Apple Event: May 7th at 7 am PT

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

MPlayerX Malware Removal

I was recently approched by a friend who had accidentally downloaded and run the installer for what appears to be a trojan. The installer says it is "MPlayerX" which appears to be a legitimate application, however the installer bears no resemblence to the one of the actual application.

Virus total link

Here is a screenshot:

User uploaded file

He followed through the install process, and entered his password. I did a lot of googling but could not find any information. I then decided to give it a crack mysef and opened up the install binary in a disassembler. Unfortunatley, this was way above my level and I could not make sense of it. Here are the details of his computer:

User uploaded file

As he supplied his password, it is possible that it may have installed a rootkit as well.

Has anyone ever encountered this before, or do you know how to remove it?

MacBook Pro, OS X Mavericks (10.9.1)

Posted on May 19, 2014 9:36 AM

Reply
Question marked as Best reply

Posted on May 19, 2014 10:56 AM

After looking at the launch agents loaded on his computer (launchctl list) I found several plists that seemed out of order:


  • /Library/LaunchAgents/com.vsearch.agent.plist
  • /Library/LaunchDaemons/com.vsearch.daemon.plist
  • /Library/LaunchDaemons/com.vsearch.helper.plist
  • /Library/LaunchDaemons/Jack.plist


After googling these I ended up finding an article explaining how to remove it
46 replies

Sep 4, 2014 7:33 AM in response to thomas_r.

THOMAS_R . A very big BIG Thank you to you Thank you, THANK YOU….


I also downloaded the mplayerx app. not knowing what it contained and it instantly started slowing everything down. Googled mplayerx and noticed ‘malware’ as a search possibility. went to several sites and then found this thread with your wonderful “App” Just in the nick of time I think, it really seemed like a race against the clock as things were getting so slow, to such an extent that it was taking 10 minutes to open a new webpage. quite scary (had visions of losing everything)


Took ages but managed to finally download and run your wonder cure. Everything totally back on the rails after re-start. A thousand thank yous again.


Mark Briscoe (artist)

Oct 11, 2014 2:41 PM in response to Tesla735

Just created an account to also thank Thomas. The way I accidentally downloaded the adware was as I was studying for a test, I'd burned the midnight oil and idly clicked on one of those sites that says, "You'll never guess who they got to play Aquaman." Took it hook, line and sinker. Then the site popped up to update the video player. I feel so gullible right now. But Thomas's program seems to have done the trick. Thank you, Thomas!

Oct 12, 2014 12:12 AM in response to thomas_r.

Thanks Thomas! Seems like I am one of many who accidentally ended up with MplayerX and your app worked great...my pages seem to be back to normal, but I'm still seeing the "MplayerX" icon on my computer along with something called "Time Machine" that looks similar to it and that won't go to the trashcan/delete. Any idea of how to get rid of them/deleted completely?? Thank you!!


-Lindsey

Oct 16, 2014 3:15 PM in response to Tesla735

I can't thank you enough for all this VERY useful information !! You guys saved me from my temporary insanity. I couldn't find the file called Jack, but no matter. I simply dumped everything indicated from the Safe Mac Adware Removal Guide : DownLite site, and now all my problems are gone.


http://www.thesafemac.com/arg-downlite/


Thank you again,


Malcolm

Nov 4, 2014 12:12 PM in response to bryanus

YES ! A giant thank you to Thomas. I was not trying to pirate anything (my friend was downloading the player to watch football games). But the AdMedic worked faster than anything I've ever seen. And I possess ZERO computer skills. Thanks for making it so easy !


And as a side note…..I hope others are making a donation, too. We need to keep guys like this is business !

MPlayerX Malware Removal

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.