You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

ad-injection software infestation

Hi,


I have been having problems with what I assume is what they call ad-injection softwareUser uploaded file. In the recent past, it was something called InstallerT, which I understand is some kind of ad-ware injection software and is most likely connected with URL sites not representing a "true" purpose, such as "Genio", or something like that. I have followed the recommendations found on this forum and have removed these infestations, but now I have found something else. I can't describe how it got onto my MacBook pro, but it has the names of "AppT", "MegaBackup", and "Oliverto", whatever they are. I did a little on-line research and found out that "MegaBackup" is a MicroSoft PC app and has no counterpart for the Mac OSX systems, so I assume that this is another "ad-ware virus" attempt at an invasion. I think I have removed these offending elements by simplily moving them to my Trash and choosing "Secure Delete". I would like to know if this is efficient or that I need to take additional steps. In the end, I find all this to be a bit tiresome, like getting telemarketer calls at the most inappropriate times. Thanks in advance...

MacBook Pro, OS X Yosemite (10.10.3)

Posted on May 31, 2015 10:42 PM

Reply
Question marked as Top-ranking reply

Posted on May 31, 2015 10:48 PM

Helpful Links Regarding Malware Problems


If you are having an immediate problem with ads popping up see The Safe Mac » Adware Removal Guide, remove adware that displays pop-up ads and graphics on your Mac, and AdwareMedic. If you require anti-virus protection Thomas Reed recommends using ClamXAV. (Thank you to Thomas Reed for this recommendation.) You might consider adding this Safari extensions: Adblock Plus 1.8.9.


Open Safari, select Preferences from the Safari menu. Click on Extensions icon in the toolbar. Disable all Extensions. If this stops your problem, then re-enable them one by one until the problem returns. Now remove that extension as it is causing the problem.


The following comes from user stevejobsfan0123. I have made minor changes to adapt to this presentation.


Fix Some Browser Pop-ups That Take Over Safari.


Common pop-ups include a message saying the government has seized your computer and you must pay to have it released (often called "Moneypak"), or a phony message saying that your computer has been infected, and you need to call a tech support number (sometimes claiming to be Apple) to get it resolved. First, understand that these pop-ups are not caused by a virus and your computer has not been affected. This "hijack" is limited to your web browser. Also understand that these messages are scams, so do not pay any money, call the listed number, or provide any personal information. This article will outline the solution to dismiss the pop-up.


Quit Safari


Usually, these pop-ups will not go away by either clicking "OK" or "Cancel." Furthermore, several menus in the menu bar may become disabled and show in gray, including the option to quit Safari. You will likely have to force quit Safari. To do this, press Command + option + esc, select Safari, and press Force Quit.


Relaunch Safari


If you relaunch Safari, the page will reopen. To prevent this from happening, hold down the 'Shift' key while opening Safari. This will prevent windows from the last time Safari was running from reopening.


This will not work in all cases. The shift key must be held at the right time, and in some cases, even if done correctly, the window reappears. In these circumstances, after force quitting Safari, turn off Wi-Fi or disconnect Ethernet, depending on how you connect to the Internet. Then relaunch Safari normally. It will try to reload the malicious webpage, but without a connection, it won't be able to. Navigate away from that page by entering a different URL, i.e. www.apple.com, and trying to load it. Now you can reconnect to the Internet, and the page you entered will appear rather than the malicious one.

3 replies
Question marked as Top-ranking reply

May 31, 2015 10:48 PM in response to tmoonbeam437

Helpful Links Regarding Malware Problems


If you are having an immediate problem with ads popping up see The Safe Mac » Adware Removal Guide, remove adware that displays pop-up ads and graphics on your Mac, and AdwareMedic. If you require anti-virus protection Thomas Reed recommends using ClamXAV. (Thank you to Thomas Reed for this recommendation.) You might consider adding this Safari extensions: Adblock Plus 1.8.9.


Open Safari, select Preferences from the Safari menu. Click on Extensions icon in the toolbar. Disable all Extensions. If this stops your problem, then re-enable them one by one until the problem returns. Now remove that extension as it is causing the problem.


The following comes from user stevejobsfan0123. I have made minor changes to adapt to this presentation.


Fix Some Browser Pop-ups That Take Over Safari.


Common pop-ups include a message saying the government has seized your computer and you must pay to have it released (often called "Moneypak"), or a phony message saying that your computer has been infected, and you need to call a tech support number (sometimes claiming to be Apple) to get it resolved. First, understand that these pop-ups are not caused by a virus and your computer has not been affected. This "hijack" is limited to your web browser. Also understand that these messages are scams, so do not pay any money, call the listed number, or provide any personal information. This article will outline the solution to dismiss the pop-up.


Quit Safari


Usually, these pop-ups will not go away by either clicking "OK" or "Cancel." Furthermore, several menus in the menu bar may become disabled and show in gray, including the option to quit Safari. You will likely have to force quit Safari. To do this, press Command + option + esc, select Safari, and press Force Quit.


Relaunch Safari


If you relaunch Safari, the page will reopen. To prevent this from happening, hold down the 'Shift' key while opening Safari. This will prevent windows from the last time Safari was running from reopening.


This will not work in all cases. The shift key must be held at the right time, and in some cases, even if done correctly, the window reappears. In these circumstances, after force quitting Safari, turn off Wi-Fi or disconnect Ethernet, depending on how you connect to the Internet. Then relaunch Safari normally. It will try to reload the malicious webpage, but without a connection, it won't be able to. Navigate away from that page by entering a different URL, i.e. www.apple.com, and trying to load it. Now you can reconnect to the Internet, and the page you entered will appear rather than the malicious one.

May 31, 2015 11:09 PM in response to tmoonbeam437

There is no need to download anything to solve this problem. You installed a variant of the "InstallMac" trojan. Take the steps below to disable it.

The criminal behind this attack tries to make the malware difficult to remove by varying the names of the files it installs. This procedure works as of now, as far as I know. It may not work in the future. Anyone finding this comment a few days or more after it was posted should look for a more recent discussion, or start a new one.

Back up all data before continuing.

1. Triple-click the line below on this page to select it, then copy the text to the Clipboard by pressing the key combination command-C:

~/Library/LaunchAgents

In the Finder, select

Go Go to Folder...

from the menu bar and paste into the box that opens by pressing command-V. You won't see what you pasted because a line break is included. Press return. A folder named "LaunchAgents" will open.

2. Inside the folder you just opened, there may be files with a name beginning in either of the following ways:

Oliverto

Texiday

Move all such items to the Trash.

Log out or restart the computer. The trojan will now be inactive, but there are a few more components of it that should be cleaned up.

3. Open this folder in the same way as above:

~/Library/Application Support

and move to the Trash any items named as in Step 2.

Empty the Trash.

4. From the Safari menu bar, select

Safari Preferences... Extensions

Uninstall all extensions you don't know you need. If in doubt, remove all of them. None is required for normal operation. Do the equivalent in the Chrome and Firefox browsers, if you use either of those.

ad-injection software infestation

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.