I think someone is spying on me :(

Hi all, new to the community and was just wondering if anyone could help me.


I've noticed some strange activities happening recently on my mac.


Like application closing themselves, strange things on my console and messages saying someone is sharing my I.P. address but the main one is videos pausing themselves. I could put this down to coincidence however last an audio book I was listening to on VLC player kept pausing itself so I decided to check my console to see if anything showed up. At the exact same time time of the video pausing it shows up that my network and my country code had changed and something about my DNS changing. please see the screenshots below


User uploaded file

User uploaded file


I've also seen this in my console before. So next step was I looked up ways to detect if your mac is being spied on and found this thread


Detect spyware and determine who is spying on my imac


Which tells me to check my terminal. I should state at this point that I know of terminal but never use it. So I open terminal and am greeted with the message that I had logged in two days ago, I never use terminal so this would leave me to believe someone has some sort of remote access to my MAC?. This is the message I got after typing in a code suggested in the link^^^


User uploaded file


Anyway I would be very grateful to any kind soul who can give me a bit of guidance. This has been going on for quite some time now and is really starting to take up too much of my time and stress. Am I paranoid or is the evidence above reason for concern? are there any steps I can take to know for certain?


Many Thanks.

Posted on Jul 14, 2017 3:47 AM

Reply
12 replies

Jul 14, 2017 6:28 AM in response to dublindublin

Please post the EtreCheck output

<https://discussions.apple.com/docs/DOC-6174> or <https://etrecheck.com>

Use the EtreCheck "Share" button to "Copy to clipboard" (See the image below)

User uploaded file

If, when trying to post the output, you get the error:

"The message contains invalid characters"

then try posting to PasteBin.com, and give us a pointer.

<http://pastebin.com/>

.

EtreCheck is a tool that helps Apple Support Community volunteers debug problems without any access to the troubled computers. Debugging problems can be a difficult task even when the machine is in front of you. Attempting it via a discussion forum is extremely difficult. EtreCheck is a great help that regards.

Jul 14, 2017 7:50 AM in response to BobHarris

Hi thanks for the reply here it is-

EtreCheck version: 3.4 (420)

Report generated 2017-07-14 15:49:35

Download EtreCheck from https://etrecheck.com

Runtime: 19:16

Performance: Poor


Click the [Lookup] links for more information from Apple Support Communities.

Click the [Details] links for more information about that line.


Problem: No problem - just checking


Hardware Information:

MacBook Pro (13-inch, Mid 2012)

[Technical Specifications] - [User Guide] - [Warranty & Service]

MacBook Pro - model: MacBookPro9,2

1 2.5 GHz Intel Core i5 (i5-3210M) CPU: 2-core

4 GB RAM Upgradeable - [Instructions]

BANK 0/DIMM0

2 GB DDR3 1600 MHz ok

BANK 1/DIMM0

2 GB DDR3 1600 MHz ok

Bluetooth: Good - Handoff/Airdrop2 supported

Wireless:
en1: 802.11 a/b/g/n

Battery: Health = Replace Soon - Cycle count = 1620


Video Information:

Intel HD Graphics 4000 - VRAM: 1024 MB

Color LCD 1280 x 800


Disk Information:

ST1000LM014-1EJ164-SSHD disk0: (1 TB) (Rotational)

[Show SMART report]

(disk0s1) <not mounted>
[EFI]: 210 MB

(disk0s2) <not mounted>
[CoreStorage Container]: 999.35 GB

(disk0s3) <not mounted>
[Recovery]: 650 MB


HL-DT-ST DVDRW
GS31N
()


USB Information:

XHCI Root Hub SS Simulation

XHCI Root Hub USB 2.0 Simulation

EHCI Root Hub Simulation

hub_device

Apple Inc. FaceTime HD Camera (Built-in)

EHCI Root Hub Simulation

hub_device

hub_device

Apple Inc. Apple Internal Keyboard / Trackpad

Apple Inc. BRCM20702 Hub

Apple Inc. Bluetooth USB Host Controller

Apple Computer, Inc. IR Receiver


Thunderbolt Information:

Apple Inc. thunderbolt_bus


Virtual disks:

Untitled 1 (disk1 - Journaled HFS+) /
[Startup]: 998.97 GB (574.27 GB free)

Physical disk: disk0s2 999.35 GB Online


System Software:

OS X Yosemite 10.10.5 (14F2411) - Time since boot: about 2 days


Configuration files:

/etc/hosts - Count: 21


Gatekeeper:

Mac App Store and identified developers


Kernel Extensions:

/Library/Extensions

[loaded] com.globaldelight.driver.Boom2Device (1.2 - SDK 10.10) [Lookup]


System Launch Agents:

[not loaded] 5 Apple tasks

[loaded] 147 Apple tasks

[running] 49 Apple tasks

[killed] 11 Apple tasks

11 processes killed due to insufficient RAM


System Launch Daemons:

[not loaded] 47 Apple tasks

[loaded] 136 Apple tasks

[running] 71 Apple tasks

[killed] 7 Apple tasks

7 processes killed due to insufficient RAM


Launch Agents:

[not loaded] com.adobe.AAM.Updater-1.0.plist (Adobe Systems, Inc. - installed 2016-02-27) [Lookup]

[running] com.adobe.AdobeCreativeCloud.plist (Adobe Systems, Inc. - installed 2015-08-18) [Lookup]

[failed] com.adobe.CS5ServiceManager.plist (? 40cdc1ff dd391a6f - installed 2016-02-22) [Lookup]


Launch Daemons:

[loaded] com.adobe.SwitchBoard.plist (? 856489a3 0 - installed 2016-02-22) [Lookup]

[running] com.adobe.adobeupdatedaemon.plist (Adobe Systems, Inc. - installed 2015-08-18) [Lookup]

[loaded] com.adobe.fpsaud.plist (? 2afb3af7 a0305b84 - installed 2017-06-15) [Lookup]

[loaded] com.malwarebytes.HelperTool.plist (Malwarebytes Corporation - installed 2017-07-08) [Lookup]


User Launch Agents:

[loaded] com.adobe.AAM.Updater-1.0.plist (Adobe Systems, Inc. - installed 2015-08-19) [Lookup]

[loaded] com.dropbox.DropboxMacUpdate.agent.plist (Dropbox, Inc. - installed 2017-07-13) [Lookup]

[loaded] com.google.keystone.agent.plist (Google, Inc. - installed 2017-03-29) [Lookup]

[running] com.spotify.webhelper.plist (Spotify - installed 2017-07-08) [Lookup]


User Login Items:

Flux Application

(/Applications/Flux.app)

iTunesHelper Application (? 0 - installed 2017-05-23)

(/Applications/iTunes.app/Contents/MacOS/iTunesHelper.app)

uTorrent Application

(/Applications/uTorrent.app)

Spotify Application - Hidden

(/Applications/Spotify.app)

Dropbox Application

(/Applications/Dropbox.app)

com.adobe.SwitchBoard.monitor.plist MachInit - Hidden

(/etc/mach_init_per_user.d/com.adobe.SwitchBoard.monitor.plist)

Mach Init items are deprecated


Internet Plug-ins:

FlashPlayer-10.6: 26.0.0.131 (installed 2017-07-04) [Lookup]

QuickTime Plugin: 7.7.3 (installed 2017-07-08)

Flash Player: 26.0.0.131 (installed 2017-07-04) Outdated! Update

PepperFlashPlayer: 24.0.0.221 (installed 2017-03-09) [Lookup]

AdobeAAMDetect: 3.0.0.0 (installed 2015-08-18) [Lookup]

Default Browser: 600 (installed 2015-10-26)


Safari Extensions:

AdBlock - BetaFish, Inc. - https://getadblock.com (installed 2015-10-15)


3rd Party Preference Panes:

Flash Player (installed 2017-06-15) [Lookup]


Time Machine:

Time Machine not configured!


Top Processes by CPU:

35%
Google Chrome Helper

12%
kernel_task

8%
WindowServer

7%
Google Chrome

5%
systemstatsd


Top Processes by Memory:

472 MB kernel_task

340 MB Google Chrome Helper

256 MB systemstatsd

206 MB Google Chrome Helper

132 MB Google Chrome


Top Processes by Energy Use:

35.22 Google Chrome Helper

10.22 Google Chrome

8.94 WindowServer

7.06 systemstatsd

5.94 coreaudiod


Virtual Memory Information:

764 MB Available RAM

17 MB Free RAM

3.25 GB
Used RAM

747 MB Cached files

525 MB Swap Used


Software installs:

MacKeeper:
(installed 2017-07-04)

MacKeeper:
(installed 2017-07-04)


Install information may not be complete.


Diagnostics Information:

2017-07-13 18:19:48 Adobe Illustrator.app Hang [Open]

2017-07-12 11:32:08 Spotify.app Hang [Open]

2017-07-12 11:29:25 Dropbox.app Crash [Open]

Cause: objc_msgSend() selector name: respondsToSelector:


Files deleted by EtreCheck:

2017-07-08 15:13:22 - ~/Library/LaunchAgents/com.bittorrent.uTorrent.plist - Unknown

2017-07-08 15:13:22 - ~/Library/LaunchAgents/com.spigot.ApplicationManager.plist - Unknown

2017-07-08 15:13:32 - /Library/LaunchDaemons/com.apple.quoroden.plist - Unknown

2017-07-08 15:13:32 - /Library/LaunchDaemons/com.apple.usktas.plist - Unknown

2017-07-08 15:14:07 - /Library/LaunchDaemons/com.apple.quoroden.plist - Unknown

2017-07-08 15:14:07 - /Library/LaunchDaemons/com.apple.usktas.plist - Unknown

2017-07-08 15:14:23 - /Library/LaunchDaemons/com.apple.quoroden.plist - Unknown

2017-07-08 15:14:23 - /Library/LaunchDaemons/com.apple.usktas.plist - Unknown

2017-07-08 15:14:48 - ~/Library/LaunchAgents/com.pseudoalkaloid.plist - Unknown

2017-07-08 15:14:51 - /Library/LaunchDaemons/com.apple.quoroden.plist - Unknown

2017-07-08 15:14:51 - /Library/LaunchDaemons/com.apple.usktas.plist - Unknown

2017-07-08 15:15:13 - /Library/LaunchDaemons/com.apple.quoroden.plist - Unknown

2017-07-08 15:15:13 - /Library/LaunchDaemons/com.apple.usktas.plist - Unknown

2017-07-08 15:15:48 - /Library/LaunchDaemons/com.apple.quoroden.plist - Unknown

2017-07-08 15:15:48 - /Library/LaunchDaemons/com.apple.usktas.plist - Unknown

2017-07-08 15:16:39 - /Library/LaunchDaemons/com.apple.quoroden.plist - Unknown

2017-07-08 15:16:39 - /Library/LaunchDaemons/com.apple.usktas.plist - Unknown

2017-07-08 15:17:15 - /Library/LaunchDaemons/com.apple.quoroden.plist - Unknown

2017-07-08 15:17:15 - /Library/LaunchDaemons/com.apple.usktas.plist - Unknown

2017-07-08 15:18:01 - /Library/LaunchDaemons/com.apple.quoroden.plist - Unknown

2017-07-08 15:18:01 - /Library/LaunchDaemons/com.apple.usktas.plist - Unknown

2017-07-08 15:18:14 - /Library/LaunchDaemons/com.apple.quoroden.plist - Unknown

2017-07-08 15:18:14 - /Library/LaunchDaemons/com.apple.usktas.plist - Unknown

2017-07-08 15:18:32 - /Library/LaunchDaemons/com.apple.quoroden.plist - Unknown

2017-07-08 15:18:32 - /Library/LaunchDaemons/com.apple.usktas.plist - Unknown

2017-07-08 15:21:09 - /Library/LaunchDaemons/com.apple.quoroden.plist - Unknown

2017-07-08 15:21:09 - /Library/LaunchDaemons/com.apple.usktas.plist - Unknown

2017-07-08 15:22:52 - /Library/LaunchAgents/com.Pirene.plist - Unknown

2017-07-08 15:22:52 - /Library/LaunchDaemons/com.gooyzftjjcbr.plist - Unknown

2017-07-08 15:22:52 - /Library/LaunchDaemons/com.vVEdoRBP.plist - Unknown

2017-07-08 15:22:52 - /Library/LaunchDaemons/com.zpxlqslogzbz.plist - Unknown


Jul 14, 2017 10:17 AM in response to dublindublin

It appears you are not booting from your internal disk

Disk Information:

ST1000LM014-1EJ164-SSHD disk0: (1 TB) (Rotational)

[Show SMART report]

(disk0s1) <not mounted>
[EFI]: 210 MB

(disk0s2) <not mounted>
[CoreStorage Container]: 999.35 GB

(disk0s3) <not mounted>
[Recovery]: 650 MB

Is that true? Or is EtreCheck giving us bad information?


Your system could use more RAM, or you need to cut back on high resource consuming apps, such as Chrome.


I'm not sure what this kernel extension is doing for you

Kernel Extensions:

/Library/Extensions

[loaded] com.globaldelight.driver.Boom2Device (1.2 - SDK 10.10) [Lookup]


Otherwise, I do not see anything that would be spying on you.


If you really think someone is spying on you, then backup (2 separate backups to 2 separate devices using 2 different backup utilities would be safer), totally erase your system, install a clean version of macOS, then restore ONLY your user data, and install any applications with clean copies from the vendor.

Jul 19, 2017 8:42 AM in response to dublindublin

You seem to have MacKeeper installed.


Do not install MacKeeper (and how to uninstall it if you have):

https://discussions.apple.com/docs/DOC-6221


It contains a major security flaw, recently noted:


http://www.macnn.com/articles/15/05/08/contentious.utility.ignored.apple.guideli nes.created.zero.day.exploit.128538/


There is currently a class-action against MacKeeper:


http://www.macworld.com/article/2927032/ads-for-mackeeper-refunds-will-run-on-fa cebook.html#tk.nl_mwbest


(Please note that references to the original developers, Zeobit, also now refer to Kromtech Alliance Corp, who acquired MacKeeper and PCKeeper from ZeoBit LLC in early 2013.) And in that context the foregoing also applies to their latest offering,AdwareBuster, which was quickly found to not identify much of the adware around.

Jul 20, 2017 6:53 AM in response to dublindublin

dublindublin wrote:


Thanks for the reply, but any idea why my country code keeps changing on my console?

No I do not.


Maybe start a new post, only this time do not start with a conclusion of spying, and ask about why a country code would change.


PS. I was wrong about my assumption of booting on an external disk. EtreCheck changed the way it was reporting some information, and I misinterpreted it. Sorry about that.

Jul 20, 2017 4:35 AM in response to BobHarris

Hi Bob, he is booting from the main disk: look at "virtual disk" in the list: a new "gimmick" in ertecheck.app.

His problem is probably not macKeeper, because there is nothing in the LaunchAgents and LaunchDaemons. Of course it can be that before he uninstalled it he has done "wrong" things with it.

His problem is more likely to come from the torrents and torrents app: all torrent apps are broadcasting user data to the wrong "listeners" in internet. He should remove utorrent from the LoginItems, then restart and uninstall utorrent.

Also he should remove AdobeResourceSynchroniser from the LoginItems: a resource hugger that is for Adobe information only, it does nothing for the user. I would also remove Spotlight from the LoginItems: it is already running always, so it does not have to be started.

Lex

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

I think someone is spying on me :(

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.