Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Runaway process "mdsd".

Even after I force-quit the process it will reappear and max my cpu to 100%. After quitting all applications, the process still returns every 15 minutes. Does anyone know what's causing it?

MacBook Pro, Mac OS X (10.7.2)

Posted on Nov 1, 2011 8:25 AM

Reply
54 replies

Nov 1, 2011 7:59 PM in response to tthor

I am also experiencing issues with "mdsd" running 99-100% of my CPU. CPU temp reaches 94 degrees F as well.


Any advice on what this is or how to stop it would be much appreciated.


My apologies for posting in the Macbook Pro forum, but this is the only thread that contains "mdsd."


"Open files and ports" reveals:


/Users/[DELETED FOR PRIVACY]/Library/Manager

/Users/[DELETED FOR PRIVACY/Library/Manager/mdsd

/usr/lib/libssl.0.9.7.dylib

/usr/lib/libcrypto.0.9.7.dylib

/usr/lib/dyld

/private/var/db/dyld/dyld_shared_cache_i386

/dev/null

/dev/null

->0xffffff800c9226b0

*:34123

->0xffffff800d7b9640

unknown60c547061968:49616->su.mining.eligius.st:8337

unknown60c547061968:49617->su.mining.eligius.st:8337



MBA 2011 1.7 GHz/I5, 10.7.2

Nov 1, 2011 9:23 PM in response to tthor

Upon some investigation, namely that su.mining.eligius.st address, it's become clear that this is related to a process called "bitcoin." You may have downloaded a program that has enabled bitcoin access. Bitcoins allow remote servers to use your CPU and thus heat up your drive and overwork your fans. It can more dangerously allow remote servers to access your passwords and search histories.


Again, this is just my own research, and I am by no means a techie. Just beware.


If someone else could confirm this, it would be appreciated.

Nov 2, 2011 5:34 AM in response to tthor

I ran Clamxav too but it didn't find any trojan and I wouldn't have a clue how I would have downloaded GraphicConverter, since I don't have any interest in anything related to photography.



As far as I know ( and I'm the only one using this Mac) I have no pirated software installed. Now, I have restored a cloned copy of my HD which I created 4-5 days ago and so far, everything seems to be fine.

Nov 2, 2011 5:39 AM in response to tthor

I ran a system scan with ClamXav and it found a trojan embedded in some email in my junk folder.


It seems that the database ClamXav uses was updated only last night to include the trojan you have. I don't know whether it can detect the trojan as installed, or only as downloaded.


Open your Applications folder in list view, and arrange by date with the most recent at top. What applications have you installed in the past few days?

Nov 2, 2011 5:51 AM in response to Linc Davis

Application list by date:


  • Little Snitch (official website)
  • Stuffit Expander (App store, update)
  • iPhoto (App store update)
  • Worml (App store)
  • LittleSnapper (App store)
  • ClamXav (App Store)
  • Onyx (Official site)
  • Arq (Official site)
  • Pixelmator (Official site, trial)
  • TotalTerminal (Official site, trial)
  • Trine (App store)
  • Feeds (App store)
  • Rdio (Official site)
  • BBEdit (App Store)


That goes back to October 7th, way before this problem started.

Nov 2, 2011 9:59 AM in response to tthor

I have serious doubts that this is related to the recent Devil Robber trojan making the rounds. A complete scan with both Sophos and ClamXav found nothing (both updated with the most recent definitions including DevilRobber). After some research, the trojan ClamXav picked up before in my junk email was a false positive.


The process responsible can be found at /Users/[name]/Library/Manager/mdsd


Removing that file has fixed the problem. Little Snitch said the file was trying to call out to su.mining.eligius.st:8337, which seems to be a BitCoin mining operation, and makes it unlikely to be a OS X core process.


I've never encountered something like this and my lingering concern is whether sensitive data was accessed. Perhaps this is another rogue mac trojan that security firms have yet to identify?

Runaway process "mdsd".

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.