Cinghi

Q: how to remove tradeadexchange malware from chrom and safari

Hello

how to remove tradeadexchange malware from chrom and safari

thanks

Cinghi

Posted on Oct 25, 2015 2:46 AM

Close

Q: how to remove tradeadexchange malware from chrom and safari

  • All replies
  • Helpful answers

  • by lllaass,Apple recommended

    lllaass lllaass Oct 25, 2015 3:37 AM in response to Cinghi
    Level 10 (190,832 points)
    Apple Watch
    Oct 25, 2015 3:37 AM in response to Cinghi
  • by dominic23,

    dominic23 dominic23 Oct 25, 2015 3:37 AM in response to Cinghi
    Level 8 (42,122 points)
    Mac OS X
    Oct 25, 2015 3:37 AM in response to Cinghi

    Safari 8/9

     

    Safari > Preferences > Extensions

     

    Turn all extensions off or disable all extensions and test.

    Click the "Uninstall" button to uninstall any extension.

     

    Chrome

    Find out how to uninstall extensions.

  • by Linc Davis,Helpful

    Linc Davis Linc Davis Oct 27, 2015 11:14 AM in response to Cinghi
    Level 10 (208,037 points)
    Applications
    Oct 27, 2015 11:14 AM in response to Cinghi

    You may have installed ad-injection malware ("adware").

    Don't use any kind of "anti-virus" or "anti-malware" product on a Mac. There is never a need for it, and relying on it for protection makes you more vulnerable to attack, not less.

    Some of the most common types of adware can be removed by following Apple's instructions. If those instructions don't work for you, or if you have trouble following them, see below.

    This easy procedure will detect any kind of adware that I know of. Deactivating it is a separate, and even easier, procedure that doesn't involve downloading anything.

    Some legitimate software is ad-supported and may display ads in its own windows or in a web browser while it's running. That's not malware and it may not show up. Also, some websites carry intrusive popup ads that may be mistaken for adware.

    If none of your web browsers is working well enough to carry out these instructions, restart the computer in safe mode. That will disable the malware temporarily.

    Step 1

    Please triple-click the line below on this page to select it, then copy the text to the Clipboard by pressing the key combination command-C:

    ~/Library/LaunchAgents

    In the Finder, select

              Go Go to Folder...

    from the menu bar and paste into the box that opens by pressing command-V. Press return. Either a folder named "LaunchAgents" will open, or you'll get a notice that the folder can't be found. If the folder isn't found, go to the next step.

    If the folder does open, press the key combination command-2 to select list view, if it's not already selected. Please don't skip this step.

    There should be a column in the Finder window headed Date Modified. Click that heading twice to sort the contents by date with the newest at the top. If necessary, enlarge the window so that all of the contents are showing.

    Follow the instructions in this support article under the heading "Take a screenshot of a window." An image file with a name beginning in "Screen Shot" should be saved to the Desktop. Open the screenshot and make sure it's readable. If not, capture a smaller part of the screen showing only what needs to be shown.

    Start a reply to this message. Drag the image file into the editing window to upload it. You can also include text in the reply.

    Leave the folder open for now.

    Step 2

    Do as in Step 1 with this line:

    /Library/LaunchAgents

    The folder that may open will have the same name, but is not the same, as the one in Step 1. As in that step, the folder may not exist.

    Step 3

    Repeat with this line:

    /Library/LaunchDaemons

    This time the folder will be named "LaunchDaemons."

    Step 4

    Open the Safari preferences window and select the Extensions tab. If any extensions are listed, post a screenshot. If there are no extensions, or if you can't launch Safari, skip this step.

    Step 5

    If you use the Firefox or Chrome browser, open its extension list and do as in Step 4.

  • by Cinghi,

    Cinghi Cinghi Oct 27, 2015 11:39 AM in response to Linc Davis
    Level 1 (0 points)
    Oct 27, 2015 11:39 AM in response to Linc Davis

    Zrzut ekranu 2015-10-27 o 19.34.55.png

  • by Cinghi,

    Cinghi Cinghi Oct 27, 2015 11:40 AM in response to Linc Davis
    Level 1 (0 points)
    Oct 27, 2015 11:40 AM in response to Linc Davis

    Zrzut ekranu 2015-10-27 o 19.40.11.png

  • by Cinghi,

    Cinghi Cinghi Oct 27, 2015 11:42 AM in response to Linc Davis
    Level 1 (0 points)
    Oct 27, 2015 11:42 AM in response to Linc Davis

    Zrzut ekranu 2015-10-27 o 19.41.14.png

  • by Cinghi,

    Cinghi Cinghi Oct 27, 2015 11:46 AM in response to Linc Davis
    Level 1 (0 points)
    Oct 27, 2015 11:46 AM in response to Linc Davis

    Zrzut ekranu 2015-10-27 o 19.45.43.pngZrzut ekranu 2015-10-27 o 19.45.53.png

  • by Cinghi,

    Cinghi Cinghi Oct 27, 2015 11:51 AM in response to Linc Davis
    Level 1 (0 points)
    Oct 27, 2015 11:51 AM in response to Linc Davis

    hi

    i checked your instruction but I can not find the aplication you described, than I have some tools in polish lg so I woulb be appreciate to make me maybe prtscr what I have to do .

    Safari I do not have any extention on the list , Chrom I sent you prts scr which extention I already have , I dont know how to make disable extantion in chrom in safari I did .

    many thanks for our help and undertanding that I do not this software at all couse in the past i had everytime microsoft ,thanks for understanding and help

    best regards

    Cinghi

  • by Linc Davis,

    Linc Davis Linc Davis Oct 28, 2015 6:58 PM in response to Cinghi
    Level 10 (208,037 points)
    Applications
    Oct 28, 2015 6:58 PM in response to Cinghi

    Let's go back to the original question. What exactly is happening that makes you think you have a malware infection? Do you see ads on all websites, or only some? What about this site?

  • by Cinghi,

    Cinghi Cinghi Oct 29, 2015 10:17 AM in response to Linc Davis
    Level 1 (0 points)
    Oct 29, 2015 10:17 AM in response to Linc Davis

    thanks for reply , so when I have opened chrome and make clik on the picutre or just make clik withm mouse on the web side does not matter which place this clik makes open tradexchange webside and every time I have to close it and clik again . Afer puting 2 extention which are blocking the adverteisment of tradedechange ,this web side is open but is white , so to check smth I have constantly loos time to close tradexchange .

    thnanks a lot

    regards

    Cinghi

  • by Linc Davis,

    Linc Davis Linc Davis Oct 29, 2015 11:19 AM in response to Cinghi
    Level 10 (208,037 points)
    Applications
    Oct 29, 2015 11:19 AM in response to Cinghi

    1. This procedure is a diagnostic test. It changes nothing, for better or worse, and therefore will not, in itself, solve the problem. But with the aid of the test results, the solution may take a few minutes, instead of hours or days.

    The test works on OS X 10.7 ("Lion") and later. I don't recommend running it on older versions of OS X. It will do no harm, but it won't do much good either.

    Don't be put off by the complexity of these instructions. The process is much less complicated than the description. You do harder tasks with the computer all the time.

    2. If you don't already have a current backup, back up all data before doing anything else. The backup is necessary on general principle, not because of anything in the test procedure. Backup is always a must, and when you're having any kind of trouble with the computer, you may be at higher than usual risk of losing data, whether you follow these instructions or not.

    There are ways to back up a computer that isn't fully functional. Ask if you need guidance.

    3. Below are instructions to run a UNIX shell script, a type of program. As I wrote above, it changes nothing. It doesn't send or receive any data on the network. All it does is to generate a human-readable report on the state of the computer. That report goes nowhere unless you choose to share it. If you prefer, you can act on it yourself without disclosing the contents to me or anyone else.

    You should be wondering whether you can believe me, and whether it's safe to run a program at the behest of a stranger. In general, no, it's not safe and I don't encourage it.

    In this case, however, there are ways for you to decide whether the program is safe without having to trust me. First, you can read it. Unlike an application that you download and click to run, it's transparent, so anyone with the requisite skill can verify what it does.

    You may not be able to understand the script yourself. But variations of it have been posted on this website thousands of times over a period of years. The site is hosted by Apple, which does not allow it to be used to distribute harmful software. Any one of the millions of registered users could have read the script and raised the alarm if it was harmful. Then I would not be here now and you would not be reading this message. See, for example, this discussion.

    Another indication that the test is safe can be found in this thread, and this one, for example, where the comment in which I suggested it was recommended by one of the Apple Community Specialists, as explained here.

    Nevertheless, if you can't satisfy yourself that these instructions are safe, don't follow them. Ask for other options.

    4. Here's a general summary of what you need to do, if you choose to proceed:

    ☞ Copy a particular line of text to the Clipboard.

    ☞ Paste into the window of another application.

    ☞ Wait for the test to run. It usually takes a few minutes.

    ☞ Paste the results, which will have been copied automatically, back into a reply on this page.

    These are not specific instructions; just an overview. The details are in parts 7 and 8 of this comment. The sequence is: copy, paste, wait, paste again. You don't need to copy a second time.

    5. Try to test under conditions that reproduce the problem, as far as possible. For example, if the computer is intermittently slow, run the test during a slowdown.

    You may have started up in safe mode. If the system is now in safe mode and works well enough in normal mode to run the test, restart as usual before running it. If you can only test in safe mode, do that.

    6. If you have more than one user, and only one user is affected by the problem,, and the affected user is not an administrator, then please run the test twice: once while logged in as the affected user, and once as an administrator. The results may be different. The user that is created automatically on a new computer when you start it for the first time is an administrator. If you can't log in as an administrator, test as the affected user. Most personal Macs have only one user, and in that case this section doesn’t apply. Don't log in as root.

    7. Load this linked web page (on the website "Pastebin.") The title of the page is "Diagnostic Test." Below the title is a text box headed by three small icons. The one on the right represents a clipboard. Click that icon to select the text, then copy it to the Clipboard on your computer by pressing the key combination command-C.

    If the text doesn't highlight when you click the icon, select it by triple-clicking anywhere inside the box. Don't select the whole page, just the text in the box.

    8. Launch the built-in Terminal application in any of the following ways:

    ☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)

    ☞ In the Finder, select Go ▹ Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.

    ☞ Open LaunchPad and start typing the name.

    Click anywhere in the Terminal window to activate it. Paste from the Clipboard into the window by pressing command-V, then press return. The text you pasted should vanish immediately.

    9. If you see an error message in the Terminal window such as "Syntax error" or "Event not found," enter

    exec bash

    and press return. Then paste the script again.

    10. If you're logged in as an administrator, you'll be prompted for your login password. Nothing will be displayed when you type it. You will not see the usual dots in place of typed characters. Make sure caps lock is off. Type carefully and then press return. You may get a one-time warning to be careful. If you make three failed attempts to enter the password, the test will run anyway, but it will produce less information. If you don't know the password, or if you prefer not to enter it, just press return three times at the password prompt. Again, the script will still run.

    If the test is taking much longer than usual to run because the computer is very slow, you might be prompted for your password a second time. The authorization that you grant by entering it expires automatically after five minutes.

    If you're not logged in as an administrator, you won't be prompted for a password. The test will still run. It just won't do anything that requires administrator privileges.

    11. The test may take a few minutes to run, depending on how many files you have and the speed of the computer. A computer that's abnormally slow may take longer to run the test. While it's running, a series of lines will appear in the Terminal window like this:

    [Process started]
            Part 1 of 4 done at … sec
            …
            Part 4 of 4 done at … sec
            The test results are on the Clipboard.
            Please close this window.
    [Process completed]

    The intervals between parts won't be exactly equal, but they give a rough indication of progress.

    Wait for the final message "Process completed" to appear. If you don't see it within about 15 minutes, the test probably won't complete in a reasonable time. In that case, press the key combination control-C or command-period to stop it. Then go to the next step. You'll have incomplete results, but still something. If you close the Terminal window while the test is still running, the partial results won't be saved and you'll have to start over.

    12. When the test is complete, or if you stopped it because it was taking too long, quit Terminal. The results will have been saved to the Clipboard automatically. They are not shown in the Terminal window. Please don't copy anything from there. All you have to do is start a reply to this comment and then paste by pressing command-V again.

    At the top of the results, there will be a line that begins with the words "Start time." If you don't see that, but instead see a mass of gibberish, you didn't wait for the "Process completed" message to appear in the Terminal window. Please wait for it and try again.

    If any private information, such as your name or email address, appears in the results, anonymize it before posting. Usually that won't be necessary.

    13. When you post the results, you might see an error message on the web page: "You have included content in your post that is not permitted," or "The message contains invalid characters." That's a bug in the software that runs this website. Please post the test results on Pastebin, then post a link here to the page you created.

    14. This is a public forum, and others may give you advice based on the results of the test. They speak for themselves, not for me. The test itself is harmless, but whatever else you're told to do may not be. For others who choose to run it, I don't recommend that you post the test results on this website unless I asked you to.

    ______________________________________________________________

    Copyright © 2014, 2015 by Linc Davis. As the sole author of this work (including the referenced "Diagnostic Test"), I reserve all rights to it except as provided in the Use Agreement for the Apple Support Communities website ("ASC"). Readers of ASC may copy it for their own personal use. Neither the whole nor any part may be redistributed.

  • by sudpur,

    sudpur sudpur Mar 31, 2016 11:46 PM in response to Cinghi
    Level 1 (4 points)
    Mar 31, 2016 11:46 PM in response to Cinghi

    Recently got infected with this tradeadexchange.com advt virus. All my devices (iPad, 2 android phones) using the wifi connection were getting auto routed to random advt urL. So this can't be device specific problem, must be something common like router or modem. Tried clearing cache, history, etc. will work temporarily only, won't resolve.

     

    Read that it's got to do with router/modem. Opened the respective devices setup url like 192.168.1.1. Look at the Dns servers specified in the settings (under advanced). on my modem device, both primary and secondary dns server were specified as something like 33.*.*.* which lookup showed as UK servers. Change to auto select and make sure in the status page same is updated. For wifi router do the same changes, some will allow to manulily specify if yes you may use google public dns server like 8.8.8.8 and 8.8.4.4. Exact steps may differ by device. Reboot the devices to update. Also clean up the browser cache, reset browser settings to mare sure no trace are left.

     

    also recommend to change the default admin password so that settings can't be changed easily. Not sure how devices got infected but it's possible someone can use default admin username and password.

    hope it works, it's working so far for me, no more irritating re-routing.

     

    ps: tried using anti malware bytes, it won't detect it since device directly is not infected.