Finding and removing malware, key-loggers, spyware

There have been many threads about finding keylogers and spywear on OSX, but most of them are akin to giving a man a fish than teaching him to fish. For instance Linc Davis responded to the below thread with some instructions in terminal and requested the output be copied to the thread. This will not help anyone who doesn't have access to a "Linc Davis."
https://discussions.apple.com/thread/4243511?start=0&tstart=0
Is there a tutorial or something that we can use to monitor these kinds of things? I look in Console, Activity Monitor, Little Snitch but I don't really know what I'm looking for. And when you do find it how do you remove it? I heard once that if you back up your infected computer to a drive and computer you now connect that drive to can get infected (like my freshly wiped HD with a new copy of OSX). A list of all known malware process names.
After looking at my output in the above link someone suggested that  com.BT.kext.bpkkext was a suspect and that Blazing tools Perfect Keylogger was the software. I can't remove it; I even downloaded the uninstaller from Blazing tools.

Here is my output, if someone only has time for a fish instead of a leason. Thanks in Advanced!
kextstat -kl | awk '!/com\.apple/{printf "%s %s\n", $6, $7}'
com.oxsemi.driver.OxsemiDeviceType00 (1.28.13)
at.obdev.nke.LittleSnitch (3932)
com.asix.driver.ax88179_178a (1.3.0)
com.LaCie.ScsiType00 (1.2.13)
com.BT.kext.bpkkext (1.0.0)
com.displaylink.driver.DisplayLinkDriver (1.7)
com.parallels.kext.prl_usb_connect (7.0
com.parallels.kext.prl_hypervisor (7.0
com.parallels.kext.prl_hid_hook (7.0
com.parallels.kext.prl_netbridge (7.0
com.parallels.kext.prl_vnic (7.0
com.github.osxfuse.filesystems.osxfusefs (2.6.0)
Black-Book-108:~ Old_blackbook$
Black-Book-108:~ Old_blackbook$ sudo launchctl list | sed 1d | awk '!/0x|com\.(apple|openssh|vix)|edu\.mit|org\.(amavis|apache|cups|isc|ntp|postfi x|x)/{print $3}'
Password:
com.agilebits.onepassword-osx-thumbs
com.parallels.vm.prl_naptd
com.syniumsoftware.CleanAppDaemon
com.parallels.desktop.launchdaemon
com.microsoft.office.licensing.helper
com.micromat.TechToolProDaemon
com.google.keystone.daemon
com.displaylink.displaylinkmanager
com.adobe.SwitchBoard
com.adobe.fpsaud
com.absolute.rpcnet
com.absolute.rpcgeo
at.obdev.littlesnitchd
Black-Book-108:~ Old_blackbook$
Black-Book-108:~ Old_blackbook$ launchctl list | sed 1d | awk '!/0x|com\.apple|edu\.mit|org\.(x|openbsd)/{print $3}'
com.dayoneapp.dayone-agent
com.fiplab.clipboardhelper
com.joeworkman.mac.ClimateHelper
com.agilebits.onepassword-osx-helper
com.thursby.pkard.tokendagent
com.parallels.vm.prl_pcproxy
com.parallels.DesktopControlAgent
com.parallels.desktop.client.launch
com.micromat.TechToolProAgent
com.lacie.eventsactions.launcher.agent
com.google.keystone.system.agent
com.displaylink.useragent
com.BT.BPK
com.amazon.sendtokindle.launcher
at.obdev.LittleSnitchUIAgent
com.google.Chrome.framework.service_process/Users/Old_blackbook/Library/Applicat ion_Support/Google/Chrome
com.adobe.ARM.de23d1e3aa2d00ce38d73f10fcbdc8dcaaaf6be989610710a1ddda77
com.adobe.ARM.202f4087f2bbde52e3ac2df389f53a4f123223c9cc56a8fd83a6f7ae
com.adobe.ARM.031ead678131651e32346abaaf859369f569f63bac6112fd126a5660
Black-Book-108:~ Old_blackbook$
Black-Book-108:~ Old_blackbook$ ls -1A /e*/mach* {,/}L*/{Ad,Compon,Ex,Fram,In,Keyb,La,Mail/Bu,P*P,Priv,Qu,Scripti,Servi,Spo,Sta} * L*/Fonts 2> /dev/null
/Library/Components:
/Library/Extensions:
/Library/Frameworks:
AEProfiling.framework
AERegistration.framework
Adobe AIR.framework
AudioMixEngine.framework
EWSMac.framework
Inventoryx86.framework
MacFUSE.framework
NyxAudioAnalysis.framework
OSXFUSE.framework
PluginManager.framework
Sysinfo.framework
TSLicense.framework
geo.framework
iTunesLibrary.framework
wceprv.framework
/Library/Input Methods:
/Library/Internet Plug-Ins:
AdobeAAMDetect.plugin
AdobePDFViewer.plugin
AdobePDFViewerNPAPI.plugin
DirectorShockwave.plugin
Flash Player.plugin
Flip4Mac WMV Plugin.plugin
JavaAppletPlugin.plugin
Quartz Composer.webplugin
QuickTime Plugin.plugin
SharePointBrowserPlugin.plugin
SharePointWebKitPlugin.webplugin
WebClient.plugin
flashplayer.xpt
googletalkbrowserplugin.plugin
npgtpo3dautoplugin.plugin
nsIQTScriptablePlugin.xpt
o1dbrowserplugin.plugin
/Library/Keyboard Layouts:
/Library/LaunchAgents:
at.obdev.LittleSnitchUIAgent.plist
com.BT.BPK.plist
com.adobe.AAM.Updater-1.0.plist
com.amazon.sendtokindle.launcher.plist
com.displaylink.useragent-prelogin.plist
com.displaylink.useragent.plist
com.google.keystone.agent.plist
com.lacie.eventsactions.launcher.agent.plist
com.micromat.TechToolProAgent.plist
com.parallels.DesktopControlAgent.plist
com.parallels.desktop.launch.plist
com.parallels.vm.prl_pcproxy.plist
com.thursby.pkard.tokendagent.plist
/Library/LaunchDaemons:
at.obdev.littlesnitchd.plist
com.absolute.rpcgeo.plist
com.absolute.rpcnet.plist
com.adobe.SwitchBoard.plist
com.adobe.fpsaud.plist
com.displaylink.displaylinkmanager.plist
com.displaylink.usbnivolistener.plist
com.google.keystone.daemon.plist
com.micromat.TechToolProDaemon.plist
com.microsoft.office.licensing.helper.plist
com.parallels.desktop.launchdaemon.plist
com.syniumsoftware.CleanAppDaemon.plist
/Library/PreferencePanes:
CleanApp Logging Service.prefPane
Flash Player.prefPane
Flip4Mac WMV.prefPane
HyperDock.prefpane
OSXFUSE.prefPane
TechTool Protection.prefPane
/Library/PrivilegedHelperTools:
DisplayLink
com.microsoft.office.licensing.helper
/Library/QuickLook:
ParallelsQL.qlgenerator
iBooksAuthor.qlgenerator
iWork.qlgenerator
/Library/QuickTime:
AppleIntermediateCodec.component
AppleMPEG2Codec.component
Flip4Mac WMV Advanced.component
Flip4Mac WMV Export.component
Flip4Mac WMV Import.component
/Library/ScriptingAdditions:
Adobe Unit Types.osax
BXDockPlugin.osax
/Library/Spotlight:
Microsoft Office.mdimporter
ParallelsMD.mdimporter
iBooksAuthor.mdimporter
iWork.mdimporter
/Library/StartupItems:
PKard
/etc/mach_init.d:
/etc/mach_init_per_login_session.d:
/etc/mach_init_per_user.d:
Library/Address Book Plug-Ins:
SkypeABDialer.bundle
SkypeABSMS.bundle
YMsgrCallABPlugin.bundle
YMsgrMsnABPlugin.bundle
YMsgrSmsABPlugin.bundle
YMsgrYimABPlugin.bundle
Library/Fonts:
Library/Frameworks:
EWSMac.framework
Library/Input Methods:
.localized
Library/Internet Plug-Ins:
CitrixOnlineWebDeploymentPlugin.plugin
Picasa.plugin
Library/Keyboard Layouts:
Library/LaunchAgents:
com.adobe.ARM.031ead678131651e32346abaaf859369f569f63bac6112fd126a5660.plist
com.adobe.ARM.202f4087f2bbde52e3ac2df389f53a4f123223c9cc56a8fd83a6f7ae.plist
com.adobe.ARM.de23d1e3aa2d00ce38d73f10fcbdc8dcaaaf6be989610710a1ddda77.plist
com.apple.AddressBook.ScheduledSync.PHXCardDAVSource.F940DCE7-790C-4149-8C3E-3CC 8849882C8.plist
com.apple.FolderActions.enabled.plist
com.apple.FolderActions.folders.plist
com.google.Chrome.framework.plist
Library/PreferencePanes:
Library/Services:
.DS_Store
SymbolicLinker.service
Toggle Hidden Files.workflow
Black-Book-108:~ Old_blackbook$
Black-Book-108:~ Old_blackbook$ osascript -e 'tell application "System Events" to get name of every login item' 2> /dev/null
iTunesHelper, Quicksilver, Spark Daemon, Dropbox, HyperDock Helper, Google Chrome, Things Helper, BackTrackBA

Similar Messages

  • Finding and removing malware

    Any tools to identify and remove malware from an iMac running Mavericks?

    Helpful Links Regarding Malware Protection
    An excellent link to read is Tom Reed's Mac Malware Guide.
    Also, visit The XLab FAQs and read Detecting and avoiding malware and spyware.
    See these Apple articles:
              Mac OS X Snow Leopard and malware detection
              OS X Lion- Protect your Mac from malware
              OS X Mountain Lion- Protect your Mac from malware
              About file quarantine in OS X
    If you require anti-virus protection Thomas Reed recommends using Dr.Web Light from the App Store. It's free, and since it's from the App Store, it won't destabilize the system. If you prefer one of the better known commercial products, then Thomas recommends using Sophos.(Thank you to Thomas Reed for these recommendations.) If you already use Sophos, then be aware of this if you are using Mavericks: OS X Mavericks- Sophos Anti-Virus on-access scanner versions 8.0 - 9.1 may cause unexpected restarts
    From user Joe Bailey comes this equally useful advice:
    The facts are:
    1. There is no anti-malware software that can detect 100% of the malware out there.
    2. There is no anti-malware that can detect anything targeting the Mac because there
         is no Mac malware in the wild, and therefore, no "signatures" to detect.
    3. The very best way to prevent the most attacks is for you as the user to be aware that
         the most successful malware attacks rely on very sophisticated social engineering
         techniques preying on human avarice, ****, and fear.
    4. Internet popups saying the FBI, NSA, Microsoft, your ISP has detected malware on
        your computer is intended to entice you to install their malware thinking it is a
        protection against malware.
    5. Some of the anti-malware products on the market are worse than the malware
        from which they purport to protect you.
    6. Be cautious where you go on the internet.
    7. Only download anything from sites you know are safe.
    8. Avoid links you receive in email, always be suspicious even if you get something
        you think is from a friend, but you were not expecting.
    9. If there is any question in your mind, then assume it is malware.

  • How can I find and remove viruses from my mac

    I fear that I might have a virus on my beloved macbook pro. i message was spassing out and not sending my messages, my folders continue to dissapear from my desktop causing me to restart finder (not a big deal just annoying) and some other out-of-place things are happening. I don't like credit cards so i can't buy any intvirus software so I was curious to know if there is a way to search for, find, and remove this potential virus on my own.

    Apple provides and updates malware protection as part of the operating system functionality. There is no application you need to run. In using Macs in the corporate world and privately over the last 20+ years, the only malware that got into a Mac came from a shared MS Word document. That was in 1994.
    Everytime that I chose to run a commercial or opensource anti-virus tool, a full sweep showed no infections.
    There may be other systemic issues with your Mac that are the root cause for what you describe. As a baseline, I would do the following:
    Run /Applications/Utilities/Disk Utility. On your boot disk, choose First Aid, and verify/repair permissions.
    Reboot your Mac. Immediately press and hold the shift key until a login screen appears. Enter your login name, your password, and before continuing, press and hold the shift key again, until your desktop reappears.
    Reboot normally.
    What effect do the above have on the problems you mentioned?

  • How to find and remove specific email messages

    I just read an article about a health department employee inadvertently sending a confidential e-mail to 800 users. The IT department shutdown the mail server and wihin an hour removed all copies of the message from the system.
    I asked myself, if that happened here, how would I do that? I could shutdown the Messaging Server, but not sure what to do after that.
    How would you identify, find, and remove a particular e-mail message from everyone's inbox?
    $ imsimta version
    iPlanet Messaging Server 5.2 HotFix 1.26 (built Mar 31 2004)

    Well, each message is stored as a simple text file in the store. Assuming unix, you could do a pretty simple find and grep, looking for a key phrase. exec rm from that, and you're done....
    After such brute force methods, you do need to run
    reconstruct -r

  • On my MacBook with Lion Safari does start, does not react immediately after trying to open it. Installing a new Safari does not help. Removing parts of Safari in the Library did not help. Where can I find and remove all components (LastSession ...)?

    How can I reset Safari with all components? On my MacBook with Lion, Safari does not start, does not react immediately after trying to open it. Installing a new Safari does not help. Removing parts of Safari in the Library does not help. Where can I find and remove all components as LastSession and TopSites?

    The only way to reinstall Safari on a Mac running v10.7 Lion is to restore OS X using OS X Recovery
    Instead of restoring OS X in order to reinstall Safari, try troubleshooting extensions.
    From the Safari menu bar click Safari > Preferences then select the Extensions tab. Turn that OFF, quit and relaunch Safari to test.
    If that helped, turn one extension on then quit and relaunch Safari to test until you find the incompatible extension then click uninstall.
    If it's not an extensions issue, try troubleshooting third party plug-ins.
    Back to Safari > Preferences. This time select the Security tab. Deselect:  Allow plug-ins. Quit and relaunch Safari to test.
    If that made a difference, instructions for troubleshooting plugins here.
    If it's not an extension or plug-in issue, delete the cache.
    Open a Finder window. From the Finder menu bar click Go > Go to Folder
    Type or copy paste the following
    ~/Library/Caches/com.apple.Safari/Cache.db
    Click Go then move the Cache.db file to the Trash.
    Quit and relaunch Safari to test.

  • How do I find and remove duplicates on the 11.2 itunes?

    How do I find and remove duplicates on the 11.2 itunes?

    duplicate annihaitor
    But often duplicates are a symptom and you really need to address the cause - more information is needed to help out with that
    LN

  • How to find and remove any special character in filename?

    I have a files in various Windows Servers 2003 with a special character at his names, who are causing problem with backup software, i don´t know what character is because in explorer they are not shown and in command line they are shown only as interrogation
    mark and for this, i don´t know how i will find and remove then.
    Thanks.

    Hi,
    I agree with Dave. We can try using
    chkdsk utility to check the file system and file system metadata of a volume for logical and physical errors.
    Regarding
    chkdsk, the following article can be referred to for more information.
    Chkdsk
    http://technet.microsoft.com/en-us/library/cc730714.aspx
    Best regards,
    Frank Shen

  • HT2905 No Display Duplicates under File. How to find and remove duplicate items in your iTunes library

    I now have iTunes ver 11.0.4.4 under Windows 7. I lost all iTunes stuff when updating to Windows 7. I have loaded thousands amd thousands of music files from backup disks, but there are many duplicates. I am attemping to re-establish my old library. I used to be able to remove duplicates quickly with the old iTunes. The new iTunes doesn't seem to offer the same service. Is there any way to remove duplicates quickly, or must I do it one by one?

    When deduping use Shift > View > Show Exact Duplicate Items as this is normally a more useful selection. You need to manually select all but one of each group to remove. Sorting the list by Date Added may make it easier to select the appropriate tracks. If you have multiple entries in iTunes connected to the same file on the hard drive then don't send to the recycle bin. Use my DeDuper script if you're not sure, don't want to do it by hand, or want to preserve ratings, play counts and playlist membership. See this thread for background and please take note of the warning to backup your library before deduping.
    (If you don't see the menu bar press ALT to show it temporarily or CTRL+B to keep it displayed)
    See also HT2905: How to find and remove duplicate items in your iTunes library
    tt2

  • How can I find and remove duplicate photos in iPhoto?

    What is the best way to find and remove duplicate photos in iPhoto?

    Are you seeing these duplicates in iPhoto or via the Finder?  If it's in the iPhoto window then you can use one of these applications to identify and remove duplicate photos from an iPhoto Library:
    iPhoto Library Manager - $29.95
    Duplicate Cleaner for iPhoto - free
    Duplicate Annihilator - $7.95 - only app able to detect duplicate thumbnail files or faces files when one library has been imported into another with iPhoto 8 and earlier.
    PhotoSweeper - $9.95 - This app can search by comparing the image's bitmaps or histograms thus finding duplicates with different file names and dates.
    I also prefer iPLM as it is more than just a dup finder.  It's a the most versatile iPhoto utility available.
    OT

  • How can I find and remove duplicate photos from my computer?

    How can I find and remove duplicate photos from my computer?

    Terence,
    Yes, the duplicates appear in the iPhoto window. I have folders with same name occuring two or even three times sometimes with exactly the same set of photos (ie photos with the same ID) and sometimes with a limited set of photos. Other  folders appear only once.
    I normally take my MacBook with me if I'm shooting a lot of photos, such as on holiday, and then want to transfer them to my iMac when i get home. Other times I transfer the camera's memory stick directly to my iMac.
    I have great difficulty transferring the photos from my MacBook to my iMac. I don't want to store my photos on my iDisk due to the length of time it takes to upload them.
    Thanks again.
    Simon

  • HT2905 how do i find and remove duplicate songs in itunes 11.1.3?

    i transferred my itunes to a new computer today, and somehow half of my library was duplicated. no i cant seem to find a way to get rid of the duplicates without selecting them one at a time. any ideas?

    Apple's official advice on duplicates is here... HT2905: How to find and remove duplicate items in your iTunes library. It is a manual process and the article fails to explain some of the potential pitfalls.
    Use Shift > View > Show Exact Duplicate Items to display duplicates as this is normally a more useful selection. You need to manually select all but one of each group to remove. Sorting the list by Date Added may make it easier to select the appropriate tracks, however this works best when performed immediately after the dupes have been created.  If you have multiple entries in iTunes connected to the same file on the hard drive then don't send to the recycle bin.
    Use my DeDuper script if you're not sure, don't want to do it by hand, or want to preserve ratings, play counts and playlist membership. See this thread for background and please take note of the warning to backup your library before deduping.
    (If you don't see the menu bar press ALT to show it temporarily or CTRL+B to keep it displayed)
    Alternativey see this migrate iTunes library post, you may want to revisit the transfer method.
    tt2

  • Hi , how do i find and remove duplicate videos and photos on my ipad2 , please help

    Hello , i have an apple ipad 2 , and iphone 4s and 5s . I have transferred all videos and photos on both these phones to the ipad to make space on my iphones. I have no doubt that there is now multiple duplicates on my ipad . How can i find and remove these. Please help should you know !

    i imported all the files in my sd card to my mac and then i did format the card, it says 160kb is used up.
    I also did find files in the trash when i connected the camera to the macbook and deleted them all, there is nothing left in the camera or the trash and it still says 160kb used :/

  • HT2905 Does anyone know how to find and remove duplicate items in the new itunes 11?

    I am having a hard time trying to figure out how to find and remove duplicate items under the New iTunes 11? Its not as user friendly as in previous versions. Does anyone know how to figure this out?

    As Jim said View > Show Duplicates
    or
    Option + View > Show Exact Duplicates

  • Find and remove duplicates advice?

    hi all,
    would it be possible to get a little advice and some feedback on others' experience with finding and removing duplicates from the aperture database?
    i am doing this now for scans, pdf's, images and other data on my mac book pro and on my mac pro and it would be helpful for me to know what is possible for me to get done with the aperture database.
    TIA

    I haven't used it  myself but  Duplicate Annihilator it is mentioned here often as a solution for this.

  • How do I locate and remove malware from my macbook ?

    How do I locate and remove malware from my Macbook ?

    Check the links below for options to remove the Adware.
    The Easy, safe, effective method:
    http://www.adwaremedic.com/index.php
    If you are comfortable doing manual file removals use the somewhat more difficult method:
    http://support.apple.com/en-us/HT203987
    Also read the articles below to be more prepared for the next time there is an issue on your computer.
    https://discussions.apple.com/docs/DOC-7471
    https://discussions.apple.com/docs/DOC-8071

Maybe you are looking for

  • WRX Error-For consumables posting with Acc Assignment K

    We are doing a GR for consumables posting with account assignment category K (Cost centre).  However, while trying to post the document, system issues a message that "Account determination for WRX cannot be determined".  Why this error is coming for

  • Call drop

    I am using nokia Lumia 1320 with idea network. I am facing problem with call dropping and no signal. The same SIM using with any other mobile the signal was very good and no call dropping. The problem was facing with this nokia Lumia 1320 only. Pl gu

  • Rman backup excluding missing archivelogs

    Please help me in the following scenario : I have 2 months old archivelog in my disk..am taking full rman database backup daily at night..but not the archivelog. once I moved some of my archivelog files to another mount point as the archivelog destin

  • [SOLVED] Bootloaders and partitioning (Syslinux and GPT)

    I don't understand why this is so difficult. All I want to do is install Arch over two partitions (boot and root, both ext2) on a GPT disk, doesn't matter which bootloader.  But I can't find any obvious way to do this.  My understanding of partitioni

  • QuickTime 7.6.4 and CoreFoundation.dll Problem

    Hi, I have not been able to update my QuickTime to the latest 7.6.4 version because some of my Plugins start showing this window with the message: The procedure entry point _CBBundleCopyFileTypeForFileData could not be located in the dynamic link lib