Apple Event: May 7th at 7 am PT

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Malware including Trojan & Keylogger removal from Macbook Pro 2021

I am sure I have done this to myself but I stupidly downloaded the free version of Spyrix on my own machine as a test because I was trying to figure out a way to catch out my mums cheating partner. Since then, I haven’t been fully able to remove it and have allowed other spyware to infiltrate. I did also download UTM to make a Kali Linux VM but I have since deleted it.


I am the only account on my computer and administrator but my mouse lags or glitches, I am suddenly logged out, files will change or be renamed on desktop, I have noticed drastic speed drops that are not usual for an M1 Pro. I have noticed multiple weird instances where my camera stream would appear through FaceTime or meeting apps like Zoom & Teams to the host but from my end would be black.


There are multiple weird hidden files I have discovered through search and activity log. Lots of usage with google helper (rendering) etc. This may also be due to the fact I had multiple chrome extensions for aliexpress etc. These may also have contributed to the malware on my computer.


There is something weird going on with ~/Library/LaunchAgents vs. /Library/LaunchAgents. I believe the are swapped or aliased to enable the trojan/malware.


I have downloaded some free anti virus apps to try to resolve this (from Apple App Store only). Anti-Virus X-out/ Adware X-out discovered Spyrix at first, I paid $10 for removal and now it discovers DazzleSpy.

I downloaded virus barrier scanner (from apple App Store) and malware bytes and both pick up nothing.

I downloaded CleanmyMacX and it shows many suspicious files but nothing for malware either.


There are still Spyrix cache files in my library and other very suspicious LaunchAgent/LaunchDaemon files in both libraries including Elitekeylogger and iLifeMediaBrowser and weird Video/Music plugins etc.


I know I got myself into this mess but I am desperate for help. I have a general IT knowledge but anything with Library/system hidden files etc. is where my knowledge ends.

I have run an EtreCheck report and I would be very grateful if someone was able to help me with figuring out this mess I have gotten into.


Posted on Apr 29, 2022 11:22 PM

Reply

Similar questions

10 replies

Apr 30, 2022 2:06 AM in response to brendod

The amount of " Stuff " that was installed to remedy this computer issue may have just made a bad situation even worse.


One can attempt to find / clean up all this " Stuff " and not get all the bits and pieces left behind.


Or a more Radical approach and Wipe the Drive and reinstall Monterey Fresh. Refer to below image " Erase All Contents and Setting . . . "



If doing that - suggest Not using Migration Assist at first boot up. That would re-Introduce the existing issue that existed when the TM Backup was made.


Just Migrate the User Account and nothing more


Any Third Party Applications that will interfere with the normal operation of the OS, alter, modify, remove or delete or attempt to do so is an invitation for disaster . It may require a Reinstallation of the OS in-order to replace any modified, altered, removed or corrupted elements of the OS this software has inflected on this computer 


Although some or all of these Applications maybe available on the Apple Apps Store, it does not mean Apple has verified what exactly the Application can do, does do or is doing to the Computer. That responsibility is left to the User to perform their due diligence on the Application before purchasing and installing it.


Any of the below should be removed as per Developers Instructions 


This includes AntiVirus, Disk Cleaners, Disk Optimizes, UnInstaller etc.


This will include CleanMyMac , This will include BitDefender


This will included Norton Antivirus , Sophos Av Software


Intego AntiVirus, McAfee, MacKeeper, Avast AntiVirus


Ad Guard, Webroot


The The Built in Security  is all that is required.

Apr 30, 2022 4:29 AM in response to brendod

You don't have any malicious software installed on your computer. It is possible there could be some leftover files, but they are harmless. Some scam apps will claim that those leftover files are evidence of a continuing infection.


You still have a few parts of various antivirus apps installed. Any partially installed apps will do more harm than good.


The technical restrictions that Apple imposes on all Mac App Store apps make antivirus apps impossible on the Mac App Store.

Apr 30, 2022 5:04 AM in response to PRP_53

Are you saying that "mcafee" is synonymous with antivirus? Hmmm....Not sure I would go along with that.


But regardless, Apple does not allow Mac App Store apps to:

1) Scan the hard drive

2) Elevate user privileges


For this category of software, Mac App Store apps can be useful as advertisements to get the user to purchase the "full" product outside of the Mac App Store.

Apr 30, 2022 5:53 AM in response to PRP_53

P. Phillips wrote:

In the Full Context " Although some or all of these Applications maybe available on the Apple Apps Store," does not say it is definitively there :-)

But Avast AV is ;-)

That is just a search field. It is using a proprietary Apple algorithm to return results that the user might find useful. It is not an exact match.


Neither McAfee nor Avast is in the Mac App Store. These results should be interpreted as, "I see you are searching for antivirus apps like McAfee or Avast. Here are some apps you might like instead..."

Malware including Trojan & Keylogger removal from Macbook Pro 2021

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.