Can someone tell me if my Macbook Air is compromised?

Hi, I have had issues with all my devices for 3 months now starting first with my iPhone and it having an extra phone number put on it and the iMessage verification security check helped me identify it. I have still not received any answers from Apple nor my cell service provider as to why or how. I got rid of all old computers, printers, set up new network with new router, modem, etc to ensure no traces of whatever malware/hacking was left behind. I bought 2 new brand new MacBook Airs. First I became suspicious when I couldn't get the camera to work and in the activity monitor, I was seeing an AppleH13 and AppleH16 camera showing in the activity which did not match the factory camera listed in the system report.


Would this community be so kind to review the entrecheck report to confirm it looks consistent with a brand new computer with factory default settings with the only download being the entrecheck program. Thank you SO much!



[Re-Titled by Moderator]

MacBook Air (M3, 2024)

Posted on May 7, 2024 1:30 PM

Reply
9 replies

May 7, 2024 2:44 PM in response to _AppleHelpNeeded_

if you want an opinion on the EtreCheck data, please post it.


Brand new to you, or brand new from Apple or an authorized reseller?


Did you go through the Welcome and Mac and account setup as new, or did you transfer existing contents?


NetBIOS is old, and is rarely used outside of sites with old Microsoft network configurations, and old Novell configurations. Or were you maybe referring to ZeroConf / mDNS / Bonjour name?


Bitacora is a help desk tool used in Latin America, or is a bioinformatics tool. Probably other uses.

May 7, 2024 2:18 PM in response to IdrisSeabright

It's hard to succinctly explain so I bought a brand new MacBook Air after experiencing additional issues on another MacBookAir where I watched my NetBios Name change from "Example Name-MacBookAir" to "Example Name-Laptop" after our home network intrusion/iPhone issues, I did not use NetBios nor change the computer name. So after creating a new home network with a new modem/router and new account passwords, etc., I set up the factory sealed MacBook Air with all factory default settings and immediately ran the entrecheck report. The report shows a few items that I have questions about and am hoping for more clarification.


Network: interface en3 and interface en4 - ethernet adapters

I have never set up or used anything other than wifi for a couple hours.


Applications: 533 apps, 3 x86-only apps, 2 unsigned apps. - being a brand new computer, with M3 2024 chip - should I expect to see that many apps as well as unsigned and x86 only apps?


Diagnostic Info: BitacoraWorker Crash - I can't find any information about what BitacoraWorker is and if it should be expected to be on a few hours old computer?


I appreciate your patience and any information you can provide. I have spent a lot of time and money on getting these major security issues solved with IT professionals as well as buying all new equipment and devices so I am really just looking for honest information and reassurance that this entrecheck report showing the Network Interfaces, 500+ applications including x86 only and unsigned apps are to be expected on a brand new MacBook Air with NO appleID set up, no data transfer from iCloud accounts and no connections to any other devices besides connecting to my home wifi.


Or do I need to continue searching for vulnerabilities in my devices or network for intrusions because the report shows items not expected with an essentially blank brand new MacBook Air M3 2024.


Thank you




May 7, 2024 4:26 PM in response to MrHoffman


Thank you for your response! I posted the etrecheck report on my original post but I copied it to this response as well.


It was a Brand new MacBook Air purchased from Costco, I opened the two paper pull strips off the factory sealed box. I already confirmed that the 2 paper pull strips are factory seals with apple. During setup, I went through the Welcome/Mac setup as a brand new computer, did not transfer any data over and did not add an appleID and marked the option to add appleID later as I'm not sure where the vulnerabilities/intrusion happened on my prior devices.


And I double checked again on this new MacBook Air about NetBios and this MacBook also has a NetBios name assigned to it under the system information report.


May 12, 2024 10:36 PM in response to MrHoffman

Thank you for your reply Mr. Hoffman. I couldn’t get the commands to work but I did some digging and found a hidden .zsh folder that lists .zsh sessions and history. Does this look concerning? Snapshot of 1 text file of history showing bitacoraworker exiting as well as configurationprofiles, DevToolsSecurity, traceroute6.


There’s multiple text files similar to this. I also downloaded little snitch and I see a command related to codesign for the little snitch download I did.


i want to confirm this is not some automated Apple process and somebody unauthorized is typing those commands into the .zsh session as I am not technically knowledgeable to do this.


i also found the contents of the bitacora app and will attach snapshots of the info.plist and version.plist.

i really appreciate any insight you can provide. Thank you!

May 13, 2024 2:08 PM in response to Mac Jim ID

Ok thank you, that makes me feel better. But just to confirm, The BitaCora worker produced a Codesign error 4 - launch constraint violation report that popped up in a sysdiagnose finder window suddenly that I did not run or initiate, I should just ignore that too? This is normal behavior? Thank you so much for your insight. I appreciate your patience.


Report attached.


This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Can someone tell me if my Macbook Air is compromised?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.