'logger' process in activity monitor

Hi all,
I noticed a process running in activity monitor called 'logger' (just that). It seems to be part of the root user but i can't identify what it's connected to. Spotlight can't find it anywhere either. I've searched around on Google to see if there's any mention of it, but all i get are details of key logger software.
Naturally i'm a bit concerned by this process, especially because i haven't (voluntarily) installed any logging software on my machine.
It always seems to run at process ID 141, takes up 380KB of real memory, and 26.63 MB of virtual memory. no idea how long it's been there though. i've never seen it take up any CPU, but not sure if that means anything.
Any ideas what it might be? and if it's malicious, how might i go about getting rid of it?

blagga wrote:
In /Library/StartupItems, I have a folder for the M-Audio soundcard, 3 folders that I think relate to the Maxtor external drive, and then finally a folder called RetroRun. LaunchDaemons and LaunchAgents are both empty.
It could be one of these. If you're worried, you can search the files here for the term "logger" and see if any of these are using it. However, they might be using it even if you turn up nothing here as they might start an application elsewhere which calls it. You can either search the files using something like grep in the Terminal or open them in a text editor and use find.
The other way to find out would be to temporarily remove these, restart and see if the process still appears - if not, likely one of these is the culprit.
Incidentally, there are 16 whole folders things in /System/Library/StartupItems, as well as 33 'plist' files in /System/Library/LaunchDaemons.
I have 16 and 37 respectively!
- cfr

Similar Messages

  • What's the ActivityMonitorD process? -- Activity Monitor with a 'D'

    So I've been monitoring my computer's processes with Activity Monitor, working through some possible bugs with a hard drive and I found that there is a process running that isn't listed here: http://triviaware.com/macprocess/all
    Anyone know if there is a process called: ActivityMonitorD
    That's right *'ActivityMonitor' with a D on the end*. That is a process in addition to the regular 'ActivityMonitor.app'. Anyone able to solve that riddle for me?

    What do I make of this information in my Activity Monitor:
    PID    Process Name                    User  
    1        launchd                              root    
    323       acticitymonitord                root  
    51          autofsd                           root
    50          blued                              root
    162        com.apple.dock.extra       root
    14          configured                       root                       
    107        coreaudiod                      root
    53          coreservicesd                 root
    95          CVMserver                     root
    13          diskarbitrationd               root
    54          diagnostic                      root
    44          dynamic_pager               root
    253        filecoordinationd              root
    15          fsevensd                        root
    52          hidd                               root
    40          KernalEventAgent           root
    10          kextd                             root       

  • IMac using 100% of the CPU, but no processes in Activity Monitor show usage over 3%. What's going on?

    This iMac is about 5 years old. It has the 2GHz Intel Core 2 Duo processors, 2GB RAM, and is running 10.8.5. After rebooting the machine, CPU usage is low. After about 30 seconds, when using Activity Monitor, CPU usage bumps up to 100% and stays there without budging. When viewing the CPU tab near the botom, % User is about 95+%, and % System makes up the other 5%. They change slightly every second. The problem is, if I sort my Processes by % CPU, the largest user is Activity Monitor with around 2.3%. Everything else is at 0.0%. So there's something weird going on causing the CPU to max out and run hot, but I can't figure out what's causing it. Checking for applications to force quit doesn't show any issues, and repairing permissions doesn't do anything. Is there any way to figure out what's going on? I read about how to reset the System Management Controller, is this something I should do? Thank you for ANY help, it's driving me crazy!
    EDIT: I figured it out! Browsing All Processes, I'm running a folding@home program, but I thought I uninstalled it! The process is called FahCore_a4. Is there any way to prevent it from showing up on boot? I want to get rid of it but I deleted the applications!

    Be certain to check that you are viewing "All Processes" as opposed to "My Processes"

  • Application Sudo listed in Activity Monitor - Is this a default app that should be running?

    First Question:        Do other MBP users have an application Sudo listed in Activity Monitor from start up of their mac or with typical use?
    Second Question:   If you have Sudo process listed in your Activity Monitor, do you also use an Huawei USB wireless modem?
    Third Question:       For those experienced in relevant coding domains and given the more technical details below - your thoughts?
    (Technical)
    Using MBP Retina, mid 2012, OSX 10.8.4
    I understand sudo is a unix root level access command. 
    I have used Terminal and become familiar with some basic unix commands, including using the sudo command in very limited single action command circumstances.  I have not used Terminal for many weeks, and the sudo command probably twice several months ago. 
    Sudo showing in Activity Monitor as an active process is to my understanding an entirely different situation to it being used in Terminal.  It appears the sudo process is being activated by some other application or process not of my direct use or actions.
    I remain a little concerned about this in view of the purchase of this particular MBP. It has a story to it. I was told this MBP was available as new on discount as it had been purchased by a man for his wife, the wife then left him, and subsequently he returned it unused to the store.   I was aware that there was a slim risk the laptop had been used for some other activities, and returned so any come back comes back to the new owner.
    I noted later with use that the MBP lower keys were sticky as if something has been spilt on them, so I do wonder if the laptop was previously used, then wiped, in which case the story presented to the retailer is likely not true and a more concerning scenario becomes possible.  
    All the same, I felt a clean install should remove any risk.  The MBP arrived in standard ready to set up and go mode, so OS loaded but no activation.  So it seemed a clean install to me.   I did not wipe the HD and do a fresh OS install from scratch. A decision I now regret.
    Some months after using this new MBP, my concerns were raised when I had one day of inexplicable internet usage on a wireless internet connection.  Not only did the level of data upload and data load, about 4 GB out of 20 GB for the month not make sense with actual usage, but also the MBP system logs did not tally with the internet providers accounting of usage on that day.  There have been two or three other anomalies in usage since.  The internet service provider reimbursed me on my evidence of OSX system logs.  Not sure if the service provider has people joy riding other users accounts or something suss this end was going on. Never resolved. The ISP was not exactly forthcoming, and I had to press hard to get some collaboration on resolve the anomaly of unexplained data usage.
    On the less suspicious side, the existence of this sudo program tracked down as in part coming from the install software from a Huawei modem provided by my internet provider.  However, while widely used and therefore likely not a security risk, I still feel need for some better explanation and resolution of the persistent sudo process. 
    I have  inquired to Apple Support about this sudo app running, and it apparently was not seen as an issue of concern by the front line support staff.  I took up some further concerns with them but checks indicate no issues of concern with the MBP from their assessment. I trusted that as fairly likely a definitive view, and so left the questions and anomalies as unexplained but harmless. 
    It is now several months later and I still find the existence of sudo as a running application or process in Activity Monitor troubling, and decided to try and resolve once again how typical and for what reason it is active on my MBP. Which brings us to this post.
    I have again spent a few hours searching on Google and Apple Support Forums.   All search results I find relate to the use of sudo as a unix command in Terminal to resolve a problem.  I can not find any indication of sudo as an app being open routinely in Activity Monitor with or without Terminal being opened or used.
    The only way I can think of to resolve if this is unusal or not is to get on this forum and ask the first two questions at the top of this post.
    More technical details follow.
    For some more technically minded the details may be of interest, hence below here I have added  details for further comment.   I am hoping some MBP users on this forum may also be coders, and hence have some idea of the internal mac coding environment. Enough to shed some light on this situation. 
    As mentioned, I think the sudo Activity Monitor may originate from the running of the Internet Providers USB Wireless Modem and software (Huawei E 169? modem).  The USB modem has the install software on it.  You install that software on your HD as an application. 
    On this USB Wireless Modem front I have done some checking.  
    Killing sudo in Activity Monitor does not stop an internet connection mid session. 
    When the USB modem is removed, the sudo process remains running and listed in Activity Monitor. 
    If I remove the Modem icon, unplug modem, close all apps, restart without the modem connected, the sudo process is still loaded and running in Activity Monitor.
    Months ago on a previous check if I deleted (uninstalled) the modem software, removed associated start up files installed by the modem installation, took out the USB Modem and did a restart, there was no return of the sudo process in Activity Monitor.  When the modem software was reinstalled or the start up files restored directly, the sudo process returns to Activity Monitor.  One of the software bits installed in start up files calls sudo (or so it appears having a peak in BBedit at the files.)
    This seems to fairly much establish the source of the sudo application. However it does not resolve why it needs to be open all the time, and if this is unique to this modem, my modem,  modems in general, or if permanent running sudo processes are fairly 'normal' in general.  Since sudo is a root level access process, I do feel a little concerned of the situation.   Let's say the sudo process is needed to initiate the modem under some justification.  Does the sudo process in remaining running permanently from there on, with or without the USB modem connected leave an open access way and vulnerability that can or is used later?   i do not know enough of the coding level architecture to form a view.   Still, seeing a permanent sudo process operating does niggle by sense of suspicion.    Hence, I continue to raise this issue and ask the questions I do.
    In Activity Monitor:
    sudo as a process when running is not very active.  
    Real Mem 8 KB, Virtual Mem 9.4 MB, Sent Msgs 75, Rcved Mesgs 26, Ports 25, Intel (64 bit).
    The sudo process:
    Using Sample Process in Activity Monitor:   sudo appears to be a running of the actual sudo command from within the unix command files.
    Path:            /usr/bin/sudo  (Master Library, not the one in the User files)
    Load Address:    (removed)
    Identifier:      sudo
    Version:         ??? (???)
    Code Type:       X86-64 (Native)
    Parent Process:  launchd [1]
    Call graph
    2nd line is 2656  start  (in libdyld.dylib) + 1  [(removed)]
    Binary Images:
    Includes reference to lots of .dylib files. eg libcache.dylib, libquarantine.dylib, libremovefile.dylib, libcompiler_rt.dylib, libcorecrypto.dylib
    The parent process is launchd[1]
    Process:         launchd [1]
    Path:            /sbin/launchd
    Load Address:    (removed)
    Identifier:      launchd
    Version:         ??? (???)
    Code Type:       X86-64 (Native)
    Parent Process:  ??? [Unknown]
    It seems all of the activity of launchd[1] is from the sudo process.
    Again reference to .dylib files as captured in call graph and Binary images.
    I hope the details are valued by someone with an interest to assist with resolving concerns.

    Thanks,
    I usually use the OS connection option. So as you suggest, connect without the ISP connection software.  Doing so does not by-pass the sudo command being active in Activity Monitor however. 
    On reading my post I see my failure to link the concerns of the laptop purchase with the sudo and modem. My thought here is of an intersection of known vulnerability with this widely used modem/software (via permanent sudo process activated) and that vulnerability then being known and utilised by another party(s).
    I am pursuing the issue in part with consideration to a broader possible issue of vulnerability.
    Thanks again for your thoughts and suggestions. Valued.

  • Activity monitor- "Installer" takes 5GB of memory. What is it and how to stop it?

    In the activity monitor, there is a process name called "Installer" and it takes up to 5GB of my memory. Each time I force-quit it, it comes back on. What is it and how to stop it?

    This is often due to a failed installation of genieo/installmac adware. You should be able to double-click the process in Activity Monitor to see the Inspect window, with a list of files used by it.
    There are removal instructions at
    You installed the "Genieo/InstallMac" rootkit.
    and
    http://www.thesafemac.com/arg-genieo/

  • Can I safely quit task demanding activities in the Activity Monitor?

    1.) I see that the "Python" often groves very large and is both processor and ram demanding. Why? And it is safe to "kill the python" (quit the process) at any time?
    2.) Sometimes I see even two Pythons. Why?
    3.) Are there other processor or ram demanding activities I can quit at any time without any trouble?
    4.) Are there any ways of avoiding restarts? (I have a great new setup with a program called "Desktop Manager" which is almost like spaces in Osx 10.5 which I would like to keep
    5.) It is generally considered "good health" for the Mac to have a restart now and then and Why?
    Thanks.

    If Python is doing this all the time, then there's a bigger fish to fry. Quitting it isn't a solution. You need to find out what's causing Python to 'hang." When you view the processes in Activity Monitor one of the columns indicates who owns the process - is it you or the system? If it's you then you have something you are using on your computer that requires Python. Look for third-party software you may have installed.
    In Activity Monitor double-click on the Python process. A dialog will appear. Click on the Open Files and Ports tab. Scroll through the list to see if anything pops out at you such as another program that is using Python to run some scripts.
    You will need to track down whatever is using Python. You should also consider doing some cleanup. Download a utility such as TinkerTool System and use it to clean all user, system, and font caches. If you have a corrupted cache problem this could fix it. You need to do an immediate Restart.

  • In Activity Monitor what is PrintJobMgr?

    Don't know if this is the right place for this post, but in trouble shooting my G5 running 10.4.5 I notice the following process in Activity Monitor:
    Process ID: 191, Process Name: PrintJobMgr, User: lp. When I click "Inspect" is tells me the Parent Process is cupsd (172) User lp(26)
    I've never noticed this before, and although I'm not doing any printing and none of my printer applications are open it's % CPU amount keeps changing and is running between 50% and 97%!
    If I click to quit pricess it says "PrintJobMgr is owned by lp. You need to authorize as an administrative user to kill the process."
    Can anyone shed any light on this?
    Dual G5   Mac OS X (10.4.5)   Trouble shooting slow performance

    Vipir,
    Thanks for the reply. I ended up quiting the process in Activity Monitor which worked. Now when I print I see PrintJobMgr re-appears with owner: Root and a CPU use of about 1%. Much more logical.
    I did try "Reset Printing System" today when I was having trouble with DVD/CD feed on my Epson R200. The feeding system on this printer has always been iffy for me (sometimes it pushes out rather than pulls in the DVD). It did feed properly after I Reset. Unfortunately, I didn't realize it would delete all my saved Driver Settings. I hate to lose these as they need to be set very carefully to avoid errors. Any idea if I could restore these?

  • Email notification from activity monitor

    Hi everyone,
    does anyone know a way to have a mac send an automatic email to a specified address once a certain process in activity monitor finishes (or drops below a certain CPU usage)?
    it would be very useful in some cases.
    i am not at all familiar with applescript and couldnt find anything on the forums
    thanks in advance for any suggestions

    A good use of the terminal command : top -u
    then, for exemple, parse with grep/awk ...
    compare the values recovered,
    then a simple mail automator action if needed.

  • How do i stop two processes that are running in activity monitor

    how do i stop two processes that are running in Activity Monitor took one out of trash and it says preparing to move desktop still running with another one been running for hrs now want to stop these many thanks jen.

    Select each one and Force Quit it.
    But be careful there are many processes that are run by the OS that if quit will cause problems possibly even crash the system.
    regards

  • MBP with 10.6.8: CPU usage high, no responsible processes shown in Activity Monitor. What causes this?

    After using my computer for some time, CPU usage climbs to about 90% (ca. 65% user / 26% system) and fans run at high speed, but there is no processes that seem to use CPU (other than Activity Monitor itself ~1%).
    This has happened a few times recently. It happens when I've used my computer for some time, hours or a couple of days (I usually put my computer to sleep when not using it but rarely shut it down). I've tried to quit all running apps incl. Growl, Dropbox, and anything that could be responsible to this but with no results. Putting computer to sleep for a long time doesn't help, cpu usage will climb instantly after wake up. Restarting system is the only thing that helps.
    Most of the time I use my laptop with external monitor, lid closed and connected to power supply. When experiencing this, opening the lid causes fans to slow down, but CPU usage remains high and battery drains quick.
    Any ideas what might cause this?
    My MBP is 15" model with Core 2 Duo 2,66 GHz (MacBookPro 5,3), OS X version is 10.6.8, all available updates are installed.

    Perform a SMU reset.
    https://support.apple.com/kb/HT3964
    Remove the anti-virus, it's running a root level process all the time that's taking your CPU and it's not necessary as there are no Mac viruses, Apple has the trojan angle covered already.
    Always on anti-virus on a Mac is always a source of problems, also is MacKeeper, uninstall that here if you have it.
    http://applehelpwriter.com/2011/09/21/how-to-uninstall-mackeeper-malware/
    If you need to clean the Windows filth off PC files, then use the free, run as you need, ClamXav.
    http://www.clamxav.com/
    It seems your machine is used in a corporate enviroment, thus likely a rule that anti-virus must be used, you can avoid high CPU usuage by using the ClamXav instead.

  • A process by the name of avgcmgr is loading the CPUs by up to 100 percent. At least 5 of them have appeared on the activity monitor. I've removed them with forced quit but they return! How do I permanently get rid of them? CPUA temp is now 194F.

    A process by the name of avgcmgr is loading the CPUs by up to 100 percent. At least 5 of them have appeared on the activity monitor. I've removed them with forced quit but they return! How do I permanently get rid of them? Three of these processes has now driven the CPUA temp to 194F.
    Ray

    Hi Ray-
    I'm having the exact same problem and have searched the web for hours looking for a solution (multiple spawned avgcmgr processes that consume cpu).
    Did you find any solution?
    Thanks so much!
    Steve

  • What is a normal number of processes to appear in activity monitor?

    When I go into Activity Monitor and click on "All Processes", I have anywhere from 50-62 processes going on. A friend told me this was far too many, but she uses a different operating system than I do.
    I have a 10.4.11 OS on a Macbook that I bought in January of 2007.
    My computer overheats fairly easily, so I'm not sure if there is a problem here. It has typically maintained a number of around 60-62, but when I restart it, the numbers drop to a 56 or so and slowly rebuild. I recently downloaded Sophos, an antivirus program, which takes up 4 processes (don't know if that's normal).
    Is this a typical number of processes (these are the numbers when I have no main programs, like Safari/Microsoft Office/itunes/other open), or do I need to do some kind of cleaning? And if I do need cleaning, what should I do?

    Sophos is a real problem here, but on a PPC G5 PowerMac, so I never installed it on anything else.
    My eMac/1.42/2G/10.5.8 has about 60 to 70 Processes showing, can check 10.4.11 tomorrow if you wish, but while it depends on so many factors, I don't consider yours abnormal at all.
    do I need to do some kind of cleaning? And if I do need cleaning, what should I do?
    If anything, At this point I think you should get Applejack...
    http://www.macupdate.com/info.php/id/15667/applejack
    After installing, reboot holding down CMD+s, (+s), then when the DOS like prompt shows, type in...
    applejack AUTO
    Then let it do all 6 of it's things.
    At least it'll eliminate some questions if it doesn't fix it.
    The 6 things it does are...
    Correct any Disk problems.
    Repair Permissions.
    Clear out Cache Files.
    Repair/check several plist files.
    Dump the VM files for a fresh start.
    Trash old Log files.
    First reboot will be slower, sometimes 2 or 3 restarts will be required for full benefit... my guess is files relying upon other files relying upon other files!

  • Business Activity Monitoring for BPEL Processes

    Hello,
    IEP is capable of monitoring real time events, Real time business event collection and processing.
    In that case, can we use IEP to monitor BPEL process activities with activity data.
    One very big part, the ability to provide functionality for third parties (clients like Me) to register some sort of observer to capture live BPEL process activity, is missing.
    I'm trying to cover that big hole in my project. That's the reason I'm posting about BPEL process management capabilities and events.
    But I got no concrete answers for that. Not every business use can be provided by any generic system.
    I looked at CAM (which comes with Alaska build). But I couldn't get much info about entire picture.
    Other BPEL engines, the one I have used, has the functionality to do activity monitoring and process management. (IBM Process server, Apache ODE)
    Could any IEP, BPEL component developers answer any sort of solution to my use case?
    Thank you
    Raja

    I agree that this would be very useful. If anyone can provide additional insight it would be much appreciated.

  • How to get Activity Monitor to show processes running on one specific drive

    I clone my main drive to two cloned drives. From the clones I normally, without any problem, run both Repair Disk from the Apple Disk Utility, and a maintenance program from Disk Warrior. Now, however, neither of these utility programs are able to unmount my main drive. Rather, they return a message to quite running processes. I have tried to use Activity Monitor to locate what is running, but can find no way to determine which of the dozens of processes listed are connected to the main drive, rather than to the boot drive of the clone. Plus, I do not understand how something can be "running" on a drive that is not the boot drive. Please help. Thanks.

    Let's start in reverse order...
    I do not understand how something can be "running" on a drive that is not the boot drive
    That's easy. You can't unmount the drive if any files on that drive are in use. That does not necessarily mean the application is stored on that drive, but any file on that drive could prevent it being unmounted - for example, if an application has a document open that is on the drive, you might not be able to unmount the drive.
    Even subtler, if you're running Terminal.app and have cd'd into a directory on that drive, then you won't be able to unmount, either, since the directory is 'in use'.
    As for finding out which applications are using the disk, try lsof in terminal:
    sudo lsof +d /Volumes/diskname
    This will show any process that has an open file handle on /Volumes/diskname (and its subdirectories).

  • After launching Adobe CC many processes show as (Not Responding) in Activity Monitor

    I'm running Adobe CC on a new Apple MacPro 6,1 (12-core with 64GB RAM). I find that many processes get into a (Not Responding) state as displayed by Activity Monitor.
    Typically, when one sees a process (Not Responding) there's really not much that can be done other than using Activity Monitor to Quit or Force Quit the process. I've done this but the (Not Rsponding) processes even after being Quit/terminated, get relaunched with a different PID and will go into the (Not Responding) state almost immediately.
    Here's a typical situation I captured today. In this example it's the Qmaster process.
    This is becoming very annoying. However, I'm not sure what the implications of these (Not Responding) processes are. They do hold onto memory resouces but obviously aren't consuming/stealing CPU cycles. The Adobe CC does however become sluggish, so I'm thinking there's definitely a problem/bug here that Adobe needs to resolve.
    Any insights or help resolving this issue is most welcomed. Thank you.
    Is the Apple's Mavericks "App Nap" feature somehow involved with this I wonder ?  I do have that box unchecked in Energy Saver preferences.
    Message was edited by: foob66

    You have a program running that is incompatible. What third-party sound or audio applications are you running? It will be one of those. If you quit them the problem should disappear. You will have to force quit coreaudio and UserEventAgent via Activity Monitor or restart the computer but do not run the third-party application(s).

Maybe you are looking for

  • Need help with a 8100

    I have a bb 8100 which no register the host routing table. I do the wipe handheld and now I can not make calls. It can be a problem on the hardware or a software I don't know but I need help desperate because my contract with my provider end on 9 mon

  • Decode in an insert statement

    Is it possible to use decode base on a pl/sql variable in field declaration of an insert statement? For example: INSERT INTO emp_schedule (employee_id, schedule_date, destination, start_time, absent, late, entry_date_time, decode(v_bucket_id, 1, buck

  • Edit e-mail alerts generated by task lists

    My client wants to customise the e-mail alerts generated to notify users of tasks due or overdue. I would like to know where the default messages are stored. Thanks Chris

  • Older version ipod issue re: ipod format

    A friend of mine has been given an older ipod (one of the original ones with the rotating wheel and NO dock connector, instead it has a fire wire outlet connector) my problem is that this ipod is formatted for mac, and she has a windows computer. we

  • Question / Suggestion - OrderBy (Sorting) Feature by Clicking.

    Maybe there is a way to do this and someone can fill me in, or maybe this will be another suggestion for consideration. When I open a connection to an oracle DB, then click on a specific table. A worksheet popups with Columns Tab in focus. I'd like t