Malware / Spyware
Hello, using the referenced machine and Sierra, browsing in Chrome, I clicked on a link to an obscure bicycle-related website that was hacked, it took me to *** [****** is not part of the URL, I've included it to keep this link safe] where a robot voice started to tell me I was hacked. URL checker sites tell me this is a dirty link. Closed everything down. Installed Bitdefender, which found refog.keylogger hidden away in a Time Machine backup on an EHD (file path 1 below). That seemed like enough evidence to me that I'd been hacked so I initialised the SSD and installed High Sierra. Now Bitdefender says it's blocking malware at file path 2 below. I can't find this file path when I follow instructions to show hidden files, and I'm confused about why there should be backups on the drive - I haven't set any up.
I disconnected the EHD after the key logger was found and have not reconnected it since initialising the SSD.
I'm aware that antivirus software can come up with false positives ... a keylogger seems very suspect though. Bitdefender has also created an alert about what seems likely to be a harmless file, at file path 3 below. Bitdefender has found this on both the referenced iMac and my early 2016 MacBook.
Am I compromised by any or all these? Any other checks I should do or other advice?
My next step would be to replace the SSD. This has already taken days of my time and I have reinstalled loads of apps and restored some files (from a cloud backup pre-dating the apparent attack) so naturally I would prefer not to do this, but I will if it's the best way forward. Many thanks ...
File path 1: /Volumes/Seagate Backup Plus Drive/Backups.backupdb/Peter’s iMac/2015-12-12-002735/Macintosh HD/Library/.smoke/Refog.app/Contents/MacOS/Refog=>(Mach-O I386 ALL)
File path 2: /Volumes/iMac Backup/Backups.backupdb/Peter’s iMac/2014-05-29-192346/Macintosh HD/Library/.smoke/Refog.app/Contents/MacOS/Refog=>(Mach-O PowerPC UnknownCPUSubtype)
File path 3: /Users/peter/Desktop/Documents/cleanup old docs - NOT SORTED/Documents - from around 2009/PDJ personal docs/Peter Backup/OutLook BkUp.pst=>[Time: 2004/01/29 00:54:00][Subject: RE: report from 20 november meeting][From: Peter Duncan-Jones]=>Min Brief re Donor Responses Nov 03 Mtg.doc
<Link edited by Host as following the procedures at the site may lead to damage to the user’s device>
IMAC (RETINA 5K, 27-INCH, LATE 2015), macOS Sierra (10.12.5)