• Apfeltalk ändert einen Teil seiner Allgemeinen Geschäftsbedingungen (AGB), das Löschen von Useraccounts betreffend.
    Näheres könnt Ihr hier nachlesen: AGB-Änderung
  • Es regnet, ist neblig und kalt, alle sind krank und der Chef wird zunehmend cholerisch. Das Thema des Monats ist also folgerichtig --> Das Grau(en)
    Wir sind gespannt, war Euch dazu einfällt! Zum Wettbewerb --> Klick

Fehlermeldung "beschädigt deinen Computer"

itschus

Luxemburger Triumph
Registriert
13.04.06
Beiträge
509
Hallo in die Runde,

ich habe hier seit einiger Zeit, 2 Monate vielleicht, immer wieder ein Fenster, welches von selber aufgeht - siehe Anhang.
Lass ich mir die Datei im Finder anzeigen, gelange ich zur Library -> Application Support und dann zu einem Ordner welchen ich nicht zuordnen kann. (com.7106413947559871000)
Das blöde ist einfach, ich habe nicht die geringste Ahnung, was das sein kann.
Jemand eine Idee dazu?

Software ist aktuell, MacBook Pro M1
 

Anhänge

  • Bildschirmfoto 2024-01-17 um 10.24.18.png
    Bildschirmfoto 2024-01-17 um 10.24.18.png
    95,7 KB · Aufrufe: 51

Wuchtbrumme

Golden Noble
Registriert
03.05.10
Beiträge
22.024
Hallo in die Runde,

ich habe hier seit einiger Zeit, 2 Monate vielleicht, immer wieder ein Fenster, welches von selber aufgeht - siehe Anhang.
Lass ich mir die Datei im Finder anzeigen, gelange ich zur Library -> Application Support und dann zu einem Ordner welchen ich nicht zuordnen kann. (com.7106413947559871000)
Das blöde ist einfach, ich habe nicht die geringste Ahnung, was das sein kann.
Jemand eine Idee dazu?

Software ist aktuell, MacBook Pro M1

lass EtreCheck laufen (gib ihm Festplattenvollzugriff) und poste den Bericht.
 
  • Like
Reaktionen: itschus

itschus

Luxemburger Triumph
Registriert
13.04.06
Beiträge
509
Meint ihr das hier:

Code:
EtreCheckPro version: 6.8.4 (68040)

Report generated: 2024-01-26 08:46:45

Download EtreCheckPro from https://etrecheck.com

Runtime: 2:22


Performance: Excellent

Problem: Other problem


Major Issues:
    Anything that appears on this list needs immediate attention.


    Malware - Malware detected.

    Unsigned files - There are unsigned software files installed that could be malicious and should be reviewed.

    Heavy CPU usage - Some processes are using an unusually high amount of CPU.


Minor Issues:
    These issues do not need immediate attention but they may indicate future problems or opportunities for improvement.


    Heavy RAM usage - Apps are using a large amount of RAM.

    Apps crashing - There have been numerous app crashes.

    Apps with heavy CPU usage - There have been numerous cases of apps with heavy CPU usage.

    Clean up - There are orphan files that could be removed.

    System modifications - There are a large number of system modifications running in the background.

    Limited permissions - More information may be available with Full Disk Access.

    Kernel extensions present - This computer has kernel extensions that may not work in the future.


Hardware Information:
    MacBook Pro (16-inch, 2021)
        Status: Supported
    MacBook Pro Model: MacBookPro18,1
    Apple M1 Pro (m1) CPU: 10-core
    32 GB RAM - Not upgradeable
    Battery: Health = Normal - Cycle count = 127

Video Information:
    Apple M1 Pro
        Color LCD 3456 x 2234
        LG HDR 4K 5120 x 2880

Drives:
    disk0 - APPLE SSD AP2048R 2.00 TB (Solid State - TRIM: Yes)
    Internal Apple Fabric NVM Express
        disk0s1 [APFS Container] 524 MB
            disk1 [APFS Virtual drive] 524 MB (Shared by 4 volumes)
                disk1s1 - iSCPreboot (APFS) [APFS Preboot] (6 MB used)
                disk1s2 - xART (APFS) (6 MB used)
                disk1s3 - Hardware (APFS) (3 MB used)
                disk1s4 - Recovery (APFS) [Recovery] (20 KB used)
        disk0s2 [APFS Container] 2.00 TB
            disk3 [APFS Virtual drive] 2.00 TB (Shared by 6 volumes)
                disk3s1 (APFS) [APFS Container] (10.13 GB used)
                    disk3s1s1 - Macintosh HD (APFS) [APFS Snapshot] (10.13 GB used)
                disk3s2 - Preboot (APFS) [APFS Preboot] (5.97 GB used)
                disk3s3 - Recovery (APFS) [Recovery] (924 MB used)
                disk3s4 - Update (APFS) (91 MB used)
                disk3s5 - Data (APFS) [APFS Virtual drive] (1.17 TB used)
                disk3s6 - VM (APFS) [APFS VM] (20 KB used)
        disk0s3 [APFS Container] 5.37 GB
            disk2 [APFS Virtual drive] 5.37 GB (Shared by 2 volumes)
                disk2s1 - Recovery (APFS) [Recovery] (1.60 GB used)
                disk2s2 - Update (APFS) (4 MB used)
    disk4 - WD Elements 2621 5.00 TB
    External USB 480 Mbit/s USB
        disk4s1 - 5*****T (Journaled HFS+) 5.00 TB (1.99 TB used)
    disk5 - Seagate Desktop 8.00 TB
    External USB 480 Mbit/s USB
        disk5s1 134 MB
        disk5s2 [APFS Container] 8.00 TB
            disk6 [APFS Virtual drive] 8.00 TB (Shared by 1 volumes)
                disk6s2 - S*******************e (APFS) (2.00 TB used)

Mounted Volumes:
    disk1s1 - iSCPreboot [APFS Preboot]
        Filesystem: APFS
        Mount point: /System/Volumes/iSCPreboot
        Used: 6 MB
        Shared values
            Size: 524 MB
            Free: 504 MB
    disk1s2 - xART
        Filesystem: APFS
        Mount point: /System/Volumes/xarts
        Used: 6 MB
        Shared values
            Size: 524 MB
            Free: 504 MB
    disk1s3 - Hardware
        Filesystem: APFS
        Mount point: /System/Volumes/Hardware
        Used: 3 MB
        Shared values
            Size: 524 MB
            Free: 504 MB
    disk3s1s1 - Macintosh HD [APFS Snapshot]
        Filesystem: APFS
        Mount point: /
        Read-only: Yes
        Used: 10.13 GB
        Shared values
            Size: 2.00 TB
            Free: 809.26 GB
            Available: 983.69 GB
    disk3s2 - Preboot [APFS Preboot]
        Filesystem: APFS
        Mount point: /System/Volumes/Preboot
        Used: 5.97 GB
        Shared values
            Size: 2.00 TB
            Free: 809.26 GB
    disk3s4 - Update
        Filesystem: APFS
        Mount point: /System/Volumes/Update
        Used: 91 MB
        Shared values
            Size: 2.00 TB
            Free: 809.26 GB
    disk3s5 - Data [APFS Virtual drive]
        Filesystem: APFS
        Mount point: /System/Volumes/Data
        Encrypted
        Used: 1.17 TB
        Shared values
            Size: 2.00 TB
            Free: 809.26 GB
            Available: 983.69 GB
    disk3s6 - VM [APFS VM]
        Filesystem: APFS
        Mount point: /System/Volumes/VM
        Used: 20 KB
        Shared values
            Size: 2.00 TB
            Free: 809.26 GB
    disk4s1 - 5*****T
        Filesystem: Journaled HFS+
        Mount point: /Volumes/5*****T
        Owners enabled: No
        Used: 1.99 TB
        Size: 5.00 TB
        Free: 3.01 TB
        Available: 3.02 TB
    disk6s2 - S*******************e
        Filesystem: APFS
        Mount point: /Volumes/S*******************e
        Used: 2.00 TB
        Shared values
            Size: 8.00 TB
            Free: 6.00 TB

USB:
    USB31Bus
        MOTU - M4
    USB31Bus
        VIA Labs, Inc. - USB2.0 Hub
            VIA Labs, Inc. - USB2.0 Hub
                Apple Inc. - Apple MagSafe Charger
                Western Digital - Elements 2621
            Realtek - USB 10/100/1000 LAN
            USB 2.0 Hub
                Seagate - Desktop
                USB PnP Audio Device
    USB31Bus
        Generic - 4-Port USB 2.0 Hub
            BRIO 4K Stream Edition
            LG Electronics Inc. - LG Monitor Controls

Network:
    Interface en6: Ethernet Adapter (en6)
    Interface en5: Ethernet Adapter (en5)
    Interface en4: Ethernet Adapter (en4)
    Interface en7: USB 10/100/1000 LAN
    Interface en0: Wi-Fi
        802.11 a/b/g/n/ac/ax
    Interface bridge0: Thunderbolt Bridge
    Interface en9: iPhone

System Software:
    macOS Sonoma 14.3 (23D56)
    Time since boot: About a day

Configuration Files:
    File /etc/sysctl.conf exists but not expected

Notifications:

    Creative Cloud.app

        one notification

    Avid Link.app

        8 notifications

    ClipGrab.app

        one notification


Security:
    Gatekeeper: App Store and identified developers

    System Integrity Protection: Enabled

    Secure Boot:


    Antivirus software: Apple


Malware:
    Launchd: /Library/LaunchDaemons/com.9939567937072928661.4C4139935042D72769129AC515B470A7167F1C2770EAF1D7BC19F609D237402D.plist
        Reason: Malware pattern match
        Executable: /Library/Application Support/com.7106413947559871000/17309770538934984565 '/Library/Application Support/com.7106413947559871000/17884888223978195363' nhechbjncncmecdibbpfiejjggooemmc 'Profile 1,Profile 3,Default' '/Library/Application Support/com.7106413947559871000/3769379566947636247' B5BE608F-4AEE-53BB-9B82-16D4BE78E45E
    Launchd: ~/Library/LaunchAgents/com.2CDFF050.4FD3.46FB.B7C2.E59C363779A0.plist
        Reason: Malware pattern match
        Executable: ~/Library/Application Support/.ACA5D59B-82B4-4843-854D-9724E94AD76A/.B484F34F-181C-49F0-ACD0-DEB9B6C0BB7A h
    Launchd: /Library/LaunchDaemons/com.9939567937072928661.1154805EABA96042B8CE5D6A14F14B2891287F930B5CBB3A0D51F33D5A4AB387.plist
        Reason: Malware pattern match
        Executable: /Library/Application Support/com.7106413947559871000/17309770538934984565 '/Library/Application Support/com.7106413947559871000/17884888223978195363' lgjoojgfnlhacaeajkgalcmiigocddkf 'Profile 1,Default' '/Library/Application Support/com.7106413947559871000/3769379566947636247' B5BE608F-4AEE-53BB-9B82-16D4BE78E45E
    Launchd: /Library/LaunchDaemons/com.9939567937072928661.1ACDDB6A4DD6DB4469B53E0097482444357071EF97E70C26925A03932A0F63E6.plist
        Reason: Malware pattern match
        Executable: /Library/Application Support/com.7106413947559871000/17309770538934984565 '/Library/Application Support/com.7106413947559871000/17884888223978195363' mheochbbceodbhhkaincknngbkafcone 'Profile 1,Default' '/Library/Application Support/com.7106413947559871000/3769379566947636247' B5BE608F-4AEE-53BB-9B82-16D4BE78E45E
    Launchd: /Library/LaunchDaemons/com.9939567937072928661.5C0F9A60C48DA55A2F62A89E0FEF8F3DFD6A7D51C1BC971AE24F3D027AA5D19F.plist
        Reason: Malware pattern match
        Executable: /Library/Application Support/com.7106413947559871000/17309770538934984565 '/Library/Application Support/com.7106413947559871000/17884888223978195363' lmgoebdbaglmekdjpbaelbjdbmogdjml 'Profile 1,Profile 3,Default' '/Library/Application Support/com.7106413947559871000/3769379566947636247' B5BE608F-4AEE-53BB-9B82-16D4BE78E45E
    Launchd: /Library/LaunchDaemons/com.9939567937072928661.CD9C812D3009454CF860AB2C1361A5E181AEB3185CD8D58A1546AFE7929C76C0.plist
        Reason: Malware pattern match
        Executable: /Library/Application Support/com.7106413947559871000/17309770538934984565 '/Library/Application Support/com.7106413947559871000/17884888223978195363' ncpgobimpecjbbimafccpljjnmlpenai 'Profile 1,Default' '/Library/Application Support/com.7106413947559871000/3769379566947636247' B5BE608F-4AEE-53BB-9B82-16D4BE78E45E
    Launchd: ~/Library/LaunchAgents/com.12516838519764668975.plist
        Reason: Malware pattern match
        Executable: ~/Library/Application Support/com.7624037320547353757/12906187974344586616 B5BE608F-4AEE-53BB-9B82-16D4BE78E45E 1137
    Launchd: /Library/LaunchDaemons/com.9939567937072928661.C604E25E3A16AE1519AA5280DB5996ED6563A7127B40294E0A2377DF8654B247.plist
        Reason: Malware pattern match
        Executable: /Library/Application Support/com.7106413947559871000/17309770538934984565 '/Library/Application Support/com.7106413947559871000/17884888223978195363' dpmiknjgjknpflpjnmbidngmgcfbfkak Default '/Library/Application Support/com.7106413947559871000/3769379566947636247' B5BE608F-4AEE-53BB-9B82-16D4BE78E45E

Unsigned Files:
    Launchd: /Library/LaunchAgents/com.logitech.logiaudiod.plist
        Executable: /Library/Application Support/Logitech.localized/Audio/logiaudiod
        Details: Exact match found in the legitimate list - probably OK
    Launchd: /Library/LaunchDaemons/net.11826530350060421311.A3B1D34A-480D-4358-BB59-4C494633E7DF.plist
        Executable: /Library/Application Support/com.16249605468190217494.56D7E5EC-E158-4E70-85F0-C3F90642CCF9/_9781655933009067825
    Apps: 5

System Extensions:
    [Not Loaded] AdBlockVPNMacOSProvider - version 2.1.2 (App Store - 2024-01-13)
        Application: /Applications/AdBlock.app - version 2.1.2 (Adblock Inc. - 2024-01-13)
    [Not Loaded] NordVPN Threat Protection - version 1.1.6 (Nordvpn S.A. - 2023-10-12)
        Application: /Applications/NordVPN.app - version 8.10.4 (Nordvpn S.A. - 2023-10-12)
        Description: System extension is used to scan files downloaded from the internet for malware.

Kernel Extensions:
    /Applications/Disk Drill.app
        [Not Loaded] SecureDisk.kext - com.cleverfiles.SecureDisk (Justin Johnson, 1.0 - SDK 10.14)
        [Not Loaded] SecureDisk_11.kext - com.cleverfiles.SecureDisk-11 (Justin Johnson, 1.0 - SDK 13)
    /Applications/StellarDataRecovery.app
        [Not Loaded] diskreader-driver.kext - com.stellarinfo.diskreader-driver (Stellar Data Recovery Inc., 1.0 - SDK 10.13)
    /Library/Extensions
        [Not Loaded] G13Joystick.kext - com.driver.LogJoystick (Logitech Inc., 2.0 - SDK 10.10)
        [Not Loaded] LogiWheelForceFeedback.kext - com.logitech.LogiWheelForceFeedback (Logitech Inc., 1.0 - SDK 10.10)
        [Not Loaded] LogiGamingMouseFilter.kext - com.logitech.driver.LogiGamingMouseFilter (Logitech Inc., 1.0 - SDK 10.10)
        [Not Loaded] LogiGamingUSBAudio.kext - com.logitech.driver.LogiGamingUSBAudio (Logitech Inc., 1.0.0 - SDK 10.10)
        [Not Loaded] LogiWheelDriver.kext - com.logitech.driver.LogiWheelDriver (Logitech Inc., 1.0 - SDK 10.10)
        [Not Loaded] MOTUFireWireAudio.kext - com.motu.driver.FireWireAudio (MOTU, 1.6 83634 - SDK 10.14)
        [Not Loaded] MOTUMicroBookAudio.kext - com.motu.driver.MicroBookAudio (MOTU, 1.6. 83634 - SDK 10.14)

System Launch Daemons:
    [Not Loaded] 41 Apple tasks

    [Loaded] 172 Apple tasks

    [Running] 186 Apple tasks

    [Other] One Apple task


System Launch Agents:
    [Not Loaded] 19 Apple tasks

    [Loaded] 174 Apple tasks

    [Running] 229 Apple tasks


Launch Daemons:
    [Loaded] com.9939567937072928661.1154805EABA96042B8CE5D6A14F14B2891287F930B5CBB3A0D51F33D5A4AB387.plist (Malware - installed 2021-12-24)

        Command: /Library/Application Support/com.7106413947559871000/17309770538934984565 '/Library/Application Support/com.7106413947559871000/17884888223978195363' lgjoojgfnlhacaeajkgalcmiigocddkf 'Profile 1,Default' '/Library/Application Support/com.7106413947559871000/3769379566947636247' B5BE608F-4AEE-53BB-9B82-16D4BE78E45E


    [Loaded] com.9939567937072928661.1ACDDB6A4DD6DB4469B53E0097482444357071EF97E70C26925A03932A0F63E6.plist (Malware - installed 2021-12-24)

        Command: /Library/Application Support/com.7106413947559871000/17309770538934984565 '/Library/Application Support/com.7106413947559871000/17884888223978195363' mheochbbceodbhhkaincknngbkafcone 'Profile 1,Default' '/Library/Application Support/com.7106413947559871000/3769379566947636247' B5BE608F-4AEE-53BB-9B82-16D4BE78E45E


    [Loaded] com.9939567937072928661.4C4139935042D72769129AC515B470A7167F1C2770EAF1D7BC19F609D237402D.plist (Malware - installed 2021-12-24)

        Command: /Library/Application Support/com.7106413947559871000/17309770538934984565 '/Library/Application Support/com.7106413947559871000/17884888223978195363' nhechbjncncmecdibbpfiejjggooemmc 'Profile 1,Profile 3,Default' '/Library/Application Support/com.7106413947559871000/3769379566947636247' B5BE608F-4AEE-53BB-9B82-16D4BE78E45E


    [Loaded] com.9939567937072928661.5C0F9A60C48DA55A2F62A89E0FEF8F3DFD6A7D51C1BC971AE24F3D027AA5D19F.plist (Malware - installed 2021-12-24)

        Command: /Library/Application Support/com.7106413947559871000/17309770538934984565 '/Library/Application Support/com.7106413947559871000/17884888223978195363' lmgoebdbaglmekdjpbaelbjdbmogdjml 'Profile 1,Profile 3,Default' '/Library/Application Support/com.7106413947559871000/3769379566947636247' B5BE608F-4AEE-53BB-9B82-16D4BE78E45E


    [Loaded] com.9939567937072928661.C604E25E3A16AE1519AA5280DB5996ED6563A7127B40294E0A2377DF8654B247.plist (Malware - installed 2021-12-24)

        Command: /Library/Application Support/com.7106413947559871000/17309770538934984565 '/Library/Application Support/com.7106413947559871000/17884888223978195363' dpmiknjgjknpflpjnmbidngmgcfbfkak Default '/Library/Application Support/com.7106413947559871000/3769379566947636247' B5BE608F-4AEE-53BB-9B82-16D4BE78E45E


    [Loaded] com.9939567937072928661.CD9C812D3009454CF860AB2C1361A5E181AEB3185CD8D58A1546AFE7929C76C0.plist (Malware - installed 2021-12-24)

        Command: /Library/Application Support/com.7106413947559871000/17309770538934984565 '/Library/Application Support/com.7106413947559871000/17884888223978195363' ncpgobimpecjbbimafccpljjnmlpenai 'Profile 1,Default' '/Library/Application Support/com.7106413947559871000/3769379566947636247' B5BE608F-4AEE-53BB-9B82-16D4BE78E45E


    [Running] com.Logitech.LogiFacecam.Service.plist (Logitech Inc. - installed 2021-03-24)

        Executable: /Library/Application Support/LogiFacecam.bundle/Contents/MacOS/LogiFacecamService


    [Loaded] com.SplitMediaLabs.LogiCapture.Assistant.plist (Logitech Inc. - installed 2021-03-24)

        Command: /Library/CoreMediaIO/Plug-Ins/DAL/LogiCapture.plugin/Contents/MacOS/Assistant --timeout 300.0


    [Loaded] com.adobe.ARMDC.Communicator.plist (Adobe Inc. - installed 2023-12-14)

        Executable: /Library/PrivilegedHelperTools/com.adobe.ARMDC.Communicator


    [Loaded] com.adobe.ARMDC.SMJobBlessHelper.plist (Adobe Inc. - installed 2023-12-14)

        Executable: /Library/PrivilegedHelperTools/com.adobe.ARMDC.SMJobBlessHelper


    [Running] com.adobe.acc.installer.v2.plist (Adobe Inc. - installed 2023-12-14)

        Executable: /Library/PrivilegedHelperTools/com.adobe.acc.installer.v2


    [Loaded] com.adobe.agsservice.plist (Adobe Inc. - installed 2024-01-09)

        Executable: /Library/Application Support/Adobe/AdobeGCClient/AGSService


    [Running] com.cleverfiles.cfbackd.plist (Justin Johnson - installed 2023-01-20)

        Executable: /Library/Application Support/CleverFiles/BackService.app/Contents/MacOS/cfbackd


    [Loaded] com.fxfactory.FxFactory.helper.plist (Noise Industries, LLC - installed 2022-01-19)

        Executable: /Library/PrivilegedHelperTools/com.fxfactory.FxFactory.helper


    [Running] com.logitech.LogiRightSight.plist (Logitech Inc. - installed 2024-01-18)

        Executable: /Applications/LogiTune.app/Contents/Frameworks/LogiRightSight.app/Contents/MacOS/LogiRightSight


    [Running] com.logitech.logitune.updater.plist (Logitech Inc. - installed 2024-01-18)

        Executable: /Applications/LogiTune.app/Contents/Frameworks/LogiTuneUpdater.app/Contents/MacOS/LogiTuneUpdater


    [Running] com.microsoft.OneDriveStandaloneUpdaterDaemon.plist (Microsoft Corporation - installed 2023-12-16)

        Executable: /Applications/OneDrive.app/Contents/StandaloneUpdaterDaemon.xpc/Contents/MacOS/StandaloneUpdaterDaemon


    [Loaded] com.microsoft.OneDriveUpdaterDaemon.plist (Microsoft Corporation - installed 2023-12-16)

        Executable: /Applications/OneDrive.app/Contents/OneDriveUpdaterDaemon.xpc/Contents/MacOS/OneDriveUpdaterDaemon


    [Loaded] com.microsoft.autoupdate.helper.plist (Microsoft Corporation - installed 2024-01-19)

        Executable: /Library/PrivilegedHelperTools/com.microsoft.autoupdate.helper


    [Loaded] com.microsoft.office.licensingV2.helper.plist (Microsoft Corporation - installed 2023-10-20)

        Executable: /Library/PrivilegedHelperTools/com.microsoft.office.licensingV2.helper


    [Running] com.motu.coreuac.reenumerator.launchd.plist (MOTU - installed 2023-01-27)

        Executable: /Library/Application Support/MOTU/MSeries/com.motu.coreuac.reenumerator.xpc/Contents/MacOS/com.motu.coreuac.reenumerator


    [Running] com.nordvpn.macos.helper.plist (Nordvpn S.A. - installed 2023-10-12)

        Executable: /Library/PrivilegedHelperTools/com.nordvpn.macos.helper


    [Running] com.presonus.ucdaemon.plist (PreSonus Software Limited - installed 2022-11-30)

        Executable: /Library/Application Support/Presonus/universalcontrol/ucdaemon.bundle/Contents/MacOS/ucdaemon


    [Loaded] com.rogueamoeba.aceagent.plist (Rogue Amoeba Software, Inc. - installed 2023-11-14)

        Executable: /Library/Audio/Plug-Ins/HAL/ACE.driver/Contents/Resources/aceagent


    [Loaded] com.rogueamoeba.acetool.plist (Rogue Amoeba Software, Inc. - installed 2023-11-14)

        Executable: /Library/Audio/Plug-Ins/HAL/ACE.driver/Contents/Resources/acetool


    [Other] net.11826530350060421311.A3B1D34A-480D-4358-BB59-4C494633E7DF.plist (Not signed - installed 2021-12-24)

        Executable: /Library/Application Support/com.16249605468190217494.56D7E5EC-E158-4E70-85F0-C3F90642CCF9/_9781655933009067825


    [Other] org.6425166924274384037.E76EADA2-CF38-49A5-B415-19B1393AA141.plist (Not signed - installed 2021-06-15)

        Executable: /Library/Application Support/15381180062824520978/org.15381180062824520978_.15381180062824520978/_5324149957000811853_


    [Loaded] us.zoom.ZoomDaemon.plist (Zoom Video Communications, Inc. - installed 2023-12-15)

        Executable: /Library/PrivilegedHelperTools/us.zoom.ZoomDaemon


Launch Agents:
    [Other] com.adobe.ARMDCHelper.cc24aef4a1b90ed56a725c38014c95072f92651fb65e1bf9c8e43c37a23d420d.plist (Adobe Inc. - installed 2023-12-14)

        Executable: /Library/Application Support/Adobe/ARMDC/Application/Acrobat Update Helper.app/Contents/MacOS/Acrobat Update Helper


    [Running] com.adobe.AdobeCreativeCloud.plist (Adobe Inc. - installed 2023-12-14)

        Command: /Applications/Utilities/Adobe Creative Cloud/ACC/Creative Cloud.app/Contents/MacOS/Creative Cloud --showwindow=false --onOSstartup=true


    [Not Loaded] com.adobe.GC.Invoker-1.0.plist (Adobe Inc. - installed 2024-01-09)

        Command: /Library/Application Support/Adobe/AdobeGCClient/agcinvokerutility -mode=logon


    [Loaded] com.adobe.ccxprocess.plist (Adobe Inc. - installed 2024-01-13)

        Command: /Applications/Utilities/Adobe Creative Cloud Experience/CCXProcess/CCXProcess.app/Contents/MacOS/CCXProcess --openAtBoot


    [Running] com.avid.avidlink.plist (Avid Technology Inc - installed 2023-11-22)

        Command: /Applications/Avid/Avid Link/Avid Link.app/Contents/MacOS/AvidLink --trayonly


    [Running] com.logitech.logiaudiod.plist (Not signed - installed 2021-12-24)

        Executable: /Library/Application Support/Logitech.localized/Audio/logiaudiod


    [Running] com.logitech.logitune.launcher.plist (Logitech Inc. - installed 2024-01-18)

        Command: /Applications/LogiTune.app/Contents/MacOS/LogiTune --tray


    [Other] com.logitech.manager.daemon.plist (Not signed - installed 2021-03-24)

        Command: /Library/Application Support/Logitech.localized/Logitech Options.localized/LogiMgrDaemon.app/Contents/MacOS/LogiMgrDaemon --launchd


    [Loaded] com.microsoft.OneDriveStandaloneUpdater.plist (Microsoft Corporation - installed 2023-12-16)

        Executable: /Applications/OneDrive.app/Contents/StandaloneUpdater.app/Contents/MacOS/OneDriveStandaloneUpdater


    [Loaded] com.microsoft.update.agent.plist (Microsoft Corporation - installed 2024-01-19)

        Command: /Library/Application Support/Microsoft/MAU2.0/Microsoft AutoUpdate.app/Contents/MacOS/Microsoft Update Assistant.app/Contents/MacOS/Microsoft Update Assistant --launchByAgent


    [Running] com.motu.MOTULauncher.plist (MOTU - installed 2019-12-18)

        Executable: /Library/Application Support/MOTU/MOTUFireWireConsoleLauncher.app/Contents/MacOs/MOTUFireWireConsoleLauncher


User Launch Agents:
    [Other] com.12516838519764668975.plist (Malware - installed 2021-07-26)

        Command: ~/Library/Application Support/com.7624037320547353757/12906187974344586616 B5BE608F-4AEE-53BB-9B82-16D4BE78E45E 1137


    [Other] com.2CDFF050.4FD3.46FB.B7C2.E59C363779A0.plist (Malware - installed 2021-06-30)

        Command: ~/Library/Application Support/.ACA5D59B-82B4-4843-854D-9724E94AD76A/.B484F34F-181C-49F0-ACD0-DEB9B6C0BB7A h


    [Loaded] com.adobe.GC.Invoker-1.0.plist (Adobe Inc. - installed 2024-01-09)

        Command: /Library/Application Support/Adobe/AdobeGCClient/agcinvokerutility -mode=scheduled


    [Loaded] com.dropbox.DropboxMacUpdate.agent.plist (Dropbox, Inc. - installed 2024-01-22)

        Command: ~/Library/Dropbox/DropboxMacUpdate.app/Contents/MacOS/DropboxMacUpdate -check periodic


    [Loaded] com.google.GoogleUpdater.wake.plist (Google LLC - installed 2024-01-18)

        Command: ~/Library/Application Support/Google/GoogleUpdater/Current/GoogleUpdater.app/Contents/MacOS/GoogleUpdater --wake-all --enable-logging --vmodule=*/components/update_client/*=2,*/chrome/updater/*=2


    [Not Loaded] com.google.keystone.agent.plist (Not signed - installed 2023-12-06)

        <Empty>


    [Not Loaded] com.google.keystone.xpcservice.plist (Not signed - installed 2023-12-06)

        <Empty>


    [Loaded] com.valvesoftware.steamclean.plist (Valve Corporation - installed 2021-12-24)

        Command: ~/Library/Application Support/Steam/SteamApps/steamclean Public


User Login Items:
    [Not Loaded] LaunchAtLoginHelper (App Store - installed 2024-01-13)
        Modern Login Item
        /Applications/AdBlock.app/Contents/Library/LoginItems/LaunchAtLoginHelper.app
    [Not Loaded] LaunchAtLoginHelperApp (App Store - installed 2024-01-25)
        Modern Login Item
        /Applications/Be Focused Pro.app/Contents/Library/LoginItems/LaunchAtLoginHelperApp.app
    [Loaded] DeepLLauncher (Linguee GmbH - installed 2024-01-10)
        Modern Login Item
        /Applications/DeepL.app/Contents/Library/LoginItems/DeepLLauncher.app
    [Running] Dropbox (Dropbox, Inc. - installed 2024-01-23)
        Application
        /Applications/Dropbox.app
    [Not Loaded] NordVPNLauncher Sideload (Nordvpn S.A. - installed 2023-10-12)
        Modern Login Item
        /Applications/NordVPN.app/Contents/Library/LoginItems/NordVPNLauncher Sideload.app
    [Not Loaded] Launcher Disabler (Microsoft Corporation - installed 2023-12-16)
        Modern Login Item
        /Applications/OneDrive.app/Contents/Library/LoginItems/Launcher Disabler.app
    [Not Loaded] OneDrive Launcher (Microsoft Corporation - installed 2023-12-16)
        Modern Login Item
        /Applications/OneDrive.app/Contents/Library/LoginItems/OneDrive Launcher.app
    [Not Loaded] Trello Login Helper (App Store - installed 2023-10-08)
        Modern Login Item
        /Applications/Trello.app/Contents/Library/LoginItems/Trello Login Helper.app

Applications:
    637 apps
    40 x86-only apps
    7 unsigned apps

App Extensions:
    Widgets:
        PlannyWidgetActivity - /Applications/Planny.app
        SagittariusProductivityWidget - /Applications/Planny.app
        Be Focused Widget Pro - /Applications/Be Focused Pro.app
    Plugins:
        BluRayH264Encoder - /Applications/Final Cut Pro.app
        SagittariusIntents - /Applications/Planny.app
        FxAnalyzer - /Applications/Final Cut Pro.app
        TestFlightServiceExtension - /Applications/TestFlight.app
        DolbyDigitalEncoder - /Applications/Final Cut Pro.app
    Audio units:
        Model 15 AudioBridge Trunk - /Applications/Model 15.app
        Model 15 - /Applications/Model 15.app
        Model 15 AudioBridge Insert - /Applications/Model 15.app
    Finder sync extensions:
        DeepL Finder Integration - /Applications/DeepL.app
        Dropbox Finder Extension - /Applications/Dropbox.app
        OneDrive Finder Integration - /Applications/OneDrive.app
        Adobe Content Synchronizer Finder Extension - /Applications/Utilities/Adobe Sync/CoreSync/Core Sync.app
    Notification providers:
        FingNotification - /Applications/Fing.app
        FingNotificationService - /Applications/Fing.app
    Action services:
        Remove Background - /Applications/Pixelmator Pro.app
    Photo editing extensions:
        Edit in Affinity Photo - /Applications/Affinity Photo 2.app
        Affinity Haze Removal - /Applications/Affinity Photo.app
        Affinity Retouch - /Applications/Affinity Photo.app
        Affinity Liquify - /Applications/Affinity Photo.app
        Affinity Develop - /Applications/Affinity Photo.app
        Edit in Affinity Photo - /Applications/Affinity Photo.app
        Affinity Miniature - /Applications/Affinity Photo.app
        Affinity Monochrome - /Applications/Affinity Photo.app
    File providers:
        Dropbox - /Applications/Dropbox.app
        OneDrive File Provider - /Applications/OneDrive.app
    Share services:
        Dropbox Transfer - /Applications/Dropbox.app
        OneNote - /Applications/Microsoft OneNote.app
        Pocket - /Applications/Pocket.app
    Ad-blockers:
        AdBlock Engine - /Applications/AdBlock.app
    Safari extensions:
        AdBlock Icon - /Applications/AdBlock.app
        Connect Fonts for Safari Extension - /Applications/Connect Fonts for Safari.app
        Save to Pocket - /Applications/Save to Pocket.app
    QuickLook Previews:
        Full Size Previews - /Applications/Pixelmator Pro.app
            com.pixelmatorteam.pixelmator.document.binary *.pxd
            com.pixelmatorteam.pixelmator.document.package *.pxd
            com.pixelmatorteam.pixelmator-photo.document.binary *.photo
            com.pixelmatorteam.pixelmator-photo.document.package *.photo
            com.pixelmatorteam.pixelmator.document-pro-sidecar.binary *.pxd-sidecar
            com.pixelmatorteam.pixelmator.document-pro-sidecar.package *.pxd-sidecar
            com.pixelmatorteam.pixelmator-photo-edit.document.binary *.photo-edit
            com.pixelmatorteam.pixelmator-photo-edit.document.package *.photo-edit
            com.pixelmator.pxm *.pxm
            public.pxd
        EtreCheckQuickLook - ~/Downloads/EtreCheckPro.app
            com.etresoft.etrecheck4 *.etrecheck
        MainStageQuickLook - /Applications/MainStage.app
            com.apple.mainstage.concert *.concert
    QuickLook Thumbnails:
        Thumbnail - /Applications/Focusplan Pro.app
            com.focusplan.focusplan.focusplan *.focusplan
            com.focusplan.focusplan.sfffocusplan *.focusplan
        Thumbnails - /Applications/Pixelmator Pro.app
            com.pixelmatorteam.pixelmator.document.binary *.pxd
            com.pixelmatorteam.pixelmator.document.package *.pxd
            com.pixelmatorteam.pixelmator-photo.document.binary *.photo
            com.pixelmatorteam.pixelmator-photo.document.package *.photo
            com.pixelmatorteam.pixelmator.document-pro-sidecar.binary *.pxd-sidecar
            com.pixelmatorteam.pixelmator.document-pro-sidecar.package *.pxd-sidecar
            com.pixelmatorteam.pixelmator-photo-edit.document.binary *.photo-edit
            com.pixelmatorteam.pixelmator-photo-edit.document.package *.photo-edit
            com.pixelmator.pxm *.pxm
            public.pxd
            com.apple.videoapps.cube *.cube
    QuickLook Previews (legacy):
        DropboxQL - ~/Library/QuickLook/DropboxQL.qlgenerator
            com.adobe.illustrator.ai-image *.ai
            public.text
            org.oasis-open.opendocument.spreadsheet *.ods
            org.oasis-open.opendocument.presentation *.odp
            com.adobe.encapsulated-postscript *.eps
        QuickLook - /Applications/Affinity Photo 2.app
            com.seriflabs.affinity.package *.afpackage
            com.seriflabs.affinitypublisher.document *.afpub
            com.seriflabs.affinity *.fh10
            com.seriflabs.affinity.template *.aftemplate
            com.seriflabs.affinityphoto.document *.afphoto
            com.seriflabs.affinitypublisher.book *.afbook
            com.seriflabs.affinitydesigner.document *.afdesign

Audio Plug-ins:
    MOTUCoreUACAudioServerPlugin: 2.0.0+92737 (MOTU - installed 2023-01-27)
    IVGI2: 2.3.0 (Tony Frenzel - installed 2020-06-08)
    iZVinylAUHook: 1.10.0 (iZotope, Inc. - installed 2022-07-27)
    MJUCjr: 1.3.0 (Tony Frenzel - installed 2020-06-08)
    ACE: 11.9.6 (Rogue Amoeba Software, Inc. - installed 2024-01-20)
    BFDPlayer: 1.1.0 (inMusic LLC - installed 2023-12-15)
    AppleAES3Audio: 3.0 (Apple - installed 2023-12-03)
    CHANNEV: 2.0.0 (Ridvan Kucuk - installed 2023-02-22)
    quantum_audio_plug_in: 2.18.0 (PreSonus Software Limited - installed 2022-11-30)
    DC1A3: 3.3.0 (Tony Frenzel - installed 2020-06-08)

CoreMediaIO Plug-ins:
    LogiCapture: 1.1912.04.1 (Logitech Inc. - installed 2021-03-24)

Backup:
    Time Machine information is limited without Full Disk Access
    Destinations:
        S*******************e [Local] (Last used)
        B*******2 [Local]
    16 local snapshots
    Oldest local snapshot: 2023-12-13 15:02:52
    Last local snapshot: 2024-01-26 08:17:40

Performance:
    System Load: 4.74 (1 min ago) 4.23 (5 min ago) 4.11 (15 min ago)
    Nominal I/O usage: 0.68 MB/s
    File system: 8.45 seconds
    Write speed: 5245 MB/s
    Read speed: 4502 MB/s

CPU Usage Snapshot:
    Type Overall

    System: 6 %

    User: 12 %

    Idle: 81 %


Top Processes Snapshot by CPU:
    Process (count) CPU (Source - Location)

    Trello Helper (Renderer) (5) 62.45 % (App Store)

    syspolicyd 36.06 % (Apple)

    com.apple.WebKit.GPU (5) 35.78 % (Apple)

    WindowServer 21.36 % (Apple)

    com.apple.WebKit.WebContent (24) 21.02 % (Apple)


Top Processes Snapshot by Memory:
    Process (count) RAM usage (Source - Location)

    com.apple.WebKit.WebContent (24) 4.18 GB (Apple)

    EtreCheckPro 1.41 GB (Etresoft, Inc.)

    QtWebEngineProcess (7) 725 MB (Avid Technology Inc)

    GarageBand 676 MB (Apple)

    com.apple.WebKit.GPU (5) 606 MB (Apple)


Top Processes Snapshot by Network Use:
    Process Input / Output (Source - Location)

    com.apple.WebKit.Networking 246 MB / 97 MB (Apple)

    mDNSResponder 64 MB / 15 MB (Apple)

    apsd 866 KB / 3 MB (Apple)

    Mail 2 MB / 83 KB (Apple)

    AirPlayXPCHelper 961 KB / 364 KB (Apple)


Top Processes Snapshot by Energy Use:
    Process (count) Energy (0-100) (Source - Location)

    com.apple.WebKit.GPU (5) 7 (Apple)

    com.apple.WebKit.WebContent (24) 6 (Apple)

    WindowServer 6 (Apple)

    UVCAssistant 3 (Apple)

    Trello Helper (Renderer) (5) 3 (App Store)


Virtual Memory Information:
    Physical RAM: 32 GB


    Free RAM: 256 MB

    Used RAM: 22.29 GB

    Cached files: 9.46 GB


    Available RAM: 9.71 GB

    Swap Used: 0 B


Software Installs (past 60 days):
    Install Date Name (Version)

    2023-12-01 Compressor (4.7)

    2023-12-01 Motion (5.7)

    2023-12-01 iMovie (10.4)

    2023-12-01 Logic Pro (10.8.1)

    2023-12-03 Pro Video-Formate (2.3)

    2023-12-03 macOS 14.1.2 (14.1.2)

    2023-12-06 GarageBand (10.4.10)

    2023-12-08 MainStage (3.6.6)

    2023-12-12 macOS 14.2 (14.2)

    2023-12-14 ARMDC Agent Installer (1.0.0)

    2023-12-15 Zoom (5.16.10.25689)

    2023-12-16 iReal Pro (2023.11.2)

    2023-12-20 macOS 14.2.1 (14.2.1)

    2023-12-20 "Avid Link" (23.11.0.4629)

    2023-12-20 Sibelius (18.0.0)

    2023-12-20 PhotoScore Lite (9.0.2)

    2023-12-21 Final Cut Pro (10.7.1)

    2023-12-30 Mactracker (7.12.13)

    2024-01-07 HelloAI (3.4.0)

    2024-01-07 Adobe Acrobat Reader (23.008.20458) (23.008.20458)

    2024-01-13 AdBlock (2.1.2)

    2024-01-15 Curve (5.3.0)

    2024-01-17 XProtectPayloads (123)

    2024-01-17 Microsoft OneNote (16.81.24011420)

    2024-01-17 Microsoft Excel (16.81.24011420)

    2024-01-17 Microsoft PowerPoint (16.81.24011420)

    2024-01-17 Microsoft Word (16.81.24011420)

    2024-01-17 MOTU MSeries (1.1)

    2024-01-17 Adobe Acrobat Reader (23.008.20470) (23.008.20470)

    2024-01-17 Fello AI (3.6.0)

    2024-01-18 CHANNEV (1.0.0)

    2024-01-19 Microsoft AutoUpdate (4.67.24011420)

    2024-01-22 XProtectPlistConfigData (2181)

    2024-01-23 macOS 14.3 (14.3)

    2024-01-23 RosettaUpdateAuto (1.0.0.0.1.1705055767)

    2024-01-23 Microsoft Outlook (16.81.24012117)

    2024-01-24 Model 15 (2.2.27)

    2024-01-24 Pixelmator Pro (3.5.6)

    2024-01-25 Records (1.7.7)

    2024-01-25 Be Focused Pro (2.4.1)

    2024-01-25 Planny (9.0.4)


Clean up:
    /Library/LaunchDaemons/org.6425166924274384037.E76EADA2-CF38-49A5-B415-19B1393AA141.plist
        /Library/Application Support/15381180062824520978/org.15381180062824520978_.15381180062824520978/_5324149957000811853_
        Executable not found
    /Library/LaunchAgents/com.logitech.manager.daemon.plist
        /Library/Application Support/Logitech.localized/Logitech Options.localized/LogiMgrDaemon.app/Contents/MacOS/LogiMgrDaemon
        Executable not found

Diagnostics Information (past 60 days):
    2024-01-26 06:17:25 spotlightknowledged - High CPU Use (18 times)
        First occurrence: 2024-01-26 01:23:48
        Executable: /System/Library/Frameworks/CoreSpotlight.framework/spotlightknowledged
    2024-01-26 03:13:37 suggestd - High CPU Use (3 times)
        First occurrence: 2024-01-23 17:21:48
        Executable: /System/Library/PrivateFrameworks/CoreSuggestions.framework/Versions/A/Support/suggestd
    2024-01-25 13:26:06 MOTUCoreUACAudioServerPlugin - Crash (6 times)
        First occurrence: 2024-01-22 13:06:08
        Executable: /Library/Audio/Plug-Ins/HAL/MOTUCoreUACAudioServerPlugin.driver/Contents/MacOS/MOTUCoreUACAudioServerPlugin
        Details:
            libsystem_c.dylib: abort() called

    2024-01-25 11:53:12 apfsd - High CPU Use (3 times)
        First occurrence: 2024-01-24 13:28:16
        Executable: /usr/libexec/apfsd
    2024-01-25 10:51:55 knowledgeconstructiond - High CPU Use (3 times)
        First occurrence: 2024-01-25 10:54:29
        Executable: /System/Library/PrivateFrameworks/IntelligencePlatformCore.framework/Versions/A/knowledgeconstructiond
    2024-01-25 10:36:27 Mail - Crash (2 times)
        Executable: /System/Applications/Mail.app
        Details:
            libsystem_c.dylib: abort() called

    2024-01-25 10:10:54 MIDIServer - Crash (2 times)
        First occurrence: 2024-01-23 16:56:37
        Executable: /System/Library/Frameworks/CoreMIDI.framework/MIDIServer
    2024-01-24 10:11:11 signpost_reporter - High CPU Use
        First occurrence: 2024-01-24 10:13:09
        Executable: /usr/libexec/signpost_reporter
    2024-01-23 07:34:13 corespotlightd - High CPU Use
        First occurrence: 2024-01-23 07:36:07
        Executable: /System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/Metadata.framework/Versions/A/Support/corespotlightd
    2024-01-22 15:03:54 com.apple.WebKit.WebContent - High CPU Use (3 times)
        First occurrence: 2024-01-20 18:20:24
        Executable: /Volumes/VOLUME/*/W**************k/V******s/A/X*********s/c*****************************c/C******s/M***S/c*************************t
    2024-01-20 14:52:16 photoanalysisd - High CPU Use
        First occurrence: 2024-01-20 14:54:40
        Executable: /System/Library/PrivateFrameworks/PhotoAnalysis.framework/Versions/A/Support/photoanalysisd

End of report
 
Zuletzt bearbeitet von einem Moderator:

Macbeatnik

Golden Noble
Registriert
05.01.04
Beiträge
34.476
Jupp, seit dem 24.12.21 aber einiges auch schon früher,hast du Malware auf dem Rechner, die solltest du entfernen.
 
  • Like
Reaktionen: itschus

itschus

Luxemburger Triumph
Registriert
13.04.06
Beiträge
509
Jupp, seit dem 24.12.21 aber einiges auch schon früher,hast du Malware auf dem Rechner, die solltest du entfernen.
Hey, danke dir! Leider erkenne ich nicht aus dem Report, welches die Malware ist und wo sie sich befindet. Kannst du mir sagen, wo das zu finden ist?
 

MacAlzenau

Golden Noble
Registriert
26.12.05
Beiträge
22.589
Hey, danke dir! Leider erkenne ich nicht aus dem Report, welches die Malware ist und wo sie sich befindet. Kannst du mir sagen, wo das zu finden ist?
Steht im Report unter der Überschrift „Malware“, und da werden auch direkt die Pfade angegeben.
 
  • Like
Reaktionen: itschus

Marcel Bresink

Filippas Apfel
Registriert
28.05.04
Beiträge
8.863
Löschen reicht möglicherweise nicht. Die Malware muss mit einem passenden Antimalware-Programm (oder von Hand) deaktiviert werden. Es besteht ansonsten die Gefahr,
  • dass die im Hauptspeicher laufende Kopie das Programm einfach unter einem anderen Namen wieder neu installiert, oder zumindest
  • dass macOS die im System angemeldeten Dienste der Malware "vermisst" und versucht, sie alle 10 Sekunden wieder neu zu starten. Das kann den Rechner ziemlich verlangsamen.
 
  • Like
Reaktionen: itschus

itschus

Luxemburger Triumph
Registriert
13.04.06
Beiträge
509
Danke an alle, ich erhalte keine Fehlermeldungen mehr und bei einem weiteren Scan tritt auch keine Malware mehr auf;) Wieder was gelernt.
 

Mitglied 238571

Gast
Was hast du unternommen, um das Problem (dauerhaft) zu lösen?
 
  • Like
Reaktionen: itschus

itschus

Luxemburger Triumph
Registriert
13.04.06
Beiträge
509
Was hast du unternommen, um das Problem (dauerhaft) zu lösen?
Ich habe die oben beschrieben Punkte befolgt:
Erst EtreCheck laufen lassen, dann gesehen, dass es Malware ist. Dann die im Link verwiesene Software "Malewarebyts" das Zeug entfernen lassen. Nach einem Neustart nochmals einen Check gemacht und bis jetzt ist alles gut.
 

tiny

Westfälischer Gülderling
Registriert
15.12.11
Beiträge
4.587
Welchen link, welche software?
 

tiny

Westfälischer Gülderling
Registriert
15.12.11
Beiträge
4.587
Nein, ich poste offenbar irgendetwas nach dem Zufallsprinzip 🤣
 
  • Haha
Reaktionen: AndaleR