NetInput – a potentially unwanted application for Mac that hijacks your Google Chrome and secretly spies on you

NetInput is a potentially unwanted application designed for macOS-based devices belonging to the broad adware family known as Adload. The app rarely gets on users' machines on purpose, i.e., most people install it after they are tricked by fake Flash Player update prompts or after downloading a pirated application from an insecure site. Despite this, users are the ones who have to enter their AppleID in order to let this application into their computers,
Once installed, the so-called NetInput virus would make several changes to the way a Mac and the installed browsers function. The first sign of the hijack is an appended extension to Safari, Google Chrome, Mozilla Firefox, or another browser installed with elevated privileges (which allows the app to read your personal information, such as banking details). Also, the homepage and new tab address might be set to Safe Finder or something similar, so you will be forced to browse via an alternative provider, e.g., Yahoo or Bing.
Keeping this app installed might also lead you to potentially dangerous places on the internet and expose your sensitive data to cybercriminals. Therefore, do not delay NetInput removal, although keep in mind that it might not be easy to execute. Check form more information on how to get rid of this annoying Mac infection below.
| Name | NetInput / NetInput virus |
|---|---|
| Type | Adware, potentially unwanted program, Mac virus |
| Family | Adload |
| Distribution | Fake Flash Player updates, software bundles, torrent sites, illegal software installers |
| Symptoms | A browser extension installed on the web browser that is impossible to eliminate; homepage and new tab URL swapped to Safe Finder, Akamaihd, or something else; redirects lead to potentially malicious or scam sites, etc. |
| Dangers | Additional malware/PUP infection, sensitive information disclosure to unknown parties/crybercriminals, identity theft, monetary losses due to encountered scams, etc. |
| Elimination | To get rid of unwanted apps manually, you can follow our removal guide below. If the unwanted ads and other disruptive behavior does not stop, you should scan your computer with security software and delete all threats automatically |
| Further steps | After you terminate the infection with all its associated components, we recommend you also scan your machine with FortectIntego for best results |
As soon as NetInput is implemented, there are several changes that it does to the system, and not all of them are apparent straight away. As already mentioned, the first sign should be unexpected browser changes to the homepage address and the extension present.
The extension should be called NetInput and have a distinctive magnifying glass icon, surrounded by green, teal, or blue circle. This trait is prevalent among other versions of the virus, such as ScalableRemote, OperativeFraction, or AccessibleBoost. All these apps might be called slightly differently, but their distribution or operation methods remain identical.
NetInput is a relatively primitive adware program that seeks to gain as much revenue from ads as possible – hence the browser changes. By implementing Safe Finder, users are guaranteed to be fed with pop-ups, deals, offers, sponsored links, coupons, and other commercial content on a regular basis.
What is very malicious is that the browser extension is installed with the administrator's permission. Here is what you are likely to see if you check that extension can do on your Safari web browser:
Permissions for “NetInput”
Webpage contents
Can read sensitive information from webpages, including passwords, phone numbers, and credit cards on: all webpagesBrowsing History
Can see when you visit: all webpages
Without a doubt, there is no need for the extension to read credit cards or passwords via your web browser. This data can be exfoliated and delivered to cybercriminals. Consequently, you may lose access to your other accounts or even face serious consequences such as identity theft. Therefore, it is vital you remove NetInput as soon as possible, although this might be a harder task than it may initially seem.

For persistence, this adware app establishes new profiles and drops several .plist files all over the system with the help of the built-in AppleScript.[1] As a result, even if users drop the item to Trash, it returns straight away. In order to clean your computer properly, you need to find all the elements of the adware and delete them.
The best way to do it is by using security software such as SpyHunterCombo Cleaner or MalwarebytesMalwarebytes, although if you prefer the manual method (which might not always succeed), check the bottom section of the article. Additionally, security experts[2] highly recommend keeping your system clean with FortectIntego.
Adware for Mac can commonly be found on sites distributing pirated software
Adware has been an increasing threat for Mac users for quite a few years now. According to security research conducted at the start of 2020, the rate that malware distributed for macOS surpassed that of Windows malware.[3] Once believed to be virus-immune, Mac users are now being infected as often as never before, and one of the first steps for better cybersecurity is third-party security software that would warn users about the imminent threat.
However, it is also important to know how adware and malware spread on Macs – and there are two main ways:
- Software bundle packages. Most third-party websites bundle programs into a single package, so it is always important not to rush the installation, read the instructions carefully, delete the ticks from pre-ticked boxes, and always pick advanced/custom settings when prompted. Keep in mind that pirated program installers deliver not only Adload adware but also much more dangerous threats such as trojans.
- Fake update prompts and deceptive ads. These bogus notifications can be encountered anywhere on the internet – thousands of malicious websites are created on a daily basis. Therefore, never download any updates or alleged removal programs for websites that claim something is out of date. Flash Player is particularly abused in these scenarios, so if you still need this plugin (which you don't, really), you should go to the official Adobe site and download it from there.

Proceed with NetInput virus removal immediately
NetInput removal might not be easy if you want to do it manually. As previously mentioned, the virus drops several malicious files on the system, making it return as soon as you put the main application into the Trash. These components might be difficult to find for novice computer users. Therefore, using reputable anti-malware software could be a great solution for many users.
If your device that you want to remove NetInput virus manually, you can. First of all, before you do anything, you should launch the Activity Monitor and shut down all the suspicious processes – especially if you find the name of the adware there. Then, check System Preferences > Accounts> Login Items and System Preferences > Users&Groups > Profiles sections of your computer and delete all the related elements. After that is complete, you should proceed with the instructions we provide below. Keep in mind that cleaning your web browser from the malicious extension is just as important.
Uninstall from Windows
Uninstall from Windows 10/8:
- Type Control Panel into the Windows search box and open the result.
- Under Programs, select Uninstall a program.

Uninstall from Windows 7/XP:
- Click on Windows Start > Control Panel (Windows XP users should click on Add/Remove Programs).
- In Control Panel, select Programs > Uninstall a program.

Remove the unwanted program:
- In the Programs and Features window, look for any recently installed suspicious entries, select them, and click Uninstall.
- If User Account Control appears, click Yes to confirm, then complete the removal.

Delete from macOS
Remove the unwanted application:
- From the menu bar, select Go > Applications.
- In the Applications folder, look for any suspicious entries, then drag them to Trash (or right-click and pick Move to Trash).

Delete leftover files and folders:
- Select Go > Go to Folder.
- Enter /Library/Application Support and remove any suspicious folders related to the unwanted program.
- Repeat the same check in the /Library/LaunchAgents and /Library/LaunchDaemons folders, deleting any suspicious entries.

- Finally, empty the Trash to permanently remove the leftovers.
Remove from Microsoft Edge
Delete unwanted extensions from MS Edge:
- Select Menu (three horizontal dots at the top-right of the browser window) and pick Extensions.
- From the list, pick the extension and click on the Gear icon.
- Click Remove.

Clear cookies and other browser data:
- Click on the Menu (three horizontal dots at the top-right of the browser window) and select Settings > Privacy, search, and services..
- Under Clear browsing data, pick Choose what to clear.
- Select Cookies and other site data and Cached images and files. (apart from passwords, although you might want to include Media licenses as well, if applicable) and click on Clear.

Restore new tab and homepage settings:
- Click the menu icon and choose Settings.
- Then find On startup section.
- Click Remove next to any suspicious startup page.
Reset MS Edge if the above steps did not work:
- Press on Ctrl + Shift + Esc to open Task Manager.
- Click on More details arrow at the bottom of the window.
- Select Details tab.
- Now scroll down and locate every entry with Microsoft Edge name in it. Right-click on each of them and select End Task to stop MS Edge from running.

Instructions for Chromium-based Edge
Delete extensions from MS Edge (Chromium):
- Open Edge and click select Settings > Extensions.
- Delete unwanted extensions by clicking Remove.

Clear cache and site data:
- Click on Menu and go to Settings.
- Select Privacy, search and services.
- Under Clear browsing data, pick Choose what to clear.
- Under Time range, pick All time.
- Select Clear now.

Reset Chromium-based MS Edge:
- Click on Menu and select Settings.
- On the left side, pick Reset settings.
- Select Restore settings to their default values.
- Confirm with Reset.
- This will disable extensions and reset startup pages but will not delete bookmarks, saved passwords, or browsing history.

Remove from Mozilla Firefox (FF)
Remove dangerous extensions:
- Open Mozilla Firefox browser and click on the Menu (three horizontal lines at the top-right of the window).
- Select Add-ons.
- In here, select the unwanted extension and click Remove.

Reset the homepage:
- Click three horizontal lines at the top right corner to open the menu.
- Choose Settings.
- Under Home, set your preferred homepage and new tab settings.
Clear cookies and site data:
- Click Menu and pick Settings.
- Go to Privacy & Security section.
- Scroll down to locate Cookies and Site Data.
- Click on Clear Data...
- Select Cookies and Site Data and Temporary cached files and pages, then click Clear.

Reset Mozilla Firefox
If clearing the browser as explained above did not help, reset Mozilla Firefox:
- Open Mozilla Firefox browser and click the Menu.
- Go to Help and then choose Troubleshooting Information.

- Under Give Firefox a tune up section, click on Refresh Firefox...
- Once the pop-up shows up, confirm the action by pressing on Refresh Firefox.

Remove from Google Chrome
Delete malicious extensions from Google Chrome:
- Open Google Chrome, click on the Menu (three vertical dots at the top-right corner) and select More tools > Extensions.
- In the newly opened window, you will see all the installed extensions. Uninstall all suspicious extensions related to the unwanted program by clicking Remove.

Clear cache and web data from Chrome:
- Click on Menu and pick Settings.
- Under Privacy and security, select Clear browsing data.
- Select Browsing history, Cookies and other site data, as well as Cached images and files.
- Click Clear data.

Change your homepage:
- Click menu and choose Settings.
- Look for a suspicious site in the On startup section.
- Click on Open a specific or set of pages and click on three dots to find the Remove option.
Reset Google Chrome:
If the previous methods did not help you, reset Google Chrome to eliminate all the unwanted components:
- Click on Menu and select Settings.
- In the Settings, scroll down and click Advanced.
- Scroll down and locate Reset and clean up section.
- Now click Restore settings to their original defaults.
- Confirm with Reset settings.

Delete from Safari
Remove dangerous extensions:
- Open Safari, click Safari in the menu at the top-left of the screen, and select Preferences.
- Go to the Extensions tab, look for any suspicious entries, and click Uninstall to remove them.

Clear history and website data:
- Click Safari in the menu and pick Clear History.
- Set Clear to all history and confirm with Clear History.

Reset Safari:
- Click Safari in the menu and select Preferences > Advanced.
- Enable Show Develop menu in menu bar.
- From the menu bar, click Develop and select Empty Caches.

Was this guide helpful?
Be the first to comment