rmal2814

Q: Virus on MacBook Air - Popups, links, and videos showing up where they aren't supposed to.. please help???

Virus on MacBook Air - popups everywhere, links and videos (that aren't supposed to be there) embedded in websites, tried Ghostery and ClamXav, also tried looking for Mac Defender in Activity Monitor, wasn't even there, but a bunch of other suspicious things were.. reading all these help forums, can't find solution - please help?? I think it started when I tried to download photoshop from a sketchy source

MacBook Air, OS X Mavericks (10.9.2)

Posted on Apr 18, 2014 11:56 AM

Close

Q: Virus on MacBook Air - Popups, links, and videos showing up where they aren't supposed to.. please help???

  • All replies
  • Helpful answers

  • by Allan Eckert,

    Allan Eckert Allan Eckert Apr 18, 2014 12:00 PM in response to rmal2814
    Level 9 (53,732 points)
    Desktops
    Apr 18, 2014 12:00 PM in response to rmal2814

    Mind sharing what you think are suspicious things?

  • by rmal2814,

    rmal2814 rmal2814 Apr 18, 2014 12:41 PM in response to Allan Eckert
    Level 1 (0 points)
    Apr 18, 2014 12:41 PM in response to Allan Eckert

    well it's hard to say because I'm no expert.. but here are some screen shots of what's running...

     

    Screen Shot 2014-04-18 at 12.13.31 PM.pngScreen Shot 2014-04-18 at 12.07.05 PM.png

  • by Allan Eckert,

    Allan Eckert Allan Eckert Apr 18, 2014 1:23 PM in response to rmal2814
    Level 9 (53,732 points)
    Desktops
    Apr 18, 2014 1:23 PM in response to rmal2814

    I don't see anything there to be concerned about.

     

    Do you have Geneio installed on your Mac?

     

    For direction to find out and to uninstall it, read http://www.thesafemac.com/arg-genieo/

     

    Allan

  • by Linc Davis,

    Linc Davis Linc Davis Apr 18, 2014 2:33 PM in response to rmal2814
    Level 10 (207,995 points)
    Applications
    Apr 18, 2014 2:33 PM in response to rmal2814

    You probably installed the "DownLite" trojan, perhaps under a different name. Remove it as follows.

    Malware is constantly changing to get around the defenses against it. The instructions in this comment are valid as of now, as far as I know. They won't necessarily be valid in the future. Anyone finding this comment a few days or more after it was posted should look for more recent discussions or start a new one.

      
    Back up all data.

    Triple-click anywhere in the line below on this page to select it:

    /Library/Application Support/VSearch

    Right-click or control-click the line and select

    Services Reveal in Finder (or just Reveal)

    from the contextual menu.* A folder should open with an item named "VSearch" selected. Drag the selected item to the Trash. You may be prompted for your administrator login password.

    Repeat with each of these lines:

    /Library/LaunchAgents/com.vsearch.agent.plist
    /Library/LaunchDaemons/com.vsearch.daemon.plist
    /Library/LaunchDaemons/com.vsearch.helper.plist
    /Library/LaunchDaemons/Jack.plist
    /Library/PrivilegedHelperTools/Jack
    /System/Library/Frameworks/VSearch.framework

    Some of these items may be absent, in which case you'll get a message that the file can't be found. Skip that item and go on to the next one.

    Restart and empty the Trash. Don't try to empty the Trash until you have restarted.

    From the Safari menu bar, select

    Safari Preferences... Extensions

    Uninstall any extensions you don't know you need, including any that have the word "Spigot" in the description. If in doubt, uninstall all extensions. Do the equivalent for the Firefox and Chrome browsers, if you use either of those.

    This trojan is distributed on illegal websites that traffic in pirated movies. If you, or anyone else who uses the computer, visit such sites and follow prompts to install software, you can expect much worse to happen in the future.

    You may be wondering why you didn't get a warning from Gatekeeper about installing software from an unknown developer, as you should have. The reason is that the DownLite developer has a codesigning certificate issued by Apple, which causes Gatekeeper to give the installer a pass. Apple could revoke the certificate, but as of this writing, has not done so, even though it's aware of the problem. It must be said that this failure of oversight is inexcusable and has seriously compromised the value of Gatekeeper and the Developer ID program. You cannot rely on Gatekeeper alone to protect you from harmful software.

    *If you don't see the contextual menu item, copy the selected text to the Clipboard by pressing the key combination  command-C. In the Finder, select

    Go Go to Folder...

    from the menu bar and paste into the box that opens by pressing command-V. You won't see what you pasted because a line break is included. Press return.

  • by rmal2814,

    rmal2814 rmal2814 Apr 18, 2014 4:13 PM in response to Linc Davis
    Level 1 (0 points)
    Apr 18, 2014 4:13 PM in response to Linc Davis

    Thanks for the info, I'm sure it will help a lot of people but it didn't seem to be the issue on my computer, when I right-click on the selected text and "reveal in finder", it tells me: The operation can’t be completed because the item can’t be found.

     

    I tried this on each line, twice

     

    Just to give you more info... Here is a screen shot of just one example of what's happening when I'm on this website: http://support.apple.com/kb/HT4650

     

    Screen Shot 2014-04-18 at 3.59.35 PM.png

     

    You'll see that several words have become microlinks, and when I hover over them, it's an ad not related to apple or the forum at all.  And on the bottom right, is a pop-up ad that is continuously popping in!!  And on facebook, I am getting actual short videos or gif's showing up when viewing my photos, or other people's photos, on the right-hand side. Usually it's an ad for a video game.  This is definitely not normal.. I've used Macs for 10 years and never had a problem like this...

  • by Linc Davis,Solvedanswer

    Linc Davis Linc Davis Apr 18, 2014 4:54 PM in response to rmal2814
    Level 10 (207,995 points)
    Applications
    Apr 18, 2014 4:54 PM in response to rmal2814

    That's the "GoPhoto" trojan. It's an extension for Safari and Chrome, and an add-on for Firefox. Remove it from the first two, and if you use Firefox see below.

     

    Remove gophoto.it | Firefox Support Forum

  • by rmal2814,

    rmal2814 rmal2814 Apr 20, 2014 11:17 AM in response to Linc Davis
    Level 1 (0 points)
    Apr 20, 2014 11:17 AM in response to Linc Davis

    THANK YOU!!! That was it.. thought it'd be way more complicated as the ads were EVERYWHERE but that seems to have done that trick.

  • by JWMSales,

    JWMSales JWMSales Sep 14, 2014 6:11 PM in response to Linc Davis
    Level 1 (0 points)
    iCloud
    Sep 14, 2014 6:11 PM in response to Linc Davis

    This worked perfectly for me. Thanks.

  • by dlhj.harkins,

    dlhj.harkins dlhj.harkins Oct 8, 2014 9:56 PM in response to Linc Davis
    Level 1 (0 points)
    Oct 8, 2014 9:56 PM in response to Linc Davis

    Linc Davis, THAT WORKED. As of October 8th 2014, almost midnight, LINC DAVIS's first suggestion worked like a charm.

     

    I've had this laptop for all of THREE months, from Day 1 it was giving me multiple pop up ads. I got used to closing them over and over, but I was literally closing ads EVERY SINGLE time I opened a new page. If I clicked anywhere, a new tab would open with MacKeeper and MacBook Lock and Wix and Purifier, just to name a few.... On Amazon, windows popped open the minute the page loaded, one large on on the far right, all the way to the bottom of the page, one price comparison ad that ran across the bottom, and then a very slow and LOUD video ad that creeped up on the far left. That's just Amazon. Don't get me started on all the other ones. If I went to Victoria's Secret to do some shopping, it would open new tabs with ****. It was like living an unfathomable embarrassing nightmare, letting my mom look at it to try and fix it. Luckily, no naked people showed up that time, but she (who is a computer genius, underneath her mother/housewife hat) was so overwhelmed with the ads, and couldn't find anything else (that I hadn't already tried) that would fix it.

     

    I didn't find anything about GoPhoto anywhere, but I found almost all of those "VSearch" in my Library. And swiftly deleted them away with a vengeance. Thank you Linc Davis for saving the lives of myself, my children, and my computer. I will watch Netflix WITHOUT closing a pop-up and having to reopen the fullscreen mode every. fifteen. minutes.

     

    Excuse the dramatic emphasis. You'd be happy too.

  • by ChikaChikaGhost,

    ChikaChikaGhost ChikaChikaGhost Oct 20, 2014 8:28 AM in response to Linc Davis
    Level 1 (0 points)
    Oct 20, 2014 8:28 AM in response to Linc Davis

    Totally worked for me, thanks a lot!

  • by mahasoli,

    mahasoli mahasoli Apr 9, 2015 11:07 AM in response to dlhj.harkins
    Level 1 (0 points)
    Apr 9, 2015 11:07 AM in response to dlhj.harkins

    I have similar problem , can you please explain again how to fix it.