Have I been hacked? (Repeating APSD messages and hosts file not working)

Hi,


I keep getting these repeat Console messages on my root user even if I am not using the computer (and it had went on for days), may I know what is happening? (My hosts file is also weirdly not working)


8/5/18 4:53:57.088 PM apsd[81]: Unexpected replacement of connection in <APSConnectionServer: 0x7ffc0bd761b0>

8/5/18 4:53:57.282 PM apsd[81]: Unexpected replacement of connection in <APSConnectionServer: 0x7ffc0bd761b0>

8/5/18 4:53:57.487 PM apsd[81]: Unexpected replacement of connection in <APSConnectionServer: 0x7ffc0bd761b0>

8/5/18 4:53:57.542 PM launchservicesd[82]: Process 933 (Activity Monitor.app) attempted to bypass check for entitlement "com.apple.private.launchservices.allowedtoget.LSActivePageUserVisibleOriginsKe y" while running as root. This is no longer a supported configuration. Please file a radar against that process to adopt that entitlement.

8/5/18 4:53:57.683 PM apsd[81]: Unexpected replacement of connection in <APSConnectionServer: 0x7ffc0bd761b0>

8/5/18 4:53:57.888 PM apsd[81]: Unexpected replacement of connection in <APSConnectionServer: 0x7ffc0bd761b0>

8/5/18 4:53:58.054 PM apsd[81]: Unexpected replacement of connection in <APSConnectionServer: 0x7ffc0bd761b0>

8/5/18 4:53:58.247 PM apsd[81]: Unexpected replacement of connection in <APSConnectionServer: 0x7ffc0bd761b0>

8/5/18 4:53:58.392 PM apsd[81]: Unexpected replacement of connection in <APSConnectionServer: 0x7ffc0bd761b0>

8/5/18 4:53:58.592 PM apsd[81]: Unexpected replacement of connection in <APSConnectionServer: 0x7ffc0bd761b0>

8/5/18 4:53:58.796 PM apsd[81]: Unexpected replacement of connection in <APSConnectionServer: 0x7ffc0bd761b0>

8/5/18 4:53:58.997 PM apsd[81]: Unexpected replacement of connection in <APSConnectionServer: 0x7ffc0bd761b0>

8/5/18 4:53:59.194 PM apsd[81]: Unexpected replacement of connection in <APSConnectionServer: 0x7ffc0bd761b0>

8/5/18 4:53:59.398 PM apsd[81]: Unexpected replacement of connection in <APSConnectionServer: 0x7ffc0bd761b0>

8/5/18 4:53:59.604 PM apsd[81]: *** LOG MESSAGE QUOTA EXCEEDED - SOME MESSAGES FROM THIS PROCESS HAVE BEEN DISCARDED ***

8/5/18 4:54:00.002 PM apsd[81]: Unexpected replacement of connection in <APSConnectionServer: 0x7ffc0bd761b0>

8/5/18 4:54:01.985 PM launchservicesd[82]: Process 933 (Activity Monitor.app) attempted to bypass check for entitlement "com.apple.private.launchservices.allowedtoget.LSActivePageUserVisibleOriginsKe y" while running as root. This is no longer a supported configuration. Please file a radar against that process to adopt that entitlement.

8/5/18 4:54:07.289 PM launchservicesd[82]: Process 933 (Activity Monitor.app) attempted to bypass check for entitlement "com.apple.private.launchservices.allowedtoget.LSActivePageUserVisibleOriginsKe y" while running as root. This is no longer a supported configuration. Please file a radar against that process to adopt that entitlement.

8/5/18 4:54:12.138 PM launchservicesd[82]: Process 933 (Activity Monitor.app) attempted to bypass check for entitlement "com.apple.private.launchservices.allowedtoget.LSActivePageUserVisibleOriginsKe y" while running as root. This is no longer a supported configuration. Please file a radar against that process to adopt that entitlement.

8/5/18 4:54:17.253 PM launchservicesd[82]: Process 933 (Activity Monitor.app) attempted to bypass check for entitlement "com.apple.private.launchservices.allowedtoget.LSActivePageUserVisibleOriginsKe y" while running as root. This is no longer a supported configuration. Please file a radar against that process to adopt that entitlement.

8/5/18 4:54:22.135 PM launchservicesd[82]: Process 933 (Activity Monitor.app) attempted to bypass check for entitlement "com.apple.private.launchservices.allowedtoget.LSActivePageUserVisibleOriginsKe y" while running as root. This is no longer a supported configuration. Please file a radar against that process to adopt that entitlement.

8/5/18 4:54:26.000 PM syslogd[858]: ASL Sender Statistics

8/5/18 4:54:27.198 PM launchservicesd[82]: Process 933 (Activity Monitor.app) attempted to bypass check for entitlement "com.apple.private.launchservices.allowedtoget.LSActivePageUserVisibleOriginsKe y" while running as root. This is no longer a supported configuration. Please file a radar against that process to adopt that entitlement.

8/5/18 4:54:32.175 PM launchservicesd[82]: Process 933 (Activity Monitor.app) attempted to bypass check for entitlement "com.apple.private.launchservices.allowedtoget.LSActivePageUserVisibleOriginsKe y" while running as root. This is no longer a supported configuration. Please file a radar against that process to adopt that entitlement.

8/5/18 4:54:37.233 PM launchservicesd[82]: Process 933 (Activity Monitor.app) attempted to bypass check for entitlement "com.apple.private.launchservices.allowedtoget.LSActivePageUserVisibleOriginsKe y" while running as root. This is no longer a supported configuration. Please file a radar against that process to adopt that entitlement.

8/5/18 4:54:42.190 PM launchservicesd[82]: Process 933 (Activity Monitor.app) attempted to bypass check for entitlement "com.apple.private.launchservices.allowedtoget.LSActivePageUserVisibleOriginsKe y" while running as root. This is no longer a supported configuration. Please file a radar against that process to adopt that entitlement.

8/5/18 4:54:47.163 PM launchservicesd[82]: Process 933 (Activity Monitor.app) attempted to bypass check for entitlement "com.apple.private.launchservices.allowedtoget.LSActivePageUserVisibleOriginsKe y" while running as root. This is no longer a supported configuration. Please file a radar against that process to adopt that entitlement.

8/5/18 4:54:52.269 PM launchservicesd[82]: Process 933 (Activity Monitor.app) attempted to bypass check for entitlement "com.apple.private.launchservices.allowedtoget.LSActivePageUserVisibleOriginsKe y" while running as root. This is no longer a supported configuration. Please file a radar against that process to adopt that entitlement.

8/5/18 4:54:54.012 PM akd[1322]: *** LOG MESSAGE QUOTA EXCEEDED - SOME MESSAGES FROM THIS PROCESS HAVE BEEN DISCARDED ***

8/5/18 4:54:54.012 PM akd[314]: *** LOG MESSAGE QUOTA EXCEEDED - SOME MESSAGES FROM THIS PROCESS HAVE BEEN DISCARDED ***

8/5/18 4:54:57.181 PM launchservicesd[82]: Process 933 (Activity Monitor.app) attempted to bypass check for entitlement "com.apple.private.launchservices.allowedtoget.LSActivePageUserVisibleOriginsKe y" while running as root. This is no longer a supported configuration. Please file a radar against that process to adopt that entitlement.

8/5/18 4:55:00.056 PM apsd[81]: *** LOG MESSAGE QUOTA EXCEEDED - SOME MESSAGES FROM THIS PROCESS HAVE BEEN DISCARDED ***

8/5/18 4:55:01.799 PM launchservicesd[82]: Process 933 (Activity Monitor.app) attempted to bypass check for entitlement "com.apple.private.launchservices.allowedtoget.LSActivePageUserVisibleOriginsKe y" while running as root. This is no longer a supported configuration. Please file a radar against that process to adopt that entitlement.

8/5/18 4:55:07.012 PM apsd[81]: Unexpected replacement of connection in <APSConnectionServer: 0x7ffc0bd761b0>

8/5/18 4:55:07.395 PM launchservicesd[82]: Process 933 (Activity Monitor.app) attempted to bypass check for entitlement "com.apple.private.launchservices.allowedtoget.LSActivePageUserVisibleOriginsKe y" while running as root. This is no longer a supported configuration. Please file a radar against that process to adopt that entitlement.

8/5/18 4:55:12.100 PM launchservicesd[82]: Process 933 (Activity Monitor.app) attempted to bypass check for entitlement "com.apple.private.launchservices.allowedtoget.LSActivePageUserVisibleOriginsKe y" while running as root. This is no longer a supported configuration. Please file a radar against that process to adopt that entitlement.

8/5/18 4:55:17.269 PM launchservicesd[82]: Process 933 (Activity Monitor.app) attempted to bypass check for entitlement "com.apple.private.launchservices.allowedtoget.LSActivePageUserVisibleOriginsKe y" while running as root. This is no longer a supported configuration. Please file a radar against that process to adopt that entitlement.

8/5/18 4:55:22.164 PM launchservicesd[82]: Process 933 (Activity Monitor.app) attempted to bypass check for entitlement "com.apple.private.launchservices.allowedtoget.LSActivePageUserVisibleOriginsKe y" while running as root. This is no longer a supported configuration. Please file a radar against that process to adopt that entitlement.

8/5/18 4:55:27.189 PM launchservicesd[82]: Process 933 (Activity Monitor.app) attempted to bypass check for entitlement "com.apple.private.launchservices.allowedtoget.LSActivePageUserVisibleOriginsKe y" while running as root. This is no longer a supported configuration. Please file a radar against that process to adopt that entitlement.


Here are some other samples of the Console log message which I found weird.

5/5/18 2:51:54.948 PM WiFiAgent[438]: [NO client logger] <Sep 11 2015 20:39:39> WIFICLOUDSYNC WiFiCloudSyncEngineCreate: created...

5/5/18 2:51:54.948 PM WiFiAgent[438]: [NO client logger] <Sep 11 2015 20:39:39> WIFICLOUDSYNC WiFiCloudSyncEngineRegisterCallbacks: WiFiCloudSyncEngineCallbacks version - 0, bundle id - com.apple.wifi.WiFiAgent

5/5/18 2:51:54.949 PM secd[392]: do_with_account_if_after_first_unlock Cannot inflate account object as root

5/5/18 2:51:54.950 PM secd[392]: securityd_xpc_dictionary_handler WiFiAgent[438] View Error Domain=com.apple.security Code=550 "(null)"

5/5/18 2:51:54.986 PM diagnostics_agent[439]: AutoSubmitPreference is 0

5/5/18 2:51:55.179 PM CrashReporterSupportHelper[455]: DebugLogging not enabled

5/5/18 2:51:55.317 PM Keychain Circle Notification[425]: Posted at launch: (

)

5/5/18 2:51:55.318 PM secd[392]: do_with_account_if_after_first_unlock Cannot inflate account object as root

5/5/18 2:51:55.319 PM secd[392]: securityd_xpc_dictionary_handler Keychain Circle [425] DeviceInCircle Error Domain=com.apple.security Code=550 "(null)"

5/5/18 2:51:55.319 PM secd[392]: do_with_account_if_after_first_unlock Cannot inflate account object as root

5/5/18 2:51:55.320 PM secd[392]: securityd_xpc_dictionary_handler Keychain Circle [425] CopyApplicantPeerInfo Error Domain=com.apple.security Code=550 "(null)"

5/5/18 2:51:55.320 PM secd[392]: do_with_account_if_after_first_unlock Cannot inflate account object as root

5/5/18 2:51:55.321 PM secd[392]: securityd_xpc_dictionary_handler Keychain Circle [425] CopyPeerPeerInfo Error Domain=com.apple.security Code=550 "(null)"

5/5/18 2:51:55.321 PM Keychain Circle Notification[425]: rawStatus -1, #applicants 0, #peers 0, err=Error Domain=com.apple.security Code=550 "(null)"

5/5/18 2:51:55.325 PM Keychain Circle Notification[425]: {ChangeCallback}

5/5/18 2:51:55.339 PM SubmitDiagInfo[456]: Couldn't load config file from on-disk location. Falling back to default location. Reason: Won't serialize in _readDictionaryFromJSONData due to nil object

5/5/18 2:51:55.340 PM MRT[442]: Agent finished.

5/5/18 2:51:55.340 PM MRT[442]: Finished MRT run

5/5/18 2:51:55.000 PM kernel[0]: Sandbox: SocialPushAgent(423) deny(1) file-write-data /private/var/root/Library/Preferences/com.apple.socialpushagent.plist

5/5/18 2:51:55.000 PM kernel[0]: Sandbox: SocialPushAgent(423) deny(1) file-write-data /private/var/root/Library/Preferences/com.apple.socialpushagent.plist

5/5/18 2:51:55.436 PM Keychain Circle Notification[425]: {ChangeCallback} scheduleActivity 4001-01-01 00:00:00 +0000

5/5/18 2:51:55.436 PM Keychain Circle Notification[425]: {ChangeCallback} Applicants

5/5/18 2:51:55.436 PM Keychain Circle Notification[425]: Checking validity of 0 notes

5/5/18 2:51:55.437 PM Keychain Circle Notification[425]: writeToStorage plist={

absentCircleWithNoReason = 0;

applicationDate = "0000-12-30 00:00:00 +0000";

lastCircleStatus = "-1";

lastWritten = "2018-05-05 06:51:55 +0000";

pendingApplicationReminder = "4001-01-01 00:00:00 +0000";

pendingApplicationReminderInterval = 86400;

}

5/5/18 2:51:55.528 PM diagnostics_agent[439]: AutoSubmitPreference is 0

5/5/18 2:51:55.581 PM diagnostics_agent[439]: AutoSubmitPreference is 0

5/5/18 2:51:55.638 PM SubmitDiagInfo[456]: Couldn't load config file from on-disk location. Falling back to default location. Reason: Won't serialize in _readDictionaryFromJSONData due to nil object

5/5/18 2:51:55.655 PM com.apple.xpc.launchd[1]: (com.apple.updateEFIDesktopPicture) Service only ran for 0 seconds. Pushing respawn out by 10 seconds.

5/5/18 2:51:55.816 PM sandboxd[130]: ([407]) SpotlightNetHelp(407) deny file-write-create /private/var/root/Library/Caches/com.apple.metadata.SpotlightNetHelper

5/5/18 2:51:55.859 PM sandboxd[130]: ([407]) SpotlightNetHelp(407) deny mach-lookup com.apple.storeaccountd.daemon

5/5/18 2:51:55.876 PM sandboxd[130]: ([407]) SpotlightNetHelp(407) deny file-write-data /private/var/db/mds/system/mds.lock

5/5/18 2:51:56.513 PM fontd[393]: ATSServer: FODBVerifyReviveResults made adjustments


Another set:


5/5/18 2:54:56.853 PM com.apple.geod[510]: NSURLSession/NSURLConnection HTTP load failed (kCFStreamErrorDomainSSL, -9808)

5/5/18 2:54:56.855 PM com.apple.geod[510]: 2018-05-05 14:54:56.854, 510, 2341ea80, [CountryConfiguration]: Could not determine current country code: Error Domain=NSURLErrorDomain Code=-1202 "The certificate for this server is invalid. You might be connecting to a server that is pretending to be “gspe1-ssl.ls.apple.com” which could put your confidential information at risk."

MacBook Pro, OS X El Capitan (10.11.6), MacBook Pro 5,4

Posted on May 8, 2018 1:56 AM

Reply

Similar questions

5 replies

May 8, 2018 1:56 PM in response to tethfrog2321

tethfrog2321thanks for your reply. This is the report I've gotten from EtreCheck:

EtreCheck version: 4.2.1 (4C020)

Report generated: 2018-05-09 04:45:25

Download EtreCheck from https://etrecheck.com

Runtime: 2:37

Performance: Excellent


Problem: No problem - just checking


Major Issues:

Anything that appears on this list needs immediate attention.


No Time Machine backup - Time Machine backup not found.

Obsolete hardware - This machine may be considered obsolete.


Minor Issues:

These issues do not need immediate attention but they may indicate future problems.


Upgradeable RAM - This machine has upgradeable RAM that would help its performance.

Apps crashing - There have been numerous app crashes.

Unsigned files - There is unsigned software installed. They appear to be legitimate but should be reviewed.

Corrupt hosts file - Hosts file is corrupt.

32-bit Apps - This machine has 32-bits apps that may have problems in the future.


Hardware Information:

MacBook Pro (15-inch, 2.53GHz, Mid 2009) - Obsolete!

MacBook Pro Model: MacBookPro5,4

1 2.53 GHz Intel Core 2 Duo (Duo) CPU: 2-core

6 GB RAM Upgradeable

BANK 0/DIMM0 - 4 GB DDR3 1067 ok

BANK 1/DIMM0 - 2 GB DDR3 1067 ok

Battery: Health = Normal - Cycle count = 90


Video Information:

NVIDIA GeForce 9400M - VRAM: 256 MB

Color LCD 1440 x 900


Drives:

disk0 - Samsung SSD 750 EVO 250GB 250.06 GB (Solid State - TRIM: No)

Internal SATA 3 Gigabit Serial ATA

disk0s1 - EFI (MS-DOS FAT32) [EFI] 210 MB

disk0s2 - Macintosh HD (Journaled HFS+) 249.20 GB

disk0s3 - Recovery HD (Journaled HFS+) [Recovery] 650 MB


Mounted Volumes:

disk0s2 - Macintosh HD 249.20 GB (26.41 GB free)

Journaled HFS+

Mount point: /


Network:

Interface en1: Wi-Fi

802.11 a/b/g/n

One IPv4 address

Interface en3: iPhone


System Software:

OS X El Capitan 10.11.6 (15G20015)

Time since boot: About 2 days

System Load: 2.20 (1 min ago) 1.97 (5 min ago) 1.91 (15 min ago)


Configuration Files:

/etc/hosts - Count: 144 - Corrupt!


Security:

System

Status

Gatekeeper

Mac App Store and identified developers

System Integrity Protection

Enabled


Unsigned Files:

Launchd: /Library/LaunchDaemons/com.adobe.SwitchBoard.plist

Executable: /Library/Application Support/Adobe/SwitchBoard/SwitchBoard.app/Contents/MacOS/launch.switchboard

Details: Exact match found in the whitelist - probably OK

Launchd: /Library/LaunchDaemons/org.wireshark.ChmodBPF.plist

Executable: /Library/Application Support/Wireshark/ChmodBPF/ChmodBPF

Details: Exact match found in the whitelist - probably OK

Launchd: /Library/LaunchDaemons/org.virtualbox.startup.plist

Executable: /Library/Application Support/VirtualBox/LaunchDaemons/VirtualBoxStartup.sh restart

Details: Exact match found in the whitelist - probably OK


32-bit Applications:

24 32-bit apps


Kernel Extensions:

/Applications/eqMac2.app

[Loaded] eqMac2Driver.kext (Romans Kisils, 2.0 - SDK 10.13)


/Library/Application Support/VirtualBox

[Loaded] VBoxDrv.kext (Oracle America, Inc., 5.0.10)

[Loaded] VBoxNetAdp.kext (Oracle America, Inc., 5.0.10)

[Loaded] VBoxNetFlt.kext (Oracle America, Inc., 5.0.10)

[Loaded] VBoxUSB.kext (Oracle America, Inc., 5.0.10)


System Launch Agents:

[Not Loaded]

6 Apple tasks

[Loaded]

168 Apple tasks

[Running]

63 Apple tasks

[Other]

One Apple task


System Launch Daemons:

[Not Loaded]

46 Apple tasks

[Loaded]

155 Apple tasks

[Running]

88 Apple tasks

[Other]

2 Apple tasks


Launch Agents:

[Not Loaded]

com.adobe.AAM.Updater-1.0.plist (? ffb65062 - installed 2017-04-17)


Launch Daemons:

[Not Loaded]

org.virtualbox.startup.plist (? 700b9385 - installed 2018-05-04)

[Loaded]

com.apple.installer.osmessagetracing.plist (Apple - installed 2018-03-09)

[Loaded]

com.adobe.SwitchBoard.plist (? 68cad67 - installed 2017-04-17)

[Loaded]

com.adobe.fpsaud.plist (Adobe Systems, Inc. - installed 2018-03-27)

[Loaded]

com.microsoft.office.licensingV2.helper.plist (Microsoft Corporation - installed 2016-06-11)

[Loaded]

org.wireshark.ChmodBPF.plist (? d4207e05 - installed 2018-04-23)


User Login Items:

com.adobe.SwitchBoard.monitor.plist MachInit (?

(/etc/mach_init_per_user.d/com.adobe.SwitchBoard.monitor.plist)


Internet Plug-ins:

FlashPlayer-10.6: 29.0.0.140 (installed 2018-04-10)

QuickTime Plugin: 7.7.3 (installed 2018-05-06)

Flash Player: 29.0.0.140 (installed 2018-04-10)

Default Browser: 601 (installed 2017-08-09)

PepperFlashPlayer: 29.0.0.140 (installed 2018-04-10)

Silverlight: 5.1.50901.0 (installed 2017-06-02)

JavaAppletPlugin: 15.0.1 (installed 2017-04-17)


3rd Party Preference Panes:

Flash Player (installed 2018-03-27)

Shades Preferences (installed 2017-04-19)


Time Machine:

Time Machine Not Configured!


Top Processes by CPU:

Process (count)

Source

% of CPU

Safari

Apple

7

com.apple.WebKit.WebContent (2)

Apple

6

WindowServer

Apple

6

Activity Monitor

Apple

3

kernel_task

Apple

3


Top Processes by Memory:

Process (count)

Source

RAM usage

kernel_task

Apple

658 MB

softwareupdated

Apple

474 MB

com.apple.WebKit.WebContent (2)

Apple

413 MB

Console

Apple

251 MB

WindowServer

Apple

127 MB


Top Processes by Energy Use:

Process (count)

Source

Energy usage (0-100)

Activity Monitor

Apple

1

akd (2)

Apple

1

apsd

Apple

1

Finder

Apple

1

syslogd

Apple

0


Virtual Memory Information:

Available RAM

2.40 GB

Free RAM

32 MB

Used RAM

3.60 GB

Cached files

2.37 GB

Swap Used

0 B


Diagnostics Information (past 7 days):

2018-05-08 16:46:57 Console.app CPU (once)

2018-05-07 15:48:34 com.apple.WebKit.Databases Crash (once)

2018-05-06 16:18:12 Calendar.app Crash (2 times)

Configuration error: No SDK cache entry for extension!

2018-05-06 16:18:12 Stocks.app Crash (2 times)

Configuration error: No SDK cache entry for extension!

2018-05-06 16:18:12 Weather.app Crash (2 times)

Configuration error: No SDK cache entry for extension!

2018-05-06 15:50:38 Last Shutdown Cause: 3 - Hard shutdown (once)


End of report


I am still very worried about the fact that I could only see the processes from the current user (and missing activities from background users e.g. _launchservicesd or _launchd) in Activity Monitor, along with some weird activities in my WIFI router log.

May 9, 2018 9:01 AM in response to Eric Root

Hi @ Eric Root thanks for your replies. My hosts file is correct (I've tried replacing it with a hosts file from a working Mac or re-do another hosts file from scratch), but I still get the following from Terminal.


Last login: Wed May 9 23:17:54 on console

/etc/hosts ; exit;

Homes-MBP:~ Main$ /etc/hosts ; exit;

/etc/hosts: line 8: 127.0.0.1: command not found

/etc/hosts: line 9: 255.255.255.255: command not found

/etc/hosts: line 10: ::1: command not found

/etc/hosts: line 11: fe80::1%lo0: command not found

/etc/hosts: line 13: 127.0.0.1: command not found

/etc/hosts: line 14: 127.0.0.1: command not found

/etc/hosts: line 15: 127.0.0.1: command not found

/etc/hosts: line 16: 127.0.0.1: command not found

/etc/hosts: line 17: 127.0.0.1: command not found

/etc/hosts: line 18: 127.0.0.1: command not found

/etc/hosts: line 19: 127.0.0.1: command not found

/etc/hosts: line 20: 127.0.0.1: command not found

/etc/hosts: line 21: 127.0.0.1: command not found

/etc/hosts: line 22: 127.0.0.1: command not found

/etc/hosts: line 23: 127.0.0.1: command not found

/etc/hosts: line 24: 127.0.0.1: command not found

/etc/hosts: line 25: 127.0.0.1: command not found

/etc/hosts: line 26: 127.0.0.1: command not found

/etc/hosts: line 27: 127.0.0.1: command not found

/etc/hosts: line 28: 127.0.0.1: command not found

/etc/hosts: line 29: 127.0.0.1: command not found

/etc/hosts: line 30: 127.0.0.1: command not found

/etc/hosts: line 31: 127.0.0.1: command not found

/etc/hosts: line 32: 127.0.0.1: command not found

/etc/hosts: line 33: 127.0.0.1: command not found

/etc/hosts: line 34: 127.0.0.1: command not found

/etc/hosts: line 35: 127.0.0.1: command not found

/etc/hosts: line 36: 127.0.0.1: command not found

/etc/hosts: line 37: 127.0.0.1: command not found

/etc/hosts: line 38: 127.0.0.1: command not found

/etc/hosts: line 39: 127.0.0.1: command not found

/etc/hosts: line 40: 127.0.0.1: command not found

/etc/hosts: line 41: 127.0.0.1: command not found

/etc/hosts: line 42: 127.0.0.1: command not found

/etc/hosts: line 43: 127.0.0.1: command not found

/etc/hosts: line 44: 127.0.0.1: command not found

/etc/hosts: line 45: 127.0.0.1: command not found

/etc/hosts: line 46: 127.0.0.1: command not found

/etc/hosts: line 47: 127.0.0.1: command not found

/etc/hosts: line 48: 127.0.0.1: command not found

/etc/hosts: line 49: 127.0.0.1: command not found

/etc/hosts: line 50: 127.0.0.1: command not found

/etc/hosts: line 51: 127.0.0.1: command not found

/etc/hosts: line 52: 127.0.0.1: command not found

/etc/hosts: line 53: 127.0.0.1: command not found

/etc/hosts: line 54: 127.0.0.1: command not found

/etc/hosts: line 55: 127.0.0.1: command not found

/etc/hosts: line 56: 127.0.0.1: command not found

/etc/hosts: line 57: 127.0.0.1: command not found

/etc/hosts: line 58: 127.0.0.1: command not found

/etc/hosts: line 59: 127.0.0.1: command not found

/etc/hosts: line 60: 127.0.0.1: command not found

/etc/hosts: line 61: 127.0.0.1: command not found

/etc/hosts: line 62: 127.0.0.1: command not found

/etc/hosts: line 63: 127.0.0.1: command not found

/etc/hosts: line 64: 127.0.0.1: command not found

/etc/hosts: line 65: 127.0.0.1: command not found

/etc/hosts: line 66: 127.0.0.1: command not found

/etc/hosts: line 67: 127.0.0.1: command not found

/etc/hosts: line 68: 127.0.0.1: command not found

/etc/hosts: line 69: 127.0.0.1: command not found

/etc/hosts: line 70: 127.0.0.1: command not found

/etc/hosts: line 71: 127.0.0.1: command not found

/etc/hosts: line 72: 127.0.0.1: command not found

/etc/hosts: line 73: 127.0.0.1: command not found

/etc/hosts: line 74: 127.0.0.1: command not found

/etc/hosts: line 75: 127.0.0.1: command not found

/etc/hosts: line 76: 127.0.0.1: command not found

/etc/hosts: line 77: 127.0.0.1: command not found

/etc/hosts: line 78: 127.0.0.1: command not found

/etc/hosts: line 79: 127.0.0.1: command not found

/etc/hosts: line 80: 127.0.0.1: command not found

/etc/hosts: line 81: 127.0.0.1: command not found

/etc/hosts: line 82: 127.0.0.1: command not found

/etc/hosts: line 83: 127.0.0.1: command not found

/etc/hosts: line 84: 127.0.0.1: command not found

/etc/hosts: line 85: 127.0.0.1: command not found

/etc/hosts: line 86: 127.0.0.1: command not found


At the same time, I am getting weird Console logs (removed all UUIDs and personal information; these are the first Console logs when I on my computer for the first time today so there's no miscapture of other dates or anything)


09 May 2018 11:17:54.705 PM lsd[246]: LaunchServices: Scheme mapping file does not exist, creating file.

09 May 2018 11:17:56.388 PM lsd[246]: LaunchServices: Seeding database with UID: 502, EUID 502

09 May 2018 11:17:57.700 PM fontd[272]: Failed to open read-only database, regenerating DB

09 May 2018 11:17:57.818 PM sharingd[273]: 23:17:57.814 : Starting Up...

09 May 2018 11:17:57.850 PM sharingd[273]: 23:17:57.849 : Device Capabilities (Handoff:NO, Instant Hotspot:NO, AirDrop:NO, Legacy AirDrop:YES, Remote Disc:NO)

09 May 2018 11:18:00.619 PM CalendarAgent[254]: [com.apple.calendar.agent.log.accounts] [All of iCloud (identifier=D---; type=com.apple.account.CalDAV; childAccount=YES)'s principals are in Calendar's database.]

09 May 2018 11:18:00.619 PM CalendarAgent[254]: [com.apple.calendar.agent.log.accounts] [All of --- (identifier=---; type=com.apple.account.Exchange; childAccount=NO)'s principals are in Calendar's database.]

09 May 2018 11:18:02.061 PM identityservicesd[268]: <IMMacNotificationCenterManager: 0x7fb7c34c3ed0>: Configuring notification center for identifier: com.apple.iChat topics: (

"com.apple.private.alloy.icloudpairing",

"com.apple.private.alloy.continuity.encryption",

"com.apple.private.alloy.continuity.activity",

"com.apple.private.ids",

"com.apple.private.alloy.phonecontinuity",

"com.apple.private.alloy.phone.auth",

"com.apple.private.alloy.keychainsync",

"com.apple.private.alloy.fmf",

"com.apple.private.alloy.screensharing",

"com.apple.private.alloy.maps",

"com.apple.private.alloy.thumper.keys",

"com.apple.private.alloy.continuity.tethering"

)

09 May 2018 11:18:02.109 PM identityservicesd[268]: <IMMacNotificationCenterManager: 0x7fb7c34c3ed0>: NC Disabled: NO

09 May 2018 11:18:02.119 PM identityservicesd[268]: <IMMacNotificationCenterManager: 0x7fb7c34c3ed0>: DND Enabled: NO

09 May 2018 11:18:02.119 PM identityservicesd[268]: <IMMacNotificationCenterManager: 0x7fb7c34c3ed0>: Updating enabled: YES (Topics: (

"com.apple.private.alloy.icloudpairing",

"com.apple.private.alloy.continuity.encryption",

"com.apple.private.alloy.continuity.activity",

"com.apple.private.ids",

"com.apple.private.alloy.phonecontinuity",

"com.apple.private.alloy.phone.auth",

"com.apple.private.alloy.keychainsync",

"com.apple.private.alloy.fmf",

"com.apple.private.alloy.screensharing",

"com.apple.private.alloy.maps",

"com.apple.private.alloy.thumper.keys",

"com.apple.private.alloy.continuity.tethering"

))

09 May 2018 11:18:02.142 PM identityservicesd[268]: <IMMacNotificationCenterManager: 0x7fb7c34c3ed0>: NC Disabled: NO

09 May 2018 11:18:02.150 PM identityservicesd[268]: <IMMacNotificationCenterManager: 0x7fb7c34c3ed0>: DND Enabled: NO

09 May 2018 11:18:02.150 PM identityservicesd[268]: <IMMacNotificationCenterManager: 0x7fb7c34c3ed0>: Updating enabled: YES (Topics: (

"com.apple.private.alloy.icloudpairing",

"com.apple.private.alloy.continuity.encryption",

"com.apple.private.alloy.continuity.activity",

"com.apple.ess",

"com.apple.private.ids",

"com.apple.private.alloy.phonecontinuity",

"com.apple.private.alloy.phone.auth",

"com.apple.private.alloy.keychainsync",

"com.apple.private.alloy.fmf",

"com.apple.private.alloy.screensharing",

"com.apple.private.alloy.maps",

"com.apple.private.alloy.thumper.keys",

"com.apple.private.alloy.continuity.tethering"

))

09 May 2018 11:18:02.245 PM imagent[280]: <IMMacNotificationCenterManager: 0x7fedb14274a0>: Configuring notification center for identifier: com.apple.FaceTime topics: (null)

09 May 2018 11:18:02.329 PM identityservicesd[268]: <IMMacNotificationCenterManager: 0x7fb7c34c3ed0>: NC Disabled: NO

09 May 2018 11:18:02.343 PM imagent[280]: <IMMacNotificationCenterManager: 0x7fedb14274a0>: NC Disabled: NO

09 May 2018 11:18:02.343 PM identityservicesd[268]: <IMMacNotificationCenterManager: 0x7fb7c34c3ed0>: DND Enabled: NO

09 May 2018 11:18:02.344 PM identityservicesd[268]: <IMMacNotificationCenterManager: 0x7fb7c34c3ed0>: Updating enabled: YES (Topics: (

"com.apple.private.alloy.icloudpairing",

"com.apple.private.alloy.continuity.encryption",

"com.apple.private.alloy.continuity.activity",

"com.apple.ess",

"com.apple.private.ids",

"com.apple.private.alloy.phonecontinuity",

"com.apple.madrid",

"com.apple.private.alloy.phone.auth",

"com.apple.private.alloy.keychainsync",

"com.apple.private.alloy.fmf",

"com.apple.private.alloy.screensharing",

"com.apple.private.alloy.maps",

"com.apple.private.alloy.thumper.keys",

"com.apple.private.alloy.continuity.tethering"

))

09 May 2018 11:18:02.368 PM imagent[280]: <IMMacNotificationCenterManager: 0x7fedb14274a0>: DND Enabled: NO

09 May 2018 11:18:02.368 PM imagent[280]: <IMMacNotificationCenterManager: 0x7fedb14274a0>: Updating enabled: YES (Topics: (null))

09 May 2018 11:18:02.398 PM identityservicesd[268]: <IMMacNotificationCenterManager: 0x7fb7c34c3ed0>: NC Disabled: NO

09 May 2018 11:18:02.406 PM identityservicesd[268]: <IMMacNotificationCenterManager: 0x7fb7c34c3ed0>: DND Enabled: NO

09 May 2018 11:18:02.407 PM identityservicesd[268]: <IMMacNotificationCenterManager: 0x7fb7c34c3ed0>: Updating enabled: YES (Topics: (

"com.apple.private.alloy.icloudpairing",

"com.apple.private.alloy.continuity.encryption",

"com.apple.private.alloy.continuity.activity",

"com.apple.ess",

"com.apple.private.ids",

"com.apple.private.alloy.phonecontinuity",

"com.apple.madrid",

"com.apple.private.ac",

"com.apple.private.alloy.phone.auth",

"com.apple.private.alloy.keychainsync",

"com.apple.private.alloy.fmf",

"com.apple.private.alloy.screensharing",

"com.apple.private.alloy.maps",

"com.apple.private.alloy.thumper.keys",

"com.apple.private.alloy.continuity.tethering"

))

09 May 2018 11:18:02.409 PM imagent[280]: <IMMacNotificationCenterManager: 0x7fedb14274a0>: NC Disabled: NO

09 May 2018 11:18:02.424 PM imagent[280]: <IMMacNotificationCenterManager: 0x7fedb14274a0>: DND Enabled: NO

09 May 2018 11:18:02.425 PM imagent[280]: <IMMacNotificationCenterManager: 0x7fedb14274a0>: Updating enabled: YES (Topics: (

"com.apple.ess",

"com.apple.private.ac"

))

09 May 2018 11:18:02.474 PM identityservicesd[268]: <IMMacNotificationCenterManager: 0x7fb7c34c3ed0>: NC Disabled: NO

09 May 2018 11:18:02.482 PM identityservicesd[268]: <IMMacNotificationCenterManager: 0x7fb7c34c3ed0>: DND Enabled: NO

09 May 2018 11:18:02.482 PM identityservicesd[268]: <IMMacNotificationCenterManager: 0x7fb7c34c3ed0>: Updating enabled: YES (Topics: (

"com.apple.private.alloy.icloudpairing",

"com.apple.private.alloy.continuity.encryption",

"com.apple.private.alloy.continuity.activity",

"com.apple.ess",

"com.apple.private.ids",

"com.apple.private.alloy.phonecontinuity",

"com.apple.madrid",

"com.apple.private.ac",

"com.apple.private.alloy.phone.auth",

"com.apple.private.alloy.keychainsync",

"com.apple.private.alloy.fmf",

"com.apple.private.alloy.sms",

"com.apple.private.alloy.screensharing",

"com.apple.private.alloy.maps",

"com.apple.private.alloy.thumper.keys",

"com.apple.private.alloy.continuity.tethering"

))

09 May 2018 11:18:02.576 PM fmfd[284]: Initialized sandbox

09 May 2018 11:18:04.301 PM nsurlsessiond[255]: No directory for bundleID: com.apple.cloudd, sessionID: CKBackgroundSession:bundleID:com.apple.Safari:sourceApplicationSecondaryIdentif ier::containerIdentifier:com.apple.SafariShared.WBSCloudHistoryStore:containerEn vironment:Production:allowsExpensiveAccess:true:discretionary:infers:uuid:---

09 May 2018 11:18:05.609 PM lsd[246]: LaunchServices: Could not store lsd-identifiers file at /private/var/db/lsd/com.apple.lsdschemes.plist

09 May 2018 11:18:05.617 PM lsd[246]: LaunchServices: Could not store lsd-identifiers file at /private/var/db/lsd/com.apple.lsdschemes.plist

09 May 2018 11:18:05.629 PM lsd[246]: LaunchServices: Could not store lsd-identifiers file at /private/var/db/lsd/com.apple.lsdschemes.plist

09 May 2018 11:18:05.859 PM lsd[246]: LaunchServices: Could not store lsd-identifiers file at /private/var/db/lsd/com.apple.lsdschemes.plist

09 May 2018 11:18:05.865 PM lsd[246]: LaunchServices: Could not store lsd-identifiers file at /private/var/db/lsd/com.apple.lsdschemes.plist

09 May 2018 11:18:05.867 PM lsd[246]: LaunchServices: Could not store lsd-identifiers file at /private/var/db/lsd/com.apple.lsdschemes.plist

09 May 2018 11:18:05.868 PM lsd[246]: LaunchServices: Could not store lsd-identifiers file at /private/var/db/lsd/com.apple.lsdschemes.plist

09 May 2018 11:18:06.001 PM lsd[246]: LaunchServices: Could not store lsd-identifiers file at /private/var/db/lsd/com.apple.lsdschemes.plist

09 May 2018 11:18:06.002 PM lsd[246]: LaunchServices: Could not store lsd-identifiers file at /private/var/db/lsd/com.apple.lsdschemes.plist

09 May 2018 11:18:06.102 PM lsd[246]: LaunchServices: Could not store lsd-identifiers file at /private/var/db/lsd/com.apple.lsdschemes.plist

I am puzzled by the line

09 May 2018 11:18:02.576 PM fmfd[284]: Initialized sandbox

Why would fmfd (Find My Friend Daemon) be the one initialising the sandbox? Shouldn't sandbox be untouchable in any sense?


And also these


09 May 2018 11:18:12.995 PM cdpd[321]: Saw change in network reachability (isReachable=2)

09 May 2018 11:18:12.995 PM cdpd[321]: Received new connection <NSXPCConnection: 0x7fe679d24870> connection from pid 279, checking entitlements...

09 May 2018 11:18:12.996 PM cdpd[321]: Unknown client type with bundleID 'com.apple.iCloudHelper'

09 May 2018 11:18:12.996 PM cdpd[321]: Accepting new connection <NSXPCConnection: 0x7fe679d24870> connection from pid 279 with entitlements mask 3

09 May 2018 11:18:12.999 PM cdpd[321]: Received new connection <NSXPCConnection: 0x7fe679c14230> connection from pid 279, checking entitlements...

09 May 2018 11:18:12.999 PM cdpd[321]: Unknown client type with bundleID 'com.apple.iCloudHelper'

09 May 2018 11:18:12.999 PM cdpd[321]: Accepting new connection <NSXPCConnection: 0x7fe679c14230> connection from pid 279 with entitlements mask 3

09 May 2018 11:18:13.038 PM com.apple.iCloudHelper[279]: iCDP status for DSID 1036903816 is ENABLED

09 May 2018 11:18:13.039 PM com.apple.iCloudHelper[279]: Checking user-visible keychain sync status

09 May 2018 11:18:13.039 PM cdpd[321]: Received new connection <NSXPCConnection: 0x7fe679c36320> connection from pid 279, checking entitlements...

09 May 2018 11:18:13.040 PM cdpd[321]: Unknown client type with bundleID 'com.apple.iCloudHelper'

09 May 2018 11:18:13.040 PM cdpd[321]: Accepting new connection <NSXPCConnection: 0x7fe679c36320> connection from pid 279 with entitlements mask 3

09 May 2018 11:18:13.043 PM com.apple.iCloudHelper[279]: iCDP status for DSID 1036903816 is ENABLED

09 May 2018 11:18:13.044 PM cdpd[321]: Calling SOSCCView returned status 1 for view Passwords - (error: (null))

09 May 2018 11:18:13.044 PM cdpd[321]: Calling SOSCCView for view Passwords reported device is MEMBER - (error: (null))

09 May 2018 11:18:13.044 PM com.apple.iCloudHelper[279]: Checking user-visible keychain sync status

09 May 2018 11:18:13.044 PM cdpd[321]: Checking circle status with SOSCCThisDeviceIsInCircle to verify view membership is accurate

09 May 2018 11:18:13.045 PM com.apple.iCloudHelper[279]: User-visible keychain sync status is ENABLED

09 May 2018 11:18:13.046 PM cdpd[321]: Received new connection <NSXPCConnection: 0x7fe679c45c60> connection from pid 279, checking entitlements...

09 May 2018 11:18:13.047 PM cdpd[321]: Unknown client type with bundleID 'com.apple.iCloudHelper'

09 May 2018 11:18:13.047 PM cdpd[321]: Accepting new connection <NSXPCConnection: 0x7fe679c45c60> connection from pid 279 with entitlements mask 3

09 May 2018 11:18:13.051 PM cdpd[321]: Calling SOSCCView returned status 1 for view Passwords - (error: (null))

09 May 2018 11:18:13.051 PM cdpd[321]: Calling SOSCCView for view Passwords reported device is MEMBER - (error: (null))

09 May 2018 11:18:13.051 PM cdpd[321]: Checking circle status with SOSCCThisDeviceIsInCircle to verify view membership is accurate


And this


09 May 2018 11:18:23.805 PM cdpd[321]: Calling SOSCCView returned status 1 for view Passwords - (error: (null))

09 May 2018 11:18:23.806 PM cdpd[321]: Calling SOSCCView for view Passwords reported device is MEMBER - (error: (null))


What is this cdpd thing and why issit connecting with somewhere and viewing my password? (Hasn't found any information on this SOSCCView thing anywhere).


09 May 2018 11:18:35.323 PM com.apple.InputMethodKit.TextReplacementService[389]: -[PFUbiquitySwitchboardEntryMetadata setUseLocalStorage:](898): CoreData: Ubiquity: main~DBFE198D-4F8E-5146-9D07-3E2D3C617758:UserDictionary

Using local storage: 0 for new NSFileManager current token <fa45d864 0e852ac9 5f3f5962 1b692392 90c6f23c>

09 May 2018 11:18:40.308 PM WiFiAgent[352]: [NO client logger] <Sep 11 2015 20:39:39> WIFICLOUDSYNC WiFiCloudSyncEngineCreate: created...

09 May 2018 11:18:40.308 PM WiFiAgent[352]: [NO client logger] <Sep 11 2015 20:39:39> WIFICLOUDSYNC WiFiCloudSyncEngineRegisterCallbacks: WiFiCloudSyncEngineCallbacks version - 0, bundle id - com.apple.wifi.WiFiAgent


The above 2 lines really scares me. It seems like some things I read or type may be auto-replaced to something else, and I don't use any WiFi sync nor am I syncing my Mac with any other devices.


So am I really being hacked? What can I, or should I do now if I am being hacked?

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Have I been hacked? (Repeating APSD messages and hosts file not working)

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.