How do I get rid of Adobe flash update virus on Safari browser?

Hello. I've been having problems with a pop-up asking me to update my adobe flash player in my Safari browser. It blocks everything - and if I close it - it closes the entire site I was trying to reach. I know it's a virus/scam/malware because when I go to the adobe site, it says my flash is up to date.


This only occurs with the Safari browser - not with Chrome or firefox. I've tried using malwarebytes and Avast - and neither find the malware.


I've tried clearing my caches and that doesn't work either.


Does anyone have a solution?

MacBook Pro 13", macOS 10.13

Posted on Mar 4, 2020 11:50 PM

Reply
Question marked as Top-ranking reply

Posted on Mar 11, 2020 2:53 PM

Please follow this procedure to determine if the problem is isolated to your Mac, or lies elsewhere.


  1. Shut down your Mac.
  2. Load macOS Recovery by holding and r (two fingers) while you start your Mac with a third finger.
  3. When the macOS Utilities screen appears, release those two fingers.
  4. Choose Get Help Online.
  5. Safari will launch, but it will lack your bookmarks, favorites, history and other preferences.


Peruse your usual websites and determine if the phony pop-ups appear while using Safari in that mode. It probably won't.


If the problem does not occur in Recovery mode, but returns after restarting your Mac normally, please read If Safari is slow, stops responding, quits unexpectedly, or has other issues - Apple Support. The applicable section is likely to be "Remove Internet plug-ins and other add-ons" and the Support documents that follow "Learn more".


None of the Internet Plug-ins that appear in the report you posted are required for normal operation, so I suggest you remove all of them. For example, the Internet Plug-Ins, Input Methods, InputManagers, and ScriptingAdditions folders it describes in that Support document are either completely empty or absent on the Macs I typically use.


If you remain unable to resolve the problem, please write back.

37 replies
Question marked as Top-ranking reply

Mar 11, 2020 2:53 PM in response to madisonNYC

Please follow this procedure to determine if the problem is isolated to your Mac, or lies elsewhere.


  1. Shut down your Mac.
  2. Load macOS Recovery by holding and r (two fingers) while you start your Mac with a third finger.
  3. When the macOS Utilities screen appears, release those two fingers.
  4. Choose Get Help Online.
  5. Safari will launch, but it will lack your bookmarks, favorites, history and other preferences.


Peruse your usual websites and determine if the phony pop-ups appear while using Safari in that mode. It probably won't.


If the problem does not occur in Recovery mode, but returns after restarting your Mac normally, please read If Safari is slow, stops responding, quits unexpectedly, or has other issues - Apple Support. The applicable section is likely to be "Remove Internet plug-ins and other add-ons" and the Support documents that follow "Learn more".


None of the Internet Plug-ins that appear in the report you posted are required for normal operation, so I suggest you remove all of them. For example, the Internet Plug-Ins, Input Methods, InputManagers, and ScriptingAdditions folders it describes in that Support document are either completely empty or absent on the Macs I typically use.


If you remain unable to resolve the problem, please write back.

Mar 6, 2020 11:08 PM in response to madisonNYC

Please load EtreCheck from the Mac App Store.

That tool then provides us with the hardware and software configuration details.

Otherwise, we basically tell you how to execute the many commands that EtreCheck uses, one at a rime.

This would be a more detailed path and very much akin to what Patricia666 was following.

Poke around the forums for the (many) other times this EtreCheck tool has been used.

Wouldn’t surprise me to find an add-on cleaner, add-on anri-malware, add-on anri-virus, add-on VPN client, or such.

Some of those are problematic, and others are sketchy.

Or yes, generic adware.

Mar 6, 2020 10:21 PM in response to dominic23

Yes, those are the pop-ups that I'm seeing.

When I clear the library caches, it seems to get rid of them temporarily - especially in the morning.

But by evening, they're back again.

I've tried to force quit safari - and then re-open with the shift key down, and it doesn't change anything. The pop-up virus is still there.


I'm not familiar with etrecheck.com - so I don't feel comfortable downloading it. I already have one virus, with the Adobe Flash scam - so I don't want to risk downloading another one. (I don't see etrecheck in the Apple store).

Are there any other suggestions for permanently getting rid of this virus? If so, I would really appreciate any suggestions.

Mar 8, 2020 10:21 PM in response to MrHoffman

But if I do all of that, will it get rid of the adobe flash virus? I'm concerned that I'll do all of that - and the virus will still be there. :(


The reason I have the two anti-virus apps was to get rid of viruses and malware - and they actually worked in the past. But they didn't spot this one. ... Won't removing those two apps make me more vulnerable to malware?


Yes, it's an old MacBook Pro. But I love having all of the USB ports and SD card slot - which all of the newer models don't offer. (I'm not a fan of dongles - and I'd need lots of them in the newer models as I plug everything into my laptop - speakers, cameras, digital recorders, etc. ). ...... I increased my RAM a few years ago. (I think it's at the max now for this laptop). I know I'm going to have to bite the bullet and go with a newer model soon (since Apple excluded my laptop for the first time from the latest OS upgrade), but I'm hanging onto this one for as long as possible.

Mar 10, 2020 7:00 PM in response to MrHoffman

I removed Avast, Malwarebytes, Easy-WebPrint app, and other old Canon printer apps.

 

I'm not sure how to remove Java. When I do a search, there seems to be a lot of JavaScript files. Do I just move the JavaAppletPlugin.plugin into the trash? Will  deleting the plugin remove all of it?


I couldn't find anything called "Paragon" - so I don't know where to find it or how to upgrade it.


I kept Flash for now because I have needed it in the past for certain sites. But if you think it's related to the Flash update virus, then I'll delete it.


After all of this - the Flash Update virus is still there.

Mar 4, 2020 11:59 PM in response to madisonNYC

Have you tried the following steps to manually remove the redirection on your MAC?


1. Remove suspicious Login Items

Most malware will try to enable itself automatically when you log in to your mac.

a. Go to the Apple menu → System Preferences

b. Choose the Users & Groups section.

c. Make sure your username is highlighted. Open Login Items tab.

d. Choose any recently-added suspicious applications and use the "-" or minus sign to disable all the suspicious apps.

e. Restart your Mac for the changes to take place.


2. Remove malicious profiles

Some malware will install a malicious configuration profile that forced the home page of your browser.

Note: Profiles won't be visible until you have at least one profile installed. If there is none you may skip this step.

a. Go to the Apple menu → System Preferences

b. Click Profiles

c. Check if there is a profile named AdminPrefs or other profile you know that you did not set up on your Mac and delete it.


3. Stop potentially unwanted process running on your Mac

a. Go to Utilities and open Activity Monitor

b. Look for suspicious processes you are not familiar with.

c. Double click the process. A new window will appear, then click Quit. Click Force Quit on the confirmation message to stop the process.


4. Remove potentially unwanted applications from your "Applications" folder:

a. Open your applications folder : Click Go> Applications

b. Look for any recently-added suspicious applications and drag them to the Trash.


5. Remove malicious extensions on your browser.

For Safari

1. Launch Safari.

2. On the top Menu, click Safari. Then select Preferences.

3. Click the Extensions icon, and then uninstall any recently-added suspicious extensions you want to remove.


For Chrome

1. Launch Chrome.

2. Click the menu on the top right corner. Then click More Tools → Extensions

3. A new Tab for Chrome’s Extension will open. Look for any recently-added suspicious extensions you want to remove and click the remove button.


For Firefox

1. Launch Firefox

2. Click the Menu bar on the top right corner and then select Add-Ons.

3. A new tab for Firefox’s add-ons will appear. Select the Extensions Tab. Look for any recently-added suspicious add-ons you want to remove and click the remove button


6. Remove related files and folders.

To manually delete any recently-added suspicious files. Do the following:

a. Click Go > Go to Folder

b. Type the following locations below and click go. (One at a time)


Look for any recently-added suspicious files in these locations.

~/Library/ApplicationSupport

~/Library/Caches

~/Library/containers

~/Library/LaunchAgents

~/Library/Logs

~/Library/Preferences

~/Library/Webkit

/Library/ApplicationSupport

/Library/Caches

/Library/Frameworks

/Library/LaunchAgents

/Library/LaunchDaemons

/Library/Preferences

/Library/Logs

/Library/Webkit


Delete any recently-added suspicious files you want to delete by dragging and dropping it to Trash.


7. After you complete all the steps, please empty your trash and restart your Mac


Hope it helps!

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

How do I get rid of Adobe flash update virus on Safari browser?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.