Help, please!  I've Been Hacked!  Firewall & Admin permissions changed?

Running on 10.4
MacBook Pro
You guys have been great, and I tried to read as many threads as I could to solve the problem on my own, but I'm in way too over my head. Okay, I'm going to struggle through explaining this as best I can and just list the "highlights" of what has been going on. More details are below.
Several events occurred simultaneously, and I'm not sure which did what damage.
Scanned my machine with ClamXav. Trojan was found. I deleted the Trojan.
I downloaded a script (against my better judgement), opened it and my machine started working hard. Activity monitor was going crazy. Immediately shut down Airport. Looked at my Firewall, and EVERYTHING was open. I always keep Firewall on. Looked at logs (and saved a few). Good thing I did because for some reason, I now do not have permission to view sa or security logs. Awesome.
Here is a more detailed account of what happened. I know it's long, but I'm trying to answer any questions you guys might have.
Two nights ago, I scanned my machine using Clam. It was the first time I had run the scan, and it found a Trojan in the form of an mp3. I located the file in Finder so that I would know where it was located to delete it, clicked on info, and iTunes opened, which I had not planned on because I had only selected info. I immediately force quit iTunes and deleted the file. I was never prompted for my password, so *was the virus executed*? I have since run Clam several times, and there are no infected files.
Next thing: I downloaded a script which I'm 99% sure was malicious. I'm not a techie, and I know this was incredibly stupid given my lack of knowledge. After opening it, I saw that it was all in a different language (Portuguese, I think?), and immediately closed and deleted. Then my machine started running hard... I checked activity monitor, and things were going crazy. I immediately disconnected from Airport. I don't remember exactly what the numbers were, but there were a lot of page ins/page outs and data being read/written. (I don't even know what those mean exactly, but I check Activity Monitor fairly frequently to look at memory and see what programs are taking up space.) But I was also doing a scan with Clam and I had about 14 tabs open in Safari, so I'm not certain if the activity was correlated to the scan or to the script or to having so many things open and going at once.
I checked my firewall, and it was off. I hadn't looked at it in a few months, but I'm fairly certain I had it activated. Remote access, FTP, etc. - basically all sharing options were enabled. I disabled everything and started the Firewall. I looked at the logs (even though I don't really know how to read them) and saved several of them which I would be glad to post here. One I saved was the Secure Log - I tried to look at any new activity today, and I got the message "You do not have permission to read this log file". What's strange is that my Firewall has logs dated for preceding days and months... but the Firewall was not activated when I initially checked it.?? That doesn't make a lot of sense to me.
I created a Master Password (alphanumeric 17 characters) in File Vault, but I did not turn on Fire Vault... I'm not sure if this changed any settings and has to do with why I can't read certain log files.? To my knowledge, I'm still the admin.? How do I tell if that has been changed? I ran Disk Utility, and it changed a few permissions, fwiw, but I still don't have access to particular logs.
I have Little Snitch running, and it hasn't shown anything abnormal. I looked at my DNS, and it's the same as what it always has been. I'll be glad to post the logs I have, but I don't know what's pertinent and what isn't. Here's a Big Problem: I don't have my installation disk. I know I will probably be advised to wipe everything and reload, but the disk is 500+ miles away tucked in a storage facility. This is killing me. I've been reading everything I can on this forum (you guys are awesome, btw), and was going to try to muddle through this on my own, but I'm way over my head. How can I reinstall if I don't have the installation disks? Or maybe I'm being paranoid and someone didn't get in to my system? Any help would be appreciated.

If this helps, this is my Firewall plist. The plist was created on the day and around the time of all this happening. If everything is enabled to be editable, does that mean that they could have rewritten the codes after I locked everything down?
<plist version="1.0">
<dict>
<key>allports</key>
<array/>
<key>alludpports</key>
<array/>
<key>firewall</key>
<dict>
<key>Apple Remote Desktop</key>
<dict>
<key>editable</key>
<integer>0</integer>
<key>enable</key>
<integer>0</integer>
<key>port</key>
<array>
<string>3283</string>
<string>5900</string>
</array>
<key>row</key>
<integer>5</integer>
<key>udpport</key>
<array>
<string>3283</string>
<string>5900</string>
</array>
</dict>
<key>FTP Access</key>
<dict>
<key>editable</key>
<integer>0</integer>
<key>enable</key>
<integer>0</integer>
<key>port</key>
<array>
<string>21</string>
</array>
<key>row</key>
<integer>4</integer>
</dict>
<key>Network Time</key>
<dict>
<key>editable</key>
<integer>1</integer>
<key>enable</key>
<integer>0</integer>
<key>row</key>
<integer>11</integer>
<key>udpport</key>
<array>
<string>123</string>
</array>
</dict>
<key>Personal File Sharing</key>
<dict>
<key>editable</key>
<integer>0</integer>
<key>enable</key>
<integer>0</integer>
<key>port</key>
<array>
<string>548</string>
<string>427</string>
</array>
<key>row</key>
<integer>0</integer>
</dict>
<key>Personal Web Sharing</key>
<dict>
<key>editable</key>
<integer>0</integer>
<key>enable</key>
<integer>0</integer>
<key>port</key>
<array>
<string>80</string>
<string>427</string>
<string>443</string>
</array>
<key>row</key>
<integer>2</integer>
</dict>
<key>Printer Sharing</key>
<dict>
<key>editable</key>
<integer>0</integer>
<key>enable</key>
<integer>0</integer>
<key>port</key>
<array>
<string>631</string>
<string>515</string>
</array>
<key>row</key>
<integer>7</integer>
</dict>
<key>Remote Apple Events</key>
<dict>
<key>editable</key>
<integer>0</integer>
<key>enable</key>
<integer>0</integer>
<key>port</key>
<array>
<string>3031</string>
</array>
<key>row</key>
<integer>6</integer>
</dict>
<key>Remote Login - SSH</key>
<dict>
<key>editable</key>
<integer>0</integer>
<key>enable</key>
<integer>0</integer>
<key>port</key>
<array>
<string>22</string>
</array>
<key>row</key>
<integer>3</integer>
</dict>
<key>Samba Sharing</key>
<dict>
<key>editable</key>
<integer>0</integer>
<key>enable</key>
<integer>0</integer>
<key>port</key>
<array>
<string>139</string>
</array>
<key>row</key>
<integer>1</integer>
<key>udpport</key>
<array>
<string>137</string>
<string>138</string>
</array>
</dict>
<key>iChat Rendezvous</key>
<dict>
<key>editable</key>
<integer>1</integer>
<key>enable</key>
<integer>0</integer>
<key>port</key>
<array>
<string>5297</string>
<string>5298</string>
</array>
<key>row</key>
<integer>8</integer>
</dict>
<key>iPhoto Rendezvous Sharing</key>
<dict>
<key>editable</key>
<integer>1</integer>
<key>enable</key>
<integer>0</integer>
<key>port</key>
<array>
<string>8770</string>
</array>
<key>row</key>
<integer>10</integer>
</dict>
<key>iTunes Music Sharing</key>
<dict>
<key>editable</key>
<integer>1</integer>
<key>enable</key>
<integer>0</integer>
<key>port</key>
<array>
<string>3689</string>
</array>
<key>row</key>
<integer>9</integer>
</dict>
</dict>
<key>loggingenabled</key>
<integer>1</integer>
<key>state</key>
<true/>
<key>stealthenabled</key>
<integer>1</integer>
<key>udpenabled</key>
<integer>1</integer>
</dict>
</plist>

Similar Messages

  • Hey People! My apple id has been hacked and there was changed an email address for the apple id! so now i don't know which email it is! Please help!

    My apple id has been hacked and there was changed an email address for the apple id! so now i don't know which email it is! Please help! There was bought for 50+ $ !

    just try to make a new apple id with the same name. because the hacker change the email, so your apple id before is not active or not use.

  • I downloaded an upgrade to my adobe reader today, and ever since my search engine has switched to yahoo and wont change back to google. I have a macbook pro, help please? Does anyone know how I can change this back? I have tried through my settings but it

    I downloaded an upgrade to my adobe reader today, and ever since my search engine has switched to yahoo and wont change back to google. I have a macbook pro, help please? Does anyone know how I can change this back? I have tried through my settings but it doesnt work

    Hi Timia,
    If you are using Safari as a web browser :-
    Open Safari, go to Safari menu > Preferences > General, and put Google as the homepage. Then, choose Google as your default search engine.
    If you are using Google Chrome as the web browser :-
      Open Google Chrome.
      In the top right corner of the page, click the Chrome menu Chrome menu > Settings.
      In the "Search" section, select Google from the drop-down menu.
    Let me know if you still experience any issue.
    Regards,
    Aadesh

  • HELP my account has been hack and i cannot restore...

    hi, 
    my account has been hacked and i am unable to restore my password. for some reason when i used the token it said an error has accured and contact support... when i clicked on the link nothing happended.
    im stressed coz i have received an email that my card has been blocked coz someone has been trying to use it on another account!!!! what is going on with skype security?????? 8 years i had this account and 0 problems 
    E. 

    you can visit the link below for suggestions;
    Suggestions on how to handle “Hacked Skype Accounts”
    CONTACT SKYPE CUSTOMER SERVICE   |  HOW TO RECORD SKYPE VIDEO CALLS  | HOW TO HANDLE SUPICIOUS CALLS AND MESSAGES   |  WINDOWS PROBLEMS TROUBLESHOOTING   |  SKYPE DOWNLOAD LINKS  
    MORE TIPS, TRICKS AND UPDATES AT
    skypefordummies.blogspot.com

  • My imessages have been hacked and recovery email changed and I can't delete it! (with pic)

    My iMessages have been hacked and the hacker entered his email as the recovery email with security questions I can't answer. I contacted Apple support and went through the 24 hour process of changing my info so that I could get into the account, but his email address is still the recovery address and it does not give me the option to delete it. I've added alternate emails that can be deleted, but it will not let me change or delete the recovery email. I can change phones and passwords a million times, but if he can just recover my password what am I supposed to do? I have turned iMessage off on my phone (as well as the gps) but I would really like help in deleting that recovery email if anyone has any bright ideas! The pic below shows the only place in all of the settings that his email address shows up anywhere! Any help is very very very appreciated.

    Hi,
    I don't think that can be solved by any advice the regular posters could post here.
    I would go back to Apple and explain the situation (again).
    I would also consider closing the account (Apple rarely seem to do this as accounts are never deleted but just closed).
    I understand this may cause issues for things purchased in iTunes and the App Store which my include Restoring the OS at some point.
    8:20 pm      Tuesday; September 16, 2014
    ​  iMac 2.5Ghz i5 2011 (Mavericks 10.9)
     G4/1GhzDual MDD (Leopard 10.5.8)
     MacBookPro 2Gb (Snow Leopard 10.6.8)
     Mac OS X (10.6.8),
     Couple of iPhones and an iPad

  • My email address book has been hacked, how do I change my password on an hotmail account.?

    My email address book has been hacked, need a new passwork for my hotmail account. How is it done?

    Go here >  Forgotten password and other sign-in problems - Windows Help
    Then click: I think I've been hacked

  • My Apple ID has been hacked. I have changed my password. Still loosing money. What can I do!? Please help!

    Hello,
    This morning i woke up to find a new app on my ipod. It was a foreign app, with asian characters. Plus an email stating my account had been access from an unathorise computer. I reset my password immidiatly. Recently about 5 minutes ago, a $20 item was purchased.
    How did they get my new password?
    Please help!
    I feel un safe online now.

    Go here:
    http://www.apple.com/support/itunes/contact/
    and follow the instructions to report the issue to the iTunes Store.
    Regards.

  • Help, My account has been hacked and phone calls a...

    hi everyone,
    I just recieved a mail from skype saying my default email address has been changed successfully but i didnt change it. when i try to log in using my skype account name i cant, it says wrong password. 
    so i log in using my hotmaill address and i see the default email has changed to a mail somewhere in russia. I try to contact customer support and its near impossible, can someone help me please.
    I just checked the usage history in my account (using the hotmail address to view) and there are calls being made in russia right now using my credit.
    i have this account for years and i would like to get it back.
    Is there anyone who can help?

    iTunes Customer Service Contact
    http://www.apple.com/support/itunes/contact.html
    Support iTunes
    http://www.apple.com/support/itunes/

  • Help my account has been hacked

    I have had $180 of purchases made on my iTunes can I be refunded or not

    No idea.
    Contact itunes support and ask

  • Help Please - Function not available to this reponsibility. Change....

    Hi,
    I am implementing Quality Module.
    I have copied the collection plans
    Defined parent-child relationship
    Updated menu entry to point to the correct plan (Mandatory). Made changes to Form Functions window
    I am in Receiving Transactions and I enter the quality results, select the child plan (Nonconformance Master Plan) and click on Enter. I get the message "Function not available to this responsibility. change responsibilities or contact system administrator".
    Ideally I should be getting Nonconformance form.
    Kindly help. Thanks

    How do you suggest me to go to Quality Plan?
    I have selected the child entry mode as "immediate". So even if I try closing the form, it is suggesting me to enter the child plan (As per trigger I set) and I do select the child plan from drop down and click Enter.

  • Help Please. Since I remarried I need to change my email address. How do I do that without deleting my iCloud account and starting over?

    How do I change my email address?   [email protected]  ????
    Thanks

    Once you have created an iCloud account and chosen an @icloud.com address to go with it you can't change the address (short of creating an entirely new account).
    However, all is not lost. You can add up to three 'email aliases' - these are additional addresses (not accounts) which deliver into the same inbox as the main account. (New aliases can only be @icloud.com ones; @me.com addresses cannot now be created.)
    You should be aware before you start that once you've created an alias you cannot turn that address into a full iCloud account or move it to another account.
    More information on aliases here: http://help.apple.com/icloud/#mm6b1a490a

  • My Account Has Been Hacked and Email Address Changed

     Hi  I have logged a request for this and have received a ticket number # 03369303. The email I have received back isn't clear as to whether the issue is being dealt with or whether I have to go and find the solution myself from the support channels suggested in the email itself.   Can someone clarify? Cheers Mark  

  • Can't log into Game Center even after my password has been reset Help please

    I have 2 gamecenter accounts, I tried logging into one last night but its telling me to reset my password which I have done but its still saying wrong password. Any ideas on what I should try next please? Oh I have a ipad 2 and all my software is up to date thanks

    Can anyone help please I have been able to download apps send and receive emails.. Just not log into Game Center has anyone got any idea what is going on please. Both Game Center accounts are on the same devise but that has been working up until now.....

  • HT2305 i have just bought a iphone 5 and am trying to back my 4 up so i can transfer everytghing on to my 5. it has said i need to update my itunes which i have tryed to do but still isnt working any help please

    i have just upgraded my iphone 4 to a 5. and was trying to back my 4 up on the computure so i could get all my pics and music on to my 5. but its saying i need to update my itunes which i have tried to do and is still not working any help please i have been trying for hours

    how is it not working?
    what version of itunes?
    what ios on iphone4?
    does it give an error msg?

  • How do I know if my computer has been hacked into?

    I am having two issues with my iMac. One is with my wireless -- in the past few days I've received a few times an IP address error, which seems to be solved by renewing the DHCP lease and restarting. Also, at the login screen when I restart, it takes two tries to log in -- on the first one, my password only partially registers and the screen "bounces", then the second try works. Could this mean that my computer has been compromised? We had some workmen alone in our flat while we were away recently, so there are a few people who've had access to the physical machine as well. Thanks for any help.

    You have not been hacked.  Something went wrong with Word and it crashed, and something must have reopened Word.  (The system will usually ask if you want to reopen a crashed app...  did you see such a message?)  Word must have simply reopened the docs you had open when it crashed.
    It's actually quite difficult to hack a Mac, and pretty much requires you to help out by opening it up for potential access by hackers.

Maybe you are looking for