aliendays

Q: possible unidentified trojan

I think my computer is infected with some kind of trojan. I bought this MacBook Air in October and it was working perfectly until today. I was trying to read a website and the page couldn't finish loading and it kept opening other very suspect tabs. When I visited perfectly regular website firefox kept redirecting them to pages like this:

 

Captura de Tela 2015-12-05 as 18.55.43.png

And there's always a pop-up asking me to download MacKeeper (I didn't download it!). The same thing happens when I use Safari.

 

I checked the add-ons and I don't know what might me causing it (even though I don't know what these add-ons are besides Flash and Java). I read that Java can cause trojans and I installed it recently. But it was earlier this week and I didn't notice anything different.

 

Captura de Tela 2015-12-05 as 18.54.22.png

Then I unstalled firefox and installed it again but nothing changed. I google and I found that trojans and malwares can be in the Library and then I found just this:

Captura de Tela 2015-12-05 as 20.47.07.png

What should I delete without damaging my brand new computer? Can one of them be the trojan that I'm looking for? Besides that I also found a local.cfg in Macintosh HD, is it suspect?

 

I updated to El Capitan earlier this week and it was all going well. A day earlier I installed Adobe Illustrator and it required me to install Java, I don't care about Java at all. But as I said previously this computer started showing this weird behaviour today. Yesterday I tried to download a pdf from a website with lots of pop-ups, that might be the cause. But what can I do? I searched for lots of common trojans and didn't find anything.

 

I friend suggested that I should download Malwarebytes and run some tests. But is it safe?

MacBook Air, El Capitan

Posted on Dec 5, 2015 3:53 PM

Close

Q: possible unidentified trojan

  • All replies
  • Helpful answers

Previous Page 2
  • by aliendays,

    aliendays aliendays Dec 6, 2015 6:35 PM in response to MrHoffman
    Level 1 (0 points)
    Dec 6, 2015 6:35 PM in response to MrHoffman

    Thank you. I think I'm going to Genius Bar or an authrorized Apple repair technician and ask them to help me to start over but before that I'm really worried about the data collection thing. So far there's nothing wrong with my bank account.

     

    Warsaw is my banking software, so it's safe.


    How can I get rid of "com.pref.net-preferences", "com.Supporter.helper" or "com.begar.net-preferences"? I can find "etc/change_net_settings.sh" through Go to File, so should I just delete it?

  • by Linc Davis,

    Linc Davis Linc Davis Dec 6, 2015 6:52 PM in response to aliendays
    Level 10 (208,037 points)
    Applications
    Dec 6, 2015 6:52 PM in response to aliendays

    If you've done what I suggested and there's no functional problem now, you don't need to do anything else. A few malware files may remain but they have no effect.

Previous Page 2