how to remove keylogger/spyware from my mac
i believe that my mac is being keylogged or some other type of spyware is present , how can i get rid of this spyware?
i believe that my mac is being keylogged or some other type of spyware is present , how can i get rid of this spyware?
Mshawaizs-MacBook-Pro:~ khan$ kextstat -kl | awk '!/com\.apple/{printf "%s %s\n", $6, $7}'
com.globaldelight.driver.BoomDevice (1.3)
com.sophos.nke.swi (9.2.50)
com.sophos.kext.sav (9.2.50)
Mshawaizs-MacBook-Pro:~ khan$ sudo launchctl list | sed 1d | awk '!/0x|com\.(apple|openssh|vix)|edu\.mit|org\.(amavis|apache|cups|isc|ntp|postfi x|x)/{print $3}'
Password:
com.vsearch.helper
com.vsearch.daemon
com.raynersw.nshctldo
com.google.keystone.daemon
com.raynersw.nshfixer
com.adobe.SwitchBoard
com.adobe.fpsaud
com.teamviewer.Helper
Mshawaizs-MacBook-Pro:~ khan$ launchctl list | sed 1d | awk '!/0x|com\.apple|edu\.mit|org\.(x|openbsd)/{print $3}'
com.BT.PKL
com.jdibackup.JustCloud.signup
com.macpaw.CleanMyMac2Helper.diskSpaceWatcher
com.google.keystone.system.agent
com.macpaw.CleanMyMac2.39224
com.bittorrent.uTorrent.48028
com.macpaw.CleanMyMac-2-Helper.61376
com.valvesoftware.steamclean
com.jdibackup.JustCloud.autostart
com.valvesoftware.steam.ipctool
org.mozilla.firefox.38940
com.macpaw.CleanMyMac2Helper.trashWatcher
com.adobe.AAM.Scheduler-1.0
com.macpaw.CleanMyMac2Helper.scheduledScan
com.macpaw.CleanMyMac-2-Helper.12244
com.vsearch.agent
Mshawaizs-MacBook-Pro:~ khan$ ls -1A /e*/mach* {,/}L*/{Ad,Compon,Ex,Fram,In,Keyb,La,Mail/Bu,P*P,Priv,Qu,Scripti,Servi,Spo,Sta} * L*/Fonts 2> /dev/null
/Library/Components:
/Library/Extensions:
ACS6x.kext
ATTOCelerityFC8.kext
ATTOExpressSASHBA2.kext
ATTOExpressSASRAID2.kext
ArcMSR.kext
BoomDevice.kext
CalDigitHDProDrv.kext
HighPointIOP.kext
HighPointRR.kext
PromiseSTEX.kext
SoftRAID.kext
tap.kext
tun.kext
/Library/Frameworks:
AEProfiling.framework
AERegistration.framework
AudioMixEngine.framework
NyxAudioAnalysis.framework
PluginManager.framework
iTunesLibrary.framework
/Library/Input Methods:
/Library/Internet Plug-Ins:
Default Browser.plugin
Flash Player.plugin
JavaAppletPlugin.plugin
Quartz Composer.webplugin
QuickTime Plugin.plugin
Unity Web Player.plugin
Unused
flashplayer.xpt
googletalkbrowserplugin.plugin
nsIQTScriptablePlugin.xpt
/Library/Keyboard Layouts:
/Library/LaunchAgents:
com.adobe.AAM.Updater-1.0.plist
com.google.keystone.agent.plist
/Library/LaunchDaemons:
com.adobe.SwitchBoard.plist
com.adobe.fpsaud.plist
com.google.keystone.daemon.plist
com.macpaw.CleanMyMac2.Agent.plist
com.raynersw.nshctldo.plist
com.raynersw.nshfixer.plist
com.teamviewer.Helper.plist
/Library/PreferencePanes:
Flash Player.prefPane
/Library/PrivilegedHelperTools:
com.macpaw.CleanMyMac2.Agent
com.raynersw.nshctldo
com.raynersw.nshfixer
com.teamviewer.Helper
/Library/QuickLook:
iBooksAuthor.qlgenerator
iWork.qlgenerator
/Library/QuickTime:
AppleIntermediateCodec.component
AppleMPEG2Codec.component
/Library/ScriptingAdditions:
Adobe Unit Types.osax
/Library/Spotlight:
Microsoft Office.mdimporter
iBooksAuthor.mdimporter
iWork.mdimporter
/Library/StartupItems:
/etc/mach_init.d:
/etc/mach_init_per_login_session.d:
/etc/mach_init_per_user.d:
Library/Address Book Plug-Ins:
Library/Fonts:
Library/Input Methods:
.localized
Library/Internet Plug-Ins:
ConduitNPAPIPlugin.plugin
Library/Keyboard Layouts:
Library/LanguageModeling:
de-dynamic.lm
en-dynamic.lm
es-dynamic.lm
fr-dynamic.lm
it-dynamic.lm
nl-dynamic.lm
pt-dynamic.lm
sv-dynamic.lm
tr-dynamic.lm
Library/LaunchAgents:
com.BT.PKL.plist
com.adobe.AAM.Updater-1.0.plist
com.jdibackup.JustCloud.autostart.plist
com.jdibackup.JustCloud.signup.plist
com.macpaw.CleanMyMac2Helper.diskSpaceWatcher.plist
com.macpaw.CleanMyMac2Helper.scheduledScan.plist
com.macpaw.CleanMyMac2Helper.trashWatcher.plist
com.valvesoftware.steamclean.plist
Library/PreferencePanes:
Library/Services:
Mshawaizs-MacBook-Pro:~ khan$ osascript -e 'tell application "System Events" to get name of every login item' 2> /dev/null
Steam, iTunesHelper, iTunes
Mshawaizs-MacBook-Pro:~ khan$
Mshawaizs-MacBook-Pro:~ khan$ kextstat -kl | awk '!/com\.apple/{printf "%s %s\n", $6, $7}'
com.globaldelight.driver.BoomDevice (1.3)
com.sophos.nke.swi (9.2.50)
com.sophos.kext.sav (9.2.50)
Mshawaizs-MacBook-Pro:~ khan$ sudo launchctl list | sed 1d | awk '!/0x|com\.(apple|openssh|vix)|edu\.mit|org\.(amavis|apache|cups|isc|ntp|postfi x|x)/{print $3}'
Password:
com.vsearch.helper
com.vsearch.daemon
com.raynersw.nshctldo
com.google.keystone.daemon
com.raynersw.nshfixer
com.adobe.SwitchBoard
com.adobe.fpsaud
com.teamviewer.Helper
Mshawaizs-MacBook-Pro:~ khan$ launchctl list | sed 1d | awk '!/0x|com\.apple|edu\.mit|org\.(x|openbsd)/{print $3}'
com.BT.PKL
com.jdibackup.JustCloud.signup
com.macpaw.CleanMyMac2Helper.diskSpaceWatcher
com.google.keystone.system.agent
com.macpaw.CleanMyMac2.39224
com.bittorrent.uTorrent.48028
com.macpaw.CleanMyMac-2-Helper.61376
com.valvesoftware.steamclean
com.jdibackup.JustCloud.autostart
com.valvesoftware.steam.ipctool
org.mozilla.firefox.38940
com.macpaw.CleanMyMac2Helper.trashWatcher
com.adobe.AAM.Scheduler-1.0
com.macpaw.CleanMyMac2Helper.scheduledScan
com.macpaw.CleanMyMac-2-Helper.12244
com.vsearch.agent
Mshawaizs-MacBook-Pro:~ khan$ ls -1A /e*/mach* {,/}L*/{Ad,Compon,Ex,Fram,In,Keyb,La,Mail/Bu,P*P,Priv,Qu,Scripti,Servi,Spo,Sta} * L*/Fonts 2> /dev/null
/Library/Components:
/Library/Extensions:
ACS6x.kext
ATTOCelerityFC8.kext
ATTOExpressSASHBA2.kext
ATTOExpressSASRAID2.kext
ArcMSR.kext
BoomDevice.kext
CalDigitHDProDrv.kext
HighPointIOP.kext
HighPointRR.kext
PromiseSTEX.kext
SoftRAID.kext
tap.kext
tun.kext
/Library/Frameworks:
AEProfiling.framework
AERegistration.framework
AudioMixEngine.framework
NyxAudioAnalysis.framework
PluginManager.framework
iTunesLibrary.framework
/Library/Input Methods:
/Library/Internet Plug-Ins:
Default Browser.plugin
Flash Player.plugin
JavaAppletPlugin.plugin
Quartz Composer.webplugin
QuickTime Plugin.plugin
Unity Web Player.plugin
Unused
flashplayer.xpt
googletalkbrowserplugin.plugin
nsIQTScriptablePlugin.xpt
/Library/Keyboard Layouts:
/Library/LaunchAgents:
com.adobe.AAM.Updater-1.0.plist
com.google.keystone.agent.plist
/Library/LaunchDaemons:
com.adobe.SwitchBoard.plist
com.adobe.fpsaud.plist
com.google.keystone.daemon.plist
com.macpaw.CleanMyMac2.Agent.plist
com.raynersw.nshctldo.plist
com.raynersw.nshfixer.plist
com.teamviewer.Helper.plist
/Library/PreferencePanes:
Flash Player.prefPane
/Library/PrivilegedHelperTools:
com.macpaw.CleanMyMac2.Agent
com.raynersw.nshctldo
com.raynersw.nshfixer
com.teamviewer.Helper
/Library/QuickLook:
iBooksAuthor.qlgenerator
iWork.qlgenerator
/Library/QuickTime:
AppleIntermediateCodec.component
AppleMPEG2Codec.component
/Library/ScriptingAdditions:
Adobe Unit Types.osax
/Library/Spotlight:
Microsoft Office.mdimporter
iBooksAuthor.mdimporter
iWork.mdimporter
/Library/StartupItems:
/etc/mach_init.d:
/etc/mach_init_per_login_session.d:
/etc/mach_init_per_user.d:
Library/Address Book Plug-Ins:
Library/Fonts:
Library/Input Methods:
.localized
Library/Internet Plug-Ins:
ConduitNPAPIPlugin.plugin
Library/Keyboard Layouts:
Library/LanguageModeling:
de-dynamic.lm
en-dynamic.lm
es-dynamic.lm
fr-dynamic.lm
it-dynamic.lm
nl-dynamic.lm
pt-dynamic.lm
sv-dynamic.lm
tr-dynamic.lm
Library/LaunchAgents:
com.BT.PKL.plist
com.adobe.AAM.Updater-1.0.plist
com.jdibackup.JustCloud.autostart.plist
com.jdibackup.JustCloud.signup.plist
com.macpaw.CleanMyMac2Helper.diskSpaceWatcher.plist
com.macpaw.CleanMyMac2Helper.scheduledScan.plist
com.macpaw.CleanMyMac2Helper.trashWatcher.plist
com.valvesoftware.steamclean.plist
Library/PreferencePanes:
Library/Services:
Mshawaizs-MacBook-Pro:~ khan$ osascript -e 'tell application "System Events" to get name of every login item' 2> /dev/null
Steam, iTunesHelper, iTunes
Mshawaizs-MacBook-Pro:~ khan$
There's a lot of adware and crapware (such as CleanMyMac, JustCloud and µTorrent) installed. However, the bigger issue is that you have the keyloggers installed. Someone would have to have installed them, or tricked you into running some kind of custom script or app that would have installed them. Most likely, the former is true.
If you don't know how those got there, and this is your computer (not a company computer, school computer, etc), then you need to erase your hard drive immediately and reinstall everything from scratch, then restore only documents from backup. For instructions, see:
How to reinstall Mac OS X from scratch
Be aware that there may be other things that have been done, so don't assume that removing those two keyloggers will be sufficient. Also be aware that there's no anti-virus software that can detect all possible malicious changes that a hacker with access to the computer might have made. So, yes, although it's unpleasant, erasing really is the only solution.
Also, be aware that the presence of a keylogger means that anything you may have typed should be considered compromised. This includes things like passwords and credit card numbers, but could include any number of other things as well, such as bank account numbers or social security number. You will need to change ALL your passwords (after cleaning the machine), alert your credit card companies and any other financial institutions, and consider subscribing to a credit monitoring service.
If this is not a computer that is on loan to you from somewhere, like your place of work or school, then the fact that they would be willing to log all your keystrokes should be greatly concerning, and you should not do ANYTHING on that computer that you're not willing for them to monitor.
(Fair disclosure: I may receive compensation from links to my sites, TheSafeMac.com and AdwareMedic.com.)
how to remove keylogger/spyware from my mac