Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

HOW TO REMOVE ADWARE????

Lately lots of ads have been popping up whenever i try to log in somewhere or click enter. I've already checked and deleted the extensions and checked in my files if i have any malware but I don't. Mainly, mackeeper and ZipCloud ads pop up. I've been trying to resolve this problem but I can't find the origin. Any ideas on how to remove ads?

MacBook Pro (Retina, 13-inch, Late 2013), OS X Yosemite (10.10.4)

Posted on Aug 3, 2015 12:13 PM

Reply
5 replies

Aug 3, 2015 12:18 PM in response to AnakarenNunez

A

Don't use any kind of "anti-virus" or "anti-malware" product on a Mac. There is never a need for it, and relying on it for protection makes you more vulnerable to attack, not less.

You may have installed a variant of the "VSearch" ad-injection malware. Follow Apple Support's instructions to remove it.

If you have trouble following those instructions, see below.

Malware is always changing to get around the defenses against it. This procedure works as of now, as far as I know. It may not work in the future. Anyone finding this comment a few days or more after it was posted should look for a more recent discussion, or start a new one.

The VSearch malware tries to hide itself by varying the names of the files it installs. To remove it, you must first identify the naming pattern.

Triple-click the line below on this page to select it, then copy the text to the Clipboard by pressing the key combination command-C:

/Library/LaunchDaemons

In the Finder, select

Go Go to Folder...

from the menu bar and paste into the box that opens by pressing command-V. You won't see what you pasted because a line break is included. Press return.

A folder named "LaunchDaemons" may open. Look inside it for two files with names of the form

com.something.daemon.plist

and

com.something.helper.plist

Here something is a variable string of characters, which can be different in each VSearch infection. So far it has always been an alphanumeric string without punctuation, such as "cloud," "dot," "highway," "submarine," or "trusteddownloads." Sometimes it's a meaningless string such as "e8dec5ae7fc75c28" rather than a word. Sometimes the string is "apple," and then you must be especially careful not to delete the wrong files, because many built-in OS X files have similar names.

If you find these files, leave the LaunchDaemons folder open, and open the following folder in the same way:

/Library/LaunchAgents

In this folder, there may be a file named

com.something.agent.plist

where the string something is the same as before.

If you feel confident that you've identified the above files, back up all data, then drag just those three files—nothing else—to the Trash. You may be prompted for your administrator login password. Close the Finder windows and restart the computer.

Don't delete the "LaunchAgents" or "LaunchDaemons" folder or anything else inside either one.

The malware is now permanently inactivated, as long as you never reinstall it. You can stop here if you like, or you can remove two remaining components for the sake of completeness.

Open this folder:

/Library/Application Support

If it has a subfolder named just

something

where something is the same string you saw before, drag that subfolder to the Trash and close the window.

Don't delete the "Application Support" folder or anything else inside it.

Finally, in this folder:

/System/Library/Frameworks

there may be an item named exactly

v.framework

It's actually a folder, though it has a different icon than usual. This item always has the above name; it doesn't vary. Drag it to the Trash and close the window.

Don't delete the "Frameworks" folder or anything else inside it.

If you didn't find the files or you're not sure about the identification, post what you found.

If in doubt, or if you have no backups, change nothing at all.

The trouble may have started when you downloaded and ran an application called "MPlayerX." That's the name of a legitimate free movie player, but the name is also used fraudulently to distribute VSearch. If there is an item with that name in the Applications folder, delete it. I don't recommend that you install the genuine "MPlayerX," because it's hosted on the rogue "SourceForge" website and is bundled with other malware.

This trojan is often found on illegal websites that traffic in pirated content such as movies. If you, or anyone else who uses the computer, visit such sites and follow prompts to install software, you can expect more of the same, and worse, to follow. Never install any software that you downloaded from a bittorrent, or that was downloaded by someone else from an unknown source.

In the Security & Privacy pane of System Preferences, select the General tab. The radio button marked Anywhere should not be selected. If it is, click the lock icon to unlock the settings, then select one of the other buttons. After that, don't ignore a warning that you are about to run or install an application from an unknown developer.

Then, still in System Preferences, open the App Store or Software Update pane and check the box marked

Install system data files and security updates (OS X 10.10 or later)

or

Download updates automatically (OS X 10.9 or earlier)

if it's not already checked.

B

"ZipCloud," sometimes named "JustCloud," is a cloud-storage service with a doubtful reputation. The OS X client is sometimes distributed along with malware. Although ZipCloud may not be malicious itself, it should be suspected by virtue of the company it keeps.

To remove ZipCloud, start by backing up all data (not with ZipCloud itself, of course.)

Quit the "ZipCloud" or "JustCloud" application, if it's running, and drag it from the Applications folder to the Trash. Don't try to empty yet.

Triple-click anywhere in the line below on this page to select it:

~/Library/LaunchAgents

Right-click or control-click the highlighted line and select

Services Open

from the contextual menu.* A folder named "LaunchAgents" should open.

In the folder, there may be one or more files with a name beginning as follows:

com.jdibackup.

Move all such files to the Trash.

Log out or restart the computer and empty the Trash.

*If you don't see the contextual menu item, copy the selected text to the Clipboard by pressing the key combination command-C. In the Finder, select

Go Go to Folder...

from the menu bar and paste into the box that opens by pressing command-V. You won't see what you pasted because a line break is included. Press return.

Aug 3, 2015 1:04 PM in response to AnakarenNunez

Your question brings up the subject of removing adware. This is a general comment on that subject.

The only tools that anyone needs to detect and remove adware are the Finder and a web browser, both of which you already have. Anyone who has enough computer skill to install adware can just as well remove it without using anything else.

Under no circumstances should you ever allow anti-virus software to delete something for you.

Apple doesn't endorse any third-party "anti-virus" or "anti-malware" product. Here and here are its general statements about malware protection, and here are its instructions for removing the most common types of ad-injection malware. None of those support pages mentions anti-malware products. An Apple employee who recommends such a product is speaking only for himself or herself, not for the company. See this thread for an example of what the results can be.

You become infected with malware by downloading unknown software without doing research to determine whether it's safe. If you keep making that mistake, the same, and worse, will keep happening, and no anti-malware will rescue you. Your own intelligence and caution are the only reliable defense.

The Windows/Android anti-malware industry had more than $75 billion in sales in 2014 [source: Gartner, Inc.] Its marketing strategy is to convince people that they're helpless against malware attack unless they use its products. But with all that anti-malware, the Windows and Android platforms are still infested with malware—most of it far more harmful than mere adware. The same can be expected to happen to the Mac platform if its users trust the same industry to protect them, instead of protecting themselves.

You are not helpless, and you don't have to give full control of your computer—and your data—to strangers in order to be rid of adware.

<Edited By Host>

Aug 3, 2015 1:00 PM in response to AnakarenNunez

AnakarenNunez wrote:


Lately lots of ads have been popping up whenever i try to log in somewhere or click enter. I've already checked and deleted the extensions and checked in my files if i have any malware but I don't. Mainly, mackeeper and ZipCloud ads pop up. I've been trying to resolve this problem but I can't find the origin. Any ideas on how to remove ads?

Use MalwareBytes I have never had a negative issue with any Mac I have used it on


Cheers


Pete

HOW TO REMOVE ADWARE????

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.