jbgriffee

Q: malware

Appear that I downloaded malware.  I removed MegaBackup and Mac Defender but now safari goes to a blank window with a search field and the web address is ChumSearch.  How do I get rid of this and get back to having Safari go to my preference search engine?

Posted on Mar 11, 2016 3:27 PM

Close

Q: malware

  • All replies
  • Helpful answers

Previous Page 2 of 4 last Next
  • by Linc Davis,

    Linc Davis Linc Davis Apr 30, 2016 8:35 AM in response to dalwan1
    Level 10 (207,931 points)
    Applications
    Apr 30, 2016 8:35 AM in response to dalwan1

    Below is a suggested procedure to inactivate the malware you installed.

    Please back up all data before making any changes.

    The numbers refer to the items in the screenshots, in the order shown. Use the screenshots as a guide. #1 would be the topmost item, #2 the one below, and so on.

    The names in quotes refer to malware types, not to the names of the files. Don't expect the files to have similar names. For example, if you installed the "VSearch" malware, usually none of the files will have the word "VSearch" in the name. Malware attackers don't make it that easy for you.

    You may be prompted for your administrator name and/or password when you delete some of the files listed below, or you may be prompted to confirm because a file is locked.

    In the first folder arranged as shown in the screenshots, delete these items:

              #1 and #2 ("VSearch")

    In the second folder:

              #1 and #2 ("Flashmall")

    In the third folder:

              #3 through #5 ("Genieo")

              #7 and #8 ("Flashmall")

    Restart the computer. Until you've done that, the malware will still be active, even after you delete the files.

    Uninstall any Safari extensions you don't know you need. If in doubt, remove all of them. None is needed for normal operation.

    Do the equivalent in the Chrome and Firefox browsers, if you use either of those.

    Reset the Safari home page and search engine, if either was changed. You may need to do the same in the other browsers.

    From the Applications folder (not shown in the screenshots), delete items with any of the following names:

              MPlayerX

              PDF Pronto

    Open your home folder by clicking the house icon with your name in the sidebar of a Finder window. If there is a subfolder named "Applications" (different from the main Applications folder), remove anything in it that you don't recognize.

    These steps will permanently inactivate the malware, as long as you never reinstall it. A few small files may remain in hidden folders, but they have no effect.

  • by maru3,

    maru3 maru3 May 6, 2016 7:22 AM in response to Linc Davis
    Level 1 (4 points)
    May 6, 2016 7:22 AM in response to Linc Davis

    Screen Shot 2016-05-06 at 7.32.57 pm.png

  • by wdinaun,

    wdinaun wdinaun May 9, 2016 3:07 PM in response to Linc Davis
    Level 1 (4 points)
    May 9, 2016 3:07 PM in response to Linc Davis

    Step 1

    Screen Shot 2016-05-09 at 4.55.30 PM.png

     

    Step 2

    Screen Shot 2016-05-09 at 4.56.48 PM.png

     

    Step 3

    Screen Shot 2016-05-09 at 4.58.09 PM.png

     

    Step 4

    Screen Shot 2016-05-09 at 4.59.48 PM.png

     

    Step 5

    Chrome

    Screen Shot 2016-05-09 at 5.01.58 PM.png

    Screen Shot 2016-05-09 at 5.02.17 PM.png

     

    Step 5

    Firefox

    Screen Shot 2016-05-09 at 5.05.43 PM.png

  • by wdinaun,

    wdinaun wdinaun May 9, 2016 3:09 PM in response to Linc Davis
    Level 1 (4 points)
    May 9, 2016 3:09 PM in response to Linc Davis

    Just replied and looking forward to your help. Thanks!

  • by wdinaun,

    wdinaun wdinaun May 10, 2016 11:03 AM in response to wdinaun
    Level 1 (4 points)
    May 10, 2016 11:03 AM in response to wdinaun

    And... nevermind. I got it worked out.

  • by esd216,

    esd216 esd216 May 27, 2016 6:57 PM in response to Linc Davis
    Level 1 (4 points)
    May 27, 2016 6:57 PM in response to Linc Davis

    Can you help me with this problem?

     

    Screen Shot 2016-05-27 at 9.45.59 PM.png

     

    Screen Shot 2016-05-27 at 9.47.04 PM.png

  • by esd216,

    esd216 esd216 May 27, 2016 7:02 PM in response to Linc Davis
    Level 1 (4 points)
    May 27, 2016 7:02 PM in response to Linc Davis

    For chrome:

     

    Screen Shot 2016-05-27 at 10.01.29 PM.png

  • by Ladyfarah,

    Ladyfarah Ladyfarah May 27, 2016 7:31 PM in response to Linc Davis
    Level 1 (4 points)
    May 27, 2016 7:31 PM in response to Linc Davis

    Screen Shot 2016-05-28 at 10.22.11.png

  • by Ladyfarah,

    Ladyfarah Ladyfarah May 27, 2016 7:40 PM in response to Linc Davis
    Level 1 (4 points)
    May 27, 2016 7:40 PM in response to Linc Davis

    Screen Shot 2016-05-28 at 10.22.11.png

    Screen Shot 2016-05-28 at 10.38.01.png

    Screen Shot 2016-05-28 at 10.38.01.png

  • by M.E. Kynan,

    M.E. Kynan M.E. Kynan Jun 2, 2016 9:43 PM in response to Linc Davis
    Level 1 (4 points)
    Jun 2, 2016 9:43 PM in response to Linc Davis

    I would very much appreciate your help getting Chumsearch off my computer. I installed MacKeeper before fully researching it to try to solve that problem, and I hope I have successfully uninstalled it. I also found Mega Backup in my applications, and I put it in the trash. All this trouble came from my trying to update Adobe and not paying enough attention to what I was doing.

     

    Screen Shot 2016-06-03 at 12.30.05 AM.png

     

    Screen Shot 2016-06-03 at 12.32.51 AM.png

     

    Screen Shot 2016-06-03 at 12.34.09 AM.png

     

    Screen Shot 2016-06-03 at 12.34.20 AM.png

     

    Screen Shot 2016-06-03 at 12.34.30 AM.png

  • by mmenigma,

    mmenigma mmenigma Jun 3, 2016 12:13 PM in response to Linc Davis
    Level 1 (8 points)
    Mac OS X
    Jun 3, 2016 12:13 PM in response to Linc Davis

    I followed Linc's instructions here and it was a big help. But I had to do one more thing to insure the adware was gone.  What was happening on my iMac was when I startup, after everything loads from the system, the following files were created and placed in private/var/tmp

     

    Screen Shot 2016-06-03 at 7.19.53 AM.png

    If dit8.tgz is allowed to decompress, it installs a folder in tmp called Injector.  Inside this folder is bad stuff that creates the files Linc discusses. The injector files infects browsers with adware selling virus removal software. What a surprise, right?  Deleting the files Linc recommendes got rid of the source but I also needed to delete the files from private/var/tmp. 

  • by lucreziaaaas,

    lucreziaaaas lucreziaaaas Jun 6, 2016 7:08 AM in response to Linc Davis
    Level 1 (4 points)
    Jun 6, 2016 7:08 AM in response to Linc Davis


    Looking forward to your help.. I had chum search installed and I don't know how.. Could you help me?

  • by mmenigma,

    mmenigma mmenigma Jun 6, 2016 7:57 AM in response to lucreziaaaas
    Level 1 (8 points)
    Mac OS X
    Jun 6, 2016 7:57 AM in response to lucreziaaaas

    I'm no expert.  All I did was follow these instructions:

     

    Re: malware

     

    You can do the same.

  • by lizadanger,

    lizadanger lizadanger Jun 6, 2016 2:11 PM in response to Linc Davis
    Level 1 (4 points)
    Jun 6, 2016 2:11 PM in response to Linc Davis

    Same issue. Any help is appreciated! Thanks!

    1.jpg2.jpg3.jpg4.jpg5.jpg

  • by poeman15,

    poeman15 poeman15 Jun 8, 2016 7:42 AM in response to Linc Davis
    Level 1 (4 points)
    Jun 8, 2016 7:42 AM in response to Linc Davis

    Seems i have some type of adware. Saw your post and thought i would ask for help.

    The LaunchAgents window came up and I deleted those files within a week ago. The window will

    still appear but has no contents.  This is the LaunchDaemons window that appears.

    Thanks

    Screen Shot 2016-06-08 at 10.33.30 AM.png

Previous Page 2 of 4 last Next