Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Need help with my etrecheck report

I'm looking for spyware on my Mac and it was suggested that I use EtreCheck and ask for the communities help understanding the report. Can anybody help me?

EtreCheck version: 4.3.6 (4D041)

Report generated: 2018-08-30 10:13:06

Download EtreCheck from https://etrecheck.com

Runtime: 3:27

Performance: Good


Problem: No problem - just checking

Description:

Checking for spyware or key logger


Major Issues:

Anything that appears on this list needs immediate attention.


Time Machine backup out-of-date - The last Time Machine backup is over 10 days old.


Minor Issues:

These issues do not need immediate attention but they may indicate future problems.


Heavy RAM usage - This machine is using a large amount of RAM.

Clean up - There are orphan files that could be removed.

Unsigned files - There are unsigned software file installed. They appear to be legitimate but should be reviewed.

32-bit Apps - This machine has 32-bits apps that may have problems in the future.


Hardware Information:

MacBook Pro (Retina, 15-inch, Late 2013)

MacBook Pro Model: MacBookPro11,3

1 2.6 GHz Intel Core i7 (i7-4960HQ) CPU: 4-core

16 GB RAM - Not upgradeable

BANK 0/DIMM0 - 8 GB DDR3 1600 ok

BANK 1/DIMM0 - 8 GB DDR3 1600 ok

Battery: Health = Normal - Cycle count = 175


Video Information:

Intel Iris Pro - VRAM: 1536 MB

Color LCD

NVIDIA GeForce GT 750M - VRAM: 2048 MB


Drives:

disk0 - APPLE SSD SM1024F 1.00 TB (Solid State - TRIM: Yes)

Internal PCI 5.0 GT/s x4 Serial ATA

disk0s1 - EFI (MS-DOS FAT32) [EFI] 210 MB

disk0s2 1.00 TB

disk1s1 - M****D (APFS) 1.00 TB (416.25 GB used)

disk1s2 - Preboot (APFS) [APFS Preboot] 1.00 TB (20 MB used)

disk1s3 - Recovery (APFS) [Recovery] 1.00 TB (518 MB used)

disk1s4 - VM (APFS) [APFS VM] 1.00 TB (8.77 GB used)


disk2 - Disk Image 24 MB (Disk Image)

External Disk Image

disk2s1 [Partition Map] 32 KB

disk2s2 - Flash Player (HFS+) 24 MB


disk3 - Disk Image 35 MB (Disk Image)

External Disk Image

disk3s1 - P****r (HFS+) 35 MB


disk4 - Disk Image 24 MB (Disk Image)

External Disk Image

disk4s1 [Partition Map] 32 KB

disk4s2 - Flash Player (HFS+) 24 MB


disk5 - Disk Image 24 MB (Disk Image)

External Disk Image

disk5s1 [Partition Map] 32 KB

disk5s2 - Flash Player (HFS+) 24 MB


Mounted Volumes:

disk1s1 - M****D 1.00 TB (574.58 GB free)

APFS

Mount point: /


disk1s4 - VM [APFS VM] 1.00 TB (574.58 GB free)

APFS

Mount point: /private/var/vm


disk2s2 - Flash Player 24 MB

HFS+

Mount point: /Volumes/Flash Player


disk3s1 - P****r 35 MB (34 MB free)

HFS+

Mount point: /Volumes/P****r


Network:

Interface en4: Thunderbolt Ethernet

Interface en6: Thunderbolt Ethernet Slot 1

Interface en7: Thunderbolt Ethernet Slot 2

Interface fw0: Thunderbolt FireWire

Interface fw1: Thunderbolt FireWire 2

Interface en0: Wi-Fi

802.11 a/b/g/n/ac

One IPv4 address

3 IPv6 addresses

Interface en5: iPhone

Interface en3: Bluetooth PAN

Interface bridge0: Thunderbolt Bridge


System Software:

macOS High Sierra 10.13.5 (17F77)

Time since boot: About 79 days

System Load: 3.45 (1 min ago) 3.56 (5 min ago) 3.05 (15 min ago)


Security:

SystemStatus
GatekeeperMac App Store and identified developers
System Integrity ProtectionEnabled


Unsigned Files:

Launchd: /Library/LaunchDaemons/com.microsoft.office.licensing.helper.plist

Executable: /Library/PrivilegedHelperTools/com.microsoft.office.licensing.helper

Details: Exact match found in the whitelist - probably OK

Launchd: /Library/LaunchDaemons/com.oracle.java.Helper-Tool.plist

Executable: /Library/Internet Plug-Ins/JavaAppletPlugin.plugin/Contents/Resources/Helper-Tool

Details: Exact match found in the whitelist - probably OK

Launchd: /Library/LaunchAgents/com.fujitsu.pfu.ScanSnap.AOUMonitor.plist

Executable: /Applications/ScanSnap Online Update.localized/AutoOnlineUpdater.app/Contents/MacOS/AOUMonitor.app/Contents/M acOS/AOUMonitor

Details: Exact match found in the whitelist - probably OK

Launchd: /Library/LaunchDaemons/com.fitbit.fitbitd.plist

Executable: /usr/local/bin/fitbitd

Details: Exact match found in the whitelist - probably OK

Launchd: /Library/LaunchAgents/com.oracle.java.Java-Updater.plist

Executable: /Library/Internet Plug-Ins/JavaAppletPlugin.plugin/Contents/Resources/Java Updater.app/Contents/MacOS/Java Updater -bgcheck

Details: Exact match found in the whitelist - probably OK


32-bit Applications:

69 32-bit apps


Kernel Extensions:

/Library/Application Support/LogMeIn/drivers

[Loaded] LogMeInSoundDriver.kext (LogMeIn, Inc., 4.1.9593)


/System/Library/Extensions

[Not Loaded] DymoUsbPrinterClassDriver.kext (1.1 - SDK 10.9)


System Launch Agents:

[Not Loaded] 9 Apple tasks
[Loaded] 160 Apple tasks
[Running] 124 Apple tasks
[Other] One Apple task


System Launch Daemons:

[Not Loaded] 40 Apple tasks
[Loaded] 162 Apple tasks
[Running] 133 Apple tasks
[Other] One Apple task


Launch Agents:

[Not Loaded] com.logmein.logmeinguiagentatlogin.plist (LogMeIn, Inc. - installed 2018-08-27)
[Not Loaded] com.adobe.AAM.Updater-1.0.plist (? ffb65062 - installed 2017-01-29)
[Running] com.fujitsu.pfu.ScanSnap.AOUMonitor.plist (? 1d61e789 - installed 2016-01-07)
[Loaded] com.google.keystone.agent.plist (Google, Inc. - installed 2018-07-17)
[Loaded] com.adobe.GC.Invoker-1.0.plist (Adobe Systems, Inc. - installed 2018-05-29)
[Running] com.logmein.logmeinguiagent.plist (LogMeIn, Inc. - installed 2018-08-27)
[Running] com.oracle.java.Java-Updater.plist (? ac0c582c - installed 2016-12-12)
[Other] com.adobe.ARMDCHelper.cc24aef4a1b90ed56a725c38014c95072f92651fb65e1bf9c8e43c37a2 3d420d.plist (Adobe Systems, Inc. - installed 2018-04-15)
[Running] com.logmein.logmeingui.plist (LogMeIn, Inc. - installed 2018-08-27)


Launch Daemons:

[Running] com.adobe.ARMDC.SMJobBlessHelper.plist (Adobe Systems, Inc. - installed 2018-04-15)
[Running] com.logmein.logmeinserver.plist (LogMeIn, Inc. - installed 2018-08-27)
[Running] com.malwarebytes.HelperTool.plist (Malwarebytes Corporation - installed 2017-05-25)
[Loaded] com.adobe.fpsaud.plist (Adobe Systems, Inc. - installed 2018-07-27)
[Running] com.fitbit.fitbitd.plist (? 969bfef5 - installed 2012-06-21)
[Loaded] com.microsoft.office.licensing.helper.plist (? 6d8cb30e - installed 2012-04-01)
[Loaded] com.oracle.java.Helper-Tool.plist (? e3fefdd2 - installed 2016-12-12)
[Loaded] com.adobe.agsservice.plist (Adobe Systems, Inc. - installed 2018-05-29)
[Running] com.fitbit.galileod.plist (? 485714a8 - installed 2017-03-23)
[Running] com.adobe.ARMDC.Communicator.plist (Adobe Systems, Inc. - installed 2018-04-15)
[Running] com.adobe.ARM.***.plist (? e489e9cb - installed 2017-01-29)
[Running] com.adobe.agmservice.plist (Adobe Systems, Inc. - installed 2018-05-29)
[Not Loaded] com.logmein.raupdate.plist (? c8be1d3f - installed 2014-07-08)
[Loaded] com.google.keystone.daemon.plist (Google, Inc. - installed 2018-07-17)
[Running] com.dymo.pnpd.plist (? 0 - installed 2014-10-16)


User Launch Agents:

[Loaded] com.adobe.ARM.***.plist (? 0 - installed 2018-08-12)
[Loaded] com.adobe.GC.Invoker-1.0.plist (Adobe Systems, Inc. - installed 2018-05-29)


User Login Items:

iTunesHelper Application (Apple - installed 2018-07-16)

(/Applications/iTunes.app/Contents/MacOS/iTunesHelper.app)


Internet Plug-ins:

FlashPlayer-10.6: (installed 2018-08-14)

QuickTime Plugin: (installed 2018-05-29)

AdobePDFViewerNPAPI: (installed 2018-08-16)

AdobePDFViewer: (installed 2018-08-16)

DYMO NPAPI Addin: (installed 2016-03-07)

Flash Player: (installed 2018-08-14)

SharePointBrowserPlugin: (installed 2014-07-01)

DYMO Safari Addin: (installed 2016-03-07)

Silverlight: (installed 2016-08-19)

MeetingJoinPlugin: (installed 2014-07-01)

JavaAppletPlugin: (installed 2017-02-08)


3rd Party Preference Panes:

Flash Player (installed 2018-07-27)

Java (installed 2017-02-08)


Time Machine:

Skip System Files: No

Mobile backups: Yes

Auto backup: Yes

Volumes being backed up:

M****D: Disk size: 1.00 TB - Disk used: 425.77 GB

Destinations:

S***********************e [Local]

Total size: 1.50 TB

Total number of backups: 51

Oldest backup: 2015-11-10 11:05:49

Last backup: 2017-05-23 15:25:06

t*********e [Network] (Last used)

Total size: 5.00 TB

Total number of backups: 27

Oldest backup: 2016-09-08 11:57:25

Last backup: 2017-05-23 14:32:16


Top Processes by CPU:

Process (count)Source% of CPULocation
plugin-container (5)Mozilla Corporation15
firefoxMozilla Corporation7
WindowServerApple4
kernel_taskApple3
Microsoft Word?1 /Applications/Microsoft Office 2011/Microsoft Word.app


Top Processes by Memory:

Process (count)SourceRAM usageLocation
plugin-container (5)Mozilla Corporation2.44 GB
kernel_taskApple2.43 GB
firefoxMozilla Corporation1.38 GB
softwareupdatedApple710 MB
mdworker (15)Apple348 MB


Top Processes by Network Use:

ProcessSourceInputOutputLocation
mDNSResponderApple177 MB68 MB
netbiosdApple15 MB7 MB
firefoxMozilla Corporation3 MB724 KB
SystemUIServerApple0 B122 KB
apsdApple4 KB2 KB


Top Processes by Energy Use:

Process (count)SourceEnergy (0-100)Location
plugin-container (5)Mozilla Corporation14
mdworker (15)Apple0
WindowServerApple0
mdsApple0
MTLCompilerService (11)Apple0


Virtual Memory Information:

Available RAM4.36 GB
Free RAM487 MB
Used RAM11.64 GB
Cached files3.88 GB
Swap Used5.67 GB


Software Installs (past 30 days):

NameVersionInstall Date
Google Earth1.2.10.1052018-08-02
Adobe Flash Player30.0.0.1542018-08-14
Adobe Acrobat Reader DC (18.011.20058)18.011.200582018-08-16
Gatekeeper Configuration Data1532018-08-27


Clean up:

/Library/LaunchDaemons/com.logmein.raupdate.plist

/Library/Application Support/LogMeIn/update/raupdate

Executable not found


Diagnostics Information (past 7 days):

2018-08-30 02:07:49 Microsoft Word.app CPU

/Applications/Microsoft Office 2011/Microsoft Word.app


2018-08-25 07:47:17 Adobe Acrobat Pro.app Crash (2 times)

/Applications/Adobe Acrobat XI Pro/Adobe Acrobat Pro.app


Thanks





End of report

Posted on Aug 30, 2018 1:28 PM

Reply
Question marked as Best reply

Posted on Aug 30, 2018 4:10 PM

It's a used computer and I was concerned someone could use it to get my information. Is that a legitimate concern?

Yes. You can't know what someone else did. You need to boot into Internet Recovery, Erase the drive completely, then install the OS.

About macOS Recovery - Apple Support

How to reinstall macOS - Apple Support

You can't do everything on this list, but for the most part, here is what should have been done:

What to do before you sell or give away your Mac - Apple Support

Similar questions

7 replies
Question marked as Best reply

Aug 30, 2018 4:10 PM in response to Tim96744

It's a used computer and I was concerned someone could use it to get my information. Is that a legitimate concern?

Yes. You can't know what someone else did. You need to boot into Internet Recovery, Erase the drive completely, then install the OS.

About macOS Recovery - Apple Support

How to reinstall macOS - Apple Support

You can't do everything on this list, but for the most part, here is what should have been done:

What to do before you sell or give away your Mac - Apple Support

Aug 30, 2018 4:12 PM in response to Tim96744

i would not bother. by the time you study enough to know you'll be too old to care 🙂


read apple security articles at leasure perhaps. etrecheck is NOT a security application. apple has good security.


you can monitor application activity by checking your "system logs"


a GOOD tool for you is to watch your modem lights. you can use (tools) to monitor why the lights are lighting up. you can learn to know what "idle/nothing" looks like and what suspicious activity looks like. For example you can easily determine if you give some Non Apple Store game an admin passwd if it immediately begins using the internet after you give that passwd. but since an honest game might do that (poorly laid out software) ...


there is NO OS available to consumers that allows one to surely know if they are being watched by a higher entity


there just isn't. however - be sure that Apple does not play games with your privacy and rights. you are being protected. keep up with your updates.

Aug 30, 2018 4:21 PM in response to QuietMacFan

How do I check the system logs? I know next to nothing about computers. This use to be the work computer, got a new one gifted this one for personal use...but I'm sure about the i.t. guy I found out he still had admin privileges on the computer I removed him from that but a little worried he still may have access because I can't get rid of the logmein. maybe I'm being over-concerned but now days you never know.

Need help with my etrecheck report

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.