Sample Header Ad - 728x90

Adware file in /var/root/

1 vote
1 answer
947 views
My MacBook Pro has had a common adware virus on it ExploreSearchResults. I have already gone through all of my extensions and deleted anything related. Anything in the Applications folder that did not belong has been deleted. I also know this virus is common through fake flash player updates so I went through and deleted all of them. I also went through these folders and deleted anything suspicious or included the ExploreSearchResults name
/Users/Shared/
/Library/LaunchDaemons/
~/Library/LaunchAgents/
/Library/LaunchAgents/
I then shutdown the computer and restarted in Safe mode. I ran the activity monitor and found both ExploreSearchResults and ExploreSearchResultsDaemon running. When I force quit both they would reappear so I ran a sample to find the parent folder /Private/var/root/.ExploreSearchResults. I then ran a sudo ls -l /var/root command in Terminal to find this list of files.
total 8  
-rw-r--r--   1 root  wheel    3 Mar 29  2014 .CFUserTextEncoding   
drwxr-xr-x   6 root  wheel  192 Jan  6 05:46 .ExploreSearchResults  
drwx------  24 root  wheel  768 Jan  6 04:02 .Trash  
-r--r--r--   1 root  wheel   10 Sep  9  2014 .forward  
drwxr-xr-x   8 root  wheel  256 Dec 26 13:52 .mitmproxy  
drwxr-xr-x   3 root  wheel   96 Jun 26  2019 .oracle_jre_usage  
drwx------  17 root  wheel  544 Apr 21  2020 Library
Three questions here first is can I safely delete the .ExploreSearchResults file with sudo rm /var/root/.ExploreSearchResults command? The second question is that is this the origin of this adware virus or could it be hidden elsewhere? Last question are all the other files in the root folder safe a supposed to be there? I know that the root folder is extremely important to the system so I am treading lightly while accessing this folder I know MacOS blocks access from it for a reason. sw_vers ProductName: Mac OS X ProductVersion: 10.14.6 BuildVersion: 18G5033
Asked by Will K (11 rep)
Jan 6, 2022, 11:56 AM
Last activity: Feb 5, 2022, 04:02 PM