?Virus ?Malware in my Software Update

Hi Guys,
Being a little cautious - I like to run Little Snitch on my MacBook to see the network connections each program makes.
I've just noticed Software Update trying to connect to:
1) swscan.apple.com (to be expected)
2) b.scorecardresearch.com (??why ?malware)
3) ds.serving-sys.com (??why ?malware)
If I block access to these domains (2 & 3) using Little Snitch - the software update still appears to work normally -so they are obviously not 'required'.
Does anyone else's Software Update on 10.6.6 try and connect to these sites. Any further info anyone?

Hi WZZZ
- yes, I have been using OpenDNS at the router level for over 12 months now
- yes, it still confirms that I'm using OpenDNS when I go to http://www.opendns.com/welcome/
I temporarily removed all rules for Software Update from Little Snitch and ran again to follow what was happening. Little Snitch requested permission in the following order:
swscan.apple.com (accepted)
swcdn.apple.com port 80 (accepted once)
which interestingly on Little Snitch appears as a connection to 'ds.serving-sys.com'
(didn't ask to specifically connect to 'ds.serving-sys.com')
(didn't ask for b.scorecardresearch this time)
doing a TraceRoute on swcdn.apple.com ends up after 16 hops as akamaitechnologies.com
16 a204-2-160-16.deploy.akamaitechnologies.com (204.2.160.16) 307.173 ms 298.943 ms 306.822 ms
doing a TraceRoute on ds.serving-sys.com ALSO ends up after 16 hops as akamaitechnologies.com
16 a204-2-160-16.deploy.akamaitechnologies.com (204.2.160.16) 261.007 ms 352.034 ms 307.811 ms
After some googling, it appears akamaitechnologies.com is a CDN which apple may use (http://forums.whirlpool.net.au/archive/350920).
Running Software Update while only allowing connections to swscan.apple.com, completes the check but shows 'All Software Is Up To Date'.
Running Software Update while allowing connections to swscan.apple.com + swcdn.apple.com (appearing as ds.serving-sys.com in Little Snitch connection history) shows that there are Garage Band Instrument updates (which would be expected as I told Garage Band to download the other available instruments).
Perhaps it is just a CDN used by Apple for users (after all, I am in Australia). It still bothers me that it shows up as ds.serving-sys.com - especially given the nature of that company.
Any other Australian Apple users seeing the same appear on there Little Snitch??
Any other ideas? Am I just being paranoid?
Thanks again for input guys.

Similar Messages

  • HT5244 If "flashback malware removal tool" was in your software updates...does that mean you have the flashback virus?

    If "flashback malware removal tool" was in your software updates...does that mean you have the flashback virus?

    carol afromfl wrote:
    If "flashback malware removal tool" was in your software updates...does that mean you have the flashback virus?
    No, it just means that you are running Lion and do not have Java installed. The update will simply check for any previous infection and let you know if it finds anything. If it doesn't find anything it will quit without any notices. In either case, it will then delete itself and you can sleep easy until the next one comes along.

  • Virus Malware Malicious content protection software?

    Is it true that I will not need to have active virus/malware /malicious content protection on my Mac?   Should I, or dont bother?

    1. This comment applies to malicious software ("malware") that's installed unwittingly by the victim of a network attack. It does not apply to software, such as keystroke loggers, that may be installed deliberately by an intruder who has hands-on access to the victim's computer. That threat is in a different category, and there's no easy way to defend against it. If you have reason to suspect that you're the target of such an attack, you need expert help.
    2. All versions of OS X since 10.6.7 have been able to detect known Mac malware in downloaded files, and to block insecure web plugins. This feature is transparent to the user, but internally Apple calls it "XProtect." The malware recognition database is automatically updated once a day; however, you shouldn't rely on it, because the attackers are always at least a day ahead of the defenders.
    The following caveats apply to XProtect:
    It can be bypassed by some third-party networking software, such as BitTorrent clients and Java applets (see below.)
    It only applies to software downloaded from the network. Software installed from a CD or other media is not checked.
    3. Starting with OS X 10.7.5, there has been another layer of built-in malware protection, designated "Gatekeeper" by Apple. By default, applications and Installer packages downloaded from the network will only run if they're digitally signed by a developer with a certificate issued by Apple. Software certified in this way hasn't actually been tested by Apple (unless it comes from the Mac App Store), but you can be reasonably sure that it hasn't been modified by anyone other than the developer. His identity is known to Apple, so he could be held legally responsible if he distributed malware. For most practical purposes, applications recognized by Gatekeeper as signed can be considered safe.
    Gatekeeper has, however, the same limitations as XProtect, and in addition the following:
    It can easily be disabled or overridden by the user.
    A malware attacker could get control of a code-signing certificate under false pretenses, or could find some other way to evade Apple's controls.
    For more information about Gatekeeper, see this Apple Support article.
    4. Beyond XProtect and Gatekeeper, there’s no benefit, in most cases, from any other automated protection against malware. The first and best line of defense is always your own intelligence. All known malware circulating on the Internet that affects a fully-updated installation of OS X 10.6 or later takes the form of so-called "trojan horses," which can only have an effect if the victim is duped into running them. The threat therefore amounts to a battle of wits between you and the malware attacker. If you're smarter than he thinks you are, you'll win.
    That means, in practice, that you never use software that comes from an untrustworthy source. How do you know whether a source is trustworthy?
    Any website that prompts you to install a “codec,” “plug-in,” "player," "archive extractor," or “certificate” that comes from that same site, or an unknown one, is untrustworthy.
    A web operator who tells you that you have a “virus,” or that anything else is wrong with your computer, or that you have won a prize in a contest you never entered, is trying to commit a crime with you as the victim. (Some reputable websites did legitimately warn users who were infected with the "DNSChanger" malware. That exception to this rule no longer applies.)
    Pirated copies or "cracks" of commercial software, no matter where they come from, are unsafe.
    Software of any kind downloaded from a BitTorrent or from a Usenet binary newsgroup is unsafe.
    Software with a corporate brand, such as Adobe Flash Player, must be downloaded directly from the developer’s website. If it comes from any other source, it's unsafe.
    5. Java on the Web (not to be confused with JavaScript, to which it's not related, despite the similarity of the names) is a weak point in the security of any system. Java is, among other things, a platform for running complex applications in a web page, on the client. That was never a good idea, and Java's developers have had a lot of trouble implementing it without also creating a portal for malware to enter. Past Java exploits are the closest thing there has ever been to a Windows-style "virus" affecting OS X. Merely loading a page with malicious Java content could be harmful. Fortunately, Java on the Web is mostly extinct. Only a few outmoded sites still use it. Try to hasten the process of extinction by avoiding those sites, if you have a choice.
    Java is not included in OS X 10.7 and later. A separate Java installer is distributed by Apple, and another one by Oracle (the developer of Java.) Don't use either one unless you need it. Most people don't. If Java is installed, disable it — not JavaScript — in your browsers. In Safari, this is done by unchecking the box marked Enable Java in the Security tab of the preferences dialog.
    Regardless of version, experience has shown that Java on the Web can't be trusted. If you must use a Java applet for a specific task, enable Java only when needed for the task and disable it immediately when done. Close all other browser windows and tabs, and don't visit any other sites while Java is active. Never enable any version of Java on a public web page that carries third-party advertising. Use it, if at all, only on well-known, password-protected, secure business or government websites without ads. In Safari 6 or later, you'll see a lock icon in the address bar with the abbreviation "https" when visiting a secure site.
    Follow these guidelines, and you’ll be as safe from malware as you can reasonably be.
    6. Never install any commercial "anti-virus" or "Internet security" products for the Mac, as they all do more harm than good, if they do any good at all. If you need to be able to detect Windows malware in your files, use the free software ClamXav — nothing else.
    Why shouldn't you use commercial "anti-virus" products?
    Their design is predicated on the nonexistent threat that malware may be injected at any time, anywhere in the file system. Malware is downloaded from the network; it doesn't materialize from nowhere.
    In order to meet that nonexistent threat, the software modifies or duplicates low-level functions of the operating system, which is a waste of resources and a common cause of instability, bugs, and poor performance.
    By modifying the operating system, the software itself may create weaknesses that could be exploited by malware attackers.
    7. ClamXav doesn't have these drawbacks. That doesn't mean it's entirely safe. It may report email messages that have "phishing" links in the body, or Windows malware in attachments, as infected files, and offer to delete or move them. Doing so will corrupt the Mail database. The messages should be deleted from within the Mail application.
    ClamXav is not needed, and should not be relied upon, for protection against OS X malware. It's useful only for detecting Windows malware. Windows malware can't harm you directly (unless, of course, you use Windows.) Just don't pass it on to anyone else.
    A Windows malware attachment in email is usually easy to recognize. The file name will often be targeted at people who aren't very bright; for example:
    ♥♥♥♥♥♥♥♥♥♥♥♥♥♥!!!!!!!H0TBABEZ4U!!!!!!!.AVI♥♥♥♥♥♥♥♥♥♥♥♥♥♥.exe
    ClamXav may be able to tell you which particular virus or trojan it is, but do you care? In practice, there's seldom a reason to use ClamXav unless a network administrator requires you to run an anti-virus application.
    8. The greatest harm done by anti-virus software, in my opinion, is in its effect on human behavior. It does little or nothing to protect people from emerging threats, but they get a false sense of security from it, and then they may behave in ways that expose them to higher risk. Nothing can lessen the need for safe computing practices.
    9. It seems to be a common belief that the built-in Application Firewall acts as a barrier to infection, or prevents malware from functioning. It does neither. It blocks inbound connections to certain network services you're running, such as file sharing. It's disabled by default and you should leave it that way if you're behind a router on a private home or office network. Activate it only when you're on an untrusted network, for instance a public Wi-Fi hotspot, where you don't want to provide services. Disable any services you don't use in the Sharing preference pane. All are disabled by default.

  • Prelude software update caused Norton anti virus to remove file

    Hi,
    My version of prelude was updated today by the automatic software update system.
    During installation, my Norton 360 anti virus system identified the following file as a threat and removed it:
    Any one got any advice?
    thanks
    Chris Anderson
    Full Path: c:\program files (x86)\adobe\adobe prelude cs6\mc_enc_dv.dll
    Threat: Suspicious.Cloud.7.F
    On computers as of Not Available
    Last Used 28/05/2012 at 22:39:37
    Startup Item No
    Launched No
    Unknown
    Number of users in the Norton Community that have used this file: Unknown
    Unknown
    This file release is currently not known.
    High
    This file risk is high.
    Threat Details
    Threat type: Heuristic Virus. Detection of a threat based on malware heuristics.
    File Actions
    File: c:\program files (x86)\adobe\adobe prelude cs6\mc_enc_dv.dll
    Removed
    File Thumbprint - SHA:
    c100739136c152fe596a851635a0644c88daa231396bc29acb5b883f7029212c
    File Thumbprint - MD5:
    abf68500798f002d97a8e282ff3e7b2b

    HI Preran,
    Thanks for your reply, I have read the thread but I am confused!
    Is the anti virus situation effecting this prelude problem also???
    Prelude wont run because it is missing a file mc_enc_dv.dll
    If i reinstall to gfet this back, norton will only dump it again.
    Why is this happening on the latest adobe software update?
    I havent changed anything on my PC, installed softaere or codecs or anything, all I did was
    allow adobe to update
    I also have the probelm with Premiere loading taking 3 mins or so - is this related to the same issue?
    Help!
    Chris Anderson

  • I loaded software updates to Settings now my lock button won't work. I was told to do a restore but it keeps timing out. I disabled virus software which didn't help. How do I get it to restore?

    I loaded software updates to Settings and now my lock button won't work. I was told to do a Restore but it keeps timing out. It says it will take 58 minutes to do the restore. I disabled my virus software but that didn't help. Any suggestions so I can do a Restore?

    Try the Manual Install discussed here:
    iDevice Troubleshooting 101 :: iPhone, iPad, iPod touch

  • I am new to this forum. Just installed adobe iplayer for the numerous time. Then decided to have a software update immediately on my mac computer. Then a a small screen appeared afterwards stating the maleware virus was removed. What do I do now?

    Just installed adobe iplayer for the umpteeth time.
    Then decided to have a software update immediately on my mac.
    Then a small screen appeared afterwards stating maleware virus removed.
    What do I do now? Was not aware that I had a virus in the first place.

    That latest update is a removal tool for the Flashback trojan.
    One of the ways the earlier versions of that trojan were distributed was through fake Adobe Flash downloaders.
    Why are you repeatedly installing Adobe Flash Player? (not iPlayer - that's a BBC thing.)
    The only place from which to get the Flash Player plug-in is directly from Adobe themselves - Never Trust a Pop Up that says you have a missing plugin!
    Also be aware that the Flash Player is not a standalone player; it's a plug-in which installs in the Library and is available for all the browsers to use.
    As for what you do now?
    Nothing for the moment - you should be clear.
    But to be on the safe side, go to the Prefences for each of your browsers and disable Java (not JavaScript - that's a whole different animal). As Java is the vector used by the most recent versions, that should ensure you don't get reinfected.

  • Flashback malware removal tool? Recent Software Update

    Any knowledge of a Recent (4/13/12) Software Update?  (it says Flashback malware removal tool)

    Use Software Update. If you have Java installed then you will be able to download and install the update. Also, see:
    Helpful Links Regarding Flashback Trojan
    A link to a great User Tip about the trojan: Flashback Trojan User Tip
    A related link in the tip to a checker: Malware Checker Dowload Link
    Another excellent reference on malware: Mac Malware Guide
    A Google search can reveal a variety of alternatives on how the remove the trojan should your computer get infected. This can get you started.
    Checking for and removing the "Flashback" trojan
    Kaspersky Flashback Trojan Site:Flashback Trojan Detection and Removal
    F-Secure Tool: Flashback Removal Tool
    Also see Apple's article About Flashback malware.

  • I have a 6 yr old iMac, operating 10.5.8 OS "X".  Have not seen any software updates all 2013.  Might I have a virus?

    Every time I manually ask computer to go see if there is any new update after several seconds it will come back and say that I'm up to date. I am skeptical that I am up to date.  Is there a way of checking a log somewhere in the computer that will show me if indeed I''ve been taking software updates all 2013? 

    Start by checking if you can run Snow Leopard:
    Requirements for OS X 10.6 'Snow Leopard'
    http://support.apple.com/kb/SP575
    The OS 10.6 Snow Leopard install DVD is available for $19.99 from the Apple Store:
    http://store.apple.com/us/product/MC573/mac-os-x-106-snow-leopard
    and in the UK:
    http://store.apple.com/uk/product/MC573/mac-os-x-106-snow-leopard
    but nobody knows for how long it will be available.
    When you have installed it, run Software Update to download and install the latest updates for Snow Leopard to bring it up to 10.6.8, or download the combo update from here:
    http://support.apple.com/kb/DL1399
    Check via Software Update whether further updates are required.
    You should now see the App Store icon in iTunes, and you now need to set up your account:
    http://support.apple.com/kb/HT4479
    To use iCloud you have to upgrade at least to Lion, but some functions are only available in Mountain Lion:
    http://support.apple.com/kb/HT4759
    You can also purchase the code to use to download Lion (Lion requires an Intel-based Mac with a Core 2 Duo, i3, i5, i7 or Xeon processor and 2GB of RAM, running the latest version of Snow Leopard), or you can purchase Mountain Lion from the App Store - if you can run that:
    http://www.apple.com/osx/specs/

  • Is there a virus with the iTunes 11 update?

    A friend mentioned to me that there is a virus with the new iTunes update 11.1. Has anyone heard of this?

    Absolutely not.
    It's conceivable that there could be a site out there somewhere offering a fake iTunes update, but if so, I haven't heard of it. This would be security industry news if it was happening, and if anyone had seen it, and I follow just about every Mac-related security news source there is. So, while conceivable, this is highly unlikely, and has nothing to do with the official update available from Apple anyway.
    There have also been a number of reports I've seen where some Windows anti-virus software has been falsely identifying iTunes updates as malware. Perhaps that's what your friend is referring to.

  • How do I find and remove viruses, malware, etc. from my Macs?

    I have been plagued with pop-ups suggesting that I have a virus and need to call a certain number immediately.  Won't do that but need to know how to clean my Mac PowerBook and MacAir and am having trouble making a Genius Bar appointment.  Can anyone help?

    There is no need to download anything to solve this problem. You may have installed a variant of the "VSearch" ad-injection malware. Follow Apple Support's instructions to remove it.
    If you have trouble following those instructions, see below.
    Malware is always changing to get around the defenses against it. This procedure works as of now, as far as I know. It may not work in the future. Anyone finding this comment a few days or more after it was posted should look for a more recent discussion, or start a new one.
    The VSearch malware tries to hide itself by varying the names of the files it installs. To remove it, you must first identify the naming pattern.
    Triple-click the line below on this page to select it, then copy the text to the Clipboard by pressing the key combination  command-C:
    /Library/LaunchDaemons
    In the Finder, select
              Go ▹ Go to Folder...
    from the menu bar and paste into the box that opens by pressing command-V. You won't see what you pasted because a line break is included. Press return.
    A folder named "LaunchDaemons" may open. Look inside it for two files with names of the form
              com.something.daemon.plist
    and
               com.something.helper.plist
    Here something is a variable string of characters, which can be different in each case. So far it has always been a string of letters without punctuation, such as "cloud," "dot," "highway," "submarine," or "trusteddownloads." Sometimes it's a meaningless string such as "e8dec5ae7fc75c28" rather than a word. Sometimes the string is "apple," and then you must be especially careful not to delete the wrong files, because many built-in OS X files have similar names.
    If you find these files, leave the LaunchDaemons folder open, and open the following folder in the same way:
    /Library/LaunchAgents
    In this folder, there may be a file named
              com.something.agent.plist
    where the string something is the same as before.
    If you feel confident that you've identified the above files, back up all data, then drag just those three files—nothing else—to the Trash. You may be prompted for your administrator login password. Close the Finder windows and restart the computer.
    Don't delete the "LaunchAgents" or "LaunchDaemons" folder or anything else inside either one.
    The malware is now permanently inactivated, as long as you never reinstall it. You can stop here if you like, or you can remove two remaining components for the sake of completeness.
    Open this folder:
    /Library/Application Support
    If it has a subfolder named just
               something
    where something is the same string you saw before, drag that subfolder to the Trash and close the window.
    Don't delete the "Application Support" folder or anything else inside it.
    Finally, in this folder:
    /System/Library/Frameworks
    there may an item named exactly
                v.framework
    It's actually a folder, though it has a different icon than usual. This item always has the above name; it doesn't vary. Drag it to the Trash and close the window.
    Don't delete the "Frameworks" folder or anything else inside it.
    If you didn't find the files or you're not sure about the identification, post what you found.
    If in doubt, or if you have no backups, change nothing at all.
    The trouble may have started when you downloaded and ran an application called "MPlayerX." That's the name of a legitimate free movie player, but the name is also used fraudulently to distribute VSearch. If there is an item with that name in the Applications folder, delete it, and if you wish, replace it with the genuine article from mplayerx.org.
    This trojan is often found on illegal websites that traffic in pirated content such as movies. If you, or anyone else who uses the computer, visit such sites and follow prompts to install software, you can expect more of the same, and worse, to follow. Never install any software that you downloaded from a bittorrent, or that was downloaded by someone else from an unknown source.
    In the Security & Privacy pane of System Preferences, select the General tab. The radio button marked Anywhere  should not be selected. If it is, click the lock icon to unlock the settings, then select one of the other buttons. After that, don't ignore a warning that you are about to run or install an application from an unknown developer.
    Then, still in System Preferences, open the App Store or Software Update pane and check the box marked
              Install system data files and security updates (OS X 10.10 or later)
    or
              Download updates automatically (OS X 10.9 or earlier)
    if it's not already checked.

  • How can I stop the software updater pop ups advising me to update to 11.0.03?

    Can anyone help with how to stop the software updater pop ups advising me to update to Reader 11.0.03? My antivirus advises the link in the pop up is unsafe, so I went to the Adobe website to update from Reader 9. The website doesn't offer X1, but did offer X, so I updated to 10.1.7.
    Why is the site not offering a download for X1?
    Even though I have updated to X I am still getting the pop ups for X1. I have attached a screen shot of the pop up - is this legitimate or some kind of scam carrying a virus?
    Thanks.

    There are literally thousands of sites with videos (linked to from yet thousands more) that will prompt you to "upgrade" or update your already updated Flash Player. This is the most common method of delivery for malware like that.
    A friend who runs a PC Repair business told me that if you've updated your Flash Player and you see a warning in a web page that you need to download an update to watch a video, it's an attack site.
    A simple gesture of holding your mouse over the warning or link, will indicate the address it points to. If it DOESN'T say Adobe anywhere in the beginning of the address (download.adobe.com, or adobe.com/downloads), it's a forgery, and you should leave that page immedaitely. If you download and install whatever they link you to, it may play the content you were looking for, but you've just been infected with something that may lay dormant for months and then suddenly take over your whole system.
    If you use your PC for work, you're really in trouble.

  • Can't open iTunes any more?! (after software update)

    After the last software update I can't open iTunes any more. Error message: "you can't open the application itunes because it is not supported on this type of mac". how is that possible? does the system really update to a itunes version, I can't run? how stupid is that?
    thanks!

    I think what you are saing is that you have error message free launch failure with iTunes.exe persisting on the processes tab .
    If so this is commonly due to a problem with cryptographic services. Here is a diagnostic Method for working out the problem:
    Before checking if iTunes works, restart your PC or close the iTunes.exe process with task manager if it is running.
    A couple of simple things to try:
    http://support.apple.com/kb/TS1776?viewlocale=en_US
    Stop the bonjour service, this FAQ has instructions:
    http://support.apple.com/kb/HT2250?viewlocale=en_US
    But usually it is due to a problem with cryptographic services.
    Check to see if you have your smart card service and that it is not set to disabled. For some reason iTunes needs it.
    Start>>Run>>Services.msc
    you should find the smart card service in the list. Report back with your findings.
    Malware can interfere with cryptographic services and also prevent a resolution so it is important to check that your system is clean before proceeding: Run a virus and spyware scan with up to date definitions.
    Then work through *Method 4* in the following link:
    http://support.microsoft.com/kb/822798
    You should be able to copy and paste the individual lines to save on typing.
    Make a careful note of any error messages you get, they are important for diagnosis. Report back any error messages especially the names of any dlls mentioned.
    If there are no errors try starting iTunes.

  • How do I identify get rid of virus/malware/something bad?

    How do I know what has gotten into my computer, and how do I get rid of it?  Got little weird pop-up messages that said if it showed up several more times, it meant my "PC" was infected with a virus.   I tried to close it out and it wouldn't let me.  I tried to Force Quit things, and at some point it threw a bigger window up on the screen, and right on top of that came a photo of a girl in a bikini asking me when I wanted to eff someone. 
    Using Mavericks 10.9.5.   Have just installed and run a Norton anti-virus program, which said I have no viruses.  I realize that isn't the best software around, but it's free from Comcast and the first thing I could do.   I haven't had anything like this happen since I was on a PC
    I was getting close to paying bills online, which clearly isn't the thing to do now.   What are my options as a low-tech user, and what are my official Apple options?  Past Apple Care coverage date.   Tried to call to find options through them, was told there was a long hold time, then got disconnected. 

    If you saw a fake alert that "suspicious activity might have been detected," take Step B. Otherwise, take Step A when needed. In either case, remove the worthless Norton product according to the developer's instructions.
    A
    It's not malware. It's a JavaScript scam that only affects your web browser, and only temporarily. There are several ways to recover.
    1. Some of those scam pages can be dismissed very easily. Press the key combination command-W to close the tab or window. A huge box will pop up. Press the return key and both the box and the page will close. If that doesn't happen, continue.
    2. Press and hold command-W. You may hear repeating alert sounds. While holding the keys, click the OK button in the popup. A different popup may appear, which you can cancel out of as usual.
    3. From the Safari menu bar, select
              Safari ▹ Preferences... ▹ Security
    and uncheck the box marked Enable JavaScript. Leave the preferences dialog open.
    Close the malicious window or tab.
    Re-enable JavaScript and close the preferences dialog.
    4. If the Preferences menu item is grayed out, quit Safari. Force quit if necessary. Relaunch it by holding down the shift key and clicking its icon in the Dock. None of the windows and tabs will reopen.
    After closing the malicious page, from the menu bar, select
              Safari ▹ Preferences... ▹ Privacy ▹ Remove All Website Data
    to get rid of any cookies or other data left by the server. Open your Downloads folder and delete anything you don't recognize.
    B
    You may have installed the "Downlite" or "VSearch" ad-injection malware. Follow the instructions on this Apple Support page to remove it.
    Back up all data before making any changes.
    Besides the files listed in the support article, you may also need to remove this item in the same way:
    ~/Library/Internet Plug-Ins/ConduitNPAPIPlugin.plugin
    One of the steps in the article is to remove malicious Safari extensions. Do the equivalent in the Chrome and Firefox browsers, if you use either of those. If Safari crashes on launch, skip that step and come back to it after you've done everything else.
    If you don't find any of the files or extensions listed, or if removing them doesn't stop the ad injection, then you may have one of the other kinds of adware covered by the support article. Follow the rest of the instructions in the article.
    The problem may have started when you downloaded and ran an application called "MPlayerX." That's the name of a legitimate free movie player, but the name is also used fraudulently to distribute VSearch. If there is an item with that name in the Applications folder, delete it, and if you wish, replace it with the genuine article from mplayerx.org.
    This malware is often found on illegal websites that traffic in pirated content such as movies. If you, or anyone else who uses the computer, visit such sites and follow prompts to install software, you can expect more of the same, and worse, to follow. Never install any software that you downloaded from a bittorrent, or that was downloaded by someone else from an unknown source.
    In the Security & Privacy pane of System Preferences, select the General tab. The radio button marked Anywhere  should not be selected. If it is, click the lock icon to unlock the settings, then select one of the other buttons. After that, don't ignore a warning that you are about to run or install an application from an unknown developer.
    Still in System Preferences, open the App Store or Software Update pane and check the box marked
              Install system data files and security updates
    if it's not already checked.

  • Way weird behavior since last software update...

    I have had my machine 3years and never experienced issues like this... First of all I just had to re-set my password to get in here... The secret question I set for myself was not the one I set for myself... Dig? nor was it my mac.com address in the window when it came time for me to have it emailed... Second time I have had to reset my password in 72hrs... Mail has gone nutz too! deleted mail reappears... drafts multiply then dont go away after being sent... mail moved to created folders shows back up in inbox... Then acts like its sending when there is nothing in drafts or outbox... Almost always have to force quit... All of this started about a week ago with latest software update... Checked permissions... ran thru disk utility... gettin more nutty every 6-8 hours..***???

    I am having very similar difficulties. Is this a symptom of the dreaded virus or malware attacks I have heard of. Anyone with insight please help. My Mail is completely useless in this state.

  • HT5228 Java patch not in software update

    This Java patch does not appear when I click on software update. It isn't on my list of recent updates either. Could the virus block the patch? My email account was attacked on Wednesday so I assume my laptop is infected.

    Briar7 wrote:
    This Java patch does not appear when I click on software update. It isn't on my list of recent updates either. Could the virus block the patch?
    It is more likely that you don't even have Java installed.
    Go to: http://www.java.com/en/download/testjava.jsp
    If you don't see anything that looks like this:
    then you don't have Java and you are fine.
    My email account was attacked on Wednesday so I assume my laptop is infected.
    In what way? Usually people just mistake forged return addresses for some kind of malware infection. A forged return address is just standard SPAM behaviour. It is fairly common for people to use easy-to-guess password on web-based e-mail systems like gmail and get their e-mail account hacked. That has nothing to do with your laptop.

Maybe you are looking for

  • Hiding a form card layout

    Hey folks i have the code below, its an example that i have been messing around with. I have a on the first card button 2 which has an action listener on, it simply opens another formwhich it does correct but i want the form with the card layout on i

  • Should i get the current MacBook Pro or the new design MacBook pro 2012?

    Dear all, GImme some opinions which to choose? Should i wait for the supposedly new design MacBook Pro? or get the current models that hae pretty good specs? I'm doing college at the moment and my current laptop is 4yrs old in need of a new one and h

  • Linking python and Java

    Hello there. im in need of a little help. I about to embark on a project where I have a cad program that has a built in python api, so the user can write a script and automate running a series of simulations in the program. My project is to write an

  • Oracle pl/sql ??

    i am trying to get working that block but i am getting errors ora-01422 ora-06512 can someone run that and see what mistake i am making. rem create salesman table create table SALESMAN ( Sid char(4), name char(10), yrs number(4), base number(7), sale

  • Error:1 duplicate record found. 0 recordings used in table /BI0/XBPARTNER

    Hei everyone I get an error of duplicate data records when trying to load masterdata to InfoObject. I've tried to load to PSA  and then to InfoObject. In PSA it doesn't show any errors but when loading to infoobject it again gets an error. I've also