A
Please back up all data before making any changes.
Below is a suggested procedure to inactivate the malware you installed.
The numbers refer to the items in the screenshots, in the order shown. Use the screenshots as a guide. #1 would be the topmost item, #2 the one below, and so on.
The names in quotes refer to malware types, not to the names of the files. Don't expect the files to have similar names. For example, if you installed the "VSearch" malware, usually none of the files will have the word "VSearch" in the name. Malware attackers don't make it that easy for you.
In the first folder arranged as shown in the screenshots, delete these items:
#1 ("Flashmall")
In the second folder:
None
Restart the computer. Until you've done that, the malware will still be active, even after you delete the files.
Uninstall any Safari extensions you don't know you need. If in doubt, remove all of them. None is needed for normal operation.
Do the equivalent in the Chrome and Firefox browsers, if you use either of those.
Reset the Safari home page, if it was changed. You may need to do the same in the other browsers.
From the Applications folder (not shown in the screenshots), delete items with any of the following names:
EasyShopper
mediaDownloader
SoftwareUpdater
These steps will permanently inactivate the malware, as long as you never reinstall it. A few small files may remain in hidden folders, but they have no effect.
The instructions above apply only to you. I'm including more general—and complete—self-contained removal instructions below for the benefit of others who may find this discussion. You can skip the remaining steps, but you should read them.
B (optional)
You installed a variant of the "Flashmall" trojan. To remove it, start by backing up all data.
Don't use any kind of "anti-virus" or "anti-malware" product on a Mac. There is never a need for it, and relying on it for protection makes you more vulnerable to attack, not less.
Malware is always changing to get around the defenses against it. This procedure works as of now, as far as I know. It may not work in the future. Anyone finding this comment a few days or more after it was posted should look for a more recent discussion, or start a new one.
1. Please triple-click anywhere in the line below on this page to select it:
/Library/LaunchAgents
Right-click or control-click the highlighted line and select
Services ▹ Open
from the contextual menu.* A folder named "LaunchAgents" should open.
In the folder, there may be one or more files with a name that begins in either of the following ways:
com.EasyShopper
com.SoftwareUpdater
Move each such file to the Trash. You may be prompted for your administrator password.
2. Log out or restart the computer.
3. Open the Applications folder in the Finder. It may have subfolders with any of these names:
EasyShopper
mediaDownloader
SoftwareUpdater
Move each such subfolder to the Trash. Empty the Trash.
4. From the Safari menu bar, select
Safari ▹ Preferences... ▹ Extensions
Uninstall all extensions you don't know you need, including one called "SearchAssist," if it's present. If in doubt, remove all of them. None is required for normal operation. Do the equivalent in the Chrome and Firefox browsers, if you use either of those.
*If you don't see the contextual menu item, copy the selected text to the Clipboard by pressing the key combination command-C. In the Finder, select
Go ▹ Go to Folder...
from the menu bar and paste into the box that opens by pressing command-V. You may not see what you pasted because a line break is included. Press return.