fsmobilez

Q: macbook infected with fast-ads.us popup virus

my macbook is infected with fast-ads.us pop us virus, have tried almost each and everything mentioned on this forum and net, run different malware programes, it detected cinema pro as malware, removed it, but still issue

than ran norton and avg anti virus, nothing detected, deleted each and every plugin but still having this pop up virus

 

virus detail, when a new site is opened in chrome or safari, it shows popup with different sites

 

i can even browse net coz of this malware, virus, some one help get out of this. im really frustrated.

MacBook Pro with Retina display, OS X Yosemite (10.10.2)

Posted on Feb 5, 2015 12:14 AM

Close

Q: macbook infected with fast-ads.us popup virus

  • All replies
  • Helpful answers

Previous Page 2 of 3 last Next
  • by Linc Davis,

    Linc Davis Linc Davis Feb 6, 2015 10:25 AM in response to fsmobilez
    Level 10 (208,044 points)
    Applications
    Feb 6, 2015 10:25 AM in response to fsmobilez

    Start up in Recovery mode. In the OS X Utilities screen, select Get Help Online. A clean copy of Safari will launch. No plugins, such as Flash, will be available. While in Recovery, you'll have no access to your saved bookmarks or passwords, so make a note of those before you begin, if they're needed for the test.

    Test. After testing, restart as usual and post the results.

  • by Denon69,

    Denon69 Denon69 Feb 7, 2015 1:24 AM in response to Leopardus
    Level 1 (0 points)
    Feb 7, 2015 1:24 AM in response to Leopardus

    Thanks. great advice and very much appreciated.

  • by MadMacs0,

    MadMacs0 MadMacs0 Feb 7, 2015 1:41 AM in response to Denon69
    Level 5 (4,801 points)
    Feb 7, 2015 1:41 AM in response to Denon69

    Denon69 wrote:

     

    Thanks. great advice and very much appreciated.

    So just to make sure we understand (since the OP has not yet solved this issue) you were seeing ads from fast-ads.us and AdwareMedic solved the problem? Do you recall what the name of the Adware found was? If you have forgotten and still have AdwareMedic, can you open it again and choose "Open Log file" from the Scanner Menu (a TextEdit file), then copy and paste the results back here?

  • by fsmobilez,

    fsmobilez fsmobilez Feb 7, 2015 12:26 PM in response to MadMacs0
    Level 1 (0 points)
    Feb 7, 2015 12:26 PM in response to MadMacs0

    2015-01-22 23:45:05: ----- Scan Started -----

    2015-01-22 23:45:05: Scanning with signatures version 48

    2015-01-22 23:45:08: Buca Apps : /Users/zulqarnainmalik/Library/Safari/Extensions/cinema-+-pro1-1.safariextz , /Users/zulqarnainmalik/Library/Application Support/Mozilla/Extensions/{ec8030f7-c20a-464f-9b0e-13a3a9e97384}/FNILGZ81840990@OKCZ70157576.c om

    2015-01-22 23:45:08: Buca Apps : /Users/zulqarnainmalik/Library/Safari/Extensions/cinema-+-pro1-1.safariextz , /Users/zulqarnainmalik/Library/Application Support/Mozilla/Extensions/{ec8030f7-c20a-464f-9b0e-13a3a9e97384}/FNILGZ81840990@OKCZ70157576.c om

    2015-01-22 23:45:08: ----- Scan Ended -----

  • by fsmobilez,

    fsmobilez fsmobilez Feb 7, 2015 1:06 PM in response to Linc Davis
    Level 1 (0 points)
    Feb 7, 2015 1:06 PM in response to Linc Davis

    In recovery mode not even a single pop up is showing while using safari but when i loged in back in my account, pop up start showing.

  • by MadMacs0,

    MadMacs0 MadMacs0 Feb 7, 2015 2:12 PM in response to fsmobilez
    Level 5 (4,801 points)
    Feb 7, 2015 2:12 PM in response to fsmobilez

    fsmobilez wrote:

     

    2015-01-22 23:45:05: ----- Scan Started -----

    2015-01-22 23:45:05: Scanning with signatures version 48

    Thanks. I'm hoping to hear from Denon69 since he/she seems to have solved it.

  • by Linc Davis,

    Linc Davis Linc Davis Feb 7, 2015 2:20 PM in response to fsmobilez
    Level 10 (208,044 points)
    Applications
    Feb 7, 2015 2:20 PM in response to fsmobilez

    I'm not sure why they would not show up in the test results, but select the Extensions tab in the Safari preferences window and check for installed extensions. If there are any, delete them. Do the equivalent in your other browsers. Test.

  • by fsmobilez,

    fsmobilez fsmobilez Feb 7, 2015 11:41 PM in response to Linc Davis
    Level 1 (0 points)
    Feb 7, 2015 11:41 PM in response to Linc Davis

    as mentioned in my first post, i have already deleted all plugin from all browers but im confused that in one of the above post u mentioned im using 4 browsers while i know about 3 browsers installed, chrome, firefox and safari,

     

    can u please mention the fourth one so i can delete that browser.

     

    what if i restore using recovery will it solve my problem but please note my data is very important , do recovery deletes any data or its safe to run recovery because i want to get rid of this virus at any cost

  • by MadMacs0,

    MadMacs0 MadMacs0 Feb 8, 2015 12:44 AM in response to fsmobilez
    Level 5 (4,801 points)
    Feb 8, 2015 12:44 AM in response to fsmobilez

    fsmobilez wrote:

     

    u mentioned im using 4 browsers while i know about 3 browsers installed, chrome, firefox and safari, can u please mention the fourth one so i can delete that browser.

    Opera.

    what if i restore using recovery will it solve my problem but please note my data is very important , do recovery deletes any data or its safe to run recovery because i want to get rid of this virus at any cost

    Restoring OS X from your Recovery HD does not delete anything (unless you choose to erase your hard drive first). All it does is give you a fresh version of the last version of OS X you installed using a full installer.

  • by Linc Davis,

    Linc Davis Linc Davis Feb 8, 2015 8:07 AM in response to fsmobilez
    Level 10 (208,044 points)
    Applications
    Feb 8, 2015 8:07 AM in response to fsmobilez

    Are you in Nigeria, or from there? If not, why do you have software from a Nigerian ISP (Visafone) installed?

  • by fsmobilez,

    fsmobilez fsmobilez Feb 8, 2015 10:44 PM in response to Linc Davis
    Level 1 (0 points)
    Feb 8, 2015 10:44 PM in response to Linc Davis

    i dont remember why and when visafone software was installed but just removed it , restart the mac but still same popups .

     

    any other recommendations?

  • by Linc Davis,

    Linc Davis Linc Davis Feb 8, 2015 11:33 PM in response to fsmobilez
    Level 10 (208,044 points)
    Applications
    Feb 8, 2015 11:33 PM in response to fsmobilez

    You have some pretty dubious apps, including one ("HackStore") that seems to be a torrent client specifically for pirated software. I also notice that Microsoft Office is installed, but the activation daemon that goes along with it is missing. That would mean that Office couldn't run unless it had been hacked.

     

    If you've been running pirated software downloaded from a torrent, you're an excellent candidate to be the first to install every new kind of malware that comes along. Within the scope of a Google search, no one else has ever reported an adware infection like the one you seem to have, not even on Windows.

     

    Taking everything you say at face value, I almost have to suspect that you may have installed some kind of rootkit that modifies the operating system at a level that can't be detected by the means I use. Maybe it's causing the test script to give false results. That's always a theoretical possibility, though I've never actually seen it happen as far as I know. A rooted system can't be trusted to analyze itself.

     

    If I'm right, then the only thing you can do is a full post-intrusion cleanup.

    Back up all data to at least two different storage devices, if you haven't already done so. One backup is not enough to be safe. The backups can be made with Time Machine or with Disk Utility. Preferably both.

    Erase and install OS X. This operation will destroy all data on the startup volume, so you had be better be sure of the backups. If you upgraded from an older version of OS X, you'll need the Apple ID and password that you used, so make a note of those before you begin.

    When you restart, you'll be prompted to go through the initial setup process in Setup Assistant. That’s when you transfer the data from a backup.

    Select only users and Computer & Network Settings in the Setup Assistant dialog—not Applications or Other files and folders. Don't transfer the Guest account, if it was enabled.

    After that, check the App Store for software updates.

    If the problem is resolved after the clean installation, reinstall third-party software selectively. I can only suggest general guidelines. Self-contained applications that install into the Applications folder by drag-and-drop or download from the App Store are usually safe. Anything that comes packaged as an installer or that prompts for an administrator password is suspect, and you must test thoroughly after reinstalling each such item to make sure you haven't restored the problem.

    I strongly recommend that you never reinstall commercial "security" products or "utilities," nor any software that changes the user interface or the behavior of built-in applications such as Safari. If you do that, the problem is likely to recur.

    Do not reinstall "AVG," any pirated commercial software such as Office, or anything at all that came from a torrent or from a third-world ISP.

    Any system modifications that you do choose to install must be kept up to date. None is required for normal operation.

    Before installing any software, ask yourself the question: "Am I sure I know how to uninstall this without having to wipe the volume again?" If the answer is "no," stop.

    Never install any third-party software unless you know how to uninstall it.

    That being done, change all Internet passwords and check all financial accounts for unauthorized transactions. Do this  after the system has been secured, not before.

  • by fsmobilez,

    fsmobilez fsmobilez Feb 8, 2015 11:36 PM in response to Linc Davis
    Level 1 (0 points)
    Feb 8, 2015 11:36 PM in response to Linc Davis

    another finding the same popups are showing in my iphone 6 ios 8.1.2 in safari.

  • by Linc Davis,

    Linc Davis Linc Davis Feb 9, 2015 12:26 AM in response to fsmobilez
    Level 10 (208,044 points)
    Applications
    Feb 9, 2015 12:26 AM in response to fsmobilez

    But not on the Mac in Recovery mode?

  • by fsmobilez,

    fsmobilez fsmobilez Feb 9, 2015 11:13 AM in response to Linc Davis
    Level 1 (0 points)
    Feb 9, 2015 11:13 AM in response to Linc Davis

    Yes no popups in Mac in Recovery mode and also on website which have https://

Previous Page 2 of 3 last Next