|
Alles rund um Mac OSX & Linux: Malwarebytes entdeckt Trojaner - in Quarantäne nicht zu findenWindows 7 Für alle Fragen rund um Mac OSX, Linux und andere Unix-Derivate. |
24.03.2018, 14:32 | #16 |
| Malwarebytes entdeckt Trojaner - in Quarantäne nicht zu finden Nein ich habe es noch nicht am Kabel getestet, wenn du eine Ethernet Verbindung meinst. Ich müsste mir hierfür einen Adapter und ein Kabel kaufen. Ist das zwingend notwendig? Meinst du es liegt vielleicht am WLAN-Modul? Hier mein Log-File: Code:
ATTFilter Timestamp (14): Sat Mar 24 14:28:51 2018 DetectX Swift v1.060 macOS: Version 10.13.3 (Build 17D102) File System: apfs Temp: The thermal state is within normal limits. Boot time: Sat Mar 24 13:46:18 2018 Uptime: 43 mins, 2 users Spotlight status for /: Indexing enabled. System Integrity Protection status: enabled. Gatekeeper status: enabled for App Store and identified developers. FileVault is Off. Internet: Reachable Hardware Overview: Model Name: MacBook Pro Model Identifier: MacBookPro10,1 Processor Name: Intel Core i7 Processor Speed: 2.3 GHz Number of Processors: 1 Total Number of Cores: 4 L2 Cache (per Core): 256 KB L3 Cache: 6 MB Memory: 8 GB Boot ROM Version: MBP101.00F2.B00 SMC Version (system): 2.3f36 Sharing Preferences: File Sharing: On Screen Sharing: On Remote Management: On Back To My Mac: Off Remote Login: Off Remote Apple Events: Off 3rd Party Kexts (loaded): com.malwarebytes.mbam.rtprotection $PATH: PATH=/usr/bin:/bin:/usr/sbin:/sbin /etc/paths: /usr/local/bin /usr/bin /bin /usr/sbin /sbin /etc/paths.d/: /Library/TeX/texbin /opt/X11/bin ~/.bash_profile: ~/.bashrc: /usr/local/bin /usr/bin /bin /usr/sbin /sbin /opt/X11/bin /path/to/whtaever ~/.bash_login: ~/.profile: ~/.bash_logout: PID Status Label - 0 com.skype.skype.shareagent 408 0 com.malwarebytes.mbam.frontend.agent - 0 com.openssh.ssh-agent - 0 com.adobe.ARM.202f4087f2bbde52e3ac2df389f53a4f123223c9cc56a8fd83a6f7ae - 0 com.google.keystone.system.agent - 0 com.sqwarq.DetectX-Swift.observer - 0 com.valvesoftware.steamclean - 0 org.macosforge.xquartz.startx - 0 com.cisco.anyconnect.gui - 0 com.cisco.anyconnect.notification - 0 com.adobe.AAM.Scheduler-1.0 407 0 com.hp.devicemonitor - 0 com.oracle.java.Java-Updater 419 0 QA2G25RMZ4.com.wunderkinder.wunderlist-helper 428 0 OpenObject.fuspredownloader.3944 413 0 com.spotify.webhelper 427 0 com.getdropbox.dropbox.18852 410 0 com.greentreeapplications.YTD-Helper - 0 com.dropbox.DropboxMacUpdate.agent System Launchd processes: 61 - com.malwarebytes.mbam.rtprotection.daemon 0 - com.malwarebytes.HelperTool 66 - com.cisco.anyconnect.vpnagentd 0 - com.vix.cron 0 - com.microsoft.office.licensing.helper 0 - org.macosforge.xquartz.privileged_startx 0 - org.postfix.master 0 - com.ea.origin.ESHelper 0 - com.google.keystone.daemon 0 - com.teamviewer.Helper 0 - com.microsoft.office.licensingV2.helper 0 - com.microsoft.autoupdate.helper 0 - com.disc-soft.DAEMONTools.PrivilegedHelper 91 - Adobe_Genuine_Software_Integrity_Service 0 - org.cups.cupsd 0 - com.adobe.fpsaud 0 - com.anchorfree.ajaxserver 261 - com.malwarebytes.mbam.settings.daemon 0 - com.oracle.java.Helper-Tool User Login Items: Dropbox Mail AdobeResourceSynchronizer CleanMyMac 3 Menu Android File Transfer Agent fuspredownloader /Library/LaunchDaemons: com.malwarebytes.mbam.settings.daemon.plist -> Program: /Library/Application Support/Malwarebytes/MBAM/Engine.bundle/Contents/PlugIns/SettingsDaemon.app/Contents/MacOS/SettingsDaemon com.adobe.agsservice.plist --> Program Arguments: /Library/Application Support/Adobe/AdobeGCClient/AGSService com.malwarebytes.mbam.rtprotection.daemon.plist -> Program: /Library/Application Support/Malwarebytes/MBAM/Engine.bundle/Contents/PlugIns/RTProtectionDaemon.app/Contents/MacOS/RTProtectionDaemon org.macosforge.xquartz.privileged_startx.plist --> Program Arguments: /opt/X11/lib/X11/xinit/privileged_startx --> Program Arguments: -d --> Program Arguments: /opt/X11/lib/X11/xinit/privileged_startx.d com.google.keystone.daemon.plist --> Program Arguments: /Library/Google/GoogleSoftwareUpdate/GoogleSoftwareUpdate.bundle/Contents/MacOS/GoogleSoftwareUpdateDaemon com.teamviewer.Helper.plist -> Program: /Library/PrivilegedHelperTools/com.teamviewer.Helper --> Program Arguments: /Library/PrivilegedHelperTools/com.teamviewer.Helper com.disc-soft.DAEMONTools.PrivilegedHelper.plist --> Program Arguments: /Library/PrivilegedHelperTools/com.disc-soft.DAEMONTools.PrivilegedHelper com.malwarebytes.HelperTool.plist -> Program: /Library/PrivilegedHelperTools/com.malwarebytes.HelperTool --> Program Arguments: /Library/PrivilegedHelperTools/com.malwarebytes.HelperTool com.cisco.anyconnect.vpnagentd.plist --> Program Arguments: /opt/cisco/anyconnect/bin/vpnagentd --> Program Arguments: -execv_instance com.teamviewer.teamviewer_service.plist --> Program Arguments: /Applications/TeamViewer.app/Contents/MacOS/TeamViewer_Service --> Program Arguments: -Module --> Program Arguments: Full com.adobe.fpsaud.plist --> Program Arguments: /Library/Application Support/Adobe/Flash Player Install Manager/fpsaud com.ea.origin.ESHelper.plist --> Program Arguments: /Library/PrivilegedHelperTools/com.ea.origin.ESHelper com.anchorfree.ajaxserver.plist -> Program: /Library/Application Support/Hotspot Shield/ajaxserver --> Program Arguments: /Library/Application Support/Hotspot Shield/ajaxserver com.microsoft.office.licensingV2.helper.plist -> Program: /Library/PrivilegedHelperTools/com.microsoft.office.licensingV2.helper --> Program Arguments: /Library/PrivilegedHelperTools/com.microsoft.office.licensingV2.helper com.oracle.java.Helper-Tool.plist --> Program Arguments: /Library/Internet Plug-Ins/JavaAppletPlugin.plugin/Contents/Resources/Helper-Tool com.microsoft.office.licensing.helper.plist --> Program Arguments: /Library/PrivilegedHelperTools/com.microsoft.office.licensing.helper com.microsoft.autoupdate.helper.plist -> Program: /Library/PrivilegedHelperTools/com.microsoft.autoupdate.helper /Library/LaunchAgents: com.teamviewer.teamviewer_desktop.plist --> Program Arguments: /Applications/TeamViewer.app/Contents/Helpers/TeamViewer_Desktop --> Program Arguments: -RunAsAgent --> Program Arguments: YES --> Program Arguments: -Module --> Program Arguments: Full com.google.keystone.agent.plist --> Program Arguments: /Library/Google/GoogleSoftwareUpdate/GoogleSoftwareUpdate.bundle/Contents/Resources/GoogleSoftwareUpdateAgent.app/Contents/MacOS/GoogleSoftwareUpdateAgent --> Program Arguments: -runMode --> Program Arguments: ifneeded com.cisco.anyconnect.gui.plist --> Program Arguments: open --> Program Arguments: --wait-apps --> Program Arguments: /Applications/Cisco/Cisco AnyConnect Secure Mobility Client.app org.macosforge.xquartz.startx.plist --> Program Arguments: /opt/X11/lib/X11/xinit/launchd_startx --> Program Arguments: /opt/X11/bin/startx --> Program Arguments: -- --> Program Arguments: /opt/X11/bin/Xquartz com.teamviewer.teamviewer.plist --> Program Arguments: /Applications/TeamViewer.app/Contents/MacOS/TeamViewer --> Program Arguments: -RunAsAgent --> Program Arguments: YES com.malwarebytes.mbam.frontend.agent.plist -> Program: /Library/Application Support/Malwarebytes/MBAM/Engine.bundle/Contents/PlugIns/FrontendAgent.app/Contents/MacOS/FrontendAgent com.oracle.java.Java-Updater.plist --> Program Arguments: /Library/Internet Plug-Ins/JavaAppletPlugin.plugin/Contents/Resources/Java Updater.app/Contents/MacOS/Java Updater --> Program Arguments: -bgcheck com.adobe.AAM.Updater-1.0.plist -> Program: /Library/Application Support/Adobe/OOBE/PDApp/UWA/UpdaterStartupUtility --> Program Arguments: /Library/Application Support/Adobe/OOBE/PDApp/UWA/UpdaterStartupUtility --> Program Arguments: -mode=logon com.adobe.GC.Invoker-1.0.plist -> Program: /Library/Application Support/Adobe/AdobeGCClient/agcinvokerutility --> Program Arguments: /Library/Application Support/Adobe/AdobeGCClient/agcinvokerutility --> Program Arguments: -mode=logon com.cisco.anyconnect.notification.plist --> Program Arguments: open --> Program Arguments: --wait-apps --> Program Arguments: /opt/cisco/anyconnect/bin/Cisco AnyConnect Secure Mobility Client Notification.app ~/Library/LaunchAgents: com.adobe.ARM.202f4087f2bbde52e3ac2df389f53a4f123223c9cc56a8fd83a6f7ae.plist --> Program Arguments: /Applications/Adobe Reader.app/Contents/MacOS/Updater/Adobe Reader Updater Helper.app/Contents/MacOS/Adobe Reader Updater Helper com.adobe.AAM.Updater-1.0.plist -> Program: /Library/Application Support/Adobe/OOBE/PDApp/UWA/UpdaterStartupUtility --> Program Arguments: /Library/Application Support/Adobe/OOBE/PDApp/UWA/UpdaterStartupUtility --> Program Arguments: -mode=scheduled com.hp.devicemonitor.plist --> Program Arguments: /Library/Printers/hp/Frameworks/HPDeviceMonitoring.framework/Versions/1.0/Helpers/HP Device Monitor Manager.app/Contents/Library/LoginItems/HP Device Monitor.app/Contents/MacOS/HP Device Monitor com.adobe.GC.Invoker-1.0.plist -> Program: /Library/Application Support/Adobe/AdobeGCClient/agcinvokerutility --> Program Arguments: /Library/Application Support/Adobe/AdobeGCClient/agcinvokerutility --> Program Arguments: -mode=scheduled com.skype.skype.shareagent.plist -> Program: /Applications/Skype.app/Contents/Library/LaunchServices/com.skype.skype.shareagent.bundle/Contents/MacOS/com.skype.skype.shareagent com.dropbox.DropboxMacUpdate.agent.plist --> Program Arguments: /Users/[U501]/Library/Dropbox/DropboxMacUpdate.app/Contents/MacOS/DropboxMacUpdate --> Program Arguments: -check --> Program Arguments: periodic com.valvesoftware.steamclean.plist -> Program: /Users/[U501]/Library/Application Support/Steam/SteamApps/steamclean --> Program Arguments: /Users/[U501]/Library/Application Support/Steam/SteamApps/steamclean --> Program Arguments: Public com.sqwarq.DetectX-Swift.observer.plist --> Program Arguments: /Applications/DetectX Swift.app/Contents/MacOS/DetectX Swift --> Program Arguments: -observer com.spotify.webhelper.plist -> Program: /Users/[U501]/Library/Application Support/Spotify/SpotifyWebHelper User Crontab: No cron jobs /etc: rc.common php.ini.default-5.2-previous~orig bashrc_Apple_Terminal .hosts.swp bashrc hosts.prl_bak zshrc ssh_config~orig hosts.save authorization.deprecated moduli~previous bashrc-Original rc.netboot efax.rc~previous php.ini.default-previous~orig php.ini.default-5.2-previous sshd_config~previous aliases zprofile / $Root: .HFS+ Private Directory Data / .. children: 1 .PKInstallSandboxManager / .. children: 0 file collectionCache.bnk Incompatible Software / .. children: 3 installer.failurerequests .file Benutzerinformationen .Trashes / .. children: 0 opt / .. children: 4 .apdisk .dbfseventsd ~/ $Home: intel / .. children: 1 .eclipse / .. children: 11 .config / .. children: 4 Music / .. children: 4 libtool .cfir$$.$$$ .anyconnect .vim / .. children: 1 EB17 DMSB_Suspension.zip iCloud Drive (Archiv) / .. children: 3 .soncukfe eclipse / .. children: 1 .lldb / .. children: 2 .CFUserTextEncoding test / .. children: 4 .tooling / .. children: 1 bin / .. children: 1 .subversion / .. children: 4 .jssc / .. children: 1 .bashrc .fqlpegarc Makefile .adobe / .. children: 2 .mime.types .local / .. children: 1 Creative Cloud Files / .. children: 1 Pictures / .. children: 5 .rnd 0 Samsung / .. children: 3 .assistant / .. children: 1 .p2 / .. children: 6 Desktop / .. children: 34 Library / .. children: 83 .matplotlib / .. children: 2 1 config.system .oracle_jre_usage / .. children: 11 .android / .. children: 2 .cups / .. children: 1 .bash_sessions / .. children: 33 config.status .matlab / .. children: 2 Public / .. children: 3 .dropbox / .. children: 13 .jchempaint / .. children: 0 .dia-etc / .. children: 6 .cisco / .. children: 1 examples / .. children: 2 .sh_history .dtLiteMacLicense.dat .ssh / .. children: 2 Applications (Parallels) / .. children: 3 Movies / .. children: 7 Applications / .. children: 6 .filezilla / .. children: 6 lib / .. children: 1 Dropbox / .. children: 10 Data_Inp.dat .Trash / .. children: 9 doc / .. children: 7 config.log Documents / .. children: 24 .mailcap .mcf / .. children: 2 mpich-doxygen .Xauthority Downloads / .. children: 80 restore / .. children: 0 .cache / .. children: 3 config.lt COSMOlogicAppData / .. children: 1 .bash_history .viminfo PlayOnMac's virtual drives config.nice src / .. children: 15 ~/Library: TeXShop / .. children: 16 Receipts / .. children: 4 Filters / .. children: 2 Wunderlist / .. children: 3 Touchgrind / .. children: 4 Address Book Plug-Ins / .. children: 4 Mobile Documents.1954483901 / .. children: 11 viaverbifree / .. children: 1 Arduino15 / .. children: 7 Google / .. children: 2 Network / .. children: 1 Family / .. children: 1 Personas / .. children: 3 MC Domination / .. children: 2 Icons / .. children: 1 Dropbox / .. children: 1 Fonts Disabled / .. children: 0 Frameworks / .. children: 2 RescueTime.com / .. children: 2 Widgets / .. children: 1 ~/Library/Application Support: Firefox / .. children: 4 Librarian / .. children: 1 com.apple.sbd / .. children: 0 Ulysses / .. children: 4 Propellerhead Software / .. children: 2 SyncServices / .. children: 1 Mozilla / .. children: 1 com.apple.touristd / .. children: 11 DiskImages / .. children: 1 Steam / .. children: 9 iLifeAssetManagement / .. children: 4 iLifePageLayout / .. children: 1 HP / .. children: 1 NCH Software / .. children: 2 BibDesk / .. children: 6 audacity / .. children: 3 MobileSync / .. children: 1 com.apple.QuickLook / .. children: 1 Google / .. children: 4 GeoComply / .. children: 1 Ubisoft Game Launcher / .. children: 5 Microsoft / .. children: 2 HTC_FOTA / .. children: 1 HTC Sync Manager / .. children: 1 Spotify / .. children: 9 .FUS / .. children: 7 Oracle / .. children: 1 Mindjet / .. children: 1 PokerStarsEU / .. children: 6 YTD / .. children: 6 Bitdefender Virus Scanner / .. children: 7 Wine / .. children: 3 T / .. children: 1 Sony Corporation / .. children: 2 NetDrive2 / .. children: 6 ETSII / .. children: 16 CEF / .. children: 1 Marble Arena 2 / .. children: 6 Max / .. children: 0 VLC / .. children: 3 Poker Copilot / .. children: 1 Adobe / .. children: 34 Malwarebytes / .. children: 2 org.videolan.vlc / .. children: 1 Gtk2 / .. children: 4 .ACCC_Lock com.operasoftware.Opera / .. children: 32 AnyMP4 Studio / .. children: 1 NotificationCenter / .. children: 2 NVIDIA / .. children: 1 TeamViewer / .. children: 1 Ubiquity / .. children: 3 com.sqwarq.DetectX-Swift / .. children: 4 Aperture / .. children: 0 .settings Dropbox / .. children: 3 Preview / .. children: 0 LaTeXiT / .. children: 0 Origin / .. children: 17 Komodo Edit / .. children: 1 .HotShoppy / .. children: 1 Skype / .. children: 12 Bannister / .. children: 2 Ubisoft / .. children: 1 Trimble Connect for SketchUp / .. children: 1 HTC_DeviceImage / .. children: 1 TechSmith / .. children: 1 Helper / .. children: 0 Bigasoft FLAC Converter 4 / .. children: 1 OnLive App / .. children: 4 SketchUp 2018 / .. children: 6 ConfigurationProfiles / .. children: 1 Impulse / .. children: 0 GIMP / .. children: 1 JREInstaller / .. children: 1 Feral Interactive / .. children: 1 .ADCS_Lock ~/Library/Safari/Extensions: OpenIE.safariextz AdBlock.safariextz Adblock Plus.safariextz Extensions.plist ~/Library/Internet Plug-Ins: Google Earth Web Plug-in.plugin Picasa.plugin /Users/Shared: adi / .. children: 3 SC Info / .. children: 2 HP / .. children: 1 Hotspot Shield / .. children: 1 Library / .. children: 2 Parallels / .. children: 2 Adobe / .. children: 0 .MJMM10Info.log Documents / .. children: 1 .com.hp.Installer.plist TechSmith / .. children: 1 Feral Interactive / .. children: 1 /Applications: Combine PDFs.app VLC.app Malwarebytes Anti-Malware .app Hewlett-Packard / .. children: 6 TeX / .. children: 12 TeamViewer.app Battery Health.app Steam.app Origin.app Google Chrome.app Camtasia 3.app Notebooks.app Mindjet MindManager.app jDownloader.app Dropbox.app Android File Transfer.app Aptana Studio 3 / .. children: 15 Parallels Desktop.app iMovie / .. children: 1 Adobe Reader.app Spotify.app Mein CEWE FOTOBUCH.app Intel(R) Software Manager.app texmaker.app DetectX Swift.app Microsoft Word.app StuffIt Expander.app JDownloader2.app Cisco / .. children: 2 Keychain Access.app GeoGebra 5.app SimplyRAR.app Smart Switch / .. children: 3 Microsoft Excel.app Yamaha Steinberg USB Control Panel.app Microsoft Silverlight Adobe / .. children: 2 MATLAB_R2016b.app Adobe Acrobat XI Pro / .. children: 6 WhatsApp.app Microsoft Outlook.app Adobe Photoshop CC 2015 / .. children: 10 Malwarebytes.app MATLAB_R2016a.app Memory Clean.app Adobe Download Assistant.app YTD.app Microsoft OneNote.app Adobe InDesign CC 2015 / .. children: 14 Skype.app COSMOlogic / .. children: 1 Wunderlist.app Firefox.app PokerStarsEU.app Microsoft PowerPoint.app Evernote.app SketchUp 2018 / .. children: 4 iPhoto.app Adobe Application Manager /Library: settings.dat DropboxHelperTools / .. children: 3 TeX / .. children: 7 Google / .. children: 1 petsc-3.6.3 / .. children: 28 HostUUID backup.zip Automator / .. children: 96 petsc / .. children: 25 Fonts Disabled / .. children: 16 pfutil /Library/Application Support: Propellerhead Software / .. children: 1 Developer / .. children: 1 Mozilla / .. children: 1 Hewlett-Packard / .. children: 6 Steinberg / .. children: 1 Hotspot Shield / .. children: 12 Macromedia / .. children: 5 Microsoft / .. children: 5 Oracle / .. children: 1 iTunes / .. children: 1 Adobe / .. children: 39 Malwarebytes / .. children: 1 .JfQIUKtkcG Origin / .. children: 1 Ubisoft / .. children: 2 regid.1986-12.com.adobe / .. children: 6 /Library/Extensions: acsock.kext EPSONUSBPrintClass.kext MB_MBAM_Protection.kext YamahaSteinbergUSBAudio.kext hp_io_enabler_compound.kext /Library/Internet Plug-Ins: AdobeAAMDetect.plugin Disabled Plug-Ins / .. children: 2 OnLiveGameClientDetector.plugin SharePointBrowserPlugin.plugin Unity Web Player.plugin Silverlight.plugin Flash Player.plugin flashplayer.xpt readerdetect.bundle DirectorShockwave.plugin SharePointWebKitPlugin.webplugin JavaAppletPlugin.plugin PepperFlashPlayer / .. children: 2 /Library/Managed Preferences: *-- Folder doesn't exist --* /Library/PrivilegedHelperTools: com.microsoft.office.licensing.helper com.ea.origin.ESHelper com.teamviewer.Helper com.disc-soft.DAEMONTools.PrivilegedHelper com.malwarebytes.HelperTool com.microsoft.autoupdate.helper com.microsoft.office.licensingV2.helper /Library/ScriptingAdditions: Adobe Unit Types.osax /Library/StartupItems: /Library/Updates: ProductMetadata.plist PPDVersions.plist index.plist Top Processes: %CPU PID COMMAND 4.4 222 WindowServer 2.7 0 kernel_task 2.6 61 RTProtectionDaem 2.3 1722 DetectX Swift 1.5 116 hidd 0.2 427 Dropbox 0.2 1518 Safari 0.1 59 UserEventAgent 0.1 64 fseventsd Running Processes: PPID PID %CPU USER COMMAND 0 1 0.0 root /sbin/launchd 1 58 0.0 root /usr/sbin/syslogd 1 59 0.2 root /usr/libexec/UserEventAgent (System) 1 61 0.1 root /Library/Application Support/Malwarebytes/MBAM/Engine.bundle/Contents/PlugIns/RTProtectionDaemon.app/Contents/MacOS/RTProtectionDaemon 1 62 0.0 root /System/Library/PrivateFrameworks/Uninstall.framework/Resources/uninstalld 1 63 0.0 root /usr/libexec/kextd 1 64 0.0 root /System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/FSEvents.framework/Versions/A/Support/fseventsd 1 66 0.0 root /opt/cisco/anyconnect/bin/vpnagentd -execv_instance 1 67 0.0 root /System/Library/PrivateFrameworks/MediaRemote.framework/Support/mediaremoted 1 69 0.0 _appleevents /System/Library/CoreServices/appleeventsd --server 1 70 0.0 root /usr/sbin/systemstats --daemon 1 72 0.0 root /usr/libexec/configd 1 73 0.0 root /System/Library/CoreServices/powerd.bundle/powerd 1 76 0.0 root /usr/libexec/logd 1 77 0.0 root /usr/libexec/keybagd -t 15 1 82 0.0 root /usr/libexec/warmd 1 83 0.0 root /System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Support/mds 1 84 0.0 _iconservices /System/Library/CoreServices/iconservicesd 1 85 0.0 root /System/Library/CoreServices/iconservicesagent 1 86 0.0 root /usr/libexec/diskarbitrationd 1 89 0.0 root /System/Library/CoreServices/backupd.bundle/Contents/Resources/backupd-helper -launchd 1 90 0.0 root /usr/libexec/coreduetd 1 91 0.0 root /Library/Application Support/Adobe/AdobeGCClient/AGSService 1 94 0.0 root /usr/libexec/opendirectoryd 1 96 0.0 root /System/Library/PrivateFrameworks/ApplePushService.framework/apsd 1 97 0.0 root /System/Library/PrivateFrameworks/Noticeboard.framework/Versions/A/Resources/nbstated 1 98 0.0 root /System/Library/CoreServices/launchservicesd 1 99 0.0 _timed /usr/libexec/timed 1 100 0.0 root /usr/sbin/securityd -i 1 101 0.0 _usbmuxd /System/Library/PrivateFrameworks/MobileDevice.framework/Versions/A/Resources/usbmuxd -launchd 1 103 0.0 _locationd /usr/libexec/locationd 1 104 0.0 root autofsd 1 105 0.0 _displaypolicyd /usr/libexec/displaypolicyd -k 1 1 106 0.0 root /usr/libexec/dasd 1 107 0.0 root /System/Library/PrivateFrameworks/Heimdal.framework/Helpers/kdc 1 110 0.0 [U501] /System/Library/CoreServices/loginwindow.app/Contents/MacOS/loginwindow console 1 111 0.0 root /System/Library/CoreServices/logind 1 112 0.0 root /System/Library/PrivateFrameworks/GenerationalStorage.framework/Versions/A/Support/revisiond 1 113 0.0 root /usr/sbin/KernelEventAgent 1 115 0.0 root /usr/sbin/bluetoothd 1 116 0.4 _hidd /usr/libexec/hidd 1 117 0.0 root /usr/libexec/corebrightnessd --launchd 1 118 0.0 root /usr/libexec/AirPlayXPCHelper 1 119 0.0 root /usr/sbin/notifyd 1 121 0.0 _distnote /usr/sbin/distnoted daemon 1 126 0.0 root /usr/sbin/cfprefsd daemon 1 147 0.0 root /usr/libexec/amfid 1 149 0.0 root /System/Library/Frameworks/Security.framework/Versions/A/XPCServices/authd.xpc/Contents/MacOS/authd 1 150 0.0 root /System/Library/CoreServices/coreservicesd 1 152 0.0 root aslmanager 1 155 0.0 root /usr/libexec/sandboxd 1 157 0.0 root /usr/libexec/trustd 1 159 0.0 root /usr/libexec/lsd runAsRoot 1 160 0.0 root /usr/libexec/nehelper 1 161 0.0 root /System/Library/Frameworks/PCSC.framework/Versions/A/XPCServices/com.apple.ctkpcscd.xpc/Contents/MacOS/com.apple.ctkpcscd 1 166 0.0 _ctkd /System/Library/Frameworks/CryptoTokenKit.framework/ctkd -s 1 171 0.0 root /usr/libexec/airportd 1 172 0.0 root /usr/libexec/mobileassetd 1 173 0.0 root /usr/sbin/ocspd 1 174 0.0 _coreaudiod /usr/sbin/coreaudiod 1 178 0.0 _nsurlsessiond /usr/libexec/nsurlsessiond --privileged 1 179 0.0 _coreaudiod /System/Library/Frameworks/CoreAudio.framework/Versions/A/XPCServices/com.apple.audio.DriverHelper.xpc/Contents/MacOS/com.apple.audio.DriverHelper 1 203 0.0 _mdnsresponder /usr/sbin/mDNSResponder 1 204 0.0 root /System/Library/PrivateFrameworks/WirelessDiagnostics.framework/Support/awdd 1 205 0.0 _analyticsd /System/Library/PrivateFrameworks/CoreAnalytics.framework/Support/analyticsd 1 206 0.0 root /System/Library/Frameworks/AudioToolbox.framework/AudioComponentRegistrar -daemon 1 207 0.0 root /usr/sbin/mDNSResponderHelper 1 208 0.0 _coreaudiod /System/Library/Frameworks/AudioToolbox.framework/XPCServices/com.apple.audio.SandboxHelper.xpc/Contents/MacOS/com.apple.audio.SandboxHelper 1 209 0.0 _nsurlstoraged /usr/libexec/nsurlstoraged --privileged 1 210 0.0 root /System/Library/PrivateFrameworks/PerformanceAnalysis.framework/Versions/A/XPCServices/com.apple.PerformanceAnalysis.animationperfd.xpc/Contents/MacOS/com.apple.PerformanceAnalysis.animationperfd 1 212 0.0 root /usr/libexec/sysmond 70 213 0.0 root /usr/sbin/systemstats --logger-helper /var/db/systemstats 1 214 0.0 _cmiodalassistants /System/Library/Frameworks/CoreMediaIO.framework/Resources/VDC.plugin/Contents/Resources/VDCAssistant 1 215 0.0 root /usr/libexec/apfsd 1 216 0.0 root /usr/libexec/usbd 1 217 0.0 root /usr/libexec/powerlogd 1 218 0.0 root /System/Library/CryptoTokenKit/com.apple.ifdreader.slotd/Contents/MacOS/com.apple.ifdreader 1 219 0.0 root /System/Library/PrivateFrameworks/CoreSymbolication.framework/coresymbolicationd 1 220 0.0 _networkd /usr/libexec/symptomsd 1 221 0.0 root /usr/libexec/ApplicationFirewall/socketfilterfw 1 222 4.1 _windowserver /System/Library/PrivateFrameworks/SkyLight.framework/Resources/WindowServer -daemon 1 223 0.0 root /usr/libexec/syspolicyd 1 228 0.0 root /usr/libexec/smd 1 231 0.0 root /usr/libexec/watchdogd 1 233 0.0 root /System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mds_stores 1 244 0.0 root /usr/libexec/secinitd 1 246 0.0 root /System/Library/Frameworks/OpenGL.framework/Versions/A/Libraries/CVMServer 1 247 0.0 root /usr/libexec/colorsync.displayservices 1 248 0.0 root /usr/libexec/colorsyncd 1 258 0.0 root /System/Library/Frameworks/Security.framework/Versions/A/XPCServices/com.apple.CodeSigningHelper.xpc/Contents/MacOS/com.apple.CodeSigningHelper 1 259 0.0 root /usr/libexec/bootinstalld 1 261 0.0 root /Library/Application Support/Malwarebytes/MBAM/Engine.bundle/Contents/PlugIns/SettingsDaemon.app/Contents/MacOS/SettingsDaemon 1 262 0.0 root /System/Library/CoreServices/sharedfilelistd 1 264 0.0 _captiveagent /usr/libexec/captiveagent 1 266 0.0 root /usr/libexec/findmydeviced 1 268 0.0 root /System/Library/Frameworks/CryptoTokenKit.framework/ctkahp.bundle/Contents/MacOS/ctkahp -d 1 271 0.0 _netbios /usr/sbin/netbiosd 1 276 0.0 root /usr/sbin/systemsoundserverd 1 277 0.0 root /System/Library/PrivateFrameworks/TCC.framework/Resources/tccd system 1 285 0.0 root /System/Library/PrivateFrameworks/AccountPolicy.framework/XPCServices/com.apple.AccountPolicyHelper.xpc/Contents/MacOS/com.apple.AccountPolicyHelper 1 292 0.0 root /System/Library/Frameworks/LocalAuthentication.framework/Support/coreauthd 1 295 0.0 root /System/Library/PrivateFrameworks/SignpostNotification.framework/Versions/A/XPCServices/signpost_notificationd.xpc/Contents/MacOS/signpost_notificationd 1 296 0.0 root /System/Library/Frameworks/ApplicationServices.framework/Frameworks/SpeechSynthesis.framework/Resources/com.apple.speech.speechsynthesisd 1 299 0.0 root /System/Library/PrivateFrameworks/AmbientDisplay.framework/Versions/A/XPCServices/com.apple.AmbientDisplayAgent.xpc/Contents/MacOS/com.apple.AmbientDisplayAgent 1 300 0.0 root /System/Library/PrivateFrameworks/AuthKit.framework/Versions/A/Support/akd 1 301 0.0 _fpsd /System/Library/PrivateFrameworks/CoreADI.framework/adid 1 303 0.0 root /usr/sbin/filecoordinationd 1 306 0.0 root /System/Library/Frameworks/GSS.framework/Helpers/GSSCred 1 308 0.0 root /usr/libexec/diskmanagementd 1 320 0.0 root /usr/libexec/securityd_service 1 321 0.0 [U501] /usr/sbin/cfprefsd agent 1 322 0.0 [U501] /usr/libexec/UserEventAgent (Aqua) 1 324 0.0 [U501] /usr/sbin/distnoted agent 1 325 0.0 [U501] /usr/sbin/universalaccessd launchd -s 1 326 0.1 [U501] /System/Library/Frameworks/CoreTelephony.framework/Support/CommCenter -L 1 327 0.0 [U501] /usr/libexec/trustd --agent 1 329 0.0 [U501] /usr/libexec/lsd 1 331 0.0 [U501] /System/Library/CoreServices/Dock.app/Contents/MacOS/Dock 1 332 0.0 [U501] /System/Library/CoreServices/talagent 1 333 0.0 [U501] /System/Library/CoreServices/SystemUIServer.app/Contents/MacOS/SystemUIServer 1 334 0.0 [U501] /System/Library/CoreServices/Finder.app/Contents/MacOS/Finder 1 337 0.0 [U501] /usr/libexec/secd 1 338 0.0 [U501] /usr/libexec/pboard 1 339 0.0 [U501] /System/Library/PrivateFrameworks/CloudKitDaemon.framework/Support/cloudd 1 340 0.0 [U501] /System/Library/PrivateFrameworks/CloudDocsDaemon.framework/Versions/A/Support/bird 1 342 0.0 [U501] /System/Library/CoreServices/sharedfilelistd 1 344 0.0 [U501] /usr/libexec/pkd 1 345 0.0 [U501] /System/Library/PrivateFrameworks/TCC.framework/Resources/tccd 1 347 0.0 [U501] /usr/libexec/nsurlsessiond 1 348 0.0 [U501] /System/Library/CoreServices/iconservicesagent 1 349 0.0 [U501] /System/Library/Frameworks/Accounts.framework/Versions/A/Support/accountsd 1 352 0.0 root /usr/sbin/WirelessRadioManagerd 1 353 0.0 [U501] /System/Library/PrivateFrameworks/TelephonyUtilities.framework/callservicesd 1 355 0.0 [U501] /System/Library/PrivateFrameworks/IDS.framework/identityservicesd.app/Contents/MacOS/identityservicesd 1 356 0.0 [U501] /System/Library/PrivateFrameworks/CoreCDP.framework/Versions/A/Resources/cdpd 1 357 0.0 [U501] /System/Library/Frameworks/ApplicationServices.framework/Frameworks/ATS.framework/Support/fontd 1 358 0.0 [U501] /System/Library/PrivateFrameworks/IMCore.framework/imagent.app/Contents/MacOS/imagent 1 360 0.0 [U501] /System/Library/PrivateFrameworks/IMDPersistence.framework/XPCServices/IMDPersistenceAgent.xpc/Contents/MacOS/IMDPersistenceAgent 1 361 0.0 [U501] /System/Library/Frameworks/AddressBook.framework/Executables/ContactsAccountsService 1 362 0.0 [U501] /usr/libexec/secinitd 1 363 0.0 [U501] /System/Library/PrivateFrameworks/UserActivity.framework/Agents/useractivityd 1 364 0.0 [U501] /usr/sbin/usernoted 1 365 0.0 [U501] /System/Library/CoreServices/Dock.app/Contents/XPCServices/com.apple.dock.extra.xpc/Contents/MacOS/com.apple.dock.extra 1 366 0.0 [U501] /usr/libexec/sharingd 1 367 0.0 [U501] /System/Library/CoreServices/NotificationCenter.app/Contents/MacOS/NotificationCenter 1 368 0.0 [U501] /System/Library/PrivateFrameworks/AuthKit.framework/Versions/A/Support/akd 1 369 0.0 [U501] /System/Library/CoreServices/Spotlight.app/Contents/MacOS/Spotlight 1 370 0.0 [U501] /Applications/Dropbox.app/Contents/PlugIns/garcon.appex/Contents/MacOS/garcon 1 371 0.0 [U501] /System/Library/PrivateFrameworks/CoreParsec.framework/parsecd 1 372 0.0 root /usr/sbin/wirelessproxd 1 373 0.0 [U501] /usr/libexec/rapportd 1 374 0.0 [U501] /System/Library/PrivateFrameworks/IMFoundation.framework/XPCServices/IMRemoteURLConnectionAgent.xpc/Contents/MacOS/IMRemoteURLConnectionAgent 1 375 0.0 [U501] /System/Library/PrivateFrameworks/GeoServices.framework/Versions/A/XPCServices/com.apple.geod.xpc/Contents/MacOS/com.apple.geod 1 376 0.0 [U501] /System/Library/Frameworks/LocalAuthentication.framework/Support/coreauthd 1 378 0.0 [U501] /usr/libexec/nsurlstoraged 1 379 0.0 [U501] /System/Library/PrivateFrameworks/CommerceKit.framework/Versions/A/Resources/commerce 1 380 0.0 [U501] /System/Library/PrivateFrameworks/CalendarAgent.framework/Executables/CalendarAgent 1 381 0.0 [U501] /System/Library/PrivateFrameworks/CoreWLANKit.framework/Versions/A/XPCServices/WiFiProxy.xpc/Contents/MacOS/WiFiProxy 1 383 0.0 [U501] /System/Library/PrivateFrameworks/MessagesKit.framework/Resources/soagent.app/Contents/MacOS/soagent 1 385 0.0 [U501] /usr/libexec/fmfd 1 386 0.0 [U501] /System/Library/PrivateFrameworks/IMFoundation.framework/XPCServices/IMRemoteURLConnectionAgent.xpc/Contents/MacOS/IMRemoteURLConnectionAgent 1 387 0.0 [U501] /System/Library/PrivateFrameworks/CommerceKit.framework/Versions/A/Resources/storeaccountd 1 388 0.0 [U501] /usr/libexec/networkserviceproxy 1 389 0.0 [U501] /System/Library/PrivateFrameworks/CalendarNotification.framework/Versions/A/XPCServices/CalNCService.xpc/Contents/MacOS/CalNCService 1 391 0.0 [U501] /System/Library/PrivateFrameworks/CallHistory.framework/Support/CallHistoryPluginHelper 1 392 0.0 [U501] /System/Library/CoreServices/CoreLocationAgent.app/Contents/MacOS/CoreLocationAgent 1 393 0.0 [U501] /System/Library/CoreServices/CoreServicesUIAgent.app/Contents/MacOS/CoreServicesUIAgent 1 395 0.0 [U501] /System/Library/PrivateFrameworks/AssistantServices.framework/assistantd 1 396 0.0 [U501] /System/Library/PrivateFrameworks/CoreSpeech.framework/corespeechd 1 397 0.0 [U501] /System/Library/PrivateFrameworks/FileProvider.framework/Support/fileproviderd 1 398 0.0 [U501] /usr/libexec/routined LAUNCHED_BY_LAUNCHD 1 399 0.0 [U501] /usr/sbin/ckkeyrolld 1 401 0.0 [U501] /System/Library/CoreServices/SocialPushAgent.app/Contents/MacOS/SocialPushAgent 1 404 0.0 [U501] /System/Library/Frameworks/InputMethodKit.framework/Resources/imklaunchagent 1 405 0.0 [U501] /System/Library/CoreServices/Siri.app/Contents/MacOS/Siri launchd 1 406 0.0 [U501] /System/Library/Image Capture/Support/icdd 1 407 0.0 [U501] /Library/Printers/hp/Frameworks/HPDeviceMonitoring.framework/Versions/1.0/Helpers/HP Device Monitor Manager.app/Contents/Library/LoginItems/HP Device Monitor.app/Contents/MacOS/HP Device Monitor 1 408 0.0 [U501] /Library/Application Support/Malwarebytes/MBAM/Engine.bundle/Contents/PlugIns/FrontendAgent.app/Contents/MacOS/FrontendAgent 1 409 0.0 [U501] /System/Library/CoreServices/AppleIDAuthAgent 1 410 0.0 [U501] com.greentreeapplications.YTD-Helper 1 413 0.0 [U501] /Users/[U501]/Library/Application Support/Spotify/SpotifyWebHelper 1 414 0.0 [U501] /System/Library/CoreServices/AirPlayUIAgent.app/Contents/MacOS/AirPlayUIAgent --launchd 1 415 0.0 [U501] /usr/libexec/knowledge-agent 1 416 0.0 [U501] /System/Library/CoreServices/cloudpaird 1 418 0.0 [U501] /System/Library/PrivateFrameworks/Noticeboard.framework/Versions/A/Resources/nbagent.app/Contents/MacOS/nbagent 1 419 0.0 [U501] QA2G25RMZ4.com.wunderkinder.wunderlist-helper 1 420 0.0 [U501] /System/Library/CoreServices/diagnostics_agent 1 423 0.0 [U501] /System/Library/CoreServices/backgroundtaskmanagementagent 1 424 0.0 [U501] /System/Library/Frameworks/CryptoTokenKit.framework/ctkahp.bundle/Contents/MacOS/ctkahp 1 425 0.0 root /usr/libexec/taskgated -s 1 426 0.0 [U501] /System/Library/Frameworks/CryptoTokenKit.framework/ctkd -tw 1 427 0.1 [U501] /Applications/Dropbox.app/Contents/MacOS/Dropbox 1 428 0.0 [U501] /Users/[U501]/Library/Application Support/.FUS/fuspredownloader.app/Contents/MacOS/fuspredownloader 1 429 0.0 [U501] /System/Library/PrivateFrameworks/IMFoundation.framework/XPCServices/IMRemoteURLConnectionAgent.xpc/Contents/MacOS/IMRemoteURLConnectionAgent 1 430 0.0 [U501] /System/Library/Input Methods/PressAndHold.app/Contents/PlugIns/PAH_Extension.appex/Contents/MacOS/PAH_Extension 1 433 0.0 [U501] /Applications/Dropbox.app/Contents/MacOS/Dropbox -type:crashpad-handler --capture-python --no-upload-gzip --no-rate-limit --database=/Users/[U501]/.dropbox/Crashpad --metrics-dir=0 --url=https://d.dropbox.com/report_crashpad_minidump --https-pin=0x23,0xf2,0xed,0xff,0x3e,0xde,0x90,0x25,0x9a,0x9e,0x30,0xf4,0xa,0xf8,0xf9,0x12,0xa5,0xe5,0xb3,0x69,0x4e,0x69,0x38,0x44,0x3,0x41,0xf6,0x6,0xe,0x1,0x4f,0xfa --https-pin=0xaf,0xf9,0x88,0x90,0x6d,0xde,0x12,0x95,0x5d,0x9b,0xeb,0xbf,0x92,0x8f,0xdc,0xc3,0x1c,0xce,0x32,0x8d,0x5b,0x93,0x84,0xf2,0x1c,0x89,0x41,0xca,0x26,0xe2,0x3,0x91 --https-pin=0x5a,0x88,0x96,0x47,0x22,0xe,0x54,0xd6,0xbd,0x8a,0x16,0x81,0x72,0x24,0x52,0xb,0xb5,0xc7,0x8e,0x58,0x98,0x4b,0xd5,0x70,0x50,0x63,0x88,0xb9,0xde,0xf,0x7,0x5f --https-pin=0xfe,0xa2,0xb7,0xd6,0x45,0xfb,0xa7,0x3d,0x75,0x3c,0x1e,0xc9,0xa7,0x87,0xc,0x40,0xe1,0xf7,0xb0,0xc5,0x61,0xe9,0x27,0xb9,0x85,0xbf,0x71,0x18,0x66,0xe3,0x6f,0x22 --https-pin=0x76,0xee,0x85,0x90,0x37,0x4c,0x71,0x54,0x37,0xbb,0xca,0x6b,0xba,0x60,0x28,0xea,0xdd,0xe2,0xdc,0x6d,0xbb,0xb8,0xc3,0xf6,0x10,0xe8,0x51,0xf1,0x1d,0x1a,0xb7,0xf5 --https-pin=0x6d,0xbf,0xae,0x0,0xd3,0x7b,0x9c,0xd7,0x3f,0x8f,0xb4,0x7d,0xe6,0x59,0x17,0xaf,0x0,0xe0,0xdd,0xdf,0x42,0xdb,0xce,0xac,0x20,0xc1,0x7c,0x2,0x75,0xee,0x20,0x95 --https-pin=0x1e,0xa3,0xc5,0xe4,0x3e,0xd6,0x6c,0x2d,0xa2,0x98,0x3a,0x42,0xa4,0xa7,0x9b,0x1e,0x90,0x67,0x86,0xce,0x9f,0x1b,0x58,0x62,0x14,0x19,0xa0,0x4,0x63,0xa8,0x7d,0x38 --https-pin=0x87,0xaf,0x34,0xd6,0x6f,0xb3,0xf2,0xfd,0xf3,0x6e,0x9,0x11,0x1e,0x9a,0xba,0x2f,0x6f,0x44,0xb2,0x7,0xf3,0x86,0x3f,0x3d,0xb,0x54,0xb2,0x50,0x23,0x90,0x9a,0xa5 --https-pin=0xbc,0xfb,0x44,0xaa,0xb9,0xad,0x2,0x10,0x15,0x70,0x6b,0x41,0x21,0xea,0x76,0x1c,0x81,0xc9,0xe8,0x89,0x67,0x59,0xf,0x6f,0x94,0xae,0x74,0x4d,0xc8,0x8b,0x78,0xfb --https-pin=0xab,0x98,0x49,0x52,0x76,0xad,0xf1,0xec,0xaf,0xf2,0x8f,0x35,0xc5,0x30,0x48,0x78,0x1e,0x5c,0x17,0x18,0xda,0xb9,0xc8,0xe6,0x7a,0x50,0x4f,0x4f,0x6a,0x51,0x32,0x8f --https-pin=0x49,0x5,0x46,0x66,0x23,0xab,0x41,0x78,0xbe,0x92,0xac,0x5c,0xbd,0x65,0x84,0xf7,0xa1,0xe1,0x7f,0x27,0x65,0x2d,0x5a,0x85,0xaf,0x89,0x50,0x4e,0xa2,0x39,0xaa,0xaa --https-pin=0x56,0x32,0xd9,0x7b,0xfa,0x77,0x5b,0xf3,0xc9,0x9d,0xde,0xa5,0x2f,0xc2,0x55,0x34,0x10,0x86,0x40,0x16,0x72,0x9c,0x52,0xdd,0x65,0x24,0xc8,0xa9,0xc3,0xb4,0x48,0x9f --https-pin=0x2a,0x8f,0x2d,0x8a,0xf0,0xeb,0x12,0x38,0x98,0xf7,0x4c,0x86,0x6a,0xc3,0xfa,0x66,0x90,0x54,0xe2,0x3c,0x17,0xbc,0x7a,0x95,0xbd,0x2,0x34,0x19,0x2d,0xc6,0x35,0xd0 --https-pin=0x32,0xb6,0x4b,0x66,0x72,0x7a,0x20,0x63,0xe4,0x6,0x6f,0x3b,0x95,0x8c,0xb0,0xaa,0xee,0x57,0x6a,0x5e,0xce,0xfd,0x95,0x33,0x99,0xbb,0x88,0x74,0x73,0x1d,0x95,0x87 --https-pin=0xf5,0x3c,0x22,0x5,0x98,0x17,0xdd,0x96,0xf4,0x0,0x65,0x16,0x39,0xd2,0xf8,0x57,0xe2,0x10,0x70,0xa5,0x9a,0xbe,0xd9,0x7,0x94,0x0,0xd9,0xf6,0x95,0x50,0x69,0x0 --https-pin=0x67,0xdc,0x4f,0x32,0xfa,0x10,0xe7,0xd0,0x1a,0x79,0xa0,0x73,0xaa,0xc,0x9e,0x2,0x12,0xec,0x2f,0xfc,0x3d,0x77,0x9e,0xa,0xa7,0xf9,0xc0,0xf0,0xe1,0xc2,0xc8,0x93 --https-pin=0x19,0x6,0xc6,0x12,0x4d,0xbb,0x43,0x85,0x78,0xd0,0xe,0x6,0x6d,0x50,0x54,0xc6,0xc3,0x7f,0xf,0xa6,0x2,0x8c,0x5,0x54,0x5e,0x9,0x94,0xed,0xda,0xec,0x86,0x29 --https-pin=0x1d,0x75,0xd0,0x83,0x1b,0x9e,0x8,0x85,0x39,0x4d,0x32,0xc7,0xa1,0xbf,0xdb,0x3d,0xbc,0x1c,0x28,0xe2,0xb0,0xe8,0x39,0x1f,0xb1,0x35,0x98,0x1d,0xbc,0x5b,0xa9,0x36 --annotation=buildno=Dropbox-mac-45.4.92 --annotation=client_session_id=db49a432-ff4c-45fb-97c8-dcb44de6408d --annotation=host_int_account1_boot=372728435 --annotation=machine_id=c8dbb8d2-9ff5-570a-ba19-eac19e2e7d15 --annotation=platform=mac --annotation=platform_version=10.13.3 --handshake-fd=4 427 434 0.0 [U501] /Applications/Dropbox.app/Contents/MacOS/Dropbox -type:exit-monitor -method:collectupload -session-token:db49a432-ff4c-45fb-97c8-dcb44de6408d -target-handle:427 -target-shutdown-event:4 -target-command-line:/Applications/Dropbox.app/Contents/MacOS/Dropbox 1 437 0.0 [U501] /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/MacOS/ARDAgent 1 438 0.0 root /System/Library/CoreServices/CrashReporterSupportHelper server-init 1 439 0.0 [U501] /System/Library/CoreServices/WiFiAgent.app/Contents/MacOS/WiFiAgent 1 440 0.0 [U501] /System/Library/CoreServices/APFSUserAgent 1 441 0.0 [U501] /System/Library/PrivateFrameworks/PrintingPrivate.framework/Versions/A/PrintUITool 1 443 0.0 [U501] /System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/corespotlightd 1 444 0.0 [U501] /System/Library/CoreServices/cloudphotosd.app/Contents/MacOS/cloudphotosd 1 445 0.0 [U501] /System/Library/PrivateFrameworks/CoreSuggestions.framework/Versions/A/Support/suggestd 1 446 0.0 [U501] /System/Library/PrivateFrameworks/CoreFollowUp.framework/Versions/A/Support/followupd 1 447 0.0 [U501] /System/Library/PrivateFrameworks/PhotoAnalysis.framework/Versions/A/Support/photoanalysisd 1 449 0.0 [U501] /System/Library/CoreServices/mapspushd 1 453 0.0 [U501] /System/Library/CoreServices/pbs 1 454 0.0 [U501] /usr/libexec/videosubscriptionsd 1 457 0.0 [U501] /System/Library/PrivateFrameworks/CacheDelete.framework/deleted 1 478 0.0 [U501] /System/Library/PrivateFrameworks/ContactsAgent.framework/Executables/ContactsAgent 1 543 0.0 [U501] /System/Library/PrivateFrameworks/CloudPhotoServices.framework/Versions/A/Frameworks/CloudPhotosConfigurationXPC.framework/Versions/A/XPCServices/com.apple.CloudPhotosConfiguration.xpc/Contents/MacOS/com.apple.CloudPhotosConfiguration 1 544 0.0 [U501] /System/Library/CoreServices/SafariSupport.bundle/Contents/MacOS/SafariBookmarksSyncAgent 1 550 0.0 [U501] /System/Library/PrivateFrameworks/AssistantServices.framework/Versions/A/XPCServices/media-indexer.xpc/Contents/MacOS/media-indexer 1 575 0.0 [U501] /Library/Frameworks/iTunesLibrary.framework/Versions/A/XPCServices/com.apple.iTunesLibraryService.xpc/Contents/MacOS/com.apple.iTunesLibraryService 1 576 0.0 [U501] /System/Library/PrivateFrameworks/PhotoLibraryPrivate.framework/Versions/A/Support/photolibraryd 1 578 0.0 root /usr/sbin/spindump 1 597 0.0 [U501] /System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdworker -s mdworker -c MDSImporterWorker -m com.apple.mdworker.shared 1 599 0.0 [U501] /System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdworker -s mdworker -c MDSImporterWorker -m com.apple.mdworker.shared 1 600 0.0 [U501] /System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdworker -s mdworker -c MDSImporterWorker -m com.apple.mdworker.shared 1 609 0.0 [U501] /Applications/Dropbox.app/Contents/XPCServices/DropboxActivityProvider.xpc/Contents/MacOS/DropboxActivityProvider 427 626 0.0 root /Library/DropboxHelperTools/Dropbox_u501/dbfseventsd 626 627 0.0 root /Library/DropboxHelperTools/Dropbox_u501/dbfseventsd 1 628 0.0 [U501] /System/Library/Frameworks/Security.framework/Versions/A/Resources/CloudKeychainProxy.bundle/Contents/MacOS/CloudKeychainProxy 1 629 0.0 [U501] /Applications/Dropbox.app/Contents/XPCServices/DropboxFolderTagger.xpc/Contents/MacOS/DropboxFolderTagger 627 630 0.0 [U501] /Library/DropboxHelperTools/Dropbox_u501/dbfseventsd 1 632 0.0 [U501] /System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/DictionaryServices.framework/Versions/A/XPCServices/com.apple.DictionaryServiceHelper.xpc/Contents/MacOS/com.apple.DictionaryServiceHelper 1 633 0.0 [U501] /System/Library/CoreServices/Software Update.app/Contents/Resources/softwareupdate_notify_agent 1 634 0.0 _softwareupdate /System/Library/CoreServices/Software Update.app/Contents/Resources/softwareupdated 1 635 0.0 root /System/Library/CoreServices/Software Update.app/Contents/Resources/suhelperd 1 637 0.0 [U501] /System/Library/PrivateFrameworks/CommerceKit.framework/Versions/A/Resources/storelegacy 1 638 0.0 [U501] /System/Library/PrivateFrameworks/CommerceKit.framework/Versions/A/Resources/storeassetd 1 641 0.0 [U501] /System/Library/PrivateFrameworks/CommerceKit.framework/Resources/LaterAgent.app/Contents/MacOS/LaterAgent 1 643 0.0 [U501] /System/Library/PrivateFrameworks/PassKitCore.framework/passd 1 645 0.0 [U501] /System/Library/PrivateFrameworks/ContactsDonation.framework/Versions/A/Support/contactsdonationagent 1 646 0.0 _applepay /usr/libexec/nfcd 1 651 0.0 _assetcache /usr/libexec/AssetCache/AssetCache 1 652 0.0 root /System/Library/PrivateFrameworks/PackageKit.framework/Resources/installd 1 653 0.0 [U501] /System/Library/PrivateFrameworks/CommerceKit.framework/Versions/A/Resources/storedownloadd 1 654 0.0 root /System/Library/PrivateFrameworks/PackageKit.framework/Resources/system_installd 1 655 0.0 root /usr/bin/sysdiagnose 1 656 0.0 [U501] /System/Library/PrivateFrameworks/QuickLookThumbnailing.framework/Support/com.apple.quicklook.ThumbnailsAgent 1 658 0.0 [U501] /System/Library/Frameworks/MediaLibrary.framework/Versions/A/XPCServices/com.apple.MediaLibraryService.xpc/Contents/MacOS/com.apple.MediaLibraryService 1 743 0.0 _spotlight /System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdworker -s mdworker-sizing -c MDSSizingWorker -m com.apple.mdworker.sizing 1 754 0.0 [U501] /System/Library/Services/AppleSpell.service/Contents/MacOS/AppleSpell 1 756 0.0 [U501] /usr/libexec/keyboardservicesd 1 779 0.0 _spotlight /usr/libexec/trustd --agent 1 782 0.0 _spotlight /usr/sbin/distnoted agent 1 793 0.0 _spotlight /System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdworker -s mdworker -c MDSImporterWorker -m com.apple.mdworker.shared 1 794 0.0 [U501] /System/Library/CoreServices/Siri.app/Contents/XPCServices/SiriNCService.xpc/Contents/MacOS/SiriNCService 1 799 0.0 [U501] /System/Library/PrivateFrameworks/CallHistory.framework/Support/CallHistorySyncHelper 1 800 0.0 [U501] /usr/libexec/siriknowledged 1 801 0.0 [U501] /System/Library/PrivateFrameworks/AskPermission.framework/Versions/A/Resources/askpermissiond 1 802 0.0 [U501] /System/Library/PrivateFrameworks/GameCenterFoundation.framework/Versions/A/gamed 1 816 0.0 [U501] /System/Library/PrivateFrameworks/SafariShared.framework/Versions/A/XPCServices/com.apple.Safari.History.xpc/Contents/MacOS/com.apple.Safari.History 1 817 0.0 [U501] /System/Library/PrivateFrameworks/CommerceKit.framework/Versions/A/XPCServices/com.apple.CommerceKit.TransactionService.xpc/Contents/MacOS/com.apple.CommerceKit.TransactionService 1 818 0.0 [U501] /System/Library/Frameworks/AudioToolbox.framework/AudioComponentRegistrar 1 819 0.0 [U501] /System/Library/Frameworks/AudioToolbox.framework/XPCServices/com.apple.audio.SandboxHelper.xpc/Contents/MacOS/com.apple.audio.SandboxHelper 1 926 0.0 [U501] /Applications/TextEdit.app/Contents/MacOS/TextEdit 1 927 0.0 [U501] /System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdwrite 1 928 0.0 [U501] /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/HIServices.framework/Versions/A/XPCServices/com.apple.hiservices-xpcservice.xpc/Contents/MacOS/com.apple.hiservices-xpcservice 1 1038 0.0 [U501] /System/Library/CoreServices/ReportCrash agent 1 1372 0.0 [U501] /usr/libexec/swcd 1 1486 0.0 [U501] /Applications/Utilities/Terminal.app/Contents/MacOS/Terminal 1 1518 0.1 [U501] /Applications/Safari.app/Contents/MacOS/Safari 1 1519 0.0 [U501] /System/Library/Frameworks/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.Networking.xpc/Contents/MacOS/com.apple.WebKit.Networking 1 1520 0.0 [U501] /System/Library/Frameworks/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.WebContent.xpc/Contents/MacOS/com.apple.WebKit.WebContent 1 1521 0.0 [U501] /System/Library/Frameworks/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.WebContent.xpc/Contents/MacOS/com.apple.WebKit.WebContent 1 1524 0.0 [U501] /usr/libexec/spindump_agent 1 1525 0.0 root /System/Library/CoreServices/SubmitDiagInfo server-init 1 1526 0.0 [U501] /usr/libexec/webinspectord 1 1527 0.0 [U501] /usr/libexec/SafariNotificationAgent 1 1528 0.0 [U501] /System/Library/PrivateFrameworks/SafariSafeBrowsing.framework/com.apple.Safari.SafeBrowsing.Service 1 1529 0.0 root /usr/libexec/dprivacyd 1 1531 0.0 [U501] /System/Library/Frameworks/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.Databases.xpc/Contents/MacOS/com.apple.WebKit.Databases 1 1533 0.0 [U501] /System/Library/PrivateFrameworks/SafariShared.framework/Versions/A/XPCServices/com.apple.Safari.SearchHelper.xpc/Contents/MacOS/com.apple.Safari.SearchHelper 1 1544 0.0 [U501] /System/Library/PrivateFrameworks/ContextKit.framework/Versions/A/XPCServices/ContextService.xpc/Contents/MacOS/ContextService 1 1546 0.0 [U501] /System/Library/Frameworks/MediaAccessibility.framework/Versions/A/XPCServices/com.apple.accessibility.mediaaccessibilityd.xpc/Contents/MacOS/com.apple.accessibility.mediaaccessibilityd 1 1548 0.0 [U501] /System/Library/Frameworks/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.WebContent.xpc/Contents/MacOS/com.apple.WebKit.WebContent 1 1552 0.0 [U501] /System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdworker -s mdworker -c MDSImporterWorker -m com.apple.mdworker.shared 1 1691 0.0 [U501] /System/Library/PrivateFrameworks/HelpData.framework/Versions/A/Resources/helpd 1 1693 0.0 [U501] /System/Library/Frameworks/Quartz.framework/Versions/A/Frameworks/QuickLookUI.framework/Versions/A/XPCServices/QuickLookUIService.xpc/Contents/MacOS/QuickLookUIService 1 1694 0.0 [U501] /System/Library/PrivateFrameworks/ViewBridge.framework/Versions/A/XPCServices/ViewBridgeAuxiliary.xpc/Contents/MacOS/ViewBridgeAuxiliary 1 1699 0.0 [U501] /Applications/Dropbox.app/Contents/PlugIns/garcon.appex/Contents/MacOS/garcon 1 1703 0.0 [U501] /System/Library/PrivateFrameworks/XprotectFramework.framework/Versions/A/XPCServices/XprotectService.xpc/Contents/MacOS/XprotectService 1 1704 0.0 [U501] /System/Library/PrivateFrameworks/SyncedDefaults.framework/Support/syncdefaultsd 1 1705 0.0 root /System/Library/PrivateFrameworks/DiskImages.framework/Resources/hdiejectd 1 1707 0.0 [U501] /System/Library/PrivateFrameworks/DiskImages.framework/Resources/diskimages-helper -uuid DE1EBA97-A086-4DDA-8412-B0BBBE024D50 -post-exec 4 1 1721 0.0 [U501] /System/Library/Frameworks/QuickLook.framework/Resources/quicklookd.app/Contents/MacOS/quicklookd 1 1722 2.6 [U501] /Applications/DetectX Swift.app/Contents/MacOS/DetectX Swift -psn_0_356439 1 1723 0.0 [U501] /System/Library/Frameworks/QuickLook.framework/Versions/A/Resources/quicklookd.app/Contents/XPCServices/QuickLookSatellite.xpc/Contents/MacOS/QuickLookSatellite 1 1849 0.0 [U501] /System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdworker -s mdworker-bundle -c MDSImporterBundleFinder -m com.apple.mdworker.bundles 1 1850 0.0 _spotlight /System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdworker -s mdworker-bundle -c MDSImporterBundleFinder -m com.apple.mdworker.bundles 1486 1487 0.0 root login -pf [U501] 1487 1488 0.0 [U501] -bash «»EOF»« Andrija |
24.03.2018, 20:34 | #17 |
/// Mac Expert | Malwarebytes entdeckt Trojaner - in Quarantäne nicht zu finden Du hast sehr viele Startobjekte die das Netz nutzen.
__________________TeamViewer, AnyConnect, einen Ajax Server... und Samsung Kies Software wobei ich glaube das diese das grösste Problem darstellt. Wenn du also einige dieser Apps nicht mehr benötigst, solltest du diese nach Anweisung der entsprechenden Tools deinstallieren. Für die Kies Software (Samsung) benötigst du den Original Installer. Dort befindet sich die Unistall.app mit der du die Software vollständig entfernen kannst. In deinen Anmeldeobjekten befindet sich noch das CleanMyMac Menu. Bitte diesen aus dem Autologin entfernen. -> Öffne die Systemeinstellungen, > Benutzer & Gruppen > Anmeldeobjekte Entferne CleanMyMac in dem du es auswählst und das Minus-Zeichen betätigst. Wenn das erledigt ist, melde dich nochmal damit wir weiterhin den Fehler suchen können (falls danach noch vorhanden).
__________________ |
25.03.2018, 17:02 | #18 |
| Malwarebytes entdeckt Trojaner - in Quarantäne nicht zu finden Hallo Dante12,
__________________zum einen konnte ich nur Dropbox und den fuspredownloader in den Anmeldeobjekten finden und entfernen und zudem werden bei DetectX weiterhin folgende login items weiterhin angezeigt: Code:
ATTFilter User Login Items: Dropbox Mail AdobeResourceSynchronizer CleanMyMac 3 Menu Android File Transfer Agent fuspredownloader Liebe Grüße, Andrija |
25.03.2018, 17:29 | #19 |
/// Mac Expert | Malwarebytes entdeckt Trojaner - in Quarantäne nicht zu finden
__________________ ----------------- -Gruß dante12 ----------------- Lob, Kritik, Wünsche? Spende fürs trojaner-board? |
25.03.2018, 22:59 | #20 |
| Malwarebytes entdeckt Trojaner - in Quarantäne nicht zu finden Okay scheinbar sind keine Programme mehr im User Login: Code:
ATTFilter Malwarebytes System Profile Scanned Sonntag, 25. März 2018 um 21:22:02 Malwarebytes version 3.2.36.1163 Mac OS X version 10.13.3 Uptime: 21:22 up 3:29, 1 user, load averages: 1.49 1.67 1.65 Safari extensions --------------- total 3296 -rw-r--r--@ 1 Andrija staff 981137 Feb 12 22:44 AdBlock.safariextz -rw-------@ 1 Andrija staff 494807 Jan 18 2017 Adblock Plus.safariextz -rw-r--r--@ 1 Andrija staff 65017 Mar 25 21:21 Extensions.plist -rw-r--r-- 1 Andrija staff 78341 Feb 14 2017 OpenIE.safariextz Chrome extensions --------------- ghbmnnjooekpmoecnnnilnnbdlolhkhi : modified Montag, 2. Mai 2016 um 20:35:28 -> Google Docs Offline pkedcjkdefgpdelpbcmbmeomcjbeemfm : modified Dienstag, 6. März 2018 um 17:02:10 -> Chrome Media Router cfhdojbkjhnklbpkdaibdccddilifddb : modified Dienstag, 6. März 2018 um 17:02:09 -> Adblock Plus Temp : modified Dienstag, 6. März 2018 um 17:02:10 -> pjkljhegncpnkpknbcohdijeoejaedia : modified Samstag, 15. August 2015 um 13:37:28 -> Gmail apdfllckaahabafndbhieahigkjlhalf : modified Dienstag, 29. Dezember 2015 um 16:44:25 -> Google Drive aapocclcgogkmnckokdopfmhonfmgoek : modified Dienstag, 6. März 2018 um 17:00:30 -> Slides aohghmighlieiainnegkcijnfilokake : modified Dienstag, 6. März 2018 um 17:00:30 -> Docs nmmhkkegccagdldgiimedpiccmgmieda : modified Montag, 4. September 2017 um 14:18:34 -> nmmhkkegccagdldgiimedpiccmgmieda coobgpohoikkiipiblmjeljniedjpjpf : modified Dienstag, 29. Dezember 2015 um 16:44:25 -> Google Search blpcfgokakmgnkcojhhkbfbldkacnbeo : modified Samstag, 14. November 2015 um 15:23:32 -> YouTube felcaaldnbdncclmgdcncolpebgiejap : modified Dienstag, 6. März 2018 um 17:00:30 -> Sheets Chrome external extensions --------------- +++ For user +++ --- Contents of nbomelmanadmkncbnblcnmipiljemjke.json : modified Sonntag, 30. Juli 2017 um 12:19:27 --- {"external_update_url":"https:\/\/clients2.google.com\/service\/update2\/crx"} --- End Contents --- +++ Global +++ Folder does not exist Mozilla extensions --------------- Folder does not exist Firefox extensions --------------- {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi : modified Dienstag, 26. Dezember 2017 um 18:32:09 -> Error getting extension information fireml@sirma.bg.xpi : modified Dienstag, 26. Juli 2016 um 17:26:26 -> install.rdf: <em:name>Marklogic Console for Firebug</em:name> {73a6fe31-595d-460b-a920-fcc0f8843232}.xpi : modified Samstag, 17. März 2018 um 12:48:48 -> Error getting extension information firebug@software.joehewitt.com.xpi : modified Freitag, 13. Januar 2017 um 22:36:35 -> install.rdf: <em:name>Firebug</em:name> Login items --------------- None Sandboxed login items (overrides.plist) --------------- { "_com.apple.SMLoginItemBookmarks" => { "com.apple.photostream-agent" => <626f6f6b 98030000 00000410 30000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 c4020000 0c000000 01010000 4170706c 69636174 696f6e73 0a000000 01010000 6950686f 746f2e61 70700000 08000000 01010000 436f6e74 656e7473 07000000 01010000 4c696272 61727900 0a000000 01010000 4c6f6769 6e497465 6d730000 14000000 01010000 50686f74 6f537472 65616d41 67656e74 2e617070 18000000 01060000 04000000 18000000 2c000000 3c000000 4c000000 60000000 08000000 04030000 32745f00 00000000 08000000 04030000 81157000 00000000 08000000 04030000 82157000 00000000 08000000 04030000 ee167000 00000000 08000000 04030000 ef167000 00000000 08000000 04030000 f0167000 00000000 18000000 01060000 9c000000 ac000000 bc000000 cc000000 dc000000 ec000000 08000000 00040000 41b855cd 44000000 18000000 01020000 02000000 00000000 0f000000 00000000 00000000 00000000 0c000000 01010000 4d616369 6e746f73 68204844 08000000 04030000 0040ca94 27000000 08000000 00040000 41b5bb99 f2000000 24000000 01010000 46324441 39423546 2d463830 422d3332 30442d39 3332342d 42373930 35454343 37463636 18000000 01020000 81000000 01000800 ef170000 01000800 00000000 00000000 01000000 01010000 2f000000 00000000 01050000 da000000 01020000 30616364 30343638 39643031 36396131 38646539 34356533 38373934 62393437 62316663 36336636 3b303030 30303030 303b3030 30303030 30303b30 30303030 30303030 30303030 3032303b 636f6d2e 6170706c 652e6170 702d7361 6e64626f 782e7265 61642d77 72697465 3b303030 30303030 313b3031 30303030 30333b30 30303030 30303030 30373031 3666303b 2f617070 6c696361 74696f6e 732f6970 686f746f 2e617070 2f636f6e 74656e74 732f6c69 62726172 792f6c6f 67696e69 74656d73 2f70686f 746f7374 7265616d 6167656e 742e6170 70000000 9c000000 feffffff 01000000 00000000 0c000000 04100000 7c000000 00000000 05100000 fc000000 00000000 10100000 2c010000 00000000 40100000 1c010000 00000000 02200000 cc010000 00000000 10200000 4c010000 00000000 11200000 80010000 00000000 12200000 60010000 00000000 13200000 70010000 00000000 20200000 ac010000 00000000 30200000 d8010000 00000000 80f00000 e0010000 00000000> "com.fiplab.BatteryHealthHelper" => <626f6f6b b0030000 00000410 30000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 dc020000 0c000000 01010000 4170706c 69636174 696f6e73 12000000 01010000 42617474 65727920 4865616c 74682e61 70700000 08000000 01010000 436f6e74 656e7473 07000000 01010000 4c696272 61727900 0a000000 01010000 4c6f6769 6e497465 6d730000 17000000 01010000 42617474 65727948 65616c74 6848656c 7065722e 61707000 18000000 01060000 04000000 18000000 34000000 44000000 54000000 68000000 08000000 04030000 32745f00 00000000 08000000 04030000 9f658b00 00000000 08000000 04030000 a0658b00 00000000 08000000 04030000 ae658b00 00000000 08000000 04030000 af658b00 00000000 08000000 04030000 b0658b00 00000000 18000000 01060000 a8000000 b8000000 c8000000 d8000000 e8000000 f8000000 08000000 00040000 41b986d0 9b000000 18000000 01020000 02000000 00000000 0f000000 00000000 00000000 00000000 0c000000 01010000 4d616369 6e746f73 68204844 08000000 04030000 0040ca94 27000000 08000000 00040000 41b5bb99 f2000000 24000000 01010000 46324441 39423546 2d463830 422d3332 30442d39 3332342d 42373930 35454343 37463636 18000000 01020000 81000000 01000800 ef170000 01000800 00000000 00000000 01000000 01010000 2f000000 00000000 01050000 e5000000 01020000 63643335 64363835 38303435 62303231 65353835 34373539 64306363 62393439 36353465 64326633 3b303030 30303030 303b3030 30303030 30303b30 30303030 30303030 30303030 3032303b 636f6d2e 6170706c 652e6170 702d7361 6e64626f 782e7265 61642d77 72697465 3b303030 30303030 313b3031 30303030 30323b30 30303030 30303030 30386236 3562303b 2f617070 6c696361 74696f6e 732f6261 74746572 79206865 616c7468 2e617070 2f636f6e 74656e74 732f6c69 62726172 792f6c6f 67696e69 74656d73 2f626174 74657279 6865616c 74686865 6c706572 2e617070 00000000 9c000000 feffffff 01000000 00000000 0c000000 04100000 88000000 00000000 05100000 08010000 00000000 10100000 38010000 00000000 40100000 28010000 00000000 02200000 d8010000 00000000 10200000 58010000 00000000 11200000 8c010000 00000000 12200000 6c010000 00000000 13200000 7c010000 00000000 20200000 b8010000 00000000 30200000 e4010000 00000000 80f00000 ec010000 00000000> "com.fiplab.MemoryCleanHelper" => <626f6f6b 9c030000 00000410 30000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 c8020000 0c000000 01010000 4170706c 69636174 696f6e73 10000000 01010000 4d656d6f 72792043 6c65616e 2e617070 08000000 01010000 436f6e74 656e7473 07000000 01010000 4c696272 61727900 0a000000 01010000 4c6f6769 6e497465 6d730000 15000000 01010000 4d656d6f 7279436c 65616e48 656c7065 722e6170 70000000 18000000 01060000 04000000 18000000 30000000 40000000 50000000 64000000 08000000 04030000 4f000000 00000000 08000000 04030000 73681600 00000000 08000000 04030000 74681600 00000000 08000000 04030000 d5681600 00000000 08000000 04030000 d6681600 00000000 08000000 04030000 d7681600 00000000 18000000 01060000 a4000000 b4000000 c4000000 d4000000 e4000000 f4000000 08000000 00040000 41b60b70 ab000000 18000000 01020000 02000000 00000000 0f000000 00000000 00000000 00000000 0c000000 01010000 4d616369 6e746f73 68204844 08000000 04030000 0020883d 3a000000 08000000 00040000 41b5bb99 f2000000 24000000 01010000 46324441 39423546 2d463830 422d3332 30442d39 3332342d 42373930 35454343 37463636 18000000 01020000 81000000 01000800 ef3f0000 01000800 00000000 00000000 01000000 01010000 2f000000 00000000 01050000 d8000000 01020000 65313365 33623061 38306432 37376661 31353832 33353830 66346639 63396239 32376366 38343135 3b303030 30303030 303b3030 30303030 30303030 30303030 32303b63 6f6d2e61 70706c65 2e617070 2d73616e 64626f78 2e726561 642d7772 6974653b 30303030 30303031 3b303130 30303030 313b3030 30303030 30303030 31363638 64373b2f 6170706c 69636174 696f6e73 2f6d656d 6f727920 636c6561 6e2e6170 702f636f 6e74656e 74732f6c 69627261 72792f6c 6f67696e 6974656d 732f6d65 6d6f7279 636c6561 6e68656c 7065722e 61707000 9c000000 feffffff 01000000 00000000 0c000000 04100000 84000000 00000000 05100000 04010000 00000000 10100000 34010000 00000000 40100000 24010000 00000000 02200000 d4010000 00000000 10200000 54010000 00000000 11200000 88010000 00000000 12200000 68010000 00000000 13200000 78010000 00000000 20200000 b4010000 00000000 30200000 e0010000 00000000 80f00000 e8010000 00000000> "com.hp.devicemonitor" => <626f6f6b ac040000 00000410 30000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 d8030000 07000000 01010000 4c696272 61727900 08000000 01010000 5072696e 74657273 02000000 01010000 68700000 09000000 01010000 5574696c 69746965 73000000 0e000000 01010000 48502055 74696c69 74792e61 70700000 08000000 01010000 436f6e74 656e7473 0a000000 01010000 4c6f6769 6e497465 6d730000 15000000 01010000 48502044 65766963 65204d6f 6e69746f 722e6170 70000000 34000000 01060000 04000000 14000000 24000000 30000000 44000000 5c000000 04000000 6c000000 80000000 5c000000 04000000 6c000000 80000000 08000000 04030000 4d745f00 00000000 08000000 04030000 bb7c0100 00000000 08000000 04030000 dd967e00 00000000 08000000 04030000 28a47e00 00000000 08000000 04030000 29a47e00 00000000 08000000 04030000 2aa47e00 00000000 08000000 04030000 aca67e00 00000000 08000000 04030000 ada67e00 00000000 08000000 04030000 aea67e00 00000000 08000000 04030000 afa67e00 00000000 08000000 04030000 49229400 00000000 08000000 04030000 4a229400 00000000 08000000 04030000 4b229400 00000000 34000000 01060000 dc000000 ec000000 fc000000 0c010000 1c010000 2c010000 3c010000 4c010000 5c010000 6c010000 7c010000 8c010000 9c010000 08000000 00040000 41b9e822 22000000 18000000 01020000 02000000 00000000 0f000000 00000000 00000000 00000000 0c000000 01010000 4d616369 6e746f73 68204844 08000000 04030000 0040ca94 27000000 08000000 00040000 41b5bb99 f2000000 24000000 01010000 46324441 39423546 2d463830 422d3332 30442d39 3332342d 42373930 35454343 37463636 18000000 01020000 81000000 01000800 ef170000 01000800 00000000 00000000 01000000 01010000 2f000000 00000000 01050000 22010000 01020000 63383964 61336336 38663830 64336332 38303765 38333331 61326536 61656531 66373038 33656235 3b303030 30303030 303b3030 30303030 30303b30 30303030 30303030 30303030 3032303b 636f6d2e 6170706c 652e6170 702d7361 6e64626f 782e7265 61642d77 72697465 3b303030 30303030 313b3031 30303030 30343b30 30303030 30303030 30393432 3234623b 2f6c6962 72617279 2f707269 6e746572 732f6870 2f757469 6c697469 65732f68 70207574 696c6974 792e6170 702f636f 6e74656e 74732f6c 69627261 72792f6c 6f67696e 6974656d 732f6870 20646576 69636520 6d6f6e69 746f722e 6170702f 636f6e74 656e7473 2f6c6962 72617279 2f6c6f67 696e6974 656d732f 68702064 65766963 65206d6f 6e69746f 722e6170 70000000 9c000000 feffffff 01000000 00000000 0c000000 04100000 a0000000 00000000 05100000 ac010000 00000000 10100000 f8010000 00000000 40100000 e8010000 00000000 02200000 98020000 00000000 10200000 18020000 00000000 11200000 4c020000 00000000 12200000 2c020000 00000000 13200000 3c020000 00000000 20200000 78020000 00000000 30200000 a4020000 00000000 80f00000 ac020000 00000000> "QA2G25RMZ4.com.wunderkinder.wunderlist-helper" => <626f6f6b a0030000 00000410 30000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 cc020000 0c000000 01010000 4170706c 69636174 696f6e73 0e000000 01010000 57756e64 65726c69 73742e61 70700000 08000000 01010000 436f6e74 656e7473 07000000 01010000 4c696272 61727900 0a000000 01010000 4c6f6769 6e497465 6d730000 14000000 01010000 57756e64 65726c69 73744865 6c706572 2e617070 18000000 01060000 04000000 18000000 30000000 40000000 50000000 64000000 08000000 04030000 32745f00 00000000 08000000 04030000 65d79400 00000000 08000000 04030000 66d79400 00000000 08000000 04030000 b9d79400 00000000 08000000 04030000 bad79400 00000000 08000000 04030000 bbd79400 00000000 18000000 01060000 a0000000 b0000000 c0000000 d0000000 e0000000 f0000000 08000000 00040000 41b9f000 45000000 18000000 01020000 02000000 00000000 0f000000 00000000 00000000 00000000 0c000000 01010000 4d616369 6e746f73 68204844 08000000 04030000 0040ca94 27000000 08000000 00040000 41b5bb99 f2000000 24000000 01010000 46324441 39423546 2d463830 422d3332 30442d39 3332342d 42373930 35454343 37463636 18000000 01020000 81000000 01000800 ef170000 01000800 00000000 00000000 01000000 01010000 2f000000 00000000 01050000 de000000 01020000 61396130 63616132 33356230 62326161 35303831 61326136 39633932 64383162 64633539 62323830 3b303030 30303030 303b3030 30303030 30303b30 30303030 30303030 30303030 3032303b 636f6d2e 6170706c 652e6170 702d7361 6e64626f 782e7265 61642d77 72697465 3b303030 30303030 313b3031 30303030 30343b30 30303030 30303030 30393464 3762623b 2f617070 6c696361 74696f6e 732f7775 6e646572 6c697374 2e617070 2f636f6e 74656e74 732f6c69 62726172 792f6c6f 67696e69 74656d73 2f77756e 6465726c 69737468 656c7065 722e6170 70000000 9c000000 feffffff 01000000 00000000 0c000000 04100000 80000000 00000000 05100000 00010000 00000000 10100000 30010000 00000000 40100000 20010000 00000000 02200000 d0010000 00000000 10200000 50010000 00000000 11200000 84010000 00000000 12200000 64010000 00000000 13200000 74010000 00000000 20200000 b0010000 00000000 30200000 dc010000 00000000 80f00000 e4010000 00000000> } "at.obdev.LittleSnitchUIAgent" => { "Disabled" => 0 } "com.adobe.AAM.Scheduler-1.0" => { "Disabled" => 0 } "com.adobe.AdobeCreativeCloud" => { "Disabled" => 1 } "com.apple.FileStatsAgent" => { "Disabled" => 1 } "com.apple.mrt.uiagent" => { "Disabled" => 0 } "com.apple.photostream-agent" => { "Disabled" => 1 } "com.apple.TMHelperAgent.SetupOffer" => { "Disabled" => 1 } "com.apple.TMLaunchAgent" => { "Disabled" => 1 } "com.cisco.anyconnect.gui" => { "Disabled" => 0 } "com.fiplab.BatteryHealthHelper" => { "Disabled" => 1 } "com.fiplab.MemoryCleanHelper" => { "Disabled" => 1 } "com.hp.devicemonitor" => { "Disabled" => 0 } "com.spotify.webhelper" => { "Disabled" => 0 } "QA2G25RMZ4.com.wunderkinder.wunderlist-helper" => { "Disabled" => 0 } } Startup items --------------- None System startup items --------------- None User launch agents --------------- total 72 -rw-r--r-- 1 Andrija staff 697 Nov 16 2015 com.adobe.AAM.Updater-1.0.plist -rw-r--r-- 1 Andrija staff 574 Aug 25 2012 com.adobe.ARM.202f4087f2bbde52e3ac2df389f53a4f123223c9cc56a8fd83a6f7ae.plist -rw-r--r-- 1 Andrija staff 688 Jan 31 23:09 com.adobe.GC.Invoker-1.0.plist -rw-r--r-- 1 Andrija staff 687 Aug 11 2017 com.dropbox.DropboxMacUpdate.agent.plist -rw-r--r-- 1 Andrija staff 538 Mar 25 17:53 com.hp.devicemonitor.plist -rw-r--r-- 1 Andrija staff 524 Jul 17 2017 com.skype.skype.shareagent.plist -rw-r--r--@ 1 Andrija staff 534 Mar 17 11:57 com.spotify.webhelper.plist -rw-r--r--@ 1 Andrija staff 579 Mar 24 13:42 com.sqwarq.DetectX-Swift.observer.plist -rw-r--r-- 1 Andrija staff 819 Sep 23 2015 com.valvesoftware.steamclean.plist System launch agents --------------- total 72 -rw-r--r-- 1 root wheel 612 Oct 22 15:53 com.adobe.AAM.Updater-1.0.plist -rw-r--r-- 1 root wheel 612 Jan 30 16:47 com.adobe.GC.Invoker-1.0.plist -rw-r--r-- 1 root wheel 635 Jan 19 13:48 com.cisco.anyconnect.gui.plist -rw-r--r-- 1 root wheel 664 Jan 19 13:48 com.cisco.anyconnect.notification.plist -rw-r--r--@ 1 root wheel 792 Jul 12 2016 com.google.keystone.agent.plist -rw-r--r-- 1 root wheel 651 Feb 26 16:06 com.malwarebytes.mbam.frontend.agent.plist lrwxr-xr-x 1 root wheel 104 Jun 5 2013 com.oracle.java.Java-Updater.plist -> /Library/Internet Plug-Ins/JavaAppletPlugin.plugin/Contents/Resources/com.oracle.java.Java-Updater.plist -rw-r--r-- 1 root wheel 668 Dec 21 2016 com.teamviewer.teamviewer.plist -rw-r--r-- 1 root wheel 779 Dec 21 2016 com.teamviewer.teamviewer_desktop.plist -rw-r--r-- 1 root wheel 720 Sep 28 2012 org.macosforge.xquartz.startx.plist System launch daemons --------------- total 128 -rw-r--r-- 1 root wheel 642 Jan 30 16:47 com.adobe.agsservice.plist -rw-r--r-- 1 root wheel 462 Oct 26 03:00 com.adobe.fpsaud.plist -rw-r--r-- 1 root wheel 739 Nov 8 2013 com.anchorfree.ajaxserver.plist -rw-r--r-- 1 root wheel 666 Jan 19 13:48 com.cisco.anyconnect.vpnagentd.plist -rw-r--r-- 1 root wheel 880 Aug 13 2013 com.disc-soft.DAEMONTools.PrivilegedHelper.plist -rw-r--r-- 1 root wheel 717 Sep 16 2014 com.ea.origin.ESHelper.plist -rw-r--r--@ 1 root wheel 818 Mar 6 10:01 com.google.keystone.daemon.plist -rw-r--r-- 1 root wheel 568 Mar 17 15:58 com.malwarebytes.HelperTool.plist -rw-r--r-- 1 root wheel 786 Feb 26 16:06 com.malwarebytes.mbam.rtprotection.daemon.plist -rw-r--r-- 1 root wheel 562 Feb 26 16:06 com.malwarebytes.mbam.settings.daemon.plist -rw-r--r-- 1 root wheel 267 Jan 2 2017 com.microsoft.autoupdate.helper.plist -rw-r--r-- 1 root wheel 568 Mar 10 2011 com.microsoft.office.licensing.helper.plist -rw-r--r-- 1 root wheel 657 Aug 30 2015 com.microsoft.office.licensingV2.helper.plist lrwxr-xr-x 1 root wheel 103 Jun 5 2013 com.oracle.java.Helper-Tool.plist -> /Library/Internet Plug-Ins/JavaAppletPlugin.plugin/Contents/Resources/com.oracle.java.Helper-Tool.plist -rw-r--r-- 1 root wheel 544 Dec 21 2016 com.teamviewer.Helper.plist -rw-r--r-- 1 root wheel 611 Dec 21 2016 com.teamviewer.teamviewer_service.plist -rw-r--r-- 1 root wheel 661 Sep 28 2012 org.macosforge.xquartz.privileged_startx.plist Third-party kexts --------------- com.malwarebytes.mbam.rtprotection (3.2.36) 197B3B52-FE0A-386A-BC14-5F28B2F4E8F1 <5 4 3 1> DNS settings --------------- Server: 192.168.178.1 Hosts file --------------- ## # Host Database # # localhost is used to configure the loopback interface # when the system is booting. Do not change this entry. ## 127.0.0.1 localhost 255.255.255.255 broadcasthost ::1 localhost fe80::1%lo0 localhost Cron tasks --------------- User tasks: No user cron tasks Root tasks: No root cron tasks LoginHook --------------- No login hooks Apps to re-launch at restart --------------- { "TALAppsToRelaunchAtLogin" => [ 0 => { "BackgroundState" => 2 "BundleID" => "com.apple.scripteditor.id.get-system-profile" "Hide" => 0 "Path" => "/private/var/folders/xn/g1pdffy97gz3nf6jpvfrs13m0000gn/T/AppTranslocation/BCE6C449-945A-48C1-AA04-B2C518E34C32/d/Get System Profile.app" } 1 => { "BackgroundState" => 2 "BundleID" => "com.apple.safari" "Hide" => 0 "Path" => "/Applications/Safari.app" } 2 => { "BackgroundState" => 2 "BundleID" => "com.apple.mail" "Hide" => 0 "Path" => "/Applications/Mail.app" } 3 => { "BackgroundState" => 2 "BundleID" => "com.apple.finder" "Hide" => 0 "Path" => "/System/Library/CoreServices/Finder.app" } ] } Contents of Quarantine --------------- total 8 drwxr-xr-x 5 Andrija staff 160 Aug 9 2017 AppCommon -rw-r--r-- 1 Andrija staff 482 Dec 3 2016 sisinfo.plist Sirius health check --------------- {"status":"ok"} Keystone health check --------------- {"status":"ok"} Liebe Grüße, Andrija |
26.03.2018, 09:08 | #21 |
/// Mac Expert | Malwarebytes entdeckt Trojaner - in Quarantäne nicht zu finden Der ajaxserver server wurde von deinem VPN Hotspot shield erstellt. Verwendest du diesen? Wenn nicht, solltest du diese Einträge löschen aber zuerst prüfe doch bitte folgende Einstellungen in deinem WLAN-Netzwerk
__________________ --> Malwarebytes entdeckt Trojaner - in Quarantäne nicht zu finden |
03.04.2018, 14:28 | #22 |
| Malwarebytes entdeckt Trojaner - in Quarantäne nicht zu finden Leider besteht das Problem weiterhin, obwohl der Server jetzt nicht mehr vorhanden ist. Liebe Grüße, Andrija |
03.04.2018, 18:03 | #23 |
/// Mac Expert | Malwarebytes entdeckt Trojaner - in Quarantäne nicht zu finden Erstelle doch bitte noch einmal ein Log mit DetectX. Zusätzlich mache bitte folgendes: DetextX-Swift History
SysDiag
__________________ ----------------- -Gruß dante12 ----------------- Lob, Kritik, Wünsche? Spende fürs trojaner-board? |
Themen zu Malwarebytes entdeckt Trojaner - in Quarantäne nicht zu finden |
abbruch, code, community, datei, entdeck, entdeckt, immernoch, installier, installiert, interne, internetverbindung, konstant, mac, malwarebytes, phone, quarantäne, scan, sekunden, software, steigt, troja, trojaner, verbindung, verschoben, wlan |