Start time: 21:45:03 09/18/22 Model Identifier: iMac14,1 System Version: macOS 10.15.7 (19H2026) Kernel Version: Darwin 19.6.0 Boot Mode: Normal System Integrity Protection: Enabled CPU per process: com.apple.WebKit (UID 501) is using 26 % Daemons com.apple.XprotectFramework.PluginService com.apple.XProtect.daemon.scan Agents com.apple.SafariHistoryServiceAgent com.apple.SafariBookmarksSyncAgent com.ReplayInfo com.apple.XprotectFramework.PluginService com.CheckTime.app com.apple.XProtect.agent.scan QuicklookPI bc20 rp2 launchd /System/Library/LaunchAgents/com.apple.SafariBookmarksSyncAgent.plist - com.apple.SafariBookmarksSyncAgent /System/Library/LaunchAgents/com.apple.SafariLaunchAgent.plist - com.apple.SafariLaunchAgent /System/Library/LaunchAgents/com.apple.SafariHistoryServiceAgent.plist - com.apple.SafariHistoryServiceAgent Library/LaunchAgents/com.QuicklookPI.plist - QuicklookPI Library/LaunchAgents/com.rp2.plist - rp2 Library/LaunchAgents/com.ReplayInfo.plist - com.ReplayInfo Library/LaunchAgents/com.bc20.plist - bc20 Library/LaunchAgents/com.CheckTime.plist - com.CheckTime.app Bundles /Library/Audio/Plug-Ins/RemoteInput/AudioAppleSiriRemoteInput.bundle - com.apple.AudioAppleSiriRemoteInput /Library/Extensions/ATTOExpressSASHBA2.kext - com.ATTO.driver.ATTOExpressSASHBA2 /Library/Extensions/ACS6x.kext - com.Accusys.driver.Acxxx /Library/Extensions/AppleMobileDevice.kext - com.apple.driver.AppleMobileDevice /Library/Extensions/SoftRAID.kext - com.softraid.driver.SoftRAID /Library/Extensions/HighPointIOP.kext - com.highpoint-tech.kext.HighPointIOP /Library/Extensions/CalDigitHDProDrv.kext - com.CalDigit.driver.HDPro /Library/Extensions/HighPointRR.kext - com.highpoint-tech.kext.HighPointRR /Library/Extensions/ArcMSR.kext - com.Areca.ArcMSR /Library/Extensions/ATTOCelerityFC8.kext - com.ATTO.driver.ATTOCelerityFC8 /Library/Extensions/hp_io_enabler_compound.kext - com.hp.kext.io.enabler.compound /Library/Extensions/PromiseSTEX.kext - com.promise.driver.stex /Library/Extensions/ATTOExpressSASRAID2.kext - com.ATTO.driver.ATTOExpressSASRAID2 /Library/Internet Plug-Ins/AdobePDFViewer.plugin - com.adobe.acrobat.pdfviewer /Library/Internet Plug-Ins/SharePointBrowserPlugin.plugin - com.microsoft.sharepoint.browserplugin /Library/Internet Plug-Ins/Silverlight.plugin - com.microsoft.SilverlightPlugin /Library/Internet Plug-Ins/AdobePDFViewerNPAPI.plugin - com.adobe.acrobat.pdfviewerNPAPI /Library/Internet Plug-Ins/Flash Player.plugin - N/A /Library/Internet Plug-Ins/SharePointWebKitPlugin.webplugin - com.microsoft.sharepoint.webkitplugin /Library/Internet Plug-Ins/JavaAppletPlugin.plugin - com.oracle.java.JavaAppletPlugin /Library/PreferencePanes/JavaControlPanel.prefPane - com.oracle.java.JavaControlPanel /Library/PreferencePanes/Flash Player.prefPane - com.adobe.flashplayerpreferences /Library/QuickTime/AppleIntermediateCodec.component - com.apple.AppleIntermediateCodec /Library/Spotlight/iBooksAuthor.mdimporter - com.apple.MDImporter.iBooksAuthor Library/Keyboard/en-dynamic.lm - com.apple.LanguageModeling.en Library/Keyboard/it-dynamic.lm - com.apple.LanguageModeling.it Library/Keyboard/pt-dynamic.lm - com.apple.LanguageModeling.pt Library/Keyboard/es-dynamic.lm - com.apple.LanguageModeling.es Contents of /etc/hosts 127.0.0.1 localhost 255.255.255.255 broadcasthost ::1 localhost fe80::1%lo0 localhost Contents of /etc/pf.conf scrub-anchor "com.apple/*" nat-anchor "com.apple/*" rdr-anchor "com.apple/*" dummynet-anchor "com.apple/*" anchor "com.apple/*" load anchor "com.apple" from "/etc/pf.anchors/com.apple" Contents of /etc/syslog.conf install.* @127.0.0.1:32376 Contents of /etc/pam.d/authorization auth optional pam_krb5.so use_first_pass use_kcminit auth optional pam_ntlm.so use_first_pass auth required pam_opendirectory.so use_first_pass nullok account required pam_opendirectory.so Contents of /etc/pam.d/authorization_aks auth required pam_aks.so account required pam_opendirectory.so Contents of /etc/pam.d/authorization_ctk auth required pam_smartcard.so use_first_pass pkinit account required pam_opendirectory.so Contents of /etc/pam.d/authorization_la auth required pam_localauthentication.so auth required pam_aks.so account required pam_opendirectory.so Contents of /etc/pam.d/authorization_lacont auth required pam_localauthentication.so continuityunlock auth required pam_aks.so account required pam_opendirectory.so Contents of /etc/pam.d/checkpw auth required pam_opendirectory.so use_first_pass nullok account required pam_opendirectory.so no_check_home no_check_shell Contents of /etc/pam.d/chkpasswd auth required pam_opendirectory.so account required pam_opendirectory.so password required pam_permit.so session required pam_permit.so Contents of /etc/pam.d/cups auth required pam_opendirectory.so account required pam_permit.so password required pam_deny.so session required pam_permit.so Contents of /etc/pam.d/login auth optional pam_krb5.so use_kcminit auth optional pam_ntlm.so try_first_pass auth optional pam_mount.so try_first_pass auth required pam_opendirectory.so try_first_pass account required pam_nologin.so account required pam_opendirectory.so password required pam_opendirectory.so session required pam_launchd.so session required pam_uwtmp.so session optional pam_mount.so Contents of /etc/pam.d/login.term account required pam_nologin.so account required pam_opendirectory.so session required pam_uwtmp.so Contents of /etc/pam.d/other auth required pam_deny.so account required pam_deny.so password required pam_deny.so session required pam_deny.so Contents of /etc/pam.d/passwd auth required pam_permit.so account required pam_opendirectory.so password required pam_opendirectory.so session required pam_permit.so Contents of /etc/pam.d/screensaver auth optional pam_krb5.so use_first_pass use_kcminit auth required pam_opendirectory.so use_first_pass nullok account required pam_opendirectory.so account sufficient pam_self.so account required pam_group.so no_warn group=admin,wheel fail_safe account required pam_group.so no_warn deny group=admin,wheel ruser fail_safe Contents of /etc/pam.d/screensaver_aks auth required pam_aks.so account required pam_opendirectory.so account sufficient pam_self.so account required pam_group.so no_warn group=admin,wheel fail_safe account required pam_group.so no_warn deny group=admin,wheel ruser fail_safe Contents of /etc/pam.d/screensaver_ctk auth required pam_smartcard.so use_first_pass account required pam_opendirectory.so account sufficient pam_self.so account required pam_group.so no_warn group=admin,wheel fail_safe account required pam_group.so no_warn deny group=admin,wheel ruser fail_safe Contents of /etc/pam.d/screensaver_la auth required pam_localauthentication.so auth required pam_aks.so account required pam_opendirectory.so account sufficient pam_self.so account required pam_group.so no_warn group=admin,wheel fail_safe account required pam_group.so no_warn deny group=admin,wheel ruser fail_safe Contents of /etc/pam.d/smbd account required pam_sacl.so sacl_service=smb allow_trustacct session required pam_permit.so Contents of /etc/pam.d/sshd auth optional pam_krb5.so use_kcminit auth optional pam_ntlm.so try_first_pass auth optional pam_mount.so try_first_pass auth required pam_opendirectory.so try_first_pass account required pam_nologin.so account required pam_sacl.so sacl_service=ssh account required pam_opendirectory.so password required pam_opendirectory.so session required pam_launchd.so session optional pam_mount.so Contents of /etc/pam.d/su auth sufficient pam_rootok.so auth required pam_opendirectory.so account required pam_group.so no_warn group=admin,wheel ruser root_only fail_safe account required pam_opendirectory.so no_check_shell password required pam_opendirectory.so session required pam_launchd.so Contents of /etc/pam.d/sudo auth sufficient pam_smartcard.so auth required pam_opendirectory.so account required pam_permit.so password required pam_deny.so session required pam_permit.so Contents of /etc/periodic/daily/110.clean-tmps if [ -r /etc/defaults/periodic.conf ] then . /etc/defaults/periodic.conf source_periodic_confs fi case "$daily_clean_tmps_enable" in [Yy][Ee][Ss]) if [ -z "$daily_clean_tmps_days" ] then echo '$daily_clean_tmps_enable is set but' \ '$daily_clean_tmps_days is not' rc=2 else echo "" echo "Removing old temporary files:" set -f noglob args="-atime +$daily_clean_tmps_days -mtime +$daily_clean_tmps_days" args="${args} -ctime +$daily_clean_tmps_days" dargs="-empty -mtime +$daily_clean_tmps_days" dargs="${dargs} ! -name .vfs_rsrc_streams_*" [ -n "$daily_clean_tmps_ignore" ] && { args="$args "`echo " ${daily_clean_tmps_ignore% }" | sed 's/[ ][ ]*/ ! -name /g'` dargs="$dargs "`echo " ${daily_clean_tmps_ignore% }" | sed 's/[ ][ ]*/ ! -name /g'` ...and 21 more line(s) Contents of /etc/periodic/daily/130.clean-msgs if [ -r /etc/defaults/periodic.conf ] then . /etc/defaults/periodic.conf source_periodic_confs fi case "$daily_clean_msgs_enable" in [Yy][Ee][Ss]) if [ ! -d /var/msgs ] then echo '$daily_clean_msgs_enable is set but /var/msgs' \ "doesn't exist" rc=2 else echo "" echo "Cleaning out old system announcements:" [ -n "$daily_clean_msgs_days" ] && arg=-${daily_clean_msgs_days#-} || arg= msgs -c $arg && rc=0 || rc=3 fi;; *) rc=0;; esac exit $rc Contents of /etc/periodic/daily/140.clean-rwho if [ -r /etc/defaults/periodic.conf ] then . /etc/defaults/periodic.conf source_periodic_confs fi case "$daily_clean_rwho_enable" in [Yy][Ee][Ss]) if [ -z "$daily_clean_rwho_days" ] then echo '$daily_clean_rwho_enable is enabled but' \ '$daily_clean_rwho_days is not set' rc=2 elif [ ! -d /var/rwho ] then echo '$daily_clean_rwho_enable is enabled but /var/rwho' \ "doesn't exist" rc=2 else echo "" echo "Removing stale files from /var/rwho:" case "$daily_clean_rwho_verbose" in [Yy][Ee][Ss]) print=-print;; *) print=;; ...and 14 more line(s) Contents of /etc/periodic/daily/199.clean-fax if [ -r /etc/defaults/periodic.conf ] then . /etc/defaults/periodic.conf source_periodic_confs fi if [ -d /var/spool/fax ]; then echo "" echo "Removing scratch fax files" cd /var/spool/fax && \ find . -type f -name '[0-9]*.[0-9][0-9][0-9]' -mtime +7 -delete >/dev/null 2>&1; fi Contents of /etc/periodic/daily/310.accounting if [ -r /etc/defaults/periodic.conf ] then . /etc/defaults/periodic.conf source_periodic_confs fi case "$daily_accounting_enable" in [Yy][Ee][Ss]) if [ ! -f /var/account/acct ] then echo '$daily_accounting_enable is set but /var/account/acct' \ "doesn't exist" rc=2 elif [ -z "$daily_accounting_save" ] then echo '$daily_accounting_enable is set but ' \ '$daily_accounting_save is not' rc=2 else echo "" echo "Rotating accounting logs and gathering statistics:" cd /var/account rc=0 n=$daily_accounting_save rm -f acct.$n.gz acct.$n || rc=3 m=$n ...and 18 more line(s) Contents of /etc/periodic/daily/400.status-disks if [ -r /etc/defaults/periodic.conf ] then . /etc/defaults/periodic.conf source_periodic_confs fi case "$daily_status_disks_enable" in [Yy][Ee][Ss]) echo "" echo "Disk status:" df $daily_status_disks_df_flags && rc=1 || rc=3 ;; *) rc=0;; esac exit $rc Contents of /etc/periodic/daily/420.status-network if [ -r /etc/defaults/periodic.conf ] then . /etc/defaults/periodic.conf source_periodic_confs fi case "$daily_status_network_enable" in [Yy][Ee][Ss]) echo "" echo "Network interface status:" case "$daily_status_network_usedns" in [Yy][Ee][Ss]) netstat -i && rc=0 || rc=3;; *) netstat -in && rc=0 || rc=3;; esac;; *) rc=0;; esac exit $rc Contents of /etc/periodic/daily/430.status-rwho if [ -r /etc/defaults/periodic.conf ] then . /etc/defaults/periodic.conf source_periodic_confs fi case "$daily_status_rwho_enable" in [Yy][Ee][Ss]) rwho=$(echo /var/rwho/*) if [ -f "${rwho%% *}" ] then echo "" echo "Local network system status:" prog=ruptime else echo "" echo "Local system status:" prog=uptime fi rc=$($prog | tee /dev/stderr | wc -l) if [ $? -eq 0 ] then [ $rc -gt 1 ] && rc=1 else rc=3 fi;; ...and 3 more line(s) Contents of /etc/periodic/daily/999.local if [ -r /etc/defaults/periodic.conf ] then . /etc/defaults/periodic.conf source_periodic_confs fi rc=0 for script in $daily_local do echo '' case "$script" in /*) if [ -f "$script" ] then echo "Running $script:" sh $script || rc=3 else echo "$script: No such file" [ $rc -lt 2 ] && rc=2 fi;; *) echo "$script: Not an absolute path" [ $rc -lt 2 ] && rc=2;; esac done exit $rc Contents of /etc/periodic/monthly/199.rotate-fax if [ -r /etc/defaults/periodic.conf ] then . /etc/defaults/periodic.conf source_periodic_confs fi echo "" printf %s "Rotating fax log files:" cd /var/log/fax for i in *.log; do if [ -f "${i}" ]; then echo -n " $i" if [ -x /usr/bin/gzip ]; then gzext=".gz"; else gzext=""; fi if [ -f "${i}.3${gzext}" ]; then mv -f "${i}.3${gzext}" "${i}.4${gzext}"; fi if [ -f "${i}.2${gzext}" ]; then mv -f "${i}.2${gzext}" "${i}.3${gzext}"; fi if [ -f "${i}.1${gzext}" ]; then mv -f "${i}.1${gzext}" "${i}.2${gzext}"; fi if [ -f "${i}.0${gzext}" ]; then mv -f "${i}.0${gzext}" "${i}.1${gzext}"; fi if [ -f "${i}" ]; then mv -f "${i}" "${i}.0" && if [ -x /usr/bin/gzip ]; then gzip -9 "${i}.0"; fi; fi touch "${i}" && chmod 640 "${i}" && chown root:admin "${i}" fi done echo "" Contents of /etc/periodic/monthly/200.accounting if [ -r /etc/defaults/periodic.conf ] then . /etc/defaults/periodic.conf source_periodic_confs fi oldmask=$(umask) umask 066 case "$monthly_accounting_enable" in [Yy][Ee][Ss]) W=/var/log/wtmp rc=0 remove=NO if [ $rc -eq 0 ] then echo "" echo "Doing login accounting:" rc=$(ac -p | sort -nr -k 2 | tee /dev/stderr | wc -l) [ $rc -gt 0 ] && rc=1 fi [ $remove = YES ] && rm -f $W.0;; *) rc=0;; esac umask $oldmask exit $rc Contents of /etc/periodic/monthly/999.local if [ -r /etc/defaults/periodic.conf ] then . /etc/defaults/periodic.conf source_periodic_confs fi rc=0 for script in $monthly_local do echo '' case "$script" in /*) if [ -f "$script" ] then echo "Running $script:" sh $script || rc=3 else echo "$script: No such file" [ $rc -lt 2 ] && rc=2 fi;; *) echo "$script: Not an absolute path" [ $rc -lt 2 ] && rc=2;; esac done exit $rc Contents of /etc/periodic/weekly/999.local if [ -r /etc/defaults/periodic.conf ] then . /etc/defaults/periodic.conf source_periodic_confs fi rc=0 for script in $weekly_local do echo '' case "$script" in /*) if [ -f "$script" ] then echo "Running $script:" sh $script || rc=3 else echo "$script: No such file" [ $rc -lt 2 ] && rc=2 fi;; *) echo "$script: Not an absolute path" [ $rc -lt 2 ] && rc=2;; esac done exit $rc Contents of /Library/Preferences/com.apple.security.appsandbox.plist (XML 1.0 document text, ASCII text) UnrestrictSpotlightContainerScope Contents of /Library/Preferences/SystemConfiguration/com.apple.Boot.plist (XML 1.0 document text, ASCII text) Kernel Flags Font issues: 15 Bad plists /Library/Preferences/com.apple.TimeMachine.plist Library/Preferences/com.webroot.WSA.plist Library/Preferences/com.apple.mail-shared.plist Library/Preferences/com.apple.AddressBook.plist Library/Preferences/com.apple.homed.notbackedup.plist Library/Preferences/com.apple.homed.plist DNS: 2001 558 User crontab 13 * * * * ~/Library/inconsumed.qq/inconsumed.qq cr Restricted files: 44 Widgets World Clock Weather Calculator Calendar Elapsed time (s): 469