You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Safari in Lion hijacked by malware

I hope someone can help...


I have the new Lion operating system and was in Safari this morning trying to find a game for my son to play. I clicked on a site and I got a pop up window from www.theconsumerwinner.com telling me to answer a survey...only option was to click ok. I did not...I force quit Safari instead. When I restarted Safari the website and popup comes back and has basically hijacked my safari. I cannot get into any of Safari's menu options...even help.


I went into the Safari folder and deleted the history from today, but it's still there. How can I get rid of this? I love my Safari...luckily I have Firefox installed for a work program, so I'm using it for now. I want my Safari back though...


Please help.


Thank you!

MacBook Pro

Posted on Jul 27, 2011 9:30 AM

Reply
32 replies

Jul 27, 2011 12:02 PM in response to gingertodd

Quit Safri.


Open a Finder window. Select your Home folder in the Sidebar on the left. It has a small house icon.


Now open the Library folder then the Safari folder.


Move these files from the Safari folder to the Trash.


Downloads.plist


History.plist


HistoryIndex.sk


LastSession.plist


TopSites.plist


WebpageIcons.db


Empty the Trash. Relaunch Safari.


See if that helped.


FYI. Some game sites do contain malware. Instead of playing games on a site or downloading games using Safari, use the Mac App Store instead. Lots of games available there. You can access the App Store from your Apple menu, your Dock, or your Applications folder.

Jul 27, 2011 3:30 PM in response to gingertodd

You have acquired either a flash cookie or a tracker cookie.


For those who do not know about Flash cookies, more properly referred to as Local Shared Objects (LSO), they operate in a similar way to regular browser cookies but are stored outside the purview of your browser, meaning you cannot delete them from within your browser, whether Safari, Firefox, Opera or any other. Typically they are issued from sites or 3rd party sites that contain Adobe Flash content. Since virtually all internet advertising is delivered in Flash, Google/Doubleclick and all other internet advertising companies are sure to be tracking your browsing behavior with Flash cookies. These companies can see you traverse the Internet as you come upon the plethora of sites that contain their embedded advertising. Check out the Wikipedia entry here.In Mac OS X they are stored in the following location:/User’s Home Folder/Library/Preferences/Macromedia/Flash Player/#SharedObjectsThe settings for the Flash cookies are stored in:/User’s Home Folder/Library/Preferences/Macromedia/Flash Player/macromedia.com/support/flashplayer/sysIn OS X Local Shared Objects, or Flash Cookies, are appended with a .sol suffix. Flush deletes all the Flash cookies (.sol) and their settings.


Flush can be downloaded from this website:


http://machacks.tv/2009/01/27/flushapp-flash-cookie-removal-tool-for-os-x/

.

If you want to retain certain Flash cookies but not others, the excellent add-on for Safari called SafariCookies does just that:


http://www.sweetpproductions.com/safaricookies/index.htm


which not only does that but much more equally useful stuff!


This article covers the issue in more depth:


http://www.wired.com/epicenter/2009/08/you-deleted-your-cookies-think-again/


Flash cookies are also known as 'Zombie Cookies' and are used by a number of firms, including Hulu, MTV, and Myspace. Graham Cluley, senior technology consultant at the internet security firm Sophos, told BBC News that the source of the trouble was Adobe Flash itself, which he called "one of the weirdest programs on the planet".


"I think it's highly unlikely that these large companies have abused Flash cookies - which are different from browser cookies - with malicious intent," he said.


"I think it's much more likely that the vast majority of users are simply oblivious to the bizarre way in which Adobe allows them to configure the software."


http://www.bbc.co.uk/news/technology-10787882


And a more recent article:


http://www.nytimes.com/2010/09/21/technology/21cookie.html?_r=3&scp=1&sq=flash&s t=cse


For other tracker cookies:


If you allow a Trojan to be installed, the user's DNS records can be modified, redirecting incoming internet traffic through the attacker's servers, where it can be hijacked and injected with malicious websites and pornographic advertisements. The trojan also installs a watchdog process that ensures the victim's (that's you!) DNS records stay modified on a minute-by-minute basis.


You can read more about how, for example, the OSX/DNSChanger Trojan works (by falsely suggesting extra codecs are required for Quicktime) here:


http://www.f-secure.com/v-descs/trojan_osx_dnschanger.shtml


SecureMac has introduced a free Trojan Detection Tool for Mac OS X. It's available here:


http://macscan.securemac.com/


First update the MacScan malware definitions before scanning. You can also contact their support team for any additional support - macsec@securemac.com [/b]


The DNSChanger Removal Tool detects and removes spyware targeting Mac OS X and allows users to check to see if the trojan has been installed on their computer; if it has, the software helps to identify and remove the offending file. After a system reboot, the users' DNS records will be repaired.


(Note that a 30 day trial version of MacScan can be downloaded free of charge from:


http://macscan.securemac.com/buy/


and this can perform a complete scan of your entire hard disk. After 30 days free trial the cost is $29.99. The full version permits you to scan selected files and folders only, as well as the entire hard disk. It will detect (and delete if you ask it to) all 'tracker cookies' that switch you to web sites you did not want to go to.)


VIRUSES


No viruses that can attack OS X have so far been detected 'in the wild', i.e. in anything other than laboratory conditions.


It is possible, however, to pass on a Windows virus to another Windows user, for example through an email attachment. To prevent this all you need is the free anti-virus utility ClamXav, which you can download for Tiger and Leopard (check with them about Lion) from:


http://www.clamxav.com/


The new version for Snow Leopard is available here:


http://www.clamxav.com/index.php?page=v2beta


Note: ClamAV adds a new user group to your Mac. That makes it a little more difficult to remove than some apps. You’ll find an uninstaller link in ClamXav’s FAQ page online.


If you are already using ClamXav: please ensure that you have installed all recent Apple Security Updates and that your version of ClamXav is the latest available.


Do not install Norton Anti-Virus on a Mac as it can seriously damage your operating system. Norton Anti-Virus is not compatible with Apple OS X.

Jul 28, 2011 6:51 AM in response to Tony the Bald Eagle

Wow...THANK YOU!!!!! I spent most of yesterday trying to figure this out....I did all the suggestions above with no results. I was thinking last night that this could be a PC mal-ware/virus trying to attach itself to my Mac, and got hung up because it couldn't....but still couldn't figure it out.


Badunit - you're a genius...haha! I'm with you, Tony, I don't know how it worked, but it did. I'm storing this little "trick" away for future reference.


Thanks guys!


Ginger

Jul 31, 2011 8:30 AM in response to gingertodd

I have the same exact pop up window affecting the operation of my Safari.

My problem was similar in that I could not quit Safari or restart my computer and have it go away.


So I spoke with Apple customer service and they showed me a way to Force Quit my Safari. Press the keys: Option, Command, and Esc at the same time to bring up the force quit window and select Safari.


Hope this helps

Aug 1, 2011 7:00 AM in response to tuxedo32

I was able to force quit through the apple icon at the top left corner...but this will be helpful info for the future (Thank you!).


The little "trick" suggested above (holding down shift while clicking on the safari icon in the dock to open) worked for me. Safari opened normally and I haven't had any problems since. Hope this works for you also.


Ginger

Safari in Lion hijacked by malware

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.