Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

how do I get rid of Malware/Spyware?

I think I have a virus picked up from a CNET download, cananyone suggest a way to get rid of it? When I open a browser, an additional tab opens with no content. I can't get it to go away even after restarts.

MacBook, iOS 7.0.3

Posted on Oct 28, 2013 12:58 PM

Reply
Question marked as Best reply

Posted on Oct 28, 2013 12:59 PM

You don't have a virus. See:


Helpful Links Regarding Malware Protection


An excellent link to read is Tom Reed's Mac Malware Guide.

Also, visit The XLab FAQs and read Detecting and avoiding malware and spyware.

See these Apple articles:


Mac OS X Snow Leopard and malware detection

OS X Lion- Protect your Mac from malware

OS X Mountain Lion- Protect your Mac from malware

About file quarantine in OS X


If you require anti-virus protection I recommend using VirusBarrier Express 1.1.6 or Dr.Web Light both from the App Store. They're both free, and since they're from the App Store, they won't destabilize the system. (Thank you to Thomas Reed for these recommendations.)

15 replies
Question marked as Best reply

Oct 28, 2013 12:59 PM in response to chetko

You don't have a virus. See:


Helpful Links Regarding Malware Protection


An excellent link to read is Tom Reed's Mac Malware Guide.

Also, visit The XLab FAQs and read Detecting and avoiding malware and spyware.

See these Apple articles:


Mac OS X Snow Leopard and malware detection

OS X Lion- Protect your Mac from malware

OS X Mountain Lion- Protect your Mac from malware

About file quarantine in OS X


If you require anti-virus protection I recommend using VirusBarrier Express 1.1.6 or Dr.Web Light both from the App Store. They're both free, and since they're from the App Store, they won't destabilize the system. (Thank you to Thomas Reed for these recommendations.)

Oct 28, 2013 3:29 PM in response to chetko

You should never download anything from CNET's Download.com. It's not to be trusted. Both Download.com and Softonic have been known to insert self-serving adware into the installers of applications downloaded through their sites. However, the adware in question is not technically malware, and will not be detected as such by most anti-virus software.


The behavior you describe, though, does not sound like adware (or malware, for that matter). Is this happening only in one browser? If so, which one? It sounds like the browser may be trying to restore a previous state when it reopens, and thinks that state should be two empty tabs. If the browser in question is Safari, try quitting Safari, then holding down the shift key while re-opening Safari.

Oct 28, 2013 3:36 PM in response to thomas_r.

It has happened in Safari but not on every launch. Chrome opens up with it every time with an "Untitled" tab and this url string:http://%3C%21doctype%20html%20public%20%22-//W3C//DTD%20XHTML%201.0%20Strict//EN %22%20%22http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd%22%3E%3Chtml%20xmlns= %22http://www.w3.org/1999/xhtml%22%3E%3Chead%3E%20%20%3Cmeta%20http-equiv=%22Con tent-Type%22%20content=%22text/html;%20charset=utf-8%22%20/%3E%20%20%3Ctitle%3EK 9%20Web%20Protection%20Alert:%20Category%20Blocked%3C/title%3E%20%20%3Clink%20hr ef=%22reset.css%22%20rel=%22stylesheet%22%20type=%22text/css%22%20/%3E%20%20%3Cl ink%20href=%22embedded.css%22%20rel=%22stylesheet%22%20type=%22text/css%22%20/%3 E%20%20%3Cscript%20src=%22k9.js%22%20type=%22text/javascript%22%3E%3C/script%3E% 3C/head%3E%3Cbody%20class=%22blk3%22%3E%3Cdiv%20id=%22pageBody%22%3E%20%20%3Cdiv %20id=%22pageHead%22%3E%20%20%20%20%3Ch1%20class=%22alert%22%3EK9%20Web%20Protec tion%20Alert%3C/h1%3E%20%20%3C/div%3E%20%20%3Cdiv%20id=%22noMenu%22%3E%20%20%3C/ div%3E%20%20%3Cdiv%20id=%22pageMain%22%3E%20%20%20%20%3Cdiv%20id=%22subMenu%22%3 E%20%20%20%20%20%20%3Ch2%20id=%22title-block%22%3EFiltering%20Alert%3C/h2%3E%20% 20%20%20%20%20%3Cdiv%20id=%22subMenuContainer%22%3E%20%20%20%20%20%20%3C/div%3E% 20%20%20%20%3C/div%3E%20%20%20%20%3Cdiv%20id=%22pageContent%22%3E%20%20%20%20%20 %20%3Ch3%20class=%22block%22%20id=%22title-blk3%22%3ECategory%20Blocked%3C/h3%3E %20%20%20%20%3Cdiv%20id=%22notifier%22%3E%3C/div%3E%3Cdiv%20class=%22summary%20b odyDiv%22%3E%20%20The%20site%20you%20tried%20to%20visit%20belongs%20to%20a%20cat egory%20that%20your%20computer%20is%20set%20to%20block.%3C/div%3E%3Cdiv%20class= %22details%20bodyDiv%22%3E%20%20%3Cspan%20class=%22url%22%3Ewww.mybrowserbar.com /cgi/sapi.cgi?cnid=576859&src=gc&get=hp%3C/span%3E%20is%20blocked%20because%20it %20is%20currently%20categorized%20as:%20%3Cdl%20class=%22category%22%3E%20%20%3C dt%20id=%22category-40%22%3E%20%20%20%20%3Ca%20href=%22#category-40">Search Engines / Portals</a> </dt> <dd> Sites that support searching the Internet, indices, and directories. </dd></dl><dl class="category"> <dt class="blockCat" id="category-43"> <a href="#category-43">Spyware / Malware Sources</a> </dt> <dd> Sites which distribute spyware and other malware. Spyware is defined as software which takes control of your computer, modifies computer settings, collects or reports personal information, or misrepresents itself by tricking users to install, download, or enter personal information. This includes drive-by downloads; browser hijackers; dialers; intrusive advertising; any program which modifies your homepage, bookmarks, or security settings; and keyloggers. It also includes any software which bundles spyware (as defined above) as part of its offering. Information collected or reported is "personal" if it contains uniquely identifying data, such as email addresses, name, social security number, ip address, etc. A site is not classified as spyware if the user is reasonably notified that the software will perform these actions (i.e., it alerts that it will send personal information, be installed, or that it will log keystrokes). </dd></dl></div><div class="blkSep"></div><div class="button"> <a class="button" href="#" id="btn-back"> <span class="title">Go Back</span> <span class="description">Return to the previous page.</span> </a></div><div class="blkSep"></div><div class="buttonset bodyDiv smallButtons"> <h4 class="noPreceed">You may also choose from the following administrative options:</h4> <div class="blockPageAdminControlsDiv"><div class="button"> <a class="button admin" href="#" id="btn-allowSite"> <span class="title">Allow This Site</span> <span class="description">Allow access to <span class="url">http://www.mybrowserbar.com</span> <select id="btn-allowSite-dd"> <option value="5">for 5 minutes</option> <option value="15" selected="selected">for 15 minutes</option> <option value="30">for 30 minutes</option> <option value="60">for 60 minutes</option> <option value="-1">permanently</option></select></span> </a></div><div class="button"> <a class="button admin" href="#" id="btn-allowCat"> <span class="title">Allow This Category</span> <span class="description">Allow access to Web sites rated as Spyware / Malware Sources <select id="btn-allowCat-dd"> <option value="5">for 5 minutes</option> <option value="15" selected="selected">for 15 minutes</option> <option value="30">for 30 minutes</option> <option value="60">for 60 minutes</option> <option value="-1">permanently</option></select></span> </a></div></div><span class="clear"></span></div><div class="clear"></div><div class="buttonset bodyDiv smallButtons"> <div class="blockPageAdminOptsDiv"><div class="button"> <a class="button" href="http://www.mybrowserbar.com/cgi/sapi.cgi?cnid=576859&src=gc&get=hp" id="btn-dispute"> <span class="title">Request Site Review</span> <span class="description"></span> </a></div><div class="button"> <a class="button admin" href="#" id="btn-url-categories"> <span class="title">Change Your Settings</span> <span class="description"></span> </a></div></div></div><div class="clear"></div><br><div class='supervisorModeInfoDiv'>To enter Supervisor Mode, which allows all Web access, go to the <a class='advPageUrl' href='http://127.0.0.1:2372/other'>Advanced Page</a></div> </div> </div> <div id="blueCoat"></div> <div id="copyright"> Copyright &copy; 2006-2009 Blue Coat Systems, Inc. All Rights Reserved. </div></div><div id="floater"></div><div id="selection"></div></body></html>

Oct 28, 2013 3:50 PM in response to chetko

Is that entire string actually in the URL field? That looks like badly corrupt data, including a bunch of HTML code.


One clue I see in there, though, points to a bit of adware called MyBrowserBar.com. Do you have something along those lines installed somewhere? Check your browsers extensions. In Safari's preferences, check the Extensions tab. What do you see there?

Oct 28, 2013 4:42 PM in response to chetko

There is a thing called "Search me" along with an Amazon and Ebay ext.


That is an adware program that probably rode in on some other app's installer. Did this show up right after you installed the app you downloaded from CNET? If so, what app was it that you downloaded? They may be up to their old tricks again.


Delete the SearchMe extension in Safari's Extensions preferences. Look at Chrome's preferences, too... click the Extensions link in the left-hand column in Chrome's preferences, and if you see a similar SearchMe item, remove it from there as well.


I do have K9 by Blue Coar Systems installed which blocks sites that have spyware/malware, **** etc.


I suspected you may have something like that installed. That also explains the text you posted above, found in the URL field in your browser, and the fact that all these tabs are opening blank... K9 would seem to be not functioning properly. I would advise removing that as well. As long as you keep your browser, and any internet plug-ins (like Flash), up-to-date, and keep Java disabled, you have nothing to fear from malware sites. (See my Mac Malware Guide for more information.)

Oct 29, 2013 3:42 AM in response to chetko

I just downloaded that and installed it in a clean test system. CNET is caught red-handed! Not only does the installer add SearchMe, but it is also responsible for the Amazon and Ebay extensions you found. On my test system, it also installed a Slick Savings extension!


User uploaded file

All of those extensions should be removed, and you should never visit Download.com again!

May 5, 2014 10:27 AM in response to Kappy

I have been trying to get rid of this malware for 2 weeks


http://123srv.com/ads-clicktrack/click/newjump1.do?affiliate=63799&subid=DP2040A AAAAA&terms=how%20do%20i%20get%20rid%20of%20malwarespyware%20apple%20support%20c ommunities%20apple&ai=LAfm4A5Qy05kDNdtRk57Url8WS4YNlKnxPq3YGRYiMBuuuDBcib6gJqmzP 6HqGFm03a78Jh_5KINKAuwXCginOr8tgckxM-IuRpW0CdN_ASZwDdZ0PIKL_rpwMz7OQes0HX-thEcFL 3hFjJlKqfo9bq-DHioGnLlhr7tQlhDYVd6HXgoZofmxxWI8gIFfTUSQsUz1rkDgdAlGHJ66BaYoNQF7T s6KCEGU7g4A_CJ_xAF2pZvKvA22lp7atGaEKNHQIvQz_GgR6-FX5aVitZB1MYaXmNvWzgo_huXphguJQ Hwg4rfyFv5vvc4mLRwRNdTNY4h-DI1CZuXE_YFc7RIYeXgZnxviYfB7eN8ND0EQVyPLONg3XMXph8pTl apLBkSuzOYvw5N_xfPG8pipseL_g&version=1.1


I have installed Sophos and ran it on my Mac, OS X Version 10.7.5 , It found infected files quarenteed them and deleted them, I ran Sophos again just to be sure , rebooted my Mac and I still get these pop ups.


I am using Chrome, and have run Sophos on the specifically on the Crome browers after running it on all files on my Mac, no infected files found. Can you please advise what I can do to get ride of the mal ware?

how do I get rid of Malware/Spyware?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.