Start time: 21:45:03 09/18/22
Model Identifier: iMac14,1
System Version: macOS 10.15.7 (19H2026)
Kernel Version: Darwin 19.6.0
Boot Mode: Normal
System Integrity Protection: Enabled
CPU per process: com.apple.WebKit (UID 501) is using 26 %
Daemons
com.apple.XprotectFramework.PluginService
com.apple.XProtect.daemon.scan
Agents
com.apple.SafariHistoryServiceAgent
com.apple.SafariBookmarksSyncAgent
com.ReplayInfo
com.apple.XprotectFramework.PluginService
com.CheckTime.app
com.apple.XProtect.agent.scan
QuicklookPI
bc20
rp2
launchd
/System/Library/LaunchAgents/com.apple.SafariBookmarksSyncAgent.plist
- com.apple.SafariBookmarksSyncAgent
/System/Library/LaunchAgents/com.apple.SafariLaunchAgent.plist
- com.apple.SafariLaunchAgent
/System/Library/LaunchAgents/com.apple.SafariHistoryServiceAgent.plist
- com.apple.SafariHistoryServiceAgent
Library/LaunchAgents/com.QuicklookPI.plist
- QuicklookPI
Library/LaunchAgents/com.rp2.plist
- rp2
Library/LaunchAgents/com.ReplayInfo.plist
- com.ReplayInfo
Library/LaunchAgents/com.bc20.plist
- bc20
Library/LaunchAgents/com.CheckTime.plist
- com.CheckTime.app
Bundles
/Library/Audio/Plug-Ins/RemoteInput/AudioAppleSiriRemoteInput.bundle
- com.apple.AudioAppleSiriRemoteInput
/Library/Extensions/ATTOExpressSASHBA2.kext
- com.ATTO.driver.ATTOExpressSASHBA2
/Library/Extensions/ACS6x.kext
- com.Accusys.driver.Acxxx
/Library/Extensions/AppleMobileDevice.kext
- com.apple.driver.AppleMobileDevice
/Library/Extensions/SoftRAID.kext
- com.softraid.driver.SoftRAID
/Library/Extensions/HighPointIOP.kext
- com.highpoint-tech.kext.HighPointIOP
/Library/Extensions/CalDigitHDProDrv.kext
- com.CalDigit.driver.HDPro
/Library/Extensions/HighPointRR.kext
- com.highpoint-tech.kext.HighPointRR
/Library/Extensions/ArcMSR.kext
- com.Areca.ArcMSR
/Library/Extensions/ATTOCelerityFC8.kext
- com.ATTO.driver.ATTOCelerityFC8
/Library/Extensions/hp_io_enabler_compound.kext
- com.hp.kext.io.enabler.compound
/Library/Extensions/PromiseSTEX.kext
- com.promise.driver.stex
/Library/Extensions/ATTOExpressSASRAID2.kext
- com.ATTO.driver.ATTOExpressSASRAID2
/Library/Internet Plug-Ins/AdobePDFViewer.plugin
- com.adobe.acrobat.pdfviewer
/Library/Internet Plug-Ins/SharePointBrowserPlugin.plugin
- com.microsoft.sharepoint.browserplugin
/Library/Internet Plug-Ins/Silverlight.plugin
- com.microsoft.SilverlightPlugin
/Library/Internet Plug-Ins/AdobePDFViewerNPAPI.plugin
- com.adobe.acrobat.pdfviewerNPAPI
/Library/Internet Plug-Ins/Flash Player.plugin
- N/A
/Library/Internet Plug-Ins/SharePointWebKitPlugin.webplugin
- com.microsoft.sharepoint.webkitplugin
/Library/Internet Plug-Ins/JavaAppletPlugin.plugin
- com.oracle.java.JavaAppletPlugin
/Library/PreferencePanes/JavaControlPanel.prefPane
- com.oracle.java.JavaControlPanel
/Library/PreferencePanes/Flash Player.prefPane
- com.adobe.flashplayerpreferences
/Library/QuickTime/AppleIntermediateCodec.component
- com.apple.AppleIntermediateCodec
/Library/Spotlight/iBooksAuthor.mdimporter
- com.apple.MDImporter.iBooksAuthor
Library/Keyboard/en-dynamic.lm
- com.apple.LanguageModeling.en
Library/Keyboard/it-dynamic.lm
- com.apple.LanguageModeling.it
Library/Keyboard/pt-dynamic.lm
- com.apple.LanguageModeling.pt
Library/Keyboard/es-dynamic.lm
- com.apple.LanguageModeling.es
Contents of /etc/hosts
127.0.0.1 localhost
255.255.255.255 broadcasthost
::1 localhost
fe80::1%lo0 localhost
Contents of /etc/pf.conf
scrub-anchor "com.apple/*"
nat-anchor "com.apple/*"
rdr-anchor "com.apple/*"
dummynet-anchor "com.apple/*"
anchor "com.apple/*"
load anchor "com.apple" from "/etc/pf.anchors/com.apple"
Contents of /etc/syslog.conf
install.* @127.0.0.1:32376
Contents of /etc/pam.d/authorization
auth optional pam_krb5.so use_first_pass use_kcminit
auth optional pam_ntlm.so use_first_pass
auth required pam_opendirectory.so use_first_pass nullok
account required pam_opendirectory.so
Contents of /etc/pam.d/authorization_aks
auth required pam_aks.so
account required pam_opendirectory.so
Contents of /etc/pam.d/authorization_ctk
auth required pam_smartcard.so use_first_pass pkinit
account required pam_opendirectory.so
Contents of /etc/pam.d/authorization_la
auth required pam_localauthentication.so
auth required pam_aks.so
account required pam_opendirectory.so
Contents of /etc/pam.d/authorization_lacont
auth required pam_localauthentication.so continuityunlock
auth required pam_aks.so
account required pam_opendirectory.so
Contents of /etc/pam.d/checkpw
auth required pam_opendirectory.so use_first_pass nullok
account required pam_opendirectory.so no_check_home no_check_shell
Contents of /etc/pam.d/chkpasswd
auth required pam_opendirectory.so
account required pam_opendirectory.so
password required pam_permit.so
session required pam_permit.so
Contents of /etc/pam.d/cups
auth required pam_opendirectory.so
account required pam_permit.so
password required pam_deny.so
session required pam_permit.so
Contents of /etc/pam.d/login
auth optional pam_krb5.so use_kcminit
auth optional pam_ntlm.so try_first_pass
auth optional pam_mount.so try_first_pass
auth required pam_opendirectory.so try_first_pass
account required pam_nologin.so
account required pam_opendirectory.so
password required pam_opendirectory.so
session required pam_launchd.so
session required pam_uwtmp.so
session optional pam_mount.so
Contents of /etc/pam.d/login.term
account required pam_nologin.so
account required pam_opendirectory.so
session required pam_uwtmp.so
Contents of /etc/pam.d/other
auth required pam_deny.so
account required pam_deny.so
password required pam_deny.so
session required pam_deny.so
Contents of /etc/pam.d/passwd
auth required pam_permit.so
account required pam_opendirectory.so
password required pam_opendirectory.so
session required pam_permit.so
Contents of /etc/pam.d/screensaver
auth optional pam_krb5.so use_first_pass use_kcminit
auth required pam_opendirectory.so use_first_pass nullok
account required pam_opendirectory.so
account sufficient pam_self.so
account required pam_group.so no_warn group=admin,wheel fail_safe
account required pam_group.so no_warn deny group=admin,wheel ruser fail_safe
Contents of /etc/pam.d/screensaver_aks
auth required pam_aks.so
account required pam_opendirectory.so
account sufficient pam_self.so
account required pam_group.so no_warn group=admin,wheel fail_safe
account required pam_group.so no_warn deny group=admin,wheel ruser fail_safe
Contents of /etc/pam.d/screensaver_ctk
auth required pam_smartcard.so use_first_pass
account required pam_opendirectory.so
account sufficient pam_self.so
account required pam_group.so no_warn group=admin,wheel fail_safe
account required pam_group.so no_warn deny group=admin,wheel ruser fail_safe
Contents of /etc/pam.d/screensaver_la
auth required pam_localauthentication.so
auth required pam_aks.so
account required pam_opendirectory.so
account sufficient pam_self.so
account required pam_group.so no_warn group=admin,wheel fail_safe
account required pam_group.so no_warn deny group=admin,wheel ruser fail_safe
Contents of /etc/pam.d/smbd
account required pam_sacl.so sacl_service=smb allow_trustacct
session required pam_permit.so
Contents of /etc/pam.d/sshd
auth optional pam_krb5.so use_kcminit
auth optional pam_ntlm.so try_first_pass
auth optional pam_mount.so try_first_pass
auth required pam_opendirectory.so try_first_pass
account required pam_nologin.so
account required pam_sacl.so sacl_service=ssh
account required pam_opendirectory.so
password required pam_opendirectory.so
session required pam_launchd.so
session optional pam_mount.so
Contents of /etc/pam.d/su
auth sufficient pam_rootok.so
auth required pam_opendirectory.so
account required pam_group.so no_warn group=admin,wheel ruser root_only fail_safe
account required pam_opendirectory.so no_check_shell
password required pam_opendirectory.so
session required pam_launchd.so
Contents of /etc/pam.d/sudo
auth sufficient pam_smartcard.so
auth required pam_opendirectory.so
account required pam_permit.so
password required pam_deny.so
session required pam_permit.so
Contents of /etc/periodic/daily/110.clean-tmps
if [ -r /etc/defaults/periodic.conf ]
then
. /etc/defaults/periodic.conf
source_periodic_confs
fi
case "$daily_clean_tmps_enable" in
[Yy][Ee][Ss])
if [ -z "$daily_clean_tmps_days" ]
then
echo '$daily_clean_tmps_enable is set but' \
'$daily_clean_tmps_days is not'
rc=2
else
echo ""
echo "Removing old temporary files:"
set -f noglob
args="-atime +$daily_clean_tmps_days -mtime +$daily_clean_tmps_days"
args="${args} -ctime +$daily_clean_tmps_days"
dargs="-empty -mtime +$daily_clean_tmps_days"
dargs="${dargs} ! -name .vfs_rsrc_streams_*"
[ -n "$daily_clean_tmps_ignore" ] && {
args="$args "`echo " ${daily_clean_tmps_ignore% }" |
sed 's/[ ][ ]*/ ! -name /g'`
dargs="$dargs "`echo " ${daily_clean_tmps_ignore% }" |
sed 's/[ ][ ]*/ ! -name /g'`
...and 21 more line(s)
Contents of /etc/periodic/daily/130.clean-msgs
if [ -r /etc/defaults/periodic.conf ]
then
. /etc/defaults/periodic.conf
source_periodic_confs
fi
case "$daily_clean_msgs_enable" in
[Yy][Ee][Ss])
if [ ! -d /var/msgs ]
then
echo '$daily_clean_msgs_enable is set but /var/msgs' \
"doesn't exist"
rc=2
else
echo ""
echo "Cleaning out old system announcements:"
[ -n "$daily_clean_msgs_days" ] &&
arg=-${daily_clean_msgs_days#-} || arg=
msgs -c $arg && rc=0 || rc=3
fi;;
*) rc=0;;
esac
exit $rc
Contents of /etc/periodic/daily/140.clean-rwho
if [ -r /etc/defaults/periodic.conf ]
then
. /etc/defaults/periodic.conf
source_periodic_confs
fi
case "$daily_clean_rwho_enable" in
[Yy][Ee][Ss])
if [ -z "$daily_clean_rwho_days" ]
then
echo '$daily_clean_rwho_enable is enabled but' \
'$daily_clean_rwho_days is not set'
rc=2
elif [ ! -d /var/rwho ]
then
echo '$daily_clean_rwho_enable is enabled but /var/rwho' \
"doesn't exist"
rc=2
else
echo ""
echo "Removing stale files from /var/rwho:"
case "$daily_clean_rwho_verbose" in
[Yy][Ee][Ss])
print=-print;;
*)
print=;;
...and 14 more line(s)
Contents of /etc/periodic/daily/199.clean-fax
if [ -r /etc/defaults/periodic.conf ]
then
. /etc/defaults/periodic.conf
source_periodic_confs
fi
if [ -d /var/spool/fax ]; then
echo ""
echo "Removing scratch fax files"
cd /var/spool/fax && \
find . -type f -name '[0-9]*.[0-9][0-9][0-9]' -mtime +7 -delete >/dev/null 2>&1;
fi
Contents of /etc/periodic/daily/310.accounting
if [ -r /etc/defaults/periodic.conf ]
then
. /etc/defaults/periodic.conf
source_periodic_confs
fi
case "$daily_accounting_enable" in
[Yy][Ee][Ss])
if [ ! -f /var/account/acct ]
then
echo '$daily_accounting_enable is set but /var/account/acct' \
"doesn't exist"
rc=2
elif [ -z "$daily_accounting_save" ]
then
echo '$daily_accounting_enable is set but ' \
'$daily_accounting_save is not'
rc=2
else
echo ""
echo "Rotating accounting logs and gathering statistics:"
cd /var/account
rc=0
n=$daily_accounting_save
rm -f acct.$n.gz acct.$n || rc=3
m=$n
...and 18 more line(s)
Contents of /etc/periodic/daily/400.status-disks
if [ -r /etc/defaults/periodic.conf ]
then
. /etc/defaults/periodic.conf
source_periodic_confs
fi
case "$daily_status_disks_enable" in
[Yy][Ee][Ss])
echo ""
echo "Disk status:"
df $daily_status_disks_df_flags && rc=1 || rc=3
;;
*) rc=0;;
esac
exit $rc
Contents of /etc/periodic/daily/420.status-network
if [ -r /etc/defaults/periodic.conf ]
then
. /etc/defaults/periodic.conf
source_periodic_confs
fi
case "$daily_status_network_enable" in
[Yy][Ee][Ss])
echo ""
echo "Network interface status:"
case "$daily_status_network_usedns" in
[Yy][Ee][Ss])
netstat -i && rc=0 || rc=3;;
*)
netstat -in && rc=0 || rc=3;;
esac;;
*) rc=0;;
esac
exit $rc
Contents of /etc/periodic/daily/430.status-rwho
if [ -r /etc/defaults/periodic.conf ]
then
. /etc/defaults/periodic.conf
source_periodic_confs
fi
case "$daily_status_rwho_enable" in
[Yy][Ee][Ss])
rwho=$(echo /var/rwho/*)
if [ -f "${rwho%% *}" ]
then
echo ""
echo "Local network system status:"
prog=ruptime
else
echo ""
echo "Local system status:"
prog=uptime
fi
rc=$($prog | tee /dev/stderr | wc -l)
if [ $? -eq 0 ]
then
[ $rc -gt 1 ] && rc=1
else
rc=3
fi;;
...and 3 more line(s)
Contents of /etc/periodic/daily/999.local
if [ -r /etc/defaults/periodic.conf ]
then
. /etc/defaults/periodic.conf
source_periodic_confs
fi
rc=0
for script in $daily_local
do
echo ''
case "$script" in
/*)
if [ -f "$script" ]
then
echo "Running $script:"
sh $script || rc=3
else
echo "$script: No such file"
[ $rc -lt 2 ] && rc=2
fi;;
*)
echo "$script: Not an absolute path"
[ $rc -lt 2 ] && rc=2;;
esac
done
exit $rc
Contents of /etc/periodic/monthly/199.rotate-fax
if [ -r /etc/defaults/periodic.conf ]
then
. /etc/defaults/periodic.conf
source_periodic_confs
fi
echo ""
printf %s "Rotating fax log files:"
cd /var/log/fax
for i in *.log; do
if [ -f "${i}" ]; then
echo -n " $i"
if [ -x /usr/bin/gzip ]; then gzext=".gz"; else gzext=""; fi
if [ -f "${i}.3${gzext}" ]; then mv -f "${i}.3${gzext}" "${i}.4${gzext}"; fi
if [ -f "${i}.2${gzext}" ]; then mv -f "${i}.2${gzext}" "${i}.3${gzext}"; fi
if [ -f "${i}.1${gzext}" ]; then mv -f "${i}.1${gzext}" "${i}.2${gzext}"; fi
if [ -f "${i}.0${gzext}" ]; then mv -f "${i}.0${gzext}" "${i}.1${gzext}"; fi
if [ -f "${i}" ]; then mv -f "${i}" "${i}.0" && if [ -x /usr/bin/gzip ]; then gzip -9 "${i}.0"; fi; fi
touch "${i}" && chmod 640 "${i}" && chown root:admin "${i}"
fi
done
echo ""
Contents of /etc/periodic/monthly/200.accounting
if [ -r /etc/defaults/periodic.conf ]
then
. /etc/defaults/periodic.conf
source_periodic_confs
fi
oldmask=$(umask)
umask 066
case "$monthly_accounting_enable" in
[Yy][Ee][Ss])
W=/var/log/wtmp
rc=0
remove=NO
if [ $rc -eq 0 ]
then
echo ""
echo "Doing login accounting:"
rc=$(ac -p | sort -nr -k 2 | tee /dev/stderr | wc -l)
[ $rc -gt 0 ] && rc=1
fi
[ $remove = YES ] && rm -f $W.0;;
*) rc=0;;
esac
umask $oldmask
exit $rc
Contents of /etc/periodic/monthly/999.local
if [ -r /etc/defaults/periodic.conf ]
then
. /etc/defaults/periodic.conf
source_periodic_confs
fi
rc=0
for script in $monthly_local
do
echo ''
case "$script" in
/*)
if [ -f "$script" ]
then
echo "Running $script:"
sh $script || rc=3
else
echo "$script: No such file"
[ $rc -lt 2 ] && rc=2
fi;;
*)
echo "$script: Not an absolute path"
[ $rc -lt 2 ] && rc=2;;
esac
done
exit $rc
Contents of /etc/periodic/weekly/999.local
if [ -r /etc/defaults/periodic.conf ]
then
. /etc/defaults/periodic.conf
source_periodic_confs
fi
rc=0
for script in $weekly_local
do
echo ''
case "$script" in
/*)
if [ -f "$script" ]
then
echo "Running $script:"
sh $script || rc=3
else
echo "$script: No such file"
[ $rc -lt 2 ] && rc=2
fi;;
*)
echo "$script: Not an absolute path"
[ $rc -lt 2 ] && rc=2;;
esac
done
exit $rc
Contents of /Library/Preferences/com.apple.security.appsandbox.plist (XML 1.0 document text, ASCII text)
UnrestrictSpotlightContainerScope
Contents of /Library/Preferences/SystemConfiguration/com.apple.Boot.plist (XML 1.0 document text, ASCII text)
Kernel Flags
Font issues: 15
Bad plists
/Library/Preferences/com.apple.TimeMachine.plist
Library/Preferences/com.webroot.WSA.plist
Library/Preferences/com.apple.mail-shared.plist
Library/Preferences/com.apple.AddressBook.plist
Library/Preferences/com.apple.homed.notbackedup.plist
Library/Preferences/com.apple.homed.plist
DNS: 2001 558
User crontab
13 * * * * ~/Library/inconsumed.qq/inconsumed.qq cr
Restricted files: 44
Widgets
World Clock
Weather
Calculator
Calendar
Elapsed time (s): 469