What is mshelper?

Hi - I have mshelper constantly showing in CPU of Activity Monitor at super high levels. I probably wouldn't have noticed except I installed BitDefender today and it's continuously showing me that it's deleting it!


I can't find too much online about it, ** the little suggests it's malware, how do I get rid of it though!


I've tried Malware Bytes which doesn't detect anything!


Activity Monitor

Dropbox - Screenshot 2018-05-15 17.22.25.png


AntiVirus For Mac

Dropbox - Screenshot 2018-05-15 17.26.07.png


Any help would be appreciated!


I've also got CoinMiner showing up a lot and being deleted, but again keeps coming back!


https://www.dropbox.com/s/l2ieww49qcjrh4j/Screenshot%202018-05-15%2017.29.46.png ?dl=0


I can't work out how they're being found and deleted, but keep coming back soon after!!


Thanks!!

Posted on May 15, 2018 1:01 AM

Reply
Question marked as Top-ranking reply

Posted on May 19, 2018 6:53 AM

Malwarebytes will detect this now.


There are three pieces to this malware installed on your Mac, which have all been discussed here.


/Library/Application Support/pplauncher/pplauncher

This is the launcher. Its sole job is to extract and launch the mshelper file.


/Library/LaunchDaemons/com.pplauncher.plist

This keeps the launcher running at all times.


/tmp/mshelper/mshelper

This is the cryptominer, which uses lots of CPU power to mine Monero cryptocurrency (similar to Bitcoin).


All of these must be removed. Malwarebytes will remove them all.


What I haven't been able to locate yet is the "dropper," which is the installer that infected your machine with the malware. I'm very curious about that. Do you have any idea what you installed recently, and where it came from? There doesn't seem to be any subtlety about this malware - it will start hammering your CPU as soon as it starts running, so it should be fairly easy to correlate the last thing you installed with when this started happening.


If you can identify that dropper, I'd be very interested in seeing it. You can't post it here, but you can upload it to VirusTotal:


https://virustotal.com


Once VirusTotal has finished analyzing it, post a link to the VirusTotal analysis page here.

Similar questions

26 replies

May 18, 2018 2:35 PM in response to RonEdwards

It's fairly simple. Etrecheck flags everything it doesn't already know about as possible adware.


Other, more responsible, software only flags something that it can positively identify as a threat as a threat.


Etrecheck's philosophy is a strength for anyone who is running nothing but well-known, commercial-like software. It's a false positive nightmare for anyone who isn't.

May 18, 2018 5:16 PM in response to softwater

softwater wrote:


Etrecheck flags everything it doesn't already know about as possible adware.

No. That is false.


Other, more responsible, software only flags something that it can positively identify as a threat as a threat.

That isn't being "more responsible". That is being standard, run-of-the-mill 3rd party anti-virus software. Ask the people in this thread how well that software worked out for them.


Etrecheck's philosophy is a strength for anyone who is running nothing but well-known, commercial-like software. It's a false positive nightmare for anyone who isn't.

"False positives" are what 3rd party antivirus software generates. Because EtreCheck is not antivirus or security software, "false positive" are impossible.


As a convenience for users, EtreCheck does have the same kind of basic adware detection that some 3rd party security apps provide. But ultimately EtreCheck isn't looking for adware or malware. EtreCheck is looking for anything that might be a problem. Any software in 2018 that still doesn't have a digital signature is a potential problem. It is impossible to say anything definitive about software that doesn't have a digital signature. EtreCheck will try to make a guess. As can be seen in the EtreCheck report above:

Unsigned Files:

Launchd: /Library/LaunchDaemons/com.adobe.SwitchBoard.plist

Executable: /Library/Application Support/Adobe/SwitchBoard/SwitchBoard.app/Contents/MacOS/launch.switchboard

Details: Exact match found in the whitelist - probably OK

Launchd: ~/Library/LaunchAgents/com.valvesoftware.steamclean.plist

Executable: /Users/***/Library/Application Support/Steam/SteamApps/steamclean

Details: Exact match found in the whitelist - probably OK

Launchd: /Library/LaunchDaemons/com.pplauncher.plist

Executable: /Library/Application Support/pplauncher/pplauncher

Details: Domain name invalid - possibly adware

Launchd: /Library/LaunchDaemons/com.macpaw.CleanMyMac3.Agent.plist

Executable: /Library/PrivilegedHelperTools/com.macpaw.CleanMyMac3.Agent

Details: Exact match found in the whitelist - probably OK


32-bit Applications:

16 32-bit apps


Kernel Extensions:

/Library/Extensions

[Loaded] Soundflower.kext (MATT INGALLS, 2.0b2 - SDK 10.10)

[Loaded] MB_MBAM_Protection.kext (Malwarebytes Corporation, 3.3 - SDK 10.13)

[Loaded] SophosFileProtection.kext (Sophos, 9.7.4 - SDK 10.12)

[Loaded] SophosFileMonitor.kext (Sophos, 9.7.4 - SDK 10.12)

[Loaded] SophosWebProtection.kext (Sophos, 9.7.4 - SDK 10.12)

sometimes EtreCheck guesses are better than "more responsible" antivirus software.

May 17, 2018 8:19 AM in response to RonEdwards

Hello RonEdwards,

I'm happy that EtreCheck was able to help. However, I would like to clarify a couple of things.


You don't need to purchase a license to remove adware, or even something that might be adware. As dominic23 points out, you can just find the file in the "Security" section of your EtreCheck report and click the "Remove" button. No license purchase is required for this.


There are some operations in EtreCheck that are restricted to people who have purchased a license. Primarily, these are for safety considerations. I always advise people to stay out of hidden directories. I have seen too many cases where people go into those directories and just start deleting any file they don't recognize or understand. Before Apple added System Integrity Protection, a person could damage their operating system that way. It is still possible to damage installations of legitimate 3rd party software. Some of the "Reveal in Finder" buttons in EtreCheck will dump the user right into those hidden directories. In cases where these are Apple-provided folders for user-accessible files like plug-ins, EtreCheck will let anyone access the folder. But if the target is likely deep inside some 3rd party software bundle, I need to protect people from causing self-harm. Too often, people think they need to delete anything that they see listed in an EtreCheck report and I want to discourage that. So, some advanced features like this are restricted to more advanced users who have purchased a license.


This particular file is interesting. I would appreciate it if anyone who had saved an EtreCheck report with this file could send it to me via the "Report a Problem" feature. The "mshelper" name doesn't appear to be related to the "com.pplauncher.plist". But I have always expected malware developers to eventually start getting more clever about these things. I would really like to know where "mshelper" is installed in your system. I have an open issue in EtreCheck to show the full path for items listed only in one or more of the "top process" lists. I guess I need to finally get that implemented now.


It certainly does appear that "mshelper" is a bitcoin mining trojan. I don't doubt it is related to "com.pplauncher.plist".

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

What is mshelper?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.