Notices
Computer/Internet Issues & Troubleshooting Anyone with questions about the terribly complex world of computers or the internet should try here. NOT FOR REPORTING ISSUES WITH PPRuNe FORUMS! Please use the subforum "PPRuNe Problems or Queries."

Virus in osx

Old 7th August 2016 | 18:10
  #1 (permalink)  
Thread Starter
 
Joined: Jan 2008
Posts: 3,156
Likes: 113
From: There and here
Virus in osx

So, this is not a tale of how whilst visiting a transvestite donkey witch porn website a virus was downloaded, but on a totally innocent mountain walking website……Trying to view a series of mountain views, an Adobe message box came up to say that i didn't have the latest version to view the series of photos. All kosher and that went well, but thereafter i have been plagued with pop up pages (despite being blocked in settings) of various ads for 'getting rid of viruses', 'cleaning up your slow mac' and so on. The virus seems to be (e.tre456_worm_osx) and despite running ClamX no viruses were found, despite clearing all cookies, doing clearings with Onyx, and of course getting rid of the Adobe download, it's still happening, seemingly set off by pressing either the page down button, or the space bar which brings up various new windows…VERY ANNOYING indeed. Anyone have a clue as to what to do ? Is this all it's doing ? Any help appreciated chaps.
SpringHeeledJack is offline  
Reply
Old 7th August 2016 | 18:57
  #2 (permalink)  
 
Joined: Mar 2002
Posts: 4,569
Likes: 1
From: Florida
Probably not much help for your problem but I also get occasional problems with totally innocent websites.

Mostly it's a plant or re-direct type problem looking for me to buy something

I suspect that the innocent website (with cheap virus potection) has been slightly hacked.

The real danger to me is now clicking on those links that try to get me to buy something I wasn't looking for.

PS I never try to improve my ability to view something by clicking on something in the site that asks for it. Figuring if they can't make it simple to match my quick scan than forget it.
lomapaseo is offline  
Reply
Old 7th August 2016 | 19:13
  #3 (permalink)  
 
Joined: Nov 2015
Posts: 317
Likes: 0
From: Here
I'm still new to Apple kit so bit of a random thought, can you use Time Machine to put your device back to how it was before you visited the website that has caused you problems?

Perhaps set up an online chat with Apple support - I find them very good.
yellowtriumph is offline  
Reply
Old 8th August 2016 | 08:06
  #4 (permalink)  
Chief Tardis Technician
 
Joined: Jan 2001
Posts: 554
Likes: 0
From: Western Australia S31.715 E115.737
This may be of help.
https://malwaretips.com/blogs/remove-mac-os-x-virus/

google for browser hijack, lots of stuff out there.
Avtrician is offline  
Reply
Old 8th August 2016 | 11:44
  #5 (permalink)  
 
Joined: Apr 2016
Posts: 221
Likes: 0
From: localhost
Again, not much help for your present situation but for future reference: NEVER click on any unsolicited pop up asking you to scan/download anything, saying piece of software x is out of date. They are becoming increasingly common and of greater danger.

I would recommend you back up what you can and factory reset the laptop which may be inconvenient but in my experience is the only way to rid yourself of the blight.
crablab is offline  
Reply
Old 8th August 2016 | 13:49
  #6 (permalink)  
Hippopotomonstrosesquipidelian title
 
Joined: Oct 2006
Posts: 1,825
Likes: 1
From: is everything
As others said, it looks like malware got itself installed by social engineering: it persuaded you to do it. Malwarebytes for Mac should be able to kill it.

https://www.malwarebytes.com/antimalware/mac/
Bushfiva is offline  
Reply
Old 9th August 2016 | 15:34
  #7 (permalink)  
Thread Starter
 
Joined: Jan 2008
Posts: 3,156
Likes: 113
From: There and here
Thankyou for all the advice chaps! As i'm travelling at the moment, the blocking of anything is at best difficult. Apart from the steps taken in the OP, I also deleted Safari and all it's associated files and then re-installed it, sadly to the same state as before. Mr Bushfiva's link seems to have provided the solution (fingers crossed).

The culprits were 'Adware.Awesome Screenshot' and 'Adware.Crossrider' hidden away in the launch items where 'MyShopMate' and 'Software-Updater.agent were causing browsing havoc. The effects have been sporadically persistent , even when logging into pprune, the moment the cursor touched the box up popped another window of supposed linked content. Thankfully DIDN'T do anything whilst checking e-mails. This is my 1st experience with malware, and in general i'm pretty careful. My laptop is an older Apple MBP running Mountain Lion, serves me very well in most cases, but now and again certain websites can't function as they are set up to liase with the more up to date OS's etc, and i do get messages saying that i need to upgrade to the latest version of XYZ to use the facilities. How do 'we' tell the good from the bad in such cases ?

Thanks again for help.
SpringHeeledJack is offline  
Reply
Old 9th August 2016 | 15:37
  #8 (permalink)  
 
Joined: Apr 2016
Posts: 221
Likes: 0
From: localhost
Ultimately, it is getting more and more difficult to tell these malware pop ups apart from the real mccoy. I advise, if you get a pop up saying, for example, to update your Adobe Flash player; you go to the Adobe website (without clicking on said popup) and download any update there.

Hope this helps and glad you're getting it sorted

EDIT: this thread may help: http://www.pprune.org/computer-inter...urity-faq.html
crablab is offline  
Reply

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Thread Tools
Search this Thread

Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service

Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.