Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

MPlayerX Malware Removal

I was recently approched by a friend who had accidentally downloaded and run the installer for what appears to be a trojan. The installer says it is "MPlayerX" which appears to be a legitimate application, however the installer bears no resemblence to the one of the actual application.

Virus total link

Here is a screenshot:

User uploaded file

He followed through the install process, and entered his password. I did a lot of googling but could not find any information. I then decided to give it a crack mysef and opened up the install binary in a disassembler. Unfortunatley, this was way above my level and I could not make sense of it. Here are the details of his computer:

User uploaded file

As he supplied his password, it is possible that it may have installed a rootkit as well.

Has anyone ever encountered this before, or do you know how to remove it?

MacBook Pro, OS X Mavericks (10.9.1)

Posted on May 19, 2014 9:36 AM

Reply
Question marked as Best reply

Posted on May 19, 2014 10:56 AM

After looking at the launch agents loaded on his computer (launchctl list) I found several plists that seemed out of order:


  • /Library/LaunchAgents/com.vsearch.agent.plist
  • /Library/LaunchDaemons/com.vsearch.daemon.plist
  • /Library/LaunchDaemons/com.vsearch.helper.plist
  • /Library/LaunchDaemons/Jack.plist


After googling these I ended up finding an article explaining how to remove it
46 replies

Nov 6, 2014 1:41 PM in response to thomas_r.

Thomas, thank you so much for writing your script and sharing your knowledge. I stupidly clicked on what I thought was an update this morning, and this thread and your script saved me from doom. I appreciate your willingness to share with those who are less computer-saavy. From the bottom of my heart, thank you.


And now I'm off to make a healthy donation to "The Safe Mac!"


Machta

Nov 9, 2014 9:06 AM in response to thomas_r.

Hi Thomas - I am having similar issues. I think I have downloaded the MPlayerX file and its infected my computer. I've tried accessing the links provided in the thread and it looks like I'm being blocked. Syas either page is not available or re-routes me to another page. Are you able to send me an alternate like to your tool. I don't know what else to do to remove this Malware. Hoping that you can help please. Thanks.

Nov 9, 2014 9:42 AM in response to missdiva78

You are infected with Downlite, which is preventing you from accessing the AdwareMedic site. For an explanation and some solutions, see:


http://www.thesafemac.com/adware-blocking-adwaremedic-downloads/


If the adware prevents you from loading that page as well, try this one:


https://discussions.apple.com/docs/DOC-7792


(Fair disclosure: I may receive compensation from links to my sites, TheSafeMac.com and AdwareMedic.com, in the form of buttons allowing for donations. Donations are not required to use my site or software.)

Nov 9, 2014 1:30 PM in response to thomas_r.

Just a follow up question. The MPlayerX icon still appears on my Launchpad page is this normal after using the Adware Medic to clean the computer? If so how do I remove it from the desktop? The computer is performing normally now and I did see the deleted files in my trash which I have now emptied but the icon remains on the Launchpad. Don't know if this is something that I should be concerned about. Your thoughts please?

Nov 10, 2014 11:00 AM in response to Tesla735

I received this same adware content by attempting to listen to a live radio/tv broadcast online. My internet browser ran amuck with ads immediately after downloading what I thought was legitimate software. Thanks to the trusty mac forum, and this particular thread - and especially the efforts of Thomas to rid us all of this ghastly brew of incessant advertising (I had no idea this kind of maliciousness existed until now), I now have my computer back to good.

It worked! Phew!

Jan 17, 2015 1:41 PM in response to Tesla735

I wanted to shout out to Thomas, I like most on this blog, have been very protective of my mac being educated enough to know they can still get malware or viruses. However made the mistake on a site that looked exactly like my cable provider of downloading Mplayerx. Shortly after searching found this and due to being on the Apple communities site trusted it. I am impressed. I love the convenience and entering manual code I didn't have time for, so thanks Thomas we need more people like you out there.

Mar 17, 2015 10:42 AM in response to thomas_r.

Thomas, wanted to point out that I used admedic, which seemed to remove a few crapwares from my mac, but my problem persisted (shoedazzle, housemastery, etc). Then I used your old tool script, it found conduit and deleted that crap, totally fixed my issue! thanks, and hope this helps others.


osx 10.9.5

chrome Version 41.0.2272.89 (64-bit)

2.5ghz core 2 duo/4gb ram

Mar 17, 2015 1:13 PM in response to MacCook Pro

AdwareMedic should remove everything that the older script did, and more, with a few exceptions. The main exceptions are things like Firefox settings files that are modified by some versions of Conduit. AdwareMedic does not remove those by default, but warns you about the problem so you can decide how you want to handle it. The older script had little subtlety, and would just delete those files.

Mar 21, 2015 9:53 PM in response to praiford

After downloading MPlayerX malware (oops!) ran your TSM Adware Removal Tool but when trying to empty the Trash the following messages appear: The operation can’t be completed because the item “codecm_uploader” is in use.

The operation can’t be completed because the item “MPlayerX-2.dmg” is in use.

The operation can’t be completed because the item “MPlayerX-1.dmg” is in use.


There is also a folder entitled TSMART20....


Can you help please

Mar 23, 2015 9:54 AM in response to selbats

selbats wrote:


After downloading MPlayerX malware (oops!) ran your TSM Adware Removal Tool but when trying to empty the Trash the following messages appear:


First, note that that tool is extremely outdated and has been discontinued. I don't recommend using it anymore.


Second, you need to restart your computer in order to fully remove the adware and make it possible to empty the trash.

MPlayerX Malware Removal

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.