Skip to content
  • Active
  • Severity: Medium
  • Mac Viruses
  • Windows, Mac
  • Verified · Nov 2020

How to remove RequestPlan

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Jake Doevan · Computer technology expert

RequestPlan – another deceptive app from the Adload adware strain

RequestPlan

RequestPlan is a potentially unwanted application designed for Mac systems exclusively and belongs to adware category with browser-hijacking features. Belonging to the Adload malware family, this infection is considerably more dangerous than typical PUPs that users might encounter around the web. First of all, its distribution methods are more than questionable – pirated application bundles and fake Flash Player updates are often used, thus resulting in unintentional installation on a Mac machine.

Once installed, RequestPlan installs an extension on Safari, Google Chrome, Mozilla Firefox, or another browser which has elevated permissions to read even the most sensitive information, such as login credentials or banking details. This add-on would also change the homepage and the new tab address of the web browser to Safe Finder or another unreliable search provider. Due to this, users' searches are filled with sponsored links, and they typically face more more pop-ups, deals, offers, coupons, and other commercial content when browsing the web.

To make matters worse, the virus uses various persistence techniques which prevents an easy RequestPlan removal from the web browser and the computer. If you are here because you want to get rid of this annoying and dangerous application, check for more details below.

Name RequestPlan
Type Mac virus, adware
Malware family Adload adware strain, which targets macOS devices
Installation Most users do not install PUPs from Adload family intentionally as they are mostly distributed via fake Flash Player installers or software bundles downloaded from pirated program distribution sites
Symptoms RequestPlan browser extension installed on the web browser, along with an application of the same name; search and browsing settings altered to Safe Finder or another search provider; New profiles and login items setup on the account; ads and redirects lead to malicious sites 
Removal You can get rid of Mac malware with the help of powerful security tools, such as SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. If you want to attempt to get rid of the infection yourself, check the manual instructions below
System optimization Malware and adware can meddle with your system, reducing its performance. If you want to quickly fix various issues, we recommend you try using automated tools like FortectIntego 

While RequestPlan is typically distributed via deceptive methods, users themselves type in their AppleID in order to let the app in, as Apple always warns about the potential danger. Therefore, you should always be very careful what you install – stick to official sources for your downloads.

Once inside the system, the infection spreads quickly, establishing several new components, such as Login items or new entries in the Profile section. For that, the malware uses the built-in Apple script – scripting language primarily developed for inter-application communication.[1] This allows the app to be persistent on the computer it is installed on. This is also the precise reason why users struggle with RequestPlan uninstall.

Since these changes within the operating system environment are performed in the background, most users are unaware of them. However, these are several infection symptoms that are apparent straight away:

  • RequestPlan browser extension installed on Safari, Google Chrome, or another browser;
  • Homepage and new tab address is set to something else;
  • Search engine is set to Safe Finder, and multiple suspicious URLs are visible when searchers are performed;
  • All search results are filled with sponsored links;
  • Overall increase of ads across the board;
  • Browser extension and the installed application is impossible to delete.

All Adload members (such as NetInput, ScalableRemote, or PracticalProcesser) use a distinctive magnifying glass icon, which is placed on a teal, green, or red background. Besides having different names, these apps are generally identical in terms of their distribution and operation principles. This is very typical of PUP developers – they attempt to avoid a bad reputation online, as well as being detected by anti-malware solutions.

RequestPlan virus

Besides the disruptive ads, it is important to remember that the RequestPlan virus also gathers sensitive information, which it absolutely shouldn't. For example, login credentials or credit card details is something that should be invisible to everybody – even the owners of the accounts. And that is widely practiced – most reputable companies use encryption to ensure that sensitive information would not be leaked and abused by cybercriminals. In other words, even your bank does not know your password, so why should this application?

If you can't remove RequestPlan in a regular way (which you most likely won't), you have two choices: either follow our manual elimination guide below or employ SpyHunterCombo Cleaner, MalwarebytesMalwarebytes, or another reputable anti-malware to delete the infection automatically. For computer stability and remediation, experts[2] also recommend employing FortectIntego.

Do not install apps that do not come from the official sources

macOS is generally considered much more safe than Windows due to Gatekeeper, Xprotect, and other built-in security features. In fact, it took years before some users acknowledged, that Mac malware really exists – breakouts of Shlayer Trojan and CrescentCore are just a couple examples that affect Macs. Adware is one of the most significant threats, however, as more and more users get infected. In fact, based on research conducted at the start of 2020, security researchers found that Mac malware is outpacing that one of Windows,[3] which is alarming statistic.

There are two main methods how malicious and potentially unwanted applications can manage to break in:

  • Software bundle packages downloaded from torrent and similar sites that host pirated installers;
  • Fake updates, which include Flash or similar familiar software – can be found on thousands of malicious sites.

Therefore, you should never visit sites that distributed pirated applications – you can infect your computer with malware and cause significant damage to it, along with compromising your privacy. Stick to official sources and find free application counterparts if you don't want to pay.

When it comes to fake updates, it is important to note that Flash Player, fake versions of which are constantly abused for malware distribution, should never be downloaded, even if it is a legitimate version. Adobe ends support for this flawed plugin by the end of 2020, as modern browsers and websites now use HTML 5 or other technologies for multimedia playback.

RequestPlan distribution

Terminate RequestPlan easily

As mentioned above, you might struggle with RequestPlan removal due to its ability to install additional components, such as malicious .plist files, and spread them around the system. Even if you drag the app to the trash, it will return very soon because of it. Additionally, the ability to delete the browser extension might not even be present, i.e., disabled.

If you want to remove RequestPlan manually, you need to first eliminate the Login items and Profiles that have been established by the virus. For that, visit  System Preferences > Accounts> Login Items and System Preferences > Users&Groups > Profiles sections and also follow the steps provided below. When it comes to the extension, you might have to reset the browser fully.

The best way to uninstall the RequestPlan virus is by using security software, as it will detect and eliminate all the malicious entries for good automatically. Besides, anti-malware can ensure that your system stays secure in the future.

Delete from macOS

Remove the unwanted application:

  1. From the menu bar, select Go > Applications.
  2. In the Applications folder, look for any suspicious entries, then drag them to Trash (or right-click and pick Move to Trash).Uninstall from Mac

Delete leftover files and folders:

  1. Select Go > Go to Folder.
  2. Enter /Library/Application Support and remove any suspicious folders related to the unwanted program.
  3. Repeat the same check in the /Library/LaunchAgents and /Library/LaunchDaemons folders, deleting any suspicious entries.Delete leftover files from Mac
  4. Finally, empty the Trash to permanently remove the leftovers.

Remove from Microsoft Edge

Delete unwanted extensions from MS Edge:

  1. Select Menu (three horizontal dots at the top-right of the browser window) and pick Extensions.
  2. From the list, pick the extension and click on the Gear icon.
  3. Click Remove.Remove extensions from Edge

Clear cookies and other browser data:

  1. Click on the Menu (three horizontal dots at the top-right of the browser window) and select Settings > Privacy, search, and services..
  2. Under Clear browsing data, pick Choose what to clear.
  3. Select Cookies and other site data and Cached images and files. (apart from passwords, although you might want to include Media licenses as well, if applicable) and click on Clear.Clear Edge browsing data

Restore new tab and homepage settings:

  1. Click the menu icon and choose Settings.
  2. Then find On startup section.
  3. Click Remove next to any suspicious startup page.

Reset MS Edge if the above steps did not work:

  1. Press on Ctrl + Shift + Esc to open Task Manager.
  2. Click on More details arrow at the bottom of the window.
  3. Select Details tab.
  4. Now scroll down and locate every entry with Microsoft Edge name in it. Right-click on each of them and select End Task to stop MS Edge from running.Reset MS Edge

Instructions for Chromium-based Edge

Delete extensions from MS Edge (Chromium):

  1. Open Edge and click select Settings > Extensions.
  2. Delete unwanted extensions by clicking Remove.Remove extensions from Chromium Edge

Clear cache and site data:

  1. Click on Menu and go to Settings.
  2. Select Privacy, search and services.
  3. Under Clear browsing data, pick Choose what to clear.
  4. Under Time range, pick All time.
  5. Select Clear now.Clear browser data from Chroum Edge

Reset Chromium-based MS Edge:

  1. Click on Menu and select Settings.
  2. On the left side, pick Reset settings.
  3. Select Restore settings to their default values.
  4. Confirm with Reset.
  5. This will disable extensions and reset startup pages but will not delete bookmarks, saved passwords, or browsing history.Reset Chromium Edge

Remove from Mozilla Firefox (FF)

Remove dangerous extensions:

  1. Open Mozilla Firefox browser and click on the Menu (three horizontal lines at the top-right of the window).
  2. Select Add-ons.
  3. In here, select the unwanted extension and click Remove.Remove extensions from Firefox

Reset the homepage:

  1. Click three horizontal lines at the top right corner to open the menu.
  2. Choose Settings.
  3. Under Home, set your preferred homepage and new tab settings.

Clear cookies and site data:

  1. Click Menu and pick Settings.
  2. Go to Privacy & Security section.
  3. Scroll down to locate Cookies and Site Data.
  4. Click on Clear Data...
  5. Select Cookies and Site Data and Temporary cached files and pages, then click Clear.Clear cookies and site data from Firefox

Reset Mozilla Firefox

If clearing the browser as explained above did not help, reset Mozilla Firefox:

  1. Open Mozilla Firefox browser and click the Menu.
  2. Go to Help and then choose Troubleshooting Information.Reset Firefox 1
  3. Under Give Firefox a tune up section, click on Refresh Firefox...
  4. Once the pop-up shows up, confirm the action by pressing on Refresh Firefox.Reset Firefox 2

Remove from Google Chrome

Delete malicious extensions from Google Chrome:

  1. Open Google Chrome, click on the Menu (three vertical dots at the top-right corner) and select More tools > Extensions.
  2. In the newly opened window, you will see all the installed extensions. Uninstall all suspicious extensions related to the unwanted program by clicking Remove.Remove extensions from Chrome

Clear cache and web data from Chrome:

  1. Click on Menu and pick Settings.
  2. Under Privacy and security, select Clear browsing data.
  3. Select Browsing history, Cookies and other site data, as well as Cached images and files.
  4. Click Clear data.Clear cache and web data from Chrome

Change your homepage:

  1. Click menu and choose Settings.
  2. Look for a suspicious site in the On startup section.
  3. Click on Open a specific or set of pages and click on three dots to find the Remove option.

Reset Google Chrome:

If the previous methods did not help you, reset Google Chrome to eliminate all the unwanted components:

  1. Click on Menu and select Settings.
  2. In the Settings, scroll down and click Advanced.
  3. Scroll down and locate Reset and clean up section.
  4. Now click Restore settings to their original defaults.
  5. Confirm with Reset settings.Reset Chrome 2

Delete from Safari

Remove dangerous extensions:

  1. Open Safari, click Safari in the menu at the top-left of the screen, and select Preferences.
  2. Go to the Extensions tab, look for any suspicious entries, and click Uninstall to remove them.Remove extensions from Safari

Clear history and website data:

  1. Click Safari in the menu and pick Clear History.
  2. Set Clear to all history and confirm with Clear History.Clear history from Safari

Reset Safari:

  1. Click Safari in the menu and select Preferences > Advanced.
  2. Enable Show Develop menu in menu bar.
  3. From the menu bar, click Develop and select Empty Caches.Reset Safari

Be the first to comment

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.