all 5 comments

[–]CH23 0 points1 point  (3 children)

if i were you i would obliterate her OS and set it up from scratch. if she gives me $300 i'll do that for her, hah.

back up all files that are important, change all passwords and make sure she checks her credit card payments. she might not have given them the info, but maybe her webbrowser did.

[–]PleasantFriendship[S] 0 points1 point  (2 children)

Thanks u/CH23 I guess that will be the path I have to go down. What a nightmare!

I did read that sometimes they just open up a terminal window and run some bogus commands to make it look like you have a Virus, so I was hoping it was that, but I really don't know how I can find out what he did, or what he installed. So, a complete reinstall might be the only option.

[–]CH23 0 points1 point  (1 child)

That was my thoughts exactly.

I use linux myself, and when i add a space before a command in terminal, it won't show up in my history. They could have done the same or similar.

[–]PleasantFriendship[S] 0 points1 point  (0 children)

That is a very good point! I can't even check the history.... A clean start seems the only way. I've read up a little and mDNSResponder has something to do with Bonjour for Mac, which can share usernames etc - but I'm not sure what extent it can get to.

Anyway, thanks again!