Zurück   Trojaner-Board > Web/PC > Alles rund um Mac OSX & Linux

Alles rund um Mac OSX & Linux: infizierte Doc Datei mit Macros am Macbook geöffnet

Windows 7 Für alle Fragen rund um Mac OSX, Linux und andere Unix-Derivate.

Antwort
Alt 14.05.2019, 16:45   #1
ThomasHoll
 
infizierte Doc Datei mit Macros am Macbook geöffnet - Standard

infizierte Doc Datei mit Macros am Macbook geöffnet



Hallo,
ich habe heute eine Email erhalten die wie eine von mir geschriebene aussah und dort war eine .doc Datei. Diese habe ich dummerweise geöffnet. Es wurde mit Makros geöffnet und es war kurz eine Art Programmier Code oder Script zu sehen. Ich habe sofort alles beendet und wollte auch Word beenden. Doch es kamen dann immer Popups ob ich die Datei sichern will usw.
Erst als ich Word über die Aktivitätsanzeige den Prozess beendete war Schluß.
Ich habe eigentlich Kaspersky Internet Security drauf, doch der meldete nix.
Auch ein Scan mit Malwarebyte Antimalware und auch Vollscan Kaspersky sagte keinen Fund.

Ich habe bisher noch keine Veränderung bemerkt am Mac.
Kann ich noch andere bessere Programme scannen lassen oder ist der Trojaner nicht aktiv da er eventuell nur für Win war?

Bitte um Hilfe.

Thomas

Alt 14.05.2019, 18:07   #2
stefanbecker
 
infizierte Doc Datei mit Macros am Macbook geöffnet - Standard

infizierte Doc Datei mit Macros am Macbook geöffnet



Hast du die Mail noch? Man kann den Anhang bei virustotal hochladen und prüfen lassen.

In der Regel ist das aber Windows-Only, von daher dürfte nichts passiert sein.
__________________


Alt 15.05.2019, 06:26   #3
ThomasHoll
 
infizierte Doc Datei mit Macros am Macbook geöffnet - Standard

infizierte Doc Datei mit Macros am Macbook geöffnet



Ich habe die Mail gleich in den Papierkorb befördert.
Wenn Sie noch da ist dann prüfe ich gleich mit Virustotal.

Danke

Bei Virustotal erkannten 9 Anbieter sofort einen Befund.
Leider war auch Malwarebytes und kaspersky dabei die den Virus/Trojaner nicht erkannten.
Diese Programme nutze ich und werde mir nun andere zulegen.
Kaspersky erkannte später dann plötzlich auch die Bedrohung.

Mir geht es nun hauptsächlich darum das im Hintergrund schon der Trojaner aktiv ist.
Da hoffe ich wirklich das es nur auf Win Rechner gefährlich wäre.
Würde denn eine gutes Adware/Virus Software diese Hintergrundaktivitäten finden?
__________________

Alt 15.05.2019, 07:05   #4
stefanbecker
 
infizierte Doc Datei mit Macros am Macbook geöffnet - Standard

infizierte Doc Datei mit Macros am Macbook geöffnet



Bei der nächsten Mail sind es andere Programme, die das Problem erkennen.

Nur weil der Kasper und MBAM diesmal nicht dabei waren, müssen sie nicht schlecht sein.

Jedem anderen Programm, was du stattdessen installierst, kann man genau so wenig vertrauen. Kein AV-System erkennt jede Bedrohung.


Bzgl. Untersuchung: Das macht in diesem Bereich der User Dante, da wirst du dich gedulden müssen.

Evtl. kannst du schon mal vorarbeiten:

- Die bisherigen Logs (Kasper, MBAM) posten.

- Den Link auf die Ergebnisseite zum Trojaner bei Virustotal posten.

- Ein Etrecheck-Log. Wird immer in den anderen Mac Threads erstellt, schau mal in einem nach, wie man das macht.


Und dann wie gesagt Geduld. Aber mit Logs dürftest du das ganze schleunigen.

Alt 15.05.2019, 10:42   #5
ThomasHoll
 
infizierte Doc Datei mit Macros am Macbook geöffnet - Standard

infizierte Doc Datei mit Macros am Macbook geöffnet



Hier der Link zu Virustotal
https://www.virustotal.com/gui/file/6086928902d476257488c321755e42a53dc13b5bde739a9ad7bd1cdbb71e4d96/behavior/Lastline

Etre-Check Log
Code:
ATTFilter
EtreCheck version: 5.2 (5029)
Report generated: 2019-05-15 11:23:52
Download EtreCheck from https://etrecheck.com
Runtime: 2:59
Performance: Excellent
Sandbox: Enabled
Full drive access: Disabled

Problem: No problem - just checking

Major Issues:
  Anything that appears on this list needs immediate attention. 
  More than one antivirus app - This machine has multiple antivirus apps installed.

Minor Issues:
  These issues do not need immediate attention but they may indicate future problems or opportunities for improvement. 
  High battery cycle count - Your battery may be losing capacity.
  Clean up - There are orphan files that could be removed.
  Unsigned files - There are unsigned software files installed. They appear to be legitimate but should be reviewed.
  System modifications - There are a large number of system modifications running in the background.
  Limited drive access - More information may be available with Full Drive Access.

Hardware Information:
  MacBook Pro (Retina, 15-inch, Mid 2015)
  MacBook Pro Model: MacBookPro11,4
  1 2,2*GHz Intel Core i7 (i7-4770HQ) CPU: 4-core
  16 RAM - Not upgradeable
    BANK 0/DIMM0 - 8*GB DDR3 1600* ok
    BANK 1/DIMM0 - 8*GB DDR3 1600* ok
  Battery: Health = Normal - Cycle count = 770

Video Information:
  Intel Iris Pro - VRAM: 1536*MB
    Color LCD 2880 x 1800

Drives:
  disk0 - APPLE SSD SM0256G 251.00*GB (Solid State - TRIM: Yes) 
  Internal PCI 8.0 GT/s x4 Serial ATA
    disk0s1 - EFI (MS-DOS FAT32) [EFI] 210*MB
    disk0s2 [APFS Container] 250.14*GB
      disk1 [APFS Virtual drive] 250.14*GB (Shared by 4 volumes)
        disk1s1 - Macintosh HD (APFS) (Shared - 175.84*GB used)
        disk1s2 - Preboot (APFS) [APFS Preboot] (Shared)
        disk1s3 - Recovery (APFS) [Recovery] (Shared)
        disk1s4 - VM (APFS) [APFS VM] (Shared - 2.15*GB used)

  disk3 - Samsung Flash Drive FIT 128.31*GB
  External USB 5 Gbit/s USB
    disk3s1 - S*********B (MS-DOS FAT32) 128.31*GB (125.84*GB used)

  disk4 - APPLE SD Card Reader 250.14*GB (SD Card) 
  Internal USB 5 Gbit/s USB
    disk4s1 - T*******d 250.11*GB (102.90*GB used)

Mounted Volumes:
  disk1s1 - Macintosh HD 250.14*GB (71.45*GB free)
    APFS
    Mount point: /
    Encrypted

  disk1s4 - VM [APFS VM] (Shared - 2.15*GB used)
    APFS
    Mount point: /private/var/vm

  disk3s1 - S*********B 128.31*GB (2.43*GB free)
    MS-DOS FAT32
    Mount point: /Volumes/S*********B

  disk4s1 - T*******d 250.11*GB (147.17*GB free)
        Mount point: /Volumes/T*******d

Network:
  Interface SAMSUNG_MDM: SAMSUNG Modem
  Interface en5: USB 10/100/1000 LAN
  Interface en6: iPad
  Interface en4: iPhone
  Interface en0: Wi-Fi
    802.11 a/b/g/n/ac
  Interface en3: Bluetooth PAN
  Interface bridge0: Thunderbolt Bridge

System Software:
  macOS Mojave 10.14.4 (18E226) 
  Time since boot: About a day

Notifications:
  Notifications not available without Full Drive Access.

Security:
  System Status
  Gatekeeper: Enabled
  System Integrity Protection: Enabled

  Antivirus apps: Bitdefender, Kaspersky,  and MalwareBytes

Unsigned Files:
  Launchd: /Library/Internet Plug-Ins/JavaAppletPlugin.plugin/Contents/Resources/com.oracle.java.Helper-Tool.plist
    Executable: /Library/Internet Plug-Ins/JavaAppletPlugin.plugin/Contents/Resources/Helper-Tool
    Details: Exact match found in the whitelist - probably OK

  Launchd: /Library/LaunchDaemons/org.virtualbox.startup.plist
    Executable: /Library/Application Support/VirtualBox/LaunchDaemons/VirtualBoxStartup.sh restart
    Details: Exact match found in the whitelist - probably OK

  Launchd: /Library/LaunchDaemons/org.wireshark.ChmodBPF.plist
    Executable: /Library/Application Support/Wireshark/ChmodBPF/ChmodBPF
    Details: Exact match found in the whitelist - probably OK

  Launchd: ~/Library/LaunchAgents/com.cisco.videoguard10.uninstall.plist
    Executable: /bin/sh ~/.cisco/VideoGuard/uninstall/cisco_videoguard10/condUninstall.sh
    Details: Exact match found in the whitelist - probably OK

  Launchd: /Library/Internet Plug-Ins/JavaAppletPlugin.plugin/Contents/Resources/com.oracle.java.Java-Updater.plist
    Executable: /Library/Internet Plug-Ins/JavaAppletPlugin.plugin/Contents/Resources/Java Updater.app/Contents/MacOS/Java Updater -bgcheck
    Details: Exact match found in the whitelist - probably OK

  Launchd: ~/Library/LaunchAgents/com.cisco.videoguard10.plist
    Executable: /bin/sh -c $HOME/Library/Cisco/VideoGuardPlayer/VideoGuard10/VideoGuard10.bundle/Contents/Resources/setupServer.sh
    Details: Exact match found in the whitelist - probably OK

  Launchd: /Library/LaunchAgents/com.paragon-software.facebook.agent.plist
    Executable: /Library/Application Support/Paragon Software/Paragon Software Facebook Agent.app/Contents/MacOS/Paragon Software Facebook Agent
    Details: Exact match found in the whitelist - probably OK

  Launchd: /Library/LaunchDaemons/com.bitdefender.AuthHelperTool.plist
    Executable: /Library/Bitdefender/AVP/common.bundle/AuthHelperTool /Library/Bitdefender/AVP/common.bundle/Common.plist
    Details: Exact match found in the whitelist - probably OK

  Launchd: ~/Library/LaunchAgents/com.cisco.videoguardmonitor.plist
    Executable: /bin/sh -c $HOME/Library/Cisco/VideoGuardPlayer/VideoGuardMonitor/VideoGuardMonitor.bundle/Contents/Resources/launch.sh
    Details: Exact match found in the whitelist - probably OK

  Launchd: /Library/LaunchAgents/com.oracle.java.Java-Updater.plist
    Executable: /Library/Internet Plug-Ins/JavaAppletPlugin.plugin/Contents/Resources/Java Updater.app/Contents/MacOS/Java Updater -bgcheck
    Details: Exact match found in the whitelist - probably OK

  Launchd: /Library/LaunchAgents/com.sony.WirelessAutoImportLauncher.agent.plist
    Executable: /Library/Application Support/WirelessAutoImport/WirelessImporterDaemon
    Details: Exact match found in the whitelist - probably OK

  Launchd: /Library/LaunchDaemons/com.oracle.java.Helper-Tool.plist
    Executable: /Library/Internet Plug-Ins/JavaAppletPlugin.plugin/Contents/Resources/Helper-Tool
    Details: Exact match found in the whitelist - probably OK

  Launchd: ~/Library/LaunchAgents/com.valvesoftware.steamclean.plist
    Executable: ~/Library/Application Support/Steam/SteamApps/steamclean Public
    Details: Exact match found in the whitelist - probably OK

  Launchd: /Library/LaunchDaemons/com.seagate.TBDecorator.plist
    Executable: /Library/Application Support/Seagate/TBLoopDriveParams
    Details: Exact match found in the whitelist - probably OK

Kernel Extensions:
  /Library/Application Support/Malwarebytes/MBAM/Kext
    MB_MBAM_Protection.kext (3.7 - SDK 10.14)

  /Library/Application Support/Paragon Software/com.paragon-software.spbackup
    com.paragon-software.kernelio.kext (1.0 - SDK 10.12)

  /Library/Application Support/VirtualBox
    VBoxDrv.kext (5.2.26)
    VBoxNetAdp.kext (5.2.26)
    VBoxNetFlt.kext (5.2.26)
    VBoxUSB.kext (5.2.26)

  /Library/Extensions
    LittleSnitch.kext (4.3.2 - SDK 10.11)
    FileProtect.kext (1.1 - SDK 10.11)
    TMProtection.kext (5.0.0 - SDK 10.11)
    Boom2Device.kext (1.2 - SDK 10.10)
    kimul.kext (46)
    klif.kext (3.6.12a2)
    klsat.kext (1.0.1a2)
    mark.kext (1.0.6)
    klnke.kext (2.1.0)
    ufsd_NTFS.kext (15.5.41 - SDK 10.10)
    VDMounter.kext (1370.2 - SDK 10.8)
    Seagate Storage Driver.kext (5.2.7 (26995) - SDK 10.4)
    SONYDeviceType04.kext (1.4.0.11070 - SDK 10.9)
    tap.kext (20090913)
    tun.kext (20090913)

  /Library/Extensions/Seagate Storage Driver.kext/Contents/PlugIns
    SeagateLeafPowSecDriver_10_4.kext (5.2.7 (26995) - SDK 10.4)
    SeagateLeafPowSecDriver_10_5.kext (5.2.7 (26995) - SDK 10.5)
    SeagateDriveIcons.kext (5.2.7 (26995) - SDK 10.4)

  /System/Library/Extensions
    ssuddrv.kext (1.4.45 - SDK 10.6)
    fabio.kext (1.0)
    SamsungPortableSSDDriver.kext (1.5.02 - SDK 10.7)
    SamsungPortableSSDDriverX.kext (1.5.09 - SDK 10.12)

  /System/Library/Extensions/ssuddrv.kext/Contents/PlugIns
    ssudmdmcontrol.kext (1.4.45 - SDK 10.6)
    ssudmdmdata.kext (1.4.45 - SDK 10.6)
    ssudmtp.kext (1.4.45 - SDK 10.5)
    ssudserial.kext (1.4.45 - SDK 10.6)
    ssdumdrv.kext (1.3)

Startup Items:
  tun Path: /Library/StartupItems/tun 
  tap Path: /Library/StartupItems/tap 

System Launch Agents:
  [Not Loaded]  16 Apple tasks
  [Loaded]  160 Apple tasks
  [Running]  125 Apple tasks

System Launch Daemons:
  [Not Loaded]  36 Apple tasks
  [Loaded]  179 Apple tasks
  [Running]  120 Apple tasks
  [Other]  One Apple task

Launch Agents:
  [Other] Magic_Tune.plist (? 190f76a1  - installed 2008-03-17)
  [Running] at.obdev.LittleSnitchHelper.plist (Objective Development Software GmbH - installed 2019-05-14)
  [Running] at.obdev.LittleSnitchUIAgent.plist (Objective Development Software GmbH - installed 2019-05-14)
  [Not Loaded] com.adobe.AAM.Updater-1.0.plist (Adobe Systems, Inc. - installed 2019-02-04)
  [Other] com.adobe.ARMDCHelper.cc24aef4a1b90ed56a725c38014c95072f92651fb65e1bf9c8e43c37a23d420d.plist (Adobe Systems, Inc. - installed 2018-02-13)
  [Running] com.adobe.AdobeCreativeCloud.plist (Adobe Systems, Inc. - installed 2019-03-11)
  [Running] com.adobe.GC.AGM.plist (Adobe Systems, Inc. - installed 2019-05-13)
  [Not Loaded] com.adobe.GC.Invoker-1.0.plist (Adobe Systems, Inc. - installed 2019-05-13)
  [Other] com.bitdefender.antivirusformac.plist (? 17d3b6ae  - installed 2017-09-20)
  [Loaded] com.google.keystone.agent.plist (Google, Inc. - installed 2019-05-10)
  [Loaded] com.google.keystone.xpcservice.plist (Google, Inc. - installed 2019-05-10)
  [Running] com.kaspersky.kav.gui.plist (Kaspersky Lab UK Limited - installed 2019-03-28)
  [Running] com.malwarebytes.mbam.frontend.agent.plist (Malwarebytes Corporation - installed 2019-02-26)
  [Not Loaded] com.oracle.java.Java-Updater.plist (? 7e0236b9  - installed 2017-09-16)
  [Loaded] com.paragon-software.facebook.agent.plist (? 95fb0bd4  - installed 2016-11-29)
  [Running] com.paragon-software.ntfs.notification-agent.plist (Paragon Software GmbH - installed 2019-04-26)
  [Loaded] com.paragon.updater.plist (Paragon Software GmbH - installed 2016-11-29)
  [Running] com.sony.SonyAutoLauncher.agent.plist (Sony Corporation - installed 2017-12-06)
  [Running] com.sony.WirelessAutoImportLauncher.agent.plist (? c33fba7e  - installed 2017-12-06)
  [Not Loaded] com.teamviewer.teamviewer.plist (TeamViewer GmbH - installed 2019-01-15)
  [Not Loaded] com.teamviewer.teamviewer_desktop.plist (TeamViewer GmbH - installed 2019-01-15)

Launch Daemons:
  [Running] at.obdev.littlesnitchd.plist (Objective Development Software GmbH - installed 2019-05-14)
  [Loaded] com.adobe.ARMDC.Communicator.plist (Adobe Systems, Inc. - installed 2018-02-13)
  [Loaded] com.adobe.ARMDC.SMJobBlessHelper.plist (Adobe Systems, Inc. - installed 2018-02-13)
  [Running] com.adobe.acc.installer.v2.plist (Adobe Systems, Inc. - installed 2019-03-11)
  [Loaded] com.adobe.agsservice.plist (Adobe Systems, Inc. - installed 2019-05-13)
  [Loaded] com.adobe.fpsaud.plist (Adobe Systems, Inc. - installed 2019-04-30)
  [Loaded] com.apple.installer.osmessagetracing.plist (Apple - installed 2019-03-21)
  [Loaded] com.bitdefender.AuthHelperTool.plist (? 58c03e34  - installed 2017-09-20)
  [Other] com.bitdefender.upgrade.plist (? e64689aa  - installed 2017-09-20)
  [Loaded] com.google.keystone.daemon.plist (Google, Inc. - installed 2019-05-10)
  [Running] com.kaspersky.kav.plist (Kaspersky Lab UK Limited - installed 2018-10-24)
  [Running] com.malwarebytes.mbam.rtprotection.daemon.plist (Malwarebytes Corporation - installed 2019-03-02)
  [Running] com.malwarebytes.mbam.settings.daemon.plist (Malwarebytes Corporation - installed 2019-02-26)
  [Running] com.microsoft.autoupdate.helper.plist (Microsoft Corporation - installed 2017-01-19)
  [Loaded] com.microsoft.office.licensingV2.helper.plist (Microsoft Corporation - installed 2016-11-16)
  [Not Loaded] com.oracle.java.Helper-Tool.plist (? e3fefdd2  - installed 2017-09-16)
  [Running] com.paragon-software.installer.plist (Paragon Software GmbH - installed 2019-04-27)
  [Loaded] com.paragon-software.ntfs.loader.plist (Apple - installed 2019-04-26)
  [Running] com.paragon-software.ntfsd.plist (Paragon Software GmbH - installed 2019-04-26)
  [Loaded] com.paragon-software.spbackup.helper.plist (Paragon Software GmbH - installed 2019-04-26)
  [Loaded] com.paragon-software.vdmounter.plist (Apple - installed 2019-03-21)
  [Running] com.seagate.TBDecorator.plist (? 595582c  - installed 2015-11-02)
  [Loaded] com.teamviewer.Helper.plist (TeamViewer GmbH - installed 2019-01-15)
  [Not Loaded] com.teamviewer.teamviewer_service.plist (TeamViewer GmbH - installed 2019-01-15)
  [Not Loaded] org.virtualbox.startup.plist (? 700b9385  - installed 2019-02-07)
  [Loaded] org.wireshark.ChmodBPF.plist (? d4207e05  - installed 2019-02-26)
  [Other] pcloudd.plist (? 37acd5b3  - installed 2018-04-07)

User Launch Agents:
  [Loaded] com.adobe.AAM.Updater-1.0.plist (Adobe Systems, Inc. - installed 2016-09-15)
  [Loaded] com.adobe.GC.Invoker-1.0.plist (Adobe Systems, Inc. - installed 2018-01-31)
  [Running] com.amazon.music.plist (AMZN Mobile LLC - installed 2018-04-24)
  [Loaded] com.cisco.videoguard10.plist (? 0  - installed 2018-10-24)
  [Loaded] com.cisco.videoguard10.uninstall.plist (? 0  - installed 2018-10-24)
  [Running] com.cisco.videoguardmonitor.plist (? 0  - installed 2018-10-24)
  [Running] com.coconut-flavour.coconutBattery-Menu.plist (? 0  - installed 2017-04-20)
  [Loaded] com.dropbox.DropboxMacUpdate.agent.plist (Dropbox, Inc. - installed 2019-02-14)
  [Running] com.samsung.portablessd.mon.plist (Samsung Electronics - installed 2019-01-08)
  [Loaded] com.valvesoftware.steamclean.plist (? 0  - installed 2017-08-06)

User Login Items:
  Boom Helper (Global Delight Technologies Pvt. Ltd - installed 2019-04-16)
    (Modern Login Item - /Applications/Boom 3D.app/Contents/Library/LoginItems/BoomHelper.app)

  CheatSheet.app (? - installed 2019-01-07)
    (Application - ~/Applications/CheatSheet.app)

  Dropbox.app (Dropbox, Inc. - installed 2019-05-09)
    (Application - /Applications/Dropbox.app)

  FSMenuAppLoginItemHelper (Paragon Software GmbH - installed 2019-04-27)
    (Modern Login Item - /Applications/NTFS for Mac.app/Contents/Library/LoginItems/FSMenuAppLoginItemHelper.app)

Internet Plug-ins:
  AdobeAAMDetect: 3.0.0.0 (Adobe Systems, Inc. - installed 2019-03-11)
  FlashPlayer-10.6: 32.0.0.192 (Adobe Systems, Inc. - installed 2019-05-14)
  AdobePDFViewerNPAPI: 17.012.20098 (Adobe Systems, Inc. - installed 2019-04-10)
  AdobePDFViewer: 19.010.20099 (Adobe Systems, Inc. - installed 2019-04-10)
  Flash Player: 32.0.0.192 (Adobe Systems, Inc. - installed 2019-05-14)
  EntertainTV mobil: 1.0 (? - installed 2017-03-07)
  PepperFlashPlayer: 32.0.0.192 (Adobe Systems, Inc. - installed 2019-05-14)
  Silverlight: 5.1.50901.0 (? - installed 2016-11-05)
  JavaAppletPlugin: Java 8 Update 144 build 01 (? - installed 2017-10-07)

Audio Plug-ins:
  AirPlay: 2.0 (Apple - installed 2019-03-26)
  BridgeAudioSP: 5.39 (Apple - installed 2019-03-26)
  iSightAudio: 7.7.3 (Apple - installed 2019-03-26)
  BoomAudio: 1.0.2 (Global Delight Technologies Pvt. Ltd - installed 2019-01-18)
  AppleAVBAudio: 740.1 (Apple - installed 2019-03-26)
  BluetoothAudioPlugIn: 6.0.11 (Apple - installed 2019-03-26)
  AppleTimeSyncAudioClock: 1.0 (Apple - installed 2019-03-26)

Safari Extensions:
  Kaspersky Security - App Store (installed 2019-04-16)
  KeeperFill - App Store (installed 2019-05-09)

3rd Party Preference Panes:
  Flash Player (installed 2019-04-30)
  Java (installed 2017-10-07)
  NTFS (installed 2019-04-26)
  Seagate Dashboard for Mac OSX (installed 2017-07-10)

Time Machine:
  Time Machine information not available without Full Drive Access.

Performance:
  System Load: 2.06 (1 min ago) 2.13 (5 min ago) 2.08 (15 min ago)
  Nominal I/O speed: 1.96*MB/s
  File system: 57.15 seconds
  Write speed: 461*MB/s
  Read speed: 1906*MB/s

CPU Usage Snapshot:
  Type Overall
  System 4*%
  User 11*%
  Idle 86*%

Top Processes Snapshot by CPU:
  Process (count) CPU (Source - Location)
  Other processes 105.76*% (?)
  EtreCheck 4.01*% (App Store)
  com.apple.WebKit.WebContent (14) 1.37*% (Apple)
  Little Snitch Agent 0.47*% (Objective Development Software GmbH)
  Google Chrome 0.32*% (Google, Inc.)

Top Processes Snapshot by Memory:
  Process (count) RAM usage (Source - Location)
  EtreCheck 706*MB (App Store)
  Google Chrome 304*MB (Google, Inc.)
  Google Chrome Helper 219*MB (Google, Inc.)
  Microsoft Word 177*MB (? - /Applications/Microsoft Word.app)
  Mail 169*MB (Apple)

Top Processes Snapshot by Network Use:
  Process (count) Input / Output (Source - Location)
  Mail 3*MB / 612*KB (Apple)
  kav 483*KB / 975*KB (Kaspersky Lab UK Limited)
  Dropbox 454*KB / 536*KB (Dropbox, Inc.)
  mDNSResponder 592*KB / 395*KB (Apple)
  netbiosd 146*KB / 22*KB (Apple)

Virtual Memory Information:
  Physical RAM: 16*GB

  Free RAM: 1.18*GB
  Used RAM: 10.52*GB
  Cached files: 4.30*GB

  Available RAM: 5.48*GB
  Swap Used: 14*MB

Software Installs (past 30 days):
  Install Date Name (Version)
  2019-04-24 WhatsApp (0.3.2848)
  2019-04-26 CotEditor (3.7.3)
  2019-05-02 XProtectPlistConfigData (2103)
  2019-05-02 MRTConfigData (1.41)
  2019-05-09 Keynote (9.0)
  2019-05-10 OneDrive (19.043.0304)
  2019-05-14 Gatekeeper Configuration Data (166)
  2019-05-14 EtreCheck (5.2)
  2019-05-14 Adobe Flash Player
  2019-05-14 Adobe Pepper Flash Player
  2019-05-15 Keeper (14.0.1)
  2019-05-15 Kindle (1.26.1)

Clean up:
  /Library/LaunchDaemons/pcloudd.plist
    /Applications/LenovoEMC Storage Manager.app/Contents/Resources/pcloudd
    Executable not found
  /Library/LaunchAgents/Magic_Tune.plist
    /Applications/MagicTune.app/Contents/MacOS/JavaApplicationStub
    Executable not found
  /Library/LaunchAgents/com.bitdefender.antivirusformac.plist
    /Library/Bitdefender/AVP/AntivirusforMac.app/Contents/MacOS/AntivirusforMac
    Executable not found
  /Library/LaunchDaemons/com.bitdefender.upgrade.plist
    /Library/Bitdefender/AVP/antivirus.bundle/BDUpgDaemon
    Executable not found


Diagnostics Information (past 7 days):
  Directory /Library/Logs/DiagnosticReports is not accessible.
  Enable Full Drive Access to see more information.

End of report
         
DetectX meldet das (siehe screenshot)
Kann ich das löschen?

Angehängte Grafiken
Dateityp: jpg Bildschirmfoto 2019-05-15 um 11.35.58.jpg (64,7 KB, 242x aufgerufen)

Alt 15.05.2019, 10:44   #6
ThomasHoll
 
infizierte Doc Datei mit Macros am Macbook geöffnet - Standard

infizierte Doc Datei mit Macros am Macbook geöffnet



Code:
ATTFilter
Timestamp (2): Wed May 15 11:38:27 2019
DetectX Swift v1.089

macOS: Version 10.14.4 (Build 18E226)
File System: apfs
Temp: The thermal state is within normal limits.

Boot time: Tue May 14 11:29:21 2019
Uptime: 1 day, 9 mins

Spotlight status for /:
	Indexing enabled. 
System Integrity Protection status: enabled.
Gatekeeper status: enabled for App Store and identified developers.
FileVault is On.

Internet:	Reachable


    Hardware Overview:

      Model Name: MacBook Pro
      Model Identifier: MacBookPro11,4
      Processor Name: Intel Core i7
      Processor Speed: 2,2 GHz
      Number of Processors: 1
      Total Number of Cores: 4
      L2 Cache (per Core): 256 KB
      L3 Cache: 6 MB
      Memory: 16 GB
      Boot ROM Version: 189.0.0.0.0
      SMC Version (system): 2.29f24



  Sharing Preferences:

	File Sharing:  Off
	Screen Sharing:  Off
	Remote Management:  Off
	Back To My Mac:  Off
	Remote Login:  Off
	Remote Apple Events:  Off


3rd Party Kexts (loaded):

	at.obdev.nke.LittleSnitch
	com.kaspersky.kext.klsat
	com.kaspersky.kext.kimul
	com.paragon-software.kext.VDMounter
	com.kaspersky.kext.klif
	com.kaspersky.nke
	com.globaldelight.driver.Boom2Device
	com.paragon-software.filesystems.ntfs
	org.virtualbox.kext.VBoxDrv
	org.virtualbox.kext.VBoxUSB
	org.virtualbox.kext.VBoxNetFlt
	org.virtualbox.kext.VBoxNetAdp
	com.malwarebytes.mbam.rtprotection


 $PATH:

PATH=/usr/bin:/bin:/usr/sbin:/sbin


/etc/paths:
	/usr/local/bin
	/usr/bin
	/bin
	/usr/sbin
	/sbin

/etc/paths.d/:
	/Applications/Wireshark.app/Contents/MacOS

~/.bash_profile:
	
~/.bashrc:

~/.bash_login:

~/.profile:

~/.bash_logout:


PID	Status	Label
704	0	at.obdev.LittleSnitchHelper
712	0	com.sony.SonyAutoLauncher.agent
715	0	com.globaldelight.Boom3DHelper
-	0	com.cisco.videoguard10
724	0	com.adobe.GC.AGM
546	0	com.getdropbox.dropbox.35916
-	0	com.cisco.videoguard10.uninstall
713	0	com.sony.WirelessAutoImportLauncher.agent
714	0	com.malwarebytes.mbam.frontend.agent
723	0	com.paragon-software.ntfs.notification-agent
730	0	com.adobe.AdobeCreativeCloud
413	0	com.cisco.videoguardmonitor
-	0	com.openssh.ssh-agent
-	0	com.google.keystone.system.agent
708	-9	at.obdev.LittleSnitchUIAgent
-	0	com.sqwarq.DetectX-Swift.observer
466	0	com.kaspersky.kav.gui
-	0	com.valvesoftware.steamclean
11136	0	com.etresoft.EtreCheckMAS.36220
-	0	com.paragon-software.facebook.agent
-	0	com.adobe.GC.Scheduler-1.0
-	0	at.obdev.LittleSnitchNetworkMonitor.35976
-	111	com.adobe.ARMDCHelper.cc24aef4a1b90ed56a725c38014c95072f92651fb65e1bf9c8e43c37a23d420d
-	0	com.adobe.AAM.Scheduler-1.0
-	0	com.paragon-software.ntfs.FSMenuAppLoginItemHelper
547	0	com.mediaatelier.CheatSheet.30416
-	0	com.oracle.java.Java-Updater
846	0	com.adobe.CCXProcess.35984
11003	0	com.microsoft.Word.30200
-	0	com.google.keystone.system.xpcservice
-	0	com.paragon.updater
876	0	com.adobe.CCLibrary.32696
735	0	com.amazon.music
-	78	com.bitdefender.antivirusformac
710	0	com.coconut-flavour.coconutBattery-Menu
845	0	com.adobe.accmac.35980
718	0	com.samsung.portablessd.mon
-	0	com.dropbox.DropboxMacUpdate.agent
-	78	Magic_Tune


 System Launchd processes:

62      - 	com.malwarebytes.mbam.rtprotection.daemon
864      - 	com.adobe.acc.installer.v2
267      - 	com.paragon-software.installer
0      - 	com.vix.cron
0      - 	com.bitdefender.AuthHelperTool
0      - 	org.postfix.master
0      0 	com.google.keystone.daemon
258      - 	com.paragon-software.ntfsd
86      - 	com.seagate.TBDecorator.plist
0      - 	com.teamviewer.Helper
0      - 	com.microsoft.office.licensingV2.helper
90      - 	at.obdev.littlesnitchd
1511      - 	com.microsoft.autoupdate.helper
0     78 	com.bitdefender.upgrade
(dp)      0 	Adobe_Genuine_Software_Integrity_Service
266      - 	org.cups.cupsd
0      0 	com.adobe.fpsaud
0      - 	com.adobe.ARMDC.Communicator
(dp)     78 	com.Iomega.pcloudd
700      - 	com.malwarebytes.mbam.settings.daemon
108      - 	com.kaspersky.kav
0      - 	com.oracle.java.Helper-Tool
(dp)      0 	com.paragon-software.ntfs.loader
0      - 	com.adobe.ARMDC.SMJobBlessHelper
(dp)      0 	com.paragon-software.vdmounter
0      - 	com.paragon-software.spbackup.helper
(dp)      0 	org.wireshark.ChmodBPF



 User Login Items:
 
	/Applications/NTFS for Mac.app
	/Applications/NTFS for Mac.app/Contents/Library/LoginItems/FSMenuAppLoginItemHelper.app
	/Applications/Dropbox.app
	/Applications/Boom 3D.app
	/Applications/Boom 3D.app/Contents/Library/LoginItems/BoomHelper.app
	/Users/[U501]/Applications/CheatSheet.app



 /Library/LaunchDaemons:

	com.malwarebytes.mbam.settings.daemon.plist
		-> Program: /Library/Application Support/Malwarebytes/MBAM/Engine.bundle/Contents/PlugIns/SettingsDaemon.app/Contents/MacOS/SettingsDaemon
	
	com.paragon-software.ntfs.loader.plist
		--> Program Arguments: /sbin/kextload
		--> Program Arguments: /Library/Extensions/ufsd_NTFS.kext
	
	com.adobe.agsservice.plist
		--> Program Arguments: /Library/Application Support/Adobe/AdobeGCClient/AGSService
	
	com.adobe.ARMDC.SMJobBlessHelper.plist
		--> Program Arguments: /Library/PrivilegedHelperTools/com.adobe.ARMDC.SMJobBlessHelper
	
	com.bitdefender.AuthHelperTool.plist
		--> Program Arguments: /Library/Bitdefender/AVP/common.bundle/AuthHelperTool
		--> Program Arguments: /Library/Bitdefender/AVP/common.bundle/Common.plist
	
	com.malwarebytes.mbam.rtprotection.daemon.plist
		-> Program: /Library/Application Support/Malwarebytes/MBAM/Engine.bundle/Contents/PlugIns/RTProtectionDaemon.app/Contents/MacOS/RTProtectionDaemon
		--> Program Arguments: /Library/Application Support/Malwarebytes/MBAM/Engine.bundle/Contents/PlugIns/RTProtectionDaemon.app/Contents/MacOS/RTProtectionDaemon
		--> Program Arguments: -i
		--> Program Arguments: 85631028-E7CD-408C-A2D2-E11E13C6670D.pkg
	
	com.paragon-software.vdmounter.plist
		--> Program Arguments: /sbin/kextload
		--> Program Arguments: /Library/Extensions/VDMounter.kext
	
	com.bitdefender.upgrade.plist
		-> Program: /Library/Bitdefender/AVP/antivirus.bundle/BDUpgDaemon
		--> Program Arguments: /Library/Bitdefender/AVP/antivirus.bundle/BDUpgDaemon
	
	org.wireshark.ChmodBPF.plist
		-> Program: /Library/Application Support/Wireshark/ChmodBPF/ChmodBPF
	
	com.adobe.ARMDC.Communicator.plist
		--> Program Arguments: /Library/PrivilegedHelperTools/com.adobe.ARMDC.Communicator
	
	at.obdev.littlesnitchd.plist
		--> Program Arguments: /Library/Little Snitch/Little Snitch Daemon.bundle/Contents/MacOS/Little Snitch Daemon
	
	com.google.keystone.daemon.plist
		--> Program Arguments: /Library/Google/GoogleSoftwareUpdate/GoogleSoftwareUpdate.bundle/Contents/MacOS/GoogleSoftwareUpdateDaemon
	
	com.apple.installer.osmessagetracing.plist
		--> Program Arguments: /System/Library/PrivateFrameworks/OSInstaller.framework/Resources/OSMessageTracer
	
	com.seagate.TBDecorator.plist
		--> Program Arguments: /Library/Application Support/Seagate/TBLoopDriveParams
	
	com.teamviewer.Helper.plist
		-> Program: /Library/PrivilegedHelperTools/com.teamviewer.Helper
		--> Program Arguments: /Library/PrivilegedHelperTools/com.teamviewer.Helper
	
	org.virtualbox.startup.plist
		--> Program Arguments: /Library/Application Support/VirtualBox/LaunchDaemons/VirtualBoxStartup.sh
		--> Program Arguments: restart
	
	com.adobe.acc.installer.v2.plist
		-> Program: /Library/PrivilegedHelperTools/com.adobe.acc.installer.v2
		--> Program Arguments: /Library/PrivilegedHelperTools/com.adobe.acc.installer.v2
	
	com.paragon-software.installer.plist
		-> Program: /Library/PrivilegedHelperTools/com.paragon-software.installer
	
	com.teamviewer.teamviewer_service.plist
		--> Program Arguments: /Applications/TeamViewer.app/Contents/MacOS/TeamViewer_Service
		--> Program Arguments: -Module
		--> Program Arguments: Full
	
	com.paragon-software.spbackup.helper.plist
		--> Program Arguments: /Library/Application Support/Paragon Software/com.paragon-software.spbackup/com.paragon-software.spbackup.helper
	
	com.adobe.fpsaud.plist
		--> Program Arguments: /Library/Application Support/Adobe/Flash Player Install Manager/fpsaud
	
	com.kaspersky.kav.plist
		--> Program Arguments: /Library/Application Support/Kaspersky Lab/KAV/Binaries/kav
		--> Program Arguments: -r
		--> Program Arguments: -bl
	
	pcloudd.plist
		--> Program Arguments: /Applications/LenovoEMC Storage Manager.app/Contents/Resources/pcloudd
	
	com.microsoft.office.licensingV2.helper.plist
		-> Program: /Library/PrivilegedHelperTools/com.microsoft.office.licensingV2.helper
		--> Program Arguments: /Library/PrivilegedHelperTools/com.microsoft.office.licensingV2.helper
	
	com.oracle.java.Helper-Tool.plist
		--> Program Arguments: /Library/Internet Plug-Ins/JavaAppletPlugin.plugin/Contents/Resources/Helper-Tool
	
	com.paragon-software.ntfsd.plist
		--> Program Arguments: /Library/Application Support/Paragon Software/com.paragon-software.ntfsd
	
	com.microsoft.autoupdate.helper.plist
		-> Program: /Library/PrivilegedHelperTools/com.microsoft.autoupdate.helper
	



 /Library/LaunchAgents:

	Magic_Tune.plist
		--> Program Arguments: /Applications/MagicTune.app/Contents/MacOS/JavaApplicationStub
	
	com.google.keystone.xpcservice.plist
		--> Program Arguments: /Library/Google/GoogleSoftwareUpdate/GoogleSoftwareUpdate.bundle/Contents/Resources/GoogleSoftwareUpdateAgent.app/Contents/MacOS/GoogleSoftwareUpdateAgent
		--> Program Arguments: -runMode
		--> Program Arguments: xpchost
	
	com.adobe.AdobeCreativeCloud.plist
		-> Program: /Applications/Utilities/Adobe Creative Cloud/ACC/Creative Cloud.app/Contents/MacOS/Creative Cloud
		--> Program Arguments: /Applications/Utilities/Adobe Creative Cloud/ACC/Creative Cloud.app/Contents/MacOS/Creative Cloud
		--> Program Arguments: --showwindow=false
		--> Program Arguments: --onOSstartup=true
	
	at.obdev.LittleSnitchUIAgent.plist
		--> Program Arguments: /Library/Little Snitch/Little Snitch Agent.app/Contents/MacOS/Little Snitch Agent
	
	com.kaspersky.kav.gui.plist
		--> Program Arguments: /Library/Application Support/Kaspersky Lab/KAV/Applications/Kaspersky Anti-Virus Agent.app/Contents/MacOS/kav_agent
	
	com.teamviewer.teamviewer_desktop.plist
		--> Program Arguments: /Applications/TeamViewer.app/Contents/Helpers/TeamViewer_Desktop
		--> Program Arguments: -RunAsAgent
		--> Program Arguments: YES
		--> Program Arguments: -Module
		--> Program Arguments: Full
	
	com.google.keystone.agent.plist
		--> Program Arguments: /Library/Google/GoogleSoftwareUpdate/GoogleSoftwareUpdate.bundle/Contents/Resources/GoogleSoftwareUpdateAgent.app/Contents/MacOS/GoogleSoftwareUpdateAgent
		--> Program Arguments: -runMode
		--> Program Arguments: ifneeded
	
	com.paragon.updater.plist
		--> Program Arguments: /Library/Application Support/Paragon Updater/Paragon Updater.app/Contents/MacOS/Paragon Updater
		--> Program Arguments: --check
		--> Program Arguments: --delay=30
	
	com.sony.WirelessAutoImportLauncher.agent.plist
		--> Program Arguments: /Library/Application Support/WirelessAutoImport/WirelessImporterDaemon
	
	com.paragon-software.ntfs.notification-agent.plist
		--> Program Arguments: /Library/Application Support/Paragon Software/com.paragon-software.ntfs.notification-agent.app/Contents/MacOS/NotificationAgent
	
	com.adobe.GC.AGM.plist
		-> Program: /Library/Application Support/Adobe/AdobeGCClient/AGMService
		--> Program Arguments: /Library/Application Support/Adobe/AdobeGCClient/AGMService
		--> Program Arguments: -mode=logon
	
	com.paragon-software.facebook.agent.plist
		-> Program: /Library/Application Support/Paragon Software/Paragon Software Facebook Agent.app/Contents/MacOS/Paragon Software Facebook Agent
	
	com.teamviewer.teamviewer.plist
		--> Program Arguments: /Applications/TeamViewer.app/Contents/MacOS/TeamViewer
		--> Program Arguments: -RunAsAgent
		--> Program Arguments: YES
	
	com.malwarebytes.mbam.frontend.agent.plist
		-> Program: /Library/Application Support/Malwarebytes/MBAM/Engine.bundle/Contents/PlugIns/FrontendAgent.app/Contents/MacOS/FrontendAgent
	
	com.oracle.java.Java-Updater.plist
		--> Program Arguments: /Library/Internet Plug-Ins/JavaAppletPlugin.plugin/Contents/Resources/Java Updater.app/Contents/MacOS/Java Updater
		--> Program Arguments: -bgcheck
	
	com.adobe.AAM.Updater-1.0.plist
		-> Program: /Library/Application Support/Adobe/OOBE/PDApp/UWA/UpdaterStartupUtility
		--> Program Arguments: /Library/Application Support/Adobe/OOBE/PDApp/UWA/UpdaterStartupUtility
		--> Program Arguments: -mode=logon
	
	at.obdev.LittleSnitchHelper.plist
		--> Program Arguments: /Library/Little Snitch/Little Snitch Helper.app/Contents/MacOS/Little Snitch Helper
	
	com.adobe.GC.Invoker-1.0.plist
		-> Program: /Library/Application Support/Adobe/AdobeGCClient/agcinvokerutility
		--> Program Arguments: /Library/Application Support/Adobe/AdobeGCClient/agcinvokerutility
		--> Program Arguments: -mode=logon
	
	com.adobe.ARMDCHelper.cc24aef4a1b90ed56a725c38014c95072f92651fb65e1bf9c8e43c37a23d420d.plist
		--> Program Arguments: /Library/Application Support/Adobe/ARMDC/Application/Acrobat Update Helper.app/Contents/MacOS/Acrobat Update Helper
	
	com.bitdefender.antivirusformac.plist
		-> Program: /Library/Bitdefender/AVP/AntivirusforMac.app/Contents/MacOS/AntivirusforMac
		--> Program Arguments: /Library/Bitdefender/AVP/AntivirusforMac.app/Contents/MacOS/AntivirusforMac
	
	com.sony.SonyAutoLauncher.agent.plist
		--> Program Arguments: /Library/Application Support/Sony Application Launcher/SonyAutoLauncher.app/Contents/MacOS/SonyAutoLauncher
	



 ~/Library/LaunchAgents:

	com.amazon.music.startup.plist
	
	com.amazon.music.plist
		-> Program: /Applications/Amazon Music.app/Contents/MacOS/Amazon Music Helper
	
	com.srib.pssddaemon.plist
		--> Program Arguments: /Users/[U501]/Library/Application Support/PortableSSD/SamsungPortableSSD.app/Contents/Resources/SamsungPortableSSDMon
	
	org.virtualbox.vboxwebsrv.plist
		-> Program: /Applications/VirtualBox.app/Contents/MacOS/vboxwebsrv
	
	com.samsung.portablessd.mon.plist
		--> Program Arguments: /Users/[U501]/Library/Application Support/PortableSSD/SamsungPortableSSD.app/Contents/Resources/SamsungPortableSSDMon
	
	com.adobe.AAM.Updater-1.0.plist
		-> Program: /Library/Application Support/Adobe/OOBE/PDApp/UWA/UpdaterStartupUtility
		--> Program Arguments: /Library/Application Support/Adobe/OOBE/PDApp/UWA/UpdaterStartupUtility
		--> Program Arguments: -mode=scheduled
	
	com.cisco.videoguard10.plist
		--> Program Arguments: sh
		--> Program Arguments: -c
		--> Program Arguments: $HOME/Library/Cisco/VideoGuardPlayer/VideoGuard10/VideoGuard10.bundle/Contents/Resources/setupServer.sh
	
	com.cisco.videoguard10.uninstall.plist
		--> Program Arguments: sh
		--> Program Arguments: /Users/[U501]/.cisco/VideoGuard/uninstall/cisco_videoguard10/condUninstall.sh
	
	com.adobe.GC.Invoker-1.0.plist
		-> Program: /Library/Application Support/Adobe/AdobeGCClient/agcinvokerutility
		--> Program Arguments: /Library/Application Support/Adobe/AdobeGCClient/agcinvokerutility
		--> Program Arguments: -mode=scheduled
	
	com.coconut-flavour.coconutBattery-Menu.plist
		-> Program: /Applications/coconutBattery.app/Contents/Resources/coconutBattery Menu.app/Contents/MacOS/coconutBattery Menu
	
	com.dropbox.DropboxMacUpdate.agent.plist
		--> Program Arguments: /Users/[U501]/Library/Dropbox/DropboxMacUpdate.app/Contents/MacOS/DropboxMacUpdate
		--> Program Arguments: -check
		--> Program Arguments: periodic
	
	com.valvesoftware.steamclean.plist
		-> Program: /Users/[U501]/Library/Application Support/Steam/SteamApps/steamclean
		--> Program Arguments: /Users/[U501]/Library/Application Support/Steam/SteamApps/steamclean
		--> Program Arguments: Public
	
	com.sqwarq.DetectX-Swift.observer.plist
		--> Program Arguments: /Applications/DetectX Swift.app/Contents/MacOS/DetectX Swift
		--> Program Arguments: -observer
	
	com.cisco.videoguardmonitor.plist
		--> Program Arguments: sh
		--> Program Arguments: -c
		--> Program Arguments: $HOME/Library/Cisco/VideoGuardPlayer/VideoGuardMonitor/VideoGuardMonitor.bundle/Contents/Resources/launch.sh
	

 User Crontab:

	No cron jobs



 /etc:

	rc.common
	bashrc_Apple_Terminal
	bashrc
	zshrc
	rc.netboot
	efax.rc~previous
	php.ini.default-previous~orig
	pcloud.cfg
	aliases
	zprofile

 / $Root:

	enum_operation.log.0.gz
	.HFS+ Private Directory Data
 / .. children: 0
	.com_kaspersky_ids_drop
	.PKInstallSandboxManager / .. children: 0
	installer.failurerequests
	.file
	.Trashes / .. children: 0
	.com_kaspersky_iswift_journal
	.OSInstallerMessages
	enum_operation.log
	.dbfseventsd

 ~/ $Home:

	HDR Projects 5 / .. children: 13
	Projects Series / .. children: 3
	.eclipse / .. children: 4
	.config / .. children: 4
	Music / .. children: 10
	.kodi / .. children: 1
	iCloud Drive (Archiv) / .. children: 14
	Export.xls
	VirtualBox VMs / .. children: 1
	.CFUserTextEncoding
	.kindle / .. children: 2
	.tooling / .. children: 1
	bin / .. children: 2
	.adobe / .. children: 1
	OneDrive / .. children: 4
	.local / .. children: 1
	Creative Cloud Files / .. children: 2
	Pictures / .. children: 174
	Sharpen Projects standard / .. children: 12
	.rnd
	CaptureOne / .. children: 2
	Samsung / .. children: 2
	.plexht / .. children: 1
	.p2 / .. children: 3
	.nag
	Desktop / .. children: 81
	Library / .. children: 96
	eclipse-workspace / .. children: 4
	index_split_004.html
	.oracle_jre_usage / .. children: 9
	Calibre-Bibliothek / .. children: 6
	Garten Streibl-Facebook Titel.png
	.trial
	.android / .. children: 3
	.cups / .. children: 1
	Adlm / .. children: 1
	.bash_sessions / .. children: 27
	Google Drive / .. children: 5
	BlackWhite Projects 4 / .. children: 9
	eviltom@freenet.de Creative Cloud Files / .. children: 1
	Public / .. children: 4
	.dropbox / .. children: 11
	Wine Files / .. children: 8
	.smb / .. children: 3
	.cisco / .. children: 1
	Twonky Library.twonky / .. children: 1
	DVDFab Media Player Snapshot / .. children: 0
	onlineTV Mac / .. children: 2
	.reincubate / .. children: 1
	.mediathek3 / .. children: 8
	.ssh / .. children: 0
	Image Data Converter / .. children: 1
	Movies / .. children: 16
	Applications / .. children: 6
	Dropbox / .. children: 9
	.Trash / .. children: 0
	DSC00005.ARW
	DSC00004.ARW
	Documents / .. children: 190
	Facebook Streibl 2.png
	.mcf / .. children: 2
	Garten Streibl Brief Vorlage Kunst.doc
	.mono / .. children: 1
	DSC00006.ARW
	NetBeansProjects / .. children: 1
	.bash_profile
	.dvdcss / .. children: 5
	Downloads / .. children: 143
	Toms Drive / .. children: 7
	LenovoEMCStorageManager-[U501]
	DSC00003.ARW
	DSC00002.ARW
	.bash_history
	DSC00001.ARW
	Uninstall LenovoEMC Storage Manager.app



 ~/Library:

	Receipts / .. children: 6
	Saved Searches / .. children: 11
	Mobotix / .. children: 2
	Address Book Plug-Ins / .. children: 4
	studentd / .. children: 4
	PDF Services / .. children: 0
	HomeKit / .. children: 6
	QuickLook / .. children: 1
	Google / .. children: 3
	Network / .. children: 1
	Family / .. children: 1
	DmpBase / .. children: 3
	Cisco / .. children: 1
	.tv7
	VirtualBox / .. children: 18
	Personas / .. children: 3
	PhotoshopCrashes / .. children: 0
	FrontBoard / .. children: 3
	News / .. children: 1
	EQATEC Analytics / .. children: 4
	WebTV / .. children: 3
	Dropbox / .. children: 1
	PhotoshopElementsCrashes / .. children: 0
	Frameworks / .. children: 2
	PersonalizationPortrait / .. children: 1
	VoiceTrigger / .. children: 1
	Widgets / .. children: 1



 ~/Library/Application Support:

	Firefox / .. children: 4
	.asskb
	com.apple.sbd / .. children: 1
	Logitech / .. children: 0
	CutOut / .. children: 7
	GoToOpener / .. children: 2
	SyncServices / .. children: 1
	5KPlayer / .. children: 1
	CitrixOnline / .. children: 1
	Vectorworks RMCache / .. children: 1
	.AdobeUpdater_Lock
	Mozilla / .. children: 1
	com.paragon-software.ntfs.fsapp / .. children: 1
	com.sonos.macController / .. children: 1
	AirDroid / .. children: 4
	com.apple.touristd / .. children: 11
	WashAndGo / .. children: 7
	DiskImages / .. children: 1
	Steam / .. children: 12
	CoreParsec / .. children: 0
	com.wondershare.PDFelement6.Professional / .. children: 5
	BenVista / .. children: 2
	Aiseesoft Studio / .. children: 1
	NCH Software / .. children: 1
	audacity / .. children: 6
	Digiarty / .. children: 1
	LogMeInInc / .. children: 1
	KeepVid / .. children: 1
	PMH Mac / .. children: 14
	MobileSync / .. children: 2
	FlipBuilder / .. children: 3
	.63869F41D5AF236E45D9D9B9EE7C8860
	ProApps / .. children: 2
	IDC Mac / .. children: 2
	Google / .. children: 7
	Rheinwerk / .. children: 2
	Compressor / .. children: 2
	aimersoft / .. children: 3
	Microsoft / .. children: 1
	Spotify / .. children: 4
	.FUS / .. children: 8
	Oracle / .. children: 1
	.baskb
	com.adobe.xd / .. children: 1
	dmd / .. children: 0
	Samsung / .. children: 1
	com.malwarebytes.mbam.frontend.application / .. children: 1
	com.paragon-software.ntfs.notification-agent / .. children: 1
	Motion / .. children: 2
	Seagate Dashboard 2.0 / .. children: 2
	Action Cam Movie Creator / .. children: 0
	Path Finder / .. children: 3
	Autodesk / .. children: 13
	Capture One / .. children: 9
	CEF / .. children: 1
	AKVIS / .. children: 1
	CodecPlatform_MMPDec / .. children: 0
	com.crashlytics / .. children: 1
	Adobe / .. children: 64
	PinoklGames / .. children: 1
	org.videolan.vlc / .. children: 4
	Vectorworks Cloud Services / .. children: 3
	.ACCC_Lock
	Final Cut Pro / .. children: 2
	com.operasoftware.Opera / .. children: 56
	TeamViewer / .. children: 1
	Color Effects CC / .. children: 2
	com.sqwarq.DetectX-Swift / .. children: 3
	Vectorworks / .. children: 1
	Sky Go / .. children: 39
	.settings
	Coda 2 / .. children: 11
	DVDFab Media Player / .. children: 3
	Boom3D / .. children: 7
	vectorworks-installer-wrapper / .. children: 1
	MacPhun Software / .. children: 1
	Algoriddim / .. children: 6
	ClickCharts / .. children: 1
	CleanMyMac 3 / .. children: 1
	Dropbox / .. children: 3
	AdobeWLCMCache.dat
	Canon_Inc_IC / .. children: 1
	NetBeans / .. children: 2
	ISL / .. children: 4
	Preview / .. children: 0
	djay Pro / .. children: 2
	DVD Player / .. children: 1
	com.imobie.AnyTrans / .. children: 1
	com.wd.WDMyCloud / .. children: 1
	Amazon Music / .. children: 6
	com.iMobie.AirBackupHelper / .. children: 1
	wondershare / .. children: 2
	Little Snitch / .. children: 2
	Skype / .. children: 8
	__Caches / .. children: 2
	TEC-IT / .. children: 1
	Vivaldi / .. children: 19
	TeamViewer QuickSupport / .. children: 1
	Imaging Edge / .. children: 5
	TechSmith / .. children: 1
	Helper / .. children: 3
	DaisyDisk / .. children: 1
	__Logs / .. children: 1
	Sonos / .. children: 4
	com.malwarebytes.mbam.frontend.agent / .. children: 1
	com.mediaatelier.CheatSheet / .. children: 1
	TorBrowser-Data / .. children: 3
	DetectX Swift / .. children: 3
	com.globaldelight.Boom3D / .. children: 1
	Google Earth / .. children: 3
	.onlinetvmac / .. children: 1
	WhatsApp / .. children: 15
	Pencil / .. children: 2
	OpenMeta / .. children: 2
	PortableSSD / .. children: 6
	OpenOffice / .. children: 1
	JREInstaller / .. children: 1
	Feral Interactive / .. children: 1
	CheatSheet / .. children: 0
	.ADCS_Lock



 ~/Library/Safari/Extensions:

	*-- Could not read Folder --*



 ~/Library/Internet Plug-Ins:

	Picasa.plugin



 /Users/Shared:

	Mobotix / .. children: 1
	.system-filesandbox.plist
	adi / .. children: 4
	SC Info / .. children: 2
	.Aimersoft_toholl.dat
	.AKVIS.Sketch.conf
	Aimersoft.plist
	AdobeInstalledCodecs / .. children: 0
	Capture One / .. children: 2
	Adobe / .. children: 5
	.logishrd / .. children: 0
	Canon_Inc_IC / .. children: 2
	TechSmith / .. children: 1



 /Applications:

	FLAC MP3 Converter.app
	Adobe Character Animator CC (Beta) / .. children: 3
	VLC.app
	Adobe Photoshop CC 2019 / .. children: 7
	Path Finder.app
	MxEasy.app
	Google Earth Pro.app
	iBooks Author.app
	WashAndGo.app
	Adobe XD / .. children: 3
	Vivaldi.app
	Sonos.app
	Books.app
	TeamViewer.app
	JDownloader Installer.app
	Adobe Illustrator CC 2019 / .. children: 11
	AirDroid.app
	mVintage.app
	AnyTrans.app
	MoneyControl.app
	5KPlayer.app
	Flip HTML5.app
	Home.app
	SketchBook.app
	Google Chrome.app
	Dropbox.app
	Paragon VMDK Mounter.app
	Adobe Bridge CC 2019 / .. children: 7
	NTFS for Mac.app
	Telegram.app
	SHARPEN projects.app
	Vectorworks 2019 / .. children: 21
	ClipGrab.app
	Adobe Creative Cloud / .. children: 4
	CutOut 6.0.app
	ClickCharts.app
	OneDrive.app
	SILKYPIX Developer Studio Pro 7G.app
	News.app
	coconutBattery.app
	Spotify.app
	Apple Configurator 2.app
	CutOut 2018 professional / .. children: 4
	MindNode.app
	Adobe Media Encoder CC 2019 / .. children: 3
	iPhone Backup Extractor.app
	DetectX Swift.app
	Adobe InDesign CC 2019 / .. children: 13
	Adobe Premiere Pro CC 2019 / .. children: 4
	DaisyDisk.app
	Microsoft Word.app
	Kaspersky Anti-Virus For Mac.app
	Wireless Auto Import.app
	Kindle Previewer 3.app
	Seagate Dashboard.app
	Kindle Create.app
	JDownloader2.app
	Microsoft Remote Desktop.localized / .. children: 2
	Audacity.app
	Adobe Lightroom CC / .. children: 3
	Adobe After Effects CC 2019 / .. children: 9
	Adobe Dreamweaver CC 2019 / .. children: 8
	Beautune.app
	Stocks.app
	Adobe Acrobat Reader DC.app
	djay Pro 2.app
	PhotoZoom Pro 7.app
	Kindle.app
	Smart Switch / .. children: 2
	Microsoft Excel.app
	Microsoft Silverlight
	Adobe / .. children: 1
	Canon Utilities / .. children: 2
	calibre.app
	KeepVid Video Converter.app
	WhatsApp.app
	TextEditor.app
	Little Snitch Configuration.app
	CD-LabelPrint / .. children: 5
	Malwarebytes.app
	Wireshark.app
	Extra / .. children: 3
	MPV's Motion 5 101 - Overview and Workflow Guide.app
	Adobe Photoshop Elements 13 / .. children: 4
	StarMoney 2.app
	Keeper.app
	VirtualBox.app
	Image Data Converter / .. children: 1
	EtreCheck.app
	NetBeans / .. children: 1
	The Unarchiver.app
	Adobe Lightroom Classic / .. children: 3
	CotEditor.app
	WD My Cloud / .. children: 2
	Amazon Music.app
	Final Cut Pro.app
	SamsungPortableSSD.app
	WISO steuer 2018.app
	Skype.app
	VoiceMemos.app
	MediathekView.app
	HDR projects 5.app
	BLACK WHITE projects 4.app
	Firefox.app
	Capture One 11.app
	TorBrowser.app
	Imaging Edge / .. children: 0
	WhatsApp.localized / .. children: 2
	MxManagementCenter.app
	Microsoft PowerPoint.app
	Picasa.app
	Adobe Acrobat DC / .. children: 4
	Motion.app
	Boom 3D.app
	Logic Pro X.app



 /Library:

	Plug-Ins / .. children: 1
	CFMSupport / .. children: 1
	DropboxHelperTools / .. children: 2
	Google / .. children: 2
	Autodesk / .. children: 1
	HostUUID
	WebTVPlugin / .. children: 1
	Automator / .. children: 1
	Little Snitch / .. children: 6
	Services / .. children: 1



 /Library/Application Support:

	Bitdefender / .. children: 4
	Mozilla / .. children: 2
	Sony Application Launcher / .. children: 3
	PMH Mac / .. children: 1
	Paragon Updater / .. children: 1
	Macromedia / .. children: 2
	Vectorworks 2019 / .. children: 3
	Apple Qmaster / .. children: 1
	Kaspersky Lab / .. children: 3
	Microsoft / .. children: 3
	Oracle / .. children: 1
	.Macrovision11.12.0.0 build 136775.uct2
	FLEXnet Publisher / .. children: 1
	Antivirus for Mac / .. children: 4
	Seagate / .. children: 1
	GData / .. children: 1
	WirelessAutoImport / .. children: 1
	Autodesk / .. children: 2
	VirtualBox / .. children: 5
	Adobe / .. children: 64
	Final Cut Pro System Support / .. children: 1
	Malwarebytes / .. children: 1
	Final Cut Pro / .. children: 2
	mVintage / .. children: 10
	Objective Development / .. children: 1
	MacPhun Software / .. children: 1
	Canon_Inc_IC / .. children: 1
	TEC-IT / .. children: 1
	regid.1986-12.com.adobe / .. children: 5
	Logitech.localized / .. children: 2
	Paragon Software / .. children: 8
	Wireshark / .. children: 1
	Sony / .. children: 1



 /Library/Extensions:

	FileProtect.kext
	kimul.kext
	tun.kext
	klsat.kext
	VDMounter.kext
	ufsd_NTFS.kext
	klif.kext
	mark.kext
	SONYDeviceType04.kext
	BJUSBLoad.kext
	LittleSnitch.kext
	CIJUSBLoad.kext
	klnke.kext
	Boom2Device.kext
	TMProtection.kext
	Seagate Storage Driver.kext
	tap.kext



 /Library/Internet Plug-Ins:

	EntertainTV mobil.plugin
	AdobeAAMDetect.plugin
	Disabled Plug-Ins / .. children: 2
	AdobePDFViewer.plugin
	Silverlight.plugin
	AdobePDFViewerNPAPI.plugin
	Flash Player.plugin
	flashplayer.xpt
	JavaAppletPlugin.plugin
	PepperFlashPlayer / .. children: 2



 /Library/Managed Preferences:

	*-- Folder doesn't exist or is inaccessible --*



 /Library/PrivilegedHelperTools:

	com.adobe.ARMDC.SMJobBlessHelper
	com.teamviewer.Helper
	com.paragon-software.installer
	com.microsoft.autoupdate.helper
	com.microsoft.office.licensingV2.helper
	com.adobe.acc.installer.v2
	com.adobe.ARMDC.Communicator



 /Library/ScriptingAdditions:

	Adobe Unit Types.osax



 /Library/StartupItems:

	tun / .. children: 3
	tap / .. children: 3



 /Library/Updates:

	ProductMetadata.plist
	PPDVersions.plist
	index.plist



Top Processes: 

%CPU	PID	COMMAND	
9.6		259		WindowServer 
9.3		324		Mail 
8.5		108		kav 
5.2		15112		DetectX Swift 
4.9		0		kernel_task 
3.7		62		RTProtectionDaem 
3.1		815		Little Snitch Ne 
2.9		126		hidd 
2.5		547		CheatSheet 
2.2		192		coreaudiod 


Running Processes: 

PPID	PID	%CPU	USER	COMMAND	
0		1		0.0		root		/sbin/launchd 
1		59		0.0		root		/usr/sbin/syslogd 
1		60		0.0		root		/usr/libexec/UserEventAgent (System) 
1		62		1.4		root		/Library/Application Support/Malwarebytes/MBAM/Engine.bundle/Contents/PlugIns/RTProtectionDaemon.app/Contents/MacOS/RTProtectionDaemon -i 85631028-E7CD-408C-A2D2-E11E13C6670D.pkg 
1		64		0.0		root		/System/Library/PrivateFrameworks/Uninstall.framework/Resources/uninstalld 
1		65		0.0		root		/usr/libexec/kextd 
1		66		0.0		root		/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/FSEvents.framework/Versions/A/Support/fseventsd 
1		68		0.0		root		/System/Library/PrivateFrameworks/MediaRemote.framework/Support/mediaremoted 
1		71		0.0		_appleevents		/System/Library/CoreServices/appleeventsd --server 
1		72		0.0		root		/usr/sbin/systemstats --daemon 
1		74		0.0		root		/usr/libexec/configd 
1		75		0.1		root		/System/Library/CoreServices/powerd.bundle/powerd 
1		78		0.6		root		/usr/libexec/logd 
1		79		0.0		root		/usr/libexec/keybagd -t 15 
1		86		0.0		root		/Library/Application Support/Seagate/TBLoopDriveParams 
1		87		0.0		_iconservices		/System/Library/CoreServices/iconservicesd 
1		88		0.0		root		/usr/libexec/diskarbitrationd 
1		90		0.0		root		/Library/Little Snitch/Little Snitch Daemon.bundle/Contents/MacOS/Little Snitch Daemon 
1		92		0.0		root		/System/Library/CoreServices/backupd.bundle/Contents/Resources/backupd-helper -launchd 
1		93		0.0		root		/usr/libexec/coreduetd 
1		98		0.0		root		/usr/libexec/opendirectoryd 
1		99		0.0		root		/System/Library/PrivateFrameworks/ApplePushService.framework/apsd 
1		100		0.0		root		/System/Library/PrivateFrameworks/Noticeboard.framework/Versions/A/Resources/nbstated 
1		101		0.0		root		/System/Library/CoreServices/launchservicesd 
1		102		0.0		_timed		/usr/libexec/timed 
1		104		0.0		root		/usr/sbin/securityd -i 
1		105		0.0		_usbmuxd		/System/Library/PrivateFrameworks/MobileDevice.framework/Versions/A/Resources/usbmuxd -launchd 
1		107		0.0		_locationd		/usr/libexec/locationd 
1		108		4.4		root		/Library/Application Support/Kaspersky Lab/KAV/Binaries/kav -r -bl 
1		111		0.0		root		autofsd		
1		112		0.0		_displaypolicyd		/usr/libexec/displaypolicyd -k 1 
1		114		0.0		root		/usr/libexec/dasd 
1		117		0.0		root		/usr/libexec/PerfPowerServices 
1		119		0.0		[U501]		/System/Library/CoreServices/loginwindow.app/Contents/MacOS/loginwindow console 
1		120		0.0		root		/System/Library/CoreServices/logind 
1		121		0.0		root		/System/Library/PrivateFrameworks/GenerationalStorage.framework/Versions/A/Support/revisiond 
1		122		0.0		root		/usr/sbin/KernelEventAgent 
1		124		0.0		root		/usr/sbin/bluetoothd 
1		126		4.0		_hidd		/usr/libexec/hidd 
1		127		0.0		root		/usr/libexec/sandboxd 
1		128		0.0		root		/usr/libexec/corebrightnessd --launchd 
1		129		0.0		root		/usr/libexec/AirPlayXPCHelper 
1		130		0.0		root		/usr/libexec/amfid 
1		131		0.0		root		/usr/sbin/notifyd 
1		132		0.0		_distnote		/usr/sbin/distnoted daemon 
1		133		0.0		root		/usr/libexec/taskgated 
1		135		0.0		root		/System/Library/CoreServices/coreservicesd 
1		136		0.0		root		/usr/sbin/cfprefsd daemon 
1		139		0.0		root		/System/Library/Frameworks/Security.framework/Versions/A/XPCServices/authd.xpc/Contents/MacOS/authd 
1		141		0.0		root		aslmanager		
1		144		0.0		root		/usr/libexec/syspolicyd 
1		182		0.0		root		/System/Library/PrivateFrameworks/CoreDuetContext.framework/Resources/contextstored 
1		188		0.0		root		/System/Library/PrivateFrameworks/WirelessDiagnostics.framework/Support/awdd 
1		191		0.0		root		/usr/libexec/airportd 
1		192		3.8		_coreaudiod		/usr/sbin/coreaudiod 
1		194		0.0		root		/usr/libexec/nehelper 
1		196		0.0		root		/System/Library/Frameworks/PCSC.framework/Versions/A/XPCServices/com.apple.ctkpcscd.xpc/Contents/MacOS/com.apple.ctkpcscd 
1		199		0.0		root		/usr/libexec/trustd 
1		205		0.0		_ctkd		/System/Library/Frameworks/CryptoTokenKit.framework/ctkd -s 
1		211		0.0		_coreaudiod		/System/Library/Frameworks/CoreAudio.framework/Versions/A/XPCServices/com.apple.audio.DriverHelper.xpc/Contents/MacOS/com.apple.audio.DriverHelper 
1		215		0.0		_networkd		/usr/libexec/symptomsd 
1		216		0.0		root		/usr/libexec/mobileassetd 
1		223		0.0		root		/usr/sbin/ocspd 
1		226		0.0		_nsurlsessiond		/usr/libexec/nsurlsessiond --privileged 
1		227		0.0		_mdnsresponder		/usr/sbin/mDNSResponder 
1		228		0.0		root		/usr/sbin/mDNSResponderHelper 
1		235		0.0		root		/usr/libexec/lsd runAsRoot 
1		238		0.0		root		/System/Library/Frameworks/Security.framework/Versions/A/XPCServices/com.apple.CodeSigningHelper.xpc/Contents/MacOS/com.apple.CodeSigningHelper 
1		239		0.0		root		/System/Library/Frameworks/AudioToolbox.framework/AudioComponentRegistrar -daemon 
1		241		0.0		_coreaudiod		/System/Library/Frameworks/AudioToolbox.framework/XPCServices/com.apple.audio.SandboxHelper.xpc/Contents/MacOS/com.apple.audio.SandboxHelper 
1		258		0.0		root		/Library/Application Support/Paragon Software/com.paragon-software.ntfsd 
1		259		11.9		_windowserver		/System/Library/PrivateFrameworks/SkyLight.framework/Resources/WindowServer -daemon 
1		261		0.0		root		/System/Library/CryptoTokenKit/com.apple.ifdreader.slotd/Contents/MacOS/com.apple.ifdreader 
1		262		0.0		root		/usr/libexec/apfsd 
1		264		0.0		root		/usr/libexec/usbd 
1		265		0.0		_cmiodalassistants		/System/Library/Frameworks/CoreMediaIO.framework/Resources/VDC.plugin/Contents/Resources/VDCAssistant 
1		266		0.0		root		/usr/sbin/cupsd -l 
1		267		0.0		root		/Library/PrivilegedHelperTools/com.paragon-software.installer 
1		268		0.0		root		/usr/libexec/ApplicationFirewall/socketfilterfw 
1		269		0.0		root		/usr/libexec/watchdogd 
1		271		0.0		root		/usr/libexec/thermald 
1		273		0.0		root		/usr/libexec/secinitd 
1		274		0.0		root		/System/Library/PrivateFrameworks/TCC.framework/Resources/tccd system 
1		280		0.0		root		/System/Library/Frameworks/OpenGL.framework/Versions/A/Libraries/CVMServer 
1		281		0.0		root		/usr/libexec/colorsync.displayservices 
1		288		0.0		root		/usr/libexec/colorsyncd 
1		291		0.0		root		/usr/libexec/bootinstalld 
1		300		0.0		root		/System/Library/PrivateFrameworks/AccountPolicy.framework/XPCServices/com.apple.AccountPolicyHelper.xpc/Contents/MacOS/com.apple.AccountPolicyHelper 
1		303		0.0		root		/System/Library/Frameworks/GSS.framework/Helpers/GSSCred 
1		304		0.0		root		/System/Library/PrivateFrameworks/PerformanceAnalysis.framework/Versions/A/XPCServices/com.apple.PerformanceAnalysis.animationperfd.xpc/Contents/MacOS/com.apple.PerformanceAnalysis.animationperfd 
1		312		0.0		root		/System/Library/Frameworks/LocalAuthentication.framework/Support/coreauthd 
1		313		0.0		root		/usr/libexec/securityd_service 
1		314		0.0		[U501]		/System/Library/Frameworks/LocalAuthentication.framework/Support/coreauthd 
1		315		0.0		[U501]		/usr/sbin/cfprefsd agent 
1		317		0.0		[U501]		/usr/libexec/UserEventAgent (Aqua) 
1		319		0.0		[U501]		/usr/sbin/distnoted agent 
1		321		0.0		[U501]		/usr/libexec/lsd 
1		322		0.0		[U501]		/System/Library/Frameworks/CoreTelephony.framework/Support/CommCenter -L 
1		323		0.0		[U501]		/usr/libexec/trustd --agent 
1		324		18.3		[U501]		/Applications/Mail.app/Contents/MacOS/Mail -psn_0_32776 
1		326		0.0		[U501]		/System/Library/CoreServices/sharedfilelistd 
1		329		0.0		[U501]		/Applications/Safari.app/Contents/MacOS/Safari -psn_0_40970 
1		330		0.0		[U501]		/Applications/Google Chrome.app/Contents/MacOS/Google Chrome -psn_0_45067 
1		332		0.0		[U501]		/usr/libexec/secd 
1		335		0.0		[U501]		/System/Library/PrivateFrameworks/CloudKitDaemon.framework/Support/cloudd 
1		337		0.0		root		/usr/sbin/WirelessRadioManagerd 
1		338		0.0		[U501]		/System/Library/PrivateFrameworks/TelephonyUtilities.framework/callservicesd 
1		340		0.0		[U501]		/System/Library/PrivateFrameworks/IDS.framework/identityservicesd.app/Contents/MacOS/identityservicesd 
1		341		0.0		[U501]		/System/Library/Frameworks/Accounts.framework/Versions/A/Support/accountsd 
1		342		0.0		[U501]		/System/Library/PrivateFrameworks/TCC.framework/Resources/tccd 
1		343		0.0		[U501]		/usr/libexec/nsurlsessiond 
1		345		0.0		[U501]		/System/Library/PrivateFrameworks/IMCore.framework/imagent.app/Contents/MacOS/imagent 
1		347		0.0		[U501]		/System/Library/PrivateFrameworks/IMDPersistence.framework/XPCServices/IMDPersistenceAgent.xpc/Contents/MacOS/IMDPersistenceAgent 
1		348		0.0		[U501]		/System/Library/Frameworks/AddressBook.framework/Executables/ContactsAccountsService 
1		350		0.0		[U501]		/usr/libexec/secinitd 
1		351		0.0		[U501]		/usr/libexec/routined LAUNCHED_BY_LAUNCHD 
1		353		0.0		[U501]		/System/Library/CoreServices/talagent 
1		354		0.1		[U501]		/System/Library/CoreServices/Dock.app/Contents/MacOS/Dock 
1		355		0.0		_analyticsd		/System/Library/PrivateFrameworks/CoreAnalytics.framework/Support/analyticsd 
1		356		0.0		[U501]		/System/Library/CoreServices/SystemUIServer.app/Contents/MacOS/SystemUIServer 
1		357		0.0		root		/System/Library/CoreServices/CrashReporterSupportHelper server-init 
1		358		0.0		[U501]		/System/Library/CoreServices/Finder.app/Contents/MacOS/Finder 
1		359		0.0		root		/usr/sbin/spindump 
1		361		0.0		[U501]		/usr/libexec/pboard 
1		363		0.4		root		/usr/sbin/systemsoundserverd 
1		364		0.0		root		/System/Library/CoreServices/SubmitDiagInfo server-init 
1		373		0.0		[U501]		/System/Library/Frameworks/Security.framework/Versions/A/Resources/CloudKeychainProxy.bundle/Contents/MacOS/CloudKeychainProxy 
1		374		0.0		root		/usr/sbin/wirelessproxd 
1		375		0.0		[U501]		/usr/libexec/rapportd 
1		376		0.0		[U501]		/System/Library/PrivateFrameworks/AuthKit.framework/Versions/A/Support/akd 
1		378		0.0		[U501]		/usr/libexec/pkd 
1		379		0.0		[U501]		/System/Library/CoreServices/iconservicesagent 
1		384		0.1		[U501]		/usr/sbin/usernoted 
1		385		0.0		[U501]		/System/Library/Frameworks/ApplicationServices.framework/Frameworks/ATS.framework/Support/fontd 
1		386		0.0		[U501]		/System/Library/CoreServices/NotificationCenter.app/Contents/MacOS/NotificationCenter 
1		388		0.0		[U501]		/System/Library/PrivateFrameworks/MessagesKit.framework/Resources/soagent.app/Contents/MacOS/soagent 
1		389		0.0		[U501]		/System/Library/PrivateFrameworks/UserActivity.framework/Agents/useractivityd 
1		390		0.0		[U501]		/usr/libexec/sharingd 
1		391		0.0		[U501]		/usr/libexec/fmfd 
1		392		0.0		[U501]		/System/Library/PrivateFrameworks/ProtectedCloudStorage.framework/Helpers/ProtectedCloudKeySyncing 
1		394		0.0		[U501]		/usr/libexec/nsurlstoraged 
1		395		0.0		_fpsd		/System/Library/PrivateFrameworks/CoreADI.framework/adid 
1		396		0.0		[U501]		/usr/libexec/networkserviceproxy 
1		397		0.0		[U501]		/System/Library/CoreServices/APFSUserAgent 
1		398		0.0		[U501]		/System/Library/PrivateFrameworks/CloudDocsDaemon.framework/Versions/A/Support/bird 
1		399		0.0		[U501]		/usr/libexec/spindump_agent 
1		400		0.0		[U501]		/System/Library/CoreServices/CoreLocationAgent.app/Contents/MacOS/CoreLocationAgent 
1		401		0.0		_locationd		/System/Library/PrivateFrameworks/GeoServices.framework/Versions/A/XPCServices/com.apple.geod.xpc/Contents/MacOS/com.apple.geod 
1		402		0.0		_locationd		/usr/libexec/secinitd 
1		403		0.0		_locationd		/usr/sbin/cfprefsd agent 
1		404		0.0		[U501]		/System/Library/PrivateFrameworks/FamilyCircle.framework/Versions/A/Resources/familycircled 
1		405		0.0		[U501]		/System/Library/CoreServices/WiFiAgent.app/Contents/MacOS/WiFiAgent 
1		406		0.0		_locationd		/usr/libexec/trustd --agent 
1		408		0.0		root		/usr/libexec/findmydeviced 
1		413		0.0		[U501]		/bin/bash /Users/[U501]/Library/Cisco/VideoGuardPlayer/VideoGuardMonitor/VideoGuardMonitor.bundle/Contents/Resources/launch.sh 
413		414		0.0		[U501]		./CiscoVideoGuardMonitor		
1		415		0.0		_nsurlstoraged		/usr/libexec/nsurlstoraged --privileged 
1		417		0.0		root		/System/Library/PrivateFrameworks/AmbientDisplay.framework/Versions/A/XPCServices/com.apple.AmbientDisplayAgent.xpc/Contents/MacOS/com.apple.AmbientDisplayAgent 
1		418		0.0		[U501]		SafeEjectGPUAgent		
1		419		0.0		[U501]		/System/Library/CoreServices/Menu Extras/SafeEjectGPUExtra.menu/Contents/XPCServices/SafeEjectGPUService.xpc/Contents/MacOS/SafeEjectGPUService 
1		420		0.0		root		/usr/sbin/filecoordinationd 
1		421		0.0		root		/System/Library/PrivateFrameworks/AssetCacheServicesExtensions.framework/XPCServices/AssetCacheManagerService.xpc/Contents/MacOS/AssetCacheManagerService 
1		422		0.0		root		/usr/libexec/sysmond 
1		425		0.0		[U501]		/System/Library/PrivateFrameworks/ViewBridge.framework/Versions/A/XPCServices/ViewBridgeAuxiliary.xpc/Contents/MacOS/ViewBridgeAuxiliary 
1		427		0.0		[U501]		/System/Library/PrivateFrameworks/SafariShared.framework/Versions/A/XPCServices/com.apple.Safari.History.xpc/Contents/MacOS/com.apple.Safari.History 
1		428		0.0		[U501]		/System/Library/CoreServices/Dock.app/Contents/XPCServices/com.apple.dock.extra.xpc/Contents/MacOS/com.apple.dock.extra 
1		430		0.0		[U501]		/System/Library/Frameworks/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.Networking.xpc/Contents/MacOS/com.apple.WebKit.Networking 
1		431		0.0		[U501]		/System/Library/PrivateFrameworks/CoreParsec.framework/parsecd 
1		433		0.0		[U501]		/System/Library/PrivateFrameworks/CommerceKit.framework/Versions/A/Resources/storeaccountd 
1		434		0.0		_gamecontrollerd		/usr/libexec/gamecontrollerd 
1		436		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Framework.framework/Helpers/chrome_crashpad_handler --monitor-self-annotation=ptype=crashpad-handler --database=/Users/[U501]/Library/Application Support/Google/Chrome/Crashpad --metrics-dir=/Users/[U501]/Library/Application Support/Google/Chrome --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=OS X --annotation=prod=Chrome_Mac --annotation=ver=74.0.3729.131 --handshake-fd=8 
1		437		0.0		[U501]		/System/Library/PrivateFrameworks/CommerceKit.framework/Versions/A/Resources/commerce 
1		438		0.0		[U501]		/System/Library/PrivateFrameworks/GeoServices.framework/Versions/A/XPCServices/com.apple.geod.xpc/Contents/MacOS/com.apple.geod 
1		439		0.0		[U501]		/System/Library/Frameworks/InputMethodKit.framework/Resources/imklaunchagent 
1		441		0.0		[U501]		/System/Library/PrivateFrameworks/CalendarAgent.framework/Executables/CalendarAgent 
1		442		0.0		[U501]		/System/Library/PrivateFrameworks/CallHistory.framework/Support/CallHistoryPluginHelper 
1		443		0.0		[U501]		/System/Library/PrivateFrameworks/AssistantServices.framework/Versions/A/Support/assistantd 
1		444		0.0		[U501]		/usr/libexec/swcd 
330		446		0.1		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=gpu-process --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --gpu-preferences=KAAAAAAAAAAgAAAAAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAADgBAAAmAAAAMAEAAAAAAAA4AQAAAAAAAEABAAAAAAAASAEAAAAAAABQAQAAAAAAAFgBAAAAAAAAYAEAAAAAAABoAQAAAAAAAHABAAAAAAAAeAEAAAAAAACAAQAAAAAAAIgBAAAAAAAAkAEAAAAAAACYAQAAAAAAAKABAAAAAAAAqAEAAAAAAACwAQAAAAAAALgBAAAAAAAAwAEAAAAAAADIAQAAAAAAANABAAAAAAAA2AEAAAAAAADgAQAAAAAAAOgBAAAAAAAA8AEAAAAAAAD4AQAAAAAAAAACAAAAAAAACAIAAAAAAAAQAgAAAAAAABgCAAAAAAAAIAIAAAAAAAAoAgAAAAAAADACAAAAAAAAOAIAAAAAAABAAgAAAAAAAEgCAAAAAAAAUAIAAAAAAABYAgAAAAAAABAAAAAAAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAAAAAAABwAAABAAAAAAAAAAAAAAAAgAAAAQAAAAAAAAAAAAAAAKAAAAEAAAAAAAAAAAAAAACwAAABAAAAAAAAAAAAAAAA0AAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAAAAAAABAAAAAAAAAAAQAAAAYAAAAQAAAAAAAAAAEAAAAHAAAAEAAAAAAAAAABAAAACAAAABAAAAAAAAAAAQAAAAoAAAAQAAAAAAAAAAEAAAALAAAAEAAAAAAAAAABAAAADQAAABAAAAAAAAAAAQAAAA4AAAAQAAAAAAAAAAQAAAAAAAAAEAAAAAAAAAAEAAAABgAAABAAAAAAAAAABAAAAAcAAAAQAAAAAAAAAAQAAAAIAAAAEAAAAAAAAAAEAAAACgAAABAAAAAAAAAABAAAAAsAAAAQAAAAAAAAAAQAAAANAAAAEAAAAAAAAAAEAAAADgAAABAAAAAAAAAABgAAAAAAAAAQAAAAAAAAAAYAAAAGAAAAEAAAAAAAAAAGAAAACAAAABAAAAAAAAAABgAAAAoAAAAQAAAAAAAAAAYAAAALAAAAEAAAAAAAAAAGAAAADQAAABAAAAAAAAAABgAAAA4AAAAQAAAAAAAAAAcAAAAAAAAAEAAAAAAAAAAHAAAABgAAABAAAAAAAAAABwAAAAgAAAAQAAAAAAAAAAcAAAAKAAAAEAAAAAAAAAAHAAAACwAAABAAAAAAAAAABwAAAA0AAAAQAAAAAAAAAAcAAAAOAAAA --service-request-channel-token=17528456032067334336 
330		447		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=utility --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --service-sandbox-type=network --service-request-channel-token=11195773460551407038 
1		448		0.0		[U501]		/System/Library/Input Methods/PressAndHold.app/Contents/PlugIns/PAH_Extension.appex/Contents/MacOS/PAH_Extension 
1		449		0.0		[U501]		/System/Library/PrivateFrameworks/CalendarNotification.framework/Versions/A/XPCServices/CalNCService.xpc/Contents/MacOS/CalNCService 
1		451		0.0		[U501]		/Applications/Kaspersky Anti-Virus For Mac.app/Contents/PlugIns/KasperskySecurity.appex/Contents/MacOS/KasperskySecurity 
1		452		0.0		[U501]		/System/Library/CoreServices/NotificationCenter.app/Contents/XPCServices/com.apple.notificationcenterui.WeatherSummary.xpc/Contents/MacOS/com.apple.notificationcenterui.WeatherSummary 
1		453		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Framework.framework/Versions/A/XPCServices/AlertNotificationService.xpc/Contents/MacOS/AlertNotificationService 
1		456		0.0		[U501]		/System/Library/Frameworks/VideoToolbox.framework/Versions/A/XPCServices/VTDecoderXPCService.xpc/Contents/MacOS/VTDecoderXPCService 
1		458		0.0		[U501]		/System/Library/CoreServices/SafariSupport.bundle/Contents/MacOS/SafariBookmarksSyncAgent 
1		459		0.0		[U501]		/usr/libexec/SafariNotificationAgent 
330		461		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=702075447788123581 --renderer-client-id=4 --no-v8-untrusted-code-mitigations --seatbelt-client=90 
1		466		0.0		[U501]		/Library/Application Support/Kaspersky Lab/KAV/Applications/Kaspersky Anti-Virus Agent.app/Contents/MacOS/kav_agent 
1		467		0.0		[U501]		/System/Library/PrivateFrameworks/CloudDocsDaemon.framework/XPCServices/ContainerMetadataExtractor.xpc/Contents/MacOS/ContainerMetadataExtractor 
1		469		0.0		[U501]		/System/Library/PrivateFrameworks/CommerceKit.framework/Versions/A/Resources/storeuid.app/Contents/MacOS/storeuid 
1		470		0.0		[U501]		/System/Library/CoreServices/Spotlight.app/Contents/MacOS/Spotlight 
330		472		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=17134935684638481130 --renderer-client-id=5 --no-v8-untrusted-code-mitigations --seatbelt-client=102 
330		473		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=9796091788070216638 --renderer-client-id=6 --no-v8-untrusted-code-mitigations --seatbelt-client=101 
330		474		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=15617683117124686455 --renderer-client-id=7 --no-v8-untrusted-code-mitigations --seatbelt-client=108 
330		475		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=14669503436245094967 --renderer-client-id=8 --no-v8-untrusted-code-mitigations --seatbelt-client=110 
330		476		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=542236323832490740 --renderer-client-id=9 --no-v8-untrusted-code-mitigations --seatbelt-client=111 
330		477		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=13758064188144013988 --renderer-client-id=10 --no-v8-untrusted-code-mitigations --seatbelt-client=117 
330		478		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=3465166289619389116 --renderer-client-id=11 --no-v8-untrusted-code-mitigations --seatbelt-client=116 
330		479		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=11722664920542976655 --renderer-client-id=12 --no-v8-untrusted-code-mitigations --seatbelt-client=116 
330		480		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=1180629351833717568 --renderer-client-id=13 --no-v8-untrusted-code-mitigations --seatbelt-client=116 
1		482		0.0		[U501]		/System/Library/PrivateFrameworks/CoreWLANKit.framework/Versions/A/XPCServices/WiFiProxy.xpc/Contents/MacOS/WiFiProxy 
1		488		0.0		[U501]		/System/Library/CoreServices/pbs 
1		489		0.0		_captiveagent		/usr/libexec/captiveagent 
330		490		0.0		[U501]		/Library/Application Support/Kaspersky Lab/KAV/Binaries/nm-server chrome-extension://ganjnhaighehkjnnlmaikllkkiejibfe/ 
1		491		0.0		[U501]		/System/Library/PrivateFrameworks/IMFoundation.framework/XPCServices/IMRemoteURLConnectionAgent.xpc/Contents/MacOS/IMRemoteURLConnectionAgent 
1		492		0.0		[U501]		/System/Library/PrivateFrameworks/IMFoundation.framework/XPCServices/IMRemoteURLConnectionAgent.xpc/Contents/MacOS/IMRemoteURLConnectionAgent 
1		493		0.0		[U501]		/System/Library/PrivateFrameworks/IMFoundation.framework/XPCServices/IMRemoteURLConnectionAgent.xpc/Contents/MacOS/IMRemoteURLConnectionAgent 
1		522		0.0		[U501]		/System/Library/PrivateFrameworks/IMFoundation.framework/XPCServices/IMRemoteURLConnectionAgent.xpc/Contents/MacOS/IMRemoteURLConnectionAgent 
1		523		0.0		[U501]		/System/Library/Frameworks/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.WebContent.xpc/Contents/MacOS/com.apple.WebKit.WebContent 
1		524		0.0		[U501]		/System/Library/Frameworks/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.Networking.xpc/Contents/MacOS/com.apple.WebKit.Networking 
1		526		0.5		[U501]		/System/Library/PrivateFrameworks/CoreRecents.framework/Versions/A/Support/recentsd 
1		527		0.0		[U501]		/System/Library/Frameworks/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.WebContent.xpc/Contents/MacOS/com.apple.WebKit.WebContent 
1		530		0.0		[U501]		/System/Library/PrivateFrameworks/CoreSuggestions.framework/Versions/A/Support/suggestd 
330		535		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=18052433785371241885 --renderer-client-id=40 --no-v8-untrusted-code-mitigations --seatbelt-client=172 
1		536		0.0		root		/System/Library/PrivateFrameworks/ViewBridge.framework/Versions/A/XPCServices/ViewBridgeAuxiliary.xpc/Contents/MacOS/ViewBridgeAuxiliary 
1		537		0.0		root		/usr/sbin/distnoted agent 
1		538		0.0		[U501]		/System/Library/PrivateFrameworks/FileProvider.framework/Support/fileproviderd 
1		542		0.0		root		/System/Library/Frameworks/CryptoTokenKit.framework/ctkahp.bundle/Contents/MacOS/ctkahp -d 
1		543		0.0		[U501]		/System/Library/CoreServices/backgroundtaskmanagementagent 
1		544		0.0		[U501]		/System/Library/Frameworks/CryptoTokenKit.framework/ctkahp.bundle/Contents/MacOS/ctkahp 
1		545		0.0		[U501]		/System/Library/Frameworks/CryptoTokenKit.framework/ctkd -tw 
1		546		0.7		[U501]		/Applications/Dropbox.app/Contents/MacOS/Dropbox 
1		547		3.4		[U501]		/Users/[U501]/Applications/CheatSheet.app/Contents/MacOS/CheatSheet 
1		555		0.0		[U501]		/Applications/Dropbox.app/Contents/MacOS/Dropbox -type:crashpad-handler --no-upload-gzip --no-rate-limit --capture-python --no-identify-client-via-url --database=/Users/[U501]/.dropbox/Crashpad --metrics-dir=0 --url=https://d.dropbox.com/report_crashpad_minidump --https-pin=0x23,0xf2,0xed,0xff,0x3e,0xde,0x90,0x25,0x9a,0x9e,0x30,0xf4,0xa,0xf8,0xf9,0x12,0xa5,0xe5,0xb3,0x69,0x4e,0x69,0x38,0x44,0x3,0x41,0xf6,0x6,0xe,0x1,0x4f,0xfa --https-pin=0xaf,0xf9,0x88,0x90,0x6d,0xde,0x12,0x95,0x5d,0x9b,0xeb,0xbf,0x92,0x8f,0xdc,0xc3,0x1c,0xce,0x32,0x8d,0x5b,0x93,0x84,0xf2,0x1c,0x89,0x41,0xca,0x26,0xe2,0x3,0x91 --https-pin=0x5a,0x88,0x96,0x47,0x22,0xe,0x54,0xd6,0xbd,0x8a,0x16,0x81,0x72,0x24,0x52,0xb,0xb5,0xc7,0x8e,0x58,0x98,0x4b,0xd5,0x70,0x50,0x63,0x88,0xb9,0xde,0xf,0x7,0x5f --https-pin=0xfe,0xa2,0xb7,0xd6,0x45,0xfb,0xa7,0x3d,0x75,0x3c,0x1e,0xc9,0xa7,0x87,0xc,0x40,0xe1,0xf7,0xb0,0xc5,0x61,0xe9,0x27,0xb9,0x85,0xbf,0x71,0x18,0x66,0xe3,0x6f,0x22 --https-pin=0x76,0xee,0x85,0x90,0x37,0x4c,0x71,0x54,0x37,0xbb,0xca,0x6b,0xba,0x60,0x28,0xea,0xdd,0xe2,0xdc,0x6d,0xbb,0xb8,0xc3,0xf6,0x10,0xe8,0x51,0xf1,0x1d,0x1a,0xb7,0xf5 --https-pin=0x6d,0xbf,0xae,0x0,0xd3,0x7b,0x9c,0xd7,0x3f,0x8f,0xb4,0x7d,0xe6,0x59,0x17,0xaf,0x0,0xe0,0xdd,0xdf,0x42,0xdb,0xce,0xac,0x20,0xc1,0x7c,0x2,0x75,0xee,0x20,0x95 --https-pin=0x1e,0xa3,0xc5,0xe4,0x3e,0xd6,0x6c,0x2d,0xa2,0x98,0x3a,0x42,0xa4,0xa7,0x9b,0x1e,0x90,0x67,0x86,0xce,0x9f,0x1b,0x58,0x62,0x14,0x19,0xa0,0x4,0x63,0xa8,0x7d,0x38 --https-pin=0x87,0xaf,0x34,0xd6,0x6f,0xb3,0xf2,0xfd,0xf3,0x6e,0x9,0x11,0x1e,0x9a,0xba,0x2f,0x6f,0x44,0xb2,0x7,0xf3,0x86,0x3f,0x3d,0xb,0x54,0xb2,0x50,0x23,0x90,0x9a,0xa5 --https-pin=0xbc,0xfb,0x44,0xaa,0xb9,0xad,0x2,0x10,0x15,0x70,0x6b,0x41,0x21,0xea,0x76,0x1c,0x81,0xc9,0xe8,0x89,0x67,0x59,0xf,0x6f,0x94,0xae,0x74,0x4d,0xc8,0x8b,0x78,0xfb --https-pin=0xab,0x98,0x49,0x52,0x76,0xad,0xf1,0xec,0xaf,0xf2,0x8f,0x35,0xc5,0x30,0x48,0x78,0x1e,0x5c,0x17,0x18,0xda,0xb9,0xc8,0xe6,0x7a,0x50,0x4f,0x4f,0x6a,0x51,0x32,0x8f --https-pin=0x49,0x5,0x46,0x66,0x23,0xab,0x41,0x78,0xbe,0x92,0xac,0x5c,0xbd,0x65,0x84,0xf7,0xa1,0xe1,0x7f,0x27,0x65,0x2d,0x5a,0x85,0xaf,0x89,0x50,0x4e,0xa2,0x39,0xaa,0xaa --https-pin=0x56,0x32,0xd9,0x7b,0xfa,0x77,0x5b,0xf3,0xc9,0x9d,0xde,0xa5,0x2f,0xc2,0x55,0x34,0x10,0x86,0x40,0x16,0x72,0x9c,0x52,0xdd,0x65,0x24,0xc8,0xa9,0xc3,0xb4,0x48,0x9f --https-pin=0x2a,0x8f,0x2d,0x8a,0xf0,0xeb,0x12,0x38,0x98,0xf7,0x4c,0x86,0x6a,0xc3,0xfa,0x66,0x90,0x54,0xe2,0x3c,0x17,0xbc,0x7a,0x95,0xbd,0x2,0x34,0x19,0x2d,0xc6,0x35,0xd0 --https-pin=0x32,0xb6,0x4b,0x66,0x72,0x7a,0x20,0x63,0xe4,0x6,0x6f,0x3b,0x95,0x8c,0xb0,0xaa,0xee,0x57,0x6a,0x5e,0xce,0xfd,0x95,0x33,0x99,0xbb,0x88,0x74,0x73,0x1d,0x95,0x87 --https-pin=0xf5,0x3c,0x22,0x5,0x98,0x17,0xdd,0x96,0xf4,0x0,0x65,0x16,0x39,0xd2,0xf8,0x57,0xe2,0x10,0x70,0xa5,0x9a,0xbe,0xd9,0x7,0x94,0x0,0xd9,0xf6,0x95,0x50,0x69,0x0 --https-pin=0x67,0xdc,0x4f,0x32,0xfa,0x10,0xe7,0xd0,0x1a,0x79,0xa0,0x73,0xaa,0xc,0x9e,0x2,0x12,0xec,0x2f,0xfc,0x3d,0x77,0x9e,0xa,0xa7,0xf9,0xc0,0xf0,0xe1,0xc2,0xc8,0x93 --https-pin=0x19,0x6,0xc6,0x12,0x4d,0xbb,0x43,0x85,0x78,0xd0,0xe,0x6,0x6d,0x50,0x54,0xc6,0xc3,0x7f,0xf,0xa6,0x2,0x8c,0x5,0x54,0x5e,0x9,0x94,0xed,0xda,0xec,0x86,0x29 --https-pin=0x1d,0x75,0xd0,0x83,0x1b,0x9e,0x8,0x85,0x39,0x4d,0x32,0xc7,0xa1,0xbf,0xdb,0x3d,0xbc,0x1c,0x28,0xe2,0xb0,0xe8,0x39,0x1f,0xb1,0x35,0x98,0x1d,0xbc,0x5b,0xa9,0x36 --annotation=host_int_account1_boot=6124474399 --annotation=machine_id=76a783b0-ac8b-557d-8da7-ebafd549c580 --annotation=platform=mac --annotation=platform_version=10.14.4 --handshake-fd=4 
546		558		0.0		[U501]		/Applications/Dropbox.app/Contents/MacOS/Dropbox -type:exit-monitor -method:collectupload -python-version:3.7.2 -session-token:a0ebfcb4-83ce-4c5d-8c85-da9076bd8062 -target-handle:546 -target-shutdown-event:4 -target-restart-event:6 -target-command-line:/Applications/Dropbox.app/Contents/MacOS/Dropbox 
1		562		0.0		[U501]		/System/Library/PrivateFrameworks/SafariShared.framework/Versions/A/XPCServices/com.apple.Safari.ImageDecoder.xpc/Contents/MacOS/com.apple.Safari.ImageDecoder 
1		563		0.0		[U501]		/System/Library/PrivateFrameworks/CommerceKit.framework/Versions/A/Resources/storeassetd 
1		565		0.0		root		/System/Library/CoreServices/iconservicesagent runAsRoot 
1		566		0.0		[U501]		/System/Library/PrivateFrameworks/CoreFollowUp.framework/Versions/A/Support/followupd 
330		569		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=10068864850595594525 --renderer-client-id=37 --no-v8-untrusted-code-mitigations --seatbelt-client=196 
1		570		0.0		[U501]		/System/Library/PrivateFrameworks/CommerceKit.framework/Versions/A/Resources/storedownloadd 
330		574		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=15763932476812583068 --renderer-client-id=35 --no-v8-untrusted-code-mitigations --seatbelt-client=204 
1		577		0.0		root		/System/Library/PrivateFrameworks/CoreSymbolication.framework/coresymbolicationd 
1		578		0.0		[U501]		/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/HIServices.framework/Versions/A/XPCServices/com.apple.hiservices-xpcservice.xpc/Contents/MacOS/com.apple.hiservices-xpcservice 
1		579		0.0		[U501]		/System/Library/CoreServices/ScopedBookmarkAgent 
1		584		0.0		[U501]		/System/Library/PrivateFrameworks/WeatherKit.framework/Versions/A/XPCServices/com.apple.WeatherKitService.xpc/Contents/MacOS/com.apple.WeatherKitService 
1		585		0.0		[U501]		/System/Library/CoreServices/LocationMenu.app/Contents/MacOS/LocationMenu 
1		586		0.0		[U501]		/System/Library/CoreServices/SocialPushAgent.app/Contents/MacOS/SocialPushAgent 
1		587		0.0		[U501]		/System/Library/CoreServices/Software Update.app/Contents/Resources/softwareupdate_notify_agent 
546		592		0.0		[U501]		/Applications/Dropbox.app/Contents/Frameworks/Tungsten.framework/Versions/A/Frameworks/Dropbox Web Helper.app/Contents/MacOS/Dropbox Web Helper --type=gpu-process --disable-breakpad --framework-dir-path=/Applications/Dropbox.app/Contents/Frameworks/Tungsten.framework/Versions/A/Frameworks/Chromium Embedded Framework.framework --log-file=/Users/[U501]/Library/Logs/Dropbox_debug.log --log-severity=warning --product-version=Tungsten/67.3396.76 --suffix-user-agent=ShangriLa/72.4.136 --lang=en-US --tungsten-schemes=dbx-local --gpu-preferences=KAAAAAAAAACAAAAAAQAAAAAAAAAAAGAAEAAAAAAAAAAAAAAAAAAAADgBAAAmAAAAMAEAAAAAAAA4AQAAAAAAAEABAAAAAAAASAEAAAAAAABQAQAAAAAAAFgBAAAAAAAAYAEAAAAAAABoAQAAAAAAAHABAAAAAAAAeAEAAAAAAACAAQAAAAAAAIgBAAAAAAAAkAEAAAAAAACYAQAAAAAAAKABAAAAAAAAqAEAAAAAAACwAQAAAAAAALgBAAAAAAAAwAEAAAAAAADIAQAAAAAAANABAAAAAAAA2AEAAAAAAADgAQAAAAAAAOgBAAAAAAAA8AEAAAAAAAD4AQAAAAAAAAACAAAAAAAACAIAAAAAAAAQAgAAAAAAABgCAAAAAAAAIAIAAAAAAAAoAgAAAAAAADACAAAAAAAAOAIAAAAAAABAAgAAAAAAAEgCAAAAAAAAUAIAAAAAAABYAgAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAALAAAAEAAAAAAAAAAAAAAADAAAABAAAAAAAAAAAAAAAA0AAAAQAAAAAAAAAAAAAAAPAAAAEAAAAAAAAAAAAAAAEAAAABAAAAAAAAAAAAAAABIAAAAQAAAAAAAAAAAAAAATAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAsAAAAQAAAAAAAAAAEAAAAMAAAAEAAAAAAAAAABAAAADQAAABAAAAAAAAAAAQAAAA8AAAAQAAAAAAAAAAEAAAAQAAAAEAAAAAAAAAABAAAAEgAAABAAAAAAAAAAAQAAABMAAAAQAAAAAAAAAAMAAAAFAAAAEAAAAAAAAAADAAAACwAAABAAAAAAAAAAAwAAAAwAAAAQAAAAAAAAAAMAAAANAAAAEAAAAAAAAAADAAAADwAAABAAAAAAAAAAAwAAABAAAAAQAAAAAAAAAAMAAAASAAAAEAAAAAAAAAADAAAAEwAAABAAAAAAAAAABQAAAAUAAAAQAAAAAAAAAAUAAAALAAAAEAAAAAAAAAAFAAAADQAAABAAAAAAAAAABQAAAA8AAAAQAAAAAAAAAAUAAAAQAAAAEAAAAAAAAAAFAAAAEgAAABAAAAAAAAAABQAAABMAAAAQAAAAAAAAAAYAAAAFAAAAEAAAAAAAAAAGAAAACwAAABAAAAAAAAAABgAAAA0AAAAQAAAAAAAAAAYAAAAPAAAAEAAAAAAAAAAGAAAAEAAAABAAAAAAAAAABgAAABIAAAAQAAAAAAAAAAYAAAATAAAA --framework-dir-path=/Applications/Dropbox.app/Contents/Frameworks/Tungsten.framework/Versions/A/Frameworks/Chromium Embedded Framework.framework --log-file=/Users/[U501]/Library/Logs/Dropbox_debug.log --log-severity=warning --product-version=Tungsten/67.3396.76 --suffix-user-agent=ShangriLa/72.4.136 --lang=en-US --tungsten-schemes=dbx-local --service-request-channel-token=0E7C20B0D4E92AB3F04AC2D9DC27E451 
546		594		0.0		[U501]		/Applications/Dropbox.app/Contents/Frameworks/Tungsten.framework/Versions/A/Frameworks/Dropbox Web Helper.app/Contents/MacOS/Dropbox Web Helper --type=renderer --disable-breakpad --service-pipe-token=D1C911F157FB392DE5CACBEB936714F5 --lang=en-US --framework-dir-path=/Applications/Dropbox.app/Contents/Frameworks/Tungsten.framework/Versions/A/Frameworks/Chromium Embedded Framework.framework --log-file=/Users/[U501]/Library/Logs/Dropbox_debug.log --log-severity=warning --product-version=Tungsten/67.3396.76 --suffix-user-agent=ShangriLa/72.4.136 --uncaught-exception-stack-size=16 --tungsten-schemes=dbx-local --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=D1C911F157FB392DE5CACBEB936714F5 --renderer-client-id=2 
330		595		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=2098971922515936804 --renderer-client-id=60 --no-v8-untrusted-code-mitigations --seatbelt-client=213 
330		596		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=5542221177975964316 --renderer-client-id=61 --no-v8-untrusted-code-mitigations --seatbelt-client=214 
330		597		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=17130035137892736886 --renderer-client-id=62 --no-v8-untrusted-code-mitigations --seatbelt-client=215 
1		600		0.0		[U501]		/System/Library/PrivateFrameworks/AssetCacheServices.framework/Versions/A/XPCServices/AssetCacheLocatorService.xpc/Contents/MacOS/AssetCacheLocatorService -a 
1		602		0.0		_assetcache		/usr/libexec/AssetCache/AssetCache 
1		604		0.0		_softwareupdate		/System/Library/CoreServices/Software Update.app/Contents/Resources/softwareupdated 
330		605		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=3761461509296415872 --renderer-client-id=65 --no-v8-untrusted-code-mitigations --seatbelt-client=221 
1		606		0.0		root		/System/Library/CoreServices/Software Update.app/Contents/Resources/suhelperd 
330		608		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=13645931795496788054 --renderer-client-id=66 --no-v8-untrusted-code-mitigations --seatbelt-client=224 
330		609		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=11474244941146703428 --renderer-client-id=41 --no-v8-untrusted-code-mitigations --seatbelt-client=241 
1		611		0.0		[U501]		/System/Library/Frameworks/ApplicationServices.framework/Frameworks/SpeechSynthesis.framework/Resources/com.apple.speech.speechsynthesisd 
1		612		0.0		[U501]		/System/Library/Frameworks/VideoToolbox.framework/Versions/A/XPCServices/VTDecoderXPCService.xpc/Contents/MacOS/VTDecoderXPCService 
1		613		0.0		[U501]		/System/Library/PrivateFrameworks/SafariSafeBrowsing.framework/com.apple.Safari.SafeBrowsing.Service 
330		618		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=15122362184088381243 --renderer-client-id=42 --no-v8-untrusted-code-mitigations --seatbelt-client=225 
1		623		0.0		[U501]		/System/Library/PrivateFrameworks/CommerceKit.framework/Versions/A/Resources/storelegacy 
1		634		0.0		[U501]		/usr/libexec/videosubscriptionsd 
1		640		0.0		[U501]		/Applications/Dropbox.app/Contents/PlugIns/garcon.appex/Contents/MacOS/garcon 
330		643		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=12218422310225958369 --renderer-client-id=43 --no-v8-untrusted-code-mitigations --seatbelt-client=269 
546		646		0.0		root		/Library/DropboxHelperTools/Dropbox_u501/dbfseventsd 
646		648		0.0		root		/Library/DropboxHelperTools/Dropbox_u501/dbfseventsd 
648		649		0.0		[U501]		/Library/DropboxHelperTools/Dropbox_u501/dbfseventsd 
1		653		0.0		[U501]		/Applications/Dropbox.app/Contents/XPCServices/DropboxFolderTagger.xpc/Contents/MacOS/DropboxFolderTagger 
1		659		0.0		root		/usr/libexec/dprivacyd 
1		663		0.0		[U501]		/System/Library/Image Capture/Support/icdd 
1		668		0.0		[U501]		/System/Library/PrivateFrameworks/PrintingPrivate.framework/Versions/A/PrintUITool 
330		689		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=15953663558052879647 --renderer-client-id=28 --no-v8-untrusted-code-mitigations --seatbelt-client=284 
330		690		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=16490741247449872599 --renderer-client-id=36 --no-v8-untrusted-code-mitigations --seatbelt-client=284 
1		700		0.0		root		/Library/Application Support/Malwarebytes/MBAM/Engine.bundle/Contents/PlugIns/SettingsDaemon.app/Contents/MacOS/SettingsDaemon 
1		702		0.0		[U501]		/System/Library/PrivateFrameworks/CoreSpeech.framework/corespeechd 
1		704		0.0		[U501]		/Library/Little Snitch/Little Snitch Helper.app/Contents/MacOS/Little Snitch Helper 
1		708		0.3		[U501]		/Library/Little Snitch/Little Snitch Agent.app/Contents/MacOS/Little Snitch Agent 
1		709		0.0		[U501]		/usr/libexec/dmd 
1		710		0.0		[U501]		/Applications/coconutBattery.app/Contents/Resources/coconutBattery Menu.app/Contents/MacOS/coconutBattery Menu 
1		711		0.0		[U501]		/System/Library/CoreServices/Siri.app/Contents/MacOS/Siri launchd 
1		712		0.0		[U501]		/Library/Application Support/Sony Application Launcher/SonyAutoLauncher.app/Contents/MacOS/SonyAutoLauncher 
1		713		0.0		[U501]		/Library/Application Support/WirelessAutoImport/WirelessImporterDaemon 
1		714		0.0		[U501]		/Library/Application Support/Malwarebytes/MBAM/Engine.bundle/Contents/PlugIns/FrontendAgent.app/Contents/MacOS/FrontendAgent 
1		715		0.0		[U501]		com.globaldelight.Boom3DHelper		
1		718		0.0		[U501]		/Users/[U501]/Library/Application Support/PortableSSD/SamsungPortableSSD.app/Contents/Resources/SamsungPortableSSDMon 
1		723		0.0		[U501]		/Library/Application Support/Paragon Software/com.paragon-software.ntfs.notification-agent.app/Contents/MacOS/NotificationAgent 
1		724		0.0		[U501]		/Library/Application Support/Adobe/AdobeGCClient/AGMService -mode=logon 
1		725		0.0		[U501]		/System/Library/CoreServices/AirPlayUIAgent.app/Contents/MacOS/AirPlayUIAgent --launchd 
1		727		0.0		[U501]		/usr/libexec/knowledge-agent 
1		728		0.0		[U501]		/System/Library/CoreServices/cloudpaird 
1		730		0.0		[U501]		/Applications/Utilities/Adobe Creative Cloud/ACC/Creative Cloud.app/Contents/MacOS/Creative Cloud --showwindow=false --onOSstartup=true 
1		731		0.0		[U501]		/System/Library/PrivateFrameworks/Noticeboard.framework/Versions/A/Resources/nbagent.app/Contents/MacOS/nbagent 
1		732		0.0		[U501]		/System/Library/CoreServices/diagnostics_agent 
1		734		0.0		[U501]		/usr/libexec/adprivacyd 
1		735		0.0		[U501]		/Applications/Amazon Music.app/Contents/MacOS/Amazon Music Helper 
330		743		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=5451473169537443307 --renderer-client-id=26 --no-v8-untrusted-code-mitigations --seatbelt-client=289 
1		778		0.0		[U501]		/usr/libexec/SafariCloudHistoryPushAgent 
1		782		2.1		[U501]		/Applications/Boom 3D.app/Contents/MacOS/Boom 3D -psn_0_286790 
1		784		0.0		_spotlight		/usr/libexec/trustd --agent 
1		785		0.0		[U501]		/usr/libexec/loginitemregisterd 
1		786		0.0		root		/usr/libexec/smd 
1		809		0.0		[U501]		/System/Library/Frameworks/AudioToolbox.framework/AudioComponentRegistrar 
1		813		0.0		[U501]		/System/Library/PrivateFrameworks/ContextKit.framework/Versions/A/XPCServices/ContextService.xpc/Contents/MacOS/ContextService 
1		814		0.0		[U501]		/usr/libexec/assertiond 
1		815		3.9		[U501]		/Library/Little Snitch/Little Snitch Network Monitor.app/Contents/MacOS/Little Snitch Network Monitor -psn_0_364633 
1		817		0.0		[U501]		/System/Library/Services/AppleSpell.service/Contents/MacOS/AppleSpell 
1		822		0.0		[U501]		/Library/Application Support/Adobe/Adobe Desktop Common/IPCBox/AdobeIPCBroker.app/Contents/MacOS/AdobeIPCBroker -launchedbyvulcan /Applications/Utilities/Adobe Creative Cloud/ACC/Creative Cloud.app/Contents/MacOS/Creative Cloud 
1		823		0.0		[U501]		/usr/libexec/keyboardservicesd 
1		824		0.0		[U501]		/Applications/NTFS for Mac.app/Contents/Resources/FSMenuApp.app/Contents/MacOS/FSMenuApp -psn_0_405603 
1		826		0.0		root		/usr/libexec/diskmanagementd 
730		830		0.0		[U501]		/Applications/Utilities/Adobe Creative Cloud/ACC/Creative Cloud.app/Contents/Frameworks/AdobeCrashReporter.framework/Versions/A/AdobeCRDaemon.app/Contents/MacOS/AdobeCRDaemon 730 Creative Cloud 4.8 /Applications/Utilities/Adobe Creative Cloud/ACC/Creative Cloud.app/Contents/Resources/CreativeCloud.icns /Applications/Utilities/Adobe Creative Cloud/ACC/Creative Cloud.app/Contents/Frameworks/AdobeCrashReporter.framework/Versions/A/Adobe Crash Reporter.app/Contents/MacOS/Adobe Crash Reporter 0 Creative Cloud 1 1 
730		833		0.0		[U501]		/Library/Application Support/Adobe/Adobe Desktop Common/HEX/Adobe CEF Helper.app/Contents/MacOS/Adobe CEF Helper --type=gpu-process --disable-features=AsyncWheelEvents,TouchpadAndWheelScrollLatching --log-file=/Users/[U501]/Library/Logs/CreativeCloud/ACC/CEF.log --log-severity=warning --user-agent=Mozilla/5.0 (Macintosh) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.2987.98 Safari/537.36 CreativeCloud/4.8.1.435 --lang=en-US --gpu-preferences=KAAAAAAAAAAAAQAAAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAAOAAAAAbAAAA2AAAAAAAAADgAAAAAAAAAOgAAAAAAAAA8AAAAAAAAAD4AAAAAAAAAAABAAAAAAAACAEAAAAAAAAQAQAAAAAAABgBAAAAAAAAIAEAAAAAAAAoAQAAAAAAADABAAAAAAAAOAEAAAAAAABAAQAAAAAAAEgBAAAAAAAAUAEAAAAAAABYAQAAAAAAAGABAAAAAAAAaAEAAAAAAABwAQAAAAAAAHgBAAAAAAAAgAEAAAAAAACIAQAAAAAAAJABAAAAAAAAmAEAAAAAAACgAQAAAAAAAKgBAAAAAAAAEAAAAAAAAAAAAAAABQAAABAAAAAAAAAAAAAAAAsAAAAQAAAAAAAAAAAAAAAMAAAAEAAAAAAAAAAAAAAADgAAABAAAAAAAAAAAAAAAA8AAAAQAAAAAAAAAAAAAAARAAAAEAAAAAAAAAAAAAAAEgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAALAAAAEAAAAAAAAAABAAAADAAAABAAAAAAAAAAAQAAAA4AAAAQAAAAAAAAAAEAAAAPAAAAEAAAAAAAAAABAAAAEQAAABAAAAAAAAAAAQAAABIAAAAQAAAAAAAAAAMAAAALAAAAEAAAAAAAAAADAAAADAAAABAAAAAAAAAAAwAAAA4AAAAQAAAAAAAAAAUAAAAFAAAAEAAAAAAAAAAFAAAADgAAABAAAAAAAAAABQAAAA8AAAAQAAAAAAAAAAUAAAARAAAAEAAAAAAAAAAFAAAAEgAAABAAAAAAAAAABgAAAAUAAAAQAAAAAAAAAAYAAAAOAAAAEAAAAAAAAAAGAAAADwAAABAAAAAAAAAABgAAABEAAAAQAAAAAAAAAAYAAAASAAAA --gpu-vendor-id=0x8086 --gpu-device-id=0x0d26 --gpu-driver-vendor --gpu-driver-version --gpu-driver-date --gpu-active-vendor-id=0x8086 --gpu-active-device-id=0x0d26 --log-file=/Users/[U501]/Library/Logs/CreativeCloud/ACC/CEF.log --log-severity=warning --user-agent=Mozilla/5.0 (Macintosh) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.2987.98 Safari/537.36 CreativeCloud/4.8.1.435 --lang=en-US --service-request-channel-token=6DCFEDC00AB98F223070E1A21CE41328 
1		835		0.0		[U501]		/System/Library/Frameworks/VideoToolbox.framework/Versions/A/XPCServices/VTDecoderXPCService.xpc/Contents/MacOS/VTDecoderXPCService 
730		836		0.0		[U501]		/Library/Application Support/Adobe/Adobe Desktop Common/HEX/Adobe CEF Helper.app/Contents/MacOS/Adobe CEF Helper --type=renderer --disable-features=AsyncWheelEvents,TouchpadAndWheelScrollLatching --service-pipe-token=2EFBA9EEBEE2B96F80FD8BCAD3FD9D0F --lang=en-US --log-file=/Users/[U501]/Library/Logs/CreativeCloud/ACC/CEF.log --log-severity=warning --user-agent=Mozilla/5.0 (Macintosh) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.2987.98 Safari/537.36 CreativeCloud/4.8.1.435 --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=2EFBA9EEBEE2B96F80FD8BCAD3FD9D0F --renderer-client-id=3 
730		837		0.0		[U501]		/Library/Application Support/Adobe/Adobe Desktop Common/ADS/Adobe Desktop Service.app/Contents/MacOS/Adobe Desktop Service --onOSstartup=true --showwindow=false --waitForRegistration=true 
837		839		0.0		[U501]		/Library/Application Support/Adobe/Adobe Desktop Common/ADS/Adobe Desktop Service.app/Contents/Frameworks/AdobeCrashReporter.framework/Versions/A/AdobeCRDaemon.app/Contents/MacOS/AdobeCRDaemon 837 Adobe Desktop Service 4.8 /Library/Application Support/Adobe/Adobe Desktop Common/ADS/Adobe Desktop Service.app/Contents/Resources/AdobeDesktopService.icns /Library/Application Support/Adobe/Adobe Desktop Common/ADS/Adobe Desktop Service.app/Contents/Frameworks/AdobeCrashReporter.framework/Versions/A/Adobe Crash Reporter.app/Contents/MacOS/Adobe Crash Reporter 0 Adobe Desktop Service 1 1 
1		845		0.0		[U501]		/Applications/Utilities/Adobe Sync/CoreSync/Core Sync.app/Contents/MacOS/Core Sync 
1		846		0.0		[U501]		/Applications/Utilities/Adobe Creative Cloud Experience/CCXProcess/CCXProcess.app/Contents/MacOS/../libs/Adobe CCXProcess.app /Applications/Utilities/Adobe Creative Cloud Experience/CCXProcess/CCXProcess.app/Contents/MacOS/../js/main.js 
1		847		0.0		[U501]		/Applications/Utilities/Adobe Sync/CoreSync/Core Sync.app/Contents/PlugIns/ACCFinderSync.appex/Contents/MacOS/ACCFinderSync 
845		848		0.1		[U501]		/Applications/Utilities/Adobe Sync/CoreSync/Core Sync.app/Contents/Frameworks/AdobeCrashReporter.framework/Versions/A/AdobeCRDaemon.app/Contents/MacOS/AdobeCRDaemon 845 Core Sync 4.2.3.4 /Applications/Utilities/Adobe Sync/CoreSync/Core Sync.app/Contents/Resources/CreativeCloudIcons.icns /Applications/Utilities/Adobe Sync/CoreSync/Core Sync.app/Contents/Frameworks/AdobeCrashReporter.framework/Versions/A/Adobe Crash Reporter.app/Contents/MacOS/Adobe Crash Reporter 0 Adobe Sync 
1		861		0.0		[U501]		/System/Library/PrivateFrameworks/CoreSuggestions.framework/Versions/A/Support/reversetemplated 
1		864		0.0		root		/Library/PrivilegedHelperTools/com.adobe.acc.installer.v2 
1		869		0.0		[U501]		/System/Library/PrivateFrameworks/CacheDelete.framework/deleted 
1		871		0.0		[U501]		/System/Library/PrivateFrameworks/CommerceKit.framework/Resources/LaterAgent.app/Contents/MacOS/LaterAgent 
864		873		0.0		root		/Library/Application Support/Adobe/Adobe Desktop Common/ElevationManager/Adobe Installer --pipename=25C00F45-7463-44C3-8959-EB8A0CCB90F5 
1		876		0.0		[U501]		/Library/Application Support/Adobe/Creative Cloud Libraries/CCLibrary.app/Contents/MacOS/../libs/node /Library/Application Support/Adobe/Creative Cloud Libraries/CCLibrary.app/Contents/MacOS/../js/server.js 
1		884		0.0		[U501]		/System/Library/Frameworks/ColorSync.framework/Support/colorsync.useragent 
72		886		0.0		root		/usr/sbin/systemstats --logger-helper /private/var/db/systemstats 
1		887		0.0		_spotlight		/usr/sbin/distnoted agent 
1		888		0.0		root		/System/Library/Frameworks/CoreMediaIO.framework/Versions/A/XPCServices/com.apple.cmio.registerassistantservice.xpc/Contents/MacOS/com.apple.cmio.registerassistantservice 
1		889		0.0		root		/System/Library/PrivateFrameworks/FindMyMac.framework/Resources/FindMyMacd 
1		890		0.0		[U501]		/System/Library/PrivateFrameworks/AssistantServices.framework/Versions/A/XPCServices/media-indexer.xpc/Contents/MacOS/media-indexer 
1		891		0.0		_cmiodalassistants		/Library/CoreMediaIO/Plug-Ins/DAL/AppleCamera.plugin/Contents/Resources/AppleCameraAssistant 
1		892		0.0		_applepay		/usr/libexec/nfcd 
1		900		0.0		root		/System/Library/PrivateFrameworks/AuthKit.framework/Versions/A/Support/akd 
1		902		0.0		[U501]		/System/Library/Frameworks/iTunesLibrary.framework/Versions/A/XPCServices/com.apple.iTunesLibraryService.xpc/Contents/MacOS/com.apple.iTunesLibraryService 
1		903		0.0		[U501]		/usr/libexec/findmydevice-user-agent 
1		905		0.0		root		/usr/libexec/dmd 
1		906		0.0		[U501]		/System/Library/Frameworks/Metal.framework/Versions/A/XPCServices/MTLCompilerService.xpc/Contents/MacOS/MTLCompilerService 
1		907		0.0		[U501]		/System/Library/Frameworks/Metal.framework/Versions/A/XPCServices/MTLCompilerService.xpc/Contents/MacOS/MTLCompilerService 
1		911		0.0		[U501]		/System/Library/CoreServices/Siri.app/Contents/XPCServices/SiriNCService.xpc/Contents/MacOS/SiriNCService 
1		914		0.0		[U501]		/System/Library/Frameworks/Metal.framework/Versions/A/XPCServices/MTLCompilerService.xpc/Contents/MacOS/MTLCompilerService 
1		915		0.0		[U501]		/System/Library/Frameworks/Metal.framework/Versions/A/XPCServices/MTLCompilerService.xpc/Contents/MacOS/MTLCompilerService 
1		916		0.0		[U501]		/System/Library/Frameworks/AudioToolbox.framework/XPCServices/com.apple.audio.SandboxHelper.xpc/Contents/MacOS/com.apple.audio.SandboxHelper 
1		986		0.0		[U501]		/System/Library/PrivateFrameworks/AssistantServices.framework/Versions/A/Support/assistant_service 
1		987		0.0		[U501]		/System/Library/Frameworks/AudioToolbox.framework/XPCServices/com.apple.audio.SandboxHelper.xpc/Contents/MacOS/com.apple.audio.SandboxHelper 
1		1117		0.0		[U501]		/System/Library/CoreServices/cloudphotosd.app/Contents/MacOS/cloudphotosd 
1		1122		0.0		[U501]		/System/Library/PrivateFrameworks/CloudPhotoServices.framework/Versions/A/Frameworks/CloudPhotosConfigurationXPC.framework/Versions/A/XPCServices/com.apple.CloudPhotosConfiguration.xpc/Contents/MacOS/com.apple.CloudPhotosConfiguration 
1		1128		0.0		[U501]		/System/Library/PrivateFrameworks/PhotoLibraryPrivate.framework/Versions/A/Support/photolibraryd 
1		1129		0.0		[U501]		/System/Library/PrivateFrameworks/PhotoLibraryPrivate.framework/Versions/A/Frameworks/PhotoLibraryServices.framework/Versions/A/XPCServices/com.apple.photomoments.xpc/Contents/MacOS/com.apple.photomoments 
1		1130		0.0		[U501]		/System/Library/PrivateFrameworks/PhotoLibrary.framework/Versions/A/XPCServices/com.apple.PhotoIngestService.xpc/Contents/MacOS/com.apple.PhotoIngestService 
1		1135		0.0		[U501]		/System/Library/Frameworks/ApplicationServices.framework/Frameworks/ATS.framework/Support/atsd
         

Alt 15.05.2019, 10:46   #7
ThomasHoll
 
infizierte Doc Datei mit Macros am Macbook geöffnet - Standard

infizierte Doc Datei mit Macros am Macbook geöffnet



Code:
ATTFilter
1		1196		0.0		[U501]		/System/Library/PrivateFrameworks/SafariShared.framework/Versions/A/XPCServices/com.apple.Safari.SearchHelper.xpc/Contents/MacOS/com.apple.Safari.SearchHelper 
1		1225		0.0		[U501]		/System/Library/Frameworks/MediaAccessibility.framework/Versions/A/XPCServices/com.apple.accessibility.mediaaccessibilityd.xpc/Contents/MacOS/com.apple.accessibility.mediaaccessibilityd 
1		1273		0.0		[U501]		/System/Library/Frameworks/DiskArbitration.framework/Versions/A/Support/DiskArbitrationAgent 
1		1275		0.0		[U501]		/usr/libexec/USBAgent 
1		1276		0.0		[U501]		/System/Library/PrivateFrameworks/KerberosHelper/Helpers/DiskUnmountWatcher 
1		1348		0.0		[U501]		/System/Library/PrivateFrameworks/AppStoreDaemon.framework/Support/appstoreagent 
1		1420		0.0		[U501]		/System/Library/Frameworks/Metal.framework/Versions/A/XPCServices/MTLCompilerService.xpc/Contents/MacOS/MTLCompilerService 
1		1426		0.0		[U501]		/System/Library/Frameworks/Metal.framework/Versions/A/XPCServices/MTLCompilerService.xpc/Contents/MacOS/MTLCompilerService 
1		1432		0.0		[U501]		/System/Library/Frameworks/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.WebContent.xpc/Contents/MacOS/com.apple.WebKit.WebContent 
1		1450		0.0		[U501]		/System/Library/Frameworks/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.WebContent.xpc/Contents/MacOS/com.apple.WebKit.WebContent 
1		1469		0.0		[U501]		/Applications/Dropbox.app/Contents/PlugIns/garcon.appex/Contents/MacOS/garcon 
1		1472		0.0		root		/System/Library/PrivateFrameworks/PackageKit.framework/Resources/installd 
1		1474		0.0		root		/System/Library/PrivateFrameworks/PackageKit.framework/Resources/system_installd 
1		1475		0.0		[U501]		/System/Library/PrivateFrameworks/QuickLookThumbnailing.framework/Support/com.apple.quicklook.ThumbnailsAgent 
1		1476		0.0		root		/usr/bin/sysdiagnose 
1		1482		0.0		[U501]		/System/Library/Frameworks/MediaLibrary.framework/Versions/A/XPCServices/com.apple.MediaLibraryService.xpc/Contents/MacOS/com.apple.MediaLibraryService 
1		1485		0.0		[U501]		/System/Library/Frameworks/SafariServices.framework/Versions/A/XPCServices/com.apple.SafariServices.xpc/Contents/MacOS/com.apple.SafariServices 
1		1511		0.0		root		/Library/PrivilegedHelperTools/com.microsoft.autoupdate.helper 
837		1547		0.0		[U501]		(ExManBridgeTalkC)		
837		1549		0.0		[U501]		(ExManBridgeTalkC)		
330		1602		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=10870596164761850037 --renderer-client-id=24 --no-v8-untrusted-code-mitigations --seatbelt-client=205 
330		1606		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=8477804495214831572 --renderer-client-id=20 --no-v8-untrusted-code-mitigations --seatbelt-client=223 
330		1612		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=644390335527949192 --renderer-client-id=17 --no-v8-untrusted-code-mitigations --seatbelt-client=237 
330		1622		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=1058496347112941799 --renderer-client-id=136 --no-v8-untrusted-code-mitigations --seatbelt-client=211 
330		1633		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=2918331384487607570 --renderer-client-id=139 --no-v8-untrusted-code-mitigations --seatbelt-client=211 
1		1645		0.0		[U501]		/System/Library/Frameworks/Quartz.framework/Versions/A/Frameworks/QuickLookUI.framework/Versions/A/XPCServices/QuickLookUIService.xpc/Contents/MacOS/QuickLookUIService 
330		1678		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=16339510698954909630 --renderer-client-id=142 --no-v8-untrusted-code-mitigations --seatbelt-client=237 
330		1679		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=835508374546431926 --renderer-client-id=143 --no-v8-untrusted-code-mitigations --seatbelt-client=242 
330		1682		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=6925700165038807443 --renderer-client-id=145 --no-v8-untrusted-code-mitigations --seatbelt-client=211 
330		1685		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=4539322205584020742 --renderer-client-id=148 --no-v8-untrusted-code-mitigations --seatbelt-client=241 
330		1686		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=4873412109716419052 --renderer-client-id=149 --no-v8-untrusted-code-mitigations --seatbelt-client=242 
330		1687		1.4		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=3790301654017389234 --renderer-client-id=150 --no-v8-untrusted-code-mitigations --seatbelt-client=249 
330		1693		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=8253506305864545458 --renderer-client-id=156 --no-v8-untrusted-code-mitigations --seatbelt-client=262 
330		1694		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=16278124173912542932 --renderer-client-id=157 --no-v8-untrusted-code-mitigations --seatbelt-client=284 
330		1716		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=2813192593230255669 --renderer-client-id=169 --no-v8-untrusted-code-mitigations --seatbelt-client=232 
1		1807		0.0		root		/System/Library/PrivateFrameworks/CommerceKit.framework/Versions/A/Resources/storeinstalld 
1		1808		0.0		[U501]		/System/Library/PrivateFrameworks/CommerceKit.framework/Versions/A/XPCServices/com.apple.CommerceKit.TransactionService.xpc/Contents/MacOS/com.apple.CommerceKit.TransactionService 
1		1809		0.0		[U501]		/System/Library/PrivateFrameworks/UsageTracking.framework/Versions/A/UsageTrackingAgent 
1		1810		0.0		[U501]		/System/Library/PrivateFrameworks/PhotoAnalysis.framework/Versions/A/Support/photoanalysisd 
1		2654		0.0		[U501]		/System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdwrite 
1		2659		0.0		[U501]		/Applications/Dropbox.app/Contents/XPCServices/DropboxNotificationService.xpc/Contents/MacOS/DropboxNotificationService 
1		2674		0.0		_fpsd		/System/Library/PrivateFrameworks/CoreFP.framework/Versions/A/fpsd 
1		2677		0.0		_locationd		/usr/sbin/distnoted agent 
1		2703		0.0		[U501]		/System/Library/Frameworks/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.Networking.xpc/Contents/MacOS/com.apple.WebKit.Networking 
1		2712		0.0		[U501]		/System/Library/PrivateFrameworks/CommerceKit.framework/Versions/A/XPCServices/com.apple.CommerceKit.TransactionService.xpc/Contents/MacOS/com.apple.CommerceKit.TransactionService 
1		2713		0.0		[U501]		/System/Library/Frameworks/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.WebContent.xpc/Contents/MacOS/com.apple.WebKit.WebContent 
1		2714		0.0		root		/usr/libexec/rtcreportingd 
1		6590		0.0		[U501]		/usr/libexec/studentd 
1		6659		0.6		[U501]		/System/Library/Frameworks/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.WebContent.xpc/Contents/MacOS/com.apple.WebKit.WebContent 
1		6701		0.0		[U501]		/System/Library/Frameworks/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.WebContent.xpc/Contents/MacOS/com.apple.WebKit.WebContent 
330		6797		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=17667316111795882299 --renderer-client-id=229 --no-v8-untrusted-code-mitigations --seatbelt-client=221 
1		6883		0.0		[U501]		/System/Library/Frameworks/Metal.framework/Versions/A/XPCServices/MTLCompilerService.xpc/Contents/MacOS/MTLCompilerService 
1		6884		0.0		[U501]		/System/Library/Frameworks/Metal.framework/Versions/A/XPCServices/MTLCompilerService.xpc/Contents/MacOS/MTLCompilerService 
1		6895		0.0		[U501]		/Applications/Adobe Acrobat Reader DC.app/Contents/Helpers/AdobeResourceSynchronizer.app/Contents/MacOS/AdobeResourceSynchronizer -c 
1		6915		0.0		[U501]		/System/Library/Frameworks/iTunesLibrary.framework/Versions/A/XPCServices/com.apple.iTunesLibraryService.xpc/Contents/MacOS/com.apple.iTunesLibraryService 
1		6916		0.0		[U501]		/usr/libexec/siriknowledged 
1		6917		0.0		[U501]		/System/Library/PrivateFrameworks/FMClient.framework/Versions/A/XPCServices/FMIPClientXPCService.xpc/Contents/MacOS/FMIPClientXPCService 
1		6924		0.0		root		/System/Library/PrivateFrameworks/DiskImages.framework/Resources/hdiejectd 
1		6926		0.0		root		/System/Library/PrivateFrameworks/DiskImages.framework/Resources/diskimages-helper -uuid AB1E1283-511A-49A5-9978-B6785A9D1A77 -post-exec 4 
1		6961		0.0		[U501]		/usr/libexec/SafariPlugInUpdateNotifier 
1		6983		0.0		[U501]		/System/Library/PrivateFrameworks/IMDPersistence.framework/IMAutomaticHistoryDeletionAgent.app/Contents/MacOS/IMAutomaticHistoryDeletionAgent 
1		7059		0.0		[U501]		/System/Library/Frameworks/ApplicationServices.framework/Frameworks/PrintCore.framework/Versions/A/printtool agent 
330		7395		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=4668685930255122977 --renderer-client-id=258 --no-v8-untrusted-code-mitigations --seatbelt-client=238 
1		7412		0.0		[U501]		/System/Library/Frameworks/Metal.framework/Versions/A/XPCServices/MTLCompilerService.xpc/Contents/MacOS/MTLCompilerService 
1		7413		0.0		[U501]		/System/Library/Frameworks/Metal.framework/Versions/A/XPCServices/MTLCompilerService.xpc/Contents/MacOS/MTLCompilerService 
1		7423		0.0		[U501]		/Applications/Dropbox.app/Contents/PlugIns/garcon.appex/Contents/MacOS/garcon 
1		7425		0.0		[U501]		/System/Library/Frameworks/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.Networking.xpc/Contents/MacOS/com.apple.WebKit.Networking 
1		7426		0.0		[U501]		/System/Library/Frameworks/SafariServices.framework/Versions/A/XPCServices/com.apple.SafariServices.xpc/Contents/MacOS/com.apple.SafariServices 
1		7584		0.0		root		/System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Support/mds 
1		7585		0.1		root		/System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mds_stores 
1		7588		0.0		[U501]		/System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/corespotlightd 
1		8043		0.0		[U501]		/System/Library/CoreServices/EscrowSecurityAlert.app/Contents/MacOS/EscrowSecurityAlert 
1		8047		0.0		[U501]		/System/Library/PrivateFrameworks/CloudServices.framework/Versions/A/XPCServices/com.apple.sbd.xpc/Contents/MacOS/com.apple.sbd 
1		8056		0.0		[U501]		/System/Library/PrivateFrameworks/CoreCDP.framework/Versions/A/Resources/cdpd 
1		8261		0.0		[U501]		/System/Library/CoreServices/OSDUIHelper.app/Contents/MacOS/OSDUIHelper 
1		8277		0.0		root		/System/Library/PrivateFrameworks/DiskImages.framework/Resources/diskimages-helper -uuid B83D61A9-065F-446A-A98F-BAE8CF63C783 -post-exec 4 
1		8448		0.0		[U501]		/System/Library/CoreServices/mapspushd 
1		8487		0.0		_netbios		/usr/sbin/netbiosd 
1		8499		0.0		root		/usr/libexec/mobileactivationd 
1		8510		0.0		[U501]		/System/Library/PrivateFrameworks/PhotoLibraryPrivate.framework/Versions/A/Frameworks/PhotoLibraryServices.framework/Versions/A/XPCServices/com.apple.photomodel.xpc/Contents/MacOS/com.apple.photomodel 
1		8547		0.0		_spotlight		/System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdworker -s mdworker-sizing -c MDSSizingWorker -m com.apple.mdworker.sizing 
1		8552		0.0		[U501]		/System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdworker -s mdworker-sizing -c MDSSizingWorker -m com.apple.mdworker.sizing 
330		8724		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=4136258687335798029 --renderer-client-id=338 --no-v8-untrusted-code-mitigations --seatbelt-client=258 
1		10276		0.0		[U501]		/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ATS.framework/Versions/A/Support/fontworker 
1		10664		0.0		root		/usr/libexec/periodic-wrapper daily 
1		10733		0.0		[U501]		/usr/libexec/silhouette 
1		10847		0.0		_atsserver		/System/Library/Frameworks/ApplicationServices.framework/Frameworks/ATS.framework/Support/fontd 
1		10850		0.0		_softwareupdate		/usr/sbin/cfprefsd agent 
1		10851		0.0		_softwareupdate		/usr/sbin/distnoted agent 
1		10860		0.0		_softwareupdate		/System/Library/CoreServices/Software Update.app/Contents/Resources/softwareupdate_download_service 
1		10871		0.0		_spotlight		/System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdworker_shared -s mdworker -c MDSImporterWorker -m com.apple.mdworker.shared 
1		10916		0.0		[U501]		/System/Library/Frameworks/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.WebContent.xpc/Contents/MacOS/com.apple.WebKit.WebContent 
1		10922		0.0		[U501]		/System/Library/Frameworks/Metal.framework/Versions/A/XPCServices/MTLCompilerService.xpc/Contents/MacOS/MTLCompilerService 
1		10923		0.0		[U501]		/System/Library/Frameworks/Metal.framework/Versions/A/XPCServices/MTLCompilerService.xpc/Contents/MacOS/MTLCompilerService 
1		10935		0.0		[U501]		/System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdworker_shared -s mdworker -c MDSImporterWorker -m com.apple.mdworker.shared 
1		10937		0.0		[U501]		/System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdworker_shared -s mdworker -c MDSImporterWorker -m com.apple.mdworker.shared 
1		10938		0.0		[U501]		/System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdworker_shared -s mdworker -c MDSImporterWorker -m com.apple.mdworker.shared 
1		10939		0.0		[U501]		/System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdworker_shared -s mdworker -c MDSImporterWorker -m com.apple.mdworker.shared 
330		10958		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=5604816508265356035 --renderer-client-id=415 --no-v8-untrusted-code-mitigations --seatbelt-client=280 
330		10966		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=3531969290702815761 --renderer-client-id=423 --no-v8-untrusted-code-mitigations --seatbelt-client=223 
330		10967		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=7104864757399146251 --renderer-client-id=424 --no-v8-untrusted-code-mitigations --seatbelt-client=223 
330		10968		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=9253767776538248546 --renderer-client-id=425 --no-v8-untrusted-code-mitigations --seatbelt-client=231 
1		10979		0.0		[U501]		/System/Library/Frameworks/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.WebContent.xpc/Contents/MacOS/com.apple.WebKit.WebContent 
330		10991		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=3667729190211897255 --renderer-client-id=434 --no-v8-untrusted-code-mitigations --seatbelt-client=278 
330		10994		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=15434695684064726202 --renderer-client-id=437 --no-v8-untrusted-code-mitigations --seatbelt-client=264 
330		10995		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=8979614720138692420 --renderer-client-id=438 --no-v8-untrusted-code-mitigations --seatbelt-client=235 
1		11003		0.0		[U501]		/Applications/Microsoft Word.app/Contents/MacOS/Microsoft Word 
1		11006		0.0		[U501]		/Library/Application Support/Microsoft/MAU2.0/Microsoft AutoUpdate.app/Contents/MacOS/Microsoft AU Daemon.app/Contents/MacOS/Microsoft AU Daemon -psn_0_1864135 
1		11023		0.0		[U501]		/System/Library/PrivateFrameworks/RemoteViewServices.framework/XPCServices/com.apple.security.pboxd.xpc/Contents/MacOS/com.apple.security.pboxd 
1		11030		0.0		[U501]		/System/Library/Frameworks/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.WebContent.xpc/Contents/MacOS/com.apple.WebKit.WebContent 
1		11033		0.0		_windowserver		/System/Library/Frameworks/Metal.framework/Versions/A/XPCServices/MTLCompilerService.xpc/Contents/MacOS/MTLCompilerService 
1		11039		0.0		[U501]		/System/Library/Frameworks/Metal.framework/Versions/A/XPCServices/MTLCompilerService.xpc/Contents/MacOS/MTLCompilerService 
1		11040		0.0		[U501]		/System/Library/Frameworks/Metal.framework/Versions/A/XPCServices/MTLCompilerService.xpc/Contents/MacOS/MTLCompilerService 
1		11090		0.0		[U501]		/System/Library/Frameworks/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.WebContent.xpc/Contents/MacOS/com.apple.WebKit.WebContent 
1		11100		0.0		[U501]		/System/Library/Frameworks/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.WebContent.xpc/Contents/MacOS/com.apple.WebKit.WebContent 
1		11101		0.0		[U501]		/System/Library/Frameworks/AudioToolbox.framework/XPCServices/com.apple.audio.SandboxHelper.xpc/Contents/MacOS/com.apple.audio.SandboxHelper 
1		11102		0.6		[U501]		/System/Library/Frameworks/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.WebContent.xpc/Contents/MacOS/com.apple.WebKit.WebContent 
1		11103		0.0		[U501]		/System/Library/Frameworks/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.WebContent.xpc/Contents/MacOS/com.apple.WebKit.WebContent 
330		11118		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=381989176757604910 --renderer-client-id=458 --no-v8-untrusted-code-mitigations --seatbelt-client=244 
330		11126		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=18184735050200378170 --renderer-client-id=463 --no-v8-untrusted-code-mitigations --seatbelt-client=247 
330		11127		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=7625278876042890074 --renderer-client-id=464 --no-v8-untrusted-code-mitigations --seatbelt-client=247 
330		11128		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=8465329425275661825 --renderer-client-id=465 --no-v8-untrusted-code-mitigations --seatbelt-client=257 
330		11131		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=7461943623403382604 --renderer-client-id=468 --no-v8-untrusted-code-mitigations --seatbelt-client=258 
1		11135		0.0		[U501]		/System/Library/PrivateFrameworks/AOSKit.framework/Versions/A/XPCServices/com.apple.iCloudHelper.xpc/Contents/MacOS/com.apple.iCloudHelper 
1		11136		0.0		[U501]		/Applications/EtreCheck.app/Contents/MacOS/EtreCheck 
1		15039		0.0		[U501]		/System/Library/CoreServices/CoreServicesUIAgent.app/Contents/MacOS/CoreServicesUIAgent 
1		15041		0.0		[U501]		/System/Library/Frameworks/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.WebContent.xpc/Contents/MacOS/com.apple.WebKit.WebContent 
1		15042		0.0		[U501]		/System/Library/Frameworks/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.Networking.xpc/Contents/MacOS/com.apple.WebKit.Networking 
1		15053		0.0		[U501]		/System/Library/Frameworks/Metal.framework/Versions/A/XPCServices/MTLCompilerService.xpc/Contents/MacOS/MTLCompilerService 
1		15054		0.0		[U501]		/System/Library/Frameworks/Metal.framework/Versions/A/XPCServices/MTLCompilerService.xpc/Contents/MacOS/MTLCompilerService 
1		15055		0.0		[U501]		/System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdworker_shared -s mdworker -c MDSImporterWorker -m com.apple.mdworker.shared 
1		15056		0.0		_spotlight		/System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdworker_shared -s mdworker -c MDSImporterWorker -m com.apple.mdworker.shared 
1		15059		0.0		[U501]		/System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdworker_shared -s mdworker -c MDSImporterWorker -m com.apple.mdworker.shared 
1		15075		0.0		_spotlight		/System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdworker_shared -s mdworker -c MDSImporterWorker -m com.apple.mdworker.shared 
1		15082		0.0		[U501]		/System/Library/Frameworks/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.WebContent.xpc/Contents/MacOS/com.apple.WebKit.WebContent 
330		15088		0.0		[U501]		/Applications/Google Chrome.app/Contents/Versions/74.0.3729.131/Google Chrome Helper.app/Contents/MacOS/Google Chrome Helper --type=renderer --field-trial-handle=1718379636,3148097515895504315,7342861478777826764,131072 --lang=de --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --num-raster-threads=4 --enable-zero-copy --enable-gpu-memory-buffer-compositor-resources --enable-main-frame-before-activation --service-request-channel-token=16480628057907677578 --renderer-client-id=476 --no-v8-untrusted-code-mitigations --seatbelt-client=269 
1		15093		0.0		[U501]		/System/Library/PrivateFrameworks/XprotectFramework.framework/Versions/A/XPCServices/XprotectService.xpc/Contents/MacOS/XprotectService 
1		15095		0.0		[U501]		/System/Library/PrivateFrameworks/DiskImages.framework/Resources/diskimages-helper -uuid 2ACA3FBC-9395-4B16-A008-E9389B99638F -post-exec 4 
1		15111		0.0		[U501]		/System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdworker_shared -s mdworker -c MDSImporterWorker -m com.apple.mdworker.shared 
1		15112		6.6		[U501]		/Applications/DetectX Swift.app/Contents/MacOS/DetectX Swift -psn_0_2052597 
1		15449		0.0		[U501]		/System/Library/Frameworks/Metal.framework/Versions/A/XPCServices/MTLCompilerService.xpc/Contents/MacOS/MTLCompilerService 
1		15450		0.0		[U501]		/System/Library/Frameworks/Metal.framework/Versions/A/XPCServices/MTLCompilerService.xpc/Contents/MacOS/MTLCompilerService 
1		15461		0.0		[U501]		/System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdworker_shared -s mdworker -c MDSImporterWorker -m com.apple.mdworker.shared 
1		15462		0.0		[U501]		/System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdworker_shared -s mdworker -c MDSImporterWorker -m com.apple.mdworker.shared 
1		15463		0.0		[U501]		/System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdworker_shared -s mdworker -c MDSImporterWorker -m com.apple.mdworker.shared 
1		15465		0.0		[U501]		/System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdworker_shared -s mdworker -c MDSImporterWorker -m com.apple.mdworker.shared 
1		15475		0.0		[U501]		/System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdworker_shared -s mdworker -c MDSImporterWorker -m com.apple.mdworker.shared 
1		15476		0.0		[U501]		/System/Library/Frameworks/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.WebContent.xpc/Contents/MacOS/com.apple.WebKit.WebContent 
1		15477		0.0		_spotlight		/System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdworker_shared -s mdworker -c MDSImporterWorker -m com.apple.mdworker.shared 
1		15478		0.0		_spotlight		/System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdworker_shared -s mdworker -c MDSImporterWorker -m com.apple.mdworker.shared 
1		15479		0.0		[U501]		/System/Library/Frameworks/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.WebContent.xpc/Contents/MacOS/com.apple.WebKit.WebContent 
1		15736		0.0		_spotlight		/System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdworker_shared -s mdworker -c MDSImporterWorker -m com.apple.mdworker.shared 
1		15739		0.0		[U501]		/System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdworker_shared -s mdworker -c MDSImporterWorker -m com.apple.mdworker.shared 
1		15741		0.0		root		automountd		
1		15745		0.0		[U501]		/System/Library/Frameworks/QuickLook.framework/Resources/quicklookd.app/Contents/MacOS/quicklookd 
1		15748		0.0		[U501]		/System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdworker_shared -s mdworker -c MDSImporterWorker -m com.apple.mdworker.shared 
1		15749		0.0		[U501]		/System/Library/Frameworks/QuickLook.framework/Versions/A/Resources/quicklookd.app/Contents/XPCServices/QuickLookSatellite.xpc/Contents/MacOS/QuickLookSatellite 
1		15750		0.0		[U501]		/System/Library/Frameworks/Quartz.framework/Versions/A/Frameworks/QuickLookUI.framework/Versions/A/XPCServices/QuickLookUIService.xpc/Contents/MacOS/QuickLookUIService 
1		15757		0.0		[U501]		/System/Library/Frameworks/CoreServices.framework/Frameworks/Metadata.framework/Versions/A/Support/mdworker_shared -s mdworker -c MDSImporterWorker -m com.apple.mdworker.shared 

«»EOF»«
         

Alt 15.05.2019, 10:50   #8
stefanbecker
 
infizierte Doc Datei mit Macros am Macbook geöffnet - Standard

infizierte Doc Datei mit Macros am Macbook geöffnet



Wenn du mal auf den Behaviour Reiter schaust bei virustotal:

Da werden in dem Teil Registry Keys aufgelistet und Windows-Exen.

Bzw. auf dem Detailsreiter (System: Windows).

Also Windows Only. Da wird nicht passiert sein. Aber warte trotzdem mal ab, bis ein User mit Mac-Kenntnissen drüberschaut über deine Logs.

Und dann sagt, was bzw. ob was zu tun ist.

Alt 15.05.2019, 10:58   #9
ThomasHoll
 
infizierte Doc Datei mit Macros am Macbook geöffnet - Standard

infizierte Doc Datei mit Macros am Macbook geöffnet



Danke Dir.
Hast mich schon etwas beruhigt.
Ich hoffe das sonst nichts befallen ist und warte auf die Mac Spezialisten.
Übers Netzwerk hat sich da auch nichts verteilt?
Denn ich war zwar in einem "Unternetzwerk eines Extenders" verbunden. Aber am Hauptrouter waren 3 Windows Pc´s verbunden.

Alt 15.05.2019, 11:02   #10
stefanbecker
 
infizierte Doc Datei mit Macros am Macbook geöffnet - Standard

infizierte Doc Datei mit Macros am Macbook geöffnet



Wenn auf dem Mac nichts ausführbar war, kann auch im Netzwerk nichts passiert sein.

Hättest du die auf dem Win Rechner geöffnet, hättest du jetzt die Arschkarte. Das wird ein Verschlüsseler sein. Und die gehen auf alles greifbare, also auch auf externe angeschlossene Platten (USB, eSata) oder NAS-Laufwerke.

Antwort

Themen zu infizierte Doc Datei mit Macros am Macbook geöffnet
antimalware, beendet, bessere, code, datei, email, erhalte, heute, infizierte, interne, internet, kaspersky, melde, popups, programme, programmier, prozess, scan, scanne, scannen, script, security, sichern, trojaner, win




Ähnliche Themen: infizierte Doc Datei mit Macros am Macbook geöffnet


  1. LINK VON INKASSO ABTEILUNG AMAZONG GEÖFFNET / macbook
    Plagegeister aller Art und deren Bekämpfung - 01.06.2016 (6)
  2. Infizierte Datei auf dem NAS - Malwareblocker
    Diskussionsforum - 09.05.2016 (14)
  3. infizierte .doc Datei geöffnet - Banking Trojaner?
    Log-Analyse und Auswertung - 15.12.2015 (13)
  4. DHL Fake Link geöffnet, ZIP extrahiert und .exe Datei geöffnet
    Plagegeister aller Art und deren Bekämpfung - 02.06.2015 (10)
  5. Infizierte zip Datei mit iPhone geöffnet
    Smartphone, Tablet & Handy Security - 29.05.2015 (4)
  6. DHL Mail auf MacBook geöffnet
    Alles rund um Mac OSX & Linux - 22.05.2015 (3)
  7. Infizierte .doc-Datei geöffnet
    Log-Analyse und Auswertung - 18.05.2015 (4)
  8. Macbook / OSX Yosemite 10.10.3: Fake-email link geöffnet, Weiterleitung unklar
    Alles rund um Mac OSX & Linux - 12.05.2015 (5)
  9. Amazon Zip-Datei mit MacBook geöffnet
    Alles rund um Mac OSX & Linux - 12.03.2015 (2)
  10. Wieder in Mode: Trojaner in Office-Macros
    Nachrichten - 07.01.2015 (0)
  11. Macbook: 1&1 Rechnung Trojaner geöffnet
    Plagegeister aller Art und deren Bekämpfung - 19.11.2014 (5)
  12. Falsche paypal Mahnung geöffnet, Zip Datei mit Trojaner geöffnet, Avira hat Trojaner gefunden, Ist dann alles sauber?
    Log-Analyse und Auswertung - 18.09.2014 (13)
  13. Trojaner mit ungesichertem iPhone geöffnet, Gefahr einer Übertragung auf PC oder Macbook?
    Alles rund um Mac OSX & Linux - 20.11.2013 (4)
  14. Infizierte Datei auf windows xp
    Log-Analyse und Auswertung - 24.10.2013 (24)
  15. Mahnung von www.wahlbusch.de zip-Datei und darin enthaltene Datei geöffnet
    Log-Analyse und Auswertung - 18.04.2013 (7)
  16. infizierte Datei finden
    Plagegeister aller Art und deren Bekämpfung - 17.07.2012 (3)
  17. 1 infizierte datei
    Plagegeister aller Art und deren Bekämpfung - 27.11.2003 (6)

Zum Thema infizierte Doc Datei mit Macros am Macbook geöffnet - Hallo, ich habe heute eine Email erhalten die wie eine von mir geschriebene aussah und dort war eine .doc Datei. Diese habe ich dummerweise geöffnet. Es wurde mit Makros geöffnet - infizierte Doc Datei mit Macros am Macbook geöffnet...
Archiv
Du betrachtest: infizierte Doc Datei mit Macros am Macbook geöffnet auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.