James Cook2

Q: onclickads - malware or virus?

As of this morning, when I click on a link within a page, a new page opens to onclickads and then reloads with some advertisement.

 

I've searched all of the usual folders in my Library, cleared caches etc, but cannot find out how to get rid of it. Norton found nothing.

 

I've not visited any unreputable sites and the only thing I can think of that I recently installed was a Flash update - though I can't vouch now for its authenticity.

 

I'm worried about it spreading to my other devices so I've turned off Safari in iCloud, hoping it's not already too late.

 

How do I get rid of this pest?

MacBook Pro, OS X Mavericks (10.9.2)

Posted on Apr 28, 2014 7:46 AM

Close

Q: onclickads - malware or virus?

  • All replies
  • Helpful answers

Page 1 of 4 last Next
  • by Allan Jones,

    Allan Jones Allan Jones Apr 28, 2014 9:03 AM in response to James Cook2
    Level 8 (35,071 points)
    iPad
    Apr 28, 2014 9:03 AM in response to James Cook2

    First, stop using Norton. It has trashed many more Macs than it's saved. Completely uninstall it:

     

    https://support.norton.com/sp/en/us/home/current/solutions/v64924250_EndUserProf ile_en_us

     

    There are several adware types that can make your life miserable. How to find, identify, and remove is here:

     

    http://www.reedcorner.net/arg/

     

    There are fake Flash installers out there, If you did not update Flash directly from the Adobe site, you could have gotten the adware that way. Only update Flash fro this site:

     

    http://get.adobe.com/flashplayer/

  • by James Cook2,

    James Cook2 James Cook2 Apr 28, 2014 9:55 AM in response to Allan Jones
    Level 1 (15 points)
    Notebooks
    Apr 28, 2014 9:55 AM in response to Allan Jones

    At this point I'm certain that it was a fake Flash installer that started the issue.

     

    I have been through The Safe Mac checklist (reedcorner.net) and it doesn't match with anything in the Identification list. I used an excellent search utility on my hard drive. It does include the User, System and Library folders i its search. It couldn't find any of those names either or key pieces of them.

     

    It is affecting all browsers on the computer but seems to be limited to links that reference other sites, not internal links for the site I'm viewing. So here on Apple I can view other pages of the Apple site without a problem. But a click on one of the links referred to in your post, such as reedcorner.net, causes a new page to open. MacKeeper seems to be one of the advertisers it likes to promote.

     

    Since I can only find one other reference to this one on the internet, and it's recent, this may be a relatively new one.

  • by andyBall_uk,

    andyBall_uk andyBall_uk Apr 28, 2014 10:13 AM in response to James Cook2
    Level 7 (20,495 points)
    Apr 28, 2014 10:13 AM in response to James Cook2

    Do you know where the Flash updater/installer came from ?.

  • by omijan7,

    omijan7 omijan7 Apr 28, 2014 11:35 AM in response to James Cook2
    Level 1 (0 points)
    Apr 28, 2014 11:35 AM in response to James Cook2

    I'm having the same problem!  When we're on a page and click a link to something, we're transported right to an ad or sometimes a **** site!  Mostly it's been to vube.com or us.games724.com, etc.  Even though our pop-up blocker is on, it's still doing it.  I've tried rebooting, taking the pop-up blocker off, then on, plugging and unplugging the modem, clearing the history and cookies and data -- nothing works to fix this problem so far.

     

    It's possible we installed a "fake" Flash updater.  I'll trying figuring out how to uninstall/reinstall that, I guess.

  • by Allan Jones,

    Allan Jones Allan Jones Apr 28, 2014 11:37 AM in response to James Cook2
    Level 8 (35,071 points)
    iPad
    Apr 28, 2014 11:37 AM in response to James Cook2

    Dear James,

     

    It's possible that "onclickads" is simply another, newer name for a known adware. You can help us find it. Please download and install this free utility:

     

    http://www.etresoft.com/etrecheck

     

    It is secure and written by one of our most valued members to allow users to show details of their computer's configuration in Apple Support Communities without revealing any sensitive personal data.

     

    Run the program and click the "Copy report to clipboard" button when it displays the results. Then return here and paste the report into a response to your initial post. It can often show if any harmful files/programs are dragging down your performance.

  • by James Cook2,

    James Cook2 James Cook2 Apr 28, 2014 11:47 AM in response to Allan Jones
    Level 1 (15 points)
    Notebooks
    Apr 28, 2014 11:47 AM in response to Allan Jones

    Hardware Information:

              MacBook Pro (17-inch 2.4GHZ)

              MacBook Pro - model: MacBookPro3,1

              1 2.4 GHz Intel Core 2 Duo CPU: 2 cores

              4 GB RAM

     

    Video Information:

              GeForce 8600M GT     - VRAM: 256 MB

     

    System Software:

              OS X 10.9.2 (13C1021) - Uptime: 0 days 1:0:54

     

    Disk Information:

              Hitachi HTS541616J9SA00 disk0 : (160.04 GB)

                        EFI (disk0s1) <not mounted>: 209.7 MB

                        Heracles (disk0s2) / [Startup]: 159.18 GB (33.58 GB free)

                        Recovery HD (disk0s3) <not mounted>: 650 MB

     

    USB Information:

              Apple Inc. iPhone

     

              Apple Inc. Built-in iSight

     

              Apple Inc. Bluetooth USB Host Controller

     

     

              Logitech USB Receiver

     

     

              Apple Computer Apple Internal Keyboard / Trackpad

     

              Apple Computer, Inc. IR Receiver

     

    Thunderbolt Information:

     

    Configuration files:

              /etc/hosts - Count: 13

     

    Gatekeeper:

              Anywhere

     

    Kernel Extensions:

              [kext loaded] com.AmbrosiaSW.AudioSupport (4.1.2 - SDK 10.6) Support

              [kext loaded] com.Logitech.Control Center.HID Driver (3.3.0) Support

              [kext loaded] com.Logitech.Unifying.HID Driver (1.2.0) Support

              [not loaded] com.roxio.BluRaySupport (1.1.6) Support

              [not loaded] com.roxio.TDIXController (2.0) Support

              [not loaded] com.seagate.driver.PowSecDriverCore (5.0.1) Support

              [not loaded] com.targus.driver.EventDriver (2.1.0f2) Support

              [not loaded] com.wdc.driver.1394HP (1.0.11 - SDK 10.4) Support

              [not loaded] com.wdc.driver.1394_64HP (1.0.1 - SDK 10.6) Support

              [not loaded] com.wdc.driver.USBHP (1.0.11) Support

              [not loaded] com.wdc.driver.USB_64HP (1.0.0 - SDK 10.6) Support

     

    Startup Items:

              ProTec6: Path: /Library/StartupItems/ProTec6

              ProTec6b: Path: /Library/StartupItems/ProTec6b

     

    Problem System Launch Agents:

              [failed] com.paragon.NTFS.auth.plist Support

     

    Launch Daemons:

              [loaded] com.adobe.fpsaud.plist Support

              [loaded] com.adobe.SwitchBoard.plist Support

              [loaded] com.ambrosiasw.ambrosiaaudiosupporthelper.daemon.plist Support

              [loaded] com.barebones.authd.plist Support

              [loaded] com.barebones.textwrangler.plist Support

              [running] com.bjango.istatmenusdaemon.plist Support

              [not loaded] com.econtechnologies.ChronoAgentRemote.plist Support

              [not loaded] com.maintain.HideSpotlightMenuBarIcon.plist Support

              [running] com.memeo.Memeod.plist Support

              [failed] com.memeo.WDMemeod.plist Support

              [loaded] com.microsoft.office.licensing.helper.plist Support

              [loaded] com.oracle.java.Helper-Tool.plist Support

              [running] com.orbicule.uc.plist Support

              [running] com.orbicule.uclocator.plist Support

     

    Launch Agents:

              [not loaded] com.adobe.AAM.Updater-1.0.plist Support

              [loaded] com.adobe.CS5ServiceManager.plist Support

              [running] com.bjango.istatmenusagent.plist Support

              [running] com.Logitech.Control Center.Daemon.plist Support

              [not loaded] com.maintain.PurgeInactiveMemory.plist Support

              [not loaded] com.maintain.Restart.plist Support

              [not loaded] com.maintain.ShutDown.plist Support

              [running] com.maintain.SystemEvents.plist Support

              [loaded] com.oracle.java.Java-Updater.plist Support

              [running] com.seagate.SeagateStorageGauge.plist Support

              [running] com.targus.agent.plist Support

              [running] net.culater.SIMBL.Agent.plist Support

     

    User Launch Agents:

              [loaded] com.adobe.AAM.Updater-1.0.plist Support

              [loaded] com.adobe.ARM.[...].plist Support

              [failed] com.akamai.single-user-client.plist Support

              [loaded] com.google.keystone.agent.plist Support

              [loaded] com.propaganda.dejavu.dvmonitor.plist Support

              [not loaded] com.zeobit.MacKeeper.Helper Support

     

    User Login Items:

              ScreenSharingMenulet

              ChronoSync

              Canon IJ Network Scanner Selector2

              Dropbox

              Spell Catcher

              finderpop-daemon

              WDDriveManagerStatusMenu

     

    Internet Plug-ins:

              AdobeExManDetect: Version: AdobeExManDetect 1.1.0.0 - SDK 10.7 Support

              FlashPlayer-10.6: Version: 13.0.0.201 - SDK 10.6 Support

              QuickTime Plugin: Version: 7.7.3

              Flash Player: Version: 13.0.0.201 - SDK 10.6 Outdated! Update

              Default Browser: Version: 537 - SDK 10.9

              SharePointBrowserPlugin: Version: 14.3.9 - SDK 10.6 Support

              Silverlight: Version: 5.1.10516.0 - SDK 10.6 Support

              JavaAppletPlugin: Version: Java 7 Update 51 Check version

     

    Audio Plug-ins:

              BluetoothAudioPlugIn: Version: 1.0 - SDK 10.9

              AirPlay: Version: 2.0 - SDK 10.9

              AppleAVBAudio: Version: 203.2 - SDK 10.9

              iSightAudio: Version: 7.7.3 - SDK 10.9

     

    iTunes Plug-ins:

              Quartz Composer Visualizer: Version: 1.4 - SDK 10.9

     

    User Internet Plug-ins:

              CitrixOnlineWebDeploymentPlugin: Version: 1.0.94 Support

              WebEx64: Version: 1.0 - SDK 10.5 Support

     

    3rd Party Preference Panes:

              FinderPop  Support

              Flash Player  Support

              iStat Menus  Support

              Java  Support

              Logitech Control Center  Support

              Targus  Support

              Web Sharing  Support

     

    Time Machine:

              Skip System Files: NO

              Mobile backups: OFF

              Auto backup: NO - Auto backup turned off

              Volumes being backed up:

                        Heracles: Disk size: 148.25 GB Disk used: 116.98 GB

              Destinations:

                        Way Back [Local] (Last used)

                        Total size: 372.53 GB

                        Total number of backups: 29

                        Oldest backup: 2012-07-26 14:26:04 +0000

                        Last backup: 2014-04-25 18:54:23 +0000

                        Size of backup disk: Adequate

                                  Backup size 372.53 GB > (Disk used 116.98 GB X 3)

              Time Machine details may not be accurate.

              All volumes being backed up may not be listed.

     

    Top Processes by CPU:

                   4%          ChronoSyncBackgrounder

                   4%          WindowServer

                   1%          SystemUIServer

                   0%          Dropbox

                   0%          Memeod

     

    Top Processes by Memory:

              164 MB          com.apple.IconServicesAgent

              127 MB          com.apple.WebKit.WebContent

              127 MB          Mail

              94 MB          mds_stores

              86 MB          Safari

     

    Virtual Memory Information:

              1.31 GB          Free RAM

              1.83 GB          Active RAM

              336 MB          Inactive RAM

              547 MB          Wired RAM

              513 MB          Page-ins

              0 B          Page-outs

  • by James Cook2,

    James Cook2 James Cook2 Apr 28, 2014 11:59 AM in response to James Cook2
    Level 1 (15 points)
    Notebooks
    Apr 28, 2014 11:59 AM in response to James Cook2

    A footnote to my system profile, I've now deleted the few MacKeper parts that were present although they were from 2011 when I tried their demo and passed on it.

  • by omijan7,

    omijan7 omijan7 Apr 28, 2014 12:11 PM in response to omijan7
    Level 1 (0 points)
    Apr 28, 2014 12:11 PM in response to omijan7

    Hardware Information:

              iMac (21.5-inch, Mid 2010)

              iMac - model: iMac11,2

              1 3.06 GHz Intel Core i3 CPU: 2 cores

              4 GB RAM

     

    Video Information:

              ATI Radeon HD 4670 - VRAM: 256 MB

     

    System Software:

              OS X 10.9.2 (13C1021) - Uptime: 5 days 23:56:58

     

    Disk Information:

              WDC WD5000AAKS-40V6A0 disk0 : (500.11 GB)

                        EFI (disk0s1) <not mounted>: 209.7 MB

                        iMac_HD (disk0s2) / [Startup]: 499.25 GB (429.09 GB free)

                        Recovery HD (disk0s3) <not mounted>: 650 MB

     

              OPTIARC DVD RW AD-5680H 

     

    USB Information:

              Apple Computer, Inc. IR Receiver

     

              Apple Inc. Built-in iSight

     

              Western Digital My Book 1110 999.5 GB

                        EFI (disk1s1) <not mounted>: 209.7 MB

                        TimeMachine (disk1s2) /Volumes/TimeMachine: 999.16 GB (304.41 GB free)

     

              Apple Internal Memory Card Reader

     

              Apple Inc. BRCM2046 Hub

                        Apple Inc. Bluetooth USB Host Controller

     

    Thunderbolt Information:

     

    Gatekeeper:

              Mac App Store and identified developers

     

    Kernel Extensions:

              [not loaded] com.wdc.driver.1394HP (1.0.7) Support

              [not loaded] com.wdc.driver.USBHP (1.0.6) Support

     

    Launch Daemons:

              [loaded] com.adobe.fpsaud.plist Support

              [loaded] com.microsoft.office.licensing.helper.plist Support

     

    User Launch Agents:

              [loaded] com.adobe.ARM.[...].plist Support

              [running] com.ecamm.printopia.plist Support

              [loaded] com.google.keystone.agent.plist Support

     

    User Login Items:

              iTunesHelper

              Mail

              Dropbox

              StatusMenu

     

    Internet Plug-ins:

              Flip4Mac WMV Plugin: Version: 2.3.8.1 Support

              FlashPlayer-10.6: Version: 13.0.0.206 - SDK 10.6 Support

              Default Browser: Version: 537 - SDK 10.9

              AdobePDFViewerNPAPI: Version: 11.0.06 - SDK 10.6 Support

              AdobePDFViewer: Version: 11.0.06 - SDK 10.6 Support

              Flash Player: Version: 13.0.0.206 - SDK 10.6 Support

              QuickTime Plugin: Version: 7.7.3

              SharePointBrowserPlugin: Version: 14.4.1 - SDK 10.6 Support

              GarminGpsControl: Version: 2.9.3.0 Release Support

              Silverlight: Version: 5.1.20125.0 - SDK 10.6 Support

              iPhotoPhotocast: Version: 7.0 - SDK 10.8

     

    Safari Extensions:

              AdBlock: Version: 2.6.29

     

    Audio Plug-ins:

              BluetoothAudioPlugIn: Version: 1.0 - SDK 10.9

              AirPlay: Version: 2.0 - SDK 10.9

              AppleAVBAudio: Version: 203.2 - SDK 10.9

              iSightAudio: Version: 7.7.3 - SDK 10.9

     

    iTunes Plug-ins:

              Quartz Composer Visualizer: Version: 1.4 - SDK 10.9

     

    3rd Party Preference Panes:

              Flash Player  Support

              Flip4Mac WMV  Support

              Printopia  Support

     

    Time Machine:

              Auto backup: YES

              Volumes being backed up:

                        iMac_HD: Disk size: 464.96 GB Disk used: 65.34 GB

              Destinations:

                        TimeMachine [Local] (Last used)

                        Total size: 930.54 GB

                        Total number of backups: 135

                        Oldest backup: 2011-11-11 01:39:55 +0000

                        Last backup: 2014-04-28 18:29:27 +0000

                        Size of backup disk: Adequate

                                  Backup size 930.54 GB > (Disk used 65.34 GB X 3)

              Time Machine details may not be accurate.

              All volumes being backed up may not be listed.

     

    Top Processes by CPU:

                   1%          WindowServer

                   0%          fontd

                   0%          com.apple.WebKit.WebContent

                   0%          SystemUIServer

                   0%          Dropbox

     

    Top Processes by Memory:

              160 MB          Safari

              127 MB          mds_stores

              94 MB          softwareupdated

              74 MB          com.apple.WebKit.Networking

              66 MB          Dropbox

     

    Virtual Memory Information:

              1.35 GB          Free RAM

              1.43 GB          Active RAM

              621 MB          Inactive RAM

              583 MB          Wired RAM

              1.63 GB          Page-ins

              83 MB          Page-outs

  • by omijan7,

    omijan7 omijan7 Apr 28, 2014 12:32 PM in response to omijan7
    Level 1 (0 points)
    Apr 28, 2014 12:32 PM in response to omijan7

    I've been trying to replicate the problem, and today the site that keeps coming up is worldnews247.org.

  • by sirpig,

    sirpig sirpig Apr 28, 2014 1:05 PM in response to James Cook2
    Level 1 (0 points)
    Apr 28, 2014 1:05 PM in response to James Cook2

    Hardware Information:

              MacBook Pro (Retina, 15-inch, Late 2013)

              MacBook Pro - model: MacBookPro11,3

              1 2.3 GHz Intel Core i7 CPU: 4 cores

              16 GB RAM

     

    Video Information:

              Intel Iris Pro - VRAM: 1024 MB

              NVIDIA GeForce GT 750M - VRAM: 2048 MB

     

    System Software:

              OS X 10.9.2 (13C1021) - Uptime: 0 days 2:0:14

     

    Disk Information:

              APPLE SSD SM0512F disk0 : (500.28 GB)

                        EFI (disk0s1) <not mounted>: 209.7 MB

                        Macintosh HD (disk0s2) / [Startup]: 499.42 GB (391.56 GB free)

                        Recovery HD (disk0s3) <not mounted>: 650 MB

     

    USB Information:

              Apple Internal Memory Card Reader

     

              Apple Inc. Apple Internal Keyboard / Trackpad

     

              Apple Inc. BRCM20702 Hub

                        Apple Inc. Bluetooth USB Host Controller

     

    Thunderbolt Information:

              Apple Inc. thunderbolt_bus

     

    Configuration files:

              /etc/hosts - Count: 5

     

    Gatekeeper:

              Anywhere

     

    Kernel Extensions:

              [kext loaded] at.obdev.nke.LittleSnitch (4050 - SDK 10.8) Support

              [kext loaded] com.AmbrosiaSW.AudioSupport (4.1.2 - SDK 10.7) Support

              [not loaded] com.mice.driver.Wireless360Controller (1.0.0d12 - SDK 10.8) Support

              [not loaded] com.mice.driver.WirelessGamingReceiver (1.0.0d12 - SDK 10.8) Support

              [not loaded] com.mice.driver.Xbox360Controller (1.0.0d12 - SDK 10.8) Support

     

    Launch Daemons:

              [running] at.obdev.littlesnitchd.plist Support

              [loaded] com.adobe.fpsaud.plist Support

              [loaded] com.adobe.SwitchBoard.plist Support

              [loaded] com.ambrosiasw.ambrosiaaudiosupporthelper.daemon.plist Support

              [loaded] com.google.keystone.daemon.plist Support

              [loaded] com.microsoft.office.licensing.helper.plist Support

              [loaded] KillLittleSnitch.plist Support

              [loaded] org.macosforge.xquartz.privileged_startx.plist Support

     

    Launch Agents:

              [running] at.obdev.LittleSnitchUIAgent.plist Support

              [not loaded] com.adobe.AAM.Updater-1.0.plist Support

              [loaded] com.google.keystone.agent.plist Support

              [loaded] KillLittleSnitch.plist Support

              [loaded] org.macosforge.xquartz.startx.plist Support

     

    User Login Items:

              Steam

              Macs Fan Control

              iTunesHelper

              ShiftIt

              Android File Transfer Agent

              Fantastical

              Google Chrome

     

    Internet Plug-ins:

              SharePointBrowserPlugin: Version: 14.4.1 - SDK 10.6 Support

              FlashPlayer-10.6: Version: 13.0.0.201 - SDK 10.6 Support

              Flash Player: Version: 13.0.0.201 - SDK 10.6 Outdated! Update

              QuickTime Plugin: Version: 7.7.3

              JavaAppletPlugin: Version: 14.9.0 - SDK 10.7 Check version

              Default Browser: Version: 537 - SDK 10.9

     

    Safari Extensions:

              AdBlock: Version: 2.6.28

              Open in Internet Explorer: Version: 1.0

     

    Audio Plug-ins:

              BluetoothAudioPlugIn: Version: 1.0 - SDK 10.9

              AirPlay: Version: 2.0 - SDK 10.9

              AppleAVBAudio: Version: 203.2 - SDK 10.9

              iSightAudio: Version: 7.7.3 - SDK 10.9

     

    iTunes Plug-ins:

              Quartz Composer Visualizer: Version: 1.4 - SDK 10.9

     

    3rd Party Preference Panes:

              Flash Player  Support

              XBox 360 Controllers  Support

     

    Time Machine:

              Time Machine not configured!

     

    Top Processes by CPU:

                   2%          WindowServer

                   1%          fontd

                   1%          Little Snitch Network Monitor

                   0%          Memory Clean

                   0%          warmd

     

    Top Processes by Memory:

              246 MB          Safari

              197 MB          Wunderlist

              164 MB          WindowServer

              164 MB          com.apple.IconServicesAgent

              131 MB          Dock

     

    Virtual Memory Information:

              11.40 GB          Free RAM

              2.86 GB          Active RAM

              476 MB          Inactive RAM

              1.26 GB          Wired RAM

              542 MB          Page-ins

              0 B          Page-outs

  • by sirpig,

    sirpig sirpig Apr 28, 2014 1:15 PM in response to James Cook2
    Level 1 (0 points)
    Apr 28, 2014 1:15 PM in response to James Cook2

    Hey everyone, I think I've found the solution, it looks like it was due to a bad version of flash player.

     

    I followed these steps from adobe to uninstall flash player (skipped step 9 because those folders didn't exist for me after uninstallation). I then rebooted after the uninstall.

     

    http://helpx.adobe.com/flash-player/kb/uninstall-flash-player-mac-os.html#main_u ninstall

     

    I am no longer experiencing the popups from before! feels so relieving

  • by omijan7,

    omijan7 omijan7 Apr 28, 2014 2:26 PM in response to sirpig
    Level 1 (0 points)
    Apr 28, 2014 2:26 PM in response to sirpig

    I tried sirpig's suggestion and I think it's fixed!  I'm holding my breath, but so far so good.  The first time I tried clicking a link on a page it went to an ad, but after that it seemed to be working.  I've tried and tried to get another ad and it's not doing it!  Yipee!

     

    You're right -- I'm very relieved!  I've now had to do this fix on my desktop as well as my laptop - may need to do it on my iPad.

     

    Thanks so much!

  • by Allan Jones,

    Allan Jones Allan Jones Apr 28, 2014 2:59 PM in response to James Cook2
    Level 8 (35,071 points)
    iPad
    Apr 28, 2014 2:59 PM in response to James Cook2

    James, You have the WD software that comes with a WD external drive, yet I don't a WD external listed. Their drives are fine; their software is a mess. Delete it (wdc.driver).

     

    you also have the horrible Conduit toolbar modifier. Gotta go!

     

    http://www.thesafemac.com/arg-conduit/

     

    EVERYBODY ELSE!

     

    Please start yourt own threads with the information you've posted here. It is horribly difficult to help multiple people in one thread. You're making me crazy!!!!

  • by James Cook2,

    James Cook2 James Cook2 Apr 28, 2014 4:08 PM in response to Allan Jones
    Level 1 (15 points)
    Notebooks
    Apr 28, 2014 4:08 PM in response to Allan Jones

    I've done the suggested cleanups. I believe they were left over debris. For sure they were not in any active use.

     

    I tried the Flash uninstall in case this is some Flash exploitation. I can say for sure that it did not make a difference.

Page 1 of 4 last Next