How to remove apps that open the optavut.com web page
Written by Tomas Meskauskas on (updated)
What is optavut[.]com?
optavut[.]com is a deceptive website used to promote potentially unwanted applications (PUAs). There are many similar pages on the internet, all of which display fake notifications stating that a device is infected, damaged, hacked, etc., and encouraging users to download and install an application, which will supposedly fix the problem (remove viruses, fix errors, etc.).
Neither optavut[.]com nor other similar page can be trusted. Commonly, these sites are promoted via dubious advertisements, other untrusted web pages, or PUAs that users download/install onto their devices inadvertently.
Research shows that there are at least three optavut[.]com website variants. One displays a fake virus alert message stating that the operating system is heavily damaged by two viruses.
The message also states that the two viruses will damage the SIM card, corrupt contacts, photos, applications, and other data, unless users remove them as soon as possible using the application, which can be downloaded via the "REPAIR FAST NOW" button.
The second optavut[.]com variant also displays a fake virus notification, a message stating that the iPhone (and installed browser) is damaged by nineteen Trojan viruses.
It encourages users to install a mobile security application to remove these viruses and states that, without the app Facebook account, WhatsApp messages, photos, and installed applications will be stolen or infected.
The third optavut[.]com variant displays a message asking users to download and install an application called AdBlocker app to keep online browsing secure. This application is available for download on the App Store. It is a legitimate application, however, this does not make the optavut[.]com website any more trustworthy. Besides, it is very likely that this page may be used to trick users into downloading adware, browser hijackers, and other PUAs.
Deceptive websites like optavut[.]com are often promoted via potentially unwanted applications that users download/install onto their browsers or devices unintentionally. These apps can generate advertisements and gather data as well.
They serve coupons, banners, surveys, pop-ups, and other advertisements that can open untrusted websites if clicked. Sometimes they can execute scripts designed to cause download/installation of unwanted software.
PUAs often target browsing-related details like geolocations, URLs of visited websites, entered search queries, IP addresses, and sometimes personal/sensitive information. The developers use the data for marketing purposes, sell it to third parties (potentially cyber criminals) or monetize it in other ways.
You are strongly advised to remove all PUAs from browsers and operating systems.
Name | optavut.com pop-up |
Threat Type | Phishing, Scam, Mac malware, Mac virus |
Fake Claim | iPhone is infected with viruses |
Detection Names | Forcepoint ThreatSeeker (Suspicious), Full List (VirusTotal) |
Serving IP Address | 64.227.11.5 |
Promoted Unwanted Application | AdBlocker |
Symptoms | Your Mac becomes slower than normal, you see unwanted pop-up ads, you are redirected to dubious websites. |
Distribution methods | Deceptive pop-up ads, free software installers (bundling), fake Flash Player installers, torrent file downloads. |
Damage | Internet browser tracking (potential privacy issues), display of unwanted ads, redirects to dubious websites, loss of private information. |
Malware Removal (Mac) | To eliminate possible malware infections, scan your Mac with legitimate antivirus software. Our security researchers recommend using Combo Cleaner. |
As mentioned, there are many pages similar to optavut[.]com on the internet. Some examples are landoseseq[.]com, security-protect[.]systems, and security-protect[.]systems. Usually, their notifications are designed to seem like legitimate system notifications or those from the Apple company, however, none of these pages have anything to do with the genuine Apple company or its products/services.
Apps that open optavut[.]com and similar pages should be removed as soon as possible.
How did potentially unwanted applications install on my computer?
People often download and install unwanted apps inadvertently via deceptive advertisements - they click ads that cause unwanted downloads/installations by executing certain scripts.
Unwanted downloads and installations also occur during download/installation of other programs. I.e., when PUAs are included into the set-ups as 'extra offers'. This PUA distribution method of PUAs is called "bundling".
Typically, offers to download and install these additional apps can be declined via "Custom", "Advanced" or other settings, or by unticking certain checkboxes within the set-ups. When users download and install programs without making these checks and changes, they often allow PUAs to infiltrate.
How to avoid installation of potentially unwanted applications
You are advised to download files and programs from official websites and via direct download links. Other tools and sources such as third party downloaders and installers, unofficial pages, and Peer-to-Peer networks (e.g., eMule, torrent clients) should not be used to download or install software.
Check all "Custom", "Advanced" and other similar settings (or available checkboxes) for offers to download and/or install unwanted apps. Do not click ads on dubious websites, since they can be designed to open bogus web pages or cause unwanted downloads and installations.
Remove any unwanted, suspicious extensions, plug-ins and add-ons installed on the browser, and software of this kind from the operating system.
If your computer is already infected with PUAs, we recommend running a scan with Combo Cleaner Antivirus for macOS to automatically eliminate them.
Text in the first optavut[.]com variant:
Your system is heavily damaged by Two viruses!
We detected that your Apple iPhone is 28.1% DAMAGED because of Two harmful viruses from recent adult sites. Soon it will damage your phone's SIM card and will corrupt your contacts, photos, data, applications , etc.
If you do not remove the virus now , it will cause severe damage to your phone .
Here's what you NEED to do (step by step ) :Step 1: Tap the button and install App for free!
Step 2: Open the App to speed up and fix your browser now!
Screenshot of the second optavut[.]com variant:
Text in this variant:
Your Apple iPhone is severely damaged by 19 viruses!
We have detected that your Browser is (59%) DAMAGED by BROWSER TROJAN VIRUSES picked up while surfing recent corrupted sites.Immediately install mobile security application or sensitive data like your Facebook account, WhatsApp messages, photos and private applications will be infected and stolen.
0 minute 42 seconds
Install Cancel
Screenshot of the third optavut[.]com variant:
Text in this variant:
Adblocker Update
Please download the free Adblocker app from the Apple Store to secure your web surfing
Screenshot of the app promoted via third variant:
To enable pop-up blocking, fraudulent website warnings, and remove web browsing data in mobile Apple devices, follow these steps:
First, go to "Settings", and then scroll down to find and tap "Safari".
Check if the "Block Pop-ups" and "Fraudulent Website Warning" toggles are enabled. If not, enable them immediately. Then, scroll down and tap "Advanced".
Tap "Website Data" and then "Remove All Website Data".
Instant automatic Mac malware removal:
Manual threat removal might be a lengthy and complicated process that requires advanced IT skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of Mac malware. Download it by clicking the button below:
▼ DOWNLOAD Combo Cleaner for Mac
By downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by Rcs Lt, the parent company of PCRisk.com read more.
Quick menu:
- What is optavut[.]com?
- STEP 1. Remove PUA related files and folders from OSX.
- STEP 2. Remove rogue extensions from Safari.
- STEP 3. Remove rogue add-ons from Google Chrome.
- STEP 4. Remove potentially unwanted plug-ins from Mozilla Firefox.
Video showing how to remove adware and browser hijackers from a Mac computer:
Potentially unwanted applications removal:
Remove potentially unwanted applications from your "Applications" folder:
Click the Finder icon. In the Finder window, select "Applications". In the applications folder, look for "MPlayerX", "NicePlayer", or other suspicious applications and drag them to the Trash. After removing the potentially unwanted application(s) that cause online ads, scan your Mac for any remaining unwanted components.
Remove adware-related files and folders
Click the Finder icon, from the menu bar. Choose Go, and click Go to Folder...
Check for adware generated files in the /Library/LaunchAgents/ folder:
In the Go to Folder... bar, type: /Library/LaunchAgents/
In the "LaunchAgents" folder, look for any recently-added suspicious files and move them to the Trash. Examples of files generated by adware - "installmac.AppRemoval.plist", "myppes.download.plist", "mykotlerino.ltvbit.plist", "kuklorest.update.plist", etc. Adware commonly installs several files with the exact same string.
Check for adware generated files in the ~/Library/Application Support/ folder:
In the Go to Folder... bar, type: ~/Library/Application Support/
In the "Application Support" folder, look for any recently-added suspicious folders. For example, "MplayerX" or "NicePlayer", and move these folders to the Trash.
Check for adware generated files in the ~/Library/LaunchAgents/ folder:
In the Go to Folder... bar, type: ~/Library/LaunchAgents/
In the "LaunchAgents" folder, look for any recently-added suspicious files and move them to the Trash. Examples of files generated by adware - "installmac.AppRemoval.plist", "myppes.download.plist", "mykotlerino.ltvbit.plist", "kuklorest.update.plist", etc. Adware commonly installs several files with the exact same string.
Check for adware generated files in the /Library/LaunchDaemons/ folder:
In the "Go to Folder..." bar, type: /Library/LaunchDaemons/
In the "LaunchDaemons" folder, look for recently-added suspicious files. For example "com.aoudad.net-preferences.plist", "com.myppes.net-preferences.plist", "com.kuklorest.net-preferences.plist", "com.avickUpd.plist", etc., and move them to the Trash.
Scan your Mac with Combo Cleaner:
If you have followed all the steps correctly, your Mac should be clean of infections. To ensure your system is not infected, run a scan with Combo Cleaner Antivirus. Download it HERE. After downloading the file, double click combocleaner.dmg installer. In the opened window, drag and drop the Combo Cleaner icon on top of the Applications icon. Now open your launchpad and click on the Combo Cleaner icon. Wait until Combo Cleaner updates its virus definition database and click the "Start Combo Scan" button.
Combo Cleaner will scan your Mac for malware infections. If the antivirus scan displays "no threats found" - this means that you can continue with the removal guide; otherwise, it's recommended to remove any found infections before continuing.
After removing files and folders generated by the adware, continue to remove rogue extensions from your Internet browsers.
Remove malicious extensions from Internet browsers
Remove malicious Safari extensions:
Open the Safari browser, from the menu bar, select "Safari" and click "Preferences...".
In the preferences window, select "Extensions" and look for any recently-installed suspicious extensions. When located, click the "Uninstall" button next to it/them. Note that you can safely uninstall all extensions from your Safari browser - none are crucial for regular browser operation.
- If you continue to have problems with browser redirects and unwanted advertisements - Reset Safari.
Remove malicious extensions from Google Chrome:
Click the Chrome menu icon (at the top right corner of Google Chrome), select "More Tools" and click "Extensions". Locate all recently-installed suspicious extensions, select these entries and click "Remove".
- If you continue to have problems with browser redirects and unwanted advertisements - Reset Google Chrome.
Remove malicious extensions from Mozilla Firefox:
Click the Firefox menu (at the top right corner of the main window) and select "Add-ons and themes". Click "Extensions", in the opened window locate all recently-installed suspicious extensions, click on the three dots and then click "Remove".
- If you continue to have problems with browser redirects and unwanted advertisements - Reset Mozilla Firefox.
▼ Show Discussion