Hi there,
I need help, please. I have a Powerbook G4. I think I got a trojan while running Tiger before the last Apple security update (Sep. 10, 2009?). Revealing hidden files with MainMenu showed a hidden mirror mount of my HDD on my 'network' (I think I have this again). Since then, I have tried to reinstall Leopard 5 or 6 times from a retail copy. Guys at the 'Genius' Bar tell me I'm just paranoid, but I think something is up.
After booting from Leopard DVD and secure erasing then formating my HDD with a single volume, running 'diskutil info' from console lists 6 mounted disks. Disk0 = my HDD, disk1 = DVD, disk2-disk5 are 'file system = UFS' (nothing is attached to comp other than power cord). Also, the volume I create is missing ~1 GB of space 'not avail' and has 3 files and 3 folders (this may all be normal, IDK, just trying to give as much detail as possible).
So...after installing Leopard (before attaching anything to the Mac or connecting to the internet), I notice many strange 'Date Created' and 'Date Modified' dates (some from 1976..see screenshots, taken immediately after install), root certificates with 'not trusted' warnings in Keychain, and lots of 'alias' and other files that seem not to belong.
When I do connect to the internet, Safari wants my 'login password', and 'Stealth Mode' firewall reveals an instant flood of UDP connection attempts (I also 'hard reset' my Airport Express and updated it).
I don't know what's going on, but it sure doesn't seem right. Please have a look and give me any thought or help!
Thanks,
Jake
I need help, please. I have a Powerbook G4. I think I got a trojan while running Tiger before the last Apple security update (Sep. 10, 2009?). Revealing hidden files with MainMenu showed a hidden mirror mount of my HDD on my 'network' (I think I have this again). Since then, I have tried to reinstall Leopard 5 or 6 times from a retail copy. Guys at the 'Genius' Bar tell me I'm just paranoid, but I think something is up.
After booting from Leopard DVD and secure erasing then formating my HDD with a single volume, running 'diskutil info' from console lists 6 mounted disks. Disk0 = my HDD, disk1 = DVD, disk2-disk5 are 'file system = UFS' (nothing is attached to comp other than power cord). Also, the volume I create is missing ~1 GB of space 'not avail' and has 3 files and 3 folders (this may all be normal, IDK, just trying to give as much detail as possible).
So...after installing Leopard (before attaching anything to the Mac or connecting to the internet), I notice many strange 'Date Created' and 'Date Modified' dates (some from 1976..see screenshots, taken immediately after install), root certificates with 'not trusted' warnings in Keychain, and lots of 'alias' and other files that seem not to belong.
When I do connect to the internet, Safari wants my 'login password', and 'Stealth Mode' firewall reveals an instant flood of UDP connection attempts (I also 'hard reset' my Airport Express and updated it).
I don't know what's going on, but it sure doesn't seem right. Please have a look and give me any thought or help!
Thanks,
Jake
Attachments
-
Picture 1.png918.6 KB · Views: 6
-
Picture 2.png331.7 KB · Views: 6
-
DirectoryService_server_log.txt2.1 KB · Views: 2
-
install_log_0_part1.txt79.6 KB · Views: 2
-
install_log_0_part2.txt78.7 KB · Views: 0
-
install_log_0_part3.txt82.3 KB · Views: 0
-
install_log_0_part4.txt98.6 KB · Views: 0
-
install_log_0_part5.txt74.1 KB · Views: 1
-
terminal_diskutil_info.txt6 KB · Views: 4
Last edited: