Quote:
Originally Posted by drewprops
Maybe we should copy those instructions over here?
...
|
Direct link to the source with all the actual details:
https://redcanary.com/blog/clipping-...parrows-wings/
TLDR: If you find a file at any of the following locations, your system is likely infected. Deleting them and rebooting is a good
start, but there are more things you should check and purge as well.
/tmp/agent
/tmp/agent.sh
/tmp/version.json
/tmp/version.plist
/tmp/verx
~/Library/._insu
~/Library/Application Support/agent_updater/agent.sh
~/Library/Application Support/verx_updater/verx.sh
~/Library/Launchagents/agent.plist
~/Library/Launchagents/init_agent.plist
~/Library/Launchagents/init_verx.plist
~/Library/Launchagents/verx.plist