Keylogger, duplicate user account, idmsa script, bug bounty files and imported notes with programming.

Hello,



Having a bit of a mare really.

I had a security issue in which my apple id had been compromised and a key logger had been installed.

A duplicate of my user account was created on my macbook at 693GB. This baffled Apple Support my hd is only 512gb. Then I found numerous json files. Idmsa files, bug bounty files, imported notes with programming.
Also contacts had been added in which some of the script related too.

I wiped my macbook completley and also my iphone. I created a new fresh apple id. However the problems are still there and some of the files keep reappering.


Im willing to post up the scripts etc if anyone needs the to help.


But really im at my witts end and so id be grateful for anyhelp please.



MacBook Air (2020 or later)

Posted on Dec 25, 2021 9:54 AM

Reply

Similar questions

1 reply

Dec 25, 2021 7:53 PM in response to GJM2777

It's not required that you have an apple id on your mac. Will be more of a hassle to run without an apple id. Could re-install and not use an apple id. First order of business is Etrecheck.


I recommend etrecheck to assist in sorting out issues.


I'd run etrecheck. Etrecheck will analyze your machine and software and generate a report. Post results here so others can view. Experienced users have found the reported information useful when diagnosing problems. The proprietary stuff in the report gets filtered.


Install and run

-- Download etrecheck. Goto the  EtreCheck download page. The download link is at the bottom of the screen

-- Install etrecheck. Goto your download folder. Double click on EtreCheckPro.zip

-- Drag the app to the application folder if you wish.

-- Turn on full disk access for EtreCheck. This was how macos used to work. Do it for etrecheck not avast as in the instructions.

Enabling Full Disk Access in macOS Mojave (10.14) and higher | Official Avast Support

-- Double click on etrecheck to run.  The first five runs are free.


An alternative explanation how to install, run and report output for the EtreCheck Application

Using EtreCheck to Troubleshoot Potential… - Apple Community

Explanation of EtreCheck output by etresoft, the author.

Using EtreCheck - Apple Community



How to report etrecheck data.

1) Run etrecheck 😎 [ see above ].

2) When the report is done, click on the Export icon.

3) click on "Copy report" to copy to the clipboard


What to do with your report

4) Get back in your web browser and access your discussion. etc.

5) click on Additional text icon


which results in...


6) Paste your report and fill in a title.

7) click on "Add Text" button

8) post your post by clicking on reply or update

Robert


PS. You may also post on pastebin.com and post a link here.








This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Keylogger, duplicate user account, idmsa script, bug bounty files and imported notes with programming.

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.