JustPaste.it

Unremovable MacOS Malware Report

EtreCheckPro version: 6.8.7 (68068)
Report generated: 2025-01-18 20:01:47
Download EtreCheckPro from https://etrecheck.com
Runtime: 1:37
Performance: Excellent

Problem: Beachballing
Description: 
Random Languages like Vietnamese, Korean, and Chinese keep appearing. 
Believe the SSV might have been compromised and I can’t get rid of it.

Feel free to contact me with any advice as I know something is wrong but I can't get through to apple to explain to them that there is a problem. 

Email: helpwithmacosmalware.flatness499@passmail.net
 

Major Issues: None

Minor Issues:
  These issues do not need immediate attention but they may indicate future problems or opportunities for improvement. 
  No Time Machine backup - Time Machine backup not found.
  Heavy RAM usage - Apps are using a large amount of RAM.
  Apps crashing - There have been numerous app crashes.
  Limited permissions - More information may be available with Full Disk Access.

Hardware Information:
  MacBook Pro (14-inch, 2024)
    Status: Supported
  MacBook Pro Model: Mac16,8
  Apple M4 Pro CPU: 14-core
  48 GB RAM - Not upgradeable
  Battery: Health = Normal - Cycle count = 20

Video Information:
  Apple M4 Pro
    Color LCD 3024 x 1964

Drives:
  disk0 - APPLE SSD AP1024Z 1.00 TB (Solid State - TRIM: Yes) 
  Internal Apple Fabric NVM Express
    disk0s1 [APFS Container] 524 MB
      disk1 [APFS Virtual drive] 524 MB (Shared by 4 volumes)
        disk1s1 - iSCPreboot (APFS) [APFS Preboot] (6 MB used)
        disk1s2 - xART (APFS) (6 MB used)
        disk1s3 - Hardware (APFS) (3 MB used)
        disk1s4 - Recovery (APFS) [Recovery] (20 KB used)
    disk0s2 [APFS Container] 994.66 GB
      disk3 [APFS Virtual drive] 994.66 GB (Shared by 6 volumes)
        disk3s1 (APFS) [Core Storage Container] (11.20 GB used)
          disk3s1s1 - Macintosh HD (APFS) (11.20 GB used)
        disk3s2 - Preboot (APFS) [APFS Preboot] (5.95 GB used)
        disk3s3 - Recovery (APFS) [Recovery] (1.04 GB used)
        disk3s4 - Update (APFS) (90 KB used)
        disk3s5 - Data (APFS) [APFS Virtual drive] (35.06 GB used)
        disk3s6 - VM (APFS) [APFS VM] (20 KB used)
    disk0s3 [APFS Container] 5.37 GB
      disk2 [APFS Virtual drive] 5.37 GB (Shared by 2 volumes)
        disk2s1 - Recovery (APFS) [Recovery] (1.04 GB used)
        disk2s2 - Update (APFS) (25 KB used)

  disk5 - Apple Disk Image 274 MB (Disk Image) 
  External Virtual Interface
    disk5s1 [Partition Map] 31 KB
    disk5s2 - S*********s (Mac OS Extended) 274 MB

Mounted Volumes:
  disk1s1 - iSCPreboot [APFS Preboot]
    Filesystem: APFS
    Mount point: /System/Volumes/iSCPreboot
    Used: 6 MB
    Shared values
      Size: 524 MB
      Free: 505 MB

  disk1s2 - xART
    Filesystem: APFS
    Mount point: /System/Volumes/xarts
    Used: 6 MB
    Shared values
      Size: 524 MB
      Free: 505 MB

  disk1s3 - Hardware
    Filesystem: APFS
    Mount point: /System/Volumes/Hardware
    Used: 3 MB
    Shared values
      Size: 524 MB
      Free: 505 MB

  disk2s2 - Update
    Filesystem: APFS
    Mount point: /private/tmp/tmp-mount-RCqon9
    Used: 25 KB
    Shared values
      Size: 5.37 GB
      Free: 4.31 GB

  disk3s1s1 - Macintosh HD
    Filesystem: APFS
    Mount point: /
    Read-only: Yes
    Used: 11.20 GB
    Shared values
      Size: 994.66 GB
      Free: 941.21 GB
      Available: 946.35 GB

  disk3s2 - Preboot [APFS Preboot]
    Filesystem: APFS
    Mount point: /System/Volumes/Preboot
    Used: 5.95 GB
    Shared values
      Size: 994.66 GB
      Free: 941.21 GB
      Available: 946.35 GB

  disk3s3 - Recovery [Recovery]
    Filesystem: APFS
    Mount point: /Volumes/Recovery
    Used: 1.04 GB
    Shared values
      Size: 994.66 GB
      Free: 941.21 GB
      Available: 946.35 GB

  disk3s4 - Update
    Filesystem: APFS
    Mount point: /System/Volumes/Update
    Used: 90 KB
    Shared values
      Size: 994.66 GB
      Free: 941.21 GB
      Available: 946.35 GB

  disk3s5 - Data [APFS Virtual drive]
    Filesystem: APFS
    Mount point: /System/Volumes/Data
    Encrypted
    Used: 35.06 GB
    Shared values
      Size: 994.66 GB
      Free: 941.21 GB
      Available: 946.35 GB

  disk3s6 - VM [APFS VM]
    Filesystem: APFS
    Mount point: /System/Volumes/VM
    Used: 20 KB
    Shared values
      Size: 994.66 GB
      Free: 941.21 GB
      Available: 946.35 GB

USB:
  USB 3.1 bus
    <Empty>

  USB 3.1 bus
    <Empty>

  USB 3.1 bus
    <Empty>

Network:
  Interface en4: Ethernet Adapter (en4)
  Interface en5: Ethernet Adapter (en5)
  Interface en6: Ethernet Adapter (en6)
  Interface en0: Wi-Fi
    802.11 a/b/g/n/ac/ax

  Firewall:
    Blocked apps: All

    Stealth mode: enabled

System Software:
  macOS Sequoia 15.2 (24C101) 
  Time since boot: About 4 hours

Security:
  Gatekeeper: App Store and identified developers
  System Integrity Protection: Enabled
  Secure Boot: Full Security

  Antivirus software: Apple and Malwarebytes

System Extensions:
  [Not Loaded] Malwarebytes Engine - version 5.9.0 (Malwarebytes Corporation - installed 2025-01-18)
    Application: /Applications/Malwarebytes.app - version 5.9.0 (Malwarebytes Corporation - installed 2025-01-18)
    Description: The Malwarebytes Engine extension manages your connection to the Malwarebytes VPN service.

System Launch Daemons:
  [Not Loaded]  43 Apple tasks
  [Loaded]  186 Apple tasks
  [Running]  179 Apple tasks
  [Other]  2 Apple tasks

System Launch Agents:
  [Not Loaded]  22 Apple tasks
  [Loaded]  200 Apple tasks
  [Running]  224 Apple tasks

Launch Daemons:
  [Running] com.malwarebytes.mbam.rtprotection.daemon.plist (Malwarebytes Corporation - installed 2025-01-18)
    Command: /Library/Application Support/Malwarebytes/MBAM/Engine.bundle/Contents/PlugIns/RTProtectionDaemon.app/Contents/MacOS/RTProtectionDaemon -i Malwarebytes-Mac-5.9.0.1975.pkg

  [Running] com.malwarebytes.mbam.settings.daemon.plist (Malwarebytes Corporation - installed 2025-01-18)
    Executable: /Library/Application Support/Malwarebytes/MBAM/Engine.bundle/Contents/PlugIns/SettingsDaemon.app/Contents/MacOS/SettingsDaemon

Launch Agents:
  [Running] com.malwarebytes.mbam.frontend.agent.plist (Malwarebytes Corporation - installed 2025-01-18)
    Executable: /Library/Application Support/Malwarebytes/MBAM/Engine.bundle/Contents/PlugIns/FrontendAgent.app/Contents/MacOS/FrontendAgent

User Login Items:
  [Not Loaded] PasswordsMenuBarExtra (Apple - installed 2024-12-07)
    Modern Login Item
    /System/Applications/Passwords.app/Contents/Library/LoginItems/PasswordsMenuBarExtra.app

  [Running] WeatherMenu (Apple - installed 2024-12-07)
    Modern Login Item
    /System/Applications/Weather.app/Contents/Library/LoginItems/WeatherMenu.app

Applications:
  778 Apple apps
  29 3rd party apps
  6 x86-only apps
  No unsigned apps

App Extensions:
  Ad-blockers:
    [Loaded] Blocklist 2 - /Applications/Wipr.app
    [Loaded] Blocklist 4 - /Applications/Wipr.app
    [Loaded] Blocklist 1 - /Applications/Wipr.app
    [Loaded] Blocklist 3 - /Applications/Wipr.app

  Share services:
    [Loaded] Wipr - /Applications/Wipr.app

  Safari extensions:
    [Loaded] BrowserMask - /Applications/BrowserMask.app
    [Loaded] Obsidian Web Clipper Extension - /Applications/Obsidian Web Clipper.app
    [Loaded] Wipr Extra - /Applications/Wipr.app
    [Loaded] Safari Extension - /Applications/Proton Pass for Safari.app

  QuickLook Previews:
    [Loaded] EtreCheckQuickLook - ~/Downloads/EtreCheckPro.app
      com.etresoft.etrecheck4 *.etrecheck

Backup:
  Time Machine information is limited without Full Disk Access

Performance:
  System Load: 2.57 (1 min ago) 4.08 (5 min ago) 4.19 (15 min ago)
  Nominal I/O usage: 0.08 MB/s
  File system: 5.93 seconds
  Write speed: 6584 MB/s
  Read speed: 3750 MB/s

CPU Usage Snapshot:
  Type Overall
  System: 4 %
  User: 5 %
  Idle: 91 %

Top Processes Snapshot by CPU:
  Process (count) CPU (Source - Location)
  WindowServer 36.74 % (Apple)
  EtreCheckPro 17.36 % (Etresoft, Inc.)
  kernel_task 13.10 % (Apple)
  Safari 5.64 % (Apple)
  iTerm2 4.32 % (GEORGE NACHMAN)

Top Processes Snapshot by Memory:
  Process (count) RAM usage (Source - Location)
  com.apple.WebKit.WebContent (7) 2.34 GB (Apple)
  EtreCheckPro 1.42 GB (Etresoft, Inc.)
  iTerm2 957 MB (GEORGE NACHMAN)
  MTLCompilerService (31) 689 MB (Apple)
  mediaanalysisd 663 MB (Apple)

Top Processes Snapshot by Network Use:
  Process (count) Input / Output (Source - Location)
  com.apple.WebKit.Networking 2 MB / 22 KB (Apple)
  mDNSResponder 1 MB / 355 KB (Apple)
  apsd 74 KB / 439 KB (Apple)
  rapportd 90 KB / 280 KB (Apple)
  trustd 18 KB / 3 KB (Apple)

Top Processes Snapshot by Energy Use:
  Process (count) Energy (0-100) (Source - Location)
  WindowServer 13 (Apple)
  Sharing 5 (Not signed)
  RTProtectionDaemon 4 (Malwarebytes Corporation)
  iconservicesagent (2) 2 (Apple)
  iTerm2 2 (GEORGE NACHMAN)

Virtual Memory Information:
  Physical RAM: 48 GB

  Free RAM: 121 MB
  Used RAM: 18.53 GB
  Cached files: 29.35 GB

  Available RAM: 29.47 GB
  Swap Used: 0 B

Software Installs (past 60 days):
  Install Date Name (Version)
  2025-01-18 macOS 15.2 (15.2)
  2025-01-18 Proton Pass for Safari (1.27.2)
  2025-01-18 Malwarebytes for Mac (1.0)
  2025-01-18 MRTConfigData (1.93)
  2025-01-18 XProtectPlistConfigData (5285)
  2025-01-18 Gatekeeper Compatibility Data (1.0)
  2025-01-18 XProtectPayloads (149)
  2025-01-18 Wipr (2.2)
  2025-01-18 BrowserMask (1.2)
  2025-01-18 Obsidian Web Clipper (0.10.7)
  2025-01-18 SF Mono Fonts (6.0.1.1726709071)

Diagnostics Information (past 60 days):
  2025-01-18 19:22:30 lsd Crash (14 times)
    First occurrence: 2025-01-18 13:00:50
    Executable: /usr/libexec/lsd

  2025-01-18 16:50:55 spotlightknowledged High CPU Use
    Executable: /System/Library/Frameworks/CoreSpotlight.framework/spotlightknowledged

  2025-01-18 16:09:25 bluetoothuserd Crash (2 times)
    Executable: /usr/libexec/bluetoothuserd


End of report