Skip to content
  • Active
  • Severity: Medium
  • Adware
  • Mac
  • Verified · Sep 2020

How to remove ExploreParameter

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Ugnius Kiguolis · The mastermind

ExploreParameter is a potentially unwanted program with plenty of malicious features

ExploreParameter

ExploreParameter is a type of computer infection that targets Mac computers exclusively and is spread via illegal software installers or fake Flash Player updates. Upon infiltration, the app installs a browser extension on Google Chrome, Safari, or Mozilla Firefox browser, and changes the homepage address to 0yrvtrh.com, search.adjustablesample.com, or another one. After that, the PUP begins intrusive advertisement campaigns: pop-ups, offers, deals, coupons, banners, and other forms of ads are a common sight on the infected users' web browsers. 

However, intrusive ads are just a surface of what the ExploreParameter virus is capable of. In the background, the application drops several items on the macOS (such as Login Items and malicious Profiles) for persistence, so the infected users are not able to remove ExploreParameter in a regular way. This also applies to the extension that changes web browser settings – users are unable to uninstall it and are forced to browse via the hijacked search engine instead.

Name ExploreParameter
Type Mac malware, adware, browser hijacker
Family Adload
Distribution Potentially unwanted programs belonging to this adware family are most commonly installed via fake Flash Player update prompts and pirated software installers 
Symptoms Unknown browser extensions installed on Safari, Google Chrome, or Mozilla Firefox browsers; homepage and new tab address set to 0yrvtrh.com or search.adjustablesample.com; all searches are redirected to Search Finder or another untrustworthy search engine; increased number of advertisements, etc.
Dangers Installation of other dangerous software, personal data disclosure to cybercriminals, identity theft, monetary losses 
Elimination You can delete malware with the help of powerful anti-malware software, such as SpyHunterCombo Cleaner or MalwarebytesMalwarebytes, although we also provide manual removal guide below 
Optimization If you machine suffers from lag or other performance issues, we recommend using FortectIntego after the virus is eliminated from the system 

Adware has become a huge problem for Apple, as more and more Mac users are getting infected every day. According to a research publication back in January 2020, the rate at which malware is produced for macOS outpaced Windows machines and jumped up by 400% on a year-over-year basis.[1] Threats like Bundlore, Slayer Trojan, CrescentCore, and many others, are now often encountered on users' machines.

The presence of ExploreParameter might, unfortunately, mean that other malicious programs are installed on the machine. Developers of this deceptive programs use deceptive methods for their propagation, some of which include:

  • Fake Flash Player installers and fake updates
  • Software bundles
  • Pirated software installers downloaded from torrent sites
  • Fake virus infection notifications.

ExploreParameter belongs to a broad adware family known as Adload – it exploits the built-in AppleScript in order to establish persistence mechanisms and install the extension with elevated privileges. This campaign is quite prevalent, and new versions emerge on a regular basis – ArchimedesLookup, BufferKey, AccessibleBoost, and PracticalProcesser are just a few examples spreading in the wild.

All of these apps, including the ExploreParameter, use a distinctive icon that incorporates a magnifying glass and a teal or green circle round it. Nonetheless, distribution and operation principles remain the same – intrusive ads, unexpected browser changes, unknown extensions, and ExploreParameter removal problems.

The adware campaign is so intrusive and extensive that the potentially unwanted application is flagged as a virus by many security applications. According to Virus Total, the installer is detected under the following names:

  • Adware.MAC.AdLoad.XF
  • OSX.Trojan.Gen
  • A Variant Of OSX/Adware.Synataeb.C
  • Adware/Adload!OSX
  • ADWARE/OSX.Synataeb.ejnsf
  • PUA:MacOS/Bitrepeyp.B, etc.

ExploreParameter virus

Another reason why the ExploreParameter malware is dangerous is that the attached extension can often be installed with elevated privileges, thanks to the AppleScript abuse. If you open the web browser and find the add-on installed, you could see the following notification:

Permissions for “ExploreParameter”

Webpage contents
Can read sensitive information from webpages, including passwords, phone numbers, and credit cards on: all webpages

Browsing History
Can see when you visit: all webpages

It goes without saying that a browser extension of this type should never have such permissions enabled, as it would allow sensitive data (credit card details, login credentials, etc.) transfer to unknown parties. Such activity should never be tolerated, as it can cause victims to suffer monetary losses or even face identity theft.

The malicious activity of ExploreParameter does not end there, however. According to security experts' research, Adload variants are capable of intercepting traffic and redirecting it to attackers' remote servers.[2] This is another way to monetize on advertisements, and is performed illegally.

You should remove ExploreParameter malware as soon as possible, as ramifications of keeping the parasite on the system might be disastrous. The only problem is that it might be difficult to do manually, as the virus inserts a variety of persistence mechanisms on the Mac system. Thus, the best way to do that is by employing powerful anti-malware software – experts[3] recommend using SpyHunterCombo Cleaner or MalwarebytesMalwarebytes for the purpose. Additionally, fixing performance issues is easiest with FortectIntego or similar advanced software.

Fake Flash Player installers are one of the main reasons Mac users get infected with adware and malware 

For years, users believed that Macs are completely immune to malware thanks to built-in defenses such as XProtect and Gatekeeper. However, defenses are quite useless when users themselves are convinced to allow malicious software to be installed on the system. For that, cybercriminals typically employ social engineering to make users install malicious applications on their devices. The technique typically involves using a well-established name and using it for malicious purposes.

Possibly one of the most abused names in the cybercriminal world is Adobe Flash Player – a plugin that was for years used to play multimedia on various websites. Notifications that were used to inform users about a missing Flash were relatively common until new technologies, such as HTML5, were released. Nonetheless, users are still unaware that most modern browsers, such as Google Chrome, have built-in technology for multimedia playback, and Flash is no longer needed.

Threat actors quickly adapted Flash Player update prompts to spread malware, as users are unaware of the deception. As soon as they see the familiar logo, they download and install software, thinking that it a required plugin for their browsing activities. In the meantime, they install malware on their Macs.

Adobe Flash Player is due to be shut down by the end of 2020, so there is no need to ever install this outdated and flawed plugin, even if it is a legitimate version.

ExploreParameter distribution

ExploreParameter removal options

It is evident that you should remove ExploreParameter from your system as soon as possible to maintain your identity private and browsing safe. Unfortunately, the process of uninstallation might be very much complicated for most users, as moving the app to Trash will not suffice.

If you would like to attempt manual ExploreParameter removal, you could check the following locations on your Mac:

System Preferences > Accounts> Login Items
System Preferences > Users&Groups > Profiles
Users/aUser/Library/LaunchAgents/
~/Library/LaunchAgents
~/Library/Application Support
~/Library/LaunchDaemons

However, you might not be able to find all the malicious files yourself, and the infection might immediately come back. Instead, we suggest you download and install powerful anti-malware software and delete the ExploreParameter virus for good. Security tools are designed to look for all malicious components on the device and eliminate them automatically.

Delete from macOS

Remove the unwanted application:

  1. From the menu bar, select Go > Applications.
  2. In the Applications folder, look for any suspicious entries, then drag them to Trash (or right-click and pick Move to Trash).Uninstall from Mac

Delete leftover files and folders:

  1. Select Go > Go to Folder.
  2. Enter /Library/Application Support and remove any suspicious folders related to the unwanted program.
  3. Repeat the same check in the /Library/LaunchAgents and /Library/LaunchDaemons folders, deleting any suspicious entries.Delete leftover files from Mac
  4. Finally, empty the Trash to permanently remove the leftovers.

Remove from Mozilla Firefox (FF)

Remove dangerous extensions:

  1. Open Mozilla Firefox browser and click on the Menu (three horizontal lines at the top-right of the window).
  2. Select Add-ons.
  3. In here, select the unwanted extension and click Remove.Remove extensions from Firefox

Reset the homepage:

  1. Click three horizontal lines at the top right corner to open the menu.
  2. Choose Settings.
  3. Under Home, set your preferred homepage and new tab settings.

Clear cookies and site data:

  1. Click Menu and pick Settings.
  2. Go to Privacy & Security section.
  3. Scroll down to locate Cookies and Site Data.
  4. Click on Clear Data...
  5. Select Cookies and Site Data and Temporary cached files and pages, then click Clear.Clear cookies and site data from Firefox

Reset Mozilla Firefox

If clearing the browser as explained above did not help, reset Mozilla Firefox:

  1. Open Mozilla Firefox browser and click the Menu.
  2. Go to Help and then choose Troubleshooting Information.Reset Firefox 1
  3. Under Give Firefox a tune up section, click on Refresh Firefox...
  4. Once the pop-up shows up, confirm the action by pressing on Refresh Firefox.Reset Firefox 2

Remove from Google Chrome

Delete malicious extensions from Google Chrome:

  1. Open Google Chrome, click on the Menu (three vertical dots at the top-right corner) and select More tools > Extensions.
  2. In the newly opened window, you will see all the installed extensions. Uninstall all suspicious extensions related to the unwanted program by clicking Remove.Remove extensions from Chrome

Clear cache and web data from Chrome:

  1. Click on Menu and pick Settings.
  2. Under Privacy and security, select Clear browsing data.
  3. Select Browsing history, Cookies and other site data, as well as Cached images and files.
  4. Click Clear data.Clear cache and web data from Chrome

Change your homepage:

  1. Click menu and choose Settings.
  2. Look for a suspicious site in the On startup section.
  3. Click on Open a specific or set of pages and click on three dots to find the Remove option.

Reset Google Chrome:

If the previous methods did not help you, reset Google Chrome to eliminate all the unwanted components:

  1. Click on Menu and select Settings.
  2. In the Settings, scroll down and click Advanced.
  3. Scroll down and locate Reset and clean up section.
  4. Now click Restore settings to their original defaults.
  5. Confirm with Reset settings.Reset Chrome 2

Delete from Safari

Remove dangerous extensions:

  1. Open Safari, click Safari in the menu at the top-left of the screen, and select Preferences.
  2. Go to the Extensions tab, look for any suspicious entries, and click Uninstall to remove them.Remove extensions from Safari

Clear history and website data:

  1. Click Safari in the menu and pick Clear History.
  2. Set Clear to all history and confirm with Clear History.Clear history from Safari

Reset Safari:

  1. Click Safari in the menu and select Preferences > Advanced.
  2. Enable Show Develop menu in menu bar.
  3. From the menu bar, click Develop and select Empty Caches.Reset Safari

Be the first to comment

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.