Hacked or is this normal

8226334


Question to the above discussion. I know this is an older post, but i wanted to follow up with Kurt Langs response. My list also has _nearbyd and _reportmemoryexception. Is this normal? Maybe new updates added those?

Posted on Jul 8, 2020 10:53 AM

Reply
10 replies

Jul 8, 2020 11:19 AM in response to Nani2020

As in the thread you refer to, if you have a suspicion that you may have been hacked (which you almost certainly were NOT):


Please run Etrecheck and post its full report here. Use the "additional text" button and paste the report into the text box.

The report will flag possible issues, including files suspected of being malware.

By posting the report here, more experienced users will be able to look at it and help you fix things or - more likely - help you be confident that things are fine.

Jul 8, 2020 1:07 PM in response to Nani2020

What you did was help a loser infect Excel with an unwanted macro. Never, never, ever enable macros on a Word or Excel document you don't know the origin of.


Every Excel file you create or open from this point on will possibly have this macro attached to it. These are virtually all Windows malware macros that can't do any harm to a Mac, but you may now a carrier.


Close Excel. Go to this folder in your user account:


/Users/your_account/Library/Group Containers/UBF8T346G9.Office/User Content/


Open these two subfolders:


Chart Templates

Templates


Delete any files with an Excel icon. A template for Excel is typically named Book1.xltx. The number 1 will increment. But it will probably be whatever the crook named it. This assuming Excel automatically saved the template after opening the infected file.


Normal.dotm is Word's template. You don't need to remove that.


If you've opened and resaved any of your own Excel documents, or created new ones since opening the garbage file in the email, open those. If they ask to load a macro, deny it. Open a new, blank document. Copy/paste the data from the infected document into the blank one. Save that and then close and throw the old one away.

Jul 8, 2020 12:51 PM in response to Luis Sequeira1

Thank you. I will definitely try that.


See what happened was, I opened a spam email, from a real company which said I owed money and they were sending me my statement on an excel sheet. This excel sheet was password protected; they did provide the password. So instead of catching that it was a spam I fell for it and opened it. It then asked me to enable macros, which I did. I couldn’t see the actual statement as there was this message in a box that said to click on the yellow bar on top to “enable editing”. However, there was no yellow bar so I couldn’t proceed. I thought it was an error on my end so I closed it down and tried again, this time I did not enable macros. When that also didn’t work, I just closed it out again. I called the number under the email’s signature. The lady who answered told me it was probably spam and that I should change my password. Which I did. Anyhow, I panicked after and searched the web. I came across this article,

https://www.google.com/amp/s/www.zdnet.com/google-amp/article/this-phishing-email-contains-a-password-protected-file-dont-open-it/


and now I’m just trying to make sure nothing was actually download it to my Mac. Is there anything else I should be checking?

Jul 9, 2020 1:58 PM in response to Kurt Lang

Under "Chart Templates" there was nothing, and under "Templates", aside from the Word template you mentioned, I also have "NormalEmail.dotm", is that a normal one too?


When this happened I had multiple excel sheets already open (before I opened the spam one), honestly I'm not sure if they saved after, since an Apple rep had me restart the computer; I just closed everything out and don't remember if I hit save or not (I was too busy panicking). I'll reopen all and see if they ask me to load a macro. If they don't, they should be fine? Or should I still Copy/paste into a new one, just in case?

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Hacked or is this normal

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.