Unrecognized User in my "EfiLoginUI" file (accessed by Root), and unrecognized Personal Shadow Keys? Have I Been Hacked?
I've been concerned that my Mac has been remotely accessed for a while now, so I've been trying to figure out where and who has been doing the accessing. Checking for login records returned nothing, but someone suggested that I check if the root user could be logged into as a sign (I didn't configure things that way) so I checked which files root have been accessing for the past couple days using this command:
-type f -user root -mtime -7 2>/dev/null
and started to look around to see what it was accessing. Most processes are pretty boring, but it seemed to be accessing a number of preboot files; a couple had proper names attatched.
In the EfiLoginUI folder there's a couple different files that I find concerning. One is labeled "Lucida13.efires" and "Lucida13White.efires" (name corresponds to someone I know) and a final one named "unknown_userUI.efires." Every time I turn on and connect to wifi (testing behaviour) the update date and the modifier date, the file's name starts to change.
I also found it accessing a file called "personal shadow keys" in KeyAccess. I set up key access a long time ago for school, but certainly never made "shadow keys." Is this normal? One seems to be tied to my zoom account and the file updated at the exact time of the call?
Have I been hacked? If I have, how can I find out more about who and what they're doing? I'll wipe it asap, but I'm curious what the forum thinks.
Edit: Also, how do I wipe this in the correct way?
MacBook Pro 14″