [Startup]: 2 TB (1.19 TB free)
      Recovery HD (disk0s3) <not mounted>: 650 MB
      OPTIARC DVD RW AD-5680H
    USB Information: ?
      Apple Computer, Inc. IR Receiver
      Apple Internal Memory Card Reader
      Apple Inc. BRCM2046 Hub
      Apple Inc. Bluetooth USB Host Controller
      Apple Inc. FaceTime HD Camera (Built-in)
    Thunderbolt Information: ?
      Apple Inc. thunderbolt_bus
    Gatekeeper: ?
      Anywhere
    Problem System Launch Daemons: ?
      [failed] com.apple.security.syspolicy.plist
    Launch Daemons: ?
      [loaded] com.adobe.fpsaud.plist Support
      [loaded] com.adobe.SwitchBoard.plist Support
      [loaded] com.barebones.authd.plist Support
      [loaded] com.bombich.ccc.plist Support
      [running] com.bombich.ccc.scheduledtask.4CD02F29-DEED-4CEF-AB0E-270D9AAA53AB.plist Support
      [invalid] com.landesk.broker.plist
      [invalid] com.landesk.cba8.plist
      [invalid] com.landesk.ldwatch.plist
      [invalid] com.landesk.msgsys.plist
      [invalid] com.landesk.pds.plist
      [invalid] com.landesk.pds1.plist
      [loaded] com.landesk.pds2.plist Support
      [invalid] com.landesk.remote.plist
      [loaded] com.microsoft.office.licensing.helper.plist Support
      [loaded] com.oracle.java.JavaUpdateHelper.plist Support
    Launch Agents: ?
      [not loaded] com.adobe.AAM.Updater-1.0.plist Support
    User Launch Agents: ?
      [loaded] com.adobe.AAM.Updater-1.0.plist Support
      [loaded] com.adobe.ARM.[...].plist Support
      [loaded] com.adobe.ARM.[...].plist Support
      [running] com.bombich.ccc-user-agent.plist Support
      [loaded] com.google.keystone.agent.plist Support
      [not loaded] com.spotify.webhelper.plist Support
    User Login Items: ?
      Dropbox
    Internet Plug-ins: ?
      FlashPlayer-10.6: Version: 15.0.0.152 - SDK 10.6 Support
      Default Browser: Version: 537 - SDK 10.9
      AdobePDFViewerNPAPI: Version: 10.1.3 Support
      CouponPrinter-FireFox_v2: Version: Version 1.1.6 Support
      AdobePDFViewer: Version: 9.5.5 Support
      Flash Player: Version: 15.0.0.152 - SDK 10.6 Support
      QuickTime Plugin: Version: 7.7.3
      SharePointBrowserPlugin: Version: 14.1.4 - SDK 10.6 Support
      JavaAppletPlugin: Version: Java 7 Update 55 Check version
    Audio Plug-ins: ?
      BluetoothAudioPlugIn: Version: 1.0 - SDK 10.9
      AirPlay: Version: 2.0 - SDK 10.9
      AppleAVBAudio: Version: 203.2 - SDK 10.9
      iSightAudio: Version: 7.7.3 - SDK 10.9
    iTunes Plug-ins: ?
      Quartz Composer Visualizer: Version: 1.4 - SDK 10.9
    User Internet Plug-ins ?
      WebEx64: Version: 1.0 - SDK 10.6 Support
      Aspera Web 3.3.3.81344: Version: (null) - SDK 10.6 Support
      npBcsMcTcIO: Version: (null) Support
      Picasa: Version: 1.0 - SDK 10.6 Support
    3rd Party Preference Panes: ?
      Flash Player  Support
      Growl  Support
      LANDesk Agent  Support
      TeXDistPrefPane  Support
    Time Machine: ?
      Time Machine not configured!
    Top Processes by CPU: ?
          4% WindowServer
          1% hidd
          1% Console
          1% notifyd
          0% Microsoft Word
    Top Processes by Memory: ?
      311 MB com.apple.IconServicesAgent
      205 MB mds_stores
      180 MB Finder
      172 MB Microsoft Word
      156 MB softwareupdated
    Virtual Memory Information: ?
      1.49 GB Free RAM
      3.57 GB Active RAM
      1.67 GB Inactive RAM
      1.25 GB Wired RAM
      2.74 GB Page-ins
      400 KB Page-outs
    Message was edited by: biomed2014

    1. This procedure is a diagnostic test. It changes nothing, for better or worse, and therefore will not, in itself, solve the problem. But with the aid of the test results, the solution may take a few minutes, instead of hours or days.
    Don't be put off by the complexity of these instructions. The process is much less complicated than the description. You do harder tasks with the computer all the time.
    2. If you don't already have a current backup, back up all data before doing anything else. The backup is necessary on general principle, not because of anything in the test procedure. Backup is always a must, and when you're having any kind of trouble with the computer, you may be at higher than usual risk of losing data, whether you follow these instructions or not.
    There are ways to back up a computer that isn't fully functional. Ask if you need guidance.
    3. Below are instructions to run a UNIX shell script, a type of program. As I wrote above, it changes nothing. It doesn't send or receive any data on the network. All it does is to generate a human-readable report on the state of the computer. That report goes nowhere unless you choose to share it. If you prefer, you can act on it yourself without disclosing the contents to me or anyone else.
    You should be wondering whether you can believe me, and whether it's safe to run a program at the behest of a stranger. In general, no, it's not safe and I don't encourage it.
    In this case, however, there are a couple of ways for you to decide whether the program is safe without having to trust me. First, you can read it. Unlike an application that you download and click to run, it's transparent, so anyone with the necessary skill can verify what it does.
    You may not be able to understand the script yourself. But variations of the script have been posted on this website thousands of times over a period of years. The site is hosted by Apple, which does not allow it to be used to distribute harmful software. Any one of the millions of registered users could have read the script and raised the alarm if it was harmful. Then I would not be here now and you would not be reading this message.
    Nevertheless, if you can't satisfy yourself that these instructions are safe, don't follow them. Ask for other options.
    4. Here's a summary of what you need to do, if you choose to proceed:
    ☞ Copy a line of text in this window to the Clipboard.
    ☞ Paste into the window of another application.
    ☞ Wait for the test to run. It usually takes a few minutes.
    ☞ Paste the results, which will have been copied automatically, back into a reply on this page.
    The sequence is: copy, paste, wait, paste again. You don't need to copy a second time. Details follow.
    5. You may have started the computer in "safe" mode. Preferably, these steps should be taken in “normal” mode, under the conditions in which the problem is reproduced. If the system is now in safe mode and works well enough in normal mode to run the test, restart as usual. If you can only test in safe mode, do that.
    6. If you have more than one user, and the one affected by the problem is not an administrator, then please run the test twice: once while logged in as the affected user, and once as an administrator. The results may be different. The user that is created automatically on a new computer when you start it for the first time is an administrator. If you can't log in as an administrator, test as the affected user. Most personal Macs have only one user, and in that case this section doesn’t apply. Don't log in as root.
    7. The script is a single long line, all of which must be selected. You can accomplish this easily by triple-clicking anywhere in the line. The whole line will highlight, though you may not see all of it in the browser window, and you can then copy it. If you try to select the line by dragging across the part you can see, you won't get all of it.
    Triple-click anywhere in the line of text below on this page to select it:
    PATH=/usr/bin:/bin:/usr/sbin:/sbin:/usr/libexec;clear;cd;p=(Software Hardware Memory Diagnostics Power FireWire Thunderbolt USB Fonts SerialATA 4 1000 25 5120 KiB/s 1024 85 \\b%% 20480 1 MB/s 25000 ports ' com.clark.\* \*dropbox \*genieo\* \*GoogleDr\* \*k.AutoCAD\* \*k.Maya\* vidinst\* ' DYLD_INSERT_LIBRARIES\ DYLD_LIBRARY_PATH -86 "` route -n get default|awk '/e:/{print $2}' `" 25 N\\/A down up 102400 25600 recvfrom sendto CFBundleIdentifier 25 25 25 1000 MB com.apple.AirPortBaseStationAgent 464843899 51 5120 files );N5=${#p[@]};p[N5]=` networksetup -listnetworkserviceorder|awk ' NR>1 { sub(/^\([0-9]+\) /,"");n=$0;getline;} $NF=="'${p[26]}')" { sub(/.$/,"",$NF);print n;exit;} ' `;f=('\n%s: %s\n' '\n%s\n\n%s\n' '\nRAM details\n%s\n' %s\ %s '%s\n-\t%s\n' );S0() { echo ' { q=$NF+0;$NF="";u=$(NF-1);$(NF-1)="";gsub(/^ +| +$/,"");if(q>='${p[$1]}') printf("%s (UID %s) is using %s '${p[$2]}'",$0,u,q);} ';};s=(' s/[0-9A-Za-z._]+@[0-9A-Za-z.]+\.[0-9A-Za-z]{2,4}/EMAIL/g;/\/Shared/!s/(\/Users\/)[^ /]+/\1USER/g;s/[-0-9A-Fa-f]{22,}/UUID/g;' ' s/^ +//;/de: S|[nst]:/p;' ' {sub(/^ +/,"")};/er:/;/y:/&&$2<'${p[10]} ' 1s/://;3,6d;/[my].+:/d;s/^ {4}//;H;${ g;s/\n$//;/s: [^EO]|x([^08]|02[^F]|8[^0])/p;} ' ' 5h;6{ H;g;/P/!p;} ' ' ($1~/^Cy/&&$3>'${p[11]}')||($1~/^Cond/&&$2!~/^N/) ' ' /:$/{ N;/:.+:/d;s/ *://;b0'$'\n'' };/^ *(V.+ [0N]|Man).+ /{ s/ 0x.... //;s/[()]//g;s/(.+: )(.+)/ (\2)/;H;};$b0'$'\n'' d;:0'$'\n'' x;s/\n\n//;/Apple[ ,]|Genesy|Intel|SMSC/d;s/\n.*//;/\)$/p;' ' s/^.*C/C/;H;${ g;/No th|pms/!p;} ' '/= [^GO]/p' '{$1=""};1' ' /Of/!{ s/^.+is |\.//g;p;} ' ' $0&&!/ / { n++;print;} END { if(n<200) print "com.apple.";} ' ' $3~/[0-9]:[0-9]{2}$/ { gsub(/:[0-9:a-f]{14}/,"");} { print|"tail -n'${p[12]}'";} ' ' NR==2&&$4<='${p[13]}' { print $4;} ' ' END { $2/=256;if($2>='${p[15]}') print int($2) } ' ' NR!=13{next};{sub(/[+-]$/,"",$NF)};'"`S0 21 22`" 'NR!=2{next}'"`S0 37 17`" ' NR!=5||$8!~/[RW]/{next};{ $(NF-1)=$1;$NF=int($NF/10000000);for(i=1;i<=3;i++){$i="";$(NF-1-i)="";};};'"`S0 19 20`" 's:^:/:p' '/\.kext\/(Contents\/)?Info\.plist$/p' 's/^.{52}(.+) <.+/\1/p' ' /Launch[AD].+\.plist$/ { n++;print;} END { print "'${p[41]}'";if(n<200) print "/System/";} ' '/\.xpc\/(Contents\/)?Info\.plist$/p' ' NR>1&&!/0x|\.[0-9]+$|com\.apple\.launchctl\.(Aqua|Background|System)$|'${p[41]}'/ { print $3;} ' ' /\.(framew|lproj)|\):/d;/plist:|:.+(Mach|scrip)/s/:[^:]+//p ' '/^root$/p' ' !/\/Contents\/.+\/Contents|Applic|Autom|Frameworks/&&/Lib.+\/Info.plist$/ { n++;print;} END { if(n<1100) print "/System/";} ' '/^\/usr\/lib\/.+dylib$/p' ' /Temp|emac/{next};/(etc|Preferences|Launch[AD].+)\// { sub(".(/private)?","");n++;print;} END { print "'${p[41]}'.plist\t'${p[42]}'";if(n<500) print "Launch";} ' ' /\/(Contents\/.+\/Contents|Frameworks)\/|\.wdgt\/.+\.([bw]|plu)/d;p;' 's/\/(Contents\/)?Info.plist$//;p' ' { gsub("^| |\n","\\|\\|kMDItem'${p[35]}'=");sub("^...."," ") };1 ' p '{print $3"\t"$1}' 's/\'$'\t''.+//p' 's/1/On/p' '/Prox.+: [^0]/p' '$2>'${p[43]}'{$2=$2-1;print}' ' BEGIN { i="'${p[26]}'";M1='${p[16]}';M2='${p[18]}';M3='${p[31]}';M4='${p[32]}';} !/^A/{next};/%/ { getline;if($5<M1) a="user "$2"%, system "$4"%";} /disk0/&&$4>M2 { b=$3" ops/s, "$4" blocks/s";} $2==i { if(c) { d=$3+$4+$5+$6;next;};if($4>M3||$6>M4) c=int($4/1024)" in, "int($6/1024)" out";} END { if(a) print "CPU: "a;if(b) print "I/O: "b;if(c) print "Net: "c" (KiB/s)";if(d) print "Net errors: "d" packets/s";} ' ' /r\[0\] /&&$NF!~/^1(0|72\.(1[6-9]|2[0-9]|3[0-1])|92\.168)\./ { print $NF;exit;} ' ' !/^T/ { printf "(static)";exit;} ' '/apsd|BKAg|OpenD/!s/:.+//p' ' (/k:/&&$3!~/(255\.){3}0/ )||(/v6:/&&$2!~/A/ ) ' ' $1~"lR"&&$2<='${p[25]}';$1~"li"&&$3!~"wpa2";' ' BEGIN { FS=":";p="uniq -c|sed -E '"'s/ +\\([0-9]+\\)\\(.+\\)/\\\2 x\\\1/;s/x1$//'"'";} { n=split($3,a,".");sub(/_2[01].+/,"",$3);print $2" "$3" "a[n]$1|p;b=b$1;} END { close(p);if(b) print("\n\t* Code injection");} ' ' NR!=4{next} {$NF/=10240} '"`S0 27 14`" ' END { if($3~/[0-9]/)print$3;} ' ' BEGIN { L='${p[36]}';} !/^[[:space:]]*(#.*)?$/ { l++;if(l<=L) f=f"\n   "$0;} END { F=FILENAME;if(!F) exit;if(!f) f="\n   [N/A]";"file -b "F|getline T;if(T!~/^(AS.+ (En.+ )?text$|(Bo|PO).+ sh.+ text ex)/) F=F" ("T")";printf("\nContents of %s\n%s\n",F,f);if(l>L) printf("\n   ...and %s more line(s)\n",l-L);} ' ' s/^ ?n...://p;s/^ ?p...:/-'$'\t''/p;' 's/0/Off/p' ' END{print NR} ' ' /id: N|te: Y/{i++} END{print i} ' ' / / { print "'"${p[28]}"'";exit;};1;' '/ en/!s/\.//p' ' NR!=13{next};{sub(/[+-M]$/,"",$NF)};'"`S0 39 40`" ' $10~/\(L/&&$9!~"localhost" { sub(/.+:/,"",$9);print $1": "$9;} ' '/^ +r/s/.+"(.+)".+/\1/p' 's/(.+\.wdgt)\/(Contents\/)?Info\.plist$/\1/p' 's/^.+\/(.+)\.wdgt$/\1/p' ' /l: /{ /DVD/d;s/.+: //;b0'$'\n'' };/s: /{ /V/d;s/^ */- /;H;};$b0'$'\n'' d;:0'$'\n'' x;/APPLE [^:]+$/d;p;' ' /^find: /d;p;' "`S0 44 45`" ' BEGIN{FS="= "} /Path/{print $2} ' ' /^ *$/d;s/^ */   /;' );c1=(system_profiler pmset\ -g nvram fdesetup find syslog df vm_stat sar ps sudo\ crontab sudo\ iotop top pkgutil 'PlistBuddy 2>&1 -c "Print' whoami cksum kextstat launchctl sudo\ launchctl crontab 'sudo defaults read' stat lsbom mdfind ' for i in ${p[24]};do ${c1[18]} ${c2[27]} $i;done;' defaults\ read scutil sudo\ dtrace sudo\ profiles sed\ -En awk /S*/*/P*/*/*/C*/*/airport networksetup mdutil sudo\ lsof test osascript\ -e );c2=(com.apple.loginwindow\ LoginHook '" /L*/P*/loginw*' "'tell app \"System Events\" to get properties of login items'|tr , \\\n" 'L*/Ca*/com.ap*.Saf*/E*/* -d 1 -name In*t -exec '"${c1[14]}"' :CFBundleDisplayName" {} \;|sort|uniq' '~ $TMPDIR.. \( -flags +sappnd,schg,uappnd,uchg -o ! -user $UID -o ! -perm -600 \)' '.??* -path .Trash -prune -o -type d -name *.app -print -prune' :${p[35]}\" :Label\" '{/,}L*/{Con,Pref}* -type f ! -size 0 -name *.plist -exec plutil -s {} \;' "-f'%N: %l' Desktop L*/Keyc*" therm sysload boot-args status " -F '\$Time \$Message' -k Sender kernel -k Message Req 'bad |Beac|caug|corru|dead[^bl]|FAIL|fail|GPU |hfs: Ru|inval|jnl:|last value [1-9]|n Cause: -|NVDA\(|pagin|proc: t|Roamed|rror|ssert|Thrott|tim(ed? ?|ing )o|WARN' -k Message Rne 'Goog|ksadm|SMC:| VALI|xpma' -o -k Sender fseventsd -k Message Req 'SL' " '-du -n DEV -n EDEV 1 10' 'acrx -o comm,ruid,%cpu' '-t1 10 1' '-f -pfc /var/db/r*/com.apple.*.{BS,Bas,Es,J,OSXU,Rem,up}*.bom' '{/,}L*/Lo*/Diag* -type f -regex .\*[cgh] ! -name *ag \( -exec grep -lq "^Thread c" {} \; -exec printf \* \; -o -true \) -execdir stat -f:%Sc:%N -t%F {} \;|sort -t: -k2 |tail -n'${p[38]} '/S*/*/Ca*/*xpc* >&- ||echo No' '-L /{S*/,}L*/StartupItems -type f -exec file {} +' '-L /S*/L*/{C*/Sec*A,E}* {/,}L*/{A*d,Ca*/*/Ex,Co{mpon,reM},Ex,In{p,ter},iTu*/*P,Keyb,Mail/B,Pr*P,Qu*T,Scripti,Sec,Servi,Spo,Widg}* -path \\*s/Resources -prune -o -type f -name Info.plist' '/usr/lib -type f -name *.dylib' `awk "${s[31]}"<<<${p[23]}` "/e*/{auto,{cron,fs}tab,hosts,{[lp],sy}*.conf,pam.d/*,ssh{,d}_config,*.local} {,/usr/local}/etc/periodic/*/* /L*/P*{,/*}/com.a*.{Bo,sec*.ap}*t {/S*/,/,}L*/Lau*/*t .launchd.conf" list getenv /Library/Preferences/com.apple.alf\ globalstate --proxy '-n get default' -I --dns -getdnsservers\ "${p[N5]}" -getinfo\ "${p[N5]}" -P -m\ / '' -n1 '-R -l1 -n1 -o prt -stats command,uid,prt' '--regexp --only-files --files com.apple.pkg.*|sort|uniq' -kl -l -s\ / '-R -l1 -n1 -o mem -stats command,uid,mem' '+c0 -i4TCP:0-1023' com.apple.dashboard\ layer-gadgets '-d /L*/Mana*/$USER&&echo On' '-app Safari WebKitDNSPrefetchingEnabled' "+c0 -l|awk '{print(\$1,\$3)}'|sort|uniq -c|sort -n|tail -1|awk '{print(\$2,\$3,\$1)}'" );N1=${#c2[@]};for j in {0..9};do c2[N1+j]=SP${p[j]}DataType;done;N2=${#c2[@]};for j in 0 1;do c2[N2+j]="-n ' syscall::'${p[33+j]}':return { @out[execname,uid]=sum(arg0) } tick-10sec { trunc(@out,1);exit(0);} '";done;l=(Restricted\ files Hidden\ apps 'Elapsed time (s)' POST Battery Safari\ extensions Bad\ plists 'High file counts' User Heat System\ load boot\ args FileVault Diagnostic\ reports Log 'Free space (MiB)' 'Swap (MiB)' Activity 'CPU per process' Login\ hook 'I/O per process' Mach\ ports kexts Daemons Agents XPC\ cache Startup\ items Admin\ access Root\ access Bundles dylibs Apps Font\ issues Inserted\ dylibs Firewall Proxies DNS TCP/IP Wi-Fi Profiles Root\ crontab User\ crontab 'Global login items' 'User login items' Spotlight Memory Listeners Widgets Parental\ Controls Prefetching SATA Descriptors );N3=${#l[@]};for i in 0 1 2;do l[N3+i]=${p[5+i]};done;N4=${#l[@]};for j in 0 1;do l[N4+j]="Current ${p[29+j]}stream data";done;A0() { id -G|grep -qw 80;v[1]=$?;((v[1]==0))&&sudo true;v[2]=$?;v[3]=`date +%s`;clear >&-;date '+Start time: %T %D%n';};for i in 0 1;do eval ' A'$((1+i))'() { v=` eval "${c1[$1]} ${c2[$2]}"|'${c1[30+i]}' "${s[$3]}" `;[[ "$v" ]];};A'$((3+i))'() { v=` while read i;do [[ "$i" ]]&&eval "${c1[$1]} ${c2[$2]}" \"$i\"|'${c1[30+i]}' "${s[$3]}";done<<<"${v[$4]}" `;[[ "$v" ]];};A'$((5+i))'() { v=` while read i;do '${c1[30+i]}' "${s[$1]}" "$i";done<<<"${v[$2]}" `;[[ "$v" ]];};';done;A7(){ v=$((`date +%s`-v[3]));};B2(){ v[$1]="$v";};for i in 0 1;do eval ' B'$i'() { v=;((v['$((i+1))']==0))||{ v=No;false;};};B'$((3+i))'() { v[$2]=`'${c1[30+i]}' "${s[$3]}"<<<"${v[$1]}"`;} ';done;B5(){ v[$1]="${v[$1]}"$'\n'"${v[$2]}";};B6() { v=` paste -d: <(printf "${v[$1]}") <(printf "${v[$2]}")|awk -F: ' {printf("'"${f[$3]}"'",$1,$2)} ' `;};B7(){ v=`grep -Fv "${v[$1]}"<<<"$v"`;};C0() { [[ "$v" ]]&&sed -E "$s"<<<"$v";};C1() { [[ "$v" ]]&&printf "${f[$1]}" "${l[$2]}" "$v";};C2() { v=`echo $v`;[[ "$v" != 0 ]]&&C1 0 $1;};C3() { v=`sed -E "${s[63]}"<<<"$v"`&&C1 1 $1;};for i in 1 2;do for j in 0 2 3;do eval D$i$j'(){ A'$i' $1 $2 $3; C'$j' $4;};';done;done;{ A0;D20 0 $((N1+1)) 2;D10 0 $N1 1;B0;C2 27;B0&&! B1&&C2 28;D12 15 37 25 8;A1 0 $((N1+2)) 3;C0;D13 0 $((N1+3)) 4 3;D23 0 $((N1+4)) 5 4;D13 0 $((N1+9)) 59 50;for i in 0 1 2;do D13 0 $((N1+5+i)) 6 $((N3+i));done;D13 1 10 7 9;D13 1 11 8 10;D22 2 12 9 11;D12 3 13 10 12;D23 4 19 44 13;D23 5 14 12 14;D22 6 36 13 15;D22 7 37 14 16;D23 8 15 38 17;D22 9 16 16 18;B1&&{ D22 35 49 61 51;D22 11 17 17 20;for i in 0 1;do D22 28 $((N2+i)) 45 $((N4+i));done;};D22 12 44 54 45;D22 12 39 15 21;A1 13 40 18;B2 4;B3 4 0 19;A3 14 6 32 0;B4 0 5 11;A1 17 41 20;B7 5;C3 22;B4 4 6 21;A3 14 7 32 6;B4 0 7 11;B3 4 0 22;A3 14 6 32 0;B4 0 8 11;B5 7 8;B1&&{ A2 19 26 23;B7 7;C3 23;};A2 18 26 23;B7 7;C3 24;D13 4 21 24 26;B4 4 12 26;B3 4 13 27;A1 4 22 29;B7 12;B2 14;A4 14 6 52 14;B2 15;B6 14 15 4;B3 0 0 30;C3 29;A1 4 23 27;B7 13;C3 30;D13 24 24 32 31;D13 25 37 32 33;A2 23 18 28;B2 16;A2 16 25 33;B7 16;B3 0 0 34;B2 21;A6 47 21&&C0;B1&&{ D13 21 0 32 19;D13 10 42 32 40;D22 29 35 46 39;};D23 14 1 62 42;D12 34 43 53 44;D12 22 20 32 25;D22 0 $((N1+8)) 51 32;D13 4 8 41 6;D12 26 28 35 34;D13 27 29 36 35;A2 27 32 39&&{ B2 19;A2 33 33 40;B2 20;B6 19 20 3;};C2 36;D23 33 34 42 37;B1&&D23 35 45 55 46;D23 32 31 43 38;D12 36 47 32 48;D13 20 42 32 41;D13 37 2 48 43;D13 4 5 32 1;D13 4 3 60 5;D12 26 48 49 49;B3 4 22 57;A1 26 46 56;B7 22;B3 0 0 58;C3 47;D22 4 4 50 0;D23 22 9 37 7;A7;C2 2;} 2>/dev/null|pbcopy;exit 2>&-
    Copy the selected text to the Clipboard by pressing the key combination command-C.
    8. Launch the built-in Terminal application in any of the following ways:
    ☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)
    ☞ In the Finder, select Go ▹ Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.
    ☞ Open LaunchPad. Click Utilities, then Terminal in the icon grid.
    Click anywhere in the Terminal window and paste by pressing command-V. The text you pasted should vanish immediately. If it doesn't, press the return key.
    9. If you see an error message in the Terminal window such as "Syntax error" or "Event not found," enter
    exec bash
    and press return. Then paste the script again.
    10. If you're logged in as an administrator, you'll be prompted for your login password. Nothing will be displayed when you type it. You will not see the usual dots in place of typed characters. Make sure caps lock is off. Type carefully and then press return. You may get a one-time warning to be careful. If you make three failed attempts to enter the password, the test will run anyway, but it will produce less information. In most cases, the difference is not important. If you don't know the password, or if you prefer not to enter it, press the key combination control-C or just press return  three times at the password prompt. Again, the script will still run.
    If you're not logged in as an administrator, you won't be prompted for a password. The test will still run. It just won't do anything that requires administrator privileges.
    11. The test may take a few minutes to run, depending on how many files you have and the speed of the computer. A computer that's abnormally slow may take longer to run the test. While it's running, there will be nothing in the Terminal window and no indication of progress. Wait for the line
    [Process completed]
    to appear. If you don't see it within half an hour or so, the test probably won't complete in a reasonable time. In that case, close the Terminal window and report what happened. No harm will be done.
    12. When the test is complete, quit Terminal. The results will have been copied to the Clipboard automatically. They are not shown in the Terminal window. Please don't copy anything from there. All you have to do is start a reply to this comment and then paste by pressing command-V again.
    At the top of the results, there will be a line that begins with the words "Start time." If you don't see that, but instead see a mass of gibberish, you didn't wait for the "Process completed" message to appear in the Terminal window. Please wait for it and try again.
    If any private information, such as your name or email address, appears in the results, anonymize it before posting. Usually that won't be necessary.
    13. When you post the results, you might see an error message on the web page: "You have included content in your post that is not permitted," or "You are not authorized to post." That's a bug in the forum software. Please post the test results on Pastebin, then post a link here to the page you created.
    14. This is a public forum, and others may give you advice based on the results of the test. They speak only for themselves, and I don't necessarily agree with them.
    Copyright © 2014 by Linc Davis. As the sole author of this work, I reserve all rights to it except as provided in the Use Agreement for the Apple Support Communities website ("ASC"). Readers of ASC may copy it for their own personal use. Neither the whole nor any part may be redistributed.

  • New Trojan Horses

    Last night, I made the mistake of downloading an app called "Wine" and "Winebottler". These are apps that allow Windows programs to be played on Macintosh without installing Windows. I ended up with 13 new OSX Trojan Horses on my Macintosh. These apps kept on installing add ons to the iTunes Store. I knew I was in trouble immediately, I guess, by instinct.I had also installed Wineskin for the same purpose, but I don't think that was the problem as I found no Trojan Horses associated with this app. I had my security set to download from App Store and Trusted Developers only. I am now going to upgrade my security to download from App Store only now, but I don't know for sure if that will help.
    Luckily, I had Kaspersky on my Mac, and it kept on finding Trojan Horses on a full scan. I had firevault on and iCloud on. I am wondering now if my iCloud account is infected. I am currently erasing my whole hard drive and reinstalling. I will not turn on iCloud until I get some advice. For those that are unaware, I know we are in a cyberwar. I don't know where these apps originated, but I wanted the community to know this. I've used Macintosh since the first day it was available in 1984. I've never had troubles with viruses and Trojan Horses like this, except for two that were found by Kaspersky a couple of months ago and were easily found, isolated and disinfected. Not these. Most were easily disinfected: all but two. I had to restart the computer and Kaspersky got rid of them. Kaspersky is a great program, but I wasn't sure if it got rid of everything, which led me to erase and reinstall.
    Please inform my about how secure iCloud is against attached viruses or should I delete my account.

    etresoft wrote:
    straycat23 wrote:
    I downloaded from WineHQ.org.
    I doubt that because WineHQ doesn't have any Mac versions of Wine available. They distribute Linux binaries and source. If you downloaded a Mac version, it must have come from somewhere else.
    As soon as I downloaded it and the Winebottler, I knew I had problems.
    Why?
    I took your earlier advice: left OS10.9.1 in place and turned iCloud back on. I hope I made the right decision. I did not delete Kaspersky because OSX did not delete the Trojan or prevent it from being downloaded. Kaspersky did.
    But you are in a catch-22 situation here. These forums are full of people reporting problems with computers and antivirus is a very common cause. By comparison, there are far fewer people reporting problems with trojans. Are these programs really trojans? And even if they are, would they cause as much trouble and be as difficult to remove as antivirus? I doubt it
    As far as I can tell WineHQ must be a trusted developer, because that is how my computer is set as I previously stated.
    I would definitely consider WineHQ to be trustworthy (more so than antivirus vendors) but they definitely do not have an Apple Developer ID that would enable them to distribute software past Gatekeeper. Someone malicious may have repackaged Wine, added trojans, and signed it with a Developer ID. The only way to address that problem is to identify where you got the software so that the illicit Developer ID can be revoked.
    I did not download these programs to play games. That's for Millenials. I downloaded these because Windows is a disaster, and I didn't want to load Windows on my computer. There are Windows programs that there is no equivalent in Mac.
    It doesn't matter why you downloaded them. If they are Windows programs, you are going to have to run Windows. Wine is a cool project, but very little software actually works on it.
    I also deleted Adobe Flash Player as was advised in another thread. Now I can't see instructions in YouTube. Does the App Store have a recommended flash player to see You Tube?
    Download Adobe Flash directly from Adobe and installer. Then download the Click2Flash Safari extension: http://hoyois.github.io/safariextensions/clicktoplugin/ so you can avoid Flash, if possible. If you ever get any Flash popup asking for an update, always close it - always. Then go to the Adobe Flash site yourself and see if there is an update and download it.
    I downloaded the program from WineHQ. It's in my history. I went back and looked today. I don't think Linux has an iTunes version. I downloaded a program I didn't request that attached itself to iTunes. This is how I knew I had problems.
    I appreciate all the advice: dismissive or not. It did give me confidence there's nothing wrong with my computer. I just don't have faith in Mac like I used to. I'm guessing that the trojans were not real, but I'm glad I had a device to delete the false positives, if for no other reason than it made me feel better. Any website can be attacked by hackers. Maybe that's what happened to WineHQ.

Maybe you are looking for

  • Calendar displays different items in list vs day/month view

    I have a strange problem. When viewing my Calendar items in List view, the items are all wrong for the day. But in Day & Month view they are correct. I have tried resetting my sync history, and also removing all items, then checking the replacing ite

  • PowerBook G4 15 Keyboard not working during Leopard install

    I need help! I have a powerbook G4 I wanted to sell. I was looking on amazon at a few reviews, and I found a MacBook Pro review that said how to do a reset of the entire computer. I was excited, because I wanted to sell, and I did it. Here is what it

  • Format Date Range in Select Statement e.b. 4/10/14 - 4/09/15

    So far thanks for all the help you've provided me on here. I'm a long time Access developer and have just worked with SQL very little throughout the years but now I'm working full-scale in it, so a learning process for me. I am familiar with the Date

  • Maximum number of emails supported in a folder

    Hi Guys, What is the maximum number of emails you can in one folder on iPhone 5S? We have a user whose Exchange mailbox is around 16.5GB and he has about 93K items overall and around 20K in the sent items. Intermittently he loses emails from his Sent

  • What is the '4' in the ABAP/4?

    hi what is the exact meaning of 4 in the ABAP/4? can any one plz postme the answers for this one. Thanks & Regards Gani