1 Start time: 08:26:51 11/26/15
2
3 Revision: 1370
4
5 Model Identifier: MacBookPro10,1
6 System Version: OS X 10.11.1 (15B42)
7 Kernel Version: Darwin 15.0.0
8 Time since boot: 49 minutes
9
10 FileVault 2
11
12 FileVault is On.
13
14 Activity
15
16 en0: in 1723, out 1750 (KiB/s)
17
18 Net out (Mb/s)
19
20 Google Chrome (UID 501): 4
21
22 System errors (per sec)
23
24 Google Chrome (UID 501, error 35): 102
25
26 Energy (lifetime)
27
28 Google Chrome (UID 501): 7.82
29
30 Memory (MB)
31
32 kernel_task (UID 0): 1497
33
34 Global prefs (system)
35
36 MultipleSessionEnabled = 1
37
38 System caches/logs
39
40 2,3 GiB: /System/Library/Caches/com.apple.coresymbolicationd/data
41
42 Diagnostic reports
43
44 2015-10-26 esets_proxy crash
45 2015-10-27 TeamViewer_Service crash
46 2015-10-30 esets_proxy crash
47 2015-11-02 VDCAssistant crash
48 2015-11-02 esets_proxy crash
49 2015-11-03 esets_proxy crash
50 2015-11-04 iTunes hang
51 2015-11-05 FinderSyncAPIExtension crash x7
52 2015-11-05 SystemUIServer crash
53 2015-11-05 esets_proxy crash
54 2015-11-06 esets_daemon crash
55 2015-11-10 netbiosd crash
56 2015-11-12 TeamViewer crash
57 2015-11-13 VDCAssistant crash
58 2015-11-15 esets_proxy crash
59 2015-11-21 esets_proxy crash
60 2015-11-25 Google Drive crash x2
61 2015-11-25 SystemUIServer crash
62 2015-11-25 VDCAssistant crash
63 2015-11-25 esets_proxy crash x3
64
65 HID errors: 1
66
67 Kernel log
68
69 Nov 26 08:17:12 **** [IOBluetoothHostControllerUSBTransport][InterruptReadHandler] -- Received kIOReturnNotResponding error - retrying: 1
70 Nov 26 08:17:22 **** [IOBluetoothHostControllerUSBTransport][InterruptReadHandler] -- Received kIOReturnNotResponding error - retrying: 1
71 Nov 26 08:18:02 **** [IOBluetoothHostControllerUSBTransport][InterruptReadHandler] -- Received kIOReturnNotResponding error - retrying: 1
72 Nov 26 08:18:19 **** [IOBluetoothHostControllerUSBTransport][InterruptReadHandler] -- Received kIOReturnNotResponding error - retrying: 1
73 Nov 26 08:18:27 **** [IOBluetoothHostControllerUSBTransport][InterruptReadHandler] -- Received kIOReturnNotResponding error - retrying: 1
74 Nov 26 08:18:37 **** [IOBluetoothHostControllerUSBTransport][InterruptReadHandler] -- Received kIOReturnNotResponding error - retrying: 1
75 Nov 26 08:18:54 **** [IOBluetoothHostControllerUSBTransport][InterruptReadHandler] -- Received kIOReturnNotResponding error - retrying: 1
76 Nov 26 08:19:01 **** [IOBluetoothHostControllerUSBTransport][InterruptReadHandler] -- Received kIOReturnNotResponding error - retrying: 1
77 Nov 26 08:19:15 **** [IOBluetoothHostControllerUSBTransport][InterruptReadHandler] -- Received kIOReturnNotResponding error - retrying: 1
78 Nov 26 08:19:24 **** [IOBluetoothHostControllerUSBTransport][InterruptReadHandler] -- Received kIOReturnNotResponding error - retrying: 1
79 Nov 26 08:19:35 **** [IOBluetoothHostControllerUSBTransport][InterruptReadHandler] -- Received kIOReturnNotResponding error - retrying: 1
80 Nov 26 08:19:40 **** [IOBluetoothHostControllerUSBTransport][InterruptReadHandler] -- Received kIOReturnNotResponding error - retrying: 1
81 Nov 26 08:19:50 **** [IOBluetoothHostControllerUSBTransport][InterruptReadHandler] -- Received kIOReturnNotResponding error - retrying: 1
82 Nov 26 08:20:05 **** [IOBluetoothHostControllerUSBTransport][InterruptReadHandler] -- Received kIOReturnNotResponding error - retrying: 1
83 Nov 26 08:21:45 **** [IOBluetoothHostControllerUSBTransport][InterruptReadHandler] -- Received kIOReturnNotResponding error - retrying: 1
84 Nov 26 08:21:53 **** [IOBluetoothHostControllerUSBTransport][InterruptReadHandler] -- Received kIOReturnNotResponding error - retrying: 1
85 Nov 26 08:22:01 **** [IOBluetoothHostControllerUSBTransport][InterruptReadHandler] -- Received kIOReturnNotResponding error - retrying: 1
86 Nov 26 08:22:25 **** [IOBluetoothHostControllerUSBTransport][InterruptReadHandler] -- Received kIOReturnNotResponding error - retrying: 1
87 Nov 26 08:22:40 **** [IOBluetoothHostControllerUSBTransport][InterruptReadHandler] -- Received kIOReturnNotResponding error - retrying: 1
88 Nov 26 08:22:49 **** [IOBluetoothHostControllerUSBTransport][InterruptReadHandler] -- Received kIOReturnNotResponding error - retrying: 1
89 Nov 26 08:22:59 **** [IOBluetoothHostControllerUSBTransport][InterruptReadHandler] -- Received kIOReturnNotResponding error - retrying: 1
90 Nov 26 08:23:10 **** [IOBluetoothHostControllerUSBTransport][InterruptReadHandler] -- Received kIOReturnNotResponding error - retrying: 1
91 Nov 26 08:23:28 **** [IOBluetoothHostControllerUSBTransport][InterruptReadHandler] -- Received kIOReturnNotResponding error - retrying: 1
92 Nov 26 08:23:35 **** [IOBluetoothHostControllerUSBTransport][InterruptReadHandler] -- Received kIOReturnNotResponding error - retrying: 1
93 Nov 26 08:26:29 **** [IOBluetoothHostControllerUSBTransport][InterruptReadHandler] -- Received kIOReturnNotResponding error - retrying: 1
94
95 System log
96
97 Nov 26 08:00:15 WindowServer: _CGXRemoveWindowFromWindowMovementGroup: window 0x99 is not attached to window 0x9b
98 Nov 26 08:00:21 WindowServer: _CGXRemoveWindowFromWindowMovementGroup: window 0x99 is not attached to window 0x9b
99 Nov 26 08:00:45 WindowServer: _CGXRemoveWindowFromWindowMovementGroup: window 0x99 is not attached to window 0x9b
100 Nov 26 08:00:52 WindowServer: _CGXRemoveWindowFromWindowMovementGroup: window 0x99 is not attached to window 0x9b
101 Nov 26 08:05:00 esets: error[01fd0000]: Protoscan Proxy Agent: [0x7cb2c400] CONNECT - c_fd=651 s_fd=-1 c_addr=127.0.0.1:52693 s_addr=192.168.100.7:80 pid=5710 ppid=5709 uid=501 ruuid=501 gid=20 app_name=mnmap app_path=/Applications/Path Finder.app/Contents/Frameworks/CocoaTechAppKit.framework/Versions/A/Helpers/mnm ap
102 Nov 26 08:05:00 esets: error[01fd0000]: Protoscan Proxy Agent: Cannot get socket address: Invalid argument
103 Nov 26 08:05:00 esets: error[01fd0000]: Protoscan Proxy Agent: Cannot get socket address: Invalid argument
104 Nov 26 08:05:00 esets: error[01fd0000]: Protoscan Proxy Agent: Cannot get socket address: Invalid argument
105 Nov 26 08:05:00 esets: error[01fd0000]: Protoscan Proxy Agent: [0x7baff200] CONNECT - c_fd=649 s_fd=-1 c_addr=127.0.0.1:52704 s_addr=192.168.100.17:80 pid=5710 ppid=5709 uid=501 ruuid=501 gid=20 app_name=mnmap app_path=/Applications/Path Finder.app/Contents/Frameworks/CocoaTechAppKit.framework/Versions/A/Helpers/mnm ap
106 Nov 26 08:09:14 esets: error[01fd0000]: Protoscan Proxy Agent: Cannot get socket address: Invalid argument
107 Nov 26 08:09:14 esets: error[01fd0000]: Protoscan Proxy Agent: Cannot get socket address: Invalid argument
108 Nov 26 08:09:16 WindowServer: _CGXRemoveWindowFromWindowMovementGroup: window 0x99 is not attached to window 0x9b
109 Nov 26 08:09:26 WindowServer: _CGXRemoveWindowFromWindowMovementGroup: window 0x99 is not attached to window 0x9b
110 Nov 26 08:10:00 WindowServer: CGXGetWindowWorkspace: invalid window id: 95
111 Nov 26 08:10:00 WindowServer: CGXGetWindowWorkspace: invalid window id: b3
112 Nov 26 08:13:43 WindowServer: _CGXRemoveWindowFromWindowMovementGroup: window 0x99 is not attached to window 0x9a
113 Nov 26 08:13:50 WindowServer: _CGXRemoveWindowFromWindowMovementGroup: window 0x99 is not attached to window 0x9a
114 Nov 26 08:17:32 WindowServer: _CGXRemoveWindowFromWindowMovementGroup: window 0x99 is not attached to window 0x9a
115 Nov 26 08:18:04 WindowServer: _CGXRemoveWindowFromWindowMovementGroup: window 0x99 is not attached to window 0x9a
116 Nov 26 08:18:13 WindowServer: _CGXRemoveWindowFromWindowMovementGroup: window 0x99 is not attached to window 0x9a
117 Nov 26 08:23:00 WindowServer: CGXGetWindowWorkspace: invalid window id: 99
118 Nov 26 08:23:39 WindowServer: _CGXRemoveWindowFromWindowMovementGroup: window 0x48 is not attached to window 0x7e
119 Nov 26 08:26:30 WindowServer: _CGXRemoveWindowFromWindowMovementGroup: window 0x48 is not attached to window 0x7e
120 Nov 26 08:27:02 WindowServer: _CGXRemoveWindowFromWindowMovementGroup: window 0x48 is not attached to window 0x7e
121 Nov 26 08:27:36 WindowServer: CGXGetWindowWorkspace: invalid window id: bf
122
123 launchd log
124
125 Nov 26 07:37:59 : Failed to remove file or directory: name = dyld_shared_cache_x86_64, error = 1: Operation not permitted. Further logging suppressed.
126 Nov 26 07:37:59 com.apple.airplaydiagnostics.server: Unrecognized MachService property: ResetAtClose
127 Nov 26 07:38:05 com.apple.xpc.launchd.user.domain.501.100008.Aqua: Could not import service from caller: caller = otherbsd.265, service = com.squirrels.Reflector-2-Helper, error = 119: Service is disabled
128 Nov 26 07:38:05 com.apple.xpc.launchd.user.domain.501.100008.Aqua: Could not import service from caller: caller = otherbsd.265, service = U4MRT5KL8R.com.globaldelight.Voila.MovieTrimHelper, error = 119: Service is disabled
129 Nov 26 07:38:05 com.apple.xpc.launchd.user.domain.501.100008.Aqua: Could not import service from caller: caller = otherbsd.265, service = com.globaldelight.VoilaCapture, error = 119: Service is disabled
130 Nov 26 07:38:05 com.apple.xpc.launchd.user.domain.501.100008.Aqua: Could not import service from caller: caller = otherbsd.265, service = com.bombich.cccuseragent, error = 119: Service is disabled
131
132 Console log
133
134 Nov 25 20:23:52 DatAnywhere: *** LOG MESSAGE QUOTA EXCEEDED - SOME MESSAGES FROM THIS PROCESS HAVE BEEN DISCARDED ***
135 Nov 25 20:42:39 DatAnywhere: *** LOG MESSAGE QUOTA EXCEEDED - SOME MESSAGES FROM THIS PROCESS HAVE BEEN DISCARDED ***
136
137 Loaded kernel extensions
138
139 at.obdev.nke.LittleSnitch (4356)
140 com.eset.kext.esets-kac (601.01.20f01)
141 com.eset.kext.esets-pfw (601.01.20f01)
142 org.virtualbox.kext.VBoxDrv (5.0.10)
143 org.virtualbox.kext.VBoxNetAdp (5.0.10)
144 org.virtualbox.kext.VBoxNetFlt (5.0.10)
145 org.virtualbox.kext.VBoxUSB (5.0.10)
146
147 System services loaded
148
149 at.obdev.littlesnitchd
150 com.apple.logd
151 - status: 1
152 com.apple.watchdogd
153 com.cocoatech.pathfinder.SMFHelper7
154 com.equinux.VPNTracker9.agent
155 com.objectiveSee.blockblock.daemon
156 com.sparklabs.ViscosityHelper
157 com.teamviewer.Helper
158 com.teamviewer.service
159 com.varonis.DatAnywhere.Injector
160 com.varonis.DatAnywhere.Installer
161
162 Login services loaded
163
164 2BUA8C4S2C.com.agilebits.onepassword-osx-helper
165 at.obdev.LittleSnitchUIAgent
166 at.obdev.MicroSnitchOpenAtLoginHelper
167 com.google.keystone.user.agent
168 com.objectiveSee.blockblock.agent
169 com.teamviewer.desktop
170 com.teamviewer.teamviewer
171
172 Login services disabled
173
174 U4MRT5KL8R.com.globaldelight.Voila.MovieTrimHelper
175 com.bombich.cccuseragent
176
177 User services disabled
178
179 U4MRT5KL8R.com.globaldelight.Voila.MovieTrimHelper
180 com.bombich.cccuseragent
181
182 Startup items
183
184 /Library/StartupItems/TuxeraNTFSUnmountHelper/StartupParameters.plist
185 /Library/StartupItems/TuxeraNTFSUnmountHelper/TuxeraNTFSUnmountHelper
186
187 Global login items
188
189 /Applications/ESET Cyber Security.app
190
191 Contents of /Library/LaunchAgents/at.obdev.LittleSnitchUIAgent.plist
192 - mod date: Nov 25 14:42:13 2015
193 - size (B): 464
194 - checksum: 2014742307
195
196 <?xml version="1.0" encoding="UTF-8"?>
197 <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
198 <plist version="1.0">
199 <dict>
200 <key>KeepAlive</key>
201 <true/>
202 <key>Label</key>
203 <string>at.obdev.LittleSnitchUIAgent</string>
204 <key>ProgramArguments</key>
205 <array>
206 <string>/Library/Little Snitch/Little Snitch Agent.app/Contents/MacOS/Little Snitch Agent</string>
207 </array>
208 <key>RunAtLoad</key>
209 <true/>
210 </dict>
211 </plist>
212
213 Contents of /Library/LaunchDaemons/at.obdev.littlesnitchd.plist
214 - mod date: Nov 25 14:42:12 2015
215 - size (B): 631
216 - checksum: 4174275850
217
218 <?xml version="1.0" encoding="UTF-8"?>
219 <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
220 <plist version="1.0">
221 <dict>
222 <key>KeepAlive</key>
223 <true/>
224 <key>Label</key>
225 <string>at.obdev.littlesnitchd</string>
226 <key>ProgramArguments</key>
227 <array>
228 <string>/Library/Little Snitch/Little Snitch Daemon.bundle/Contents/MacOS/Little Snitch Daemon</string>
229 </array>
230 <key>RunAtLoad</key>
231 <true/>
232 <key>StandardErrorPath</key>
233 <string>/Library/Logs/LittleSnitchDaemon.log</string>
234 <key>StandardOutPath</key>
235 <string>/Library/Logs/LittleSnitchDaemon.log</string>
236 </dict>
237 </plist>
238
239 Contents of /Library/LaunchDaemons/com.cocoatech.pathfinder.SMFHelper7.plist
240 - mod date: Nov 25 20:38:58 2015
241 - size (B): 659
242 - checksum: 2550986448
243
244 <?xml version="1.0" encoding="UTF-8"?>
245 <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
246 <plist version="1.0">
247 <dict>
248 <key>Label</key>
249 <string>com.cocoatech.pathfinder.SMFHelper7</string>
250 <key>MachServices</key>
251 <dict>
252 <key>com.cocoatech.pathfinder.SMFHelper7_service</key>
253 <true/>
254 </dict>
255 <key>Program</key>
256 <string>/Library/PrivilegedHelperTools/com.cocoatech.pathfinder.SMFHelper7</str ing>
257 <key>ProgramArguments</key>
258 <array>
259 <string>/Library/PrivilegedHelperTools/com.cocoatech.pathfinder.SMFHelper7</str ing>
260 </array>
261 <key>ThrottleInterval</key>
262 <integer>0</integer>
263 </dict>
264 </plist>
265
266 Contents of /Library/LaunchDaemons/com.equinux.VPNTracker9.agent.plist
267 - mod date: Nov 25 11:57:28 2015
268 - size (B): 848
269 - checksum: 4292790197
270
271 <?xml version="1.0" encoding="UTF-8"?>
272 <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
273 <plist version="1.0">
274 <dict>
275 <key>EnvironmentVariables</key>
276 <dict/>
277 <key>Label</key>
278 <string>com.equinux.VPNTracker9.agent</string>
279 <key>Program</key>
280 <string>/Library/PrivilegedHelperTools/com.equinux.VPNTracker9.agent</string>
281 <key>ProgramArguments</key>
282 <array>
283 <string>/Library/PrivilegedHelperTools/com.equinux.VPNTracker9.agent</string>
284 </array>
285 <key>Sockets</key>
286 <dict>
287 <key>IPCSocket</key>
288 <dict>
289 <key>SockFamily</key>
290 <string>Unix</string>
291 <key>SockPathMode</key>
292 <integer>438</integer>
293 <key>SockPathName</key>
294 <string>/var/run/com.equinux.VPNTracker9.agent.socket</string>
295 <key>SockType</key>
296
297 ...and 5 more line(s)
298
299 Contents of /Library/LaunchDaemons/com.eset.esets_daemon.plist
300 - mod date: Sep 25 19:46:24 2015
301 - size (B): 747
302 - checksum: 1927717527
303
304 <?xml version="1.0" encoding="UTF-8"?>
305 <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
306 <plist version="1.0">
307 <dict>
308 <key>Label</key>
309 <string>com.eset.esets_daemon</string>
310 <key>Program</key>
311 <string>/Applications/ESET Cyber Security.app/Contents/MacOS/esets_ctl</string>
312 <key>RunAtLoad</key>
313 <true/>
314 <key>RootDirectory</key>
315 <string>/</string>
316 <key>KeepAlive</key>
317 <false/>
318 <key>AbandonProcessGroup</key>
319 <false/>
320 <key>ExitTimeOut</key>
321 <integer>65</integer>
322 <key>SoftResourceLimits</key>
323 <dict>
324 <key>NumberOfFiles</key>
325 <integer>1024</integer>
326 </dict>
327 <key>HardResourceLimits</key>
328 <dict>
329
330 ...and 5 more line(s)
331
332 Contents of /Library/LaunchDaemons/com.objectiveSee.blockblock.plist
333 - mod date: Nov 23 14:38:42 2015
334 - size (B): 479
335 - checksum: 2337293076
336
337 <?xml version="1.0" encoding="UTF-8"?>
338 <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
339 <plist version="1.0">
340 <dict>
341 <key>AbandonProcessGroup</key>
342 <true/>
343 <key>Label</key>
344 <string>com.objectiveSee.blockblock.daemon</string>
345 <key>ProgramArguments</key>
346 <array>
347 <string>/Applications/BlockBlock.app/Contents/MacOS/BlockBlock</string>
348 <string>daemon</string>
349 </array>
350 <key>RunAtLoad</key>
351 <true/>
352 </dict>
353 </plist>
354
355 Contents of /Library/LaunchDaemons/com.sparklabs.ViscosityHelper.plist
356 - mod date: Nov 24 21:04:30 2015
357 - size (B): 809
358 - checksum: 2509418150
359
360 <?xml version="1.0" encoding="UTF-8"?>
361 <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
362 <plist version="1.0">
363 <dict>
364 <key>Label</key>
365 <string>com.sparklabs.ViscosityHelper</string>
366 <key>Program</key>
367 <string>/Library/PrivilegedHelperTools/com.sparklabs.ViscosityHelper</string>
368 <key>ProgramArguments</key>
369 <array>
370 <string>/Library/PrivilegedHelperTools/com.sparklabs.ViscosityHelper</string>
371 </array>
372 <key>Sockets</key>
373 <dict>
374 <key>MasterSocket</key>
375 <dict>
376 <key>SockFamily</key>
377 <string>Unix</string>
378 <key>SockPathMode</key>
379 <integer>438</integer>
380 <key>SockPathName</key>
381 <string>/var/run/com.sparklabs.ViscosityHelper.socket</string>
382 <key>SockType</key>
383 <string>Stream</string>
384 </dict>
385
386 ...and 3 more line(s)
387
388 Contents of /Library/LaunchDaemons/com.varonis.DatAnywhere.Injector.plist
389 - mod date: Oct 3 06:35:52 2015
390 - size (B): 593
391 - checksum: 1622748902
392
393 <?xml version="1.0" encoding="UTF-8"?>
394 <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
395 <plist version="1.0">
396 <dict>
397 <key>Label</key>
398 <string>com.varonis.DatAnywhere.Injector</string>
399 <key>MachServices</key>
400 <dict>
401 <key>com.varonis.DatAnywhere.Injector.mach</key>
402 <true/>
403 </dict>
404 <key>Program</key>
405 <string>/Library/PrivilegedHelperTools/com.varonis.DatAnywhere.Injector</string >
406 <key>ProgramArguments</key>
407 <array>
408 <string>/Library/PrivilegedHelperTools/com.varonis.DatAnywhere.Injector</string >
409 </array>
410 </dict>
411 </plist>
412
413 Contents of /Library/LaunchDaemons/com.varonis.DatAnywhere.Installer.plist
414 - mod date: Oct 3 06:35:51 2015
415 - size (B): 597
416 - checksum: 3585503937
417
418 <?xml version="1.0" encoding="UTF-8"?>
419 <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
420 <plist version="1.0">
421 <dict>
422 <key>Label</key>
423 <string>com.varonis.DatAnywhere.Installer</string>
424 <key>MachServices</key>
425 <dict>
426 <key>com.varonis.DatAnywhere.Installer.mach</key>
427 <true/>
428 </dict>
429 <key>Program</key>
430 <string>/Library/PrivilegedHelperTools/com.varonis.DatAnywhere.Installer</strin g>
431 <key>ProgramArguments</key>
432 <array>
433 <string>/Library/PrivilegedHelperTools/com.varonis.DatAnywhere.Installer</strin g>
434 </array>
435 </dict>
436 </plist>
437
438 Contents of /Library/LaunchDaemons/org.virtualbox.startup.plist
439 - mod date: Nov 19 19:35:07 2015
440 - size (B): 76
441 - checksum: 3094394405
442
443 <?xml version="1.0" encoding="UTF-8"?>
444 <!DOCTYPE plist PUBLIC "-//Apple Computer//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
445 <plist version="1.0">
446 <dict>
447 <key>Label</key> <string>org.virtualbox.startup</string>
448 <key>Disabled</key> <false/>
449 <key>RunAtLoad</key> <true/>
450 <key>KeepAlive</key> <false/>
451 <key>LaunchOnlyOnce</key> <true/>
452 <key>ProgramArguments</key>
453 <array>
454 <string>/Library/Application Support/VirtualBox/LaunchDaemons/VirtualBoxStartup.sh</string>
455 <string>restart</string>
456 </array>
457 </dict>
458 </plist>
459
460 Contents of /private/etc/pam.d/esets
461 - mod date: Nov 26 08:29:49 2015
462 - size (B): 210
463 - checksum: 1921608844
464
465 auth required pam_opendirectory.so nullok
466 account required pam_permit.so
467 password required pam_deny.so
468 session required pam_permit.so
469
470 Contents of Library/LaunchAgents/com.google.keystone.agent.plist
471 - mod date: Oct 3 15:31:50 2015
472 - size (B): 799
473 - checksum: 1876572684
474
475 <?xml version="1.0" encoding="UTF-8"?>
476 <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
477 <plist version="1.0">
478 <dict>
479 <key>Label</key>
480 <string>com.google.keystone.user.agent</string>
481 <key>LimitLoadToSessionType</key>
482 <string>Aqua</string>
483 <key>ProgramArguments</key>
484 <array>
485 <string>/Users/USER/Library/Google/GoogleSoftwareUpdate/GoogleSoftwareUpdate.bu ndle/Contents/Resources/GoogleSoftwareUpdateAgent.app/Contents/MacOS/GoogleSoftw areUpdateAgent</string>
486 <string>-runMode</string>
487 <string>ifneeded</string>
488 </array>
489 <key>RunAtLoad</key>
490 <true/>
491 <key>StartInterval</key>
492 <integer>3523</integer>
493 <key>StandardErrorPath</key>
494 <string>/dev/null</string>
495 <key>StandardOutPath</key>
496 <string>/dev/null</string>
497 </dict>
498 </plist>
499
500 Contents of Library/LaunchAgents/com.objectiveSee.blockblock.plist
501 - mod date: Nov 23 14:38:43 2015
502 - size (B): 520
503 - checksum: 3558375073
504
505 <?xml version="1.0" encoding="UTF-8"?>
506 <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
507 <plist version="1.0">
508 <dict>
509 <key>AbandonProcessGroup</key>
510 <true/>
511 <key>Label</key>
512 <string>com.objectiveSee.blockblock.agent</string>
513 <key>ProgramArguments</key>
514 <array>
515 <string>/Applications/BlockBlock.app/Contents/MacOS/BlockBlock</string>
516 <string>agent</string>
517 </array>
518 <key>RunAtLoad</key>
519 <true/>
520 <key>firstTime</key>
521 <string>NO</string>
522 </dict>
523 </plist>
524
525 Contents of Library/LaunchAgents/org.virtualbox.vboxwebsrv.plist
526 - mod date: Nov 19 19:35:09 2015
527 - size (B): 677
528 - checksum: 3654809970
529
530 <?xml version="1.0" encoding="UTF-8"?>
531 <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
532 <plist version="1.0">
533 <dict>
534 <key>Disabled</key>
535 <true/>
536 <key>KeepAlive</key>
537 <false/>
538 <key>Label</key>
539 <string>org.virtualbox.vboxwebsvc</string>
540 <key>Program</key>
541 <string>/Applications/VirtualBox.app/Contents/MacOS/vboxwebsrv</string>
542 <key>Sockets</key>
543 <dict>
544 <key>Listeners</key>
545 <dict>
546 <key>SockServiceName</key>
547 <string>18083</string>
548 <key>SockType</key>
549 <string>stream</string>
550 <key>SockFamily</key>
551 <string>IPv4</string>
552 </dict>
553 </dict>
554 </dict>
555
556 ...and 1 more line(s)
557
558 Bad plists
559
560 Library/Preferences/com.screenlabs.Orange.plist
561 Library/Preferences/org.boxsource.Satellite.plist
562
563 User login items
564
565 iTunesHelper
566 - /Applications/iTunes.app/Contents/MacOS/iTunesHelper.app
567 Contacts
568 - /Applications/Contacts.app
569 Calendar
570 - /Applications/Calendar.app
571 Mail
572 - /Applications/Mail.app
573 Messages
574 - /Applications/Messages.app
575 Path Finder
576 - /Applications/Path Finder.app
577 DatAnywhere
578 - /Applications/DatAnywhere.app
579 VMware Fusion Start Menu
580 - /Applications/VMware Fusion.app/Contents/Library/VMware Fusion Start Menu.app
581 Google Drive
582 - /Applications/Google Drive.app
583 HyperDock Helper
584 - /Library/PreferencePanes/HyperDock.prefpane/Contents/Resources/HyperDock Helper.app
585 Google Photos Backup
586 - /Applications/Google Photos Backup.app
587 BitTorrent Sync
588 - missing value
589 Bleep
590 - missing value
591 Google Chrome
592 - /Applications/Google Chrome.app
593 CCC User Agent
594 - /Applications/Carbon Copy Cloner.app/Contents/Library/LoginItems/CCC User Agent.app
595 WaltrAgent
596 - missing value
597 Flickr Uploadr
598 - missing value
599 ESET Cyber Security
600 - /Applications/ESET Cyber Security.app
601
602 Safari extensions
603
604 1Password
605 - com.agilebits.onepassword4-safari
606 AdBlock
607 - com.betafish.adblockforsafari
608 Ghostery
609 - com.betteradvertising.ghostery
610
611 iCloud errors
612
613 cloudd 35
614 bird 8
615 comapple.CloudPhotosConfiguration 1
616 Finder 1
617
618 Continuity errors
619
620 sharingd 28
621
622 Restricted files: 191
623
624 Lockfiles: 6
625
626 Global prefs (user)
627
628 ContextMenuGesture = 1
629
630 Extensions
631
632 /Library/Extensions/LittleSnitch.kext
633 - at.obdev.nke.LittleSnitch
634 /Library/Extensions/com.equinux.VPNTracker9.kext
635 - com.equinux.VPNTracker9
636
637 Applications
638
639 /Applications/WinBox.app
640 - 50874520349566134.wineskin.prefs
641 /Users/USER/Applications/Chrome Apps.localized/Default apdfllckaahabafndbhieahigkjlhalf.app
642 - com.google.Chrome.app.Default-apdfllckaahabafndbhieahigkjlhalf
643 /Users/USER/Applications/Chrome Apps.localized/Default blpcfgokakmgnkcojhhkbfbldkacnbeo.app
644 - com.google.Chrome.app.Default-blpcfgokakmgnkcojhhkbfbldkacnbeo
645 /Users/USER/Applications/Chrome Apps.localized/Default coobgpohoikkiipiblmjeljniedjpjpf.app:́vání Google:
646 - N/A
647 /Users/USER/Applications/Chrome Apps.localized/Default ejidjjhkpiempkbhmpbfngldlkglhimk.app
648 - com.google.Chrome.app.Default-ejidjjhkpiempkbhmpbfngldlkglhimk
649 /Users/USER/Applications/Chrome Apps.localized/Default ejjicmeblgpmajnghnpcppodonldlgfn.app
650 - com.google.Chrome.app.Default-ejjicmeblgpmajnghnpcppodonldlgfn
651 /Users/USER/Applications/Chrome Apps.localized/Default knipolnnllmklapflnccelgolnpehhpl.app
652 - com.google.Chrome.app.Default-knipolnnllmklapflnccelgolnpehhpl
653 /Users/USER/Applications/Chrome Apps.localized/Default pjkljhegncpnkpknbcohdijeoejaedia.app
654 - com.google.Chrome.app.Default-pjkljhegncpnkpknbcohdijeoejaedia
655 /Users/USER/Documents/copy/Desktop/Desktop/AirRadar.app
656 - com.koingosw.AirRadar
657 /Users/USER/Documents/copy/Desktop/Desktop/CLIX/CLIX-32/CLIX.app
658 - com.rixstep.CLIX
659 /Users/USER/Documents/copy/Desktop/Desktop/CLIX/CLIX-64/CLIX.app
660 - com.rixstep.CLIX
661 /Users/USER/Documents/copy/Desktop/Desktop/SpotlightMetadata.app
662 - com.HAMSoft.SpotlightMetadata
663 /Users/USER/Documents/copy/Desktop/Desktop/Vidnik.app
664 - com.google.code.vidnik
665 /Users/USER/Documents/copy/Desktop/Desktop/World of Goo.app
666 - com.2dboy.wog
667 /Users/USER/Documents/copy/Desktop/Desktop/iPhoneTracker.app
668 - com.yourcompany.iPhoneTracker
669 /Users/USER/Documents/copy/Downloads/GoodReaderUSB.app
670 - com.goodiware.GoodReaderUSB
671 /Users/USER/Documents/copy/Downloads/ImageOptim.app
672 - net.pornel.ImageOptim
673 /Users/USER/Documents/copy/Downloads/Sachesi-2.app
674 - com.yourcompany.Sachesi
675 /Users/USER/Documents/copy/Downloads/Sachesi-3.app
676 - com.yourcompany.Sachesi
677 /Users/USER/Documents/copy/Downloads/WhatsMac.app
678 - com.samstone.WhatsMac
679 /Users/USER/Downloads/teleport/teleport.app
680 - com.abyssoft.teleport
681 /Users/USER/Library/Application Support/Google/Chrome/Default/Web Applications/_crx_aohghmighlieiainnegkcijnfilokake/Default aohghmighlieiainnegkcijnfilokake.app
682 - com.google.Chrome.app.Default-aohghmighlieiainnegkcijnfilokake-internal
683 /Users/USER/Library/Application Support/Google/Chrome/Default/Web Applications/_crx_apdfllckaahabafndbhieahigkjlhalf/Default apdfllckaahabafndbhieahigkjlhalf.app
684 - com.google.Chrome.app.Default-apdfllckaahabafndbhieahigkjlhalf-internal
685 /Users/USER/Library/Application Support/Google/Chrome/Default/Web Applications/_crx_blpcfgokakmgnkcojhhkbfbldkacnbeo/Default blpcfgokakmgnkcojhhkbfbldkacnbeo.app
686 - com.google.Chrome.app.Default-blpcfgokakmgnkcojhhkbfbldkacnbeo-internal
687 /Users/USER/Library/Application Support/Google/Chrome/Default/Web Applications/_crx_coobgpohoikkiipiblmjeljniedjpjpf/Default coobgpohoikkiipiblmjeljniedjpjpf.app:́vání Google:
688 - N/A
689 /Users/USER/Library/Application Support/Google/Chrome/Default/Web Applications/_crx_ejidjjhkpiempkbhmpbfngldlkglhimk/Default ejidjjhkpiempkbhmpbfngldlkglhimk.app
690 - com.google.Chrome.app.Default-ejidjjhkpiempkbhmpbfngldlkglhimk-internal
691 /Users/USER/Library/Application Support/Google/Chrome/Default/Web Applications/_crx_ejjicmeblgpmajnghnpcppodonldlgfn/Default ejjicmeblgpmajnghnpcppodonldlgfn.app
692 - com.google.Chrome.app.Default-ejjicmeblgpmajnghnpcppodonldlgfn-internal
693 /Users/USER/Library/Application Support/Google/Chrome/Default/Web Applications/_crx_kkgpfcbanbnipdjijjaljkhhlhaiehpo/Default kkgpfcbanbnipdjijjaljkhhlhaiehpo.app
694 - com.google.Chrome.app.Default-kkgpfcbanbnipdjijjaljkhhlhaiehpo-internal
695 /Users/USER/Library/Application Support/Google/Chrome/Default/Web Applications/_crx_knipolnnllmklapflnccelgolnpehhpl/Default knipolnnllmklapflnccelgolnpehhpl.app
696 - com.google.Chrome.app.Default-knipolnnllmklapflnccelgolnpehhpl-internal
697 /Users/USER/Library/Application Support/Google/Chrome/Default/Web Applications/_crx_pjkljhegncpnkpknbcohdijeoejaedia/Default pjkljhegncpnkpknbcohdijeoejaedia.app
698 - com.google.Chrome.app.Default-pjkljhegncpnkpknbcohdijeoejaedia-internal
699 /Users/USER/Library/Application Support/WebEx Folder/Add-ons/Cisco WebEx Start.app
700 - com.cisco.webex.Cisco-WebEx-Start
701 /Users/USER/Library/Printers/Assistant Xerox.app
702 - com.apple.print.PrinterProxy
703 /Users/USER/Library/Printers/OKI-MC352-B61DF7.app
704 - com.apple.print.PrinterProxy
705
706 Frameworks
707
708 /Library/Frameworks/mach_inject_bundle.framework
709 - com.rentzsch.mach_inject_bundle
710
711 PrefPane
712
713 /Library/PreferencePanes/HyperDock.prefpane
714 - de.bahoom.HyperDock.prefpane
715 /Library/PreferencePanes/Tuxera NTFS.prefPane
716 - com.tuxera.ntfs.mac.prefpane
717
718 Bundles
719
720 /Library/Internet Plug-Ins/WebVideoPlugin.plugin
721 - com.hikvision.WebVideoPlugin
722 /Users/USER/Library/Address Book Plug-Ins/SkypeABCaller.bundle
723 - com.skype.SkypeABCaller
724 /Users/USER/Library/Address Book Plug-Ins/SkypeABChatter.bundle
725 - com.skype.SkypeABChatter
726 /Users/USER/Library/Address Book Plug-Ins/SkypeABDialer.bundle
727 - com.skype.skypeabdialer
728 /Users/USER/Library/Address Book Plug-Ins/SkypeABSMS.bundle
729 - com.skype.skypeabsms
730 /Users/USER/Library/Application Support/Google/Chrome/PepperFlash/19.0.0.226/PepperFlashPlayer.plugin
731 - com.macromedia.PepperFlashPlayer.pepper
732 /Users/USER/Library/Internet Plug-Ins/WebEx64.plugin
733 - com.cisco_webex.plugin.gpc64
734
735 Bundles (new)
736
737 /Applications/AppDelete.app
738 - com.apps4macs.AppDelete
739 /Applications/BlockBlock.app
740 - com.objectivesee.BlockBlock
741 /Applications/Little Snitch Configuration.app
742 - at.obdev.LittleSnitchConfiguration
743 /Applications/Path Finder.app
744 - com.cocoatech.PathFinder
745 /Applications/VPN Tracker 9.app
746 - com.equinux.VPNTracker9
747 /Applications/VirtualBox.app
748 - org.virtualbox.app.VirtualBox
749 /Applications/Viscosity.app
750 - com.viscosityvpn.Viscosity
751 /Library/Little Snitch/Little Snitch Agent.app
752 - at.obdev.LittleSnitchAgent
753 /Library/Little Snitch/Little Snitch Daemon.bundle
754 - at.obdev.LittleSnitchDaemon
755 /Library/Little Snitch/Little Snitch Network Monitor.app
756 - at.obdev.LittleSnitchNetworkMonitor
757 /Library/Little Snitch/Little Snitch Software Update.app
758 - at.obdev.LittleSnitchSoftwareUpdate
759 /Library/Little Snitch/Little Snitch Uninstaller.app
760 - at.obdev.LittleSnitchUninstaller
761 /System/Library/Intelligent Suggestions/Assets.suggestionsassets
762 - com.apple.MobileAsset.CoreSuggestions
763 /Users/USER/Applications/Chrome Apps.localized/Default knipolnnllmklapflnccelgolnpehhpl.app
764 - com.google.Chrome.app.Default-knipolnnllmklapflnccelgolnpehhpl
765 /Users/USER/Downloads/DHS.app
766 - com.objective-see.DHS
767 /Users/USER/Downloads/KextViewr.app
768 - com.objective-see.KextViewr
769 /Users/USER/Downloads/KnockKnock.app
770 - com.objective-see.KnockKnock
771 /Users/USER/Downloads/TaskExplorer.app
772 - com.objective-see.TaskExplorer
773 /Users/USER/Library/Application Support/Flickr/UpdateCache/1448284540/Flickr Uploadr.app
774 - com.yahoo.flickrmac
775 /Users/USER/Library/Application Support/Google/Chrome/Default/Web Applications/_crx_knipolnnllmklapflnccelgolnpehhpl/Default knipolnnllmklapflnccelgolnpehhpl.app
776 - com.google.Chrome.app.Default-knipolnnllmklapflnccelgolnpehhpl-internal
777
778 Library paths
779
780 /Users/USER/Documents/DatAnywhere/FD_Sandro/001_Sandro/Sandro/1Password/Extensi ons/30700/EMAIL/components/libosxform_xpcom.dylib
781 /Users/USER/Documents/DatAnywhere/FD_Sandro/001_Sandro/Sandro/1Password/Extensi ons/30709/EMAIL/components/libosxform_xpcom.dylib
782 /Users/USER/Documents/copy/Documents/Password/1Password/Extensions/31419/EMAIL/ components/libosxform_xpcom.dylib
783 /Users/USER/Documents/copy/Documents/Password/1Password/Extensions/31419/EMAIL/ components/libosxform_xpcom.dylib
784 /Users/USER/Documents/copy/Documents/Password/1Password/Extensions/31499/EMAIL/ components/libosxform_xpcom.dylib
785 /Users/USER/Documents/copy/Documents/Password/1Password/Extensions/31499/EMAIL/ components/libosxform_xpcom.dylib
786 /Users/USER/Documents/copy/Documents/Password/1Password/Extensions/32009/EMAIL/ components/libosxform_xpcom.dylib
787 /Users/USER/Documents/copy/Documents/Password/1Password/Extensions/32009/EMAIL/ components/libosxform_xpcom.dylib
788 /Users/USER/Library/Application Support/Firefox/Profiles/eg714s2a.default/gmp-gmpopenh264/1.4/libgmpopenh264.dy lib
789 /Users/USER/Library/Application Support/Google/Chrome/WidevineCDM/1.4.8.824/_platform_specific/mac_x64/libwidev inecdm.dylib
790 /Users/USER/Library/Application Support/WebEx Folder/1524/cmcrypto-29.13.0.2.dylib
791 /Users/USER/Library/Application Support/WebEx Folder/1524/libcrypto-0.2.5.4.dylib
792 /Users/USER/Library/Application Support/WebEx Folder/1524/libssl-0.2.5.4.dylib
793 /Users/USER/Library/Application Support/WebEx Folder/1524/xml-29.0.0.1.dylib
794
795 App extensions
796
797 com.agilebits.onepassword-osx.safariextensioncompanion
798 com.google.GoogleDrive.FinderSyncAPIExtension
799 com.pixelmatorteam.pixelmator.Repair-Tool-Action-Extension
800 com.pixelmatorteam.pixelmator.photos-distort-extension
801 com.varonis.DatAnywhere.DNFinderSync
802
803 Modifications
804
805 file missing: /Applications/Fotolab Fotosvet.app/Contents/Resources/photofun/icons/svg_not_ready_2.svg
806 file added: /Applications/VLC.app/Contents/MacOS/plugins/plugins.dat
807 file added: /Applications/VMware Fusion.app/Contents/Library/isoimages/darwin.iso
808 file added: /Applications/VMware Fusion.app/Contents/Library/isoimages/darwin.iso.sig
809 file added: /Applications/VMware Fusion.app/Contents/Library/isoimages/freebsd.iso
810 file added: /Applications/VMware Fusion.app/Contents/Library/isoimages/freebsd.iso.sig
811 file added: /Applications/VMware Fusion.app/Contents/Library/isoimages/linux.iso
812 file added: /Applications/VMware Fusion.app/Contents/Library/isoimages/linux.iso.sig
813 file added: /Applications/VMware Fusion.app/Contents/Library/isoimages/netware.iso
814 file added: /Applications/VMware Fusion.app/Contents/Library/isoimages/netware.iso.sig
815 file added: /Applications/VMware Fusion.app/Contents/Library/isoimages/solaris.iso
816 file added: /Applications/VMware Fusion.app/Contents/Library/isoimages/solaris.iso.sig
817 ...
818 file modified: /Library/Frameworks/mach_inject_bundle.framework/Versions/Current/Resources/mac h_inject_bundle_stub.bundle/Contents/MacOS/mach_inject_bundle_stub
819
820 Bad kernel extensions
821
822 /System/Library/Extensions/AppleOSXUSBNCM.kext
823
824 Installations
825
826 Oracle VM VirtualBox: 19.11.15 19:35
827 TeamViewer: 12.11.15 11:44
828 WiFi Scanner: 12.11.15 8:21
829 Microsoft Remote Desktop: 05.11.15 20:55
830 iThoughtsX: 05.11.15 8:19
831
832 Elapsed time (sec): 587