rachealfromva

Q: After downloading Mavericks Spibot has installed itself on my MacBook Pro

After downloading Mavericks 10.9.5 on my MacBook Pro Spibot has installed itself on my Mac, I installed AdBlock to remove any Ads and did a Systems scan and noticed this wretch.  I cannot find Library even with doing a search via Spotlight, it seems that some Maverick Applications are missing such as movies music pictures and public.  Half of the Snow Leopard 10.6.8 applications are unusable.  I have changed all my password and stopped using the MacBook Pro.  If someone can please advise what action I should take without formatting my hard drive which,  I have no experience in doing this.  I have looked on the net to see if I can get any straightforward instruction without all the technical jargon to format the hard drive and still looking.

 

Thank you ladies and gentleman

 

rachealfromva

Mac mini, Mac OS X (10.6.8)

Posted on Oct 8, 2014 4:50 AM

Close

Q: After downloading Mavericks Spibot has installed itself on my MacBook Pro

  • All replies
  • Helpful answers

  • by Linc Davis,

    Linc Davis Linc Davis Oct 8, 2014 1:41 PM in response to rachealfromva
    Level 10 (208,037 points)
    Applications
    Oct 8, 2014 1:41 PM in response to rachealfromva
    Spibot has installed itself on my Mac

    How do you know that?

  • by rachealfromva,

    rachealfromva rachealfromva Oct 8, 2014 4:15 PM in response to rachealfromva
    Level 1 (11 points)
    Desktops
    Oct 8, 2014 4:15 PM in response to rachealfromva

    Hello Mr. Davis,

     

    Thank you for your response when I did an AdBlock system scan this is what I found Spigot:/users/my name/library/safari/extensions/amazon shopping,

    furthermore I cannot find Library, tried to do a Spotlight and Finder go to but nothing.  I read your response to another unfortunate person, unfortunately, I am a little nervous trying to delve to far in case I create a further hornets nest.  Generally I am the most caution person and only use Itunes and Apple to download items I require.

     

    Kind regards

     

    rachealfromva

  • by Linc Davis,

    Linc Davis Linc Davis Oct 8, 2014 5:04 PM in response to rachealfromva
    Level 10 (208,037 points)
    Applications
    Oct 8, 2014 5:04 PM in response to rachealfromva

    You may have installed the "InstallMac" trojan. I suggest the procedure below to disable it. This procedure may leave a few small files behind, but it will permanently deactivate the trojan (as long as you never reinstall it.)

    Malware is always changing to get around the defenses against it. These instructions are valid as of now, as far as I know. They won't necessarily be valid in the future. Anyone finding this comment a few days or more after it was posted should look for more recent discussions or start a new one.

    Back up all data before proceeding.

    Step 1

    From the Safari menu bar, select

              Safari Preferences... Extensions

    Uninstall any extensions you don't know you need, including one called "Omnibar," and any that have the word "Conduit," "Spigot," or "InstallMac" in the description. If in doubt, uninstall all extensions. Do the equivalent for the Firefox and Chrome browsers, if you use either of those.

    Step 2

    In the Applications folder, there may be items named "Installer," "InstallMac," "Reset Search," or "Uninstall IM Completer." Drag each such item to the Trash.

    Step 3

    Triple-click anywhere in the line below on this page to select it:

    ~/Library/LaunchAgents/com.genieo.completer.download.plist

    Right-click or control-click the line and select

              Services Reveal in Finder (or just Reveal)

    from the contextual menu.

    If you don't see the contextual menu item, copy the selected text to the Clipboard by pressing the key combination command-C. In the Finder, select

              Go Go to Folder...

    from the menu bar and paste into the box that opens by pressing command-V. You won't see what you pasted because a line break is included. Press return.

    A folder may open with an item named "com.genieo.completer.download.plist" selected. Move that item to the Trash.

    In the same folder there may be an item named "com.genieo.completer.update.plist". Move it to the Trash as well.

    Optionally, move this item, if it exists, to the Trash in the same way:

    ~/Library/Application Support/com.genieoinnovation.Installer

    Log out or restart the computer and empty the Trash.

    Make sure you don't repeat the mistake that led you to install this trojan. Chances are you got it from an Internet cesspit such as "Softonic" or "CNET Download." Never visit either of those sites again. You might also have downloaded it from an ad in a page on some other site. The ad has a large green button labeled "Download" or "Download Now" in white letters. The button is designed to confuse people who intend to download something else on the same page. If you ever download a file that isn't obviously what you expected, delete it immediately.

    You may be wondering why you didn't get a warning from Gatekeeper about installing software from an unknown developer, as you should have. The reason is that the Internet criminal behind this attack has a codesigning certificate issued by Apple, which causes Gatekeeper to give the installer a pass. Apple could revoke the certificate, but as of this writing, has not done so, even though it's aware of the problem. This failure of oversight has compromised both Gatekeeper and the Developer ID program. You can't rely on Gatekeeper alone to protect you from harmful software.

  • by rachealfromva,

    rachealfromva rachealfromva Oct 9, 2014 2:15 AM in response to Linc Davis
    Level 1 (11 points)
    Desktops
    Oct 9, 2014 2:15 AM in response to Linc Davis

    Hello Mr. Davis,

     

    Many thanks for your valued support, I have tried to follow your instructions, when I go to Finder>go to> Library it cannot find folder, tried all the other steps but it cannot find anything whatsoever, it seems Library has been totally wiped out and everything is a total mess.  Whilst waiting for your news I looked for instructions for formating the hard drive and installing Mavericks 10.9 on a clean slate, the site I looked on is OXDaily, your recommendations would be much appreciated.  I was,  as a last resort going to the Apple Store, but I must learn to do these things myself.  I normally am very vigilant, I will be even more vigilant.  Once again Thank you.

     

    rachealfromva

  • by Linc Davis,

    Linc Davis Linc Davis Oct 9, 2014 7:15 AM in response to rachealfromva
    Level 10 (208,037 points)
    Applications
    Oct 9, 2014 7:15 AM in response to rachealfromva

    The "Genieo" files may not be present. In that case, all you need to do is Step 1.

  • by rachealfromva,

    rachealfromva rachealfromva Oct 10, 2014 3:59 AM in response to Linc Davis
    Level 1 (11 points)
    Desktops
    Oct 10, 2014 3:59 AM in response to Linc Davis

    Hello Mr. Davis,

     

    Thank you for your response, I have since found my Library, went into Application Support and could not find any signs of Genieo or Spigot, however, I did find com.apple.TCC, which will not allow me to open saying I have no permission to do so, I did follow the instructions you gave to another person I was not able to access Terminal to enter the instructions.  Could these creatures be sitting in this folder?  I apologise for my limited knowledge and very much appreciate your valued help. One more thing that I noticed in Library some folders are missing, I do not know what they are I just see blank spaces rather that the normal uniform display.  Is it worth me formating the hard drive and re-installing Mavericks on a clean drive.  Thank you once again

  • by Linc Davis,

    Linc Davis Linc Davis Oct 10, 2014 7:24 AM in response to rachealfromva
    Level 10 (208,037 points)
    Applications
    Oct 10, 2014 7:24 AM in response to rachealfromva

    Please post a screenshot that shows what you mean. Be careful not to include any private information.

    Start a reply to this message. Drag the image file into the editing window to upload it. You can also include text in the reply.

  • by rachealfromva,

    rachealfromva rachealfromva Oct 14, 2014 3:36 AM in response to Linc Davis
    Level 1 (11 points)
    Desktops
    Oct 14, 2014 3:36 AM in response to Linc Davis

    Dear Mr. Davis,

     

    Thank you for your response, out sheer of desperation,  I tried once more going through all your suggestions, I finally got rid of the nasties and my MacBook Pro looks good as it should. I cannot thank you,  or any of the other supporters for such wonderful and dedicated help we Mac lovers receive from you,  I am glad I keep printed copies of discussions, which, I am sure will help in the near future.  Once again THANK YOU

     

    rachealfromva