Does the following show infection of flashback or flashfake etc? I followed some instructions about Launchagents but don't know how to read them
ls -la ~/Library/LaunchAgents
grep "/Users/$USER/\..*" ~/Library/LaunchAgents/* | grep -v "/Users/$USER/\.Trash"
William-Nicols-iMac:~ billynicol$ ls -la ~/Library/LaunchAgents
total 64
drwx------ 9 billynicol staff 306 9 Apr 22:26 .
drwx------@ 59 billynicol staff 2006 9 Apr 22:21 ..
-rw-r--r--@ 1 billynicol staff 6148 9 Apr 22:26 .DS_Store
-rw-r--r-- 1 billynicol staff 618 12 Oct 21:00 com.apple.AddressBook.ScheduledSync.PHXCardDAVSource.2DF3B7F9-9CFE-47E0-BE4C-51 E3F211FE7E.plist
-rw-r--r-- 1 billynicol staff 901 28 Feb 2011 com.apple.CSConfigDotMacCert-billynicol@me.com-SharedServices.Agent.plist
-rw-r--r-- 1 billynicol staff 817 28 Feb 2011 com.apple.SafariBookmarksSyncer.plist
-rw-r--r-- 1 billynicol staff 540 28 Feb 16:47 com.avast.install.plist
-rw-r--r-- 1 billynicol staff 807 9 Jul 2011 com.google.keystone.agent.plist
-rw-r--r-- 1 billynicol staff 776 16 Sep 2011 com.valvesoftware.steamclean.plist
William-Nicols-iMac:~ billynicol$
William-Nicols-iMac:~ billynicol$ grep "/Users/$USER/\..*" ~/Library/LaunchAgents/* | grep -v "/Users/$USER/\.Trash"
William-Nicols-iMac:~ billynicol$
and
can I ask:
I found the ".flserv" and "com.adobe.flp.plist" on my mac, but when I checked using instructions from http://brakertech.com/detect-mac-flashback/ through terminal it says system clear. I also checked through Kaperskyhttp://www.flashbackcheck.com/ and if I put my mac UUID in, it also says I am or have been infected. I wonder if even although the files were there and created a 'bot' with my Mac, the actual malware in safari and firefox was not installed. Is this correct?
|