Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Constantly getting ads on safari/firefox/chrome. Brother downloaded a file and have tried EVERYTHING to find this malware but cannot. Can a factory reset help at all?

Alright so a few days ago my brother used my laptop to download Super Bowl 48 (huge seahawk fans). He torrented it offline, however now whenever I use Safari/Firefox/Chrome I get CONSTANT ads and pop ups. I have tried everything. Clearing extensions, uninstalling everything he did, scanned my computer with Clamxav, iAntivirus and even a free trial from Norton's latest software. Nothing, yet the problem still remains. From what I've heard/read, if I take it to the apple store they cannot help. Is a factory reset the only way to go?

User uploaded file Links are double underlined in green, and when I move the mouse over them

they pop up into an ad


This is the homepage of www.bleacherreport.com full of ads that were never ever there before. (2014 ford, play now/download/ video on left). User uploaded file

Simply very annoying and I have noticed a slower speed to my computers processing of webpages. please please please help!

MacBook Pro with Retina display, OS X Mavericks (10.9.2)

Posted on Mar 23, 2014 2:47 AM

Reply
41 replies

Mar 23, 2014 3:53 AM in response to Harford3

Your brother probably installed adware on your computer. This is often a consequence of downloading things from torrents... or worse. Don't do that anymore.


To remove it, see my Adware Removal Guide. My guess, based on the fact that this appeared after downloading from a torrent, would be that you have DownLite, but it could be something else as well. Even if you find that DownLite is installed, and successfully remove it, I'd still recommend going through the entire guide. In my experience, people who have one adware program installed fairly frequently have more than one.

Mar 23, 2014 3:55 AM in response to thomas_r.

Oh, and I forgot to add... iAntivirus is completely worthless. Norton is only fair at detecting Mac malware, and in exchange, has a penchant for ruining performance and causing instability. Get rid of both of those. Be sure to uninstall Norton properly, by running the original installer you used to install it (which will offer to remove it for you since it's already installed).

Mar 23, 2014 9:59 AM in response to Harford3

You installed the "DownLite" trojan, perhaps under a different name. Remove it as follows.

Back up all data.

Triple-click anywhere in the line below on this page to select it:

/Library/Application Support/VSearch

Right-click or control-click the line and select

Services Reveal in Finder (or just Reveal)

from the contextual menu.* A folder should open with an item named "VSearch" selected. Drag the selected item to the Trash. You may be prompted for your administrator login password.

Repeat with each of these lines:

/Library/LaunchAgents/com.vsearch.agent.plist /Library/LaunchDaemons/com.vsearch.daemon.plist /Library/LaunchDaemons/com.vsearch.helper.plist /Library/LaunchDaemons/Jack.plist /Library/PrivilegedHelperTools/Jack /System/Library/Frameworks/VSearch.framework


Some of these items may be absent, in which case you'll get a message that the file can't be found. Skip that item and go on to the next one.

Restart and empty the Trash. Don't try to empty the Trash until you have restarted.

From the Safari menu bar, select


Safari Preferences... Extensions

Uninstall any extensions you don't know you need, including any that have the word "Spigot" in the description. If in doubt, uninstall all extensions. Do the equivalent for the Firefox and Chrome browsers, if you use either of those.

This trojan is distributed on illegal websites that traffic in pirated movies. If you, or anyone else who uses the computer, visit such sites and follow prompts to install software, you can expect much worse to happen in the future.

*If you don't see the contextual menu item, copy the selected text to the Clipboard by pressing the key combination command-C. In the Finder, select

Go Go to Folder...

from the menu bar and paste into the box that opens (command-V). You won't see what you pasted because a line break is included. Press return.

Mar 23, 2014 10:48 AM in response to Harford3

In addition to "DownLite," you also installed the "Genieo" search-hijacking rootkit. The product is a fraud, and the developer knowingly distributes an uninstaller that doesn't work. I suggest the tedious procedure below to disable Genieo. You need to become a lot more careful about how you use the Internet.

Back up all data. You must know how to restore from a backup even if the system becomes unbootable. If you don't know how to do that, or if you don't have any backups, stop here and ask for guidance.

Step 1

Triple-click anywhere in the line below on this page to select it:

/etc/launchd.conf

Right-click or control-click the line and select

Services Reveal in Finder (or just Reveal)

from the contextual menu.

If you don't see the contextual menu item, copy the selected text to the Clipboard by pressing the key combination command-C. In the Finder, select

Go Go to Folder...

from the menu bar and paste into the box that opens (command-V). You won't see what you pasted because a line break is included. Press return.

A folder may open with a file selected, or the file may not exist, in which case you'll get a message that it can't be found. If it does exist, it's a configuration file created or replaced by the Genieo installer. Any software installer that does this should be considered ipso facto malware. Move the file to the Trash. You'll be prompted for your administrator password. Then restart, empty the Trash, and continue as below.

IMPORTANT: If the launchd.conf file exists, you must move it to the Trash and restart before continuing. Otherwise the system may become unbootable. In that case, restore from your backup and start over. That's how badly Genieo has sabotaged your system. If you're not completely sure you can complete this step, stop here and ask for guidance.

Some variants of Genieo don't include the launchd.conf file. The absence of that file doesn't mean that Genieo is not installed.

Step 2

Quit the Genieo application, if it's running. Force quit if necessary.

Move each of these items to the Trash in the same way as above:

/Applications/Genieo.app
/Applications/Uninstall Genieo.app
/Library/Frameworks/GenieoExtra.framework
/Library/LaunchAgents/com.genieo.engine.plist
/Library/LaunchAgents/com.genieoinnovation.macextension.plist
/Library/LaunchDaemons/com.genieoinnovation.macextension.client.plist
/Library/PrivilegedHelperTools/com.genieoinnovation.macextension.client
/usr/lib/libgenkit.dylib
  
 
    
/usr/lib/libgenkitsa.dylib
/usr/lib/libimckit.dylib
/usr/lib/libimckitsa.dylib

There's no need to restart after each one. Again, some of these items may be absent, in which case you'll get a message that the file can't be found. Skip that item and go on to the next one.

Restart and empty the Trash. Don't try to empty the Trash until you have restarted.

Your web browser(s) should now function normally, and you should be able to reset the home page and search engine. If not, stop here and post your results.

Step 3

From the Safari menu bar, select

Safari Preferences... Extensions

Uninstall any extensions you don't know you need, including ones called "Genieo" or "Omnibar," and any that have the word "Spigot" or "InstallMac" in the description. If in doubt, uninstall all extensions. Do the equivalent for the Firefox and Chrome browsers, if you use either of those.

This procedure may leave a few files behind, but it will deactivate any version of Genieo that I know of. Make sure you don't repeat the mistake that led you to install it. Chances are you got it from one of the Internet's open sewers such as "Softonic" or "CNET Download." Never visit either of those sites again. You might also have downloaded it from an ad in a page on some other site.

Finally, be forewarned that when Genieo is mentioned on this site, the developer sometimes shows up under the name "Genieo support." If that happens, don't believe anything he says, but feel free to tell him what you think of his scam.

Constantly getting ads on safari/firefox/chrome. Brother downloaded a file and have tried EVERYTHING to find this malware but cannot. Can a factory reset help at all?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.