Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

Edgar Spayce

macrumors regular
Original poster
Jun 2, 2015
204
149
Hi, so I've been using Macs for 15 years and never have I ever had any Windows-like virus, the kind that get deep into your system without you knowing, is hard to remove and can ****-up your computer.

Yesterday my browsers (all of them) started acting weird: every link I clicked was highjacked by adware, especially an "Iphone for 1$/€ by RockyFrogger" scam was popping-up.

When I looked it up I found very little information, until I stumble on someone who knew exactly what it was: apparently this not a regular adware but a very dangerous IRP Hook, that can modify the kernel, make your computer vulnerable and steal your data.

So I'm searching for solutions, I haven't updated to 10.10.5 yet, but I suspect this sudden and urgent update might be a fix to that (given that apparently it installs itself through DNS vulnerabilities), but I'm not sure it fixes that, and so far I've found to tool to remove it.

Any solutions?
 
Yesterday my browsers (all of them) started acting weird: every link I clicked was highjacked by adware, especially an "Iphone for 1$/€ by RockyFrogger" scam was popping-up.
There's no evidence that this is anything more than a simple browser extension.
Have you run any sort of malware detection?
 
There's no evidence that this is anything more than a simple browser extension.
Have you run any sort of malware detection?

Yes, and I have deactivated all my extensions. I prefer to trust the guy who seems to knew his topic, on this scam that may have not hit lots of people yet.
 
Where are the links to this, then?

This is very recent so I haven't found much information but this article http://www.lefigaro.fr/secteur/high...ux-fausses-promos-qui-peuvent-couter-cher.php

And if you look in the comment someones rightfully describes the symptoms and solutions. Two of my friends have the same problems.

But for it seems to have stopped, and I don't know how. So it might not be a trojan virus although apparently it was describe as a particular one, and I did witness it and couldn't stop it from happening no matter what I did on my browsers.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.