You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

What is mshelper?

Hi - I have mshelper constantly showing in CPU of Activity Monitor at super high levels. I probably wouldn't have noticed except I installed BitDefender today and it's continuously showing me that it's deleting it!


I can't find too much online about it, bu the little suggests it's malware, how do I get rid of it though!


I've tried Malware Bytes which doesn't detect anything!


Activity Monitor

Dropbox - Screenshot 2018-05-15 17.22.25.png


AntiVirus For Mac

Dropbox - Screenshot 2018-05-15 17.26.07.png


Any help would be appreciated!


I've also got CoinMiner showing up a lot and being deleted, but again keeps coming back!


https://www.dropbox.com/s/l2ieww49qcjrh4j/Screenshot%202018-05-15%2017.29.46.png ?dl=0


I can't work out how they're being found and deleted, but keep coming back soon after!!


Thanks!!

Posted on May 15, 2018 1:01 AM

Reply
Question marked as Top-ranking reply

Posted on May 15, 2018 4:30 AM

Run and post a diagnostic report.


Please run EtreCheck and post the report here.

https://etrecheck.com

Click “Free Download” button, open Downloads folder, click on it to open, and then select ”Open”.

Click on the bouncing EtreCheck icon in the Dock.

“Choose a problem” from the popup menu box, and then “Start EtreCheck” in the dialog.


Click “Share Report” button in the toolbar, select “Copy to Clipboard” .

Paste it into the reply.

Similar questions

26 replies

May 18, 2018 5:16 PM in response to softwater

softwater wrote:


Etrecheck flags everything it doesn't already know about as possible adware.

No. That is false.


Other, more responsible, software only flags something that it can positively identify as a threat as a threat.

That isn't being "more responsible". That is being standard, run-of-the-mill 3rd party anti-virus software. Ask the people in this thread how well that software worked out for them.


Etrecheck's philosophy is a strength for anyone who is running nothing but well-known, commercial-like software. It's a false positive nightmare for anyone who isn't.

"False positives" are what 3rd party antivirus software generates. Because EtreCheck is not antivirus or security software, "false positive" are impossible.


As a convenience for users, EtreCheck does have the same kind of basic adware detection that some 3rd party security apps provide. But ultimately EtreCheck isn't looking for adware or malware. EtreCheck is looking for anything that might be a problem. Any software in 2018 that still doesn't have a digital signature is a potential problem. It is impossible to say anything definitive about software that doesn't have a digital signature. EtreCheck will try to make a guess. As can be seen in the EtreCheck report above:

Unsigned Files:

Launchd: /Library/LaunchDaemons/com.adobe.SwitchBoard.plist

Executable: /Library/Application Support/Adobe/SwitchBoard/SwitchBoard.app/Contents/MacOS/launch.switchboard

Details: Exact match found in the whitelist - probably OK

Launchd: ~/Library/LaunchAgents/com.valvesoftware.steamclean.plist

Executable: /Users/***/Library/Application Support/Steam/SteamApps/steamclean

Details: Exact match found in the whitelist - probably OK

Launchd: /Library/LaunchDaemons/com.pplauncher.plist

Executable: /Library/Application Support/pplauncher/pplauncher

Details: Domain name invalid - possibly adware

Launchd: /Library/LaunchDaemons/com.macpaw.CleanMyMac3.Agent.plist

Executable: /Library/PrivilegedHelperTools/com.macpaw.CleanMyMac3.Agent

Details: Exact match found in the whitelist - probably OK


32-bit Applications:

16 32-bit apps


Kernel Extensions:

/Library/Extensions

[Loaded] Soundflower.kext (MATT INGALLS, 2.0b2 - SDK 10.10)

[Loaded] MB_MBAM_Protection.kext (Malwarebytes Corporation, 3.3 - SDK 10.13)

[Loaded] SophosFileProtection.kext (Sophos, 9.7.4 - SDK 10.12)

[Loaded] SophosFileMonitor.kext (Sophos, 9.7.4 - SDK 10.12)

[Loaded] SophosWebProtection.kext (Sophos, 9.7.4 - SDK 10.12)

sometimes EtreCheck guesses are better than "more responsible" antivirus software.

May 19, 2018 3:04 AM in response to lohnguyen

So the last bit of info that nobody seems to know yet, is how these files came to be installed on your computer, apparently back on 2018-04-20. I thought maybe EtreCheck could give us some clues, but doesn't seem to include recently installed apps.

Can you please hold down the <Option>-key and select "System Information..." from the Apple menu then go down to Software->Installations. Click on the "Install Date" column header a couple of times to bring most recent to the top and see what you installed around the 20th of last month. Not everything is registered there, but most is.

May 19, 2018 6:53 AM in response to RonEdwards

Malwarebytes will detect this now.


There are three pieces to this malware installed on your Mac, which have all been discussed here.


/Library/Application Support/pplauncher/pplauncher

This is the launcher. Its sole job is to extract and launch the mshelper file.


/Library/LaunchDaemons/com.pplauncher.plist

This keeps the launcher running at all times.


/tmp/mshelper/mshelper

This is the cryptominer, which uses lots of CPU power to mine Monero cryptocurrency (similar to Bitcoin).


All of these must be removed. Malwarebytes will remove them all.


What I haven't been able to locate yet is the "dropper," which is the installer that infected your machine with the malware. I'm very curious about that. Do you have any idea what you installed recently, and where it came from? There doesn't seem to be any subtlety about this malware - it will start hammering your CPU as soon as it starts running, so it should be fairly easy to correlate the last thing you installed with when this started happening.


If you can identify that dropper, I'd be very interested in seeing it. You can't post it here, but you can upload it to VirusTotal:


https://virustotal.com


Once VirusTotal has finished analyzing it, post a link to the VirusTotal analysis page here.

What is mshelper?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.