Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Socks proxy re enabling it self after I would restart my Mac

I have had a problem with socks proxy re enabling it self after I would restart my Mac . I was recommended to use etrecheck and I have the result can someone help me with what it means


Problem: Other problem

Description: 

Sock proxy


Major Issues:

    Anything that appears on this list needs immediate attention. 


    No Time Machine backup - Time Machine backup not found.

    Proxies - Network proxies detected. This could be evidence of malware.

    Adware - Adware detected.

    Unsigned files - There are unsigned software files installed that could be adware and should be reviewed.

   

Network:

    Interface en0: Wi-Fi

        802.11 a/b/g/n/ac

    Interface en4: Bluetooth PAN

        Proxies: SOCKS

    Interface bridge0: Thunderbolt Bridge

        Proxies: SOCKS

Security:

    Gatekeeper: Enabled

    System Integrity Protection: Enabled

Antivirus software: Apple


Adware:

    Launchd: /Library/LaunchDaemons/com.AdvancedNetworkSearchDaemon.plist

        Reason: Adware pattern match

        Executable: /Library/Application Support/com.AdvancedNetworkSearchDaemon/AdvancedNetworkSearch r

    Launchd: ~/Library/LaunchAgents/com.AdvancedNetworkSearch.plist

        Reason: Adware pattern match

        Executable: ~/Library/Application Support/com.AdvancedNetworkSearch/AdvancedNetworkSearch r


Unsigned Files:

    Launchd: ~/Library/LaunchAgents/com.DD765005.2EED.4816.9136.F4B969ECD558.plist

        Executable: ~/Library/Application Support/.80ABB8EE-2B44-4155-ACB7-AE4FE6406A23/.EC24B8AB-96BB-4CBF-8684-A398029A7FBD h

        Details: Domain name invalid - possibly adware


    Launchd: ~/Library/LaunchAgents/com.3161667095523784861.10379307047.plist

        Executable: ~/Library/Application Support/com.8368861493495759311/12758236039931688514 A9F89476-A693-4F93-91A1-2D5A97DAFAB9 AE5AE421-E909-4867-8798-C2FB68D2456D

        Details: Domain name invalid - possibly adware


    Launchd: ~/Library/LaunchAgents/com.service.1824.plist

        Executable: /Users/***/1824/_10728941154

        Details: Executable file is not accessible without Full Drive Access


    Launchd: /Library/LaunchDaemons/com.AdvancedNetworkSearchP.plist

        Executable: /var/root/.AdvancedNetworkSearch/AdvancedNetworkSearchDaemon pd

        Details: Domain name invalid - possibly adware


    Safari Extension: UpgradeCommand


System Launch Agents:

    [Not Loaded] 17 Apple tasks

    [Loaded] 154 Apple tasks

    [Running] 142 Apple tasks


System Launch Daemons:

    [Not Loaded] 38 Apple tasks

    [Loaded] 161 Apple tasks

    [Running] 137 Apple tasks

    [Other] One Apple task


Launch Agents:

    [Running] com.adobe.AdobeCreativeCloud.plist (Adobe Inc. - installed 2020-07-28)

    [Running] com.adobe.GC.AGM.plist (Adobe Systems, Inc. - installed 2020-07-26)

    [Not Loaded] com.adobe.GC.Invoker-1.0.plist (Adobe Systems, Inc. - installed 2020-07-26)

    [Loaded] com.adobe.ccxprocess.plist (Apple - installed 2020-08-10)


Launch Daemons:

    [Other] com.AdvancedNetworkSearchDaemon.plist (Adware - installed 2020-08-17)

    [Running] com.AdvancedNetworkSearchP.plist (? 9dbce7a0 - installed 2020-08-24)

    [Loaded] com.adobe.acc.installer.v2.plist (Adobe Inc. - installed 2020-07-28)

    [Loaded] com.adobe.agsservice.plist (Adobe Systems, Inc. - installed 2020-07-26)

    [Loaded] com.adobe.fpsaud.plist (Adobe Inc. - installed 2020-07-25)

    [Running] com.crystalidea.macsfancontrol.smcwrite.plist (Ilya Parniuk - installed 2020-06-24)


User Launch Agents:

    [Other] com.3161667095523784861.10379307047.plist (? 0 - installed 2020-07-15)

    [Loaded] com.AdvancedNetworkSearch.plist (Adware - installed 2020-06-22)

    [Other] com.DD765005.2EED.4816.9136.F4B969ECD558.plist (? 0 - installed 2020-07-29)

    [Loaded] com.adobe.GC.Invoker-1.0.plist (Adobe Systems, Inc. - installed 2020-07-03)

    [Loaded] com.service.1824.plist (? 0 - installed 2020-08-25)


User Login Items:

    [Not Loaded] AppCleaner SmartDelete (X85ZX835W9 - installed 2018-11-18)

        Modern Login Item

        ~/Desktop/AppCleaner.app/Contents/Library/LoginItems/AppCleaner SmartDelete.app


    [Loaded] StartUpHelper (2FNC3A47ZF - installed 2020-08-11)

        Modern Login Item

        ~/Desktop/Spotify.app/Contents/Library/LoginItems/StartUpHelper.ap


[Re-Titled by Moderator]


MacBook Pro 13″, macOS 10.15

Posted on Sep 2, 2020 4:26 AM

Reply
Question marked as Best reply

Posted on Sep 2, 2020 5:20 AM

If you suspect you have installed adware/malware:



Adware/malware launch daemons can set SOCKS proxies without user participation.

(SOCKS is an Internet protocol that exchanges network packets between a client and server through a proxy server.)


Verify you are not using SOCKS proxy:

>System Preferences>Networks>Advanced>Proxy uncheck the box



>System Preferences>Profiles. found next to Accessibility (click into it and then remove all the suspicious things from the list.)

This Preference pane may not be present if no profiles found.


Adware Removal Guide—Manual removal of : http://www.thesafemac.com/arg-identification/

or

Try running this trusted utility https://www.malwarebytes.com/mac/




Similar questions

2 replies
Question marked as Best reply

Sep 2, 2020 5:20 AM in response to Liam_kavanagh

If you suspect you have installed adware/malware:



Adware/malware launch daemons can set SOCKS proxies without user participation.

(SOCKS is an Internet protocol that exchanges network packets between a client and server through a proxy server.)


Verify you are not using SOCKS proxy:

>System Preferences>Networks>Advanced>Proxy uncheck the box



>System Preferences>Profiles. found next to Accessibility (click into it and then remove all the suspicious things from the list.)

This Preference pane may not be present if no profiles found.


Adware Removal Guide—Manual removal of : http://www.thesafemac.com/arg-identification/

or

Try running this trusted utility https://www.malwarebytes.com/mac/




Socks proxy re enabling it self after I would restart my Mac

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.