You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

GOODGAME EMPIRE - POPUP - MALWARE? ADWARE?

Hi,


COMPUTER AND OS:

MacBook Pro (2011), OSX Yosemite, Version 10.10.5


PROBLEM:

I have a pop-up appearing for the past week. It appears both when safari is open, and when safari is not open. Screen shot Attached. When I first noticed this pop-up, the game appeared installed in my applications folder. I deleted the application, but the pop-up continues to appear.


SOLUTIONS I'VE TRIED:

I've went through my LaunchAgents and LaunchDaemons files, but I didn't see anything suscipious. Screen shot attached.User uploaded fileUser uploaded file


CALL FOR HELP!

Please help. I have no clue where else to look.

User uploaded file

MacBook Pro (13-inch Early 2011), OS X Yosemite (10.10.5)

Posted on Jan 21, 2016 3:56 AM

Reply
8 replies

Jan 21, 2016 9:36 AM in response to sadsdnfkas

First, never use any kind of "anti-virus" or "anti-malware" software on a Mac. That's how you cause problems, not how you solve them.

You may have installed a fake "utility" called "Advanced Mac Cleaner." Like any software that purports to automatically "clean up" or "speed up" a Mac, it's a scam, and some or all variants of it are ad-injection malware.

To remove it, please take the steps below. Some of the files listed may be absent in your case. Back up all data before proceeding.

Malware is always changing to get around the defenses against it. This procedure works as of now, as far as I know. It may not work in the future. Anyone finding this comment a few days or more after it was posted should look for a more recent discussion, or start a new one.

If you paid for the software with a credit card, consider reporting the charge to the bank as fraudulent.

Step 1

Triple-click anywhere in the line below on this page to select it:

~/Library/LaunchAgents

Right-click or control-click the highlighted line and select

Services Open

from the contextual menu.* A folder named "LaunchAgents" may open. If it does, look inside it for files with a name that begins like this:

com.pcv.

Move any such file to the Trash.

*If you don't see the contextual menu item, copy the selected text to the Clipboard by pressing the key combination command-C. In the Finder, select

Go Go to Folder...

from the menu bar and paste into the box that opens by pressing command-V. You may not see what you pasted because a line break is included. Press return.

Step 2

The malware is now permanently inactivated, provided that you don't reinstall it. This step is optional.

Delete the following items, if they exist, as in Step 1:

/Library/Application Support/amc

~/Library/AdvancedMacCleaner

There's no need to log out or restart after taking this step.

The problem may have started when you downloaded something, such as the application "FileZilla," from the "Sourceforge" website or some other Internet cesspit. Never visit that site again. All software should be downloaded only from the developer's website or from the Mac App Store, if applicable.

Jan 21, 2016 9:45 AM in response to sadsdnfkas

MalwareBytes is fine, it will not cause any problems regardless of what the above poster says. It was written by one of the most trusted members on these boards originally as AdwareMedic. It's often recommended by Apple Support personnel.

You'll note that I also linked to Apple's own support page regarding unwanted adware, use those instructions if you're comfortable with finding and deleting files on your own.

If anything beware of internet strangers telling you to find specific files and deleting them.

Feb 24, 2016 2:13 AM in response to Linc Davis

Thank-you Linc Davis for your post. I found & removed every file you mentioned.

You stated: /Library/Application Support/amc, but I found "that" file in my home library, not my computer library.

In addition to your post, I found & did the following:

1) turn on AppTrap (in System Preferences) >go to Applications/goodgame empire >delete > turn off AppTrap.

AppTrap: is an app that attempts to find and remove additional related folders & files.

AppTrap did find a few offending folders & files.

2) System Preferences >Users & Groups >your admin account >Login Items >remove the adware item.

I believe I unknowingly brought in this adware when I installed an update for YTD.app (YouTube Downloader).

YouTube Downloader is a great app, but I have to do browser preference & extension clean-ups after each of it's updates.

During it's last update, it installed a Mac cleaner app (as a prerequisite) but sneaked in the game adware.

Thank-you, Michael Rooney

Feb 24, 2016 3:42 AM in response to Esquared

Hi Esquared, I don't remember. I immediately deleted that "clean-up" app. I did not trust it. I only wanted to update my "Youtube Downloader" app. I may have to stop using "Youtube Downloader" if it's creating more problems than it's worth. I've used "Youtube Downloader" for years. Michael

GOODGAME EMPIRE - POPUP - MALWARE? ADWARE?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.