Apple Event: May 7th at 7 am PT

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

how do I remove the "only Search" virus?

My Mac Pro has got the "Only Search Virus " how can I remove this and resolve the issue

Posted on Nov 11, 2014 10:39 AM

Reply
48 replies

Dec 15, 2014 9:24 PM in response to lp690

You have what seems to be a new variant of the "VSearch" malware, makingthis Apple Support page obsolete. Use the technique in the linked article to remove these items:


/Library/Application Support/dot

/Library/LaunchAgents/com.dot.agent.plist

/Library/LaunchDaemons/com.dot.daemon.plist

/Library/LaunchDaemons/com.dot.helper.plist


You don't have any Safari extensions, but you should remove any Chrome or Firefox extensions that you don't know you need. If in doubt, remove all of them.


Without a sample of this new malware to test, I can't be sure that it's nothing more than an ad injector, so you may prefer to consider the machine totally compromised. That decision is yours to make. Ask for guidance if you need it.


If you know where you downloaded the fake MPlayerX application, please post a link.

Dec 16, 2014 5:35 AM in response to Linc Davis

Linc Davis wrote:


/Library/Application Support/dot

/Library/LaunchAgents/com.dot.agent.plist

/Library/LaunchDaemons/com.dot.daemon.plist

/Library/LaunchDaemons/com.dot.helper.plist


There will probably also be another file:


/System/Library/Frameworks/v.framework


[Edit: fixed error in path]


That also needs to be removed, if present. It's possible that the file will have a different name, but probably not.


Also, Linc, FYI - there's another variant that appears to be nearly identical to this one, with the only difference being the use of the name "heizenberg" in place of "dot" or "vsearch". I suspect we'll see others as well. I've forwarded this information on to Apple's product security team.

Dec 16, 2014 6:45 AM in response to lp690

It's not in the /Library folder like all the other items, it's in /System/Library. Select the path to that v.framework file and copy it, then go to the Finder and choose Go -> Go to Folder and paste the path in, then click Go. A Finder window should open showing that file. If it's not there, it may be named something else in the case of the variant of Downlite that you have installed.

Dec 16, 2014 8:58 AM in response to lp690

It's there. If it weren't, your system wouldn't start up.


Let's try to figure out where this is going wrong. Select and copy the following line in its entirety:


/System/Library/Frameworks/


Now, go to the Finder and choose Go -> Go to Folder, paste the copied text into the box, and click Go. Does a folder named Frameworks open in the Finder? If it doesn't, you did something wrong, and need to review and repeat the instructions.


In the folder that opens, look for an item named "v.framework" and drag it to the trash. Report back here if you don't see this item.

Dec 21, 2014 9:12 AM in response to lydcarol

lydcarol wrote:


I didn't find any files that you mentioned. Found the 'v.framework' files though and deleted it.


You have one of the newest variants of Downlite, and the files mentioned by Linc above containing the word "dot" will have a different name on your system. This variant seems to be using random words as filenames... only the v.framework item has the same name among all the variants I've seen.


For manual removal, see:


http://www.thesafemac.com/arg-downlite


Alternately, you could download my AdwareMedic app, which will find these files no matter what they are named and remove them:


http://www.adwaremedic.com


(Fair disclosure: I may receive compensation from links to my sites, TheSafeMac.com and AdwareMedic.com, in the form of buttons allowing for donations. Donations are not required to use my site or software.)

how do I remove the "only Search" virus?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.