macOS: Malware called “mshelper” is burning through CPU cycles, possibly as part of a crypto-mining scheme.
macOS:称为“ mshelper”的恶意软件正在整个CPU周期中燃烧,可能是作为加密挖掘方案的一部分。
Checking if you have the malware is easy: just open Activity Monitor and search for “mshelper.” Killing the process doesn’t do anything—it just opens again—but users have reported that running Etrecheck, which runs diagnostics and removes malware, gets rid of mshelper quickly. Alternatively you can manually delete two files:
检查您是否有恶意软件很容易:只需打开“活动监视器”并搜索“ mshelper”。 终止该进程无济于事-它只是再次打开-但用户报告说,运行Etrecheck (可运行诊断程序并删除恶意软件)可以Swift摆脱mshelper。 或者,您可以手动删除两个文件:
- /Library/LaunchDaemons/com.pplauncher.plist /Library/LaunchDaemons/com.pplauncher.plist
- /Library/Application Support/pplauncher /图书馆/应用支持/支持
Do that, then kill the process, and mshelper should be gone.
这样做,然后终止该进程,mshelper应该消失了。
The malware was noticed by users on Apple’s forums and on Reddit, but what is it actually doing? That part is not clear. Here’s Malcolm Owen, writing for Apple Insider:
苹果论坛和Reddit上的用户都注意到了该恶意软件,但实际上它在做什么呢? 那部分不清楚。 这是Malcolm Owen,为Apple Insider撰写:
It is unknown what exactly mshelper is doing to utilize the processor at such a high rate, but speculation on the Apple support forum suggests it could be some form of adware, or possibly a program used for mining cryptocurrency on a victim’s computer. Aside from using the processor, there also doesn’t seem to be any other issues it causes on affected desktops.
尚不清楚mshelper到底会如何以如此高的速度使用处理器,但苹果支持论坛上的猜测表明,它可能是某种形式的广告软件,或者可能是用于在受害者计算机上挖掘加密货币的程序。 除了使用处理器外,在受影响的台式机上似乎也没有引起任何其他问题。
Whatever the application is up to, you don’t want it. Remove it as soon as you notice it.
无论应用程序做什么,您都不需要它。 注意到它后立即将其删除。
翻译自: https://www.howtogeek.com/fyi/how-to-remove-mshelper-the-latest-mac-malware/