My MacBook Air is under a MITM attack??!

Hi, I’m sort of panicking right now because I’m on a 6 hour bus ride and I think my computer may be compromised.

I was at a bus terminal and for just approximately five minutes was trying to download music with Spotify for offline listening. There was a wifi network open and me and my friend connected with our macs, and the connection was super fast, almost impossibly fast which we didn’t doubt at all.

We board the bus right after, I open my laptop and see these error messages from 2 apps; Spotify and Calendar. I disconnect from the wifi and just turn off wifi and bluetooth because there was also a galaxy s6 trying to connect to my mac? which I believe probably was a mistake.. Anyways I’ve just used my friend’s iPhone to disconnect all cards from my PayPal account just in case, and am posting this on her phone because I’m scared to connect my Mac to the internet. The other error message I will post as a reply. What do you think?!? Have I been hacked? What can I do? Also somehow I can’t log in to forums using my main Apple ID, so I’m using a second one. I hope nothing serious happened..User uploaded file

Posted on Jul 10, 2018 7:05 PM

Reply

Similar questions

9 replies

Jul 17, 2018 12:43 PM in response to coolmichelle

I suspect that you connected to a malicious wifi network. The intent would have likely been phishing attacks, by directing you to malicious domains pretending to be the real thing. The good news is that this by itself would not have infected your Mac. The bad news is that it could have captured any data you transmitted while connected to that network.


If you're still seeing the effects when you're no longer connected to that network, and are connected to a legitimate network, then you probably need to restart the computer to flush any cached network settings.


I don't see anything I can immediately identify as malicious on your computer, but there's a lot of stuff I'm not familiar with, so I can't say for sure. I can say that PUP.MPlayerX would not have caused this problem... that's just junk software.

Jul 10, 2018 7:43 PM in response to coolmichelle

Download this program which was written by Thomas Reed, a long time poster. The program will do the work for you which makes it easy. There is no reason to leave it installed once troubleshooting is finished. The free version doesn't update itself. If you need it again, you can download it again.


Malwarebytes Anti-Malware for Mac 10.10 and later


Malwarebytes uninstall


If that doesn't find anything, try running this program in your normal user account, then copy and paste the output in a reply. The program was created by etresoft, a frequent contributor. Please use copy and paste as screen shots can be hard to read. Click “Share Report” button in the toolbar, select “Copy Report” and then paste into a reply. This will show what is running on your computer. No personal information is shown. You can run the report for free at least once, but if you run it several times, at some point it will ask you to pay a license fee.

Etrecheck – System Information

Jul 11, 2018 2:13 AM in response to Eric Root

EtreCheck version: 4.3.4 (4D037)

Report generated: 2018-07-11 11:11:13

Download EtreCheck from https://etrecheck.com

Runtime: 2:42

Performance: Excellent


Problem: Other problem

Description:

My MacBook might be under a MITM attack; various alerts that it cannot verify the identity of the server have arisen


Major Issues:

Anything that appears on this list needs immediate attention.


No Time Machine backup- Time Machine backup not found.

Unsigned files- There are unsigned software installed that could be adware and should be reviewed.

More than one antivirus app- This machine has multiple antivirus apps installed.


Minor Issues:

These issues do not need immediate attention but they may indicate future problems.


High battery cycle count- Your battery may be losing capacity.

Apps with heavy CPU usage- There have been numerous cases of apps with heavy CPU usage.

System modifications- There are a large number of system modifications running in the background.

32-bit Apps- This machine has 32-bits apps that may have problems in the future.


Hardware Information:

MacBook Air (11-inch, Early 2015)

MacBook Air Model: MacBookAir7,1

1 1.6 GHz Intel Core i5 (i5-5250U) CPU: 2-core

4 GB RAM - Not upgradeable

BANK 0/DIMM0 - 2 GB DDR3 1600 ok

BANK 1/DIMM0 - 2 GB DDR3 1600 ok

Battery: Health = Normal - Cycle count = 874


Video Information:

Intel HD Graphics 6000 - VRAM: 1536 MB

Color LCD 1366 x 768


Drives:

disk0 - APPLE SSD AP0256H 251.00 GB (Solid State - TRIM: Yes)

Internal PCI-Express 5.0 GT/s x4 NVM Express

disk0s1 - EFI [EFI] 315 MB

disk0s2 - C******r [Core Storage Container] 250.04 GB

disk1 - Macintosh HD (Journaled HFS+) 249.68 GB

disk0s3 - Recovery HD [Recovery] 650 MB


Mounted Volumes:

disk1 - Macintosh HD 249.68 GB (33.77 GB free)

Journaled HFS+

Mount point: /

Encrypted


Network:

Interface usbmodem1420: MT65xx Preloader

Interface en0: Wi-Fi

802.11 a/b/g/n/ac

One IPv4 address

Interface en3: iPhone

Interface en2: Bluetooth PAN

Interface bridge0: Thunderbolt Bridge


System Software:

OS X El Capitan 10.11.6 (15G17023)

Time since boot: About a day

System Load: 1.67 (1 min ago) 2.32 (5 min ago) 2.44 (15 min ago)


Configuration Files:

/etc/hosts - Count: 6


Security:

System Status
Gatekeeper Mac App Store and identified developers
System Integrity Protection Enabled


Unsigned Files:

Launchd: /Library/LaunchAgents/com.unet.trustnetcert.plist

Executable: /Applications/TrustNetCert.app/Contents/MacOS/TrustNetCert

Details: Exact match found in the whitelist - probably OK

Launchd: ~/Library/LaunchAgents/com.valvesoftware.steamclean.plist

Executable: /Users/***/Library/Application Support/Steam/SteamApps/steamclean

Details: Exact match found in the whitelist - probably OK

Launchd: /Library/LaunchAgents/com.wizvera.delfino.plist

Executable: /Applications/Delfino/delfino.app/Contents/MacOS/delfino

Details: Exact match found in the whitelist - probably OK

Launchd: /Library/LaunchAgents/com.wizvera.veraport.plist

Executable: /Applications/Veraport/veraport.app/Contents/MacOS/veraport

Details: Exact match found in the whitelist - probably OK

Launchd: /Library/LaunchDaemons/com.nprotect.nosintgdmn.plist

Executable: /Applications/nProtect/nProtect Online Security V1/nosintgdmn

Details: Exact match found in the whitelist - probably OK

Launchd: /Library/LaunchDaemons/PT.updd.plist

Executable: /Library/PrivilegedHelperTools/PT.updd

Details: Exact match found in the whitelist - probably OK

Launchd: ~/Library/LaunchAgents/mega.mac.megaupdater.plist

Executable: /Applications/MEGAsync.app/Contents/MacOS/MEGAupdater

Details: Domain name invalid - possibly adware



32-bit Applications:

28 32-bit apps


Kernel Extensions:

/Library/Extensions

[Loaded] MB_MBAM_Protection.kext (Malwarebytes Corporation, 3.3 - SDK 10.13)


System Launch Agents:

[Not Loaded] 7 Apple tasks
[Loaded] 145 Apple tasks
[Running] 88 Apple tasks


System Launch Daemons:

[Not Loaded] 46 Apple tasks
[Loaded] 152 Apple tasks
[Running] 93 Apple tasks
[Other] One Apple task


Launch Agents:

[Running] com.ahnlab.astxagent.plist (AhnLab, INC. - installed 2018-05-04)
[Running] com.adobe.AdobeCreativeCloud.plist (Adobe Systems, Inc. - installed 2017-09-25)
[Not Loaded] com.adobe.AAM.Updater-1.0.plist (? ffb65062 - installed 2016-12-22)
[Running] com.huion.HuionTabletInfo.agent.plist (Tan Huang - installed 2017-05-17)
[Loaded] com.google.keystone.agent.plist (Google, Inc. - installed 2018-02-04)
[Not Loaded] com.adobe.GC.Invoker-1.0.plist (Adobe Systems, Inc. - installed 2018-06-02)
[Other] com.adobe.ARMDCHelper.cc24aef4a1b90ed56a725c38014c95072f92651fb65e1bf9c8e43c37a2 3d420d.plist (Adobe Systems, Inc. - installed 2018-02-15)
[Running] com.wizvera.delfino.plist (? d943b725 - installed 2017-06-20)
[Running] com.wizvera.veraport.plist (? fefe0305 - installed 2017-05-24)
[Running] com.malwarebytes.mbam.frontend.agent.plist (Malwarebytes Corporation - installed 2018-05-22)
[Running] com.unet.trustnetcert.plist (? bd8cfd1b - installed 2016-07-12)
[Running] com.huion.HuionTabletConsole.agent.plist (? acd8d801 - installed 2017-05-17)


Launch Daemons:

[Loaded] com.adobe.ARMDC.SMJobBlessHelper.plist (Adobe Systems, Inc. - installed 2018-02-15)
[Running] com.malwarebytes.mbam.settings.daemon.plist (Malwarebytes Corporation - installed 2018-05-22)
[Running] com.malwarebytes.mbam.rtprotection.daemon.plist (Malwarebytes Corporation - installed 2018-05-22)
[Not Loaded] org.eyebeam.SelfControl.plist (Charlie Stigler - installed 2017-11-29)
[Running] com.ahnlab.astxd.plist (AhnLab, INC. - installed 2018-05-04)
[Loaded] com.adobe.acc.installer.plist (Adobe Systems, Inc. - installed 2017-09-25)
[Running] PT.updd.plist (? 0 - installed 2017-09-23)
[Loaded] com.adobe.fpsaud.plist (Adobe Systems, Inc. - installed 2018-06-02)
[Loaded] com.nprotect.kext.nProtectFW.plist (Apple - installed 2017-10-26)
[Loaded] com.nprotect.nosintgdmn.plist (? 6a46f04e - installed 2017-04-18)
[Loaded] com.adobe.agsservice.plist (Adobe Systems, Inc. - installed 2018-06-02)
[Loaded] com.zenmate.charon-xpc.plist (ZenGuard GmbH - installed 2016-12-08)
[Loaded] com.adobe.ARMDC.Communicator.plist (Adobe Systems, Inc. - installed 2018-02-15)
[Running] com.adobe.agmservice.plist (Adobe Systems, Inc. - installed 2018-06-02)
[Loaded] com.google.keystone.daemon.plist (Google, Inc. - installed 2018-03-06)


User Launch Agents:

[Running] com.spotify.webhelper.plist (Spotify - installed 2018-07-10)
[Loaded] mega.mac.megaupdater.plist (? 0 - installed 2018-07-10)
[Loaded] com.valvesoftware.steamclean.plist (? 0 - installed 2018-06-25)
[Not Loaded] com.adobe.GC.Invoker-1.0.plist (Adobe Systems, Inc. - installed 2018-06-02)
[Not Loaded] com.adobe.AAM.Updater-1.0.plist (? 0 - installed 2016-08-29)


User Login Items:

SkyFonts Application (? - installed 2017-11-28)

(/Applications/SkyFonts/SkyFonts.app)

Flux Application (Michael Herf - installed 2018-04-24)

(/Applications/Flux.app)

iTunesHelper Application (Apple - installed 2018-06-04)

(/Applications/iTunes.app/Contents/MacOS/iTunesHelper.app)

Android File Transfer Agent Application (? - installed 2012-10-15)

(/Users/***/Library/Application Support/Google/Android File Transfer/Android File Transfer Agent.app)

Backup and Sync from Google Application (Google, Inc. - installed 2018-05-30)

(/Applications/Backup and Sync.app)

MEGAsync Application (? - installed 2018-05-23)

(/Applications/MEGAsync.app)

EOS Utility Application (? - installed 2016-12-27)

(/Applications/Canon Utilities/EOS Utility/EOS Utility.app)

StartUpHelper SMLoginItem (Spotify - installed 2018-07-09)

(/Applications/Spotify.app/Contents/Library/LoginItems/StartUpHelper.app)

WunderlistHelper SMLoginItem (Mac App Store - installed 2016-10-29)

(/Applications/Wunderlist.app/Contents/Library/LoginItems/WunderlistHelper.app)

KakaoTalkHelper SMLoginItem (Mac App Store - installed 2016-10-29)

(/Applications/KakaoTalk.app/Contents/Library/LoginItems/KakaoTalkHelper.app)

Monotype SkyFontsHelper SMLoginItem (Monotype Imaging - installed 2017-11-28)

(/Applications/SkyFonts/SkyFonts.app/Contents/Library/LoginItems/Monotype SkyFontsHelper.app)


Internet Plug-ins:

npefdsplugin: (installed 2015-07-03)

o1dbrowserplugin: 5.41.3.0 (installed 2017-10-13)

npUniSignWebPlugin: UniSignWebPlugin_x86_64 3.0.1.0 (installed 2014-03-11)

Default Browser: 601 (installed 2016-08-13)

Delfino: 1.2.3.2 (installed 2014-10-29)

npraontouchenex: 1.0.1.1106 (installed 2017-03-16)

Veraport: 1.1.0.2 (installed 2017-05-24)

AdobeAAMDetect: 3.0.0.0 (installed 2017-09-25)

FlashPlayer-10.6: 30.0.0.113 (installed 2018-06-07)

AdobePDFViewerNPAPI: 17.012.20098 (installed 2018-05-18)

QuickTime Plugin: 7.7.3 (installed 2017-11-24)

Flash Player: 30.0.0.113 (installed 2018-06-07)

googletalkbrowserplugin: 5.41.3.0 (installed 2015-12-11)

AdobePDFViewer: 18.011.20040 (installed 2018-05-18)

npUniCRSV2Plugin: UniCRSV2Plugin_x86_64 1.0.2.0 (installed 2014-02-14)


Safari Extensions:

Pin It Button.safariextz - Pinterest, Inc. - http://www.pinterest.com/(installed 2017-05-17)
Criptext Mail.safariextz - Criptext Inc - https://criptext.com(installed 2016-07-24)


3rd Party Preference Panes:

Flash Player (installed 2018-06-02)


Time Machine:

Time Machine Not Configured!


Top Processes by CPU:

Process (count) Source % of CPU Location
WindowServer Apple 11
kernel_task Apple 3
Adobe CEF Helper (3) Adobe Systems, Inc. 1
Calendar ? 1 /Applications/Calendar.app
Creative Cloud Adobe Systems, Inc. 1


Top Processes by Memory:

Process (count) Source RAM usage Location
kernel_task Apple 776 MB
com.apple.WebKit.WebContent (24) Apple 497 MB
Spotify Helper (3) Spotify 70 MB
Spotify Spotify 47 MB
WindowServer Apple 43 MB


Top Processes by Energy Use:

Process (count) Source Energy (0-100) Location
RTProtectionDaemon Malwarebytes Corporation 24
WindowServer Apple 5
Adobe CEF Helper (3) Adobe Systems, Inc. 1
com.apple.WebKit.WebContent (24) Apple 1
sysmond Apple 0


Virtual Memory Information:

Available RAM 1.09 GB
Free RAM 19 MB
Used RAM 2.91 GB
Cached files 1.07 GB
Swap Used 763 MB


Software Installs (past 30 days):

Name Version Install Date
MRTConfigData 1.35 2018-06-22
Remote Mouse 2.901 2018-06-26
GIF Brewery 3 3.8.2 2018-06-26
Melon 1.1.3 2018-07-03
Gatekeeper Configuration Data 146 2018-07-05
Malwarebytes for Mac 1.0 2018-07-11


Diagnostics Information (past 7 days):

2018-07-10 12:47:13 com.apple.WebKit.WebContent CPU (11 times)

/System/Library/StagedFrameworks/Safari/WebKit.framework/Versions/A/XPCServices/ com.apple.WebKit.WebContent.xpc/Contents/MacOS/com.apple.WebKit.WebContent


2018-07-10 01:47:56 Adobe CEF Helper.app Crash (5 times)

/Library/Application Support/Adobe/*/Adobe CEF Helper.app


2018-07-09 01:22:29 Software Update.app CPU

/System/Library/CoreServices/Software Update.app



End of report

Thank you so much! I ran MalwareBytes and it removed PUP.MPlayerX, and then ran EtreCheck.

Jul 11, 2018 4:29 PM in response to Eric Root

Hi Eric,


I've been taking another thorough look through the system, and this time I got two new error messages;

1. "Another device on the network is using your computer’s ip address" just popped up as I was using safari
2. "There was an error in iCloud preferences." when I tried to click on iCloud preferences in System Preferences as the iCloud calendar was not working. Could this be due to lack of space for not renewing subscription on iCloud?


Maybe I'm paranoid, but it's just that these errors have been occurring subsequently and I'm scared to make any bank transactions on my Mac until they return to normal. Would there be anything else I can try to get a sense of security?



Thanks.

Jul 17, 2018 1:49 PM in response to coolmichelle

Configuration Files:

/etc/hosts - Count: 6

In addition to the excellent comments provided by Eric Root and thomas_r., I suggest that you review your Mac's hosts file. It appears to have been modified ... potentially by malware or adware.


Take a look at the following articles for more details:

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

My MacBook Air is under a MITM attack??!

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.