Apple Intelligence is now available on iPhone, iPad, and Mac!

📢 Newsroom Update

Apple’s new MacBook Pro features the incredibly powerful M4 family of chips and ushers in a new era with Apple Intelligence. Learn more >

📢 Newsroom Update

Apple introduces M4 Pro and M4 Max. Learn more >

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

I may have a key logger in my software...review my terminal please!

I found a recent question where someone showed step by step instructions to find the key logger, I followed through and got this.

Please and thank you!


Last login: Fri Jan 13 20:21:52 on console

Jenahs-MacBook-Pro:~ jenahsmith$ kextstat -kl | awk '!/com\.apple/{printf "%s %s\n", $6, $7}'

Jenahs-MacBook-Pro:~ jenahsmith$ sudo launchctl list | sed 1d | awk '!/0x|com\.(apple|openssh|vix)|edu\.mit|org\.(amavis|apache|cups|isc|ntp|postfi x|x)/{print $3}'

Password:

com.DesignScience.DSMTTool

com.pref.net-preferences

com.adobe.ARMDC.Communicator

0646WatdlyCv5T

com.oracle.java.Helper-Tool

com.wacom.displayhelper

com.adobe.fpsaud

com.adobe.ARMDC.SMJobBlessHelper

com.wacom.TabletHelper

Jenahs-MacBook-Pro:~ jenahsmith$ launchctl list | sed 1d | awk '!/0x|com\.apple|edu\.mit|org\.(x|openbsd)/{print $3}'

com.akamai.single-user-client

com.reviversoft.MacReviver.LicenseChecker

Manroling.update

com.bittorrent.uTorrent

com.openssh.ssh-agent

com.wacom.wacomtablet

Swissfist.ltvbit

com.valvesoftware.steamclean

com.applicationstats.AppStats

com.jdibackup.ZipCloud.autostart

com.adobe.ARMDCHelper.cc24aef4a1b90ed56a725c38014c95072f92651fb65e1bf9c8e43c37a2 3d420d

Swissfist.AppRemoval

com.appart.AppArt

Swissfist.download

com.oracle.java.Java-Updater

Listchack.AppRemoval

Swissfist.update

com.jdibackup.ZipCloud.notify

Leperdvil.AppRemoval

com.skype.skype.21144

Smokyashan.update

Jenahs-MacBook-Pro:~ jenahsmith$ ls -1A /e*/mach* {,/}L*/{Ad,Compon,Ex,Fram,In,Keyb,La,Mail/Bu,P*P,Priv,Qu,Scripti,Servi,Spo,Sta} * L*/Fonts 2> /dev/null

/Library/Components:


/Library/Extensions:

ACS6x.kext

ATTOCelerityFC8.kext

ATTOExpressSASHBA2.kext

ATTOExpressSASRAID2.kext

ArcMSR.kext

CalDigitHDProDrv.kext

EPSONUSBPrintClass.kext

FTDIKext.kext

HighPointIOP.kext

HighPointRR.kext

PromiseSTEX.kext

SiLabsUSBDriver64.kext

SoftRAID.kext

Wacom Tablet.kext

hp_io_enabler_compound.kext


/Library/Frameworks:

AEProfiling.framework

AERegistration.framework

AudioMixEngine.framework

DivXInstallerUtilities.framework

MT6Lib.framework

NyxAudioAnalysis.framework

PluginManager.framework

WacomMultiTouch.framework

iTunesLibrary.framework


/Library/Input Methods:


/Library/Internet Plug-Ins:

AdobePDFViewer.plugin

AdobePDFViewerNPAPI.plugin

Disabled Plug-Ins

Flash Player.plugin

JavaAppletPlugin.plugin

PepperFlashPlayer

Quartz Composer.webplugin

Silverlight.plugin

Unused

WacomTabletPlugin.plugin

flashplayer.xpt


/Library/Keyboard Layouts:


/Library/LaunchAgents:

com.adobe.ARMDCHelper.cc24aef4a1b90ed56a725c38014c95072f92651fb65e1bf9c8e43c37a2 3d420d.plist

com.oracle.java.Java-Updater.plist

com.wacom.wacomtablet.plist


/Library/LaunchDaemons:

0646WatdlyCv5T.plist

com.DesignScience.DSMTTool.plist

com.adobe.ARMDC.Communicator.plist

com.adobe.ARMDC.SMJobBlessHelper.plist

com.adobe.fpsaud.plist

com.limited.net-preferences.plist

com.oracle.java.Helper-Tool.plist

com.phytophenologicalUpd.plist

com.wacom.TabletHelper.plist

com.wacom.displayhelper.plist


/Library/PreferencePanes:

Flash Player.prefPane

JavaControlPanel.prefPane

WacomTablet.prefpane


/Library/PrivilegedHelperTools:

com.DesignScience.DSMTTool

com.adobe.ARMDC.Communicator

com.adobe.ARMDC.SMJobBlessHelper

com.wacom.TabletHelper.app


/Library/QuickLook:

iBooksAuthor.qlgenerator

iWork.qlgenerator


/Library/QuickTime:

AppleIntermediateCodec.component

AppleMPEG2Codec.component


/Library/ScriptingAdditions:


/Library/Spotlight:

Microsoft Office.mdimporter

iBooksAuthor.mdimporter

iWork.mdimporter


/Library/StartupItems:


/etc/mach_init.d:


/etc/mach_init_per_login_session.d:


/etc/mach_init_per_user.d:


Library/Address Book Plug-Ins:

SkypeABCaller.bundle

SkypeABChatter.bundle

SkypeABDialer.bundle

SkypeABSMS.bundle


Library/Fonts:

215000E.ttf

A Box For 2.ttf

A Box For 3.ttf

A Box For.ttf

AlexBrush-Regular.ttf

Always In My Heart.ttf

BLESD___.otf

Copy 003.ttf

Elletniin.ttf

Freakshow.ttf

GreatVibes-Regular.ttf

KGFaithHopeAndLove.ttf

Liima, paperi, sakset2.ttf

Mustasurma.ttf

NastyMSG.ttf

NastyMSG2.ttf

Phorssa.ttf

SKHipsters.ttf

What is this - some kind of joke.ttf

ransom.ttf


Library/Input Methods:

.localized


Library/Internet Plug-Ins:

.DS_Store

CitrixOnlineWebDeploymentPlugin.plugin


Library/Keyboard:

de-dynamic.lm

en-dynamic.lm

es-dynamic.lm

fr-dynamic.lm

it-dynamic.lm

langlikelihood.dat

langlikelihood.dat-shm

langlikelihood.dat-wal


Library/Keyboard Layouts:


Library/KeyboardServices:

TextReplacements.db

TextReplacements.db-shm

TextReplacements.db-wal


Library/LanguageModeling:

da-dynamic.lm

de-dynamic.lm

en-dynamic.lm

es-dynamic.lm

fi-dynamic.lm

fr-dynamic.lm

it-dynamic.lm

nb-dynamic.lm

nl-dynamic.lm

pl-dynamic.lm

pt-dynamic.lm

sv-dynamic.lm

tr-dynamic.lm


Library/LaunchAgents:

.DS_Store

Leperdvil.AppRemoval.plist

Listchack.AppRemoval.plist

Manroling.update.plist

Smokyashan.update.plist

Swissfist.AppVemoral.plist

Swissfist.btvlit.plist

Swissfist.dolnwoad.plist

Swissfist.uadpte.plist

com.akamai.single-user-client.plist

com.appart.AppArt.plist

com.applicationstats.AppStats.plist

com.bittorrent.uTorrent.plist

com.jdibackup.ZipCloud.autostart.plist

com.jdibackup.ZipCloud.notify.plist

com.reviversoft.MacReviver.LicenseChecker.plist

com.valvesoftware.steamclean.plist


Library/PreferencePanes:

AkamaiNetSession.prefPane


Library/Services:

.localized

Jenahs-MacBook-Pro:~ jenahsmith$ osascript -e 'tell application "System Events" to get name of every login item' 2> /dev/null

iTunesHelper, uTorrent, Google Drive, Messages, MacReviver

Jenahs-MacBook-Pro:~ jenahsmith$

MacBook Pro (Retina, 13-inch, Late 2012), iOS 10.1.1

Posted on Jan 22, 2017 2:46 PM

Reply
8 replies

Jan 22, 2017 4:11 PM in response to joeqyna

I understand. A keylogger is a very specific thing though, and if the Mac has constantly remained under your sole control and in your physical possession there is little reason to suspect one may have been installed.


Although software with the ability to log keystrokes as well as generally observe user input (including the ability to periodically take pictures using a Mac's FaceTime camera and listening with its microphone) can certainly be used with malicious intent, the products themselves have legitimate purposes. Someone with Administrator privileges for that Mac, or someone with direct physical access to it would have had to install such a product deliberately. Although it is possible to identify the presence of those known products, it is literally impossible to determine their absence. Therefore it's a waste of time to use any product or utility to provide that assurance.


Nevertheless, if you have reason to believe your personal information is being harvested by something installed on your Mac without your knowledge or consent, the only remedy is to erase it completely and restore its contents from sources known to be reliable. As I wrote there is a variety of notorious garbage installed on that Mac. Most likely, you were deceived into installing it. To learn how not to do that please read How to install adware.

Jan 22, 2017 3:06 PM in response to joeqyna

Who knows what all you have on your Mac. Swissfist is bad enough on its own. MacReviver sure isn't helping. Every single app that claims to clean or speed up your Mac do more damage than good. Never install such software. That includes MacKeeper, CleanMyMac, or anything that even smells similar.


Given that you also run a torrent, I'd suspect you've downloaded and installed numerous illegal software packages. Torrents are the number one way to get not just adware and assorted malware installed without your knowledge, it's also where the worst of it comes from. That illegal cracked copy of Photoshop? Very likely to also install malware you don't know is built into the hacked installer. You may not have installed any known illegal software items, but torrents simply shouldn't be trusted for any software.


I personally wouldn't waste the time trying to fix this Mac. Backup your personal data such as photos, email, etc. Then boot into Recovery Mode, erase the drive and reinstall the OS. After that, manually bring back your personal data and install only legally obtained third party software.

Jan 23, 2017 4:37 AM in response to joeqyna

As has been pointed out, you have quite a lot of adware and PUPs (potentially unwanted programs) installed.


However, those instructions you followed are old, not very good and inadequate for identifying whether you have a keylogger installed. Malwarebytes Anti-Malware for Mac will remove all the junk you have installed, and also detects both malware keyloggers and "legit" keyloggers. (Personally, I don't believe there's such a thing as a "legit" keylogger, but some people believe it's a good idea to install them to spy on their children or, through twisted reasoning I've never understood, with the belief that having a keylogger provides some kind of "backup.")


What makes you think that you may have a keylogger installed?

Feb 7, 2017 7:50 AM in response to AwosoftTech

AwosoftTech wrote:


I can't find a keylogger in your terminal logs. i know some keyloggers like aobo keylogger/amac keylogger will hide itself from the terminal, so it is not possible to find it from the terminal logs.


That's not at all true. Both of those keyloggers are easily identified from the Terminal by those who know what to look for, and where to look for it. Neither of those is present in this case.

I may have a key logger in my software...review my terminal please!

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.