Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

'MacInstall' Google redirect trojan - how do I uninstall?

Hi,


I think I have a Google redirect trojan called 'macinstall'. I am on Mac OS X Mavericks 10.9.1 and it happens on every search in safari 7.0.1 and firefox even though I have reset all the basic preference settings (which were changed) and deleted an extension called macinstall. I have tried changing the DNS to an open one (208.67.222.222) as this was suggested in another forum, but this hasn't worked and I have also deleted a proxy redirect which I could see although had no idea if that might help. Has been a problem since I downloaded 'Paintbrush', hence why I think it must be a trojan and given its name it's likely I did let it install. I can't find any mention of this trojan online, which may partly be because it is redirecting my browsers...


For example: when I type 'test' into the google toolbar I get:

'http://search.installmac.com/results.html?c=5&v=insMac&q=test', then:

'search.conduit.com/Results...' which is too quick for me to copy, then:

'http://www.bing.com/search?q=test&pc=conduit&ptag=A23C4503E21E14808B6F&form=CONM HP&conlogo=CT3210127'

which gives a rubbish bing search full of nonsense, but not full of illegal/ dodgy sites as far as I can tell which the other redirects seem to do.


I am also pretty sure my whole system is running a lot more slowly. I am currently running the free trial of MacScan to see if it can find anything but it's only picked up tracking cookies so far.


Please help! Idiot-proof instructions please.

MacBook Pro, OS X Mavericks (10.9.1)

Posted on Mar 9, 2014 9:13 PM

Reply
11 replies

Mar 10, 2014 1:59 AM in response to Minz P

Hello Minz P.


The very word Softonic is enough to tell us you have a malware or adware problem. Never buy from this resourse again). Here's a document dealing with this kind of problem from Klaus1


Viruses, Trojans, Malware - and other aspects of InternetSecurity: Apple Support Communities


And a good discussions thread from many others.

Mar 10, 2014 2:50 AM in response to seventy one

Hi,


Ok. That's fine. I now know not to download things from there given what has happened with my first experience. However, all of the information you have given me is very general and about prevention. Arguably if mac provided a basic painting tool as standard then that would also lead to prevention of infection in this case.


My question is can anyone suggest a specific way of removing it now that it has got in?

Mar 10, 2014 3:34 AM in response to Minz P

Okay;


Firstly download the free app from the App Store, Easyfind. That will help you locate all or most of the errant files. Feed into it ANY program names you have downloaded from softonic. And delete what comes up.


Unfortunately I cannot swear this will remove everything but there will be some very good people watching this subject and will no doubt add to my comments.


You Mac is running slowly because you seem to have infected it with Softonic software. Softonic seem to be able to offer a variety of safety oriented programs but I read they have a habit of injecting adware and malware into them.


If you download anything in future, only use App Store or the Developer's site.

Mar 10, 2014 4:27 AM in response to Minz P

You have genieo / installmac adware / trojan installed :


Backup first, then carefully follow :


Adware Removal Guide : Genieo


or


You installed the "Genieo" search-hijacking rootkit.


I suggest that you don't trust the uninstaller that the company provide, since it doesn't work properly & leaves active software behind. Genieo seem unable or unwilling to resolve that, so perhaps they continue to receive some benefit from it.

Mar 10, 2014 6:16 AM in response to seventy one

I haven't checked recently, but softonic include various software 'options' in many of their downloads.

It may be that genieo adware have been paying to push theirs more, since it crops up at a great many sites, including sourceforge where it's often a link from a large green 'download' button... exactly what you expect when looking to download something.

Mar 10, 2014 6:22 PM in response to andyBall_uk

Ok great thanks. Unfortunately I am not able to back up properly as my hard drive is in the UK (I am currently on field work in the Philippines so it takes about 20 mins to load each of these posts!). Is it worth going to the city to buy a hardrive to do this now or can it wait 6 weeks? I am not sure if the adware will cause more damage the longer it is left.


The only thing I clicked on softonic was a large green download button. I think I remember the macinstall being within the downloader and there was no way of getting past it which is why I clicked ok. I was a bit suspicious but I suppose I thought it would just be an annoying toolbar or something that I could switch off, as I have never had an adware problem before that I know of.


Seventy One, the only program I have downloaded outside of the appstore is Paintbrush as I don't really use apps. Since this problem then the MacScan trial which seemed ok from a google search. I will try the easyfind thing and see what comes up.

Mar 11, 2014 1:19 AM in response to Minz P

If you bought it from Apple, No. If you bought it from Softonic, I would say yes. If you cannot remember and you now have the Easy Find App I recommended, run the app and type in Softonic in the search bar. If anything is found you will need to think of deleting it.


If a post helped you, you click the reply point of the person's post to you then the gold star. For a solved you do the same, reply, then click the green star.

Aug 26, 2015 3:25 AM in response to Minz P

Malware Bytes for Mac is good for checking for Trojan's. Use that to check your Mac and then to get rid of all the files associated with a programme do the following:

Open finder (Admin tab) and type the name of the program in the search bar. In the bar underneath that, hit the "+" button. Then change the "kind" option to "system files" and the "aren't included" to "are included". Then hit the plus button again and change the "kind" option to "name" and leave the "matches" option as it is. Type the name of the program in the box next to that and you will be left with all the application's files. Make sure that the files there are definitely related to the App (programme) that you are trying to delete. Drag them all to the trash and empty the trash. This will get rid of all your application's files.

'MacInstall' Google redirect trojan - how do I uninstall?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.