The firewall in question resides on our router. An image of a clean rules list is here.
The rules open unblocked in/out traffic to between my IP (rules change to reflect a changed IP) and WAN. The only way to remove the rules are to restore to a config backup.
A new, fresh, account sets the rules upon first connecting to the router.
One of the notes on one instance of the rules gave a string of letters and numbers that, when googled, point only to one place – some japanese manga blog. It was later confirmed that the kid using the computer was on this site. I don’t have the URL to the site anymore.
I assumed that the problem stems from samba, because it was the only portion of OS X that I considered at all insecure. If this were the case, then I would assume that the process would be smbd.
I needed safe access to the internet from that machine, so I performed an archive and install, thinking that I could manually migrate the user-generated data files from the archive, and for my own account (there are 3), I would migrate the account wholesale. Before migration of the new account, i applied all system updates and checked the firewall. It was clean. After the update and the migration of the my old account’s folder, the rules began resetting themselves.
I then slicked the drive and installed again. At present, my plan is to manually re-install apps and settings for my account manually. The other two accounts were hardly configured at all; I’ll let their respective users perform any configs they want.
I would like very much to be able to restore the system from my time machine backup, but even the earliest backup has the problem. I started backing up after the machine had been compromised. With the information you have now, do you know of a way to fix the system (if restored from the backup) without connecting it to the internet? ( can download files from other machines).
Thanks for your help, really.