Prevent infiltration of unwanted apps promoted via the Falseortruerdr scam web page
Written by Tomas Meskauskas on
(updated)
How not to become a victim of falseortruerdr scam?
What is falseortruerdr?
Scammers use the falseortruerdr web page to promote an unwanted application called Smart Mac Booster. Note that falseorrealrdr is a scam site used to trick people into believing that their computers are infected with a virus that can be removed using the aforementioned application. Do not trust this or other similar web pages (or download software from them). These sites are opened by PUAs (potentially unwanted applications) that users install on their browsers or operating systems (often, unintentionally).
Once opened, this page displays a pop-up stating that another website (visited earlier) has infected the Mac with a virus. The pop-up encourages visitors to begin the repair process. When closed, falseorrealrdr displays a table containing information regarding the 'infected device' and encourages users to scan their systems by clicking the "Scan Now" button. If clicked, this opens another table with the name of the detected virus ("Bankworm"), risk level, and name of the infected file ("/os/apps/worm.icv"). It suggests that users download this virus with the Advanced Mac Cleaner app, however, the "REMOVE VIRUS NOW" button opens a dubious web page used to advertise Smart Mac Booster. Do not trust software advertised through deceptive, scam web pages. Ignore these sites and do not trust them - claims about detected viruses or other threats are false.
Scam sites such as this are often opened by PUAs, however, these apps usually display ads and gather data. They feed users with coupons, banners, surveys, pop-ups, and other intrusive ads. People who click them are redirected to dubious sites or the ads run scripts that start downloading or even installing other PUAs. Additionally, unwanted apps collect data such as IP addresses, geolocations, entered search queries, addresses of opened/visited websites, and so on. Developers share this information with other parties (potentially, cyber criminals) who misuse it to generate revenue.
Name | falseortruerdr pop-up |
Threat Type | Mac malware, Mac virus |
Fake Claim | This scam page claims that the computer is infected with a virus. |
Promoted Unwanted Application | Smart Mac Booster |
Related Domain | reward7533.falseortruerdr56[.]life |
Serving IP Address (reward7533.falseortruerdr56[.]life) | 79.110.23.105 |
Detection Names (reward7533.falseortruerdr56[.]life) | Fortinet (Spam), Spamhaus (Spam), Full List Of Detections (VirusTotal) |
Symptoms | Your Mac becomes slower than normal, you see unwanted pop-up ads, you are redirected to dubious websites. |
Distribution methods | Deceptive pop-up ads, free software installers (bundling), fake flash player installers, torrent file downloads. |
Damage | Internet browser tracking (potential privacy issues), display of unwanted ads, redirects to dubious websites, loss of private information. |
Malware Removal (Mac) | To eliminate possible malware infections, scan your Mac with legitimate antivirus software. Our security researchers recommend using Combo Cleaner. |
The falseortruerdr scam is similar to fastsearchday, apple.com-scan-mac[.]live, apple.com-shield[.]live, and many others. Typically, scammers use these sites to advertise unwanted applications (such as Smart Mac Booster). These pages display fake notifications about detected viruses and encourage people to remove them using other software immediately. The PUAs that open these web pages are also very similar. Developers present them as legitimate and harmless apps, however, they often force people to visit dubious sites, see unwanted ads, and are used to gather data.
How did potentially unwanted applications install on my computer?
Most people download and install PUAs unintentionally. Typically, this happens when they download and install other programs that have PUAs included in the set-ups. Information relating to this is usually found in setup options such as "Custom", "Advanced", and so on. Not all people check these settings, thus allowing unwanted programs to be downloaded and installed with the chosen software. In other cases, unexpected downloads and installations happen when people click deceptive advertisements. If clicked, some ads run scripts designed to download and install unwanted software, or they lead to sites that trick people into this situation.
How to avoid installation of potentially unwanted applications?
It is not safe to download files or software using third party downloaders, unofficial (dubious) websites, Peer-to-Peer networks such as eMule, torrent clients, and so on. The best way is to use official sites and direct download links. Do not skip download or installation set-ups without checking "Custom", "Advanced" settings and deselecting offers to download or install unwanted software. Install software though third party installers. Note that intrusive ads should not be trusted or clicked, especially if shown on dubious websites. They can open untrustworthy (potentially malicious) web pages or cause unwanted downloads and installations. Browsers often display ads or open dubious sites when they are infiltrated with unwanted extensions, add-ons, or plug-ins. If there are apps of this kind installed on your browser or computer, remove them immediately. If your computer is already infected with PUAs, we recommend running a scan with Combo Cleaner Antivirus for macOS to automatically eliminate them.
Text presented in the first pop-up window:
VIRUS FOUND
A website you visited today has infected your Mac with a virus.
Press OK to begin the repair process.
Screenshot of a table displayed by falseortruerdr:
Text presented in it:
VIRUS FOUND
A website you have visited today has infected your Mac with a virus. A full system scan is now required to find and remove harmful files or applications from your Mac OS X 10_14_3 device.
DEVICE INFORMATION
Brand: Apple
Device: Mac OS X 10_14_3
Browser: Safari 12.0.3
IP: -
Provider: -
Location: -
Scan Now
Falseortruerdr encourages users to download unwanted software:
Text in this page:
DOWNLOAD REQUIRED
Please download the Advanced Mac Cleaner application to remove Bankworm from your Mac.
VIRUS INFORMATION
Virus Name: Bankworm
Risk: HIGH
Infected File: /os/apps/worm.icv
VIRUS REMOVAL
Application: Advanced Mac Cleaner
Rating: 9.9/10
Price: Free
REMOVE VIRUS NOW
Smart Mac Booster download page:
Smart Mac Booster app:
Instant automatic Mac malware removal:
Manual threat removal might be a lengthy and complicated process that requires advanced computer skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of Mac malware. Download it by clicking the button below:
▼ DOWNLOAD Combo Cleaner for Mac
By downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. To use full-featured product, you have to purchase a license for Combo Cleaner. Limited three days free trial available.
Quick menu:
- What is falseortruerdr?
- STEP 1. Remove PUA related files and folders from OSX.
- STEP 2. Remove rogue extensions from Safari.
- STEP 3. Remove rogue add-ons from Google Chrome.
- STEP 4. Remove potentially unwanted plug-ins from Mozilla Firefox.
Video showing how to remove unwanted applications promoted through Falseortruerdr pop-up scam using Combo Cleaner:
Potentially unwanted applications removal:
Remove potentially unwanted applications from your "Applications" folder:
Click the Finder icon. In the Finder window, select "Applications". In the applications folder, look for "MPlayerX", "NicePlayer", or other suspicious applications and drag them to the Trash. After removing the potentially unwanted application(s) that cause online ads, scan your Mac for any remaining unwanted components.
Remove falseortruerdr pop-up related files and folders:
Click the Finder icon, from the menu bar. Choose Go, and click Go to Folder...
Check for adware-generated files in the /Library/LaunchAgents folder:
In the Go to Folder... bar, type: /Library/LaunchAgents
In the “LaunchAgents” folder, look for any recently-added suspicious files and move them to the Trash. Examples of files generated by adware - “installmac.AppRemoval.plist”, “myppes.download.plist”, “mykotlerino.ltvbit.plist”, “kuklorest.update.plist”, etc. Adware commonly installs several files with the same string.
Check for adware generated files in the /Library/Application Support folder:
In the Go to Folder... bar, type: /Library/Application Support
In the “Application Support” folder, look for any recently-added suspicious folders. For example, “MplayerX” or “NicePlayer”, and move these folders to the Trash.
Check for adware-generated files in the ~/Library/LaunchAgents folder:
In the Go to Folder bar, type: ~/Library/LaunchAgents
In the “LaunchAgents” folder, look for any recently-added suspicious files and move them to the Trash. Examples of files generated by adware - “installmac.AppRemoval.plist”, “myppes.download.plist”, “mykotlerino.ltvbit.plist”, “kuklorest.update.plist”, etc. Adware commonly installs several files with the same string.
Check for adware-generated files in the /Library/LaunchDaemons folder:
In the Go to Folder... bar, type: /Library/LaunchDaemons
In the “LaunchDaemons” folder, look for recently-added suspicious files. For example “com.aoudad.net-preferences.plist”, “com.myppes.net-preferences.plist”, "com.kuklorest.net-preferences.plist”, “com.avickUpd.plist”, etc., and move them to the Trash.
Scan your Mac with Combo Cleaner:
If you have followed all the steps in the correct order you Mac should be clean of infections. To be sure your system is not infected run a scan with Combo Cleaner Antivirus. Download it HERE. After downloading the file double click combocleaner.dmg installer, in the opened window drag and drop Combo Cleaner icon on top of the Applications icon. Now open your launchpad and click on the Combo Cleaner icon. Wait until Combo Cleaner updates it's virus definition database and click "Start Combo Scan" button.
Combo Cleaner will scan your Mac for malware infections. If the antivirus scan displays "no threats found" - this means that you can continue with the removal guide, otherwise it's recommended to remove any found infections before continuing.
After removing files and folders generated by the adware, continue to remove rogue extensions from your Internet browsers.
falseortruerdr pop-up removal from Internet browsers:
Remove malicious extensions from Safari:
Remove falseortruerdr pop-up related Safari extensions:
Open Safari browser, from the menu bar, select "Safari" and click "Preferences...".
In the preferences window, select "Extensions" and look for any recently-installed suspicious extensions. When located, click the "Uninstall" button next to it/them. Note that you can safely uninstall all extensions from your Safari browser - none are crucial for normal browser operation.
- If you continue to have problems with browser redirects and unwanted advertisements - Reset Safari.
Remove malicious plug-ins from Mozilla Firefox:
Remove falseortruerdr pop-up related Mozilla Firefox add-ons:
Open your Mozilla Firefox browser. At the top right corner of the screen, click the "Open Menu" (three horizontal lines) button. From the opened menu, choose "Add-ons".
Choose the "Extensions" tab and look for any recently-installed suspicious add-ons. When located, click the "Remove" button next to it/them. Note that you can safely uninstall all extensions from your Mozilla Firefox browser - none are crucial for normal browser operation.
- If you continue to have problems with browser redirects and unwanted advertisements - Reset Mozilla Firefox.
Remove malicious extensions from Google Chrome:
Remove falseortruerdr pop-up related Google Chrome add-ons:
Open Google Chrome and click the "Chrome menu" (three horizontal lines) button located in the top-right corner of the browser window. From the drop-down menu, choose "More Tools" and select "Extensions".
In the "Extensions" window, look for any recently-installed suspicious add-ons. When located, click the "Trash" button next to it/them. Note that you can safely uninstall all extensions from your Google Chrome browser - none are crucial for normal browser operation.
- If you continue to have problems with browser redirects and unwanted advertisements - Reset Google Chrome.
Click to post a comment