Hey Linc Davis! We had some email go around at the office and I received it and opened it. Apparently there was a good chance of a keylogger in it... I completed your steps and have pasted the results below. Any help would be amazing! I have no idea what I'm looking for...
Last login: Tue Sep 1 08:42:01 on console
Josephs-MacBook-Pro:~ verrucktfuchs$ kextstat -kl | awk '!/com\.apple/{printf "%s %s\n", $6, $7}'
com.Cycling74.driver.Soundflower (1.6.6)
com.intego.netbarrier.kext.monitor (177)
com.intego.netbarrier.kext.network (177)
com.intego.netbarrier.kext.process (177)
com.intego.virusbarrier.kext.realtime (322)
Josephs-MacBook-Pro:~ verrucktfuchs$ sudo launchctl list | sed 1d | awk '!/0x|com\.(apple|openssh|vix)|edu\.mit|org\.(amavis|apache|cups|isc|ntp|postfi x|x)/{print $3}'
We trust you have received the usual lecture from the local System
Administrator. It usually boils down to these three things:
#1) Respect the privacy of others.
#2) Think before you type.
#3) With great power comes great responsibility.
Password:
com.intego.virusbarrier.daemon.emlparser
com.adobe.ARMDC.Communicator
com.adobe.adobeupdatedaemon
com.oracle.java.JavaUpdateHelper
com.intego.commonservices.icalserver
com.intego.netbarrier.daemon
com.intego.virusbarrier.daemon.realtime
com.intego.commonservices.daemon.taskmanager
com.microsoft.office.licensing.helper
com.oracle.java.Helper-Tool
com.intego.commonservices.metrics.kschecker
com.intego.netupdate.daemon
com.intego.netbarrier.daemon.logger
com.intego.virusbarrier.daemon
com.adobe.ARMDC.SMJobBlessHelper
com.intego.netbarrier.daemon.monitor
com.intego.virusbarrier.daemon.logger
com.teamviewer.Helper
com.intego.virusbarrier.daemon.scanner
com.intego.commonservices.daemon.integod
Josephs-MacBook-Pro:~ verrucktfuchs$ launchctl list | sed 1d | awk '!/0x|com\.apple|edu\.mit|org\.(x|openbsd)/{print $3}'
com.microsoft.autoupdate.fba.78700
com.brother.LOGINserver
com.intego.commonservices.taskmanager
com.intego.virusbarrier.alert
com.intego.netupdate.agent
com.google.GoogleDrive.44052
com.adobe.AdobeCreativeCloud
com.intego.netbarrier.alert
com.intego.commonservices.uninstaller
com.brother.utility.USBserver.14800
com.digitician.examinet.52856
com.adobe.ARMDCHelper.cc24aef4a1b90ed56a725c38014c95072f92651fb65e1bf9c8e43c37a2 3d420d
com.adobe.AAM.Scheduler-1.0
com.digitician.PeakHour-Helper
com.adobe.PDApp.AAMUpdatesNotifier.61944.BCF122F0-D7F6-479A-8D0E-E8C9580531D4
com.oracle.java.Java-Updater
com.intego.commonservices.integomenu
com.citrixonline.GoToMeeting.G2MUpdate
com.adobe.acc.AdobeDesktopService.100852.3F9B0CAF-219D-4425-954D-9D024C692F1E
com.google.Chrome.43768
com.google.keystone.user.agent
com.microsoft.Office365Service.51152
com.brother.utility.NETserver.15652
Josephs-MacBook-Pro:~ verrucktfuchs$ ls -1A /e*/mach* {,/}L*/{Ad,Compon,Ex,Fram,In,Keyb,La,Mail/Bu,P*P,Priv,Qu,Scripti,Servi,Spo,Sta} * L*/Fonts 2> /dev/null
/Library/Components:
/Library/Extensions:
ACS6x.kext
ATTOCelerityFC8.kext
ATTOExpressSASHBA2.kext
ATTOExpressSASRAID2.kext
ArcMSR.kext
CalDigitHDProDrv.kext
HighPointIOP.kext
HighPointRR.kext
PromiseSTEX.kext
SoftRAID.kext
/Library/Frameworks:
AEProfiling.framework
AERegistration.framework
Adobe AIR.framework
AudioMixEngine.framework
IntegoiCalFramework.framework
NetUpdateShared.framework
NyxAudioAnalysis.framework
PluginManager.framework
iTunesLibrary.framework
/Library/Input Methods:
/Library/Intego:
.isb6_info
.netbarrier_info
IM_ObjectiveMetrics.framework
Intego Uninstaller.app
IntegoiCalServer
TaskManager
commonservices.bundle
im_helper_tool
im_ks_tool
integod
netbarrier.bundle
netupdated.bundle
virusbarrier.bundle
/Library/Internet Plug-Ins:
AdobeAAMDetect.plugin
AdobePDFViewer.plugin
AdobePDFViewerNPAPI.plugin
Default Browser.plugin
DirectorShockwave.plugin
JavaAppletPlugin.plugin
Quartz Composer.webplugin
QuickTime Plugin.plugin
SharePointBrowserPlugin.plugin
SharePointWebKitPlugin.webplugin
nsIQTScriptablePlugin.xpt
/Library/Keyboard Layouts:
/Library/LaunchAgents:
com.adobe.AAM.Updater-1.0.plist
com.adobe.ARMDCHelper.cc24aef4a1b90ed56a725c38014c95072f92651fb65e1bf9c8e43c37a2 3d420d.plist
com.adobe.AdobeCreativeCloud.plist
com.brother.LOGINserver.plist
com.intego.commonservices.integomenu.plist
com.intego.commonservices.taskmanager.plist
com.intego.commonservices.uninstaller.plist
com.intego.netbarrier.alert.plist
com.intego.netupdate.agent.plist
com.intego.virusbarrier.alert.plist
com.oracle.java.Java-Updater.plist
com.teamviewer.teamviewer.plist
com.teamviewer.teamviewer_desktop.plist
/Library/LaunchDaemons:
com.adobe.ARMDC.Communicator.plist
com.adobe.ARMDC.SMJobBlessHelper.plist
com.adobe.adobeupdatedaemon.plist
com.intego.commonservices.daemon.integod.plist
com.intego.commonservices.daemon.taskmanager.plist
com.intego.commonservices.icalserver.plist
com.intego.commonservices.metrics.kschecker.plist
com.intego.netbarrier.daemon.logger.plist
com.intego.netbarrier.daemon.monitor.plist
com.intego.netbarrier.daemon.plist
com.intego.netupdate.daemon.plist
com.intego.virusbarrier.daemon.emlparser.plist
com.intego.virusbarrier.daemon.logger.plist
com.intego.virusbarrier.daemon.plist
com.intego.virusbarrier.daemon.scanner.plist
com.microsoft.office.licensing.helper.plist
com.oracle.java.Helper-Tool.plist
com.oracle.java.JavaUpdateHelper.plist
com.teamviewer.Helper.plist
com.teamviewer.teamviewer_service.plist
/Library/PreferencePanes:
JavaControlPanel.prefPane
Tuxera NTFS.prefPane
/Library/PrivilegedHelperTools:
NetUpdateAgent.app
com.adobe.ARMDC.Communicator
com.adobe.ARMDC.SMJobBlessHelper
com.microsoft.office.licensing.helper
com.oracle.java.JavaUpdateHelper
com.teamviewer.Helper
/Library/QuickLook:
iBooksAuthor.qlgenerator
iWork.qlgenerator
/Library/QuickTime:
AppleIntermediateCodec.component
AppleMPEG2Codec.component
/Library/ScriptingAdditions:
Adobe Unit Types.osax
/Library/Spotlight:
Microsoft Office.mdimporter
iBooksAuthor.mdimporter
iWork.mdimporter
/Library/StartupItems:
/etc/mach_init.d:
/etc/mach_init_per_login_session.d:
/etc/mach_init_per_user.d:
Library/Address Book Plug-Ins:
SkypeABDialer.bundle
SkypeABSMS.bundle
Library/Fonts:
Bentham.otf
Blokletters-Balpen.ttf
Blokletters-Potlood.ttf
Blokletters-Viltstift.ttf
Chomp.ttf
Daniel-Black.otf
Montserrat-Black.otf
Montserrat-Bold.otf
Montserrat-Hairline.otf
Montserrat-Light.otf
Montserrat-Regular.otf
Multicolore.otf
billy.ttf
daniel.ttf
danielbd.ttf
rabiohead.ttf
Library/Input Methods:
.localized
Library/Internet Plug-Ins:
CitrixOnlineWebDeploymentPlugin.plugin
WebEx64.plugin
Library/Keyboard Layouts:
Library/LanguageModeling:
da-dynamic.lm
de-dynamic.lm
en-dynamic.lm
es-dynamic.lm
fr-dynamic.lm
it-dynamic.lm
nb-dynamic.lm
nl-dynamic.lm
pt-dynamic.lm
ru-dynamic.lm
sv-dynamic.lm
tr-dynamic.lm
Library/LaunchAgents:
com.adobe.AAM.Updater-1.0.plist
com.citrixonline.GoToMeeting.G2MUpdate.plist
com.google.keystone.agent.plist
Library/PreferencePanes:
Library/Services:
Josephs-MacBook-Pro:~ verrucktfuchs$ osascript -e 'tell application "System Events" to get name of every login item' 2> /dev/null
iTunesHelper, Google Drive, AdobeResourceSynchronizer
Josephs-MacBook-Pro:~ verrucktfuchs$