Hello Everyone,
I have the same problem as the OP.
Could someone please have a look and tell me if you think the results from my mac terminal are off? I followed Linc's (thanks!!) directions
on how to do this. Super helpful!
(Here's the background info)
I found a "Steallth.ipa" iOS Application on my mac. It had the iTunes logo but wasn't an iTunes file. When I checked the info on the file (5.6MB) -
I noticed that I only had permission to read as did everyone else. Only admin could read and write. (I don't think I ever installed an admin login).
Not sure what to make of this Stealth app?
Checked my firewall and it was on, but these connections were greenlighted:
cups-lpd
iTunes
JavaApplicationStub
By the way I don't have any remote access enabled, but did find that an App was added to my login item: WDDriveManagerStatusMenu. I think this might be
for my external Western Digital.
Also found 2 invisible drives on desktop "home" and "net". And then that all the bluetooth boxes were checked which I don't think I did. But I have to say I haven't
used this machine as much as I am now.
I left everything as is, to run the Terminal with the 5 steps outlined after a normal boot.
I've since, disabled the 3 apps as incoming connections and turned on
stealth. Changed the password for Admin and permissions too.
And now am hoping to find out from one of you that's it all because my machine is
getting old.
Here are my results. Please let me know your thoughts.
Thanks so much for your time!
Mikado
Mac Book Pro circa 2006/2007 running Mac OS X 10.6.8
Mac_Terminal_results:
Last login: Sun Jun 29 13:26:54 on console
Finkston:~ mikado$
Finkston:~ mikado$ extstat -kl | awk '!/com\.apple/{printf "%s %s\n", $6, $7}'
-bash: extstat: command not found
Finkston:~ mikado$
Finkston:~ mikado$ sudo launchctl list | sed 1d | awk '!/0x|com\.(apple|openssh|vix)|edu\.mit|org\.(amavis|apache|cups|isc|ntp|postfi x|x)/{print $3}'
Password:
com.wdc.drivemanagerservice
com.adobe.fpsaud
Finkston:~ mikado$
Finkston:~ mikado$ launchctl list | sed 1d | awk '!/0x|com\.apple|edu\.mit|org\.(x|openbsd)/{print $3}'
ws.agile.1PasswordAgent
Finkston:~ mikado$
Finkston:~ mikado$ ls -1A /e*/mach* {,/}L*/{Ad,Compon,Ex,Fram,In,Keyb,La,Mail/**,P*P,Priv,Qu,Scripti,Servi,Spo,Sta} * L*/Fonts 2> /dev/null
/Library/Address Book Plug-Ins:
.DS_Store
/Library/Components:
/Library/Extensions:
/Library/Frameworks:
.DS_Store
NyxAudioAnalysis.framework
PluginManager.framework
PrintMeSSL.framework
/Library/Input Methods:
Image Capture
/Library/Internet Plug-Ins:
.DS_Store
Flash Player.plugin
NP-PPC-Dir-Shockwave
QuickTime Plugin.plugin
flashplayer.xpt
nplastpass.plugin
/Library/Internet Plug-Ins (Disabled):
/Library/Keyboard Layouts:
/Library/LaunchAgents:
/Library/LaunchDaemons:
com.adobe.fpsaud.plist
com.wdc.drivemanagerservice.plist
/Library/PreferencePanes:
Flash Player.prefPane
/Library/PrivilegedHelperTools:
/Library/QuickLook:
GBQLGenerator.qlgenerator
iWork.qlgenerator
/Library/QuickTime:
AppleIntermediateCodec.component
AppleMPEG2Codec.component
Flip4Mac WMV Advanced.component
Flip4Mac WMV Export.component
Flip4Mac WMV Import.component
/Library/ScriptingAdditions:
Adobe Unit Types
/Library/Spotlight:
AppleWorks.mdimporter
GBSpotlightImporter.mdimporter
Microsoft Office.mdimporter
iWeb.mdimporter
iWork.mdimporter
/Library/StartupItems:
/etc/mach_init.d:
dashboardadvisoryd.plist
/etc/mach_init_per_login_session.d:
/etc/mach_init_per_user.d:
Library/Address Book Plug-Ins:
AdiumAddressBookAction_AIM.scpt
AdiumAddressBookAction_ICQ.scpt
AdiumAddressBookAction_Jabber.scpt
AdiumAddressBookAction_MSN.scpt
AdiumAddressBookAction_SMS.scpt
AdiumAddressBookAction_Yahoo.scpt
Library/Fonts:
176 DIN Schriften
AACHEN
AacheDMedSh1
Abadi MT Condensed Extra Bold
Abadi MT Condensed Light
Andale Mono
Arial
Arial Black
Arial Narrow
Arial Rounded Bold
Avant Garde
AvantGarBol
AvantGarBolObl
AvantGarBoo
AvantGarBooObl
AvantGarConBol
AvantGarConBoo
AvantGarConDem
AvantGarConMed
AvantGarDem
AvantGarDemObl
AvantGarExtLig
AvantGarExtLigObl
AvantGarMed
AvantGarMedObl
AvantGarXLig
AvantGarXLigObl
BCitNor
Base 12 Serif Family
BaseTweSer
BaseTweSerB
BaseTweSerBI
BaseTweSerI
BaseTweSerSCB
BaseTweSerSCBI
BaseTweSerSCI
BaseTweSerSma
Baskerville Old Face
Batang.ttf
Bauhaus 93
BayerArcTyp
BayerArchiType.t1
Bell MT
Bernard MT Condensed
BisteBol
BisteckBold.bmap
Bolt Bold
BoltBolICG
Book Antiqua
Bookman Old Style
Braggadocio
Britannic Bold
Brush Script
BureaEmp
BureaEmpIta
Bureau Empire (FB)
CITY
COMPACTA BD BT
CRILLEE startrek
Calisto MT
CalveMTBol
CalveMTLig
CalveMTMed
CalvertMT.bmap
Century
Century Gothic
Century Schoolbook
CitizBol
CitizBolIta
CitizLig
CitizLigIta
CitizenScreenFonts
CityBld
CityBol
CityBolIta
CityMed
CityMedIta
CityNor
Colonna
Comic Sans MS
CompaBTBol
CompaBTBolIta
CompaLig
CompaMTBol
Compacta-Light.scr
CompactaMTBd.bmap
ConduITCBol
ConduITCBolIta
ConduITCLig
ConduITCLigIta
ConduITCMed
ConduITCMedIta
Conduit ITC Bold
Conduit ITC Bold Italic
Conduit ITC Light
Conduit ITC Light Italic
Conduit ITC Medium
Conduit ITC Medium Italic
Cooper Black
Copperplate Gothic Bold
Copperplate Gothic Light
CrillTBolIta
CrillTExtBolIta
CrillTLigIta
CrillTRegIta
Curlz MT
DINEng
DINMit
DINNeuGroBolCon
DINNeuGroLig
DOT MATRIX
Desdemona
DotmaReg
Edwardian Script ITC
Engravers MT
Eurostile
Expo SSi
ExpoBlaSSiBla
ExpoBlaSSiBlaIta
ExpoBooSSiBoo
ExpoBooSSiBooIta
ExpoBooSSiMed
ExpoBooSSiMedIta
ExpoLigSSiLig
ExpoLigSSiLigIta
ExpoSSi
ExpoSSiBol
ExpoSSiBolIta
ExpoSSiIta
ExposBlaSSiBla
ExposBlaSSiBlaIta
ExposMedSSiMed
ExposMedSSiMedIta
ExposSSi
ExposSSiBol
ExposSSiBolIta
ExposSSiIta
Folio.bmap
FolioBol
FolioBolCon
FolioExtBol
FolioLig
FolioMed
Footlight Light
FreewBla
FreewDem
FreewLig
FreewRom
FreewRomIta
Garamond
GentlSanBol
GentlSanBolIta
GentlSanBoo
GentlSanBooIta
GentlSanLig
GentlSanLigIta
GentlSanUltBol
Gentle Sans
Georgia
Gill Sans Ultra Bold
Gloucester MT Extra Condensed
Goudy Old Style
Gulim.ttf
Haettenschweiler
Harrington
HelveNeuLig
HelveNeuMed
ITC Avant Garde gothic
Impact
Imprint MT Shadow
Kabel.bmap
KabelITCbyBTBol
KabelITCbyBTBoo
KabelITCbyBTDem
KabelITCbyBTMed
KabelITCbyBTUlt
Kino
KochOriginal screen fonts
Kocho
Lucida Blackletter
Lucida Bright
Lucida Calligraphy
Lucida Fax
Lucida Handwriting
Lucida Sans
Lucida Sans Typewriter
MS Gothic.ttf
MS Mincho.ttf
MS PGothic.ttf
MS PMincho.ttf
MT Extra
Matura Script Capitals
Maus
Maus.suit
Mistral
MitteNor
Modern No. 20
Monotype Corsiva
Monotype Sorts
NeogrMT
NeographikMT.bmap
News Gothic MT
OPTIBinStyBol
OPTIBinStyLig
OPTIBinderStyle.bmap
OPTIChaBol
OPTIChampion-Bold.bmap
OPTIComIta
OPTIComLig
OPTIComReg
OPTICompit
OPTIStaExt
OPTIStaXtrBolExt
OPTIStaines-Extended.bmap
OPTIVagRouBol
OPTIVagRound-Bold.bmap
Onyx
PMingLiU.ttf
Perpetua Titling MT
PlacaMTCon
Placard_MT_Cn
Playbill
RenneArcTyp
RennerArchiType.t1
Rockwell
Rockwell Extra Bold
Ronda
RondaBol
RondaLig
RondaMed
SimSun.ttf
Stencil
Tahoma
TapeGun
TapeGun.bmap
Times New Roman
Trebuchet MS
TwentCenMTUltBol
Twentieth Century
U49.t1
U49Nor
UNITUS-REGULAR
UltraBla
UltraBlack.bmap
UnituTBla
UnituTBlaIta
UnituTBol
UnituTBolIta
UnituTLig
UnituTLigIta
UnituTReg
UnituTRegIta
UnituTUltBol
Upsil
Upsilon.bmap
VAG.bmap
VAGRouBla
VAGRouBol
VAGRouLig
VAGRouThi
VectoLHBla
VectoLHBlaIta
VectoLHBol
VectoLHBolIta
VectoLHIta
VectoLHLig
VectoLHLigIta
VectoLHRom
Vectora Bitmaps
Verdana
Wide Latin
Wingdings
Wingdings 2
Wingdings 3
displdts.ttf
freeway
mittelschrift
Library/Input Methods:
.localized
Library/Internet Plug-Ins:
fbplugin_1_0_3.plugin
Library/Keyboard Layouts:
Library/LaunchAgents:
ws.agile.1PasswordAgent.plist
Library/PreferencePanes:
Growl.prefPane
Library/ScriptingAdditions:
1Password Addition.osax
Finkston:~ mikado$ osascript -e 'tell application "System Events" to get name of every login item' 2> /dev/null
WDDriveManagerStatusMenu
Finkston:~ mikado$