Maciek Lazowski

Q: Unwanted ads in Safari (nothing seems to work)

I have unwanted ads in Safari, some of them lead to MacKeeper site. I'm also unable to login to my Tidal account. I've cleared Safari history and cache, ran Malwarebytes and Avast, checked how to get rid of common malware and none of it worked. I don't seem to have any suspicious extensions or software installed, and yet the ads keep showing. Please help.

I'm using an iMac (2013) with OSX Yosemite 10.10.5 and Safari 9.1.1.

iMac (21.5-inch, Late 2013), OS X Yosemite (10.10.5)

Posted on May 18, 2016 11:42 AM

Close

Q: Unwanted ads in Safari (nothing seems to work)

  • All replies
  • Helpful answers

Page 1 Next
  • by Carolyn Samit,

    Carolyn Samit Carolyn Samit May 18, 2016 12:00 PM in response to Maciek Lazowski
    Level 10 (120,854 points)
    Apple Music
    May 18, 2016 12:00 PM in response to Maciek Lazowski

    Hi ..

     

    If you haven't tried this, the next time that happens ...

     

    Force Safari to close. The next time you open Safari, hold down the Shift key while Safari opens. This prevents Safari from automatically reopening any windows.

  • by Maciek Lazowski,

    Maciek Lazowski Maciek Lazowski May 18, 2016 12:14 PM in response to Carolyn Samit
    Level 1 (8 points)
    Safari
    May 18, 2016 12:14 PM in response to Carolyn Samit

    Thanks but tried this, didn't work

  • by Carolyn Samit,

    Carolyn Samit Carolyn Samit May 18, 2016 12:33 PM in response to Maciek Lazowski
    Level 10 (120,854 points)
    Apple Music
    May 18, 2016 12:33 PM in response to Maciek Lazowski

    Ok ..

     

    You've tried history and cache and that didn't help so try removing cookies.

     

    From your Safari menu bar click Safari > Preferences then select the Privacy tab then click:  Remove All Website Data then quit and relaunch Safari to test.



    And check Safari > Preferences > Security. Make sue:  Block pop-up windows is selected.



    If nothing above helped, please run EtreCheck then copy and paste the results in your Reply.


    No personal data is shared from your report.

     

    Hopefully that will reveal why you're seeing the pop up ads.

  • by Maciek Lazowski,

    Maciek Lazowski Maciek Lazowski May 18, 2016 1:36 PM in response to Carolyn Samit
    Level 1 (8 points)
    Safari
    May 18, 2016 1:36 PM in response to Carolyn Samit

    I've tried that too, a couple of times. Didn't help. The funny thing is, after I remove all the website data it's empty (as it should be) but after I relaunch Safari it immediately gets filled with strange websites I never visit.

     

    Oh, and these are not pop ups, they're just weird ads that show in places they shouldn't be on different websites, but not in another window. Here's an example, a weird banner that never appeared before on a Tidal landing page:

    screen.png

     

    Here's my report:

     

    EtreCheck version: 2.9.12 (265)

    Report generated 2016-05-18 22:22:51

    Download EtreCheck from https://etrecheck.com

    Runtime 2:42

    Performance: Excellent

     

    Click the [Support] links for help with non-Apple products.

    Click the [Details] links for more information about that line.

     

    Problem: Other problem

    Description:

    Adware

     

    Hardware Information:

        iMac (21.5-inch, Late 2013)

        [Technical Specifications] - [User Guide] - [Warranty & Service]

        iMac - model: iMac14,3

        1 2.9 GHz Intel Core i5 CPU: 4-core

        8 GB RAM Upgradeable - [Instructions]

            BANK 0/DIMM0

                4 GB DDR3 1600 MHz ok

            BANK 1/DIMM0

                4 GB DDR3 1600 MHz ok

        Bluetooth: Good - Handoff/Airdrop2 supported

        Wireless:  en1: 802.11 a/b/g/n/ac

     

    Video Information:

        NVIDIA GeForce GT 750M - VRAM: 1024 MB

            iMac 1920 x 1080

     

    System Software:

        OS X Yosemite 10.10.5 (14F1808) - Time since boot: about 3 hours

     

    Disk Information:

        APPLE HDD HTS541010A9E662 disk0 : (1 TB) (Rotational)

            EFI (disk0s1) <not mounted> : 210 MB

            Macintosh HD (disk0s2) / : 999.35 GB (937.06 GB free)

            Recovery HD (disk0s3) <not mounted>  [Recovery]: 650 MB

     

    USB Information:

        Apple Inc. BRCM20702 Hub

            Apple Inc. Bluetooth USB Host Controller

        Apple Inc. FaceTime HD Camera (Built-in)

     

    Thunderbolt Information:

        Apple Inc. thunderbolt_bus

     

    Gatekeeper:

        Mac App Store and identified developers

     

    Kernel Extensions:

            /Library/Application Support/Avast/components/fileshield/unsigned

        [loaded]    com.avast.AvastFileShield (3.0.0 - SDK 10.10 - 2016-04-12) [Support]

     

            /Library/Application Support/Avast/components/proxy/unsigned

        [loaded]    com.avast.PacketForwarder (2.1 - SDK 10.10 - 2016-04-12) [Support]

     

    System Launch Agents:

        [not loaded]    5 Apple tasks

        [loaded]    144 Apple tasks

        [running]    63 Apple tasks

     

    System Launch Daemons:

        [not loaded]    47 Apple tasks

        [loaded]    135 Apple tasks

        [running]    80 Apple tasks

     

    Launch Agents:

        [not loaded]    com.adobe.AAM.Updater-1.0.plist (2016-05-16) [Support]

        [failed]    com.adobe.ARMDCHelper.cc24aef4a1b90ed56a...plist (2016-05-10) [Support]

        [running]    com.adobe.AdobeCreativeCloud.plist (2016-02-14) [Support]

        [running]    com.avast.update-agent.plist (2016-05-18) [Support]

        [loaded]    com.avast.userinit.plist (2016-05-18) [Support]

     

    Launch Daemons:

        [loaded]    com.adobe.ARMDC.Communicator.plist (2016-05-10) [Support]

        [loaded]    com.adobe.ARMDC.SMJobBlessHelper.plist (2016-05-10) [Support]

        [running]    com.adobe.adobeupdatedaemon.plist (2016-04-12) [Support]

        [loaded]    com.adobe.agsservice.plist (2016-04-12) [Support]

        [loaded]    com.adobe.fpsaud.plist (2016-05-10) [Support]

        [loaded]    com.avast.init.plist (2016-05-18) [Support]

        [loaded]    com.avast.uninstall.plist (2016-05-18) [Support]

        [loaded]    com.avast.update.plist (2016-05-18) [Support]

        [loaded]    com.malwarebytes.MBAMHelperTool.plist (2016-05-18) [Support]

     

    User Launch Agents:

        [loaded]    com.adobe.AAM.Updater-1.0.plist (2015-05-05) [Support]

        [not loaded]    com.avast.home.userinit.plist (2016-05-18) [Support]

        [loaded]    com.spotify.webhelper.plist (2015-12-30) [Support]

     

    User Login Items:

        iTunesHelper    program  (/Applications/iTunes.app/Contents/MacOS/iTunesHelper.app)

        AdobeResourceSynchronizer    program Hidden (/Applications/Adobe Acrobat DC/Adobe Acrobat.app/Contents/Helpers/AdobeResourceSynchronizer.app)

        Caffeine    program  (/Applications/Caffeine.app)

     

    Other Apps:

        [running]    com.adobe.CCLibrary.120164

        [running]    com.adobe.CCXProcess.124708

        [running]    com.adobe.acc.AdobeDesktopService.67624.630B3942-6941-4A52-9926-090A3D950389

        [running]    com.adobe.accmac.66204

        [loaded]    com.avast.account

        [loaded]    com.avast.crashreport

        [running]    com.avast.daemon

        [running]    com.avast.fileshield

        [running]    com.avast.helper

        [running]    com.avast.proxy

        [running]    com.avast.service

        [running]    com.hp.devicemonitor

        [running]    com.lightheadsw.caffeine.105396

        [loaded]    372 Apple tasks

        [running]    181 Apple tasks

     

    Internet Plug-ins:

        AdobeAAMDetect: 3.0.0.0 - SDK 10.9 (2016-04-12) [Support]

        FlashPlayer-10.6: 21.0.0.242 - SDK 10.6 (2016-05-12) [Support]

        QuickTime Plugin: 7.7.3 (2016-05-18)

        AdobePDFViewerNPAPI: 15.016.20039 - SDK 10.11 (2016-05-13) [Support]

        AdobePDFViewer: 15.016.20039 - SDK 10.11 (2016-05-13) [Support]

        Flash Player: 21.0.0.242 - SDK 10.6 (2016-05-12) [Support]

        Default Browser: 600 - SDK 10.10 (2015-08-18)

     

    3rd Party Preference Panes:

        Flash Player (2016-05-10) [Support]

     

    Time Machine:

        Time Machine not configured!

     

    Top Processes by CPU:

             4%    WindowServer

             2%    fontd

             1%    Creative Cloud

             1%    kernel_task

             0%    com.avast.daemon

     

    Top Processes by Memory:

        711 MB    kernel_task

        451 MB    com.apple.WebKit.WebContent(6)

        254 MB    com.avast.daemon

        164 MB    mdworker(12)

        156 MB    mds_stores

     

    Virtual Memory Information:

        1.14 GB    Free RAM

        6.85 GB    Used RAM (3.51 GB Cached)

        0 B    Swap Used

     

    Diagnostics Information:

        May 18, 2016, 07:01:15 PM    Self test - passed

  • by thomas_r.,

    thomas_r. thomas_r. May 18, 2016 2:54 PM in response to Maciek Lazowski
    Level 7 (30,889 points)
    Mac OS X
    May 18, 2016 2:54 PM in response to Maciek Lazowski

    Those apps aren't finding anything because there's nothing to find... your system has nothing I'd consider suspicious installed (unless you count Avast, which I don't think much of, but which isn't causing that issue).

     

    If you had a laptop, I'd say to try testing on a different network and see if that solves the problem. Since you're on an iMac, that's more difficult. Instead, try rebooting in recovery mode, by holding down command-R at startup. Once booted into recovery mode, you should see a window with only four options, one of which is Get Help Online. Click that item, which will open a clean copy of Safari, running on a clean system. Do you see the same problem when browsing this way? If so, it's a problem with your network, not with software installed on your computer.

  • by Linc Davis,

    Linc Davis Linc Davis May 18, 2016 7:46 PM in response to Maciek Lazowski
    Level 10 (207,931 points)
    Applications
    May 18, 2016 7:46 PM in response to Maciek Lazowski

    You may have installed ad-injection malware ("adware").

    Don't use any kind of "anti-virus" or "anti-malware" product on a Mac. There is never a need for it, and relying on it for protection makes you more vulnerable to attack, not less.

    Back up all data first.

    If you're not already running the latest version of OS X, updating or upgrading in the App Store may cause the adware to be removed automatically. If you are already running the latest version, please log out or restart the computer. Again, some kinds of malware will be removed—not all. There is no such thing as automatic removal of all possible malware, either by OS X or by third-party software. That's why you can't rely on software to protect you.

    If the malware is removed in your case, you'll still need to make changes to the way you use the computer to protect yourself from further attacks. Ask if you need guidance.

    If the malware is not removed automatically, see below.

    This easy procedure will detect any kind of adware that I know of. Deactivating it is a separate, and even easier, procedure.

    Some legitimate software is ad-supported and may display ads in its own windows or in a web browser while it's running. That's not malware and it may not show up. Also, some websites carry intrusive popup ads that may be mistaken for adware.

    If none of your web browsers is working well enough to carry out these instructions, restart the computer in safe mode. The malware will be disabled temporarily.

    Step 1

    Please triple-click the line below on this page to select it, then copy the text to the Clipboard by pressing the key combination command-C:

    ~/Library/LaunchAgents

    In the Finder, select

              Go Go to Folder...

    from the menu bar and paste into the box that opens by pressing command-V. Press return. Either a folder named "LaunchAgents" will open, or you'll get a notice that the folder can't be found. If the folder isn't found, go to the next step.

    If the folder does open, press the key combination command-2 to select list view, if it's not already selected. Please don't skip this step.

    There should be a column in the Finder window headed Date Modified. Click that heading twice to sort the contents by date with the newest at the top. If necessary, enlarge the window so that all of the contents are showing.

    Follow the instructions in this support article under the heading "Take a screenshot of a window." An image file with a name beginning in "Screen Shot" should be saved to the Desktop. Open the screenshot and make sure it's readable. If not, capture a smaller part of the screen showing only what needs to be shown.

    Start a reply to this message. Drag the image file into the editing window to upload it. You can also include text in the reply.

    Leave the folder open for now.

    Step 2

    Do as in Step 1 with this line:

    /Library/LaunchAgents

    The folder that may open will have the same name, but is not the same, as the one in Step 1. As in that step, the folder may not exist.

    Step 3

    Repeat with this line:

    /Library/LaunchDaemons

    This time the folder will be named "LaunchDaemons."

    Step 4

    Open the Safari preferences window and select the Extensions tab. If any extensions are listed, post a screenshot. If there are no extensions, or if you can't launch Safari, skip this step.

    Step 5

    If you use the Firefox or Chrome browser, open its extension list and do as in Step 4.

  • by Eric Root,

    Eric Root Eric Root May 19, 2016 6:19 AM in response to Maciek Lazowski
    Level 9 (70,176 points)
    iTunes
    May 19, 2016 6:19 AM in response to Maciek Lazowski
  • by Maciek Lazowski,

    Maciek Lazowski Maciek Lazowski May 19, 2016 12:33 PM in response to thomas_r.
    Level 1 (8 points)
    Safari
    May 19, 2016 12:33 PM in response to thomas_r.

    thomas_r. I've tried that and the ads were still in Safari. However, I've installed Chrome and there were no ads there.

  • by Maciek Lazowski,

    Maciek Lazowski Maciek Lazowski May 19, 2016 12:38 PM in response to Linc Davis
    Level 1 (8 points)
    Safari
    May 19, 2016 12:38 PM in response to Linc Davis

    Linc Davis

     

    Thanks for the instructions. I'll update my OS (I'm still using Yosemite) and see what happens. I've been using Macs for almost 9 years and never installed any anti malware or anti virus software, but I've also never had an irritating problem like this before. Also, I'm usually pretty careful while browsing the web, I don't have any pirated stuff, but this time something must've cought me off guard. I suspect it was something that was pretening to be a Flash Player Update.

  • by thomas_r.,Helpful

    thomas_r. thomas_r. May 22, 2016 10:54 AM in response to Maciek Lazowski
    Level 7 (30,889 points)
    Mac OS X
    May 22, 2016 10:54 AM in response to Maciek Lazowski

    Maciek Lazowski wrote:

     

    thomas_r. I've tried that and the ads were still in Safari.

     

    Just to be clear: you had restarted in recovery mode (which looks nothing like starting up normally), then started Safari from the Get Help Online option, and you still saw the same ads in that copy of Safari running in recovery mode?

     

    If that's the case, the issue has nothing to do with anything installed on your computer. The problem is most likely due to a hacked piece of network hardware, either your cable/DSL modem or your wireless router (which could be one and the same). For help with that, see:

     

    https://support.malwarebytes.org/customer/portal/articles/2049288-?b_id=9511

     

    (Fair disclosure: The link I have provided goes to a page belonging to the company I work for - Malwarebytes - and that has links to pages that promote my product.)

  • by thomas_r.,Helpful

    thomas_r. thomas_r. May 22, 2016 10:54 AM in response to Maciek Lazowski
    Level 7 (30,889 points)
    Mac OS X
    May 22, 2016 10:54 AM in response to Maciek Lazowski

    Maciek Lazowski wrote:

     

     

    I'll update my OS (I'm still using Yosemite) and see what happens.

     

    Be cautious about that, especially if you plan to upgrade to El Capitan. Before any major upgrade, always back up your computer thoroughly and make sure that all the software and hardware that you rely on will work with the new system. I'm not aware of any issues with upgrading from Yosemite to El Capitan, but regardless, an upgrade is never something to rush into.

     

    Also, see my previous response... if my summary of what you did and what you saw is correct, then the problem will not be fixed by upgrading the system.

  • by Maciek Lazowski,

    Maciek Lazowski Maciek Lazowski May 20, 2016 12:38 AM in response to thomas_r.
    Level 1 (8 points)
    Safari
    May 20, 2016 12:38 AM in response to thomas_r.

    thomas_r. wrote:

     

    Just to be clear: you had restarted in recovery mode (which looks nothing like starting up normally), then started Safari from the Get Help Online option, and you still saw the same ads in that copy of Safari running in recovery mode?

     

    If that's the case, the issue has nothing to do with anything installed on your computer. The problem is most likely due to a hacked piece of network hardware, either your cable/DSL modem or your wireless router (which could be one and the same). For help with that, see:

     

    https://support.malwarebytes.org/customer/portal/articles/2049288-?b_id=9511

     

     

    Yes, I've restarted in recovery mode and used Safari via Get Help Online. It was still full of those ads. Thanks for the link, I've read it, however I'm not sure if it applies to my situation. The ads were in Safari in Recovery Mode, however when I installed Chrome and launched it normally, there were none. Also, my iPhone and iPad are connected to the same Wi-Fi network, and so is my wife's PC laptop, and the problem doesn't occur on any of those devices. So maybe it isn't the router's fault after all?

  • by thomas_r.,

    thomas_r. thomas_r. May 20, 2016 2:54 AM in response to Maciek Lazowski
    Level 7 (30,889 points)
    Mac OS X
    May 20, 2016 2:54 AM in response to Maciek Lazowski

    That is a bit of a puzzler, but nonetheless, the test is definitive - if the problem is happening in recovery mode, it's happening in a completely separate, clean system and a completely separate, clean copy of Safari, and that means it's not being caused by anything installed on your computer.

     

    One possibility is that, in this particular case, it's only designed to affect Safari on Mac OS X, although that would be a bit weird. Another possibility is that there are ad blockers or something similar installed on all those other systems/browsers that are blocking the ads in those cases.

  • by Linc Davis,

    Linc Davis Linc Davis May 20, 2016 5:49 AM in response to Maciek Lazowski
    Level 10 (207,931 points)
    Applications
    May 20, 2016 5:49 AM in response to Maciek Lazowski

    From the menu bar, please select

              ▹ System Preferences... ▹ Network ▹ Advanced... ▹ DNS

    Under DNS Servers you should have one or more numerical addresses, such as “192.168.1.1” or “10.0.0.1”. What are those addresses?

Page 1 Next