Suspicious .nyiyeverc file in home directory

I found a hidden file called ".nyiyeverc" sitting in my home (~/) directory and I can't find any info on what it is, or if it could be something malicious or unwanted. I searched Google, as well as other search engines, and got absolutely nothing.
I opened it with TextEdit and it appears to be a single line of text reading "awcnsawcnsawcnsawcnsawoolwascully wa". Very weird! I googled that too, but still nothing.
It's 8 KB, listed as a UNIX executable, created 2/19/12, modified 9/26/12 (two days ago). I am perplexed!

More than suspicious I'd say, & the fact that it isn't searchable would indicate very  sophisticated Malware.
Installed anything lately?
ClamXAV, free Virus scanner...
http://www.clamxav.com/
Free Sophos...
http://www.sophos.com/en-us/products/free-tools/sophos-antivirus-for-mac-home-ed ition/features.aspx
ClamXAV, free Virus scanner...
http://www.clamxav.com/
Free Sophos...
http://www.sophos.com/en-us/products/free-tools/sophos-antivirus-for-mac-home-ed ition/features.aspx
Get MacScan...
http://www.apple.com/downloads/macosx/networking_security/macscan.html
See these for a list of some key loggers...
http://forums.macosxhints.com/archive/index.php/t-41204.html
http://www.keylogger-mac.com/mac-keylogger-perfect-keylogger-for-mac-os-x.html
http://uglypufferfish.com/2008/10/31/mac-keyloggers/

Similar Messages

  • Conf file in home directory

    No idea what section to post this in, I'm using kde4.1.1 if thats got any relevance.  Something keeps creating a file called config in home directory, I keep deleting it and it keeps coming back, its annoying! I've no idea whats doing it, the file contains only
    0.0

    omg this is driving me mad... anyone any ideas? The file is created whenever I log in so god knows what prog is creating it

  • Macbinary file in home directory

    Hello, I have noted lately that there is a mac binary file in my home directory, does anyone know what is this for? I did not notice this file a month and half ago. Everything else is ok with my mac but I am very curious about this file. I tried opening it and it did nothing. Any ideas? The name of the file is profiles.bin. Although I have used Mac for a while I do not know some details associated to Unix and Mac System. Appreciate any help, thanks.

    Hi, vitoman.
    You wrote: "I googled it and did not find anything. "
    This Google search turns up a couple of threads concerning this file on forums in Germany and Italy. The "Translate this Page" links yield some rough translations, at least one of which seems to imply it may be related to installing the latest Office update.
    Another user seemed to indicate that he deleted the file but it later reappeared, implying it might be caused by a Startup or Login Item. If that's the case, ee my "Troubleshooting Startup and Login Items" FAQ for steps that might help you with this problem.
    If you speak/read German or Italian, perhaps you can get more from those Google results than the translations yielded.
    Good luck!
    Dr. Smoke
    Author: Troubleshooting Mac® OS X
    Note: The information provided in the link(s) above is freely available. However, because I own The X Lab™, a commercial Web site to which some of these links point, the Apple Discussions Terms of Use require I include the following disclosure statement with this post:
    I may receive some form of compensation, financial or otherwise, from my recommendation or link.

  • MacOS keep open file in home directory

    I don't know if I've changed anything but my Mac keeps open every files written in the HOME directory with the default editor. Any idea to modify this behavior? I'm using Mac OS X 10.6
    Thank you in advance.

    Never mind. I was able to fix it. Just delete every thing from ~/Library/Preferences (or move all files to another location and then move them back if you don't want to lose your settings).

  • Lots of 0kB text files in home directory

    I am using a MacBook Pro with Mac OS X 10.7.2.  Last week, I had a hard drive corruption and restored my MB Pro from a Time machine backup and the Lion Startup partition.  While I was fortunate that only a days worth of data was lost, all has not been completely smooth.
    1)  There are a lot of text files of 0 kB with either no name or non-sensical names beginning with a percent sign and other non-sensical characters (e.g.  %E1%DB %F6ޝo^%EF%FEۆ%83%A7wkx8) in my home directory /Users/isaac.
    2) The 500 GB partition that I have been using for Time Machine to back up the internal 320 GB hard disk is now not large enough to back up the volume.  There is only one backup on the drive (the one I used to restore), but Time Machine won't complete the backup although there is 197.5 GB available.  I thought that time machine didn't make complete backups and wondered why this has become a problem after the recent re-install.
    There have been some runaway processes that I can't isolate that heat up the computer (72 F) and start the fan a whirring 4400 rpm.
    I don't know if these are related to previous kernel panics that would intermittenly freeze and crash my Mac (the ciscovpn agent seemed to be the process that was always the final process before the crash), but I thought I'd mention them anyway.
    Are these issues foreshadowing future doom?
    Your thoughts are welcome.  Thank you.
    Aric

    Aric Newton wrote:
    2) The 500 GB partition that I have been using for Time Machine to back up the internal 320 GB hard disk is now not large enough to back up the volume.  There is only one backup on the drive (the one I used to restore), but Time Machine won't complete the backup although there is 197.5 GB available.  I thought that time machine didn't make complete backups and wondered why this has become a problem after the recent re-install.
    Sounds like TM wasn't able to figure out what happened.   When you did the restore, the disk got a new UUID (Universally Unique IDentifier), that OSX uses to keep track of drives (rather than the name).  So it's treated as a different drive.   Ordinarily, when you do a restore, it leaves a "trail" so Time Machine can automatically connect the "new" drive to the old backups.  Sometimes, though, it doesn't.
    You may be able to get it to "associate" the "new" disk with the backups, per #B6 in Time Machine - Troubleshooting.

  • Why can't create file under /home directory?

    I user solaris10, and login as root,I find I can't create any file or directory under /home directory! It say "operation not applicable" ,Why? I am puzzled it for a long time. Anyone could tell how to do it?
    Thanks

    For Solaris,
    /home is not an on-disk file system, it is a file system under the
    control of the automounter, and only the automounter can create
    directories/files in it.
    If you don't want the automounter to manage /home, then remove the
    "/home" entry from /etc/auto_master
    (and issue the command "automount -v" to force the file
    to be reread, or reboot).
    However, the typical setup for Solaris is to locate user's home directories
    in /export/home.
    Kapil Khanna

  • A strange file in home directory

    Hi
    Something is creating a strange file in my home direcotry:
    http://s2.postimg.org/drgqt0c3t/shot.png
    Can anyone tell me that? how can I track that which app is creating that file?
    And, how can I prevent creation of this file in the future?
    Regards
    Last edited by zetrotrack000 (2013-09-02 15:42:11)

    kaszak696 wrote:Does that file have any contents that would help identify it? Also, could you provide more info about your setup? What processes and services you have running etc. If you can, upload the entire output of lsof +d $HOME or lsof +D $HOME , don't remember which one is non-recursive.
    Here is the output of 'lsof +d $HOME':
    COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME
    startkde 308 zetro cwd DIR 8,6 4096 14942209 /home/zetro
    startkde 308 zetro 1w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    startkde 308 zetro 2w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    kdeinit4 366 zetro cwd DIR 8,6 4096 14942209 /home/zetro
    kdeinit4 366 zetro 1w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    kdeinit4 366 zetro 2w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    klauncher 367 zetro cwd DIR 8,6 4096 14942209 /home/zetro
    klauncher 367 zetro 1w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    klauncher 367 zetro 2w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    kded4 369 zetro cwd DIR 8,6 4096 14942209 /home/zetro
    kded4 369 zetro 1w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    kded4 369 zetro 2w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    kglobalac 380 zetro cwd DIR 8,6 4096 14942209 /home/zetro
    kglobalac 380 zetro 1w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    kglobalac 380 zetro 2w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    kactivity 385 zetro cwd DIR 8,6 4096 14942209 /home/zetro
    kactivity 385 zetro 1w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    kactivity 385 zetro 2w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    kwrapper4 394 zetro cwd DIR 8,6 4096 14942209 /home/zetro
    kwrapper4 394 zetro 1w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    kwrapper4 394 zetro 2w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    ksmserver 396 zetro cwd DIR 8,6 4096 14942209 /home/zetro
    ksmserver 396 zetro 1w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    ksmserver 396 zetro 2w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    kwin 461 zetro cwd DIR 8,6 4096 14942209 /home/zetro
    kwin 461 zetro 1w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    kwin 461 zetro 2w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    knotify4 463 zetro cwd DIR 8,6 4096 14942209 /home/zetro
    knotify4 463 zetro 1w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    knotify4 463 zetro 2w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    plasma-de 468 zetro cwd DIR 8,6 4096 14942209 /home/zetro
    plasma-de 468 zetro 1w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    plasma-de 468 zetro 2w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    ksysguard 498 zetro cwd DIR 8,6 4096 14942209 /home/zetro
    kio_deskt 503 zetro cwd DIR 8,6 4096 14942209 /home/zetro
    kio_deskt 503 zetro 1w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    kio_deskt 503 zetro 2w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    kio_trash 504 zetro cwd DIR 8,6 4096 14942209 /home/zetro
    kio_trash 504 zetro 1w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    kio_trash 504 zetro 2w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    kio_file 507 zetro cwd DIR 8,6 4096 14942209 /home/zetro
    kio_file 507 zetro 1w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    kio_file 507 zetro 2w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    krunner 515 zetro cwd DIR 8,6 4096 14942209 /home/zetro
    krunner 515 zetro 1w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    krunner 515 zetro 2w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    nepomukse 517 zetro cwd DIR 8,6 4096 14942209 /home/zetro
    nepomukse 517 zetro 1w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    nepomukse 517 zetro 2w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    nepomukst 520 zetro cwd DIR 8,6 4096 14942209 /home/zetro
    nepomukst 520 zetro 1w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    nepomukst 520 zetro 2w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    thunderbi 525 zetro cwd DIR 8,6 4096 14942209 /home/zetro
    thunderbi 525 zetro 1w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    thunderbi 525 zetro 2w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    CopyAgent 528 zetro cwd DIR 8,6 4096 14942209 /home/zetro
    CopyAgent 528 zetro 1w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    CopyAgent 528 zetro 2w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    polkit-kd 537 zetro cwd DIR 8,6 4096 14942209 /home/zetro
    polkit-kd 537 zetro 1w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    polkit-kd 537 zetro 2w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    kmix 539 zetro cwd DIR 8,6 4096 14942209 /home/zetro
    kmix 539 zetro 1w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    kmix 539 zetro 2w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    konsole 541 zetro cwd DIR 8,6 4096 14942209 /home/zetro
    konsole 541 zetro 1w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    konsole 541 zetro 2w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    bash 558 zetro cwd DIR 8,6 4096 14942209 /home/zetro
    kio_trash 613 zetro cwd DIR 8,6 4096 14942209 /home/zetro
    kio_trash 613 zetro 1w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    kio_trash 613 zetro 2w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    nepomukfi 616 zetro cwd DIR 8,6 4096 14942209 /home/zetro
    nepomukfi 616 zetro 1w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    nepomukfi 616 zetro 2w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    nepomukfi 617 zetro cwd DIR 8,6 4096 14942209 /home/zetro
    nepomukfi 617 zetro 1w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    nepomukfi 617 zetro 2w REG 8,6 13974 14942277 /home/zetro/.xsession-errors
    lsof 627 zetro cwd DIR 8,6 4096 14942209 /home/zetro
    lsof 627 zetro 1w REG 8,6 0 14950316 /home/zetro/lsof_output
    lsof 628 zetro cwd DIR 8,6 4096 14942209 /home/zetro

  • I have to give password to file changes in my home directory

    From yesterday, when I try to change files in my home directory, a dialog box pops up to ask the password.
    That happens even after make the file permission to 644. I tried to change the whole /Users/myplace permisson, but it doesn't work.
    The owner of the file is set as myself, but there might be something broken with this.
    This actually made everything not working, dropbox takes for ever to delete a file, evernote can't even start and on and on.
    I just happen to add New Person with the same user name that I use now in Sharing, but I'm not sure this is the cause of the problem.
    How can I solve this issue? How can I delete/move files in home directory without giving passwords?
    Thanks,
    smcho

    Your username is "smcho"? So your home folder is named "smcho"?
    Yeah for the System Folders "Movies", "Music", "Pictures", "Library", "Public" and "Desktop" there is an ACL, so you can't rename or delte them.
    It's just for your safety because these folders are used by the system and should be not renamed or removed!
    Additionally you made something wrong by chmodding your home folder to 644 - or as it showing here to 730!?!
    Normally the user home folder and the included folders should be at 700 and the Public folder at 755. Additionally the folders have an acl for "everyone deny delete".  so something get messed up!

  • AES-256 user home directory sparse image bundle in Lion?

    Snow Leopard and previous had file vault to protect users' home directories as, I believe, AES-128-encrypted sparse image bundles. As I understand it now, under Lion, the options are to enable AES-128 whole disk encryption, or, if upgrading an existing snow leopard machine with a legacy file vault user account, to maintain that legacy file vault user home directory. However, under this second approach, additional users' home directories cannot be individually "file-vaulted" and instead, would require that legacy file vault  be decrytped and then the entire disk be encrypted.
    I am thinking that it would be advantageous from a security standpoint if an individual user home directory could remain encrypted, if that user were not actively logged in. Then, all contents would be inaccessible to other users, including administratively privileged users, and also that user's home directory would remain encrypted when the computer was turned on and booted up because as I understand it, file vault 2's real strength lies in protecting "data at rest" versus "data on a powered up and mounted file vault 2 volume".
    To that end, I am wondering, regardless of whether file vault 2 is enabled or not, whether an existing user home directory and all of its contents be converted to an AES-256-encrypted sparse image bundle, using Disk Utility, and exist at the /Users directory space, mounting and decrypting "on the fly" from the login window at user login just like how a legacy file vault home directory is treated under snow leopard, independently of whether file vault 2 was enabled on the whole disk or not. This would also permit later addition/conversion of another "file vaulted" user account whether fle vault 2 were enabled or not.
    To recap, an AES-256-encrypted sparse image bundle that would mount upon user login just like a legacy file vault user home directory does. Does anyone know if something like that is doable, and has that road already been travelled successfully? If so, I'd love to read a step-by-step, play-by-play, set of instructions on how to do just that.

    I think I got a solution worked out.  I don't mind if things get installed in /opt as long as pacman tracks it, and I found ruby-enterprise-rmagick in the AUR as an orphan.  I adopted it, updated it, installed it, and it's working great with my code.

  • How do I enable opening firefox from two different computers sharing the same home directory without having to delete a lock file (linux).

    I just don't want to have to delete a lock file - which has a purpose - in order to use firefox simultaneously from two locations on the network - where the home directory, i.e. .mozilla directory - is located

    You need to use two separate profiles if you want to have two Firefox instances open at the same time.
    See also http://www.mozilla.org/unix/remote.html

  • Need to write/delete a file (token) to/from user's home directory

    I want to build a class that runs on Windows/Unix clients. It needs to get to users' home directories (both environments) and write the token on login, delete it on logout.
    What method (or code snipet) would get a user's home directory?
    What method (or code snipet) would write/delete a file from it?
    Thanks much

    Even if you are not writing an Applet, this is applicable. But I thot if you were, you might need this.
    See 'SignedAppletDemo.java'
    http://developer.java.sun.com/developer/technicalArticles/Security/Signed/

  • Is there a file in which OSX stores the home directory path, where to find it and how to edit it in Windows 7?

    Hi everyone,
    I have a SSD with the System and Apps on it, and another HDD containing the home directory.
    I made the mistake to rename the Volume the home directory is on whilst being logged in, the system reacted accordingly and prompted some Password requests,
    and I then tried to choose the newly named Volume in the Advanced options dialogue in Users & Groups (example seen below).
    I tried to change the name back to what it was in the hope of it all being back to normal again, but instead it's completely messed up now and I cannot login anymore (prompt: "You are unable to log in to the user account "xxxx" at this time. Logging in to the account failed because an error occurred")
    All I can do now is boot my Windows 7 and try to fix this from there, I can read/write the OSX Volumes thanks to MacDrive.
    So now the big question is:
    IS THERE A FILE containing the path to the home directory (red arrow)?
    IF SO, WHERE can I find it?
    And is there a way to edit it in Windows?
    My guess is that if I rename the Volume, AND change this path to something identical again, it might solve the issue.
    Thanks!

    Download THIS
     Cheers, Tom

  • Receiver File Adapter - Directory field - home directory

    How do I populate the Directory field in the receiver file adapter if I don't know the directory.  I want to use "home directory", but I don't know what that is.  I'm sending a file to a IBM i5 OS.

    I have already asked for the path.  This is the answer I got.
    Directory listings from FTP sessions are disabled.  We use IBM i5 OS for the FTP server because it's immune to exploits aimed at Windows and Linux based servers.  Since you can only "PUT" a file, it is analogous to a bank night deposit box (lots of companies can make deposits to this same metal box on the brick wall but none of them can use it to make withdrawals).

  • Strange file created in my home directory!

    I just recently noticed a zero byte size file created at the root level of my home directory (see below). It's an ip address (from Belize) with what I assume to be a high port at the end of the ip address. It was created back on December 6'th and I have no idea how it got there. I have scanned my desktop with ClamxAV and the free version of Sophos for mac but all comes back clean. Has anyone seen something like this before, should I be concerned? I did not create it and no one but me uses this profile.

  • Home Directory Synchronisation and "DS_Store" files

    I have five clients on Tiger connected to a Tiger server. All clients are 10.4.8.
    Initially I turned Home Synchronising on, but since turned it off, realising I don't really need it. One of the clients, with the biggest profile, still keeps synchronising files. They often get the following message in relation to "DS_Store" files:
    You do not have permission to synchronize this file. You can check
    your permissions in the Info window in the Finder
    Name: .DS_Store
    Size: 6.15 KB
    Modified: 09/02/2007 10:09 AM
    Location: Documents/Work - laptop/office/folders/.DS_Store
    My questions:
    1. As I haven't apparently turned off Home Sync'ing (via the Workgroup application), what else can I check?
    2. What does a DS_Store file do?
    3. Will it kill something if I delete all the DS_Store files I can find, so they no longer synchronise?
    4. Alternatively, how can I enable DS_Store files to be replicated?
    Thanks,
    Sam

    A .DS_Store file is an invisible what controls what you see in every folder/directory. The most imoportant one is the one which controls the Desktop folder in your home directory. The Desktop folder is always open—it's what you see on your desktop when the Finder is running. If you delete the file, for any folder, including the Desktop, it'll be recreated as soon as you reopen the folder or relaunch the Finder, in the case of the Desktop .DS_Store file.
    I can't answer your query WRT tp synchronization or servers. You might post the problem to the Servers forum.

Maybe you are looking for

  • How to convert Labview document into PDF format

    Hi! can any one tell me, can we convert the Labview document (Labview saved files)into PDF format. I wanted to convert it using a VI. If any one suggest me or send me the example vi i will be very thankful. Regards Ramesh.C

  • I deleted my iphone account from my mac,how do i reinstall it?

    I deleted my iphone account from my icloud on my mac-how do i reinstall it?

  • Calendar doublets in the "selected Calendars" list

    Hi. Since some months I suffer from a strange behaviour of iSync: In the calendar's list within the Sync-Settings dialog for my Nokia 6600 there are many doublets of calendars, which work quite normal in iCal. So I don't know which doublet to mark an

  • Control amount of frames a video creates in PS CS6

    I have another gif program that lets me choose how many frames I want to work with from the video, color quality wise obviously Photoshop is better so I want to use photoshop, but it doesn't seem to let me control how many frames I can split it up in

  • Mac App Store Error

    I keep getting this notification error when I try downloading Final Cut Pro X onto my Macbook Pro. "There was an error in the App Store. Please try again later. (100)" Any idea? I've tried the majority of stuff online already and nothing seems to be