I am having trouble with a redirect virus; how to fix?

I think I have a virus or spyware on my computer. It redirects me to a third-party site (something like LinkBucks) when I try to visit Facebook, Google or YouTube. This happens in both Safari and in Mozilla Firefox. I have tried scanning with ClamX, MacScan, but they are not finding any viruses. I also downloaded a kit that scans the computer for DNS redirect changer viruses, but it can't find any. What should I do now?

MacBook Pro, Mac OS X (10.6.8)

Posted on Mar 12, 2012 3:08 PM

Reply
31 replies

Jan 23, 2013 10:09 AM in response to wheel1975

This is not caused by malware of any kind. Unless you have jailbroken your phone, there is no malware that affects iOS devices.


As to what it could be, I see exactly the same behavior from the URL you provided. What this tells me is that the site has been hacked, but only the mobile version of the site is affected. (A site can deliver different pages depending on the device, and many sites will deliver a different page to mobile devices than to full-fledged computers.)


Thus, there's no need to stop using your iPhone. However, you probably should contact the owner of that site to notify them of the issue.

Feb 24, 2013 4:48 PM in response to ComputerUser23483

I have the same problem here with the Chrome browser. Sometimes it opens a new tab with a clickbucks url. I can't solve that. The return of the script you provided was:


defaults read ~/.MacOSX/environment -- 2013-02-24 21:37:49.323 defaults[56553:f07]

Domain /Users/arthursilva/.MacOSX/environment does not exist


ls -al /Applications/Safari.app/Contents/Resources/*COAA* -- ls: /Applications/Safari.app/Contents/Resources/*COAA*: No such file or directory


java version "1.6.0_41"

Java(TM) SE Runtime Environment (build 1.6.0_41-b02-445-11M4107)

Java HotSpot(TM) 64-Bit Server VM (build 20.14-b01-445, mixed mode)

Feb 24, 2013 5:14 PM in response to r2arthur

And the following command:


ls -a /Applications/Safari.app/Contents/Resources/ | grep "^\."


Returns nothing 🙂 . Empty (just . and ..)


I just noticed that the URL is also opening at Safari. So both chrome and safari are infected? I haven't been using Safari for a while, opened it today because I noticed that chrome was infected.


and I just checked my DNS and it is ok.

Feb 24, 2013 5:53 PM in response to r2arthur

r2arthur wrote:


I have the same problem here with the Chrome browser. Sometimes it opens a new tab with a clickbucks url. I can't solve that. The return of the script you provided was:


defaults read ~/.MacOSX/environment -- 2013-02-24 21:37:49.323 defaults[56553:f07]

Domain /Users/arthursilva/.MacOSX/environment does not exist


ls -al /Applications/Safari.app/Contents/Resources/*COAA* -- ls: /Applications/Safari.app/Contents/Resources/*COAA*: No such file or directory

Those are very old and had to do with the Flashback Backdoor/Trojan that was in existance almost a year ago and has been declared extinct for several months now by most all of the Anti-Virus experts. If your software is fully up-to-date, and it sounds like it is, then Apple has fully protected you against that malware and would have removed anything that you already had on your hard drive a long time ago. Your problem is almost certainly not malware and clearly not Flashback.

Apr 13, 2013 9:25 AM in response to ComputerUser23483

I got rid of my Firefox redirect problem by removing eveything related to Firefox.app and re-download and reinstalled the software again. Make sure you also remove the ~/Library/Applicaiton Support/Firefox. I think there's where the virus hiding because when I did the first clean reinstall, the problem was still there. It was until I removed the "Application Support" stuffs, the problem then went away and firefox looked like a new born baby with none of my customizations. It's a shame that I have to redo all the add-ons and things, but at least I can still use Firefox as my broswer.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

I am having trouble with a redirect virus; how to fix?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.