Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

scottvd

macrumors newbie
Original poster
Dec 6, 2017
3
0
Hi, I'm working on a Mac that may have a keylogger installed on it. In the Activity Monitor on the Energy tab I saw four suspicious applications. One without a name which was not active. Two others running under root called Processor and Main Service. Another called SoftUtil. I did a sample data from the Main Service app to determine its path and that looks super suspicious. Any ideas what I got here? I ran Mac Scan and it came back clean.
Thanks in advance.

activity_monitor.png
sample.png
 

dianeoforegon

macrumors 6502a
Apr 26, 2011
907
137
Oregon
Download "MalwareBytes Anti-Malware for Mac":
https://www.malwarebytes.com/mac/

- the download is free
- it will "invite you" to register for the paid version -- YOU DO NOT HAVE TO DO THIS
- after 30 days, the downloaded "pay/demo" version automatically reverts to the free version.

Download EtreCheck. Etrecheck is a diagnostic tool recommended by Apple Support personnel. This is similar to Apple's System Profiler but has more info that can diagnosis issues on your Mac.

http://www.etresoft.com/etrecheck

More Info on Etrecheck
https://discussions.apple.com/docs/DOC-11591
 
  • Like
Reactions: Marc_S

scottvd

macrumors newbie
Original poster
Dec 6, 2017
3
0
Download "MalwareBytes Anti-Malware for Mac":
https://www.malwarebytes.com/mac/

- the download is free
- it will "invite you" to register for the paid version -- YOU DO NOT HAVE TO DO THIS
- after 30 days, the downloaded "pay/demo" version automatically reverts to the free version.

Download EtreCheck. Etrecheck is a diagnostic tool recommended by Apple Support personnel. This is similar to Apple's System Profiler but has more info that can diagnosis issues on your Mac.

http://www.etresoft.com/etrecheck

More Info on Etrecheck
https://discussions.apple.com/docs/DOC-11591

Thanks, I'll run that scan. I installed EaseMon Cloud (keylogger app) on a test Mac and neither MacScan nor MalwareBytes found it. And it's most certainly there working. :/
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.