You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

How to remove nova rambler virus

i downloaded some freeware recently and now all my chrome urls have nova.rambler.ru prepended.

i've never had a virus or trojan on here so i have clue where to even start.


any help would be awesome

MacBook Pro with Retina display, OS X Yosemite (10.10)

Posted on Mar 16, 2017 9:11 PM

Reply
Question marked as Top-ranking reply

Posted on Mar 22, 2017 11:24 AM

Hi! I solved this problem just today after a very long nightmare. So, try to follow these steps:


- first of all, install another Browser (Firefox)

- export your Favourites if you are afraid to loose them ("Bookmarks", "Bookmarks Manager", "Organize" and choose "Export to HTML files")

- exit from Chrome

- go to the "Applications" folder and drag the Chrome icon into the Trashbox.

- Then click on the "Go" button on the upper Finder tool bar, choose "Go to Folder" and write this command:

~/Library/Application Support/Google/Chrome

- select all the Chrome folders and all the Chrome files displayed (you are inside the Chrome folder that is still inside your OS) and drag all of them inside the Trashbox

Now Chrome is completely uninstalled from your OS. Now:

- open Firefox, download the Chrome.dmg file from the Chrome official site and open it

- drag the Install file inside the "Application" folder

- launch Chrome

Now you have a "virgin" and "clear" Chrome installation. Then You have to:

- sign in with your Google account

- import your Bookmarks (but I think they will be already there after I have logged in)

- uninstall Firefox if You want or use both of them if You want.


I really hope this will help you, let me know if it works.

Bye,

39 replies
Question marked as Top-ranking reply

Mar 22, 2017 11:24 AM in response to martire

Hi! I solved this problem just today after a very long nightmare. So, try to follow these steps:


- first of all, install another Browser (Firefox)

- export your Favourites if you are afraid to loose them ("Bookmarks", "Bookmarks Manager", "Organize" and choose "Export to HTML files")

- exit from Chrome

- go to the "Applications" folder and drag the Chrome icon into the Trashbox.

- Then click on the "Go" button on the upper Finder tool bar, choose "Go to Folder" and write this command:

~/Library/Application Support/Google/Chrome

- select all the Chrome folders and all the Chrome files displayed (you are inside the Chrome folder that is still inside your OS) and drag all of them inside the Trashbox

Now Chrome is completely uninstalled from your OS. Now:

- open Firefox, download the Chrome.dmg file from the Chrome official site and open it

- drag the Install file inside the "Application" folder

- launch Chrome

Now you have a "virgin" and "clear" Chrome installation. Then You have to:

- sign in with your Google account

- import your Bookmarks (but I think they will be already there after I have logged in)

- uninstall Firefox if You want or use both of them if You want.


I really hope this will help you, let me know if it works.

Bye,

Mar 17, 2017 3:34 PM in response to thomas_r.

unfortunately nothing was found but the problem is still there :[





Malwarebytes Anti-Malware 1.2.6.730 system report - March 17, 2017 at 5:27:53 PM CDT

Mac OS X version Version 10.10.5 (Build 14F2009)

System uptime: 0d 00:16:16

Helper tool version: 1.2.6.730

Signatures version: 173



Safari extensions

-----------------------

username

username

Name: Adblock Plus

Path: /Users/username/Library/Safari/Extensions/Adblock Plus.safariextz

Modified: 2017-03-17 03:38:56 +0000


Name: AdBlock

Path: /Users/username/Library/Safari/Extensions/AdBlock.safariextz

Modified: 2015-11-24 07:59:01 +0000


Name: JS Blocker 5

Path: /Users/username/Library/Safari/Extensions/JS Blocker 5.safariextz

Modified: 2017-03-17 03:38:56 +0000




Chrome extensions

-----------------------

username

Default

Name: Google Slides

Path: /Users/username/Library/Application Support/Google/Chrome/Default/Extensions/aapocclcgogkmnckokdopfmhonfmgoek

Modified: 2015-05-29 04:58:03 +0000


Name: Google Docs

Path: /Users/username/Library/Application Support/Google/Chrome/Default/Extensions/aohghmighlieiainnegkcijnfilokake

Modified: 2015-05-29 04:58:27 +0000


Name: Google Drive

Path: /Users/username/Library/Application Support/Google/Chrome/Default/Extensions/apdfllckaahabafndbhieahigkjlhalf

Modified: 2015-11-24 08:12:14 +0000


Name: Web Developer

Path: /Users/username/Library/Application Support/Google/Chrome/Default/Extensions/bfbameneiokkgbdmiekhjnmfkcnldhhm

Modified: 2017-03-17 03:26:04 +0000


Name: ColorZilla

Path: /Users/username/Library/Application Support/Google/Chrome/Default/Extensions/bhlhnicpbhignbdhedgjhgdocnmhomnp

Modified: 2017-01-29 06:50:49 +0000


Name: YouTube

Path: /Users/username/Library/Application Support/Google/Chrome/Default/Extensions/blpcfgokakmgnkcojhhkbfbldkacnbeo

Modified: 2015-11-24 08:12:14 +0000


Name: Adblock Plus

Path: /Users/username/Library/Application Support/Google/Chrome/Default/Extensions/cfhdojbkjhnklbpkdaibdccddilifddb

Modified: 2017-03-17 22:12:40 +0000


Name: Google Search

Path: /Users/username/Library/Application Support/Google/Chrome/Default/Extensions/coobgpohoikkiipiblmjeljniedjpjpf

Modified: 2015-11-24 08:12:14 +0000


Name: Postman - REST Client

Path: /Users/username/Library/Application Support/Google/Chrome/Default/Extensions/fdmmgilgnpjigdojojpjoooidkmcomcm

Modified: 2016-09-30 05:01:05 +0000


Name: Google Sheets

Path: /Users/username/Library/Application Support/Google/Chrome/Default/Extensions/felcaaldnbdncclmgdcncolpebgiejap

Modified: 2015-05-29 04:58:04 +0000


Name: Postman

Path: /Users/username/Library/Application Support/Google/Chrome/Default/Extensions/fhbjgbiflinjbdggehcddcbncdddomop

Modified: 2017-03-17 03:26:04 +0000


Name: EditThisCookie

Path: /Users/username/Library/Application Support/Google/Chrome/Default/Extensions/fngmhnnpilhplaeedifhccceomclgfbg

Modified: 2015-05-29 04:58:33 +0000


Name: GoToMeeting Pro Screensharing

Path: /Users/username/Library/Application Support/Google/Chrome/Default/Extensions/gcgikpombjkodabhbdalkcdhmllafipp

Modified: 2016-05-20 16:31:22 +0000


Name: Google Docs Offline

Path: /Users/username/Library/Application Support/Google/Chrome/Default/Extensions/ghbmnnjooekpmoecnnnilnnbdlolhkhi

Modified: 2016-03-22 09:01:52 +0000


Name: AdBlock

Path: /Users/username/Library/Application Support/Google/Chrome/Default/Extensions/gighmmpiobklfepjocnamgkkbiglidom

Modified: 2017-03-17 03:26:04 +0000


Name: JavaScript Popup Blocker

Path: /Users/username/Library/Application Support/Google/Chrome/Default/Extensions/hiajdlfgbgnnjakkbnpdhmhfhklkbiol

Modified: 2015-11-24 08:12:16 +0000


Name: AngularJS Batarang

Path: /Users/username/Library/Application Support/Google/Chrome/Default/Extensions/ighdmehidhipcmcojjgiloacoafjmpfk

Modified: 2016-03-22 09:01:52 +0000


Name: WhatFont

Path: /Users/username/Library/Application Support/Google/Chrome/Default/Extensions/jabopobgcpjmedljpbcaablpmlmfcogm

Modified: 2016-07-16 02:37:45 +0000


Name: Cisco WebEx Extension

Path: /Users/username/Library/Application Support/Google/Chrome/Default/Extensions/jlhmfgmfgeifomenelglieieghnjghma

Modified: 2017-01-29 06:50:49 +0000


Name: Grammarly for Chrome

Path: /Users/username/Library/Application Support/Google/Chrome/Default/Extensions/kbfnbcaeplbcioakkpcpgfkobkghlhen

Modified: 2017-03-17 03:26:04 +0000


Name: The Great Suspender

Path: /Users/username/Library/Application Support/Google/Chrome/Default/Extensions/klbibkeccnjlkjkiokjodocebajanakg

Modified: 2015-09-06 05:19:00 +0000


Name: Corporate Ipsum

Path: /Users/username/Library/Application Support/Google/Chrome/Default/Extensions/lfmadckmfehehmdnmhaebniooenedcbb

Modified: 2015-05-29 04:58:33 +0000


Name: Allow-Control-Allow-Origin: *

Path: /Users/username/Library/Application Support/Google/Chrome/Default/Extensions/nlfbmbojpeacfghkpbjhddihlkkiljbi

Modified: 2016-06-14 19:02:54 +0000


Name: Chrome Web Store Payments

Path: /Users/username/Library/Application Support/Google/Chrome/Default/Extensions/nmmhkkegccagdldgiimedpiccmgmieda

Modified: 2017-03-17 03:26:04 +0000


Name: Gmail

Path: /Users/username/Library/Application Support/Google/Chrome/Default/Extensions/pjkljhegncpnkpknbcohdijeoejaedia

Modified: 2015-05-29 04:58:27 +0000


Name: Chrome Media Router

Path: /Users/username/Library/Application Support/Google/Chrome/Default/Extensions/pkedcjkdefgpdelpbcmbmeomcjbeemfm

Modified: 2017-01-29 06:50:49 +0000




Firefox extensions

-----------------------



User Login Items

-----------------------

User: username

Name: iTunesHelper

Path: /Applications/iTunes.app/Contents/MacOS/iTunesHelper.app


Name: Dropbox

Path: /Applications/Dropbox.app


Name: Remote Mouse

Path: /Applications/Remote Mouse.app


Name: EOS Utility

Path: /Applications/Canon Utilities/EOS Utility/EOS Utility.app


Name: MEGAsync

Path: /Applications/MEGAsync.app




System startup items

-----------------------



User launch agents

-----------------------

/Users/username/Library/LaunchAgents/com.adobe.AAM.Updater-1.0.plist

/Users/username/Library/LaunchAgents/com.dropbox.DropboxMacUpdate.agent.plist

/Users/username/Library/LaunchAgents/com.google.keystone.agent.plist



System launch agents

-----------------------

/Library/LaunchAgents/com.adobe.AAM.Updater-1.0.plist

/Library/LaunchAgents/com.adobe.AdobeCreativeCloud.plist

/Library/LaunchAgents/com.noextend.cmodutility.plist



System launch daemons

-----------------------

/Library/LaunchDaemons/com.adobe.adobeupdatedaemon.plist

/Library/LaunchDaemons/com.adobe.agsservice.plist

/Library/LaunchDaemons/com.adobe.fpsaud.plist

/Library/LaunchDaemons/com.malwarebytes.HelperTool.plist



Kernel extensions

-----------------------

/Library/Extensions/ACS6x.kext

/Library/Extensions/ArcMSR.kext

/Library/Extensions/ATTOCelerityFC8.kext

/Library/Extensions/ATTOExpressSASHBA2.kext

/Library/Extensions/ATTOExpressSASRAID2.kext

/Library/Extensions/CalDigitHDProDrv.kext

/Library/Extensions/HighPointIOP.kext

/Library/Extensions/HighPointRR.kext

/Library/Extensions/PromiseSTEX.kext

/Library/Extensions/SoftRAID.kext



launchd.conf contents

-----------------------





Hosts file

-----------------------

##

# Host Database

#

# localhost is used to configure the loopback interface

# when the system is booting. Do not change this entry.

##

127.0.0.1 localhost

255.255.255.255 broadcasthost

::1 localhost





Scan log

-----------------------

2017-03-17 16:46:00 :

2017-03-17 16:46:01 : ----- Scan Started -----

2017-03-17 16:46:01 : Scanning with signatures version 173 (2017-3-16)

2017-03-17 16:49:23 : PUP.JDIBackup : /Users/username/Library/LaunchAgents/com.jdibackup.ZipCloud.autostart.plist

2017-03-17 16:49:23 : PUP.JDIBackup : /Users/username/Library/LaunchAgents/com.jdibackup.ZipCloud.notify.plist

2017-03-17 16:49:30 : *** Scan time: 0d 00:03:29 ***

2017-03-17 16:49:30 : ------ Scan Ended ------

2017-03-17 17:09:26 : Removing detected threats...

2017-03-17 17:09:26 : Removing Item: /Users/username/Library/LaunchAgents/com.jdibackup.ZipCloud.autostart.plist

2017-03-17 17:09:26 : Removing Item: /Users/username/Library/LaunchAgents/com.jdibackup.ZipCloud.notify.plist

2017-03-17 17:09:26 : ---- Threat Removal Complete ----

2017-03-17 17:09:40 : ===== Attempting restart =====

2017-03-17 17:13:18 :

2017-03-17 17:13:18 : ----- Scan Started -----

2017-03-17 17:13:18 : Scanning with signatures version 173 (2017-3-16)

2017-03-17 17:16:11 : *** Scan time: 0d 00:02:52 ***

2017-03-17 17:16:11 : ------ Scan Ended ------




User uploaded file

Mar 17, 2017 5:44 AM in response to martire

Download a copy of Malwarebytes Anti-Malware for Mac from here:


https://malwarebytes.com/mac/


If it doesn't detect and remove whatever is causing this problem, then I'd like to get more information. One option would be to choose Take System Snapshot from the Scanner menu, in the menu bar at the top of the screen, within Malwarebytes Anti-Malware. Then select the entire contents of the window that opens, copy it and paste into a reply here.


Alternately, if you'd prefer not to post that info publicly on this site, choose Contact Support from the Help menu within Malwarebytes Anti-Malware to send this info directly to Malwarebytes. Include a link to this discussion and my name (Thomas Reed) in the problem description, and I'll see it and respond.


(Note that I work for Malwarebytes, and the link I provided above goes to a Malwarebytes page. There is no need to purchase anything to solve this problem.)

Mar 17, 2017 4:44 PM in response to martire

You've got quite a lot of Chrome extensions installed, but I can't identify any of them in particular as adware. Is this problem only happening in Chrome? If so, it's likely that one of them is the culprit. Keep in mind that you may recognize all of those extensions, but it's actually pretty common for abandoned Chrome extensions to be obtained by adware makers and updated with adware code.


Make sure to disable all of your Chrome extensions, regardless of whether you think they're suspicious, and see if that makes a difference.


If it doesn't you may need to reset Chrome, and potentially may also need to reset your Google sync settings. See:


https://support.google.com/chrome/answer/3296214?hl=en

https://support.google.com/chrome/answer/6386691?hl=en


If you're seeing the problem in Safari as well as in Chrome, I don't see anything installed that would explain that. If this is the case, restart the computer in recovery mode by holding down command-R at startup. Once you're in recovery mode, you'll see a window with four options, one of which is Get Help Online. Click that to open a fresh copy of Safari. Browse normally for a while and see if the problem still happens, or if it has gone away. Be sure to browse long enough that you can be sure. Then let me know what the results of that test are.

Mar 17, 2017 7:54 PM in response to martire

Hello martire,

I wrote a little diagnostic program to help show what might be causing these problems. Download EtreCheck from https://www.etrecheck.com, run it, and paste the results here. EtreCheck is perfectly safe to run, does not ask for your password to install, and is signed with my Apple Developer ID.


Specifically, I'm interested in the "/etc/hosts" value in your EtreCheck report. I have seen information on the internet that says the PC version of this malware modifies the hosts file. If this is a Mac port, it may work the same way. If so, we can help you correct the problem.


What was this freeware program anyway? Was it the "MEGA" software? It may have been this software or its installer that hacked up your system.


Finally, do you have this problem in Safari too? EtreCheck isn't going to help much with Chrome. It only reports information about Safari extensions. I just can't keep up with Apple and 3rd party software.


Disclaimer: Although EtreCheck is free, there are other links on my site that could give me some form of compensation, financial or otherwise.

Mar 18, 2017 3:40 AM in response to martire

martire wrote:


I deleted chrome and reinstalled. No issues yet


Did you delete all of Chrome's data files as well, so you were essentially starting from scratch with Chrome. If so, that's an "extreme reset," so to speak, and should solve any Chrome settings or extension issues! 🙂


If you just deleted the Chrome app itself, and not any of the data files, and that solved the problem, that will be very interesting indeed... that would suggest that something modified the Chrome app, which is not something I've seen before. (Firefox, yes, but not Chrome.)

Mar 18, 2017 8:24 AM in response to thomas_r.

thomas_r. wrote:


etresoft wrote:


Specifically, I'm interested in the "/etc/hosts" value in your EtreCheck report.


John, you can see the hosts contents in the output from Malwarebytes above. It's normal, hasn't been modified.

OK. I see that now. However, you shouldn't automatically post the contents of that file. It can have sensitive information in it. It can also have thousands of lines. A better idea is just to post the number of non-default entries. That will tell you all you need to know.


But even if the hosts file isn't modified, there are other ways to accomplish the same thing. If malware authors ever figure out how to write decent Mac software, it will be much more difficult to detect and remove. Thankfully, Apple makes writing decent Mac software really hard.

Mar 19, 2017 7:55 AM in response to martire

Hello there.


Yesterday I made a rookie mistake because I wanted to install some controllers to play PES 16 on my macbook pro.

I installed 3 things: 1) A suspicious zip file which I had no idea what was going to do -I was just following instructions like a dumb desperate rookie- (*********
); 2) The 360Controller driver (https://github.com/360Controller/360Controller/releases) which didn´t work and I already deleted; 3) USB Overdrive 3.3 (developed by Alessandro Levi Montalcini) which worked, but I uninstalled and the problem persists.

I´m pretty sure that the trojan came from the 1st file, which I installed and nothing happened after. No application appeared in the Apps folder.


The result is that now I´m infected with this nova.rambler.ru spyware. This malware replaced Google on my browser (just Google Chrome, Safari works fine). This means that every time I want to search something in Google, it changes URL and website to this nova.rambler.ru.


I already did all of the things you mentioned before: deleted and reinstalled Chrome. The problem disappeared for a while, and then came back. I reseted all the extensions and downloaded 2 anti spyware programs: Malwarebytes Anti-Malware and an app store app called Adware Doctor. None of them could find nor delete the infection.


Do you have any idea of what/where could this be?

<Link Edited by Host>

Mar 29, 2017 9:28 AM in response to WilliamChan04

I have the same problem, from yesterday.

So, try that:

- after You have trashed the Chrome Icon from "Applications" Folder and You have deleted files and folders writing the command ~/Library/Application Support/Google/Chrome, click again "Go to Folder" and write:

~/Library/Application Support/Google

As You can see, a folder called "Chrome" is still there; delete it.

Then, again, choose "Go to Folder" and write: ~/Library/Application Support

Look at some suspected files and, if you find them, trash them (for example, I found some folders that I thought I had deleted).

Mar 31, 2017 5:56 PM in response to phong113

phong113 wrote:


All the methods you guys mentioned above, I have tried them all. They don't work.


It (nova.rambler.ru) comes back after 2 days.


Thus far, from what I can determine, this is not due to any kind of adware or malware installed on your computer. It seems to be a changed setting hidden somewhere deep in Chrome's settings, or perhaps the Chrome app. However, I really don't know for sure yet. (I've talked to quite a few people with this problem now, and it's very odd how none of them will give me a straight answer to all my questions.)


My recommendation is to completely delete Chrome and all Chrome settings files. Follow the instructions here for uninstalling Chrome on the Mac, including removal of the profile data:


https://support.google.com/chrome/answer/95319?co=GENIE.Platform%3DDesktop&hl=en


If you are willing to work with me to identify the cause of this problem - which will mean you'll need to trust me with your Chrome profile info - get a copy of Malwarebytes Anti-Malware for Mac and choose Contact Support from the Help menu within that app. In the description of the problem, mention nova.rambler.ru, my name (Thomas Reed), and that you're willing to help identify the cause.

How to remove nova rambler virus

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.