• Apfeltalk ändert einen Teil seiner Allgemeinen Geschäftsbedingungen (AGB), das Löschen von Useraccounts betreffend.
    Näheres könnt Ihr hier nachlesen: AGB-Änderung
  • Das neue Jahr beginnt wie das alte - natürlich mit einem neuen Fotowettbewerb! Auch im Monat Januar freuen wir uns auf Eure Einsendungen. Wie es weitergeht, wisst Ihr ja - Hier geht es lang --> Klick

Seltsames Safariverhalten - Malware?

Aitrach

Golden Delicious
Registriert
15.06.15
Beiträge
9
Ich habe seit kurzem das Problem das Safari beim Klick auf einen Link selbstständig einen 2. Tab öffnen und dort die gleiche Seite nochmals lädt. Es sind dann zwei gleiche Tabs vorhanden, einmal der ursprüngliche sowie der neu. Das finde ich doch etwas bedenklich, gerade da der 2. Tab noch irgendwelche andere Internetadressen im Hintergrund lädt, bevor er schließlich die eigentliche Seite öffnet.

Malwarebytes hat nichts gefunden...
 

dg2rbf

Blutapfel
Registriert
07.03.10
Beiträge
2.606
Hi,
dann lade dir mal Etrcheck von der Orginal Seite, und scanne damit dein System, das Ergebnis poste dann bitte hier.

Franz
 

Aitrach

Golden Delicious
Registriert
15.06.15
Beiträge
9
Hi Frank, danke für deine schnelle Antwort. Hier das Ergebnis:
Code:
EtreCheck version: 3.4.6 (460)

Report generated 2018-02-04 15:36:20

Download EtreCheck from https://etrecheck.com

Runtime: 3:23

Performance: Good



Click the [Lookup] links for more information from Apple Support Communities.

Click the [Details] links for more information about that line.

Click the [Remove/Report] links to remove adware or update the whitelist of legitimate software.

Click the [Clean up] link to delete unused files.



Problem: Other problem



Hardware Information: ⓘ

    MacBook Pro (Retina, 13-inch, Mid 2014)

    [Technical Specifications] - [User Guide] - [Warranty & Service]

    MacBook Pro - model: MacBookPro11,1

    1 2,6 GHz Intel Core i5 (i5-4278U) CPU: 2-core

    8 GB RAM Not upgradeable

        BANK 0/DIMM0

            4 GB DDR3 1600 MHz ok

        BANK 1/DIMM0

            4 GB DDR3 1600 MHz ok

    Handoff/Airdrop2: supported

    Wireless:  en0: 802.11 a/b/g/n/ac

    Battery: Health = Normal - Cycle count = 577

    iCloud Quota: 19.14 GB available


Video Information: ⓘ

    Intel Iris - VRAM: 1536 MB

        Color LCD 2560 x 1600


Disk Information: ⓘ

    APPLE SSD SD0128F disk0: (121,33 GB) (Solid State - TRIM: Yes)

    [Show SMART report]

        EFI (disk0s1 - MS-DOS FAT32) <not mounted>  [EFI]: 210 MB

        (disk0s2) <not mounted>  [APFS Container]: 121.12 GB


USB Information: ⓘ

    USB30Bus

        Apple Inc. Apple Internal Keyboard / Trackpad

        Apple Inc. BRCM20702 Hub

            Apple Inc. Bluetooth USB Host Controller


Thunderbolt Information: ⓘ

    Apple Inc. thunderbolt_bus


Virtual disks: ⓘ

    MacBook (disk1s1 - APFS) /  [Startup]: 121.12 GB (823 MB free) (Low!)

        Physical disk: disk0s2 121.12 GB (823 MB free)

    (disk1s2) <not mounted>  [Preboot]: 121.12 GB

        Physical disk: disk0s2 121.12 GB

    (disk1s3) <not mounted>  [Recovery]: 121.12 GB

        Physical disk: disk0s2 121.12 GB

    (disk1s4) /private/var/vm  [VM]: 121.12 GB

        Physical disk: disk0s2 121.12 GB



System Software: ⓘ

    macOS High Sierra  10.13.3 (17D47) - Time since boot: about 2 days


Configuration files: ⓘ

    /etc/hosts - Count: 160


Gatekeeper: ⓘ

    Mac App Store and identified developers


Possible adware: ⓘ

    Unknown file: /Library/LaunchAgents/com.cisco.anyconnect.notification.plist

        open --wait-apps /opt/cisco/anyconnect/bin/Cisco AnyConnect Secure Mobility Client Notification.app

    Unknown file: ~/Library/LaunchAgents/com.pinwing.ln.plist

        ~/Library/pinwing.ln/pinwing.ln.app/Contents/MacOS/pinwing.ln

    Unknown file: ~/Library/LaunchAgents/com.temptatory.gt.plist

        ~/Library/temptatory.gt/temptatory.gt.app/Contents/MacOS/temptatory.gt

    3 possible adware files found. [Remove/Report]


Clean up: ⓘ

    ~/Library/LaunchAgents/com.taoeffect.EspionageHelper.plist

        ~/Library/Application Support/Espionage/EspionageHelper.app/Contents/MacOS/EspionageHelper

        Executable not found!

    ~/Library/LaunchAgents/org.virtualbox.vboxwebsrv.plist

        /Applications/VirtualBox.app/Contents/MacOS/vboxwebsrv

        Executable not found!

    2 orphan files found. [Clean up]


Kernel Extensions: ⓘ

        /Applications/Boom 2.app

    [loaded]    com.globaldelight.driver.Boom2Device (1.2 - SDK 10.10) [Lookup]



        /Applications/eqMac2.app

    [loaded]    com.bitgapp.eqMac2Driver (1.0 - SDK 10.12) [Lookup]



        /Library/Application Support/VirtualBox

    [loaded]    org.virtualbox.kext.VBoxDrv (5.0.12) [Lookup]

    [loaded]    org.virtualbox.kext.VBoxNetAdp (5.0.12) [Lookup]

    [loaded]    org.virtualbox.kext.VBoxNetFlt (5.0.12) [Lookup]

    [loaded]    org.virtualbox.kext.VBoxUSB (5.0.12) [Lookup]



        /Library/Extensions

    [not loaded]    com.cisco.kext.acsock (4.5.0 - SDK 10.9) [Lookup]

    [loaded]    com.malwarebytes.mbam.rtprotection (3.1 - SDK 10.12) [Lookup]

    [loaded]    com.paragon-software.filesystems.ntfs (15.0.828 - SDK 10.10) [Lookup]



        /System/Library/Extensions

    [not loaded]    com.taoeffect.ispy.kext (2.0.2 - SDK 10.2) [Lookup]



System Launch Agents: ⓘ

    [not loaded]    7 Apple tasks

    [loaded]    158 Apple tasks

    [running]    125 Apple tasks


System Launch Daemons: ⓘ

    [failed]    org.postfix.master.plist (Apple, Inc. - installed 2017-10-25)

    [not loaded]    35 Apple tasks

    [loaded]    175 Apple tasks

    [running]    120 Apple tasks


Launch Agents: ⓘ

    [not loaded]    com.adobe.AAM.Updater-1.0.plist (Adobe Systems, Inc. - installed 2016-02-25) [Lookup]

    [failed]    com.adobe.ARMDCHelper.cc24aef4a1b90ed56a725c38014c95072f92651fb65e1bf9c8e43c37a23d420d.plist (Adobe Systems, Inc. - installed 2017-01-11) [Lookup]

    [failed]    com.adobe.CS5ServiceManager.plist (? 40cdc1ff dd391a6f - installed 2015-07-25) [Lookup]

    [loaded]    com.adobe.GC.Invoker-1.0.plist (Adobe Systems, Inc. - installed 2018-01-30) [Lookup]

    [loaded]    com.cisco.anyconnect.gui.plist (? 40bd3462 0 - installed 2017-10-23) [Lookup]

    [loaded]    com.cisco.anyconnect.notification.plist (? 8b01cb06 0 - installed 2017-10-23) [Lookup]

    [loaded]    com.google.keystone.agent.plist (Google, Inc. - installed 2017-09-28) [Lookup]

    [running]    com.malwarebytes.mbam.frontend.agent.plist (Malwarebytes Corporation - installed 2018-02-03) [Lookup]

    [loaded]    com.microsoft.update.agent.plist (Microsoft Corporation - installed 2018-01-24) [Lookup]

    [loaded]    com.oracle.java.Java-Updater.plist (? 26b1749d 72ac4dde - installed 2017-12-28) [Lookup]

    [running]    com.paragon-software.ntfs.notification-agent.plist (Paragon Software GmbH - installed 2017-07-31) [Lookup]

    [not loaded]    com.teamviewer.teamviewer.plist (TeamViewer GmbH - installed 2017-03-15) [Lookup]

    [not loaded]    com.teamviewer.teamviewer_desktop.plist (TeamViewer GmbH - installed 2017-03-15) [Lookup]

    [loaded]    org.macosforge.xquartz.startx.plist (Apple Inc. - XQuartz - installed 2016-10-26) [Lookup]


Launch Daemons: ⓘ

    [loaded]    com.adobe.ARMDC.Communicator.plist (Adobe Systems, Inc. - installed 2017-01-11) [Lookup]

    [loaded]    com.adobe.ARMDC.SMJobBlessHelper.plist (Adobe Systems, Inc. - installed 2017-01-11) [Lookup]

    [loaded]    com.adobe.SwitchBoard.plist (? 856489a3 0 - installed 2016-02-23) [Lookup]

    [running]    com.adobe.agsservice.plist (Adobe Systems, Inc. - installed 2018-01-30) [Lookup]

    [loaded]    com.adobe.fpsaud.plist (Adobe Systems, Inc. - installed 2017-12-15) [Lookup]

    [running]    com.arubanetworks.vpnservice.plist (? 88a41d99 b2b81606 - installed 2016-09-17) [Lookup]

    [running]    com.cisco.anyconnect.vpnagentd.plist (? f363637f 86afe75f - installed 2017-09-20) [Lookup]

    [running]    com.cleverfiles.cfbackd.plist (ELTIMA LLC - installed 2017-07-10) [Lookup]

    [running]    com.easeus.dataprotectbackup.plist (? ? ? - installed 2018-01-24) [Lookup]

    [running]    com.google.keystone.daemon.plist (Google, Inc. - installed 2017-10-13) [Lookup]

    [running]    com.malwarebytes.mbam.rtprotection.daemon.plist (Malwarebytes Corporation - installed 2018-02-03) [Lookup]

    [running]    com.malwarebytes.mbam.settings.daemon.plist (Malwarebytes Corporation - installed 2018-02-03) [Lookup]

    [loaded]    com.microsoft.autoupdate.helper.plist (Microsoft Corporation - installed 2018-01-24) [Lookup]

    [loaded]    com.microsoft.office.licensingV2.helper.plist (Microsoft Corporation - installed 2015-11-05) [Lookup]

    [loaded]    com.motionvfx.mInstaller.HelperTool.plist (Szymon Masiak - installed 2016-12-11) [Lookup]

    [loaded]    com.oracle.java.Helper-Tool.plist (Shell Script e3fefdd2 - installed 2017-09-06) [Lookup]

    [running]    com.paragon-software.installer.plist (Paragon Software GmbH - installed 2017-07-31) [Lookup]

    [loaded]    com.paragon-software.ntfs.loader.plist (Apple, Inc. - installed 2018-01-19)

    [running]    com.paragon-software.ntfsd.plist (Paragon Software GmbH - installed 2017-06-16) [Lookup]

    [loaded]    com.taoeffect.ispyd.plist (? 54c63ac3 3ad7d04b - installed 2015-06-23) [Lookup]

    [loaded]    com.teamviewer.Helper.plist (TeamViewer GmbH - installed 2016-12-21) [Lookup]

    [not loaded]    com.teamviewer.teamviewer_service.plist (TeamViewer GmbH - installed 2017-03-15) [Lookup]

    [loaded]    org.macosforge.xquartz.privileged_startx.plist (Apple Inc. - XQuartz - installed 2016-10-26) [Lookup]

    [running]    org.serviio.server.plist (Shell Script 16e32f40 - installed 2017-10-25)

    [not loaded]    org.virtualbox.startup.plist (Shell Script 700b9385 - installed 2016-01-14) [Lookup]


User Launch Agents: ⓘ

    [loaded]    com.adobe.AAM.Updater-1.0.plist (Adobe Systems, Inc. - installed 2016-02-29) [Lookup]

    [loaded]    com.adobe.ARM.[...].plist (? 5c76f5f6 1c9bb8a9 - installed 2015-11-28) [Lookup]

    [loaded]    com.adobe.GC.Invoker-1.0.plist (Adobe Systems, Inc. - installed 2018-01-31) [Lookup]

    [loaded]    com.dropbox.DropboxMacUpdate.agent.plist (Dropbox, Inc. - installed 2017-08-15) [Lookup]

    [running]    com.iqoption.updateservice.plist (ALTA VISTA TRADING LIMITED - installed 2018-02-04) [Lookup]

    [loaded]    com.iqoption.updatetask.plist (ALTA VISTA TRADING LIMITED - installed 2018-02-04) [Lookup]

    [loaded]    com.pinwing.ln.plist (? 348ae223 41109ad0 - installed 2017-11-09) [Lookup]

    [loaded]    com.skype.skype.shareagent.plist (Skype Communications S.a.r.l - installed 2018-01-30) [Lookup]

    [running]    com.spotify.webhelper.plist (Spotify - installed 2018-02-02) [Lookup]

    [failed]    com.taoeffect.EspionageHelper.plist (? dcff4b56 0 - installed 2015-06-23) [Lookup] - ~/Library/Application Support/Espionage/EspionageHelper.app/Contents/MacOS/EspionageHelper: Executable not found!

    [loaded]    com.temptatory.gt.plist (? cbe0d200 41109ad0 - installed 2017-11-13) [Lookup]

    [not loaded]    org.virtualbox.vboxwebsrv.plist (? e782d02b 0 - installed 2016-01-14) [Lookup] - /Applications/VirtualBox.app/Contents/MacOS/vboxwebsrv: Executable not found!


User Login Items: ⓘ

    Scroll Reverser    Programm

        (/Applications/Scroll Reverser.app)

    SpeechSynthesisServer    Programm

        (/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/SpeechSynthesis.framework/Versions/A/SpeechSynthesisServer.app)

    WiFiSpy    Programm

        (/Applications/WiFiSpy.app)

    BetterTouchTool    Programm

        (/Applications/BetterTouchTool.app)

    Boom2Daemon    SMLoginItem - Hidden (Global Delight Technologies Pvt. Ltd - installed 2017-01-17)

        (/Applications/Boom 2.app/Contents/Library/LoginItems/Boom2Daemon.app)

    com.adobe.SwitchBoard.monitor.plist    MachInit - Hidden

        (/etc/mach_init_per_user.d/com.adobe.SwitchBoard.monitor.plist)

    Mach Init items are deprecated


Internet Plug-ins: ⓘ

    o1dbrowserplugin: 5.41.3.0 (installed 2015-12-11) [Lookup]

    Google Earth Web Plug-in: 7.1 (installed 2016-01-13) [Lookup]

    AdobeExManDetect: AdobeExManDetect 1.1.0.0 (installed 2015-07-26) [Lookup]

    AdobeAAMDetect: AdobeAAMDetect 1.0.0.0 (installed 2016-02-25) [Lookup]

    AdobePDFViewerNPAPI: 17.012.20098 (installed 2017-11-30) [Lookup]

    FlashPlayer-10.6: 28.0.0.137 (installed 2018-01-10) [Lookup]

    Silverlight: 5.1.40416.0 (installed 2015-07-26) [Lookup]

    QuickTime Plugin: 7.7.3 (installed 2018-01-31)

    Flash Player: 28.0.0.137 (installed 2018-01-10) [Lookup]

    googletalkbrowserplugin: 5.41.3.0 (installed 2015-12-11) [Lookup]

    AdobePDFViewer: 18.009.20050 (installed 2017-11-30) [Lookup]

    EPPEX Plugin: 10.0 (installed 2015-06-24) [Lookup]

    JavaAppletPlugin: Java 8 Update 151 build 12 (installed 2017-12-28) Check version



User internet Plug-ins: ⓘ

    Picasa: 1.0 (installed 2015-10-13) [Lookup]



Safari Extensions: ⓘ

    [enabled]    AdBlock - BetaFish, Inc. - https://getadblock.com (installed 2015-09-29)

    [enabled]    HoverSee - SideTree.com - Apps for Mac - http://SideTree.com/extensions.html#HoverSee (installed 2017-02-01)


3rd Party Preference Panes: ⓘ

    AppTrap (installed 2015-11-28) [Lookup]

    Flash Player (installed 2017-12-15) [Lookup]

    Java (installed 2017-12-28) [Lookup]

    NTFS (installed 2017-06-16) [Lookup]

    Perian (installed 2011-07-23) [Lookup]


Time Machine: ⓘ

    Skip System Files: NO

    Mobile backups: OFF

    Auto backup: NO - Auto backup turned off

    Volumes being backed up:

        MacBook: Disk size: 121.12 GB Disk used: 120.30 GB

    Destinations:

        Data IV [Local]

        Total size: 999.86 GB

        Total number of backups: 2

        Oldest backup: 15.03.16, 21:00

        Last backup: 02.04.16, 18:19

        Size of backup disk: Excellent

            Backup size 999.86 GB > (Disk size 121.12 GB X 3)


Top Processes by CPU: ⓘ

        9%       System Events

        9%       firefox

        7%       WindowServer

        3%       launchservicesd

        3%       mds


Top Processes by Memory: ⓘ

    1.01 GB       kernel_task

    593 MB        Safari

    273 MB        com.apple.WebKit.WebContent

    242 MB        firefox

    122 MB        WhatsApp Helper


Top Processes by Network Use: ⓘ

    Input         Output        Process name

    2 MB          2 MB          mDNSResponder

    546 KB        39 KB         firefox

    289 KB        182 KB        netbiosd

    77 KB         79 KB         Spotify

    109 KB        13 KB         com.apple.WebKit.Networking


Top Processes by Energy Use: ⓘ

    18.06    launchservicesd

    16.15    GoogleSoftwareUp

      8.48    WindowServer

      8.44    System Events

      8.40    firefox


Virtual Memory Information: ⓘ

    1.63 GB       Available RAM

    53 MB         Free RAM

    6.37 GB       Used RAM

    1.58 GB       Cached files

    993 MB        Swap Used


Software installs (last 30 days): ⓘ

    IQ Option client:  (installed 2018-01-06)

    Microsoft Excel for Mac:  (installed 2018-01-07)

    Microsoft Word for Mac:  (installed 2018-01-07)

    Microsoft PowerPoint for Mac:  (installed 2018-01-07)

    Adobe Flash Player:  (installed 2018-01-10)

    Microsoft Excel for Mac:  (installed 2018-01-20)

    Microsoft Word for Mac:  (installed 2018-01-20)

    Microsoft PowerPoint for Mac:  (installed 2018-01-20)

    LanScan: 5.0 (installed 2018-01-21)

    Microsoft AutoUpdate:  (installed 2018-01-24)

    Microsoft Word for Mac:  (installed 2018-01-27)

    Microsoft PowerPoint for Mac:  (installed 2018-01-27)

    Malwarebytes for Mac:  (installed 2018-02-03)



    Install information may not be complete.


Diagnostics Events (last 3 days for minor events): ⓘ

    2018-02-04 15:24:51    Adobe Premiere Pro CS6.app High CPU use [Open] [Details]

    2018-02-03 14:16:41    cloudd Crash [Open]

        Cause:        *** Terminating app due to uncaught exception 'NSGenericException', reason: 'Error executing SQL: "pragma journal_mode = WAL" (13) - errcode:000d, msg:"database or disk is full", size: 49152, path:/Users/USER/Library/Caches/*/Assets.db, fs:22417408/121123069952'

        terminating with uncaught exception of type NSException

        abort() called

    2018-02-02 10:22:16    FaceTime.app Crash [Open]

        Cause:        Crashing on exception: no service marshals available for modal session

        x•.ǡ

    2018-01-08 19:26:20    Kernel Panic [Open] [Details]

        3rd Party Kernel Extensions:

                com.bitgapp.eqMac2Driver    1.0

                com.malwarebytes.mbam.rtprotection    3.1.1

                org.virtualbox.kext.VBoxNetAdp    5.0.12

                org.virtualbox.kext.VBoxNetFlt    5.0.12

                com.globaldelight.driver.Boom2Device    1.1

                org.virtualbox.kext.VBoxUSB    5.0.12

                com.paragon-software.filesystems.ntfs    828.0.15

                org.virtualbox.kext.VBoxDrv    5.0.12

Mod-Info: Code-Tags eingefügt
 
Zuletzt bearbeitet von einem Moderator:

raven

Golden Noble
Registriert
12.05.12
Beiträge
19.223
@Aitrach Du hast Adware auf dem Rechner und zuwenig Platz. Die Platte ist beinahe dicht.
P.S. Bitte vrpacke das Logfile noch in die Code Tags. Es wird dann übersichtlicher.
 

Aitrach

Golden Delicious
Registriert
15.06.15
Beiträge
9
Hi Raven,

danke für die Nachricht. Das mit dem Speicherplatz ist nur temporär wegen 2 großen Dateien, trotzdem danke. Kannst du mir genau sagen, welche die Adware sind?
 

raven

Golden Noble
Registriert
12.05.12
Beiträge
19.223
Bin im Moment mobile da deshalb etwas eingeschränkt im zusammensuchen.

P.S..
Code:
[QUOTE="Aitrach, post: 5207788, member: 204149"]Possible adware: ⓘ

Unknown file: /Library/LaunchAgents/com.cisco.anyconnect.notification.plist

open --wait-apps /opt/cisco/anyconnect/bin/Cisco AnyConnect Secure Mobility Client Notification.app

Unknown file: ~/Library/LaunchAgents/com.pinwing.ln.plist

~/Library/pinwing.ln/pinwing.ln.app/Contents/MacOS/pinwing.ln

Unknown file: ~/Library/LaunchAgents/com.temptatory.gt.plist

~/Library/temptatory.gt/temptatory.gt.app/Contents/MacOS/temptatory.gt

3 possible adware files found. [Remove/Report][/QUOTE]
 
  • Like
Reaktionen: doc_holleday

ottomane

Golden Noble
Registriert
24.08.12
Beiträge
16.438
Cisco Anyconnect wird fälschlicherweise als Malware klassifiziert. Es ist die VPN-Anwendung von Cisco.