has my mac been attacked?

Macintosh software/hardware discussion and troubleshooting

Moderator: James Steele

Post Reply
User avatar
martian
Posts: 1821
Joined: Thu Aug 11, 2005 10:01 pm
Primary DAW OS: Unspecified

has my mac been attacked?

Post by martian »

someone was using my laptop in the studio..

I had created a non sensitive data account - unable to admin etc etc..

the next day - my finder is screwy from the get go..

I tried to repair permissions -

get this -

Warning: SUID file "System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/MacOS/ARDAgent" has been modified and will not be repaired.


also the dock has disappeared -

and apple tab between apps is over..

what do I need to repair?

thanks!
macpro 3 gig - 5 Gig RAM 10.6.3 Motu 2408 mk 2 Mackie HUI DP 7.21 intel imac 3 gig ram traveller OS 10.6.3

http://www.fork-media.com
User avatar
Phil O
Posts: 7347
Joined: Thu Jul 28, 2005 10:01 pm
Primary DAW OS: MacOS
Location: Scituate, MA

Re: has my mac been attacked?

Post by Phil O »

martian wrote:Warning: SUID file "System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/MacOS/ARDAgent" has been modified and will not be repaired.
http://support.apple.com/kb/TS1448?viewlocale=en_US" onclick="window.open(this.href);return false;
DP 11.34. 2020 M1 Mac Mini [9,1] (16 Gig RAM), Mac Pro 3GHz 8 core [6,1] (16 Gig RAM), OS 15.3/11.6.2, Lynx Aurora (n) 8tb, MOTU 8pre-es, MOTU M6, MOTU 828, Apogee Rosetta 800, UAD-2 Satellite, a truckload of outboard gear and plug-ins, and a partridge in a pear tree.
User avatar
FMiguelez
Posts: 8266
Joined: Sun Oct 24, 2004 10:01 pm
Primary DAW OS: MacOS
Location: Body: Narco-México Soul/Heart: NYC

Re: has my mac been attacked?

Post by FMiguelez »

.

If the account was not an "administration" account, they shouldn't have been able to even modify the preferences in that special account you created.

Are you 100% it was a regular account?

Could they somehow have logged in as the "root user"?

I know this won't help you now, but next time enable the special "guest" account. This is supposed to be easy and avoid many headaches. Everything gets deleted in that account as soon as they log out.
Mac Mini Server i7 2.66 GHs/16 GB RAM / OSX 10.14 / DP 9.52
Tascam DM-24, MOTU Track 16, all Spectrasonics' stuff,
Vienna Instruments SUPER PACKAGE, Waves Mercury, slaved iMac and Mac Minis running VEP 7, etc.

---------------------------

"In physics the truth is rarely perfectly clear, and that is certainly universally the case in human affairs. Hence, what is not surrounded by uncertainty cannot be the truth." ― Richard Feynman
User avatar
MIDI Life Crisis
Posts: 26285
Joined: Wed May 18, 2005 10:01 pm
Primary DAW OS: MacOS
Contact:

Re: has my mac been attacked?

Post by MIDI Life Crisis »

As for the dock, either under the apple logo (top left of your screen) or system prefs and have it appear again. They probably hid the dock to work "more efficiently" but rule #1 of using someone else's computer is: don't change anything w/o asking permission. Rule # 2: never let anyone use your computer unattended. Rule #3 (should be rule #1): Never let anyone use your computer, especially if you use of for work or financial records!!!
2013 Mac Pro 2TB/32GB RAM

OSX 10.14.6; Track 16; DP 12; Finale 28

LinkTree (events & peformances)
Instagram
Facebook

MIDI LIFE CRISIS
User avatar
MIDI Life Crisis
Posts: 26285
Joined: Wed May 18, 2005 10:01 pm
Primary DAW OS: MacOS
Contact:

Re: has my mac been attacked?

Post by MIDI Life Crisis »

You might want to change the admin password as well...
2013 Mac Pro 2TB/32GB RAM

OSX 10.14.6; Track 16; DP 12; Finale 28

LinkTree (events & peformances)
Instagram
Facebook

MIDI LIFE CRISIS
User avatar
Dan Walsh
Posts: 566
Joined: Tue Apr 29, 2008 4:44 pm
Primary DAW OS: MacOS
Location: Waterloo, ON
Contact:

Re: has my mac been attacked?

Post by Dan Walsh »

Phil O wrote:
martian wrote:Warning: SUID file "System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/MacOS/ARDAgent" has been modified and will not be repaired.
http://support.apple.com/kb/TS1448?viewlocale=en_US" onclick="window.open(this.href);return false;

This one shows up on my system every time I repair permissions. It has never caused me any trubs...... :D
iMac 3.06 i3|OSX 10.6.8|8 gig ram||DP 7.24|Motu 896HD|2 Avalon VT 737's|Presonus ADL600|Slate VCC|Superior Drummer 2|EZ Drummer|1.1.6|Kontakt Player 4.1|Steven Slate Drums EX|SampleTank 2 XTAntares ATR-1|Presonus Central Station|Neumann TLM 103|Rode NT1|Audio Technica AT 4033 X2| Rode NT-5's|and lot's of other junk
User avatar
martian
Posts: 1821
Joined: Thu Aug 11, 2005 10:01 pm
Primary DAW OS: Unspecified

Re: has my mac been attacked?

Post by martian »

phew thats re-assuring gents ...

actually it happened after i got a DVD from protools - cos thats why I opened the lappy up..

and the finder was like treacle -

MLC - i tried the dock pop out to right in the apple menu -

but everytime was no go.. only go slow - and cant apple tab -

something is a miss!

actually I gotta take the new macbookpro back - cos the glass screen is falling off!

naybe it's time to back it up and start again? ( i thought that was a purely windows experience?)
macpro 3 gig - 5 Gig RAM 10.6.3 Motu 2408 mk 2 Mackie HUI DP 7.21 intel imac 3 gig ram traveller OS 10.6.3

http://www.fork-media.com
User avatar
MIDI Life Crisis
Posts: 26285
Joined: Wed May 18, 2005 10:01 pm
Primary DAW OS: MacOS
Contact:

Re: has my mac been attacked?

Post by MIDI Life Crisis »

Trash your dock.plist from your home directory and restart. If that doesn't do it, trash the finder.plist and repeat.
2013 Mac Pro 2TB/32GB RAM

OSX 10.14.6; Track 16; DP 12; Finale 28

LinkTree (events & peformances)
Instagram
Facebook

MIDI LIFE CRISIS
Post Reply