Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

macbook pro gives messages regarding trojan horse virus

My mac book pro ws running slow. It now gives messages informing me that the machine has a trojan horse virus and that I should disable disruptive ads.

There was an 877 number listed to call. I did. It was a company that claim to be able to fix the problem for a fee.

How can I get 1) detect which virus might be infecting my macbook pro and 2) get rid of it and 3) block it from ever happening again?

I was thinking to bring it to an apple store for help; but there must be some software fix out there...

OS X Yosemite (10.10.5), Virus detection & removal

Posted on Sep 1, 2015 5:05 PM

Reply
Question marked as Best reply

Posted on Sep 2, 2015 7:27 PM

These are phishing scams. Do not click on any of the links nor call any telephone numbers. For more help:


Remove Browser Pop-up Problems


Malwarebytes Anti-Malware 1.0.1.7

Adblock Plus 1.8.9, GlimmerBlocker, or AdBlock

Remove adware that displays pop-up ads and graphics on your Mac

How to remove the FlashMall adware from OS X

Helpful Links Regarding Malware Problems


If you are having an immediate problem with ads popping up see The Safe Mac » Adware Removal Guide, remove adware that displays pop-up ads and graphics on your Mac, and MalwareBytes for Mac. If you require anti-virus protection Thomas Reed recommends using ClamXAV. (Thank you to Thomas Reed for this recommendation.) You might consider adding this Safari extensions: Adblock Plus 1.8.9.


Open Safari, select Preferences from the Safari menu. Click on Extensions icon in the toolbar. Disable all Extensions. If this stops your problem, then re-enable them one by one until the problem returns. Now remove that extension as it is causing the problem.


The following comes from user stevejobsfan0123. I have made minor changes to adapt to this presentation.


Fix Some Browser Pop-ups That Take Over Safari.


Common pop-ups include a message saying the government has seized your computer and you must pay to have it released (often called "Moneypak"), or a phony message saying that your computer has been infected, and you need to call a tech support number (sometimes claiming to be Apple) to get it resolved. First, understand that these pop-ups are not caused by a virus and your computer has not been affected. This "hijack" is limited to your web browser. Also understand that these messages are scams, so do not pay any money, call the listed number, or provide any personal information. This article will outline the solution to dismiss the pop-up.


Quit Safari


Usually, these pop-ups will not go away by either clicking "OK" or "Cancel." Furthermore, several menus in the menu bar may become disabled and show in gray, including the option to quit Safari. You will likely have to force quit Safari. To do this, press Command + option + esc, select Safari, and press Force Quit.


Relaunch Safari


If you relaunch Safari, the page will reopen. To prevent this from happening, hold down the 'Shift' key while opening Safari. This will prevent windows from the last time Safari was running from reopening.


This will not work in all cases. The shift key must be held at the right time, and in some cases, even if done correctly, the window reappears. In these circumstances, after force quitting Safari, turn off Wi-Fi or disconnect Ethernet, depending on how you connect to the Internet. Then relaunch Safari normally. It will try to reload the malicious webpage, but without a connection, it won't be able to. Navigate away from that page by entering a different URL, i.e. www.apple.com, and trying to load it. Now you can reconnect to the Internet, and the page you entered will appear rather than the malicious one.

6 replies
Question marked as Best reply

Sep 2, 2015 7:27 PM in response to nativeincorporated

These are phishing scams. Do not click on any of the links nor call any telephone numbers. For more help:


Remove Browser Pop-up Problems


Malwarebytes Anti-Malware 1.0.1.7

Adblock Plus 1.8.9, GlimmerBlocker, or AdBlock

Remove adware that displays pop-up ads and graphics on your Mac

How to remove the FlashMall adware from OS X

Helpful Links Regarding Malware Problems


If you are having an immediate problem with ads popping up see The Safe Mac » Adware Removal Guide, remove adware that displays pop-up ads and graphics on your Mac, and MalwareBytes for Mac. If you require anti-virus protection Thomas Reed recommends using ClamXAV. (Thank you to Thomas Reed for this recommendation.) You might consider adding this Safari extensions: Adblock Plus 1.8.9.


Open Safari, select Preferences from the Safari menu. Click on Extensions icon in the toolbar. Disable all Extensions. If this stops your problem, then re-enable them one by one until the problem returns. Now remove that extension as it is causing the problem.


The following comes from user stevejobsfan0123. I have made minor changes to adapt to this presentation.


Fix Some Browser Pop-ups That Take Over Safari.


Common pop-ups include a message saying the government has seized your computer and you must pay to have it released (often called "Moneypak"), or a phony message saying that your computer has been infected, and you need to call a tech support number (sometimes claiming to be Apple) to get it resolved. First, understand that these pop-ups are not caused by a virus and your computer has not been affected. This "hijack" is limited to your web browser. Also understand that these messages are scams, so do not pay any money, call the listed number, or provide any personal information. This article will outline the solution to dismiss the pop-up.


Quit Safari


Usually, these pop-ups will not go away by either clicking "OK" or "Cancel." Furthermore, several menus in the menu bar may become disabled and show in gray, including the option to quit Safari. You will likely have to force quit Safari. To do this, press Command + option + esc, select Safari, and press Force Quit.


Relaunch Safari


If you relaunch Safari, the page will reopen. To prevent this from happening, hold down the 'Shift' key while opening Safari. This will prevent windows from the last time Safari was running from reopening.


This will not work in all cases. The shift key must be held at the right time, and in some cases, even if done correctly, the window reappears. In these circumstances, after force quitting Safari, turn off Wi-Fi or disconnect Ethernet, depending on how you connect to the Internet. Then relaunch Safari normally. It will try to reload the malicious webpage, but without a connection, it won't be able to. Navigate away from that page by entering a different URL, i.e. www.apple.com, and trying to load it. Now you can reconnect to the Internet, and the page you entered will appear rather than the malicious one.

Sep 1, 2015 5:10 PM in response to nativeincorporated

That is not a legitimate notification, it is a scam. Do Not call the number again, and do not give those scammers access to your Mac...there is not a virus on your Mac.


Open Safari, click Safari on the menu bar, Preferences, Privacy and Remove All Website Data, that will remove any cookies that were planted in your cache for Safari.

Sep 1, 2015 7:07 PM in response to nativeincorporated

nativeincorporated wrote:


How can I get 1) detect which virus might be infecting my macbook pro and 2) get rid of it and 3) block it from ever happening again?

There is no virus. This is a total scam to get you to pay for something you absolutely do not need. There is no way for them to detect such a thing from the internet, so don't bother wasting any more time on it.

Sep 1, 2015 7:19 PM in response to nativeincorporated

First, there is no virus. That was a scam.

When you see a beachball cursor or the slowness is especially bad, note the exact time: hour, minute, second.

These instructions must be carried out as an administrator. If you have only one user account, you are the administrator.

Launch the Console application in any of the following ways:

☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)

☞ In the Finder, select Go Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.

☞ Open LaunchPad and start typing the name.

The title of the Console window should be All Messages. If it isn't, select

SYSTEM LOG QUERIES All Messages

from the log list on the left. If you don't see that list, select

View Show Log List

from the menu bar at the top of the screen.

Each message in the log begins with the date and time when it was entered. Scroll back to the time you noted above.

Select the messages entered from then until the end of the episode, or until they start to repeat, whichever comes first.

Copy the messages to the Clipboard by pressing the key combination command-C. Paste into a reply to this message by pressing command-V.

The log contains a vast amount of information, almost all of it useless for solving any particular problem. When posting a log extract, be selective. A few dozen lines are almost always more than enough.

Please don't indiscriminately dump thousands of lines from the log into this discussion.

Please don't post screenshots of log messages—post the text.

Some private information, such as your name, may appear in the log. Anonymize before posting.

When you post the log extract, you might see an error message on the web page: "You have included content in your post that is not permitted," or "The message contains invalid characters." That's a bug in the forum software. Please post the text on Pastebin, then post a link here to the page you created.

Sep 2, 2015 7:40 PM in response to nativeincorporated

Thanks to all,

I had apple care protection and called Apple. I spent about an hour speaking with a terrific technician. She (Donyke) walked me through removing troublesome ad-ware blocks. Now my machine works well again. Malwarebytes - Anti Malware really helped.

Your comments were detailed, clarifying and informative! I will walk through all of the comments made regarding the issue here, and hope learn more about the mac underworld.

macbook pro gives messages regarding trojan horse virus

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.