ICloud malware

Hi All,,,

My safari browser keeps defaulting to yahoo, i suspect due to malware. I have run malwarebytes on the advice of the support team and removed a few. However my Safari browser still defaults to yahoo.
today after a lengthy period trying to remove it with the support team who I might add were great, it has been narrowed down to the problem being on the icloud. well suspected.


My question is:
Is it possible to get malware or an infection that causes this on the icloud? I thought this was totally secure etc

I have only had the Macbook pro since march this year so I am relatively new to macs

MacBook Pro with Retina display, iOS 11.3.1

Posted on Aug 21, 2018 9:36 AM

Reply
Question marked as Top-ranking reply

Posted on Aug 22, 2018 1:08 AM

iCloud server is secured see this article https://support.apple.com/en-in/HT202303

The Mac might be infected if you click on suspicious links , in safari preferences keep all the extensions as off , in users and groups login items as empty .

You might be using some third party softwares / apps in Mac and still unaware of it run etrecheck https://etrecheck.com/

And post the results , even if you create a new user account if a single adware / malware is there in machine it will not go away ( and you will see problem in setting up home page ) , some times root user account is created and in the root user account itself scan the Mac with malwarebytes after the log out from root user account .

Also if safari is corrupted in user library - preferences - delete com.apple.Safari.plist into the trash , restart the Mac and empty the trash again set up the homepage Set your homepage in Safari on Mac - Apple Support

8 replies
Question marked as Top-ranking reply

Aug 22, 2018 1:08 AM in response to Sboroblu

iCloud server is secured see this article https://support.apple.com/en-in/HT202303

The Mac might be infected if you click on suspicious links , in safari preferences keep all the extensions as off , in users and groups login items as empty .

You might be using some third party softwares / apps in Mac and still unaware of it run etrecheck https://etrecheck.com/

And post the results , even if you create a new user account if a single adware / malware is there in machine it will not go away ( and you will see problem in setting up home page ) , some times root user account is created and in the root user account itself scan the Mac with malwarebytes after the log out from root user account .

Also if safari is corrupted in user library - preferences - delete com.apple.Safari.plist into the trash , restart the Mac and empty the trash again set up the homepage Set your homepage in Safari on Mac - Apple Support

Aug 22, 2018 4:42 AM in response to Sboroblu

Go to system preferences and click on users and groups open the pad lock by entering admin name and password ( in case if it is an admin account ) , select login items , if you see app select it and click on minus sign to get deleted .

In system preferences itself click on Security and privacy , click on Accessibility then privacy select the suspicious app click on minus sign to get deleted .

Click on finder and search in Applications and download folder .

The next step would be enter in System Library .

Click on Finder , take cursor on top menu bar click on Go - Computer - Macintosh HD - Library

You have to manually search app in some folders where they reside .

1.Application Support

2.Caches

3.LaunchAgents

4.LaunchDaemons

5.Logs

6.PriviledgedHelperTools

7.Startup-items

8.Receipts

9.Preferences - the plist of app is to be removed , if there is com.apple .xxxx .plist it could also be com.apple.xxx.plist

10.Extensions

11.Frameworks

12.internet Plug -ins

13.Input Methods

14.ScriptingAdditions

Then enter in User library macOS Sierra: Library folder

Search in folders

1.Application Support

2.Caches

3.Cookies

4.Safari

5.Logs

6.Saved Application State

7.LaunchAgents

8.Internet Plug -ins

9.Input Methods

10.Preferences - com.apple.xxx.plist .

11.Containers are also to be checked .

Then again click on Finder - Go - Macintosh HD - System - Library - Frameworks - search the app remnants in Framework folder .

Right click on remnants from the above folders and move to the trash bin , restart the computer and empty the trash .

Aug 21, 2018 2:25 PM in response to thomas_r.

All of the above was carried out several times in different ways. Safari files and anything related were deleted so safari would regenerate itself,,, but it still came back.
They had me set up a new user test account, that was ok until I signed in with my user name then the yahoo sear tab reappeared... They then assumed it came down from icloud?


I had to break off at that point for work,,,, we are continuing tomorrow

Aug 21, 2018 1:44 PM in response to Sboroblu

This problem cannot be on iCloud, they're definitely wrong about that.


Have you tried changing your Safari home page in Safari's preferences? If not, try that now. Malwarebytes will not (and cannot, due to recent changes to Safari) change Safari's home page for you. Also, before doing that, make sure you have restarted your computer following the removal of whatever Malwarebytes detected.

Aug 22, 2018 2:54 AM in response to tygb

Hi,, Thanks for that
That has all been done. Just had another hour session with apple support,,, they were great,,, but the problem is still there
What we did notice was safe finder was on the top right of the yahoo browser screen when it appears and now it seems to be making the MacBook loose the internet connection, where as other devices in the house are staying connected.
To save time I think a complete reboot is the order of the day.


I will get into that later

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

ICloud malware

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.