FiveMenM

Q: Unknown users

Yesterday at 00:49 hours I probably downloaded and opened some malicious software on my Mac. Recognizing it, I stopped any installations, moved files to the trash and deleted the stuff. Next reboot of the system and run through the files to see what damage was done.

 

Unwanted programs were installed (ZipCloud, MacKeeper), which I removed. I ran Bitdefender to search for any threats on my Ma. Results were some files in deep libraries: /Library/Hunnian/Contents/MacOS... and /private/var/tmp/Injector10052016/Injector.app/COntents/MacOS...

 

As I did not find any information on these files on the internet I decided to delete them. Especially when I noted that the timestamp of creation of the files matched 00:49 hours.

 

In addition I looked at other files that were changed around this time. Especially in the deeper directories. This is when I found the account policylog file which shows some interesting password changes that were definitely not initiated by me. It seems also that I have an active user 'borg' not known to me. The user also had a folder within the private/var dedicated to his access only.

 

Anyone known to the 'borg' user and its intentions? And _mbsetupuser?

 

Naamloos.jpgNaamloos2.jpg

MacBook, Mac OS X (10.5.2)

Posted on Sep 22, 2016 3:23 PM

Close

Q: Unknown users

  • All replies
  • Helpful answers

  • by Kappy,

    Kappy Kappy Sep 22, 2016 3:30 PM in response to FiveMenM
    Level 10 (271,323 points)
    Desktops
    Sep 22, 2016 3:30 PM in response to FiveMenM

    Not an OS X user. If you don't recognize it, then I think it may be time to erase and install OS X.

  • by Eric Root,

    Eric Root Eric Root Sep 22, 2016 8:02 PM in response to FiveMenM
    Level 9 (72,223 points)
    iTunes
    Sep 22, 2016 8:02 PM in response to FiveMenM

    Try running this program and then copy and paste the output in a reply. The program was created by Etresoft, a frequent contributor.  Please use copy and paste as screen shots can be hard to read. On the screen with Options, please open Options and check the bottom 2 boxes before running. Click “Share Report” button in the toolbar, select “Copy to Clipboard” and then paste into a reply. This will show what is running on your computer. No personal information is shown.
      

    Etrecheck – System Information

  • by FiveMenM,

    FiveMenM FiveMenM Sep 22, 2016 11:15 PM in response to Kappy
    Level 1 (4 points)
    Mac OS X
    Sep 22, 2016 11:15 PM in response to Kappy

    Many thanks for your replies. I already thought of reinstalling OS X to be my last resort.

     

    Results of EtreCheck:

    EtreCheck version: 3.0.5 (309)

    Report generated 2016-09-23 08:14:52

    Download EtreCheck from https://etrecheck.com

    Runtime 1:27

    Performance: Excellent

     

    Click the [Support] links for help with non-Apple products.

    Click the [Details] links for more information about that line.

    Click the [Remove] links to remove adware.

     

    Problem: Other problem

    Description:

    Possible malicious activity on Mac

     

    Hardware Information:

        MacBook Pro (Retina, 13-inch, Early 2015)

        [Technical Specifications] - [User Guide] - [Warranty & Service]

        MacBook Pro - model: MacBookPro12,1

        1 2,7 GHz Intel Core i5 CPU: 2-core

        16 GB RAM Not upgradeable

            BANK 0/DIMM0

                8 GB DDR3 1867 MHz ok

            BANK 1/DIMM0

                8 GB DDR3 1867 MHz ok

        Bluetooth: Good - Handoff/Airdrop2 supported

        Wireless:  en0: 802.11 a/b/g/n/ac

        Battery: Health = Normal - Cycle count = 78

     

    Video Information:

        Intel Iris Graphics 6100

            Color LCD 2560 x 1600

     

    System Software:

        OS X El Capitan 10.11.6 (15G1004) - Time since boot: less than an hour

     

    Disk Information:

        APPLE SSD SM0256G disk0 : (251 GB) (Solid State - TRIM: Yes)

            EFI (disk0s1) <not mounted> : 210 MB

            Recovery HD (disk0s3) <not mounted>  [Recovery]: 650 MB

            Macintosh HD (disk1) / : 249.78 GB (175.05 GB free)

                Encrypted AES-XTS Unlocked

                Core Storage: disk0s2 250.14 GB Online

     

    USB Information:

        Broadcom Corp. Bluetooth USB Host Controller

     

    Thunderbolt Information:

        Apple Inc. thunderbolt_bus

     

    Gatekeeper:

        Anywhere

     

    Adware:

        ~/Library/LaunchAgents/com.jdibackup.ZipCloud.autostart.plist

        ~/Library/LaunchAgents/com.jdibackup.ZipCloud.notify.plist

        2 adware files found. [Remove]

     

    Kernel Extensions:

            /Applications/Boxcryptor.app

        [loaded]    com.boxcryptor.BCFS.filesystems.bcfs (3.4.1 - SDK 10.9 - 2016-08-12) [Support]

     

    System Launch Agents:

        [not loaded]    7 Apple tasks

        [loaded]    155 Apple tasks

        [running]    77 Apple tasks

     

    System Launch Daemons:

        [not loaded]    46 Apple tasks

        [loaded]    153 Apple tasks

        [running]    91 Apple tasks

     

    Launch Agents:

        [loaded]    com.oracle.java.Java-Updater.plist (2016-02-16) [Support]

        [not loaded]    com.teamviewer.teamviewer.plist (2016-02-01) [Support]

        [not loaded]    com.teamviewer.teamviewer_desktop.plist (2016-02-01) [Support]

        [loaded]    org.macosforge.xquartz.startx.plist (2014-08-11) [Support]

     

    Launch Daemons:

        [running]    com.80pct.FreedomHelper.plist (2016-05-03) [Support]

        [loaded]    com.adobe.fpsaud.plist (2016-08-30) [Support]

        [loaded]    com.boxcryptor.BCFS.KextLoaderHelper.plist (2015-11-14) [Support]

        [running]    com.boxcryptor.osx.PrivilegedHelper.plist (2016-08-12) [Support]

        [loaded]    com.microsoft.autoupdate.helpertool.plist (2016-08-03) [Support]

        [loaded]    com.microsoft.office.licensingV2.helper.plist (2015-11-05) [Support]

        [loaded]    com.oracle.java.Helper-Tool.plist (2016-02-16) [Support]

        [loaded]    com.teamviewer.Helper.plist (2016-02-01) [Support]

        [not loaded]    com.teamviewer.teamviewer_service.plist (2016-02-01) [Support]

        [not loaded]    org.eyebeam.SelfControl.plist (2016-05-03) [Support]

        [loaded]    org.macosforge.xquartz.privileged_startx.plist (2014-08-11) [Support]

     

    User Launch Agents:

        [running]    Focus.plist (2016-05-06) [Support]

        [failed]    com.jdibackup.ZipCloud.autostart.plist (2016-09-22) Adware!  [Remove]

            /usr/bin/open

        [loaded]    com.jdibackup.ZipCloud.notify.plist (2016-09-22) Adware!  [Remove]

            /usr/bin/open

        [running]    com.spotify.webhelper.plist (2016-09-23) [Support]

     

    User Login Items:

        iTunesHelper    Programma Hidden (/Applications/iTunes.app/Contents/MacOS/iTunesHelper.app)

        Flux    Programma Hidden (/Applications/Flux.app)

        Dropbox    Programma Hidden (/Applications/Dropbox.app)

        Boxcryptor    Programma Hidden (/Applications/Boxcryptor.app)

        Spotify    Programma Hidden (/Applications/Spotify.app)

        Freedom    Programma Hidden (/Applications/Freedom.app)

     

    Internet Plug-ins:

        FlashPlayer-10.6: 23.0.0.162 - SDK 10.9 (2016-09-13) [Support]

        QuickTime Plugin: 7.7.3 (2016-09-11)

        Flash Player: 23.0.0.162 - SDK 10.9 (2016-09-13) [Support]

        JavaAppletPlugin: Java 8 Update 25 (2016-02-16) Check version

        Default Browser: 601 - SDK 10.11 (2016-09-11)

     

    3rd Party Preference Panes:

        Flash Player (2016-08-30) [Support]

        Java (2014-09-18) [Support]

     

    Time Machine:

        Time Machine not configured!

     

    Top Processes by CPU:

            13%    kernel_task

             5%    WindowServer

             2%    fontd

             2%    sysmond

             0%    Spotify Helper(2)

     

    Top Processes by Memory:

        1.00 GB    kernel_task

        393 MB    helpd

        360 MB    Safari

        344 MB    com.apple.WebKit.WebContent

        295 MB    Spotify Helper(2)

     

    Virtual Memory Information:

        8.70 GB    Free RAM

        7.29 GB    Used RAM (2.94 GB Cached)

        0 B    Swap Used

     

    Diagnostics Information:

        Sep 23, 2016, 08:04:53 AM    Self test - passed

        Sep 23, 2016, 12:34:59 AM    /Library/Logs/DiagnosticReports/DrSafety_2016-09-23-003459_[redacted].cpu_resou rce.diag [Details]

            /Applications/DrSafety.app/Contents/MacOS/DrSafety

        Sep 23, 2016, 12:00:07 AM    ~/Library/Logs/DiagnosticReports/Finder_2016-09-23-000007_[redacted].crash

            com.apple.finder - /System/Library/CoreServices/Finder.app/Contents/MacOS/Finder

        Sep 22, 2016, 07:10:54 AM    /Library/Logs/DiagnosticReports/BitdefenderVirusScanner_2016-09-22-071054_[reda cted].cpu_resource.diag [Details]

            /Applications/BitdefenderVirusScanner.app/Contents/MacOS/BitdefenderVirusScanne r

        Sep 22, 2016, 01:01:16 AM    /Library/Logs/DiagnosticReports/BitdefenderVirusScanner_2016-09-22-010116_[reda cted].cpu_resource.diag [Details]

        Sep 22, 2016, 12:45:34 AM    ~/Library/Logs/DiagnosticReports/SmartPLS_2016-09-22-004534_[redacted].crash

            com.smartpls - /Applications/SmartPLS.app/Contents/MacOS/SmartPLS

        Sep 22, 2016, 12:45:22 AM    ~/Library/Logs/DiagnosticReports/SmartPLS_2016-09-22-004522_[redacted].crash

        Sep 22, 2016, 12:45:19 AM    ~/Library/Logs/DiagnosticReports/SmartPLS_2016-09-22-004519_[redacted].crash

        Sep 22, 2016, 12:45:18 AM    ~/Library/Logs/DiagnosticReports/SmartPLS_2016-09-22-004518_[redacted].crash

        Sep 22, 2016, 12:45:17 AM    ~/Library/Logs/DiagnosticReports/SmartPLS_2016-09-22-004517_[redacted].crash

        Sep 22, 2016, 12:45:15 AM    ~/Library/Logs/DiagnosticReports/SmartPLS_2016-09-22-004515_[redacted].crash