Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

how to remove keylogger/spyware from my mac

i believe that my mac is being keylogged or some other type of spyware is present , how can i get rid of this spyware?

Posted on Jul 5, 2015 12:45 PM

Reply
Question marked as Best reply

Posted on Jul 5, 2015 12:47 PM

Mshawaizs-MacBook-Pro:~ khan$ kextstat -kl | awk '!/com\.apple/{printf "%s %s\n", $6, $7}'

com.globaldelight.driver.BoomDevice (1.3)

com.sophos.nke.swi (9.2.50)

com.sophos.kext.sav (9.2.50)

Mshawaizs-MacBook-Pro:~ khan$ sudo launchctl list | sed 1d | awk '!/0x|com\.(apple|openssh|vix)|edu\.mit|org\.(amavis|apache|cups|isc|ntp|postfi x|x)/{print $3}'




Password:

com.vsearch.helper

com.vsearch.daemon

com.raynersw.nshctldo

com.google.keystone.daemon

com.raynersw.nshfixer

com.adobe.SwitchBoard

com.adobe.fpsaud

com.teamviewer.Helper

Mshawaizs-MacBook-Pro:~ khan$ launchctl list | sed 1d | awk '!/0x|com\.apple|edu\.mit|org\.(x|openbsd)/{print $3}'

com.BT.PKL

com.jdibackup.JustCloud.signup

com.macpaw.CleanMyMac2Helper.diskSpaceWatcher

com.google.keystone.system.agent

com.macpaw.CleanMyMac2.39224

com.bittorrent.uTorrent.48028

com.macpaw.CleanMyMac-2-Helper.61376

com.valvesoftware.steamclean

com.jdibackup.JustCloud.autostart

com.valvesoftware.steam.ipctool

org.mozilla.firefox.38940

com.macpaw.CleanMyMac2Helper.trashWatcher

com.adobe.AAM.Scheduler-1.0

com.macpaw.CleanMyMac2Helper.scheduledScan

com.macpaw.CleanMyMac-2-Helper.12244

com.vsearch.agent

Mshawaizs-MacBook-Pro:~ khan$ ls -1A /e*/mach* {,/}L*/{Ad,Compon,Ex,Fram,In,Keyb,La,Mail/Bu,P*P,Priv,Qu,Scripti,Servi,Spo,Sta} * L*/Fonts 2> /dev/null

/Library/Components:


/Library/Extensions:

ACS6x.kext

ATTOCelerityFC8.kext

ATTOExpressSASHBA2.kext

ATTOExpressSASRAID2.kext

ArcMSR.kext

BoomDevice.kext

CalDigitHDProDrv.kext

HighPointIOP.kext

HighPointRR.kext

PromiseSTEX.kext

SoftRAID.kext

tap.kext

tun.kext


/Library/Frameworks:

AEProfiling.framework

AERegistration.framework

AudioMixEngine.framework

NyxAudioAnalysis.framework

PluginManager.framework

iTunesLibrary.framework


/Library/Input Methods:


/Library/Internet Plug-Ins:

Default Browser.plugin

Flash Player.plugin

JavaAppletPlugin.plugin

Quartz Composer.webplugin

QuickTime Plugin.plugin

Unity Web Player.plugin

Unused

flashplayer.xpt

googletalkbrowserplugin.plugin

nsIQTScriptablePlugin.xpt


/Library/Keyboard Layouts:


/Library/LaunchAgents:

com.adobe.AAM.Updater-1.0.plist

com.google.keystone.agent.plist


/Library/LaunchDaemons:

com.adobe.SwitchBoard.plist

com.adobe.fpsaud.plist

com.google.keystone.daemon.plist

com.macpaw.CleanMyMac2.Agent.plist

com.raynersw.nshctldo.plist

com.raynersw.nshfixer.plist

com.teamviewer.Helper.plist


/Library/PreferencePanes:

Flash Player.prefPane


/Library/PrivilegedHelperTools:

com.macpaw.CleanMyMac2.Agent

com.raynersw.nshctldo

com.raynersw.nshfixer

com.teamviewer.Helper


/Library/QuickLook:

iBooksAuthor.qlgenerator

iWork.qlgenerator


/Library/QuickTime:

AppleIntermediateCodec.component

AppleMPEG2Codec.component


/Library/ScriptingAdditions:

Adobe Unit Types.osax


/Library/Spotlight:

Microsoft Office.mdimporter

iBooksAuthor.mdimporter

iWork.mdimporter


/Library/StartupItems:


/etc/mach_init.d:


/etc/mach_init_per_login_session.d:


/etc/mach_init_per_user.d:


Library/Address Book Plug-Ins:


Library/Fonts:


Library/Input Methods:

.localized


Library/Internet Plug-Ins:

ConduitNPAPIPlugin.plugin


Library/Keyboard Layouts:


Library/LanguageModeling:

de-dynamic.lm

en-dynamic.lm

es-dynamic.lm

fr-dynamic.lm

it-dynamic.lm

nl-dynamic.lm

pt-dynamic.lm

sv-dynamic.lm

tr-dynamic.lm


Library/LaunchAgents:

com.BT.PKL.plist

com.adobe.AAM.Updater-1.0.plist

com.jdibackup.JustCloud.autostart.plist

com.jdibackup.JustCloud.signup.plist

com.macpaw.CleanMyMac2Helper.diskSpaceWatcher.plist

com.macpaw.CleanMyMac2Helper.scheduledScan.plist

com.macpaw.CleanMyMac2Helper.trashWatcher.plist

com.valvesoftware.steamclean.plist


Library/PreferencePanes:


Library/Services:

Mshawaizs-MacBook-Pro:~ khan$ osascript -e 'tell application "System Events" to get name of every login item' 2> /dev/null

Steam, iTunesHelper, iTunes

Mshawaizs-MacBook-Pro:~ khan$

3 replies
Question marked as Best reply

Jul 5, 2015 12:47 PM in response to khanMan62

Mshawaizs-MacBook-Pro:~ khan$ kextstat -kl | awk '!/com\.apple/{printf "%s %s\n", $6, $7}'

com.globaldelight.driver.BoomDevice (1.3)

com.sophos.nke.swi (9.2.50)

com.sophos.kext.sav (9.2.50)

Mshawaizs-MacBook-Pro:~ khan$ sudo launchctl list | sed 1d | awk '!/0x|com\.(apple|openssh|vix)|edu\.mit|org\.(amavis|apache|cups|isc|ntp|postfi x|x)/{print $3}'




Password:

com.vsearch.helper

com.vsearch.daemon

com.raynersw.nshctldo

com.google.keystone.daemon

com.raynersw.nshfixer

com.adobe.SwitchBoard

com.adobe.fpsaud

com.teamviewer.Helper

Mshawaizs-MacBook-Pro:~ khan$ launchctl list | sed 1d | awk '!/0x|com\.apple|edu\.mit|org\.(x|openbsd)/{print $3}'

com.BT.PKL

com.jdibackup.JustCloud.signup

com.macpaw.CleanMyMac2Helper.diskSpaceWatcher

com.google.keystone.system.agent

com.macpaw.CleanMyMac2.39224

com.bittorrent.uTorrent.48028

com.macpaw.CleanMyMac-2-Helper.61376

com.valvesoftware.steamclean

com.jdibackup.JustCloud.autostart

com.valvesoftware.steam.ipctool

org.mozilla.firefox.38940

com.macpaw.CleanMyMac2Helper.trashWatcher

com.adobe.AAM.Scheduler-1.0

com.macpaw.CleanMyMac2Helper.scheduledScan

com.macpaw.CleanMyMac-2-Helper.12244

com.vsearch.agent

Mshawaizs-MacBook-Pro:~ khan$ ls -1A /e*/mach* {,/}L*/{Ad,Compon,Ex,Fram,In,Keyb,La,Mail/Bu,P*P,Priv,Qu,Scripti,Servi,Spo,Sta} * L*/Fonts 2> /dev/null

/Library/Components:


/Library/Extensions:

ACS6x.kext

ATTOCelerityFC8.kext

ATTOExpressSASHBA2.kext

ATTOExpressSASRAID2.kext

ArcMSR.kext

BoomDevice.kext

CalDigitHDProDrv.kext

HighPointIOP.kext

HighPointRR.kext

PromiseSTEX.kext

SoftRAID.kext

tap.kext

tun.kext


/Library/Frameworks:

AEProfiling.framework

AERegistration.framework

AudioMixEngine.framework

NyxAudioAnalysis.framework

PluginManager.framework

iTunesLibrary.framework


/Library/Input Methods:


/Library/Internet Plug-Ins:

Default Browser.plugin

Flash Player.plugin

JavaAppletPlugin.plugin

Quartz Composer.webplugin

QuickTime Plugin.plugin

Unity Web Player.plugin

Unused

flashplayer.xpt

googletalkbrowserplugin.plugin

nsIQTScriptablePlugin.xpt


/Library/Keyboard Layouts:


/Library/LaunchAgents:

com.adobe.AAM.Updater-1.0.plist

com.google.keystone.agent.plist


/Library/LaunchDaemons:

com.adobe.SwitchBoard.plist

com.adobe.fpsaud.plist

com.google.keystone.daemon.plist

com.macpaw.CleanMyMac2.Agent.plist

com.raynersw.nshctldo.plist

com.raynersw.nshfixer.plist

com.teamviewer.Helper.plist


/Library/PreferencePanes:

Flash Player.prefPane


/Library/PrivilegedHelperTools:

com.macpaw.CleanMyMac2.Agent

com.raynersw.nshctldo

com.raynersw.nshfixer

com.teamviewer.Helper


/Library/QuickLook:

iBooksAuthor.qlgenerator

iWork.qlgenerator


/Library/QuickTime:

AppleIntermediateCodec.component

AppleMPEG2Codec.component


/Library/ScriptingAdditions:

Adobe Unit Types.osax


/Library/Spotlight:

Microsoft Office.mdimporter

iBooksAuthor.mdimporter

iWork.mdimporter


/Library/StartupItems:


/etc/mach_init.d:


/etc/mach_init_per_login_session.d:


/etc/mach_init_per_user.d:


Library/Address Book Plug-Ins:


Library/Fonts:


Library/Input Methods:

.localized


Library/Internet Plug-Ins:

ConduitNPAPIPlugin.plugin


Library/Keyboard Layouts:


Library/LanguageModeling:

de-dynamic.lm

en-dynamic.lm

es-dynamic.lm

fr-dynamic.lm

it-dynamic.lm

nl-dynamic.lm

pt-dynamic.lm

sv-dynamic.lm

tr-dynamic.lm


Library/LaunchAgents:

com.BT.PKL.plist

com.adobe.AAM.Updater-1.0.plist

com.jdibackup.JustCloud.autostart.plist

com.jdibackup.JustCloud.signup.plist

com.macpaw.CleanMyMac2Helper.diskSpaceWatcher.plist

com.macpaw.CleanMyMac2Helper.scheduledScan.plist

com.macpaw.CleanMyMac2Helper.trashWatcher.plist

com.valvesoftware.steamclean.plist


Library/PreferencePanes:


Library/Services:

Mshawaizs-MacBook-Pro:~ khan$ osascript -e 'tell application "System Events" to get name of every login item' 2> /dev/null

Steam, iTunesHelper, iTunes

Mshawaizs-MacBook-Pro:~ khan$

Jul 8, 2015 8:48 AM in response to khanMan62

There's a lot of adware and crapware (such as CleanMyMac, JustCloud and µTorrent) installed. However, the bigger issue is that you have the keyloggers installed. Someone would have to have installed them, or tricked you into running some kind of custom script or app that would have installed them. Most likely, the former is true.


If you don't know how those got there, and this is your computer (not a company computer, school computer, etc), then you need to erase your hard drive immediately and reinstall everything from scratch, then restore only documents from backup. For instructions, see:


How to reinstall Mac OS X from scratch


Be aware that there may be other things that have been done, so don't assume that removing those two keyloggers will be sufficient. Also be aware that there's no anti-virus software that can detect all possible malicious changes that a hacker with access to the computer might have made. So, yes, although it's unpleasant, erasing really is the only solution.


Also, be aware that the presence of a keylogger means that anything you may have typed should be considered compromised. This includes things like passwords and credit card numbers, but could include any number of other things as well, such as bank account numbers or social security number. You will need to change ALL your passwords (after cleaning the machine), alert your credit card companies and any other financial institutions, and consider subscribing to a credit monitoring service.


If this is not a computer that is on loan to you from somewhere, like your place of work or school, then the fact that they would be willing to log all your keystrokes should be greatly concerning, and you should not do ANYTHING on that computer that you're not willing for them to monitor.


(Fair disclosure: I may receive compensation from links to my sites, TheSafeMac.com and AdwareMedic.com.)

how to remove keylogger/spyware from my mac

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.