New Terminal Results 4 Spyware / Keylogger Detection Review

For Linc and all knowledgeable,
My MBPro webcam was taken over a few months ago and video was recorded of me without my knowledge. At the time I thought it was taken over from a website and was unaware of the potential of spyware that could be installed on my local harddrive. In just the last week I have reason to believe that there maybe a keylogger on my machine recording my writing in MS Word and otherwise. All of this is part of a greater and very serious stalking/harassment/surveilence threat I'm having to face down... So I'm in the process of overhauling my entire internet/Mac security set-up. I am thankful I'm on a Mac at least...
I followed the terminal scripts that Linc posted and here is the output I got.
Thanks to Linc and all who can respond with constructive help!
Step 1
com.microsoft.driver.MicrosoftMouse (8.2)
com.microsoft.driver.MicrosoftMouseUSB (8.2)
com.avg.Antivirus.OnAccess.kext (14.0)
Step 2
com.zeobit.MacKeeper.plugin.AntiTheft.daemon
com.raynersw.nshctldo
com.microsoft.office.licensing.helper
com.avg.Antivirus
com.avg.Antivirus.infosd
com.adobe.SwitchBoard
com.adobe.fpsaud
Step 3
com.zeobit.MacKeeper.plugin.AntiTheft.daemon
com.raynersw.nshctldo
com.microsoft.office.licensing.helper
com.avg.Antivirus
com.avg.Antivirus.infosd
com.adobe.SwitchBoard
com.adobe.fpsaud
new-host:~ MacBookPro$ launchctl list | sed 1d | awk '!/0x|com\.apple|edu\.mit|org\.(x|openbsd)/{print $3}'
com.extensis.FMCore
com.avg.Antivirus
com.adobe.CS5ServiceManager
com.adobe.CS4ServiceManager
com.adobe.AdobeCreativeCloud
com.zeobit.MacKeeper.Helper
com.adobe.ARM.202f4087f2bbde52e3ac2df389f53a4f123223c9cc56a8fd83a6f7ae
com.adobe.AAM.Scheduler-1.0
Step 4
/Library/Components:
/Library/Extensions:
/Library/Frameworks:
AEProfiling.framework
AERegistration.framework
Adobe AIR.framework
AudioMixEngine.framework
EWSMac.framework
ExtensisPlugins.framework
NyxAudioAnalysis.framework
PluginManager.framework
TSLicense.framework
iTunesLibrary.framework
/Library/Input Methods:
/Library/Internet Plug-Ins:
AdobeAAMDetect.plugin
AdobeExManDetect.plugin
AdobePDFViewer.plugin
AdobePDFViewerNPAPI.plugin
Flash Player.plugin
Flip4Mac WMV Plugin.plugin
JavaAppletPlugin.plugin
Quartz Composer.webplugin
QuickTime Plugin.plugin
SharePointBrowserPlugin.plugin
SharePointWebKitPlugin.webplugin
Silverlight.plugin
SurveillanceClient.plugin
flashplayer.xpt
iPhotoPhotocast.plugin
npContributeMac.bundle
nsIQTScriptablePlugin.xpt
/Library/Keyboard Layouts:
/Library/LaunchAgents:
com.adobe.AAM.Updater-1.0.plist
com.adobe.AdobeCreativeCloud.plist
com.adobe.CS4ServiceManager.plist
com.adobe.CS5ServiceManager.plist
com.avg.Antivirus.gui.plist
com.extensis.FMCore.plist
/Library/LaunchDaemons:
com.adobe.SwitchBoard.plist
com.adobe.fpsaud.plist
com.avg.Antivirus.infosd.plist
com.avg.Antivirus.services.plist
com.microsoft.office.licensing.helper.plist
com.raynersw.nshctldo.plist
com.zeobit.MacKeeper.plugin.AntiTheft.daemon.plist
/Library/PreferencePanes:
Flash Player.prefPane
Flip4Mac WMV.prefPane
Microsoft Mouse.prefPane
/Library/PrivilegedHelperTools:
com.microsoft.office.licensing.helper
com.raynersw.nshctldo
/Library/QuickLook:
GBQLGenerator.qlgenerator
iBooksAuthor.qlgenerator
iWork.qlgenerator
/Library/QuickTime:
AppleIntermediateCodec.component
AppleMPEG2Codec.component
Flip4Mac WMV Advanced.component
Flip4Mac WMV Export.component
Flip4Mac WMV Import.component
SoundboothScoreCodec.component
/Library/ScriptingAdditions:
Adobe Unit Types.osax
/Library/Spotlight:
GBSpotlightImporter.mdimporter
Microsoft Office.mdimporter
iBooksAuthor.mdimporter
iWork.mdimporter
/Library/StartupItems:
/etc/mach_init.d:
/etc/mach_init_per_login_session.d:
/etc/mach_init_per_user.d:
com.adobe.SwitchBoard.monitor.plist
Library/Extensis:
Suitcase Fusion
com.extensis.FMCore-LaunchInfo.conf
Library/Fonts:
Library/Frameworks:
EWSMac.framework
Library/Input Methods:
.localized
Library/Internet Plug-Ins:
EMusic.plugin
RealPlayer Plugin.plugin
Library/Keyboard Layouts:
Library/LaunchAgents:
com.adobe.AAM.Updater-1.0.plist
com.adobe.ARM.202f4087f2bbde52e3ac2df389f53a4f123223c9cc56a8fd83a6f7ae.plist
com.zeobit.MacKeeper.Helper.plist
Library/PreferencePanes:
Step 5
iTunesHelper

know my webcam was hijacked at one point. I believe it was probably done through a website and not installed malware.
There is no known method for remotely accessing a modern Mac's webcam in this manner. Unless your Mac was one of a few specific models made in 2008 and earlier, which were found to have a webcam vulnerability, or unless you granted permission to a website that asked to access your webcam, it's not known to be possible to do what you say happened. A webcam hack would have to be delivered through malware or physical access to your Mac.
What specifically happened that makes you believe your webcam was accessed?
The most suspicious activity that I HAVE seen actually occur on my MacBook Pro was after coming back to my Mac from dinner and waking my Mac up from sleep there was a dialog box saying that my computer had been booted off the network and another computer had been added to the network
That sounds like a very common IP address conflict message, which occurs when one or more devices on your network are misconfigured. This is not indicative of any kind of hack, just a problem with the setup of your network. Probably, some device on your network is set to have a static IP address on your network, and that address is within the range of addresses reserved by the router to assign to devices that join the network. When your computer woke up, the router tried to assign it an address that should have been free, only to find that something was using it.
I believe I read that Maverick itself has a anti keylogger feature that scrambles all keys entered at the root level of the software to prevent a keylogger program from producing any readable output.
That's not something that I've ever heard of. I think you must have misinterpreted something, perhaps a story about address space layout randomization (ASLR), a security feature that randomizes data storage in RAM. ASLR has been in place in limited fashion in Mac OS X as far back as 10.5 (Leopard), and became system-wide in 10.8 (Mountain Lion). It would not protect you against a keylogger.
Mac OS X also has basic anti-malware protections built in, but that is also not new to Mavericks. See How does Mac OS X protect me?.
(Fair disclosure: The Safe Mac is my site, and contains a Donate button, so I may receive compensation for providing links to The Safe Mac. Donations are not required.)

Similar Messages

  • I followed previous keylogger detection instructions from an older post - how do I interpret the results that appeared in Terminal?

    I have a Macbook pro that I suspect my exhusband installed keylogger software on.  I followed the keylogger detection instructions posted on an older post, but I do not know how to interpret the Terminal results.  What should I be looking for in the strings that result?

    You don't have an off-the-shelf commercial keylogger installed. I can't rule out a well-hidden rootkit. That would only be possible If the attacker is a computer expert, or if he had help from an expert. If you suspect that, you'll either have to consult an expert yourself or (less expensively) erase your hard drive, reinstall OS X and all your other software from known-good copies, and restore only your documents and settings from a backup.
    I should add that there are hardware keyloggers on the market that don't install any software at all. The cheap ones can't be accessed remotely, but with enough money you can buy pretty much anything. A highly motivated attacker could plant listening devices in your home, your car, or your office.

  • Do i have i have a spyware/keylogg on my mac?

    I tried to download something from a "shady" site and all it was was a .rar file. I tried to open the file and it extracted it and nothin happened. So i thought it was a spyware/keylogg so i looked at another tread about how to check if you have it or not. I deleted the files but im not completly sure about if I have removed all of them or not. So if anyone of you could please help me out that would be much appreciated.
    Here are the terminal results:
    kextstat -kl | awk '!/com\.apple/{printf "%s %s\n", $6, $7}'
    sudo launchctl list | sed 1d | awk '!/0x|com\.(apple|openssh|vix)|edu\.mit|org\.(amavis|apache|cups|isc|ntp|postfi x|x)/{print $3}'
    Password:
    xxx.qnation.PeerGuardian.locum
    com.microsoft.office.licensing.helper
    com.anchorfree.ajaxserver
    com.adobe.fpsaud
    launchctl list | sed 1d | awk '!/0x|com\.apple|edu\.mit|org\.(x|openbsd)/{print $3}'
    com.valvesoftware.steamclean
    com.spotify.webhelper
    com.google.keystone.user.agent
    ls -1A /e*/mach* {,/}L*/{Ad,Compon,Ex,Fram,In,Keyb,La,Mail/Bu,P*P,Priv,Qu,Scripti,Servi,Spo,Sta} * L*/Fonts 2> /dev/null
    /Library/Components:
    /Library/Extensions:
    /Library/Frameworks:
    AEProfiling.framework
    AERegistration.framework
    AudioMixEngine.framework
    NyxAudioAnalysis.framework
    PluginManager.framework
    iTunesLibrary.framework
    /Library/Input Methods:
    /Library/Internet Plug-Ins:
    Flash Player.plugin
    JavaAppletPlugin.plugin
    Quartz Composer.webplugin
    QuickTime Plugin.plugin
    SharePointBrowserPlugin.plugin
    SharePointWebKitPlugin.webplugin
    Silverlight.plugin
    flashplayer.xpt
    nsIQTScriptablePlugin.xpt
    /Library/Keyboard Layouts:
    /Library/LaunchAgents:
    /Library/LaunchDaemons:
    com.adobe.fpsaud.plist
    com.anchorfree.ajaxserver.plist
    com.microsoft.office.licensing.helper.plist
    xxx.qnation.PeerGuardian.locum.plist
    /Library/PreferencePanes:
    Flash Player.prefPane
    /Library/PrivilegedHelperTools:
    com.microsoft.office.licensing.helper
    xxx.qnation.PeerGuardian.locum
    /Library/QuickLook:
    iBooksAuthor.qlgenerator
    iWork.qlgenerator
    /Library/QuickTime:
    AppleIntermediateCodec.component
    AppleMPEG2Codec.component
    /Library/ScriptingAdditions:
    /Library/Spotlight:
    Microsoft Office.mdimporter
    iBooksAuthor.mdimporter
    iWork.mdimporter
    /Library/StartupItems:
    /etc/mach_init.d:
    /etc/mach_init_per_login_session.d:
    /etc/mach_init_per_user.d:
    Library/Address Book Plug-Ins:
    SkypeABDialer.bundle
    SkypeABSMS.bundle
    Library/Fonts:
    Library/Input Methods:
    .localized
    Library/Internet Plug-Ins:
    Library/Keyboard Layouts:
    Library/LaunchAgents:
    com.apple.AddressBook.ScheduledSync.PHXCardDAVSource.8D0DC968-CF06-477D-81EC-5CB 5A7AA17D8.plist
    com.google.keystone.agent.plist
    com.spotify.webhelper.plist
    com.valvesoftware.steamclean.plist
    Library/PreferencePanes:
    osascript -e 'tell application "System Events" to get name of every login item' 2> /dev/null
    iTunesHelper, Skype, pploader, pplogger, Innholdsadministrator-assistent

    Based on the report, I can't tell you whether anything was installed or not. The only thing I saw that seemed out of the oridinary was "xxx.qnation.Peerguardian," if only because it might be related to risky sites..
    Read this thread. http://security.stackexchange.com/questions/30744/how-to-detect-keylogger-on-mac -os-x It's a little technical, but I don't think you want dumbed-down, inaccurate information on internet security. If you're looking for additional protection, I can recommend Little Snitch, an application that blocks anything from accessing your system without your approval. I use it every day.

  • Using firefox 14.0.1. Loading a link using right-click and "Open Link In New Window", results in new window opening but address bar does not show URL..

    Using firefox 14.0.1. Loading a link using right-click and "Open Link In New Window", results in new window opening but address bar does not show URL. However, if I right click on a link and select "Open Link In New Tab", the Tab shows URL in address bar. So it's working when it's a New Tab but not a New Window.

    The Reset Firefox feature can fix many issues by restoring Firefox to its factory default state while saving your essential information.
    Note: ''This will cause you to lose any Extensions, Open websites, and some Preferences.''
    To Reset Firefox do the following:
    #Go to Firefox > Help > Troubleshooting Information.
    #Click the "Reset Firefox" button.
    #Firefox will close and reset. After Firefox is done, it will show a window with the information that is imported. Click Finish.
    #Firefox will open with all factory defaults applied.
    Further information can be found in the [[Reset Firefox – easily fix most problems]] article.
    Did this fix your problems? Please report back to us!

  • Hi. I just got the iPhone 6, plugged into itunes and made the mistake of putting an OLD back up on my new phone resulting in losing all contacts after 2013. They are not saved on the cloud. Is there any way to go back to before I screwed up?

    Hi. I just got the iPhone 6, plugged into itunes and made the mistake of putting an OLD back up on my new phone resulting in losing all contacts after 2013. They are not saved on the cloud. Is there any way to go back to before I screwed up?

    If you have performed a sync with the device since you restored this old backup, then don't bother looking for another backup. iTunes writes over the last backup each time you sync. If you were handling contacts in iCloud, you would find them by logging into iCloud. Or you can check settings and iCloud and see if the button it on for Contacts. Otherwise it might have been on the computer, if you had a program that syncs with iTunes and handles contacts, depending on the computer system you use. If Windows, it would be Windows Contacts or Outlook. If a Mac, there is a Mac Address book as well.

  • Cisco Nac agent "List of Antivirus & Anti-Spyware Products Detected by the Agent "

    Hi All,
    We have posture assessment working with cisco Nac agent. Checking only symantec Antivirus def update and installation. Since there is windows defender in all the user pcs and turned off not in use. But cisco Nac agent is showing both windows defender and symantec in List of Antivirus & Anti-Spyware Products Detected by the Agent field. We dont want windows defender to show in this list.
    Anyone encountered this list before?? Please suggest.. I want to get rid of windows defender from this list in nac agent.

    Closest enhancement I could check on this is
    CSCts34764    NAC: Request for ANY rule to pass if 1 AS/AV definition is up to date
    Currently Windows Defender AnitSpyware comes installed on all Windows 7 machines.  Many users disable this and install their own AntiSpyware product.  Currently when using the ANY AntiSpyware up to date rule, it will fail if say MSE is up to date but not Windows Defender (since it is disabled).
    This is an enhancement request to add the ability to pass the ANY check if 1 AntiSpyware or AntiVirus definition is up to date but another is installed and out of date.  Currently if a customer wants to accomplish this they need to create a rule for every AntiVirus or AntiSpyware product and use the "Any Selected Rule Succeeds" option which is very cumbersome to configure.
    ~BR
    Jatin Katyal
    **Do rate helpful posts**

  • Opening new terminal in GNOME 3

    I ofter have a terminal window open in a 2nd workspace running ncmpc. So when I want to use the terminal for something else I'll hit Alt+F1 and click the terminal icon I've added as a favourite to the 'dock' on the left.
    What this does is take me to the 2nd workspace and present me with the already open terminal.
    I would like it if instead it opened a new terminal window in the current workspace to save me having to go Ctrl+Shift+N then Ctrl+Shift+Alt+arrow every time.

    jonnybarnes wrote:
    I ofter have a terminal window open in a 2nd workspace running ncmpc. So when I want to use the terminal for something else I'll hit Alt+F1 and click the terminal icon I've added as a favourite to the 'dock' on the left.
    What this does is take me to the 2nd workspace and present me with the already open terminal.
    I would like it if instead it opened a new terminal window in the current workspace to save me having to go Ctrl+Shift+N then Ctrl+Shift+Alt+arrow every time.
    I've binded 'gnome-terminal' command to my [ctrl + t] key combination so once I press [ctrl + t] new terminal window is launched on the current workspace.

  • New Terminal tab same ssh connection

    How do I open a new terminal tab so that it opens the same remote ssh connection as my current tab?

    ssh connections are a single process running in one shell, and when you create a new tab you are creating a new local shell that will not be running this process. Furthermore the remote server will not accept a duplicate connection from you without authentication. In essence, this is impossible to do. The closest thing you can do is make use of the bash history, and press the up arrow to scroll through your most recent commands until you get to the ssh command you used for your current connection, and then execute it.
    If the connection is a standard one you regularly use, then you can bookmark it in your .bashrc file by creating a function that points to it. For instance, the following in your .bashrc file would make a specific ssh connection be run by entering "myserver" at the command line:
    function myserver() {
         ssh username|password@hostname
    You can leave out the password option to have it prompt you for the password each time (it is also more secure to leave out the password).

  • How to launch a new terminal window from the current Finder folder?

    Hello. I would like to have something like "DOS prompt here" menu item on the Finder popup menu, so that when I click it a new Terminal window is open and set to the respective directory.
    Any ideas?

    I don't know of a way to do that... You might be able to use FruitMenu
    http://www.unsanity.com/haxies/fruitmenu
    and create a script to launch for the contextual menu that does what you want.
    I just open Terminal (by clicking the icon on the Dock), type "cd " and drag the icon of the folder I want to go to to the terminal window (and Return). It's a few steps but not that bad.

  • DSUGui, close and open in new terminal.

    I'm running an Upgrade and its on the Preprocessing stage, I started the DSUGui session (Software delivery tool) from my own PC, I need to move the session to a server so I can work via Remote Terminal Services.
    The Question is,
    Is it safe to simply Exit the DSUGui and Open it in a new terminal?... I have done this while in between phases but not while a phase is running and I wonder if its possible or if it will terminate the upgrade process?
    Regards
    Juan

    Well, I decided to wait until the end of the phase and then start the Downtime phace DSUGui on a different terminal.
    In theory as long as the SL Controller session is left untouched you should be able to open and close the DSUGui without issues. BUT I will try this on my next test session.
    Regards
    Juan

  • [bash] make command appear in new terminal window

    I have a bash command that uses aria2 to download something. The problem is that it download silently in the background. I want it to display in a new terminal window so I can see the download stats. How can I do this?

    urxvt -e "some_command" ?

  • Can I open new terminal window with the same path?

    Hello.
    I use Terminal for bash-shell.
    When I work at a certain directory, can i open new terminal(command + N) with the same directory?
    For example, when i am in /Developer and press command+N, I want a new terminal window with /Developer path.
    Thanks for reading and I'm sorry for my short english.

    Command-N will open a new Terminal window in your Home (~) Directory by default.
    Use the "Open Terminal Here" script for more control
    http://www.entropy.ch/software/applescript/

  • I am switching to a new computer.  Itunes doesn't detect my ipod

    I am swithching to a new computer and iTunes doesn't detect my iPod.  I have loaded iTunes on the computer along with all my music and play lists.  When I connect my Pod to the system, the computer recognizes it but iTunes doesn't.

    OK,  I was able to get iTunes o recognize my iPod touch using the following procedures:
    http://support.apple.com/kb/TS3716
    http://support.apple.com/kb/HT1923
    But, I can't sync the iPod to iTunes on the new computer.

  • After update new OS 10.10 can't detect camera

    after update new OS 10.10 can't detect camera

    Hi..
    Try the troubleshooting steps for the built in iSight camera here >  How to Troubleshoot iSight
    iWork software must be purchased from the App Store.

  • Setting up a global shortcut to open a new terminal window

    Alright, so, here's my idea. I would like a new terminal shell to open every time I press f7. I really like this idea, but i just can't get it to work. It would have to be a global shortcut, and i've tried it via the keyboard pane in preferences, but the closest thing I can get it to change the command "new shell" to f7. not quite what I want..... any ideas/help?
    Reposted from MacOSX Tiger forum - told to go here for better answers
    Also, I've tried iTerm, but it's got a ton more stuff that I don't need. And I've looked at visor but it requries simba (or something like that) and I heard a rumor that simba wasn't going to work with lepoard.

    I've thought about quicksilver, but i understand that's it's used to do much more than just that. And, I don't really want to deal with all of quicksilver. Now that might change, but I think I want to stay away from it for now.
    However, butler looks good. I'll play around with it.
    Also, the other application "Fast Scripts" looks decent, but it's shareware and I personally would like to get an entire program free and then donate when I feel props are due. (Just my personal thing.)

Maybe you are looking for

  • How to report on balance sheet accounts using 0EC_PCA_3

    Hi Experts, How to report on balance sheet accounts using 0EC_PCA_3 Thanks nagini

  • Log miner doesn't show all transactions on a table

    I'm playing a little with log miner on oracle 11gR2 on a 32bit CentOS Linux install, but it looks like it's not showing me all DML on my test table. Am I doing something wrong? Hi, there's my test case: - Session #1, create table and insert first row

  • How to determine the percentage of the function

    Hi all, CALL FUNCTION 'SAPGUI_PROGRESS_INDICATOR'     EXPORTING     percentage = 25       text = 'Please wait, data being retrieving..'. Here I  want percentage to forward as data is retrieved. For example if I want to put this code segment between a

  • Display Multiple Lines - Edit Window

    When a user presses CNTL-e to pop up the editor window for a varchar item, is there a way for the user to show his text string on multiple lines? If you hit carriage return, the window closes. If you hit the down arrow the cursor moves to the search

  • Windows 7 64bit or 32bit

    Hi all I've been mulling over this decsiion for a while now and its driving me nuts. I have to install Windows 7 on my mac for the purpose of game development. I'll be running things like Maya 10, Mudbox and the XNA famework. The question is: do I in