ychirea1

Q: Downloaded something called InKeepr and it is impossible to remove from my Mac, please help. There is nothing out there about this!

I downloaded something by mistake from a site called InKeepr and now I can't get it off of my Mac. I am afraid to go back to the site for help uninstalling it because it is obviously malicious. What is odd is that I can't find anything about this. Please check this out for me. It has infected all of my browsers when I open them it opens to InKeeper browser. Please help. thanks!

MacBook Pro, OS X Yosemite (10.10.3)

Posted on Jun 3, 2015 10:46 AM

Close

Q: Downloaded something called InKeepr and it is impossible to remove from my Mac, please help. There is nothing out there about this ... more

  • All replies
  • Helpful answers

Previous Page 2 of 7 last Next
  • by marcomillions,

    marcomillions marcomillions Jun 12, 2015 12:20 AM in response to J.Create
    Level 1 (10 points)
    Jun 12, 2015 12:20 AM in response to J.Create

    Thank you J Create. I was able to use your strategem to trash ol' InKeepr. (The L Davis method seemed far too daunting for me.) Two brief notes: (1)  InKeeor didn't show up (ever) in the CPU monitor, nor in the Memory. But it did turn up in the Energy monitor.  (2) For those who, like me, have never looked at Activity Monitor for any other purpose than idle curiosity, the way you "Select Quit" for Inkeer is: (a) When you find InKeepr in one of the monitored streams, click on it. (b) Then, choose the left-hand-most of the three icons to the left of the monitor choices (CPU, Memory, Energy, etc.)--it is a circle with an "x" in the middle. Click  it. You'll be asked if you really want to force that process to quit. Answer "You **** betcha." "Yes" will do.]

  • by artcamp,

    artcamp artcamp Jun 13, 2015 8:01 AM in response to ychirea1
    Level 1 (0 points)
    Jun 13, 2015 8:01 AM in response to ychirea1

    i pasted the text of my results and the reply to this download was not functioning (i was signed in)

  • by artcamp,

    artcamp artcamp Jun 13, 2015 8:03 AM in response to Linc Davis
    Level 1 (0 points)
    Jun 13, 2015 8:03 AM in response to Linc Davis

    i pasted the text of my results and the reply to this download was not functioning (i was signed in)

  • by Linc Davis,Helpful

    Linc Davis Linc Davis Jun 13, 2015 8:24 AM in response to Linc Davis
    Level 10 (207,963 points)
    Applications
    Jun 13, 2015 8:24 AM in response to Linc Davis

    As others are finding this thread, I'll post instructions for removing this malware.

    You installed a variant of the "InstallMac" trojan. Take the steps below to disable it.

    The criminal behind this attack tries to make the malware difficult to remove by varying the names of the files it installs. This procedure works as of now, as far as I know. It may not work in the future. Anyone finding this comment a few days or more after it was posted should look for a more recent discussion, or start a new one.

    Back up all data before continuing.

    1. Triple-click the line below on this page to select it, then copy the text to the Clipboard by pressing the key combination command-C:

    ~/Library/LaunchAgents

    In the Finder, select

              Go Go to Folder...

    from the menu bar and paste into the box that opens by pressing command-V. You won't see what you pasted because a line break is included. Press return. A folder named "LaunchAgents" will open.

    2. Inside the folder you just opened, there may files with a name of the form

              something.download.plist

              something.ltvbit.plist

              something.update.plist

    where something is usually a meaningless string, such as "InKeepr," "Listchack," "Oliverto," or "Texiday." It could be anything.

    Move all such items to the Trash. There may not be any other files in the LaunchAgents folder; in that case, you can delete the folder, but otherwise don't delete it.

    Log out or restart the computer. The trojan will now be inactive, but there are a few more components of it that should be cleaned up.

    3. Open this folder in the same way as above:

    ~/Library/Application Support

    and move to the Trash any subfolders named with the same something you found in Step 2.

    Don't move the Application Support folder or anything else inside it.

    4. Open the Applications folder. If there is an item with the same name as in Step 3, or any of the other names listed in Step 2, drag it to the Trash.

    If in doubt, press the key combination option-command-4 to arrange the apps by date added. Look at the apps that have been added since you first noticed the problem. If there is one you don't recognize, drag it to the Trash.

    Empty the Trash.

    5. From the Safari menu bar, select

              Safari Preferences... Extensions

    Uninstall all extensions you don't know you need. If in doubt, remove all of them. None is required for normal operation. Do the equivalent in the Chrome and Firefox browsers, if you use either of those.

    6. Reset the home page in each of your browsers, if it was changed. In Safari, first load the home page you want, then select

              Safari Preferences... General

    and click

              Set to Current Page

  • by artcamp,

    artcamp artcamp Jun 13, 2015 8:27 AM in response to marcomillions
    Level 1 (0 points)
    Jun 13, 2015 8:27 AM in response to marcomillions

    J Create's method didn't work for me, so i tried the L Davis method. per instructed i tried pasting the results of my test in reply to this post, but got an error message. thanks for your help with this

  • by artcamp,

    artcamp artcamp Jun 13, 2015 8:47 AM in response to Linc Davis
    Level 1 (0 points)
    Jun 13, 2015 8:47 AM in response to Linc Davis

    thank you, thank you! this worked. and to think i was just saying, "my mac really doesn't get any viruses...." i should have knocked on wood.

  • by stevejobsfan0123,

    stevejobsfan0123 stevejobsfan0123 Jun 13, 2015 8:50 AM in response to artcamp
    Level 8 (43,718 points)
    iPhone
    Jun 13, 2015 8:50 AM in response to artcamp

    artcamp wrote:

     

    to think i was just saying, "my mac really doesn't get any viruses...."

    It doesn't. Genieo is just obnoxious adware. There are no viruses affecting OS X.

  • by artcamp,

    artcamp artcamp Jun 13, 2015 9:31 AM in response to stevejobsfan0123
    Level 1 (0 points)
    Jun 13, 2015 9:31 AM in response to stevejobsfan0123

    thanks for setting me straight on that. i can keep on boasting

  • by stevejobsfan0123,

    stevejobsfan0123 stevejobsfan0123 Jun 13, 2015 9:49 AM in response to artcamp
    Level 8 (43,718 points)
    iPhone
    Jun 13, 2015 9:49 AM in response to artcamp

    You are welcome.

  • by D Volkman,

    D Volkman D Volkman Jun 13, 2015 4:25 PM in response to Linc Davis
    Level 1 (0 points)
    Jun 13, 2015 4:25 PM in response to Linc Davis

    This solution did the trick for me.  Thanks.

    I got this "InKeeper" when I was on the website: SourceForge.net

     

     

     

    Ref:  Linc Davis        Jun 13, 2015 8:24 AM

  • by Linc Davis,

    Linc Davis Linc Davis Jun 13, 2015 5:12 PM in response to D Volkman
    Level 10 (207,963 points)
    Applications
    Jun 13, 2015 5:12 PM in response to D Volkman

    "SourceForge" has become a full-blown rogue site that intentionally distributes malware. It should not be visited for any reason. Nothing downloaded from the site is to be trusted.

  • by mcuthrie,

    mcuthrie mcuthrie Jun 13, 2015 10:40 PM in response to Linc Davis
    Level 1 (0 points)
    Jun 13, 2015 10:40 PM in response to Linc Davis

    Thank you very much for the attention to this and helping me/us remove it. The first set of instructions you provided on the other page had me lost. I was able to kill the app in activity monitor and then trash. I then was able to go to the launch agents folder and trash the obvious bad files. As you said, all my browsers got hijacked with the inkeepr home page and extension (chrome, safari, firefox). That is all clean now. I hope I never hear of this again, thanks so much.

  • by BLB2012,

    BLB2012 BLB2012 Jun 13, 2015 11:31 PM in response to J.Create
    Level 1 (0 points)
    Jun 13, 2015 11:31 PM in response to J.Create

    J.Create,

     

    I have done what you have said until moving the Innkeepr icon to the trash.  It tells me that I cannot move it there because it is open, so do you have any ideas as to what to do next?

  • by marcomillions,

    marcomillions marcomillions Jun 13, 2015 11:58 PM in response to Linc Davis
    Level 1 (10 points)
    Jun 13, 2015 11:58 PM in response to Linc Davis

    Thank you for this additional advice about how to get rid of the unseen bits.

  • by BLB2012,

    BLB2012 BLB2012 Jun 14, 2015 12:33 AM in response to BLB2012
    Level 1 (0 points)
    Jun 14, 2015 12:33 AM in response to BLB2012

    Thanks for your help J.Crew, I did it.  Yeah!!!!

Previous Page 2 of 7 last Next