kcaloca

Q: Malware: Domain Error Assistant   Ebay Shopping Assistant

I got some kind of malware. I have tried numerous tutorials online to remove it completely. I'm at a loss. I delete the extensions from Chrome (and report them every time), but when I create a new Chrome profile they come back. So I know that there are remnants lurking in my files somewhere.

 

Please help!

MacBook Pro with Retina display, OS X El Capitan (10.11.2)

Posted on Dec 26, 2015 3:57 PM

Close

Q: Malware: Domain Error Assistant   Ebay Shopping Assistant

  • All replies
  • Helpful answers

Previous Page 2
  • by Linc Davis,Solvedanswer

    Linc Davis Linc Davis Dec 26, 2015 7:35 PM in response to kcaloca
    Level 10 (207,936 points)
    Applications
    Dec 26, 2015 7:35 PM in response to kcaloca

    You may have a compromised application. That happens with Firefox sometimes, but I haven't heard of it with Chrome. Please quit Chrome if it's running, then drag it from the Applications folder to the Trash and empty. Download a fresh copy directly from Google—nowhere else.

  • by kcaloca,

    kcaloca kcaloca Dec 26, 2015 6:49 PM in response to Linc Davis
    Level 1 (0 points)
    Dec 26, 2015 6:49 PM in response to Linc Davis

    Ok, I already tried that once - is there something I can do to get rid of ALL of the application data from Chrome? Because when I reinstalled everything was still there.

  • by Linc Davis,

    Linc Davis Linc Davis Dec 26, 2015 7:00 PM in response to kcaloca
    Level 10 (207,936 points)
    Applications
    Dec 26, 2015 7:00 PM in response to kcaloca

    Please back up all data.

    Triple-click the line below on this page to select it, then copy the text to the Clipboard by pressing the key combination  command-C:

    /Library/Application Support

    In the Finder, select

              Go Go to Folder...

    from the menu bar and paste into the box that opens by pressing command-V. You may not see what you pasted because a line break is included. Press return. A folder named "Application Support" should open. If it has a subfolder named "Google," please drag that subfolder—and only that one—to the Trash. You may be prompted for your password. Relaunch Chrome, empty the Trash, and test.

    If there's no change, you can restore the folder you deleted from a backup.

  • by kcaloca,

    kcaloca kcaloca Dec 26, 2015 7:09 PM in response to Linc Davis
    Level 1 (0 points)
    Dec 26, 2015 7:09 PM in response to Linc Davis

    Did everything. Restarted after emptying trash to be sure. Upon reinstall, previous Chrome settings are all still there - so of course, I create a new profile and same thing happens again.

     

    This is nasty malware!

  • by Linc Davis,

    Linc Davis Linc Davis Dec 26, 2015 7:14 PM in response to kcaloca
    Level 10 (207,936 points)
    Applications
    Dec 26, 2015 7:14 PM in response to kcaloca

    Please read this whole message before doing anything.

    This procedure is a test, not a solution. Don’t be disappointed when you find that nothing has changed after you complete it.

    Step 1

    The purpose of this step is to determine whether the problem is localized to your user account.

    Enable guest logins* and log in as Guest. Don't use the Safari-only “Guest User” login created by “Find My Mac.”

    While logged in as Guest, you won’t have access to any of your documents or settings. Applications will behave as if you were running them for the first time. Don’t be alarmed by this behavior; it’s normal. If you need any passwords or other personal data in order to complete the test, memorize, print, or write them down before you begin.

    Test while logged in as Guest. Same problem?

    After testing, log out of the guest account and, in your own account, disable it if you wish. Any files you created in the guest account will be deleted automatically when you log out of it.

    *Note: If you’ve activated “Find My Mac” or FileVault, then you can’t enable the Guest account. The “Guest User” login created by “Find My Mac” is not the same. Create a new account in which to test, and delete it, including its home folder, after testing.

    Step 2

    The purpose of this step is to determine whether the problem is caused by third-party system modifications that load automatically at startup or login, by a peripheral device, by a font conflict, or by corruption of the file system or of certain system caches.

    Please take this step regardless of the results of Step 1.

    Disconnect all wired peripherals except those needed for the test, and remove all aftermarket expansion cards, if applicable. Start up in safe mode and log in to the account with the problem.

    Note: If FileVault is enabled in OS X 10.9 or earlier, or if a firmware password is set, or if the startup volume is a software RAID, you can’t do this. Ask for further instructions.

    Safe mode is much slower to start up and run than normal, with limited graphics performance, and some things won’t work at all, including sound output and Wi-Fi on certain models. The next normal startup may also be somewhat slow.

    The login screen appears even if you usually log in automatically. You must know your login password in order to log in. If you’ve forgotten the password, you will need to reset it before you begin.

    Test while in safe mode. Same problem?

    After testing, restart as usual (not in safe mode) and verify that you still have the problem. Post the results of Steps 1 and 2.

  • by kcaloca,

    kcaloca kcaloca Dec 26, 2015 7:34 PM in response to Linc Davis
    Level 1 (0 points)
    Dec 26, 2015 7:34 PM in response to Linc Davis

    I actually found where I had not deleted ALL of my Chrome data and did that. Now I've reinstalled Chrome and the problem SEEMS to be gone.

     

    Thank you for your help.

  • by Linc Davis,

    Linc Davis Linc Davis Dec 26, 2015 7:49 PM in response to kcaloca
    Level 10 (207,936 points)
    Applications
    Dec 26, 2015 7:49 PM in response to kcaloca

    It might help others to know what data you hadn't deleted.

  • by kcaloca,

    kcaloca kcaloca Dec 26, 2015 7:51 PM in response to Linc Davis
    Level 1 (0 points)
    Dec 26, 2015 7:51 PM in response to Linc Davis

    When I followed your instructions to search for the Library folder, it didn't bring up the Library folder under my user account.

     

    When I went directly into Finder, clicked through my user account and into Library/Application Support, I found another Google folder with more Chrome settings in it.

  • by Linc Davis,

    Linc Davis Linc Davis Dec 26, 2015 8:01 PM in response to kcaloca
    Level 10 (207,936 points)
    Applications
    Dec 26, 2015 8:01 PM in response to kcaloca

    I see. Thanks.

     

    In that case, others who find this discussion should realize that it wasn't necessary to delete the Chrome application. Just make sure you follow Google's instructions to reset your Chrome profile. Don't look in the wrong Library folder—the one you can see in the Finder.

  • by thomas_r.,

    thomas_r. thomas_r. Dec 27, 2015 4:38 AM in response to kcaloca
    Level 7 (30,889 points)
    Mac OS X
    Dec 27, 2015 4:38 AM in response to kcaloca

    It sounds to me like Chrome is syncing those extensions across all profiles. When you are signed in to Google within Chrome, open Chrome's settings. At the very top of the settings will be a Sign In group. Click the Advanced Sync Settings there. You'll see something like this pop up:

     

    Screen Shot 2015-12-27 at 7.35.38 AM.png

     

    Make sure to deselect Extensions, then click OK. Then, if those Spigot extensions are still present, remove them using whatever technique you've been using to remove them. They should no longer be synced to new profiles.

  • by cvok,

    cvok cvok Sep 7, 2016 7:06 AM in response to Linc Davis
    Level 1 (9 points)
    iPhone
    Sep 7, 2016 7:06 AM in response to Linc Davis

    Wanted to confirm that Malware Bytes does remove the dirty part of the Malware, but the extensions in Chrome are terribly difficult to remove. Have gone through all steps here and they just kept returning.

     

    Confirming that the solution was to trash everything in ~/Library/Application Support/Google/Chrome

     

    The published "Solved" is incorrect.

Previous Page 2