Is there a way to identify safe vs. malicious files on computer that was hacked?

Our MacBook (OS X ver. 10.8.5) was monitored remotely without our knowledge for over a year. Actually, we had found things that were suspicious but we listened to various experts who told us not to worry. We found several pages of commands in the Terminal window including commands for remote access.  Also many files had incorrect creation dates.
Our email and banking accounts were compromised.  A typical pattern began with our password being reset.  We’d change the password, and the new password would continue to work, but the hacker would know what that new password was.  She continued to know the password even after it was changed several times.  Computer security experts told us she installed a data logger on our computer.  We purchased a new computer and new hard disk for the old computer, and reinstalled all applications.  However, she was able to get into the email accounts on those as well.  We need to access some of our old files, but we do not know which are safe. 
We have several suspicious files on our computer that may contain malicious code, but nothing shows up when scanned with various anti-malware software applications. However, some files are suspicious because they have inaccurate creation dates that reflect times when our computer was compromised.  Others are suspicious because they were called up in the Mac Terminal application as Unix executable files, and they have Unix icons, but they were originally MS Word  documents. The hacker remotely entered several pages of commands into our Terminal application but many of the commands were of a form: filename; exit;
If anyone would be interested in examining the files, we would be happy to provide them.  We are seeking someone who can decompile Unix programs that might be associated with the MS Word files.  These files might report data to someone, or may be involved in spying through the iPhone or computer.  Any additional advice would be appreciated.

Here is the Entresoft output
EtreCheck version: 1.9.12 (48)
Report generated June 22, 2014 at 8:54:52 PM EDT
Hardware Information:
  MacBook Pro (Retina, 15-inch, Late 2013) (Verified)
  MacBook Pro - model: MacBookPro11,3
  1 2.3 GHz Intel Core i7 CPU: 4 cores
  16 GB RAM
Video Information:
  Intel Iris Pro - VRAM: (null)
  NVIDIA GeForce GT 750M - VRAM: 2048 MB
  Color LCD 2880 x 1800
System Software:
  OS X 10.9.3 (13D65) - Uptime: 5 days 12:37:21
Disk Information:
  APPLE SSD SM0512F disk0 : (500.28 GB)
  EFI (disk0s1) <not mounted>: 209.7 MB
  disk0s2 (disk0s2) <not mounted>: 499.42 GB
  Recovery HD (disk0s3) <not mounted>: 650 MB
USB Information:
  Apple Internal Memory Card Reader
  Apple Inc. BRCM20702 Hub
  Apple Inc. Bluetooth USB Host Controller
  Apple Inc. Apple Internal Keyboard / Trackpad
Thunderbolt Information:
  Apple Inc. thunderbolt_bus
Gatekeeper:
  Mac App Store and identified developers
Kernel Extensions:
  [loaded] at.obdev.nke.LittleSnitch (4052 - SDK 10.8) Support
  [not loaded] com.cisco.kext.acsock (1.1.0 - SDK 10.6) Support
  [loaded] com.sophos.kext.sav (9.0.61 - SDK 10.7) Support
  [loaded] com.sophos.nke.swi (9.0.53 - SDK 10.8) Support
Startup Items:
  ciscod: Path: /System/Library/StartupItems/ciscod
Launch Daemons:
  [running] at.obdev.littlesnitchd.plist Support
  [loaded] com.adobe.fpsaud.plist Support
  [loaded] com.bombich.ccc.plist Support
  [failed] com.cisco.anyconnect.vpnagentd.plist Support
  [loaded] com.microsoft.office.licensing.helper.plist Support
  [loaded] com.oracle.java.Helper-Tool.plist Support
  [loaded] com.oracle.java.JavaUpdateHelper.plist Support
  [running] com.sophos.autoupdate.plist Support
  [running] com.sophos.configuration.plist Support
  [running] com.sophos.intercheck.plist Support
  [running] com.sophos.notification.plist Support
  [running] com.sophos.scan.plist Support
  [running] com.sophos.sxld.plist Support
  [running] com.sophos.webd.plist Support
Launch Agents:
  [running] at.obdev.LittleSnitchUIAgent.plist Support
  [not loaded] com.adobe.AAM.Updater-1.0.plist Support
  [loaded] com.cisco.anyconnect.gui.plist Support
  [loaded] com.oracle.java.Java-Updater.plist Support
  [running] com.sophos.uiserver.plist Support
User Launch Agents:
  [loaded] com.adobe.ARM.[...].plist Support
User Login Items:
  None
Internet Plug-ins:
  AdobeAAMDetect: Version: AdobeAAMDetect 1.0.0.0 - SDK 10.6 Support
  FlashPlayer-10.6: Version: 13.0.0.214 - SDK 10.6 Support
  Default Browser: Version: 537 - SDK 10.9
  AdobePDFViewerNPAPI: Version: 11.0.06 - SDK 10.6 Support
  AdobePDFViewer: Version: 11.0.06 - SDK 10.6 Support
  Flash Player: Version: 13.0.0.214 - SDK 10.6 Outdated! Update
  QuickTime Plugin: Version: 7.7.3
  SharePointBrowserPlugin: Version: 14.4.2 - SDK 10.6 Support
  JavaAppletPlugin: Version: Java 7 Update 60 Check version
Audio Plug-ins:
  BluetoothAudioPlugIn: Version: 1.0 - SDK 10.9
  AirPlay: Version: 2.0 - SDK 10.9
  AppleAVBAudio: Version: 203.2 - SDK 10.9
  iSightAudio: Version: 7.7.3 - SDK 10.9
iTunes Plug-ins:
  Quartz Composer Visualizer: Version: 1.4 - SDK 10.9
3rd Party Preference Panes:
  Flash Player  Support
  Java  Support
Time Machine:
  Mobile backups: OFF
  Auto backup: NO - Auto backup turned off
  Volumes being backed up:
  Destinations:
  Untitled [Local] (Last used)
  Total size: 464.96 GB
  Total number of backups: 3
  Oldest backup: 2014-04-09 00:38:02 +0000
  Last backup: 2014-06-08 16:09:58 +0000
  Size of backup disk: Excellent
  Backup size 464.96 GB > (Disk size 0 B X 3)
  Time Machine details may not be accurate.
  All volumes being backed up may not be listed.
Top Processes by CPU:
      64% InterCheck
      7% WindowServer
      3% opendirectoryd
      1% coreservicesd
      1% hidd
Top Processes by Memory:
  262 MB WindowServer
  180 MB Microsoft Word
  147 MB InterCheck
  147 MB SophosScanD
  98 MB Mail
Virtual Memory Information:
  10.46 GB Free RAM
  2.65 GB Active RAM
  1.09 GB Inactive RAM
  1.38 GB Wired RAM
  1.63 GB Page-ins
  0 B Page-outs

Similar Messages

  • Is there a way to get back lost information on a phone that was synced to the wrong itunes account

    is there a way to get back lost information on a phone that was synced to the wrong itunes account? My sister and I share a computer and she accidently did the itunes restore on her phone under my name so all of my contacts, apps, ect are on her phone and all of her info is gone. Is there a way to undo the reset? PLEASE HELP!!!

    She can restore to a previous backup, if she has one. Or she
    can restore via iCloud if she has that setup.

  • Is there a way to backup the iphone without entering a passcode that was previously set?

    I have a passcode on my iphone, which I recently dropped. Both the front and back screens are cracked severely. I can see when someone txts / calls, so the phone appears to be working, however it is not usable. I cannot access anything on the phone using the touch screen. The screen continues to shake as if there are multiple fingers trying to operate it at once.
    Although it would be nice to get back into the phone, I would prefer being able to back it up just one more time. I sync frequently to icloud, but the last time I backed it up to my pc was 11/16/2011. I can access everything I've backed up(txts, images, etc via other applications), but I have some important correspendeces that took place between then and now that I would like to have.  
    Is there way for me to backup the phone without entering the passcode?  Also, I have read through some of the discussions, and pardon my ignorance but I wanted an unequivocal answer to this question:  If I restore the phone from the backup of 11/16, will I lose everything after that date? And, are there other alternatives?
    I have tried some things which I thought would be clever ways to bypass this problem, but alas...here I am asking for help. I find it frustrating that I can sync to icloud (still) yet I cannot backup to my pc without passcode. I guess a good alternative would be if I could access my txts on icloud? I may consider replacing the screen, but I don't know if this will fix the problem since the phone looks pretty bad. I also prefer not to replace the screen since I wont be using this phone any longer.
    Your comments / suggestions will be greatly appreciated.
    Thanks,
    reaL

    Restoring a phone from a backup will put the device back to the state it was when the backup took place, i.e. all info that you had on that phone before using the backup will be gone.
    You could try to restore the phone, which will back up the actual data on the phone, including the passcode, and use this backup to set up a new phone with. The passcode will still be the same, because it is  part of the backup.
    More info here, iPhone and iPod touch: Wrong passcode results in red disabled screen
    Not being able to fill in the passcode is not much different from forgetting it.
    If you cannot remember the passcode, you will need to restore your device using the computer with which you last synced it. This allows you to reset your passcode and resync the data from the device (or restore from a backup). If you restore on a different computer that was never synced with the device, you will be able to unlock the device for use and remove the passcode, but your data will not be present. Refer to Updating and restoring iPhone, iPad and iPod touch software.
    Also have a look at this one: iTunes: About iOS backups

  • My macbook pro was stolen. How can I make sure that the one that is linked to find my mac is this one and not an older computer.  Is there a way of seeing the serial number for the computer that is linked to find my mac?

    Is there a way to see serial number of computer that is linked to find my mac?

    No.
    Barry

  • Is there a way to find all the locked files my computer?

    I am having trouble importing some files into Aperture and I discovered that one of the reasons might be that some of the files are locked. I know how to unlock them but I'd like to find the locked files and unlock them all at once. Is there a way to do that?

    Back up all data before proceeding.
    This procedure will unlock all your user files (not system files) and reset their ownership, permissions, and access controls to the default. If you've intentionally set special values for those attributes on any of your files, they will be reverted. In that case, either stop here, or be prepared to recreate the settings if necessary. Do so only after verifying that those settings didn't cause the problem. If none of this is meaningful to you, you don't need to worry about it, but you do need to follow the instructions below.
    Step 1
    If you have more than one user, and the one in question is not an administrator, then go to Step 2.
    Triple-click anywhere in the following line on this page to select it:
    sudo find ~ $TMPDIR.. -exec chflags -h nouchg,nouappnd,noschg,nosappnd {} + -exec chown -h $UID {} + -exec chmod +rw {} + -exec chmod -h -N {} + -type d -exec chmod -h +x {} + 2>&-
    Copy the selected text to the Clipboard by pressing the key combination command-C.
    Launch the built-in Terminal application in any of the following ways:
    ☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)
    ☞ In the Finder, select Go ▹ Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.
    ☞ Open LaunchPad. Click Utilities, then Terminal in the icon grid.
    Paste into the Terminal window by pressing command-V. I've tested these instructions only with the Safari web browser. If you use another browser, you may have to press the return key after pasting.
    You'll be prompted for your login password, which won't be displayed when you type it. Type carefully and then press return. You may get a one-time warning to be careful. If you don’t have a login password, you’ll need to set one before you can run the command. If you see a message that your username "is not in the sudoers file," then you're not logged in as an administrator.
    The command may take several minutes to run, depending on how many files you have. Wait for a new line ending in a dollar sign ($) to appear, then quit Terminal.
    Step 2 (optional)
    Take this step only if you have trouble with Step 1, if you prefer not to take it, or if it doesn't solve the problem.
    Start up in Recovery mode. When the OS X Utilities screen appears, select
              Utilities ▹ Terminal
    from the menu bar. A Terminal window will open. In that window, type this:
    res
    Press the tab key. The partial command you typed will automatically be completed to this:
    resetpassword
    Press return. A Reset Password window will open. You’re not going to reset a password.
    Select your startup volume ("Macintosh HD," unless you gave it a different name) if not already selected.
    Select your username from the menu labeled Select the user account if not already selected.
    Under Reset Home Directory Permissions and ACLs, click the Reset button.
    Select
               ▹ Restart
    from the menu bar.

  • Is there a way to identify MRP requisitions transfered to SRM?

    Hello experts,
    We are using SRM 5.0 connected to an ECC 6.0 backend system, using ECS scenario.
    I have the following question:
    Is there a way to identify in SRM requisitions transtered from ECC that are created in R3 from an MRP process? Meaning like an indicator or a flag in a table in SRM?
    Thanks!
    Regards,
    Gilberto Gallardo

    Hi
    <u>Please go through the SAP OSS Notes below as well -></u>
    Note 451245 Framework conditions connection MRP <-> EBP
    Note 505030 Restrictions for the integration of external requirements
    Note 441892 Integrating external requirements
    Note 831348 Source List for Stock requirments and MRP list -wong results
    Note 528808 Incorrect item numbers during the update (add items)
    Note 540339 Purchase requisitions are transferred incorrectly
    Note 534419 Transfer of purchase requisitions into the procuremnt system
    Note 532293 Fulfillment: incorrect quantity for activities and limits
    Note 447516 Composite SAP note PlugIn Correction for External Requiremts
    Hope this will help.
    Regards
    - Atul

  • I have os x 10.5.8 and noticed a menu extra that I have never seen before. Is there a way to identify it? I tried to delete it i.e. comm drag, didn't work.

    I have os x 10.5.8 and noticed a menu extra that I have never seen before. Is there a way to identify it? I tried to delete it i.e. comm + drag, didn't work.

    If you can't CMD+ drag it off, try this...
    You've probably got a couple of corrupt preference files.
    Safe Boot from the HD, (holding Shift key down at bootup), run Disk Utility in Applications>Utilities, then highlight your drive, click on Repair Permissions...
    /Users/YourUserName/Library/Preferences/com.apple.systempreferences.plist
    /Users/<yourname>/Library/Preferences/ com.apple.systemuiserver.plist
    /Users/<yourname>/Library/Preferences/ByHost/com.apple.systemuiserver.xxx.plist
    where 'xxx' is a 12 digit (hexadecimal) numeric string.
    This will reset your Menu Bar to the default, you'll need to go through System Preferences to reset the ones you need. (If they are already checked, uncheck them first and then recheck them).
    reboot

  • Is there any way to identify the particular socket connection is closed ?

    Is there any way to identify the particular socket connection is closed or not ?
    Any methods ???
    How can the program knows the connection is lost or some thing ...
    Is the socket throws some excpetions when there is no active connection ???
    namanc

    If you get an IOException when you try to use the socket, the connection was obviously closed.
    The correct way for an application to know if the socket was closed is:
    1) the server sends a message indicating that the socket should be closed
    2) the client closes the socket itself

  • Is there a way to identify other users on my WiFi?

    Is there a way to identify other users on my WiFi?

    Open AirPort Utility (Applications/Utilities) and click on your AirPort. It should list all the wireless devices connected.

  • Is there a way to identify a thread you want to return to without tagging?

    Is there a way to identify a thread you want to return to without tagging?
    I will try to explain what I mean.
    Let say someone asks a question and you are curious at what people may suggest as solutions.  The interest could range from simple curiosity to "oh, I don't know how to do that, but would like to learn", or whatever reason that would cause someone to revisit a thread. 
    But the interest is weak enough that you do not want to subscribe to the discussion.  And the topic is not something you want to tag because it is an unusual thread that is unlikely going to re-occur, and you are not sure if you will or will not revisit after a solution is posted or the discussion goes a certain way. 
    Another example is if the question is interesting, you do not want to mark it because there is no answer / solution yet and you are curious if anyone would ever provide a solution, so you do not want to tag it and a subscription would be useless if no one replies.
    OR
    Maybe it is a hot topic of the day / week and that's it..  You would not revisit at a later date.
    But for the moment, you want to easily find it during the day or have a reminder that you want to revisit the thread ether in the near future or later when someone has provided an answer.
    Is there an easy way to mark threads that you want to re-visit?  Like a "todo" list, but rather a "to re-visit" list...
    R
    Solved!
    Go to Solution.

    Delicious is a website wher you can store URL for later use/retrieval. For every link you add you can add some tags, a description, and you can share them with others.
    I'm not using it for the use you have in mind, but it would be an idea. I have set up a special Mouse Gesture in Firefox that creates a delicious entry for the current page.
    I use delicious heavily when I am looking on the internet for a solution to a specific problem, what happens during such a search is that you see 20-30 pages that look promising but only 3 are actually on topic. Sometimes it turns out one of the 'not so good pages' are actually googd pages, but 3 days later you don't know exactly the search term  you used, or you are on another PC and it's hard to trace back your steps on the WWW. So by using Delicious I can easily create a list of pages on a particular topic.
    Ton
    Free Code Capture Tool! Version 2.1.3 with comments, web-upload, back-save and snippets!
    Nederlandse LabVIEW user groep www.lvug.nl
    My LabVIEW Ideas
    LabVIEW, programming like it should be!

  • Is there any way to identify the two classes are compiled by same vm

    Is there any way to identify the two classes are compiled by same vm?
    Thank's a lot.

    I think this is the better forum than java compiler. The answer to the question you asked is no.
    But that question is not the best way to address your problem.
    If this were me, I'd use a tool like ASM (http://asm.objectweb.org/) to read in that file, and replace the getToday() method, with one like this
    long getToday() {
        return 20080101;
    }and replace the class file with this new one. (keep the old one, they might be using a class loader that verifies class signatures or something)
    (They said the code you are looking at could have been changed by you - so take the hint and change it back).
    If they've ripped you off, this will restore justice much more cheaply and effectively than involving the lawyers. If they then sue you for breaching the license agreement, that would probably force them to disclose their underhand tactics.
    OTOH, if you're lying to us about the purchase, and needing to pay for upgrades to fix the performance issue, and instead are trying to crack some trial software, then I hope they are using a custom class loader that checks the integrity of the classes.
    If you are being ripped off, why are you not telling us the name of the company? I am not sure who is being ripped off here.
    Bruce

  • Is there a way to import metadata to wav files in my library?

    Is there a way to import metadata to wav files in my library?
    I have about 1,500 .wav files that are presently in my iTunes library, but as most of you are aware .wav files have their limitations with regard to how iTunes translates their specific track information. I haven't been archiving using .wav in sometime, I've since switched to another more iTunes friendly format. But, I have these 1,500 files left and I'm desperately trying to find a faster way to log the info.
    I've built a data table with all of the track information I want to import. Does anyone know of a good macro, or script that will allow me to import this data so I don't have to manually open each individual .wav file and input this manually?
    Any help would be appreciated!
    Note: I've searched the forums, and I've looked at similar posts, but nothing to solve this specific little quandary. If I've somehow overlooked a post, please forgive my repeat post.

    I can probably help with this.
    I have a script called TagFromFilename that can apply fill in the details that can be extracted from the file path if the .wavs are stored in the layout <Album Artist>\<Album>\[D-]## <Name>[ - <Artist>].<Ext> where D is an optional leading disc number and <Artist> is an optional trailing artist (otherwise both artist and album artist are set to the grandparent folder). You just need to make sure that before you add the tracks to iTunes, that it won't rename the files. You can do this by turning off the Keep option if the files are inside the media folder, or the copy option if the tracks are located outside.
    Alternatively I have another script called ExportImport which allows for almost any editable to be adjusted, as long as you can export the internal track IDs of each track and then marry them up with the data you want to import. See Batch Add Comments Tag Solution? for a previous example of how if might be done. I'll gladly go into more detail if you tell me what fields you already have and what identifying information is present.
    tt2

  • Is there a way to create a custom screensaver with pics/slides that display for different amounts of time?

    Is there a way to create a custom screensaver with pics/slides that display for different amounts of time? Or even add a "video slide" into the screensaver?
    My business has 3 TVs displayed in our lobby, each with its own apple TV and they are all linked to the same photo stream. Currently the Atv screensaver displays the photostream pictures of our products for the default 3 seconds. We just added pics/slides that now display messages and useful info for our customers but I want that info to be displayed for a longer period of time than the pictures to give people a chance to read it.
    I tried using flickr and powerpoint as a work around but no luck.  I created a slide in powerpoint with play length of 15 secs and saved it as a wmv file.  I added that file to a "screensaver" set in flickr and pointed the Atv screensaver to that flickr set.  It still displays everything, pics and the wmv file at the default 3 sec.
    I know I can increase the duration of all pics in the screensaver to display for longer but the goal is to have the pics display at 3 secs and the info slides to display at 15 secs.

    Welcome to the Apple Community.
    No that's not possible.
    If you have any suggestions that you think might enhance the Apple TV you can send Apple your feedback here 

  • Is there a way to create a project with custom audio settings that are NOT only "Stereo" or "Surround"?

    Is there a way to create a project with custom audio settings that are NOT only "Stereo" or "Surround"?
    Thanks!
    -Adrian

    the old apps are on my computer but they have had upgrades since they were put on the ipod originally.  you think you would get a warning about this when you restored. I was not worried about losing the progress of the apps but i would have been worried about the app it self!!!!!

  • Me and my partner have just brought a new MacBook. We both have individual iTunes and iCloud accounts, is there any way we can access both accounts on one computer?

    Me and my partner have just brought a new MacBook. We both have individual iTunes and iCloud accounts, is there any way we can access both accounts on one computer?

    Set up 2 accounts one for each of you.

Maybe you are looking for

  • Video Chatting and Internet Sharing at the same time.

    Does anyone know why video chat communication cannot be established while internet sharing, or how to remedy this problem by (what I imagine would be) opening/closing/redirecting a few ports? More specifically: I share my ethernet connection through

  • How did Nickname field in Address Book get filled in?

    I went to send an email to myself (I send to-do lists to myself because I forget everything ) from my imac and when I typed in my name, I noticed that in front of all of my email addresses, the label "Princess" was showing up. I had NEVER seen this b

  • Why do I get a files icon and a Firefox icon when I save a website to my desktop?

    When ever I save a website to my desktop I usually get two icons that show up on my desktop. One of the icons is the link to the website the other is a file folder filled with a bunch of files that I don't recognize. If I delete the file folder icon

  • Blocked cost center in PO

    Hello , a PO has been created. It is impossible to do goods receipt on the PO since the cost center is blocked(and should be deleted). We are unable to modify the PO since the cost center in also present in the SC. how should we tackle this?

  • Will the new update for mozilla support the Realplayer plugin?

    before I install the present new upgrade,i'd like to know if the new upgrade supports realplayer plugin as i like to download clips and stuff. when google put in a new upgrade, it disabled Realplayer. If it does, i'll stay with the older version,even