Q: system breached?
I have a friend using Mac 10.10.5 and it's infected with numerous malware ie. genieo,vsearch,trovi and I thoroughly followed procedures to remove all the mentioned malware both manually and with the app Malwarebytes for mac, although is not normal after removing the malware. The below items are very odd to me and can someone tell me if what I'm reporting could be signs that the system has been compromised? please see below and Thanks!
1)The Trovi search page still returns in Safari and hyperlinks are redirected when clicked to adware sites.
2)A rogue apple script called "InstallExtension_8" tries to launch during or when I quit Safari in the Finder (in any user acct) but fails and shows this error:
While still open I inspected this script process in Activity Monitor > Info > Open Files and Ports the below items are shown:
/
/Library/Trovi/BrowserEnhancer.app/Contents/MacOS/InstallExtension_8.app/Content s/MacOS/applet
/usr/share/icu/icudt53l.dat
*** Note: I cannot locate /Library/Trovil directory, it does not exists
$ cd /Library/Trovi
-bash: cd: /Library/Trovi: No such file or directory
/System/Library/Components/AppleScript.component/Contents/MacOS/AppleScript
/System/Library/PrivateFrameworks/AppleScript.framework/Versions/A/AppleScript
/System/Library/CoreServices/SystemAppearance.bundle/Contents/Resources/SystemAp pearance.car
/System/Library/ColorSync/Profiles/Generic RGB Profile.icc
/System/Library/ColorSync/Profiles/sRGB Profile.icc
/System/Library/CoreServices/SystemAppearance.bundle/Contents/Resources/Graphite DarkAppearance.car
/System/Library/CoreServices/SystemAppearance.bundle/Contents/Resources/Accessib ilityDarkGraphiteAppearance.car
/System/Library/CoreServices/SystemAppearance.bundle/Contents/Resources/Accessib ilityVibrantLightAppearance.car
/System/Library/ColorSync/Profiles/Generic Gray Gamma 2.2 Profile.icc
/private/var/folders/_4/_gs3tgj15g97k31wg49nlf200000gp/0/com.apple.LaunchService s-107502.csstore
/System/Library/CoreServices/SystemAppearance.bundle/Contents/Resources/Graphite Appearance.car
/System/Library/CoreServices/SystemAppearance.bundle/Contents/Resources/Accessib ilityAppearance.car
/System/Library/CoreServices/SystemAppearance.bundle/Contents/Resources/Accessib ilityGraphiteAppearance.car
/System/Library/CoreServices/SystemAppearance.bundle/Contents/Resources/DarkAppe arance.car
/System/Library/CoreServices/SystemAppearance.bundle/Contents/Resources/Accessib ilityDarkAppearance.car
/System/Library/CoreServices/SystemAppearance.bundle/Contents/Resources/VibrantL ightAppearance.car
/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/HIToolbox.fram ework/Versions/A/Resources/Extras2.rsrc
/System/Library/PrivateFrameworks/CoreUI.framework/Versions/A/Resources/SArtFile .bin
/System/Library/Fonts/HelveticaNeueDeskInterface.ttc
/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/HIToolbox.fram ework/Versions/A/Resources/HIToolbox.rsrc
/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/HIToolbox.fram ework/Versions/A/Resources/English.lproj/Localized.rsrc
/System/Library/Frameworks/OpenCL.framework/Versions/A/Libraries/ImageFormats/un orm8_bgra.dylib
/System/Library/ColorSync/Profiles/Generic Gray Profile.icc
/System/Library/Keyboard Layouts/AppleKeyboardLayouts.bundle/Contents/Resources/AppleKeyboardLayouts-L.d at
/System/Library/Fonts/Helvetica.dfont
/private/var/folders/_4/_gs3tgj15g97k31wg49nlf200000gp/C/com.apple.iconservices/ store.index
/Library/Caches/com.apple.iconservices.store/FCBC3F77-4294-4419-BEF4-81170C782B6 0.isdata
/usr/lib/dyld
/private/var/db/dyld/dyld_shared_cache_x86_64
/dev/null
/dev/null
/dev/null
count=2, state=0x2
/System/Library/CoreServices/SystemAppearance.bundle/Contents/Resources/SystemAp pearance.car
/System/Library/CoreServices/SystemAppearance.bundle/Contents/Resources/Graphite Appearance.car
/System/Library/CoreServices/SystemAppearance.bundle/Contents/Resources/Accessib ilityAppearance.car
/System/Library/CoreServices/SystemAppearance.bundle/Contents/Resources/Accessib ilityGraphiteAppearance.car
/System/Library/CoreServices/SystemAppearance.bundle/Contents/Resources/DarkAppe arance.car
/System/Library/CoreServices/SystemAppearance.bundle/Contents/Resources/Graphite DarkAppearance.car
/System/Library/CoreServices/SystemAppearance.bundle/Contents/Resources/Accessib ilityDarkAppearance.car
/System/Library/CoreServices/SystemAppearance.bundle/Contents/Resources/Accessib ilityDarkGraphiteAppearance.car
/System/Library/CoreServices/SystemAppearance.bundle/Contents/Resources/VibrantL ightAppearance.car
/System/Library/CoreServices/SystemAppearance.bundle/Contents/Resources/Accessib ilityVibrantLightAppearance.car
/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/HIToolbox.fram ework/Versions/A/Resources/Extras2.rsrc
/Library/Trovi/BrowserEnhancer.app/Contents/MacOS/InstallExtension_8.app/Content s/Resources/applet.rsrc
/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/HIToolbox.fram ework/Versions/A/Resources/HIToolbox.rsrc
/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/HIToolbox.fram ework/Versions/A/Resources/English.lproj/Localized.rsrc
3)As soon as the system is started up, there are a bunch of processes running by very unusually named users, i.e. below shows user "unrelatedness" running:
$ id unrelatedness
uid=401(unrelatedness) gid=20(staff) groups=20(staff),12(everyone),61(localaccounts),403(com.apple.sharepoint.group. 2),100(_lpoperator),402(com.apple.sharepoint.group.1)
4)there are very mysterious folders in /Library: mostly all in shown below in red bold text and contain .conf and .sh files and are run by those mysterious users:
$ ls -la /Library
total 12216
drwxr-xr-x+ 98 root wheel 3332 Jun 5 20:54 .
drwxr-xr-x 36 root wheel 1292 Jun 5 17:01 ..
-rw-r--r-- 1 root wheel 0 Sep 9 2014 .localized
drwxr-xr-x 20 root admin 680 Jun 5 16:54 Application Support
drwxr-xr-x 10 root wheel 340 Sep 17 2015 Audio
drwxrwxr-x 96 root admin 3264 Sep 17 2015 Automator
drwxr-xr-x@ 3 root wheel 102 Jun 5 20:54 Babel
drwxrwxrwt 9 root admin 306 Jun 5 20:52 Caches
drwxr-xr-x 2 root wheel 68 Sep 9 2014 ColorPickers
drwxr-xr-x 4 root wheel 136 Sep 17 2015 ColorSync
drwxr-xr-x 2 root wheel 68 Mar 6 2015 Components
drwxr-xr-x 3 root wheel 102 Sep 9 2014 Compositions
drwxr-xr-x 2 root wheel 68 Mar 6 2015 Contextual Menu Items
drwxr-xr-x 3 root wheel 102 Jul 29 2015 CoreMediaIO
drwxr-xr-x 84 root wheel 2856 Sep 17 2015 Desktop Pictures
drwxr-xr-x 23 root wheel 782 Sep 17 2015 Dictionaries
drwxr-xr-x 3 root wheel 102 Mar 6 2015 DirectoryServices
drwxr-xr-x 9 root wheel 306 Sep 17 2015 Documentation
drwxr-xr-x 5 root wheel 170 Jun 5 17:01 DropboxHelperTools
drwxr-xr-x 13 root wheel 442 Jun 3 10:11 Extensions
drwxr-xr-x 5 root wheel 170 Sep 17 2015 Filesystems
drwxrwxr-t 242 root admin 8228 Sep 17 2015 Fonts
drwxr-xr-x 18 root admin 612 Sep 17 2015 Fonts Disabled
drwxr-xr-x 15 root wheel 510 Sep 17 2015 Frameworks
drwxr-xr-x 4 root wheel 136 Sep 17 2015 Graphics
drwxr-xr-x 7 root wheel 238 Sep 17 2015 Image Capture
drwxr-xr-x 2 root wheel 68 Feb 20 2015 Input Methods
drwxr-xr-x 12 root wheel 408 Jun 2 08:01 Internet Plug-Ins
drwxr-xr-x@ 3 root wheel 102 Jun 5 17:02 Isurus
drwxr-xr-x 4 root wheel 136 Sep 17 2015 Java
drwxr-xr-x 2 root wheel 68 Sep 9 2014 Keyboard Layouts
drwxr-xr-x 9 root wheel 306 Jun 5 20:51 Keychains
drwxr-xr-x 6 root wheel 204 Jun 5 16:54 LaunchAgents
drwxr-xr-x 29 root wheel 986 Jun 5 20:54 LaunchDaemons
drwxr-xr-x 5 root wheel 170 Jun 5 11:30 Logs
drwxr-xr-x 3 root wheel 102 Jun 5 16:58 Managed Preferences
drwxr-xr-x 3 root wheel 102 Jul 22 2015 Messages
drwxr-xr-x 37 root wheel 1258 Sep 17 2015 Modem Scripts
drwxr-xr-x 5 root wheel 170 May 12 2015 OpenDirectory
drwxr-xr-x 6 root wheel 204 Sep 17 2015 PDF Services
drwxrwxr-x 7 root admin 238 Sep 17 2015 Parallels
drwxr-xr-x 4 root wheel 136 Sep 9 2014 Perl
drwxr-xr-x 4 root wheel 136 Jun 2 08:01 PreferencePanes
drwxr-xr-x 108 root wheel 3672 Jun 5 20:54 Preferences
drwxr-xr-x@ 3 root wheel 102 Oct 15 2015 PrenanthesUpd
drwxr-xr-x 10 root admin 340 Jun 5 06:49 Printers
drwxr-xr-t 4 root wheel 136 Jun 5 16:49 PrivilegedHelperTools
drwxr-xr-x 4 root wheel 136 Sep 17 2015 Python
drwxr-xr-x 5 root wheel 170 Sep 17 2015 QuickLook
drwxr-xr-x 4 root wheel 136 Sep 17 2015 QuickTime
drwxrwxr-x 12 root admin 408 Sep 17 2015 Receipts
drwxr-xr-x 4 root wheel 136 Sep 17 2015 Ruby
drwxr-xr-x 3 root wheel 102 Sep 9 2014 Sandbox
drwxr-xr-x 3 root wheel 102 Sep 17 2015 Screen Savers
drwxr-xr-x 2 root wheel 68 Sep 9 2014 ScriptingAdditions
drwxr-xr-x 10 root wheel 340 Sep 17 2015 Scripts
drwxr-xr-x 4 root wheel 136 Sep 17 2015 Security
drwxr-xr-x 3 root wheel 102 Sep 17 2015 Server
drwxr-xr-x 3 root wheel 102 Sep 17 2015 Speech
drwxr-xr-x 2 root wheel 68 Sep 9 2014 Spelling
drwxr-xr-x 7 root wheel 238 Sep 17 2015 Spotlight
drwxr-xr-x 2 root wheel 68 Sep 9 2014 StartupItems
drwxr-xr-x 4 root wheel 136 Sep 17 2015 SystemMigration
drwxr-xr-x 2 root wheel 68 Sep 9 2014 SystemProfiler
drwxr-xr-x 5 root wheel 170 Jun 5 06:51 Updates
drwxr-xr-x 8 root wheel 272 Sep 9 2014 User Pictures
drwxr-xr-x 4 root wheel 136 Sep 17 2015 Video
drwxr-xr-x 5 root wheel 170 Jul 23 2015 WebServer
drwxr-xr-x 18 root wheel 612 Sep 17 2015 Widgets
drwxr-xr-x@ 3 root wheel 102 Jun 3 10:22 anonyma
drwxr-xr-x@ 3 root wheel 102 Jun 2 11:04 arthroncus
-rw-r--r-- 1 root wheel 6118473 May 27 07:56 backup.zip
drwxr-xr-x@ 3 root wheel 102 Sep 21 2015 carobUpd
drwxr-xr-x@ 3 root wheel 102 Jun 2 11:09 carpetweb
drwxr-xr-x@ 3 root wheel 102 Jun 5 09:50 chidden
drwxr-xr-x@ 3 root wheel 102 Jun 3 08:11 chun
drwxr-xr-x@ 3 root wheel 102 Jun 5 11:33 cystosarcoma
drwxr-xr-x@ 3 root wheel 102 Oct 15 2015 discoverableUpd
drwxr-xr-x@ 3 root wheel 102 Jun 3 08:49 dooley
drwxr-xr-x@ 3 root wheel 102 Jun 5 16:06 endocyclic
drwxr-xr-x@ 3 root wheel 102 Jun 5 20:54 exosporal
drwxr-xr-x 3 root wheel 102 Feb 12 2015 iTunes
drwxr-xr-x@ 3 root wheel 102 Jun 3 11:49 madhouse
drwxr-xr-x@ 3 root wheel 102 Jun 3 10:22 misdeed
-rwxrwxrwx@ 1 root wheel 126680 May 27 07:56 morkim
drwxr-xr-x@ 3 root wheel 102 Jun 3 08:11 nonidealist
drwxr-xr-x@ 3 root wheel 102 Jun 3 11:49 noropianic
drwxr-xr-x@ 3 root wheel 102 Oct 15 2015 physiologizeUpd
drwxr-xr-x@ 3 root wheel 102 Jun 5 06:46 replenishment
-rw------- 1 root wheel 258 May 27 07:56 settings.dat
drwxr-x--- 3 root wheel 102 Jun 2 11:05 stimulancyUpd
drwxr-xr-x@ 3 root wheel 102 Jun 3 10:22 superintellectual
drwxr-xr-x@ 3 root wheel 102 Jun 5 09:48 symphyostemonous
drwxr-xr-x@ 3 root wheel 102 Jun 5 16:10 tambac
drwxr-xr-x@ 3 root wheel 102 Jun 2 11:06 tricosylic
drwxr-x--- 3 root wheel 102 May 12 13:40 uelmeld
drwxr-xr-x@ 3 root wheel 102 Jun 2 12:09 unprecocious
-rw-r--r-- 1 root wheel 156 Jun 5 21:15 watch.log
Posted on Jun 5, 2016 6:51 PM

