22.12.2016, 20:25
|
#1 |
| Ist mein Mac infiziert? Versteckter Trojaner möglich? habe mich mal etwas durchgeklickt und paar themen zu meiner frage gelesen. möchte einfach mal mein system durchchecken lassen und wissen ob es infiziert ist oder nicht.. gibt es sonst vll noch möglichkeiten einen hack / trojaner auszuschließen??
hier der log: Zitat:
EtreCheck version: 3.1.5 (343)
Report generated 2016-12-22 20:18:58
Download EtreCheck from https://etrecheck.com
Runtime 1:52
Performance: Excellent
Click the [Support] links for help with non-Apple products.
Click the [Details] links for more information about that line.
Problem: No problem - just checking
Hardware Information: ⓘ
MacBook Pro (Retina, 15-inch, Late 2013)
[Technical Specifications] - [User Guide] - [Warranty & Service]
MacBook Pro - model: MacBookPro11,3
1 2,6 GHz Intel Core i7 (i7-4960HQ) CPU: 4-core
16 GB RAM Not upgradeable
BANK 0/DIMM0
8 GB DDR3 1600 MHz ok
BANK 1/DIMM0
8 GB DDR3 1600 MHz ok
Bluetooth: Good - Handoff/Airdrop2 supported
Wireless: en0: 802.11 a/b/g/n/ac
Battery: Health = Replace Soon - Cycle count = 1350
Video Information: ⓘ
Intel Iris Pro
NVIDIA GeForce GT 750M - VRAM: 2048 MB
Color LCD 2880 x 1800
System Software: ⓘ
macOS Sierra 10.12.2 (16C67) - Time since boot: about 9 hours
Disk Information: ⓘ
APPLE SSD SM0512F disk0 : (500,28 GB) (Solid State - TRIM: Yes)
[Show SMART report]
EFI (disk0s1) <not mounted> : 210 MB
Recovery HD (disk0s3) <not mounted> [Recovery]: 650 MB
Macintosh HD (disk1) / [Startup]: 499.05 GB (168.36 GB free)
Core Storage: disk0s2 499.42 GB Online
USB Information: ⓘ
Apple Inc. Apple Internal Keyboard / Trackpad
Apple Inc. BRCM20702 Hub
Apple Inc. Bluetooth USB Host Controller
Sony Computer Entertainment Wireless Controller
Thunderbolt Information: ⓘ
Apple Inc. thunderbolt_bus
Configuration files: ⓘ
/etc/sysctl.conf - File exists but not expected
/etc/hosts - Count: 6
Gatekeeper: ⓘ
Mac App Store and identified developers
Kernel Extensions: ⓘ
/Applications/BlockBlock.app
[loaded] com.objectiveSee.kext.BlockBlock (0.9.4 - SDK 10.11 - 2015-12-25) [Support]
/Applications/HMA! Pro VPN.app
[not loaded] com.Privax.AppFirewall (1.0 - SDK 10.10 - 2015-03-13) [Support]
/Applications/Kies.app
[not loaded] com.devguru.driver.SamsungACMControl (1.4.20 - SDK 10.6 - 2014-09-16) [Support]
[not loaded] com.devguru.driver.SamsungACMData (1.4.20 - SDK 10.6 - 2014-09-16) [Support]
[not loaded] com.devguru.driver.SamsungComposite (1.4.20 - SDK 10.6 - 2014-09-16) [Support]
[not loaded] com.devguru.driver.SamsungMTP (1.4.20 - SDK 10.5 - 2014-09-16) [Support]
[not loaded] com.devguru.driver.SamsungSerial (1.4.20 - SDK 10.6 - 2014-09-16) [Support]
/Applications/Private Eye.app
[loaded] com.radiosilenceapp.nke.PrivateEye (1.1 - SDK 10.11 - 2016-10-21) [Support]
/Applications/Radio Silence.app
[loaded] com.radiosilenceapp.nke.filter (2.0 - SDK 10.11 - 2016-12-08) [Support]
/Library/Application Support/Kaspersky Lab/KAV/Bases/Cache
[loaded] com.kaspersky.kext.kimul.46 (46 - 2016-12-22) [Support]
[loaded] com.kaspersky.kext.mark.1.0.6 (1.0.6 - SDK 10.9 - 2016-12-22) [Support]
/Library/Application Support/VirtualBox
[not loaded] org.virtualbox.kext.VBoxDrv (4.3.12 - 2014-10-17) [Support]
[not loaded] org.virtualbox.kext.VBoxNetAdp (4.3.12 - 2014-10-17) [Support]
[not loaded] org.virtualbox.kext.VBoxNetFlt (4.3.12 - 2014-10-17) [Support]
[not loaded] org.virtualbox.kext.VBoxUSB (4.3.12 - 2014-10-17) [Support]
/Library/Extensions
[not loaded] com.bitdefender.TMProtection (5.0.0 - SDK 10.11 - 2016-12-21) [Support]
[loaded] com.kaspersky.kext.klif (3.4.2a30 - 2016-12-21) [Support]
[loaded] com.kaspersky.nke (2.1.0 - 2016-12-21) [Support]
[not loaded] foo.tap (20111101 - 2016-12-21) [Support]
[not loaded] foo.tun (20111101 - 2016-12-21) [Support]
/System/Library/Extensions
[not loaded] au.com.glassechidna.heimdall_usb_shield (6.0 - 2016-12-21) [Support]
[not loaded] com.eltima.SyncMate.kext (0.2.5b15 - 2016-12-21) [Support]
Startup Items: ⓘ
tap: Path: /Library/StartupItems/tap
tun: Path: /Library/StartupItems/tun
Startup items no longer function in OS X Yosemite or later
System Launch Agents: ⓘ
[not loaded] 7 Apple tasks
[loaded] 174 Apple tasks
[running] 99 Apple tasks
System Launch Daemons: ⓘ
[not loaded] 42 Apple tasks
[loaded] 166 Apple tasks
[running] 104 Apple tasks
Launch Agents: ⓘ
[running] com.Monity.Helper.plist (2016-11-24) [Support]
[not loaded] com.adobe.AAM.Updater-1.0.plist (2016-10-06) [Support]
[loaded] com.google.keystone.agent.plist (2016-08-24) [Support]
[running] com.kaspersky.kav.gui.plist (2016-12-22) [Support]
[loaded] com.oracle.java.Java-Updater.plist (2016-12-07) [Support]
[loaded] com.radiosilenceapp.agent.plist (2016-12-08) [Support]
[loaded] org.macosforge.xquartz.startx.plist (2014-08-12) [Support]
[failed] syncmateStarter.plist (2013-12-17) [Support] - /Library/Application Support/EltimaSyncMate/SyncMateServer.app/Contents/MacOS/SyncMateServer: Executable not found!
Launch Daemons: ⓘ
[loaded] com.adobe.SwitchBoard.plist (2013-11-01) [Support]
[running] com.adobe.agsservice.plist (2016-10-05) [Support]
[loaded] com.google.keystone.daemon.plist (2016-09-02) [Support]
[running] com.kaspersky.kav.plist (2016-12-22) [Support]
[loaded] com.malwarebytes.HelperTool.plist (2016-12-03) [Support]
[loaded] com.microsoft.office.licensing.helper.plist (2012-11-05) [Support]
[running] com.objective-see.ransomwhere.plist (2016-05-24) [Support]
[running] com.objectiveSee.blockblock.plist (2016-12-03) [Support]
[loaded] com.oracle.java.Helper-Tool.plist (2016-09-23) [Support]
[loaded] com.radiosilenceapp.nke.PrivateEye.plist (2016-12-10)
[loaded] com.radiosilenceapp.nke.plist (2016-12-10)
[loaded] com.securemac.MacScanDaemon.plist (2016-10-29) [Support]
[loaded] org.macosforge.xquartz.privileged_startx.plist (2014-08-12) [Support]
[not loaded] org.virtualbox.startup.plist (2014-07-07) [Support]
[failed] rapiback.plist (2013-12-17) [Support] - /Library/Application Support/EltimaSyncMate/BackService.app/Contents/MacOS/rapiback: Executable not found!
User Launch Agents: ⓘ
[loaded] com.adobe.AAM.Updater-1.0.plist (2016-05-23) [Support]
[running] com.objectiveSee.blockblock.plist (2016-12-03) [Support]
[running] com.spotify.webhelper.plist (2016-12-22) [Support]
[loaded] com.valvesoftware.steamclean.plist (2016-12-19) [Support]
[not loaded] org.virtualbox.vboxwebsrv.plist (2014-07-07) [Support] - /Applications/VirtualBox.app/Contents/MacOS/vboxwebsrv: Executable not found!
[loaded] uk.co.canimaansoftware.clamxav.UninstallWatcher.plist (2016-12-10)
User Login Items: ⓘ
iTunesHelper Programm (2016-12-14)
(/Applications/iTunes.app/Contents/MacOS/iTunesHelper.app)
puush Programm
(/Applications/puush.app)
Dropbox Programm
(/Applications/Dropbox.app)
OverSight Helper Programm (2016-10-07)
(/Applications/OverSight.app/Contents/Library/LoginItems/OverSight Helper.app)
HMA! Pro VPN Programm
(/Applications/HMA! Pro VPN.app)
Internet Plug-ins: ⓘ
AdobeAAMDetect: AdobeAAMDetect 1.0.0.0 - SDK 10.6 (2016-05-23) [Support]
FlashPlayer-10.6: 24.0.0.186 - SDK 10.9 (2016-12-13) [Support]
QuickTime Plugin: 7.7.3 (2016-12-14)
Flash Player: 24.0.0.186 - SDK 10.9 (2016-12-13) [Support]
Unity Web Player: UnityPlayer version 5.3.4f1 - SDK 10.6 (2016-04-21) [Support]
o1dbrowserplugin: 5.41.3.0 - SDK 10.8 (2016-07-19) [Support]
SharePointBrowserPlugin: 14.4.3 - SDK 10.6 (2014-08-14) [Support]
googletalkbrowserplugin: 5.41.3.0 - SDK 10.8 (2015-12-11) [Support]
Silverlight: 5.1.41105.0 - SDK 10.6 (2015-12-19) [Support]
MeetingJoinPlugin: Unknown - SDK 10.6 (2014-08-14) [Support]
JavaAppletPlugin: Java 8 Update 111 build 14 (2016-12-22) Check version
Safari Extensions: ⓘ
AdBlock - BetaFish, Inc. - https://getadblock.com (2016-12-22)
Onscreen Keyboard - Kaspersky Lab - hxxp://kaspersky.com (2016-08-31)
Open in Internet Explorer - Parallels - hxxp://www.parallels.com (2014-03-02)
URL Advisor - Kaspersky Lab - hxxp://kaspersky.com (2016-08-31)
Ghostery - GHOSTERY, Inc. - https://www.ghostery.com/ (2016-08-31)
3rd Party Preference Panes: ⓘ
Flash Player (2016-12-11) [Support]
Java (2016-09-23) [Support]
Perian (2011-07-23) [Support]
Time Machine: ⓘ
Time Machine not configured!
Top Processes by CPU: ⓘ
10% (dumpcap)
7% com.apple.WebKit.WebContent(14)
5% kernel_task
5% Safari
3% WindowServer
Top Processes by Memory: ⓘ
4.34 GB com.apple.WebKit.WebContent(14)
2.21 GB Safari
1.48 GB kernel_task
475 MB Finder
360 MB WindowServer
Virtual Memory Information: ⓘ
2.77 GB Available RAM
64 MB Free RAM
13.23 GB Used RAM
2.71 GB Cached files
0 B Swap Used
Diagnostics Information: ⓘ
Dec 22, 2016, 10:24:21 AM Self test - passed
Dec 22, 2016, 01:46:39 AM ~/Library/Logs/DiagnosticReports/MonityExtension_2016-12-22-014639_[redacted].crash
com.Monity.Widget - /Applications/Monity.app/Contents/PlugIns/MonityExtension.appex/Contents/MacOS/MonityExtension
Dec 21, 2016, 12:24:22 PM /Library/Logs/DiagnosticReports/kav_2016-12-21-122422_[redacted].crash
/Library/Application Support/Kaspersky Lab/*/kav
Dec 21, 2016, 12:21:26 PM /Library/Logs/DiagnosticReports/kav_2016-12-21-122126_[redacted].crash
Dec 21, 2016, 10:56:56 AM ~/Library/Logs/DiagnosticReports/MonityExtension_2016-12-21-105656_[redacted].crash
Dec 21, 2016, 10:07:53 AM /Library/Logs/DiagnosticReports/kav_2016-12-21-100753_[redacted].crash
Dec 20, 2016, 01:25:17 PM /Library/Logs/DiagnosticReports/Spotify_2016-12-20-132517_[redacted].cpu_resource.diag [Details]
/Applications/Spotify.app/Contents/MacOS/Spotify
Dec 20, 2016, 12:53:56 PM ~/Library/Logs/DiagnosticReports/MonityExtension_2016-12-20-125356_[redacted].crash
Dec 20, 2016, 12:47:09 PM /Library/Logs/DiagnosticReports/Dropbox_2016-12-20-124709_[redacted].cpu_resource.diag [Details]
/Applications/Dropbox.app/Contents/MacOS/Dropbox
Dec 20, 2016, 02:02:54 AM /Library/Logs/DiagnosticReports/com.apple.WebKit.WebContent_2016-12-20-020254_[redacted].cpu_resource.diag [Details]
/System/Library/Frameworks/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.WebContent.xpc/Contents/MacOS/com.apple.WebKit.WebContent | kenne mich mit der ganzen thematik nicht wirklich aus, habe zwar immer kaspersky genutzt aber es könnte sein, dass ich infizierte emails erhalten habe (evtl zip oder auch bilderdateien) würde mich riesig freuen wenn mir jemand unterstützung bei diesem thema geben könnte. über tipps und weiteres bin ich euch dankbar. |