gingertodd

Q: Safari in Lion hijacked by malware

I hope someone can help...

 

I have the new Lion operating system and was in Safari this morning trying to find a game for my son to play. I clicked on a site and I got a pop up window from www.theconsumerwinner.com telling me to answer a survey...only option was to click ok. I did not...I force quit Safari instead. When I restarted Safari the website and popup comes back and has basically hijacked my safari. I cannot get into any of Safari's menu options...even help.

 

I went into the Safari folder and deleted the history from today, but it's still there. How can I get rid of this? I love my Safari...luckily I have Firefox installed for a work program, so I'm using it for now.  I want my Safari back though...

 

Please help.

 

Thank you!

MacBook Pro

Posted on Jul 27, 2011 9:30 AM

Close

Q: Safari in Lion hijacked by malware

  • All replies
  • Helpful answers

Page 1 of 3 last Next
  • by Carolyn Samit,

    Carolyn Samit Carolyn Samit Jul 27, 2011 12:02 PM in response to gingertodd
    Level 10 (124,699 points)
    Apple Music
    Jul 27, 2011 12:02 PM in response to gingertodd

    Quit Safri.

     

    Open a Finder window. Select your Home folder in the Sidebar on the left. It has a small house icon.

     

    Now open the Library folder then the Safari folder.

     

    Move these files from the Safari folder to the Trash.

     

    Downloads.plist

     

    History.plist

     

    HistoryIndex.sk

     

    LastSession.plist

     

    TopSites.plist

     

    WebpageIcons.db

     

    Empty the Trash. Relaunch Safari.

     

    See if that helped.

     

    FYI. Some game sites do contain malware. Instead of playing games on a site or downloading games using Safari, use the Mac App Store instead. Lots of games available there. You can access the App Store from your Apple menu, your Dock, or your Applications folder.

  • by gingertodd,

    gingertodd gingertodd Jul 27, 2011 2:23 PM in response to Carolyn Samit
    Level 1 (0 points)
    Jul 27, 2011 2:23 PM in response to Carolyn Samit

    Thank you for responding, but this didn't fix the problem. Is there a reputable anti-virus download for Mac?

  • by Klaus1,

    Klaus1 Klaus1 Jul 27, 2011 3:30 PM in response to gingertodd
    Level 8 (48,918 points)
    Jul 27, 2011 3:30 PM in response to gingertodd

    You have acquired either a flash cookie or a tracker cookie.

     

    For those who do not know about Flash cookies, more properly referred to as Local Shared Objects (LSO), they operate in a similar way to regular browser cookies but are stored outside the purview of your browser, meaning you cannot delete them from within your browser, whether Safari, Firefox, Opera or any other. Typically they are issued from sites or 3rd party sites that contain Adobe Flash content. Since virtually all internet advertising is delivered in Flash, Google/Doubleclick and all other internet advertising companies are sure to be tracking your browsing behavior with Flash cookies. These companies can see you traverse the Internet as you come upon the plethora of sites that contain their embedded advertising. Check out the Wikipedia entry here.

    In Mac OS X they are stored in the following location:
    /User’s Home Folder/Library/Preferences/Macromedia/Flash Player/#SharedObjects

    The settings for the Flash cookies are stored in:
    /User’s Home Folder/Library/Preferences/Macromedia/Flash Player/macromedia.com/support/flashplayer/sys

    In OS X Local Shared Objects, or Flash Cookies, are appended with a .sol suffix. Flush deletes all the Flash cookies (.sol) and their settings.

     

    Flush can be downloaded from this website:

     

    http://machacks.tv/2009/01/27/flushapp-flash-cookie-removal-tool-for-os-x/

    .

    If you want to retain certain Flash cookies but not others, the excellent add-on for Safari called SafariCookies  does just that:

     

    http://www.sweetpproductions.com/safaricookies/index.htm

     

    which not only does that but much more equally useful stuff!

     

    This article covers the issue in more depth:

     

    http://www.wired.com/epicenter/2009/08/you-deleted-your-cookies-think-again/

     

    Flash cookies are also known as 'Zombie Cookies' and are used by a number of firms, including Hulu, MTV, and Myspace. Graham Cluley, senior technology consultant at the internet security firm Sophos, told BBC News that the source of the trouble was Adobe Flash itself, which he called "one of the weirdest programs on the planet".

     

    "I think it's highly unlikely that these large companies have abused Flash cookies - which are different from browser cookies - with malicious intent," he said.

     

    "I think it's much more likely that the vast majority of users are simply oblivious to the bizarre way in which Adobe allows them to configure the software."

     

    http://www.bbc.co.uk/news/technology-10787882

     

    And a more recent article:

     

    http://www.nytimes.com/2010/09/21/technology/21cookie.html?_r=3&scp=1&sq=flash&s t=cse

     

    For other tracker cookies:

     

    If you allow a Trojan to be installed, the user's DNS records can be modified, redirecting incoming internet traffic through the attacker's servers, where it can be hijacked and injected with malicious websites and pornographic advertisements. The trojan also installs a watchdog process that ensures the victim's  (that's you!)  DNS records stay modified on a minute-by-minute basis.

     

    You can read more about how, for example, the OSX/DNSChanger Trojan works (by falsely suggesting extra codecs are required for Quicktime) here:

     

    http://www.f-secure.com/v-descs/trojan_osx_dnschanger.shtml

     

    SecureMac has introduced a free Trojan Detection Tool for Mac OS X.  It's available here:

     

    http://macscan.securemac.com/

     

    First update the MacScan malware definitions before scanning. You can also contact their support team for any additional support - macsec@securemac.com [/b]

     

    The DNSChanger Removal Tool detects and removes spyware targeting Mac OS X and allows users to check to see if the trojan has been installed on their computer; if it has, the software helps to identify and remove the offending file. After a system reboot, the users' DNS records will be repaired.

     

    (Note that a 30 day trial version of MacScan can be downloaded free of charge from:

     

    http://macscan.securemac.com/buy/

     

    and this can perform a complete scan of your entire hard disk. After 30 days free trial the cost is $29.99. The full version permits you to scan selected files and folders only, as well as the entire hard disk. It will detect (and delete if you ask it to) all 'tracker cookies' that switch you to web sites you did not want to go to.)

     

    VIRUSES

     

    No viruses that can attack OS X have so far been detected 'in the wild', i.e. in anything other than laboratory conditions.

     

    It is possible, however, to pass on a Windows virus to another Windows user, for example through an email attachment. To prevent this all you need is the free anti-virus utility ClamXav, which you can download for Tiger and Leopard (check with them about Lion) from:

     

    http://www.clamxav.com/

     

    The new version for Snow Leopard is available here:

     

    http://www.clamxav.com/index.php?page=v2beta

     

    Note: ClamAV adds a new user group to your Mac. That makes it a little more difficult to remove than some apps. You’ll find an uninstaller link in ClamXav’s FAQ page online.

     

    If you are already using ClamXav: please ensure that you have installed all recent  Apple Security Updates  and that your version of ClamXav is the latest available.

     

    Do not install Norton Anti-Virus on a Mac as it can seriously damage your operating system. Norton Anti-Virus is not compatible with Apple OS X.

  • by Carolyn Samit,

    Carolyn Samit Carolyn Samit Jul 27, 2011 3:29 PM in response to gingertodd
    Level 10 (124,699 points)
    Apple Music
    Jul 27, 2011 3:29 PM in response to gingertodd
  • by gingertodd,

    gingertodd gingertodd Jul 27, 2011 3:44 PM in response to Klaus1
    Level 1 (0 points)
    Jul 27, 2011 3:44 PM in response to Klaus1

    Thank you very much! I wondered if it had anything to do with cookies. I've downloaded and ran VirusBarrier Plus from the App store and it's saying I'm clean, but I still can't run Safari without this problem.

     

    I'll try your suggestions and let you know what happens.

     

    Thanks again!

  • by ~Bee,

    ~Bee ~Bee Jul 27, 2011 4:37 PM in response to gingertodd
    Level 7 (31,802 points)
    Mac OS X
    Jul 27, 2011 4:37 PM in response to gingertodd

    Ginger, please read this thread, and let us know if this looks like your error screen.

    https://discussions.apple.com/thread/3198419?tstart=0

     

     

    Also -- The HOME > Library folder is now hidden.

    Helpers that have standard information will want to go back and update their material to include how to access the hidden Users library.

  • by powerbook1701,

    powerbook1701 powerbook1701 Jul 27, 2011 7:41 PM in response to ~Bee
    Level 3 (571 points)
    iWork
    Jul 27, 2011 7:41 PM in response to ~Bee

    The latest version of Adobe flash player now puts a system preference in your system preferences folder for the flash player..including a simple way to delete all flash cookies (which, as you know doesn't clear via Safari's reset in version 505).

     

    ClamXav is a GREAT peice of software!

  • by Badunit,Solvedanswer

    Badunit Badunit Jul 27, 2011 8:06 PM in response to gingertodd
    Level 6 (11,705 points)
    iTunes
    Jul 27, 2011 8:06 PM in response to gingertodd

    If you are opening Safari by clicking on its icon in the dock, hold down shift when you click on it. 

     

    I had a site hijack me the same way. After force quitting Safari, this was how I got it to go away.

  • by Tony the Bald Eagle,

    Tony the Bald Eagle Tony the Bald Eagle Jul 28, 2011 3:36 AM in response to Badunit
    Level 1 (0 points)
    Jul 28, 2011 3:36 AM in response to Badunit

    Wow!

     

    I had the same issue (https://discussions.apple.com/thread/3198419?tstart=0) & your tip worked.  No idea how or why it worked, but it did.

     

    You're a star!

     

    Thanks

     

    Tony

  • by gingertodd,

    gingertodd gingertodd Jul 28, 2011 6:51 AM in response to Tony the Bald Eagle
    Level 1 (0 points)
    Jul 28, 2011 6:51 AM in response to Tony the Bald Eagle

    Wow...THANK YOU!!!!!  I spent most of yesterday trying to figure this out....I did all the suggestions above with no results. I was thinking last night that this could be a PC mal-ware/virus trying to attach itself to my Mac, and got hung up because it couldn't....but still couldn't figure it out.

     

    Badunit - you're a genius...haha! I'm with you, Tony, I don't know how it worked, but it did.  I'm storing this little "trick" away for future reference.

     

    Thanks guys!

     

    Ginger

  • by tuxedo32,

    tuxedo32 tuxedo32 Jul 31, 2011 8:30 AM in response to gingertodd
    Level 1 (0 points)
    Jul 31, 2011 8:30 AM in response to gingertodd

    I have the same exact pop up window affecting the operation of my Safari.

    My problem was similar in that I could not quit Safari or restart my computer and have it go away.

     

    So I spoke with Apple customer service and they showed me a way to Force Quit my Safari. Press the keys: Option, Command, and Esc at the same time to bring up the force quit window and select Safari.

     

    Hope this helps

  • by gingertodd,

    gingertodd gingertodd Aug 1, 2011 7:00 AM in response to tuxedo32
    Level 1 (0 points)
    Aug 1, 2011 7:00 AM in response to tuxedo32

    I was able to force quit through the apple icon at the top left corner...but this will be helpful info for the future (Thank you!).

     

    The little "trick" suggested above (holding down shift while clicking on the safari icon in the dock to open) worked for me.  Safari opened normally and I haven't had any problems since.  Hope this works for you also.

     

    Ginger

  • by jvonrock,

    jvonrock jvonrock Aug 5, 2011 10:43 AM in response to powerbook1701
    Level 1 (9 points)
    iOS Apps
    Aug 5, 2011 10:43 AM in response to powerbook1701

    Powerbook 1701  what is the simple way to delete flash cookies ?

  • by jvonrock,

    jvonrock jvonrock Aug 5, 2011 10:51 AM in response to Badunit
    Level 1 (9 points)
    iOS Apps
    Aug 5, 2011 10:51 AM in response to Badunit

    thanks soooo much, it always seems to be something simple, but it takes a gracious mind that shares.

Page 1 of 3 last Next