How to remove the OSAMiner malware from the operating system?
Written by Tomas Meskauskas on
(updated)
How to remove OSAMiner from Mac?
What is OSAMiner?
OSAMiner is the name of a cryptocurrency miner, Monero mining trojan that uses run-only AppleScripts (it targets Mac computers). It is known that OSAMiner was first detected in 2015 and is still successfully used by cyber criminals due to its complex structure (use of run-only AppleScript files) that prevents researchers from fully analyzing it so the attacks could be stopped.
Research shows that OSAMiner embeds one run-only AppleScript inside another and uses the addresses in public websites to download an open-source Monero miner called XMR-STAK-RX – Free Monero RandomX Miner. It is known that OSAMiner setup script uses a tool that prevents the infected computer from entering sleep mode. Also, the script is designed to kill running processes belonging to certain popular system monitoring and cleaning tools. Symptoms of having OSAMiner installed on macOS are system freezes, problems with opening the Activity Monitor (Activity Monitor.app) and higher CPU usage.
Name | OSAMiner mining trojan |
Threat Type | Cryptocurrency Miner |
Detection Names | Avast (MacOS:Agent-JE [Trj]), AVG (MacOS:Agent-JE [Trj]), ESET-NOD32 (OSX/OSAMiner.C), Kaspersky (HEUR:Trojan-Downloader.OSX.Chiner.a), Full List (VirusTotal) |
Symptoms | Higher CPU usage, system freezes, problems with accessing/using Activity Monitor |
Distribution methods | Pirated copies of games and software (like Micrisoft Office, League of Legends) |
Damage | Higher electricity bills, loss of unsaved data, hardware overhear, decrease in computer performance |
Malware Removal (Mac) | To eliminate possible malware infections, scan your Mac with legitimate antivirus software. Our security researchers recommend using Combo Cleaner. |
In conclusion, cyber criminals distribute OSAMiner with a purpose to mine Monero cryptocurrency using victim's computer resources/hardware. What makes OSAMiner different from other miners is that it targets Mac users and is very difficult to detect and analyze. A couple of other cryptocurrency mining malware examples are Bird Miner and LoudMiner.
How did malware install on my computer?
Research shows that OSAMiner is distributed via pirated copies of various software and games like, for example, League of Legends and Microsoft Office. It is worthwhile to mention that malware can be distributed via malspam emails (via attachments or links in emails), fake software updating tools, third party installers, unreliable file, software download sources, and certain Trojans as well. Some examples of types of files that cyber criminals send via email are MS Office documents, JavaScript files, archive files, PDF documents and executable files. Examples of unreliable file, software download sources are unofficial pages, freeware download sites, free file hosting web pages, third party downloaders, Peer-to-Peer networks (like torrent clients, eMule).
How to avoid installation of malware?
Software and files should not be downloaded (or installed) via third party downloaders (or installers), Peer-to-Peer networks, from unofficial sites, etc. They should be downloaded only from official pages and via direct links. Attachments and website links in irrelevant emails that are sent from unknown, suspicious addresses should not be opened as well. Usually such emails are disguised as important, official and contain some malicious link or attachment When installed software needs to be updated and/or activated software, it should be done by using tools that are provided/designed by official developers. Third party activation, updating tools should never be used, it is common for them to be designed to install malware. Moreover, it is not legal to use such tools for activation of any licensed software, neither it is legal to use pirated copies of software. The operating system should be scanned for threats regularly, it is advised to do it with a reputable antivirus or anti-spyware suite and keep that suite up to date. If your computer is already infected with malware or unwanted software of other type, we recommend running a scan with Combo Cleaner Antivirus for macOS to automatically eliminate them.
Pop-up that appears once the malicious installer for pirated copy of League of Legends is executed:
Instant automatic Mac malware removal:
Manual threat removal might be a lengthy and complicated process that requires advanced computer skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of Mac malware. Download it by clicking the button below:
▼ DOWNLOAD Combo Cleaner for Mac
By downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. To use full-featured product, you have to purchase a license for Combo Cleaner. Limited three days free trial available.
Quick menu:
- What is OSAMiner?
- STEP 1. Remove PUA related files and folders from OSX.
- STEP 2. Remove rogue extensions from Safari.
- STEP 3. Remove rogue add-ons from Google Chrome.
- STEP 4. Remove potentially unwanted plug-ins from Mozilla Firefox.
Video showing how to remove adware and browser hijackers from a Mac computer:
Potentially unwanted applications removal:
Remove potentially unwanted applications from your "Applications" folder:
Click the Finder icon. In the Finder window, select "Applications". In the applications folder, look for "MPlayerX", "NicePlayer", or other suspicious applications and drag them to the Trash. After removing the potentially unwanted application(s) that cause online ads, scan your Mac for any remaining unwanted components.
Remove osaminer mining trojan related files and folders:
Click the Finder icon, from the menu bar. Choose Go, and click Go to Folder...
Check for adware-generated files in the /Library/LaunchAgents folder:
In the Go to Folder... bar, type: /Library/LaunchAgents
In the “LaunchAgents” folder, look for any recently-added suspicious files and move them to the Trash. Examples of files generated by adware - “installmac.AppRemoval.plist”, “myppes.download.plist”, “mykotlerino.ltvbit.plist”, “kuklorest.update.plist”, etc. Adware commonly installs several files with the same string.
Check for adware generated files in the /Library/Application Support folder:
In the Go to Folder... bar, type: /Library/Application Support
In the “Application Support” folder, look for any recently-added suspicious folders. For example, “MplayerX” or “NicePlayer”, and move these folders to the Trash.
Check for adware-generated files in the ~/Library/LaunchAgents folder:
In the Go to Folder bar, type: ~/Library/LaunchAgents
In the “LaunchAgents” folder, look for any recently-added suspicious files and move them to the Trash. Examples of files generated by adware - “installmac.AppRemoval.plist”, “myppes.download.plist”, “mykotlerino.ltvbit.plist”, “kuklorest.update.plist”, etc. Adware commonly installs several files with the same string.
Check for adware-generated files in the /Library/LaunchDaemons folder:
In the Go to Folder... bar, type: /Library/LaunchDaemons
In the “LaunchDaemons” folder, look for recently-added suspicious files. For example “com.aoudad.net-preferences.plist”, “com.myppes.net-preferences.plist”, "com.kuklorest.net-preferences.plist”, “com.avickUpd.plist”, etc., and move them to the Trash.
Scan your Mac with Combo Cleaner:
If you have followed all the steps in the correct order you Mac should be clean of infections. To be sure your system is not infected run a scan with Combo Cleaner Antivirus. Download it HERE. After downloading the file double click combocleaner.dmg installer, in the opened window drag and drop Combo Cleaner icon on top of the Applications icon. Now open your launchpad and click on the Combo Cleaner icon. Wait until Combo Cleaner updates it's virus definition database and click "Start Combo Scan" button.
Combo Cleaner will scan your Mac for malware infections. If the antivirus scan displays "no threats found" - this means that you can continue with the removal guide, otherwise it's recommended to remove any found infections before continuing.
After removing files and folders generated by the adware, continue to remove rogue extensions from your Internet browsers.
OSAMiner mining trojan removal from Internet browsers:
Remove malicious extensions from Safari:
Remove osaminer mining trojan related Safari extensions:
Open Safari browser, from the menu bar, select "Safari" and click "Preferences...".
In the preferences window, select "Extensions" and look for any recently-installed suspicious extensions. When located, click the "Uninstall" button next to it/them. Note that you can safely uninstall all extensions from your Safari browser - none are crucial for normal browser operation.
- If you continue to have problems with browser redirects and unwanted advertisements - Reset Safari.
Remove malicious plug-ins from Mozilla Firefox:
Remove osaminer mining trojan related Mozilla Firefox add-ons:
Open your Mozilla Firefox browser. At the top right corner of the screen, click the "Open Menu" (three horizontal lines) button. From the opened menu, choose "Add-ons".
Choose the "Extensions" tab and look for any recently-installed suspicious add-ons. When located, click the "Remove" button next to it/them. Note that you can safely uninstall all extensions from your Mozilla Firefox browser - none are crucial for normal browser operation.
- If you continue to have problems with browser redirects and unwanted advertisements - Reset Mozilla Firefox.
Remove malicious extensions from Google Chrome:
Remove osaminer mining trojan related Google Chrome add-ons:
Open Google Chrome and click the "Chrome menu" (three horizontal lines) button located in the top-right corner of the browser window. From the drop-down menu, choose "More Tools" and select "Extensions".
In the "Extensions" window, look for any recently-installed suspicious add-ons. When located, click the "Trash" button next to it/them. Note that you can safely uninstall all extensions from your Google Chrome browser - none are crucial for normal browser operation.
- If you continue to have problems with browser redirects and unwanted advertisements - Reset Google Chrome.
Click to post a comment