Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Unable to remove malware: popups, .pkg downloads, adware links

Hi everyone,

I've followed instructions for removing malware on several threads here without success, and then tried using the Malwarebytes Anti-Malware for Mac - which didn't work.


A summary of the issues:


1. I keep getting a new tab opening for Advanced Mac Cleaner -

the link is in parens:


(http://www.advancedmaccleaner.com/mr/4/?utm_source=mrtmacg&utm_campaign=mrtmacg& pxl=MRT253_MRT243_RUNT&utm_pubid=831638&x-context=for_9a25a440e496450ab1ff7d7b15 410a29)



2. Colored links are showing up on all the websites I visit. Sometimes the links show up in all caps, sometimes the links have a little green arrow in the upper right corner of the word.


Rolling over the link brings up a message: Continue to Continue > By Advertise
And and sometimes a popup ad by "Ad Set"


The links go to a url that begins with: http://s.iktmmny.com/


You don't have to click on them - seems that simply rolling over opens the window for Advanced Mac Cleaner.


3. Without clicking on any of those bad links - a .pkg file keeps downloading automatically,

filename is:


amc_rb_mrtmacg.pkg


I move the file to the trash without opening, and secure empty trash.


4. Exact same issues occurring on another Mac, Macbook Air running OSX Yosemite 10.10.4.


My iphone / ipad are not affected.


Thanks for your help!

MacBook (13-inch), OS X Yosemite (10.10.5)

Posted on Dec 30, 2015 5:35 PM

Reply
38 replies

Dec 30, 2015 8:12 PM in response to lisa sonora

Don't use any kind of "anti-virus" or "anti-malware" product on a Mac. There is never a need for it, and relying on it for protection makes you more vulnerable to attack, not less.

Some of the most common types of adware can be removed by following Apple's instructions.

If you're not already running the latest version of OS X ("El Capitan"), updating or upgrading in the App Store may cause the adware to be removed automatically. Back up all data before taking that step. If you're already running the latest version of El Capitan, you can nevertheless download the current updater from the Apple Support Downloads page and run it. Again, some kinds of malware will be removed. That may be all you need to do as far as removal is concerned, but you'll still need to make changes to the way you use the computer to protect yourself from further attacks.

If the above steps don't work for you, see below.

This easy procedure will detect any kind of adware that I know of. Deactivating it is a separate, and even easier, procedure.

Some legitimate software is ad-supported and may display ads in its own windows or in a web browser while it's running. That's not malware and it may not show up. Also, some websites carry intrusive popup ads that may be mistaken for adware.

If none of your web browsers is working well enough to carry out these instructions, restart the computer in safe mode. That will disable the malware temporarily.

Step 1

Please triple-click the line below on this page to select it, then copy the text to the Clipboard by pressing the key combination command-C:

~/Library/LaunchAgents

In the Finder, select

Go Go to Folder...

from the menu bar and paste into the box that opens by pressing command-V. Press return. Either a folder named "LaunchAgents" will open, or you'll get a notice that the folder can't be found. If the folder isn't found, go to the next step.

If the folder does open, press the key combination command-2 to select list view, if it's not already selected. Please don't skip this step.

There should be a column in the Finder window headed Date Modified. Click that heading twice to sort the contents by date with the newest at the top. If necessary, enlarge the window so that all of the contents are showing.

Follow the instructions in this support article under the heading "Take a screenshot of a window." An image file with a name beginning in "Screen Shot" should be saved to the Desktop. Open the screenshot and make sure it's readable. If not, capture a smaller part of the screen showing only what needs to be shown.

Start a reply to this message. Drag the image file into the editing window to upload it. You can also include text in the reply.

Leave the folder open for now.

Step 2

Do as in Step 1 with this line:

/Library/LaunchAgents

The folder that may open will have the same name, but is not the same, as the one in Step 1. As in that step, the folder may not exist.

Step 3

Repeat with this line:

/Library/LaunchDaemons

This time the folder will be named "LaunchDaemons."

Step 4

Open the Safari preferences window and select the Extensions tab. If any extensions are listed, post a screenshot. If there are no extensions, or if you can't launch Safari, skip this step.

Step 5

If you use the Firefox or Chrome browser, open its extension list and do as in Step 4.



<Edited by Host>

Dec 30, 2015 9:10 PM in response to Linc Davis

Link. You advise is good. But I have to tell you that I have experience with this AdvancedMac Cleaner. To be able to delete it you have to go to the activity monitor and kill it to begin to remove it. It stays running in the background. It was on my daughters Macbook and I was doing what you recommended and it would not let me delete it until I did that.

Dec 31, 2015 3:04 AM in response to lisa sonora

lisa sonora wrote:


I've followed instructions for removing malware on several threads here without success, and then tried using the Malwarebytes Anti-Malware for Mac - which didn't work.


If Malwarebytes Anti-Malware for Mac didn't detect any malware on your system, there are two likely explanations: 1) it's not due to adware, or 2) it's something new that Malwarebytes Anti-Malware for Mac isn't detecting.


With regard to #2, can you post a system snapshot taken with Malwarebytes Anti-Malware for Mac? To do so, open Malwarebytes Anti-Malware for Mac and choose Take System Snapshot from the Scanner menu. Then, in the window that opens, select all the text (Edit Select All), copy it and paste into a reply to this message.


Alternately, if you'd rather not post that in a public forum, you could choose Contact Support from the Help menu in Malwarebytes Anti-Malware for Mac to contact our support techs directly.


This will help us determine whether it's likely that you have some kind of new adware, or whether we need to be looking elsewhere for the cause of the problem.


Thomas Reed

Director of Mac Offerings, Malwarebytes

Dec 31, 2015 5:36 AM in response to thomas_r.

Malwarebytes Anti-Malware for Mac did detect one file on the MacBook Pro - removed. After restart, still having same issues, above.

It detected several files on the MacBook Air - removed. Same thing - after restart same issues occurring.

I did send a support email to Malwarebyes - figuring if you guys could help it might detect something that will help others. Thanks!

Dec 31, 2015 12:01 PM in response to my ginger

It really isn't that sneaky, unless you're trying to remove it manually. We see many apps with similar behaviors.


As for why it wasn't removed, I'm trying to determine why that might be. There are many potential issues with the system that could cause that kind of thing, or it could be a new variant of AMC.


Thomas Reed

Director of Mac Offerings, Malwarebytes

Unable to remove malware: popups, .pkg downloads, adware links

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.