-
All replies
-
Helpful answers
-
Mar 24, 2016 6:04 AM in response to claudiadicby Linc Davis,What files should I delete?
#4 and #5.
Anyone else finding this thread, please try the instructions I posted earlier. If they don't work, start a new discussion.
-
-
Apr 5, 2016 10:18 PM in response to Linc Davisby j_tailhan,Hi!
Thanks! I just have 1 question to clarify...
Do I have to delete all the files in the "LaunchDemon" folder with the names you mention AND the one with .agent.plist in the "LaunchAgents" but only if the 'something' is a word that was in the "LaunchDemon"?
Sorry if it's a stupid question but just want to make sure I delete the right thing.
Thanks!
-
-
-
Apr 23, 2016 5:19 AM in response to Han Hoangby psantos13,Hi. We have solved the problem?
I also have the same problem
-
-
-
May 1, 2016 12:57 PM in response to arnaud78by sudont,If nothing else, it should be clear to everyone who's read this discussion that files containing the string "Upd" belong to Vsearch. A closer reading of Linc's original post should help you sort through the rest. What I find interesting is how many people asking for help also seem to have MalwareBytes installed.
-
May 1, 2016 3:01 PM in response to sudontby Mike Sombrio,Nothing is clear to anyone replying to this thread asking for help. Davis posted at the top of this page that people should follow his earlier directions and/or start a new thread, but the "me too" posts just keep coming.
-
May 8, 2016 11:50 PM in response to Linc Davisby Phewbeers,Thanks Linc Davis.
This helped me get rid of Deal Top malware. The name of it was psychoclinicovercharge.
Hopefully it is all back to normal..
Cheers
-
-
Jun 1, 2016 7:10 AM in response to stumble-rby Linc Davis,You installed one or more variants of the "VSearch" trojan. Please inactivate them as follows. This procedure will leave a few small files behind, but they have no effect, and trying to remove them all would be a lot more trouble than it's worth.
This malware has many variants. Anyone else finding this comment should not expect it to be applicable.
Back up all data before proceeding.
The VSearch variant that you have regenerates itself if you try to delete it while it's running. To remove it, you must first start up in safe mode to disable the malware temporarily.
Note: If FileVault is enabled in OS X 10.9 or earlier, or if a firmware password is set, or if the startup volume is a software RAID, you can’t do this. Ask for other instructions.
While running in safe mode, move to the Trash items #7 through #12 and #14 through #16, as shown in the screenshot of the LaunchDaemons folder—in other words, everything except the Adobe and Oracle files. You may be prompted for your administrator login password.
Restart the computer and empty the Trash.
Reset the home page in each of your web browsers, if it was changed. In Safari, first load the home page you want, then select
Safari ▹ Preferences... ▹ General
and click
Set to Current Page
If you use the Firefox and/or Chrome web browser, remove any extensions or add-ons that you don't know you need. If in doubt, remove all of them.
The malware is now permanently inactivated, as long as you never reinstall it. A few small files will be left behind, but they have no effect, and trying to find them all is more trouble than it's worth.
-
Jun 1, 2016 7:48 AM in response to Linc Davisby stumble-r,Okay, I followed the steps and thought I was in the clear: but I still have the DealTop word popups on some webpages. Not as many as before, but still a few. The version my mac is running is 10.11.5 El Capitan. And all of my browsers' homepages are set to google & there are no plugins or extensions activated.
The folder looks like this now:
-
Jun 1, 2016 8:11 AM in response to stumble-rby Linc Davis,You need to delete the last item in that screenshot, then restart. If it comes back, boot in safe mode again and delete it.









