keshikun

Q: How do I remove the TopDeal / Deal Top virus?

Basically ads keep popping up everywhere on other websites. It's also changed my home page and search engine. I've deleted the files I downloaded but every time I try to reset my safari browser back to google (as the main page and search engine), as soon as I reopen my tabs / windows it goes back to bing.

 

I checked my extensions but there's nothing out of the ordinary there.

 

All help would be appreciated, thank you!

Posted on Jan 4, 2016 2:21 AM

Close

Q: How do I remove the TopDeal / Deal Top virus?

  • All replies
  • Helpful answers

Previous Page 2 of 5 last Next
  • by Linc Davis,

    Linc Davis Linc Davis Mar 24, 2016 6:04 AM in response to claudiadic
    Level 10 (208,037 points)
    Applications
    Mar 24, 2016 6:04 AM in response to claudiadic
    What files should I delete?

    #4 and #5.

     

    Anyone else finding this thread, please try the instructions I posted earlier. If they don't work, start a new discussion.

  • by zunnurain,

    zunnurain zunnurain Apr 5, 2016 4:31 AM in response to Linc Davis
    Level 1 (4 points)
    Apr 5, 2016 4:31 AM in response to Linc Davis

    Hi, can you help me to identify which files to delete? Thanks in advance!

     

    Screen Shot 2016-04-05 at 1.29.55 PM.png

  • by j_tailhan,

    j_tailhan j_tailhan Apr 5, 2016 10:18 PM in response to Linc Davis
    Level 1 (8 points)
    Apr 5, 2016 10:18 PM in response to Linc Davis

    Hi!

    Thanks! I just have 1 question to clarify...

    Do I have to delete all the files in the "LaunchDemon" folder with the names you mention AND the one with .agent.plist in the "LaunchAgents" but only if the 'something' is a word that was in the "LaunchDemon"?

    Sorry if it's a stupid question but just want to make sure I delete the right thing.

    Thanks!

  • by Han Hoang,

    Han Hoang Han Hoang Apr 18, 2016 7:07 PM in response to Linc Davis
    Level 1 (4 points)
    Apr 18, 2016 7:07 PM in response to Linc Davis

    Hi Linc,

     

    I have the same problem but can't see the files that I should delete. Could you please help?

    Screen Shot 2016-04-19 at 14.01.59.pngScreen Shot 2016-04-19 at 14.02.16.pngScreen Shot 2016-04-19 at 14.02.27.png

  • by arnaud78,

    arnaud78 arnaud78 Apr 19, 2016 10:08 AM in response to keshikun
    Level 1 (4 points)
    Apr 19, 2016 10:08 AM in response to keshikun

    launchagent.png

    launchdaemons.png

    I really don't know which one I must delete to remove TopDeal of my Mac, could you help me please ?

  • by psantos13,

    psantos13 psantos13 Apr 23, 2016 5:19 AM in response to Han Hoang
    Level 1 (4 points)
    Apr 23, 2016 5:19 AM in response to Han Hoang

    Hi. We have solved the problem?

     

    I also have the same problem

  • by Thomas1 2Skip a few,

    Thomas1 2Skip a few Thomas1 2Skip a few May 1, 2016 6:37 AM in response to Linc Davis
    Level 1 (4 points)
    May 1, 2016 6:37 AM in response to Linc Davis

    Screen Shot 2016-05-01 at 14.34.52.png

    Im also having the same issues which ones shall i delete?

  • by psantos13,

    psantos13 psantos13 May 1, 2016 10:17 AM in response to Thomas1 2Skip a few
    Level 1 (4 points)
    May 1, 2016 10:17 AM in response to Thomas1 2Skip a few

    Can anyone help me please?

    virus.jpg

  • by sudont,

    sudont sudont May 1, 2016 12:57 PM in response to arnaud78
    Level 1 (147 points)
    Mac OS X
    May 1, 2016 12:57 PM in response to arnaud78

    If nothing else, it should be clear to everyone who's read this discussion that files containing the string "Upd" belong to Vsearch. A closer reading of Linc's original post should help you sort through the rest. What I find interesting is how many people asking for help also seem to have MalwareBytes installed.

  • by Mike Sombrio,

    Mike Sombrio Mike Sombrio May 1, 2016 3:01 PM in response to sudont
    Level 6 (17,283 points)
    Apple Watch
    May 1, 2016 3:01 PM in response to sudont

    Nothing is clear to anyone replying to this thread asking for help. Davis posted at the top of this page that people should follow his earlier directions and/or start a new thread, but the "me too" posts just keep coming.

  • by Phewbeers,

    Phewbeers Phewbeers May 8, 2016 11:50 PM in response to Linc Davis
    Level 1 (4 points)
    May 8, 2016 11:50 PM in response to Linc Davis

    Thanks Linc Davis.

     

    This helped me get rid of Deal Top malware. The name of it was psychoclinicovercharge.

     

    Hopefully it is all back to normal..

     

    Cheers

  • by stumble-r,

    stumble-r stumble-r Jun 1, 2016 6:46 AM in response to Linc Davis
    Level 1 (4 points)
    Jun 1, 2016 6:46 AM in response to Linc Davis

    Hello, I tried to delete the suspicious files and restarted my mac, but I still receive the text link ads. Could someone kindly take a look? I did have Malwarebytes installed, but I did uninstall it.

     

    Screen Shot 2016-06-01 at 9.38.56 AM.png

  • by Linc Davis,

    Linc Davis Linc Davis Jun 1, 2016 7:10 AM in response to stumble-r
    Level 10 (208,037 points)
    Applications
    Jun 1, 2016 7:10 AM in response to stumble-r

    You installed one or more variants of the "VSearch" trojan. Please inactivate them as follows. This procedure will leave a few small files behind, but they have no effect, and trying to remove them all would be a lot more trouble than it's worth.

    This malware has many variants. Anyone else finding this comment should not expect it to be applicable.

    Back up all data before proceeding.

    The VSearch variant that you have regenerates itself if you try to delete it while it's running. To remove it, you must first start up in safe mode to disable the malware temporarily.

    Note: If FileVault is enabled in OS X 10.9 or earlier, or if a firmware password is set, or if the startup volume is a software RAID, you can’t do this. Ask for other instructions.

    While running in safe mode, move to the Trash items #7 through #12 and #14 through #16, as shown in the screenshot of the LaunchDaemons folder—in other words, everything except the Adobe and Oracle files. You may be prompted for your administrator login password.

    Restart the computer and empty the Trash.

    Reset the home page in each of your web browsers, if it was changed. In Safari, first load the home page you want, then select

              Safari Preferences... General

    and click

              Set to Current Page

    If you use the Firefox and/or Chrome web browser, remove any extensions or add-ons that you don't know you need. If in doubt, remove all of them.

    The malware is now permanently inactivated, as long as you never reinstall it. A few small files will be left behind, but they have no effect, and trying to find them all is more trouble than it's worth.

  • by stumble-r,

    stumble-r stumble-r Jun 1, 2016 7:48 AM in response to Linc Davis
    Level 1 (4 points)
    Jun 1, 2016 7:48 AM in response to Linc Davis

    Okay, I followed the steps and thought I was in the clear: but I still have the DealTop word popups on some webpages. Not as many as before, but still a few. The version my mac is running is 10.11.5 El Capitan. And all of my browsers' homepages are set to google & there are no plugins or extensions activated.

    
 

    The folder looks like this now:


    
 

    Screen Shot 2016-06-01 at 10.45.01 AM.png

  • by Linc Davis,

    Linc Davis Linc Davis Jun 1, 2016 8:11 AM in response to stumble-r
    Level 10 (208,037 points)
    Applications
    Jun 1, 2016 8:11 AM in response to stumble-r

    You need to delete the last item in that screenshot, then restart. If it comes back, boot in safe mode again and delete it.

Previous Page 2 of 5 last Next