Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Finding a keylogger on my macbook pro computer

Hi,

I think someone has put a keylogger on my computer and I'm trying to locate it. They have told me two pieces of info, and the only way they would know is by some how having access to my computer. Only I know the password. I'm not under 18 nor an employee. Please look through the list off my computer terminal which I got to see if there's any keylogger clues.

Is this spyware: google.keystone.agent.plist


Do you see any spyware or keylogger?


Once I find out the spy software, how do I find out who put it on?


Perhaps there are other keyloggers or spyware, do you see any?


I'm quite sure that someone has put a keylogger on my macbook pro. I followed the directions here: https://discussions.apple.com/thread/4243511 And I came up with the following. Does you see any keylogger info here? Please include any helpful info. Thank you so much for your assistance. I greatly appreciate it and I look forward to reading your response.



1.



com.mcafee.kext.Virex (1.1.0d1)

Ellies-MacBook-Pro:~ healthyinspiration$



2.



com.mcafee.reporter

com.mcafee.menulet

com.google.keystone.system.agent

com.adobe.CS4ServiceManager

Ellies-MacBook-Pro:~ healthyinspiration$

Ellies-MacBook-Pro:~ healthyinspiration$ ls -1A /e*/mach* {,/}L*/{Ad,Compon,Ex,Fram,In,Keyb,La,Mail/Bu,P*P,Priv,Qu,Scripti,Servi,Spo,Sta} * L*/Fonts 2> /dev/null/Library/Components:



/Library/Extensions:



/Library/Frameworks:

AEProfiling.framework

AERegistration.framework

AVEngine.framework

AudioMixEngine.framework

NyxAudioAnalysis.framework

PluginManager.framework

ScanBooster.framework

VirusScanPreferences.framework

iTunesLibrary.framework



/Library/Input Methods:



/Library/Internet Plug-Ins:

AdobeAAMDetect.plugin

Flash Player.plugin

JavaAppletPlugin.plugin

Quartz Composer.webplugin

QuickTime Plugin.plugin

SharePointBrowserPlugin.plugin

SharePointWebKitPlugin.webplugin

flashplayer.xpt

googletalkbrowserplugin.plugin

npgtpo3dautoplugin.plugin

nsIQTScriptablePlugin.xpt

o1dbrowserplugin.plugin



/Library/Keyboard Layouts:



/Library/LaunchAgents:

com.adobe.AAM.Updater-1.0.plist

com.adobe.CS4ServiceManager.plist

com.google.keystone.agent.plist

com.mcafee.menulet.plist

com.mcafee.reporter.plist



/Library/LaunchDaemons:

com.adobe.fpsaud.plist

com.apple.remotepairtool.plist

com.google.keystone.daemon.plist

com.mcafee.ssm.Eupdate.plist

com.mcafee.ssm.ScanFactory.plist

com.mcafee.ssm.ScanManager.plist

com.mcafee.virusscan.fmpd.plist

com.microsoft.office.licensing.helper.plist

com.wdc.WDDMservice.plist

com.wdc.WDSmartWareServer.plist



/Library/PreferencePanes:

Flash Player.prefPane



/Library/PrivilegedHelperTools:

com.microsoft.office.licensing.helper



/Library/QuickLook:

iWork.qlgenerator



/Library/QuickTime:

AppleIntermediateCodec.component

AppleMPEG2Codec.component



/Library/ScriptingAdditions:

Adobe Unit Types.osax



/Library/Spotlight:

Microsoft Office.mdimporter

iWork.mdimporter



/Library/StartupItems:

cma



/etc/mach_init.d:



/etc/mach_init_per_login_session.d:



/etc/mach_init_per_user.d:



Library/Address Book Plug-Ins:



Library/Fonts:



Library/Input Methods:

.localized



Library/Internet Plug-Ins:

Google Earth Web Plug-in.plugin

Picasa.plugin



Library/Keyboard Layouts:



Library/LaunchAgents:

com.apple.CSConfigDotMacCert-healthyinspiration@me.com-SharedServices.Agent.plist



Library/PreferencePanes:

Ellies-MacBook-Pro:~ healthyinspiration$

Ellies-MacBook-Pro:~ healthyinspiration$ osascript -e 'tell application "System Events" to get name of every login item' 2> /dev/null

iTunesHelper, HP Scheduler

Ellies-MacBook-Pro:~ healthyinspiration$

Ellies-MacBook-Pro:~ healthyinspiration$ kextstat -kl | awk '!/com\.apple/{printf "%s %s\n", $6, $7}'

com.mcafee.kext.Virex (1.1.0d1)

Ellies-MacBook-Pro:~ healthyinspiration$ sudo launchctl list | sed 1d | awk '!/0x|com\.(apple|openssh|vix)|edu\.mit|org\.(amavis|apache|cups|isc|ntp|postfi x|x)/{print $3}'

Password:

com.wdc.WDSmartWareServer

com.wdc.WDDMservice

com.microsoft.office.licensing.helper

com.mcafee.virusscan.fmpd

com.mcafee.ssm.ScanManager

com.mcafee.virusscan.ssm.ScanFactory

com.mcafee.ssm.Eupdate

com.google.keystone.daemon

com.adobe.fpsaud

Ellies-MacBook-Pro:~ healthyinspiration$



3.



Password:

com.wdc.WDSmartWareServer

com.wdc.WDDMservice

com.microsoft.office.licensing.helper

com.mcafee.virusscan.fmpd

com.mcafee.ssm.ScanManager

com.mcafee.virusscan.ssm.ScanFactory

com.mcafee.ssm.Eupdate

com.google.keystone.daemon

com.adobe.fpsaud

Ellies-MacBook-Pro:~ healthyinspiration$ launchctl list | sed 1d | awk '!/0x|com\.apple|edu\.mit|org\.(x|openbsd)/{print $3}'

com.mcafee.reporter

com.mcafee.menulet

com.google.keystone.system.agent

com.adobe.CS4ServiceManager

Ellies-MacBook-Pro:~ healthyinspiration$



4.



com.mcafee.reporter

com.mcafee.menulet

com.google.keystone.system.agent

com.adobe.CS4ServiceManager

Ellies-MacBook-Pro:~ healthyinspiration$ ls -1A /e*/mach* {,/}L*/{Ad,Compon,Ex,Fram,In,Keyb,La,Mail/Bu,P*P,Priv,Qu,Scripti,Servi,Spo,Sta} * L*/Fonts 2> /dev/null/Library/Components:



/Library/Extensions:



/Library/Frameworks:

AEProfiling.framework

AERegistration.framework

AVEngine.framework

AudioMixEngine.framework

NyxAudioAnalysis.framework

PluginManager.framework

ScanBooster.framework

VirusScanPreferences.framework

iTunesLibrary.framework



/Library/Input Methods:



/Library/Internet Plug-Ins:

AdobeAAMDetect.plugin

Flash Player.plugin

JavaAppletPlugin.plugin

Quartz Composer.webplugin

QuickTime Plugin.plugin

SharePointBrowserPlugin.plugin

SharePointWebKitPlugin.webplugin

flashplayer.xpt

googletalkbrowserplugin.plugin

npgtpo3dautoplugin.plugin

nsIQTScriptablePlugin.xpt

o1dbrowserplugin.plugin



/Library/Keyboard Layouts:



/Library/LaunchAgents:

com.adobe.AAM.Updater-1.0.plist

com.adobe.CS4ServiceManager.plist

com.google.keystone.agent.plist

com.mcafee.menulet.plist

com.mcafee.reporter.plist



/Library/LaunchDaemons:

com.adobe.fpsaud.plist

com.apple.remotepairtool.plist

com.google.keystone.daemon.plist

com.mcafee.ssm.Eupdate.plist

com.mcafee.ssm.ScanFactory.plist

com.mcafee.ssm.ScanManager.plist

com.mcafee.virusscan.fmpd.plist

com.microsoft.office.licensing.helper.plist

com.wdc.WDDMservice.plist

com.wdc.WDSmartWareServer.plist



/Library/PreferencePanes:

Flash Player.prefPane



/Library/PrivilegedHelperTools:

com.microsoft.office.licensing.helper



/Library/QuickLook:

iWork.qlgenerator



/Library/QuickTime:

AppleIntermediateCodec.component

AppleMPEG2Codec.component



/Library/ScriptingAdditions:

Adobe Unit Types.osax



/Library/Spotlight:

Microsoft Office.mdimporter

iWork.mdimporter



/Library/StartupItems:

cma



/etc/mach_init.d:



/etc/mach_init_per_login_session.d:



/etc/mach_init_per_user.d:



Library/Address Book Plug-Ins:



Library/Fonts:



Library/Input Methods:

.localized



Library/Internet Plug-Ins:

Google Earth Web Plug-in.plugin

Picasa.plugin



Library/Keyboard Layouts:



Library/LaunchAgents:

com.apple.CSConfigDotMacCert-healthyinspiration@me.com-SharedServices.Agent.plist



Library/PreferencePanes:

Ellies-MacBook-Pro:~ healthyinspiration$

Ellies-MacBook-Pro:~ healthyinspiration$



5.

iTunesHelper, HP Scheduler

Ellies-MacBook-Pro:~ healthyinspiration$

Ellies-MacBook-Pro:~ healthyinspiration$

MacBook Pro (15-inch Late 2011), Mac OS X (10.7.5)

Posted on Oct 29, 2013 11:42 PM

Reply
7 replies

Oct 30, 2013 4:48 AM in response to perseverer

I don't see anything particularly concerning - other than the fact that you have installed McAfee, which is crap and should be uninstalled. That Google item is just something installed by Google software, such as Google Earth or SketchUp.


What pieces of information has this person actually given you, and where is that information stored? It's extremely unlikely that this person has actually gotten access to your computer, unless they have had physical access to your computer. However, there are many ways someone could get personal information without hacking your computer, such as by hacking one of your online accounts, or by simply being on the same unsecured wireless network as you.

Oct 30, 2013 9:42 AM in response to perseverer

There's nothing in relation to your Mac itself that can help you with any of these issues. If your Gmail account has been compromised, you'll need to change the password to that account and if you can't, you'll probably need to abandon that account and set up a new one. If you have an unsecured wireless network, the obvious solution there is to set up a password on your WiFi router and implement the appropriate security measures your router almost certainly includes to prevent an unauthorized user from connecting. The chance that someone can intercept the WiFi signal and get any of your personal information is very small. Just make sure that the URL for any web site you connect to that asks for personal or financial data starts with HTTPS which shows that it's using encryption.


If you have reason to believe that someone has tapped your phone line, you need to take that up with your phone company.


Regards.

Oct 30, 2013 11:22 AM in response to perseverer

I fully agree with everything varjak paw said, but just have a few things to add.


Regarding GMail, changing your password would be a good idea, but is not itself sufficient. GMail provides hackers with a nice and easy way to leave a back door. See:


https://support.google.com/mail/answer/138350?hl=en&ctx=mail


If you find that another account has been delegated to access your account, remove that delegation immediately!


Also, regarding the wifi, you need to make sure to lock that down with WPA2 encryption, and any WPS setting on the router needs to be turned off. Different routers will have different methods for doing this sort of thing, so you will need to consult the manual for your router, or seek help from the manufacturer's web site, if you don't know how to do that.


Also, certain routers can have vulnerabilities that can give people remote access, or could be configured to give remote access by accident. You may want to discuss these issues with the manufacturer of your router, and see if there are any firmware updates that you need to install or changes to the settings that need to be made.

Oct 31, 2013 6:46 PM in response to thomas_r.

Hi,

I took McAfee off.

I'm concerned that someone got into my gmail account.

The other option is that the person who has the password for our home router can

access my computer or emails. The router is by Cisco. It says Linksys on it.

Model WRT 16 ONV3 I called them today and they said the person who has

the password for the router could not access my computer or my gmail.com

account.


I will include some screen shots from my gmail account. My ip address ends is 198 45 242 188

I'm in MO, but the whatismyip.com says I'm in OK. It doesn't seem too accurate.

But on my gmail activity monitor I don't know who two other ip addresses are:


198 45 12 927 Oct 17

207 119 183 139 Oct 14


I've changed my pass word and I have 2 step verification, and I am the only email address listed

to access.

Any help would be appreciated.

Oct 31, 2013 7:06 PM in response to thomas_r.

I am in the same position as persevrer. I did the same procedures and here is the output. Any help high appreciated. Do I have someone spying?


*********************kextstat -kl | awk '!/com\.apple/{printf "%s %s\n", $6, $7}'

  1. com.symantec.kext.internetSecurity (5.3f6)
  2. com.symantec.kext.pf (5.6f22)
  3. com.symantec.kext.ips (3.9f13)
  4. com.symantec.kext.fw (5.3f12)
  5. com.symantec.kext.SymAPComm (12.6f28)

*********************sudo launchctl list | sed 1d | awk '!/0x|com\.(apple|openssh|vix)|edu\.mit|org\.(amavis|apache|cups|isc|ntp|postfi x|x)/{print $3}'


WARNING: Improper use of the sudo command could lead to data loss

or the deletion of important system files. Please double-check your

typing when using sudo. Type "man sudo" for more information.


To proceed, enter your password, or type Ctrl-C to abort.


Password:

  1. com.symantec.deepsight-extractor
  2. com.symantec.symdaemon
  3. com.symantec.sharedsettings
  4. com.symantec.liveupdate.daemon
  5. com.symantec.liveupdate.daemon.ondemand
  6. com.symantec.errorreporting.periodic
  7. com.google.keystone.daemon
  8. com.adobe.SwitchBoard

*********************launchctl list | sed 1d | awk '!/0x|com\.apple|edu\.mit|org\.(x|openbsd)/{print $3}'

  1. com.symantec.uiagent.application
  2. com.symantec.nis.application
  3. com.symantec.errorreporting.periodic-agent
  4. com.Logitech.Control
  5. com.google.keystone.system.agent
  6. com.adobe.CS5ServiceManager
  7. com.adobe.ARM.925793fb327152fd34795896fa1fb9ffa268b2a852256fe56609efa3

*********************ls -1A /e*/mach* {,/}L*/{Ad,Compon,Ex,Fram,In,Keyb,La,Mail/Bu,P*P,Priv,Qu,Scripti,Servi,Spo,Sta} * L*/Fonts 2> /dev/null

/Library/Components:


/Library/Extensions:

  1. FileSecurity.kext
  2. SymAPComm.kext
  3. SymFirewall.kext
  4. SymIPS.kext
  5. SymInternetSecurity.kext
  6. SymPersonalFirewall.kext


/Library/Frameworks:

  1. AEProfiling.framework
  2. AERegistration.framework

Adobe AIR.framework

  1. AudioMixEngine.framework
  2. EWSMac.framework
  3. HPDeviceModel.framework
  4. HPPml.framework
  5. HPServicesInterface.framework
  6. HPSmartPrint.framework
  7. MacFUSE.framework
  8. NyxAudioAnalysis.framework
  9. PluginManager.framework
  10. TSLicense.framework
  11. iTunesLibrary.framework


/Library/Input Methods:


/Library/InputManagers:

LCC Scroll Enhancer Loader


/Library/Internet Plug-Ins:

AdobePDFViewer.plugin

Flip4Mac WMV Plugin.plugin

GarminGpsControl.plugin

Google Earth Web Plug-in.plugin

  1. JavaAppletPlugin.plugin
  2. NortonInternetSecurityBF.plugin

OfficeLiveBrowserPlugin.plugin

Quartz Composer.webplugin

QuickTime Plugin.plugin

  1. Silverlight.plugin
  2. flashplayer.xpt
  3. googletalkbrowserplugin.plugin
  4. iPhotoPhotocast.plugin

npgtpo3dautoplugin.plugin

nsIQTScriptablePlugin.xpt

o1dbrowserplugin.plugin


/Library/Internet Plug-Ins (Disabled):

Flash Player.plugin


/Library/Keyboard Layouts:

Microsoft Keyboards.bundle


/Library/LaunchAgents:

  1. com.Logitech.Control Center.Daemon.plist
  2. com.adobe.AAM.Updater-1.0.plist
  3. com.adobe.CS5ServiceManager.plist
  4. com.google.keystone.agent.plist
  5. com.symantec.errorreporter-periodicagent.plist
  6. com.symantec.nis.application.plist
  7. com.symantec.uiagent.application.plist


/Library/LaunchDaemons:

  1. com.adobe.SwitchBoard.plist
  2. com.google.keystone.daemon.plist
  3. com.symantec.deepsight-extractor.plist
  4. com.symantec.errorreporter-periodic.plist
  5. com.symantec.liveupdate.daemon.ondemand.plist
  6. com.symantec.liveupdate.daemon.plist
  7. com.symantec.nav.migrateqtf.plist
  8. com.symantec.sharedsettings.plist
  9. com.symantec.symdaemon.plist


/Library/PreferencePanes:

Flip4Mac WMV.prefPane

Microsoft Keyboard.prefPane

Microsoft Mouse.prefPane

SymantecQuickMenu.prefPane


/Library/PrivateFrameworks:

  1. SymAVScan.framework
  2. SymAppKitAdditions.framework
  3. SymBase.framework
  4. SymConfidential.framework
  5. SymDaemon.framework
  6. SymFirewall.framework
  7. SymIPS.framework
  8. SymLicensing.framework
  9. SymPersonalFirewall.framework
  10. SymSharedSettings.framework
  11. SymSubmission.framework
  12. SymUIAgent.framework


/Library/PrivilegedHelperTools:


/Library/QuickLook:

  1. GBQLGenerator.qlgenerator
  2. ParallelsQL.qlgenerator
  3. iBooksAuthor.qlgenerator
  4. iWork.qlgenerator


/Library/QuickTime:

AppleIntermediateCodec.component

AppleMPEG2Codec.component

Flip4Mac WMV Advanced.component

Flip4Mac WMV Export.component

Flip4Mac WMV Import.component


/Library/ScriptingAdditions:

Adobe Unit Types.osax

LCC Scroll Enhancer Loader.osax


/Library/Spotlight:

GBSpotlightImporter.mdimporter

Microsoft Office.mdimporter

  1. ParallelsMD.mdimporter
  2. iBooksAuthor.mdimporter
  3. iWork.mdimporter


/Library/StartupItems:


/etc/mach_init.d:


/etc/mach_init_per_login_session.d:


/etc/mach_init_per_user.d:


Library/Address Book Plug-Ins:

  1. SkypeABDialer.bundle
  2. SkypeABSMS.bundle


Library/Fonts:

GoodDog.otf

Linny's Stickfont.ttf

handsean.ttf


Library/Frameworks:

EWSMac.framework


Library/Input Methods:

.localized


Library/Internet Plug-Ins:

Move-Media-Player.plugin

Picasa.plugin


Library/Keyboard Layouts:


Library/LaunchAgents:

  1. com.adobe.ARM.925793fb327152fd34795896fa1fb9ffa268b2a852256fe56609efa3.plist
  2. com.apple.AddressBook.ScheduledSync.PHXCardDAVSource.BF5D5583-92FE-4192-8E8E-F7B AF6CF26C8.plist


Library/PreferencePanes:

Perian.prefPane


Library/QuickTime:

AC3MovieImport.component

Perian.component


Library/Services:

GraphicConverter.service

*********************

osascript -e 'tell application "System Events" to get name of every login item' 2> /dev/null


*********************

Finding a keylogger on my macbook pro computer

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.