dochall

Q: Perfetnight

How do I get rid of this malware ?

MacBook Pro (15-inch Mid 2012), iOS 9.1

Posted on Oct 26, 2015 3:42 PM

Close

Q: Perfetnight

  • All replies
  • Helpful answers

Page 1 of 4 last Next
  • by OGELTHORPE,

    OGELTHORPE OGELTHORPE Oct 26, 2015 3:48 PM in response to dochall
    Level 9 (52,162 points)
    Mac OS X
    Oct 26, 2015 3:48 PM in response to dochall

    Try the suggestion made by the poster in this discussion:

     

    http://www.mac-forums.com/switcher-hangout/328946-perfetnight-app.html

     

    Ciao.

  • by Linc Davis,Helpful

    Linc Davis Linc Davis Oct 26, 2015 9:21 PM in response to dochall
    Level 10 (207,931 points)
    Applications
    Oct 26, 2015 9:21 PM in response to dochall

    You may have installed ad-injection malware ("adware").

    Don't use any kind of "anti-virus" or "anti-malware" product on a Mac. There is never a need for it, and relying on it for protection makes you more vulnerable to attack, not less.

    Some of the most common types of adware can be removed by following Apple's instructions. If those instructions don't work for you, or if you have trouble following them, see below.

    This easy procedure will detect any kind of adware that I know of. Deactivating it is a separate, and even easier, procedure that doesn't involve downloading anything.

    Some legitimate software is ad-supported and may display ads in its own windows or in a web browser while it's running. That's not malware and it may not show up. Also, some websites carry intrusive popup ads that may be mistaken for adware.

    If none of your web browsers is working well enough to carry out these instructions, restart the computer in safe mode. That will disable the malware temporarily.

    Step 1

    Please triple-click the line below on this page to select it, then copy the text to the Clipboard by pressing the key combination command-C:

    ~/Library/LaunchAgents

    In the Finder, select

              Go Go to Folder...

    from the menu bar and paste into the box that opens by pressing command-V. Press return. Either a folder named "LaunchAgents" will open, or you'll get a notice that the folder can't be found. If the folder isn't found, go to the next step.

    If the folder does open, press the key combination command-2 to select list view, if it's not already selected. Please don't skip this step.

    There should be a column in the Finder window headed Date Modified. Click that heading twice to sort the contents by date with the newest at the top. If necessary, enlarge the window so that all of the contents are showing.

    Follow the instructions in this support article under the heading "Take a screenshot of a window." An image file with a name beginning in "Screen Shot" should be saved to the Desktop. Open the screenshot and make sure it's readable. If not, capture a smaller part of the screen showing only what needs to be shown.

    Start a reply to this message. Drag the image file into the editing window to upload it. You can also include text in the reply.

    Leave the folder open for now.

    Step 2

    Do as in Step 1 with this line:

    /Library/LaunchAgents

    The folder that may open will have the same name, but is not the same, as the one in Step 1. As in that step, the folder may not exist.

    Step 3

    Repeat with this line:

    /Library/LaunchDaemons

    This time the folder will be named "LaunchDaemons."

    Step 4

    Open the Safari preferences window and select the Extensions tab. If any extensions are listed, post a screenshot. If there are no extensions, or if you can't launch Safari, skip this step.

    Step 5

    If you use the Firefox or Chrome browser, open its extension list and do as in Step 4.

  • by Fox Hunter,

    Fox Hunter Fox Hunter Oct 28, 2015 12:30 PM in response to Linc Davis
    Level 1 (0 points)
    Oct 28, 2015 12:30 PM in response to Linc Davis

    Schermata 2015-10-28 alle 20.08.31.png

  • by baileydanger,

    baileydanger baileydanger Nov 20, 2015 10:22 AM in response to Linc Davis
    Level 1 (0 points)
    Nov 20, 2015 10:22 AM in response to Linc Davis

    malware1.png

    I followed your directions in another post & sent all the files from Nov 16 to the trash, restarted the comp and then permanently deleted the files. Computer instantly sped up and all the popups disappeared. Thanks for the great advice Linc!

  • by trevisan44,

    trevisan44 trevisan44 Nov 23, 2015 6:07 PM in response to Fox Hunter
    Level 1 (0 points)
    Nov 23, 2015 6:07 PM in response to Fox Hunter

    Screen Shot 2015-11-23 at 6.05.05 PM.pngScreen Shot 2015-11-23 at 6.03.27 PM.pngScreen Shot 2015-11-23 at 5.56.11 PM.png

  • by trevisan44,

    trevisan44 trevisan44 Nov 23, 2015 6:14 PM in response to trevisan44
    Level 1 (0 points)
    Nov 23, 2015 6:14 PM in response to trevisan44

    Screen Shot 2015-11-23 at 5.56.11 PM.png

  • by Birdeyes,

    Birdeyes Birdeyes Nov 24, 2015 4:58 AM in response to Linc Davis
    Level 1 (0 points)
    Nov 24, 2015 4:58 AM in response to Linc Davis

    Thanks Linc for the great advice - I managed to install "Perfetnight" and "Advanced Mac Cleaner" (and thanks for the advice on AMC removal under that thread. All seems back to normality now. I had managed to install these by naïvely being fooled by a fake "adobe flash" updated in safari (and then running the "flash updater" installer on the dmg file downloaded and entering the admin password to allow the installation - less said about the silly error the better!).

     

    While following the instructions I noted hard drive and network activity and checked using Activity Monitor to find logmein items active or in the Launch Agent/Daemon etc folders. I have an old copy of the app on my had drive, but have not used logmein for a few years (now removed and deleted).

     

    Does anyone know if this malware has been transferring account passwords or deleting files or any other destructive activity or was it limited to advertising popups, altering homepage etc in web browsers only............or is there a possibility that account passwords etc have been transferred.

     

    Thanks again Linc for the excellent instructions.

     

    Screenshot 2015-11-24 11.22.44.png

  • by Lukasananas,

    Lukasananas Lukasananas Nov 24, 2015 6:43 AM in response to Linc Davis
    Level 1 (0 points)
    Nov 24, 2015 6:43 AM in response to Linc Davis

    thank you very much for your help

  • by NCVision,

    NCVision NCVision Nov 26, 2015 7:10 PM in response to Linc Davis
    Level 1 (0 points)
    Nov 26, 2015 7:10 PM in response to Linc Davis

    Screen Shot 2015-11-26 at 9.47.32 PM.png

  • by Grant Bennet-Alder,

    Grant Bennet-Alder Grant Bennet-Alder Nov 26, 2015 7:18 PM in response to NCVision
    Level 9 (60,749 points)
    Desktops
    Nov 26, 2015 7:18 PM in response to NCVision

    google keystone agent is legitimate.

     

    I think the rest are probably malware.

  • by HSites,

    HSites HSites Nov 29, 2015 9:15 PM in response to Linc Davis
    Level 1 (0 points)
    Nov 29, 2015 9:15 PM in response to Linc Davis

    Screen Shot 2015-11-29 at 10.12.09 PM.png

  • by Mojo4Sini,

    Mojo4Sini Mojo4Sini Dec 4, 2015 12:07 PM in response to Linc Davis
    Level 1 (0 points)
    Dec 4, 2015 12:07 PM in response to Linc Davis

    Screen Shot 2015-12-04 at 2.47.16 PM.png

  • by Mojo4Sini,

    Mojo4Sini Mojo4Sini Dec 4, 2015 12:08 PM in response to Mojo4Sini
    Level 1 (0 points)
    Dec 4, 2015 12:08 PM in response to Mojo4Sini

    Screen Shot 2015-12-04 at 3.05.58 PM.png

  • by nymythe,

    nymythe nymythe Dec 4, 2015 4:56 PM in response to Linc Davis
    Level 1 (0 points)
    Dec 4, 2015 4:56 PM in response to Linc Davis

    How does posting a screen shot of

    ~/Library/LaunchAgents

    fix the problem --what am I missing to this logic?

Page 1 of 4 last Next