Spyware on my MacBook? Please Help
Hey all,
I have reasonable suspicion to believe that spyware/keylogger were installed on my MacBook I have followed the guide of I believe that I have a keylogger or some sort of spyware installed on my mac, please help!
Here are my results:
After output 1:
~ Shery$ kextstat -kl | awk '!/com\.apple/{printf "%s %s\n", $6, $7}'
com.avg.Antivirus.OnAccess.kext (2016.0)
After output 2:
Shery$ sudo launchctl list | sed 1d | awk '!/0x|com\.(apple|openssh|vix)|edu\.mit|org\.(amavis|apache|cups|isc|ntp|postfi x|x)/{print $3}'
Password:
- com.microsoft.office.licensing.helper
- com.avg.Antivirus
- com.avg.Antivirus.crashpad
- com.microsoft.office.licensingV2.helper
- com.avg.Antivirus.infosd
- com.disc-soft.DAEMONTools.PrivilegedHelper
- com.adobe.fpsaud
- com.microsoft.autoupdate.helper
After output 3:
Shery$ sudo launchctl list | sed 1d | awk '!/0x|com\.(apple|openssh|vix)|edu\.mit|org\.(amavis|apache|cups|isc|ntp|postfi x|x)/{print $3}'
Password:
- com.microsoft.office.licensing.helper
- com.avg.Antivirus
- com.avg.Antivirus.crashpad
- com.microsoft.office.licensingV2.helper
- com.avg.Antivirus.infosd
- com.disc-soft.DAEMONTools.PrivilegedHelper
- com.adobe.fpsaud
- com.microsoft.autoupdate.helper
Muhammads-MacBook-Pro:~ Shery$ launchctl list | sed 1d | awk '!/0x|com\.apple|edu\.mit|org\.(x|openbsd)/{print $3}'
- com.dropbox.DropboxMacUpdate.agent.install.1407489442
- com.microsoft.Word.5620
- com.microsoft.Office365ServiceV2.1544
- com.bittorrent.uTorrent
- com.openssh.ssh-agent
- com.canon.MFManager
- com.simplexsolutionsinc.vpnguardhelperMac
- com.avg.Antivirus
- com.simplexsolutionsinc.vpnguardMac.6312
- com.rosettastone.rosettastonedaemon
- com.canon.SLRuntimeLoader.1424
- com.microsoft.autoupdate.fba.4164
- com.google.keystone.user.agent
- com.spigot.ApplicationManager
- com.dropbox.DropboxMacUpdate.agent
After output 4:
~ Shery$ ls -1A /e*/mach* {,/}L*/{Ad,Compon,Ex,Fram,In,Keyb,La,Mail/Bu,P*P,Priv,Qu,Scripti,Servi,Spo,Sta} * L*/Fonts 2> /dev/null
/Library/Components:
/Library/Extensions:
ACS6x.kext
ATTOCelerityFC8.kext
ATTOExpressSASHBA2.kext
ATTOExpressSASRAID2.kext
- ArcMSR.kext
- BJUSBLoad.kext
- CIJUSBLoad.kext
- CalDigitHDProDrv.kext
- HighPointIOP.kext
- HighPointRR.kext
- PromiseSTEX.kext
- SoftRAID.kext
/Library/Frameworks:
- AEProfiling.framework
- AERegistration.framework
- AudioMixEngine.framework
- NyxAudioAnalysis.framework
- PluginManager.framework
- iTunesLibrary.framework
/Library/Input Methods:
/Library/Internet Plug-Ins:
Disabled Plug-Ins
Flash Player.plugin
Quartz Composer.webplugin
- SharePointBrowserPlugin.plugin
- SharePointWebKitPlugin.webplugin
- Silverlight.plugin
- flashplayer.xpt
/Library/Keyboard Layouts:
/Library/LaunchAgents:
- com.avg.Antivirus.gui.plist
- com.canon.MFManager.plist
- com.rosettastone.rosettastonedaemon.plist
/Library/LaunchDaemons:
- com.adobe.fpsaud.plist
- com.avg.Antivirus.crashpad.plist
- com.avg.Antivirus.infosd.plist
- com.avg.Antivirus.services.plist
- com.disc-soft.DAEMONTools.PrivilegedHelper.plist
- com.microsoft.autoupdate.helper.plist
- com.microsoft.office.licensing.helper.plist
- com.microsoft.office.licensingV2.helper.plist
/Library/PreferencePanes:
Flash Player.prefPane
/Library/PrivilegedHelperTools:
- com.disc-soft.DAEMONTools.PrivilegedHelper
- com.microsoft.autoupdate.helper
- com.microsoft.office.licensing.helper
- com.microsoft.office.licensingV2.helper
/Library/QuickLook:
- iBooksAuthor.qlgenerator
- iWork.qlgenerator
/Library/QuickTime:
AppleIntermediateCodec.component
AppleMPEG2Codec.component
/Library/ScriptingAdditions:
/Library/Spotlight:
Microsoft Office.mdimporter
- iBooksAuthor.mdimporter
- iWork.mdimporter
/Library/StartupItems:
/etc/mach_init.d:
/etc/mach_init_per_login_session.d:
/etc/mach_init_per_user.d:
Library/Address Book Plug-Ins:
- SkypeABCaller.bundle
- SkypeABChatter.bundle
- SkypeABDialer.bundle
- SkypeABSMS.bundle
Library/Fonts:
Managed
Library/Input Methods:
.localized
Library/Internet Plug-Ins:
SkypePlugin-7.29.0.72.bundle
Library/Keyboard:
en-dynamic.lm
fr-dynamic.lm
Library/Keyboard Layouts:
Library/KeyboardServices:
- TextReplacements.db
- TextReplacements.db-shm
- TextReplacements.db-wal
Library/LanguageModeling:
da-dynamic.lm
de-dynamic.lm
en-dynamic.lm
es-dynamic.lm
fi-dynamic.lm
fr-dynamic.lm
it-dynamic.lm
nb-dynamic.lm
nl-dynamic.lm
pl-dynamic.lm
pt-dynamic.lm
ru-dynamic.lm
sv-dynamic.lm
tr-dynamic.lm
Library/LaunchAgents:
- com.bittorrent.uTorrent.plist
- com.dropbox.DropboxMacUpdate.agent.plist
- com.google.keystone.agent.plist
- com.spigot.ApplicationManager.plist
Library/PreferencePanes:
Library/Services:
After output 5:
~ Shery$ osascript -e 'tell application "System Events" to get name of every login item' 2> /dev/null
iTunesHelper, Dropbox
Please help