Do I have unauthorized Keylogger malware on my Mac?
I was the victim of a phishing email link that I clicked on two days ago. I am concerned that the scam website I visited may have remotely placed a Keylogger program onto my personal Mac desktop.
I have run Intego, MacScan, and Malwarebytes for Mac to try to detect any Keylogger. However, I know from reading here that any Keylogger malware may elude such attempted detections.
I've followed Linc's Terminal instructions from a 2013 post below (though I had to
restart my computer in between a couple of the steps). Im hoping that Linc
or someone knowledgable in reading the results below can see if any Keylogger software is on my Mac. Any such software would be malware and unauthorized.
Note - the Admin account was used for Step 2 only (as the separate User account
is the one that is possibly infected):
com.intego.kext.VirusBarrierKPI (10.6.22)
com.intego.kext.VirusBarrier.AppBarrierKPI (10.6.22)
com.intego.iokit.VBX6NKE (1)
com.intego.iokit.VirusBarrierX6Service (10.6.22)
Password:
com.intego.VirusBarrier.antivandal.hks
com.intego.VirusBarrier.scanner.memory
com.intego.VirusBarrierX6.realtime.daemon
com.malwarebytes.MBAMHelperTool
com.intego.VirusBarrierX6.scanner.daemon
com.intego.VirusBarrierX6.daemon
com.intego.task.manager.daemon
com.intego.netupdate.daemon
com.intego.commonservices.metrics.kschecker
com.intego.commonservices.icalserver
com.intego.commonservices.daemon
com.microsoft.entourage.database_daemon.30304
com.microsoft.autoupdate.fba.36112
com.microsoft.Word.11648
jp.co.canon.cijscannerregister.24320
com.hp.scanModule3.12000.3A7A67A0-3495-4484-8A7A-FB7B337D4635
com.intego.VirusBarrierX6.alert
com.intego.task.manager.notifier
com.intego.netupdate.agent
com.intego.commonservices.statusitem
com.google.keystone.user.agent
com.adobe.ARM.202f4087f2bbde52e3ac2df389f53a4f123223c9cc56a8fd83a6f7ae
/Library/Extensions:
ATTOCelerityFC8.kext
ATTOExpressSASHBA2.kext
ATTOExpressSASRAID2.kext
ArcMSR.kext
CalDigitHDProDrv.kext
HighPointIOP.kext
HighPointRR.kext
PromiseSTEX.kext
SoftRAID.kext
hp_io_enabler_compound.kext
/Library/Frameworks:
AEProfiling.framework
AERegistration.framework
Adobe AIR.framework
AudioMixEngine.framework
EDWOCommon.framework
EDWOInternet.framework
IntegoiCalFramework.framework
NetUpdateShared.framework
NyxAudioAnalysis.framework
PluginManager.framework
TSLicense.framework
iTunesLibrary.framework
/Library/Input Methods:
/Library/Intego:
.virusbarrier_info
IM_ObjectiveMetrics.framework
IMailSenderTool
IntegoStatusItem.bundle
IntegoiCalServer
MIME.plist
TaskManager
im_helper_tool
im_ks_tool
integod
netupdated.bundle
virusbarrier.bundle
/Library/Internet Plug-Ins:
AdobePDFViewer.plugin
AdobePDFViewerNPAPI.plugin
CouponPrinter-FireFox_v2.plugin
CouponPrinter-Safari.webplugin
Default Browser.plugin
Disabled Plug-Ins
Flip4Mac WMV Plugin.plugin
JavaAppletPlugin.plugin
OfficeLiveBrowserPlugin.plugin
Quartz Composer.webplugin
Silverlight.plugin
iPhotoPhotocast.plugin
nsIQTScriptablePlugin.xpt
/Library/Keyboard Layouts:
/Library/LaunchAgents:
com.intego.VirusBarrierX6.alert.plist
com.intego.VirusBarrierX6.statusitem.plist
com.intego.commonservices.statusitem.plist
com.intego.netupdate.agent.plist
com.intego.task.manager.notifier.plist
/Library/LaunchDaemons:
com.intego.VirusBarrierX6.daemon.plist
com.intego.VirusBarrierX6.scanner.daemon.plist
com.intego.commonservices.daemon.plist
com.intego.commonservices.icalserver.plist
com.intego.commonservices.metrics.kschecker.plist
com.intego.netupdate.daemon.plist
com.intego.task.manager.daemon.plist
com.malwarebytes.MBAMHelperTool.plist
/Library/PreferencePanes:
Flip4Mac WMV.prefPane
NetUpdate.prefPane
/Library/PrivilegedHelperTools:
NetUpdateAgent.app
com.malwarebytes.MBAMHelperTool
/Library/QuickLook:
GBQLGenerator.qlgenerator
iBooksAuthor.qlgenerator
iWork.qlgenerator
/Library/QuickTime:
AppleIntermediateCodec.component
AppleMPEG2Codec.component
Flip4Mac WMV Advanced.component
Flip4Mac WMV Export.component
Flip4Mac WMV Import.component
/Library/ScriptingAdditions:
/Library/Services:
VirusBarrier X6 Service.service
/Library/Spotlight:
GBSpotlightImporter.mdimporter
Microsoft Office.mdimporter
iBooksAuthor.mdimporter
iWork.mdimporter
/Library/StartupItems:
/etc/mach_init.d:
/etc/mach_init_per_login_session.d:
/etc/mach_init_per_user.d:
Library/Address Book Plug-Ins:
SkypeABDialer.bundle
SkypeABSMS.bundle
Library/Fonts:
Library/Frameworks:
EWSMac.framework
Library/Input Methods:
.localized
Library/Internet Plug-Ins:
.DS_Store
Picasa.plugin
Library/Keyboard Layouts:
Library/LaunchAgents:
com.adobe.ARM.202f4087f2bbde52e3ac2df389f53a4f123223c9cc56a8fd83a6f7ae.plist
com.google.keystone.agent.plist
Library/PreferencePanes:
Library/Services:
.localized
TomTomMyDriveConnectHelper, MyDriveConnect
OS X Mavericks (10.9.5)