Similar experience & our solution thanks to Apple:
Dear Apple,
I wish to commend your employee, James (Atlanta), for helping us out of an exceedingly apprehensive
Malware/phishing incident. My wife and I both thought we were updating Adobe Flash on our MacBook
Pros by clicking a Flash update popup that appeared to look genuine.
James informed us this happens often and quickly identified Advanced Mac Cleaner (AMC)
877-861-1418 as the culprit. They'd enticed (spoofed) us to install their AMC malware on our
MacBooks by eluding us into thinking we were simply updating our Adobe Flash.
Here’s a summary of our phishing experience hopefully others can benefit from:
1. We were Spoofed/Phished to click a popup presumably to upgrade our Adobe Flash.
2. Clicking anywhere on their popup (even "not interested") immediately downloaded AMC malware
with popups all over our computers warning to urgently take action, even after restart.
3. On chatting with Apple (we thought), a "John Williams aka C... Charma) masqueraded as Apple.),
Soon John called our phone from 855-464-4020 and an Indian accent, and proceeded to connect
to our Macs remotely. We were very trusting as we really thought he represented Apple and he
assured us he'd clear up the mess within an hour. All seemed OK until he said our best option was
to pay him (Malware Solution) $169.99 per Mac to remove Malware (they'd put there?) plus a
guarantee it won’t occur again and if it did, theyd remove it for free.
4. We didn't believe him so we called "real” Apple (James) @ 1-800-MYAPPLE who rapidly helped via remote
login to clear up our mess: removing the culprit AMC App, clearing history, cache and checking our privacy
settings, at no cost.
James was aware of the AMC App and advised to never to update Adobe Flash via a popup. If necessary,
only download from Adobe's website. Hopefully flash will disappear soon as most websites have migrated
to the new H164 web development standard that obsoletes the need for flash.
5. Being skeptical, I made screen captures throughout our scam session, which you can find at:
http://50.142.159.90/~olaf/OS/Malware/
When I asked James if I should report our scam to Apple he said "yes" and provided your phishing email.
We hope this helps prevent such illegal scams for other Mac Users and Apple.
Sincerely,
Olaf