Apple Event: May 7th at 7 am PT

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Safari "macros"?

MacBook Pro...2017....Ventura 13.0.1......


Keep getting weird "apps" when Safari shuts down: BridgePro, CargoVictory, Connectioninteractive, EssenceSkill, GrowthConnect, IdentityStack, ProgressBox, ProjectExpress, ProjectSet, SurveyGlide, TokenSource, TrulyClick, ValueFlip. I have deleted them before...but appear to return. Related to Safari? What's the deal?

iPhone 13 Pro, iOS 16

Posted on Mar 16, 2023 10:07 AM

Reply
Question marked as Best reply

Posted on Mar 16, 2023 11:47 AM

It sounds like some Malware got installed from a possible pop-up window, like the Update Flash Player pop up.

I would try running Malwarebytes on it. In my opinion don't use any of those Mac Cleaner or Clean My Mac apps. Malwarebytes is a free app that is commonly suggested on these boards as a safe way to remove malware. Here are some things you can also try:

  • Go to System Settings > Privacy & Security > Profiles. Remove any profiles you don't recognize.
  • Open Safari and go to Settings. Select the General tab and make sure the Home Page is the one that you expect.
  • Also in Safari Settings, select the Extension tab and uncheck any extensions you don't recognize. You also have the option to uninstall them.
  • Also in Safari Settings, select the Websites tab and scroll down to Notifications. Deny any notifications from websites that you are not familiar with.
  • Also in Safari Settings, select the Search tab and make sure it is set to Google or another known search engine.
  • If you have the ConnectionInteractive app in your Application folder, delete it.
  • There are also 4 locations malware will had in your system and launch after restart. For each of these locations, choose "Go" in the Finder menu bar (you may have to click the desktop to activate it), then "Go to Folder...". Put in each of the following locations into the field and hit return. You will want to look through these files for anything with the name of ConnectionInteractive, com.ConnectionInteractive.plist, installmac.AppRemoval.plist, myppes.download.plist, mykotlerino.ltvbit.plist, or com.myppes.net-preferences.plist and delete them. There are other names of bad actors that may show up here and my require some research before deleting them. Here are the 4 locations to put in the Go to Folder prompt:
  • /Library/LaunchAgents/
  • ~/Library/LaunchAgents/
  • /Library/Application Support/
  • /Library/LaunchDaemons/


8 replies
Question marked as Best reply

Mar 16, 2023 11:47 AM in response to Arrabon

It sounds like some Malware got installed from a possible pop-up window, like the Update Flash Player pop up.

I would try running Malwarebytes on it. In my opinion don't use any of those Mac Cleaner or Clean My Mac apps. Malwarebytes is a free app that is commonly suggested on these boards as a safe way to remove malware. Here are some things you can also try:

  • Go to System Settings > Privacy & Security > Profiles. Remove any profiles you don't recognize.
  • Open Safari and go to Settings. Select the General tab and make sure the Home Page is the one that you expect.
  • Also in Safari Settings, select the Extension tab and uncheck any extensions you don't recognize. You also have the option to uninstall them.
  • Also in Safari Settings, select the Websites tab and scroll down to Notifications. Deny any notifications from websites that you are not familiar with.
  • Also in Safari Settings, select the Search tab and make sure it is set to Google or another known search engine.
  • If you have the ConnectionInteractive app in your Application folder, delete it.
  • There are also 4 locations malware will had in your system and launch after restart. For each of these locations, choose "Go" in the Finder menu bar (you may have to click the desktop to activate it), then "Go to Folder...". Put in each of the following locations into the field and hit return. You will want to look through these files for anything with the name of ConnectionInteractive, com.ConnectionInteractive.plist, installmac.AppRemoval.plist, myppes.download.plist, mykotlerino.ltvbit.plist, or com.myppes.net-preferences.plist and delete them. There are other names of bad actors that may show up here and my require some research before deleting them. Here are the 4 locations to put in the Go to Folder prompt:
  • /Library/LaunchAgents/
  • ~/Library/LaunchAgents/
  • /Library/Application Support/
  • /Library/LaunchDaemons/


Mar 16, 2023 10:49 AM in response to Arrabon

If you just deleted the app for each of those items you probably left support files in the system that are still loading. You can check to see if you've removed all of the supporting files by downloading and running the shareware app Find Any File to search for any files with the application's or the developer's name in the file name.  For IdenityShack software you'd do the following search(es): 


1 - Name contains idenityshack


Any files that are found can be dragged from the search results window to the Desktop or Trash bin in the Dock for deletion.


FAF can search areas that Spotlight can't like invisible folders, system folders and packages.  


If you get the message that the file can't be deleted because it's being used the Boot into Safe Mode according to How to use safe mode on your Mac and delete from there.


Note:  if you have a wireless keyboard with rechargeable batteries connect it with its charging cable before booting into Safe Mode.  This makes it act as a wired keyboard as will assure a successful boot into Safe Mode.


In the future when you delete an app try using AppCleaner 


WARNING: If you use AppCleaner on an app that you have other apps from the same developer, like Adobe, you must be extremely careful checking all checkboxes and deleting.  Some for those files may support other apps from the same developer and deleting them can mess them up.  Adobe apps is a primary example. I know from experience.  For singular apps from a developer it's safe.


Mar 16, 2023 3:01 PM in response to Old Toad

Hmmmmm.... Not sure about that. It only appears when (or because) Safari shuts down...or it is what causes Safari to shut down... "It" seems to install these "macros"/malware each time....with different names: BridgePro, CargoVictory, Connectioninteractive, EssenceSkill, GrowthConnect, IdentityStack, ProgressBox, ProjectExpress, ProjectSet, SurveyGlide, TokenSource, TrulyClick, ValueFlip, etc....


I think some sort of malware is the answer...

Safari "macros"?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.