Apple Intelligence is now available on iPhone, iPad, and Mac!

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

SearchBaron and SearchMarquis

SearchBaron and SearchMarquis keep alternately popping up when I open Safari with my favourites. When I change to a blank startup page they don't show up. How to get rid of them!? This started with the fake "Your memory is getting low" window that I tried several times to get rid of by restarting, but finally clicked closed because it was in the middle of the screen on my MacBook pro.



Posted on Jun 8, 2020 2:08 PM

Reply
Question marked as Top-ranking reply

Posted on Jun 10, 2020 3:39 PM

Thanks. Late last year you installed adware, and your Mac has not been operating properly since then. macOS's improved malware detection algorithms are only now making you aware of its presence.


To fix it follow the instructions below. To learn how not to make that mistake again, please read How to install adware.



First, ensure you have a reliable backup of your Mac, in case something should go wrong with continued troubleshooting. To learn how to do that, please read Back up your Mac with Time Machine.


  • A backup is a fundamental prerequisite regardless of whatever method you may choose uninstall adware, and would apply even if your Mac were running perfectly well. Do not overlook this fundamental requirement. It's important.


Next: This step will prevent the scam products from loading so that they can be removed while they are inactive. Restart in "Safe Mode", and log in: Use safe mode to isolate issues with your Mac. Starting in Safe Mode takes longer than usual so let it finish. The rogue processes affecting that Mac are inoperative in "Safe Mode".


The following files and / or folders need to be deleted while using your Mac in "Safe Mode":


Delete all the files in your first screenshot.


Nothing needs to be deleted from the folders in the second and third screenshots.


Drag those selections of files to the Trash. You may be asked to authenticate. Confirm they are no longer present in that folder. Leave all the others alone for now.


Next: open Safari and select the Safari menu > Preferences... > Extensions. If you see any Safari Extensions that you do not recognize or understand, simply click the Uninstall button and they will be gone. No Safari Extensions are required for normal operation. Then, select the General pane and review your Homepage selection. Repeat those equivalent actions for any other browser you may use (Brave, Firefox, or Opera for example).


There may also be adware-associated app icons in your Mac's Applications folder. Open it and examine its contents. Any unwanted or mysterious app icons should be obvious to you, but again please don't remove anything if you are uncertain—ask first. Identify any suspicious apps by name, or post another screenshot.


Next: In an abundance of caution, examine System Preferences > Extensions. Determine if there are any System Extensions that may have been installed without your knowledge. Ask if you're uncertain.


Remaining in System Preferences, check for the presence of any Profiles. Profiles are installed by organizations with a need to manage Macs deployed in institutional corporate or educational environments (for example), but have also been exploited by adware creators and similar malcontents. If any Profiles are installed on your Mac an icon like this will appear in System Preferences:



If you see that icon in System Preferences, select it. To remove a Profile, select it, then click the [—] (minus) button and authenticate.


Remaining in System Preferences, open Users & Groups. Select your User Account's Login Items. You may or may not find those Applications in its list. If you do, select them then click the [—] (minus) button to remove them from Login Items.


You can then restart your Mac and log in as usual. Evaluate its operation and ensure everything is working as you expect it should.


Next: if you want to eradicate all remaining adware remnants post a screenshot of the following folder, in the same manner as you did earlier:


~/Library/Application Support


It is normal for that folder to contain many items, but anything associated with the above adware may contain identical names. If you find a folder or folders bearing those names, drag those folders to the Trash. Without the files you already removed or the reintroduction of similar malware, they can do nothing but occupy space. These can be removed if you wish, but again don't remove anything if you are uncertain.


Finally: If any of the above actions result in abnormal operation or if something else stops working, the easiest way to recover would be to restore the Time Machine backup you created as a prerequisite, so the importance of that fundamental step cannot be overemphasized.

11 replies
Question marked as Top-ranking reply

Jun 10, 2020 3:39 PM in response to Janet 547

Thanks. Late last year you installed adware, and your Mac has not been operating properly since then. macOS's improved malware detection algorithms are only now making you aware of its presence.


To fix it follow the instructions below. To learn how not to make that mistake again, please read How to install adware.



First, ensure you have a reliable backup of your Mac, in case something should go wrong with continued troubleshooting. To learn how to do that, please read Back up your Mac with Time Machine.


  • A backup is a fundamental prerequisite regardless of whatever method you may choose uninstall adware, and would apply even if your Mac were running perfectly well. Do not overlook this fundamental requirement. It's important.


Next: This step will prevent the scam products from loading so that they can be removed while they are inactive. Restart in "Safe Mode", and log in: Use safe mode to isolate issues with your Mac. Starting in Safe Mode takes longer than usual so let it finish. The rogue processes affecting that Mac are inoperative in "Safe Mode".


The following files and / or folders need to be deleted while using your Mac in "Safe Mode":


Delete all the files in your first screenshot.


Nothing needs to be deleted from the folders in the second and third screenshots.


Drag those selections of files to the Trash. You may be asked to authenticate. Confirm they are no longer present in that folder. Leave all the others alone for now.


Next: open Safari and select the Safari menu > Preferences... > Extensions. If you see any Safari Extensions that you do not recognize or understand, simply click the Uninstall button and they will be gone. No Safari Extensions are required for normal operation. Then, select the General pane and review your Homepage selection. Repeat those equivalent actions for any other browser you may use (Brave, Firefox, or Opera for example).


There may also be adware-associated app icons in your Mac's Applications folder. Open it and examine its contents. Any unwanted or mysterious app icons should be obvious to you, but again please don't remove anything if you are uncertain—ask first. Identify any suspicious apps by name, or post another screenshot.


Next: In an abundance of caution, examine System Preferences > Extensions. Determine if there are any System Extensions that may have been installed without your knowledge. Ask if you're uncertain.


Remaining in System Preferences, check for the presence of any Profiles. Profiles are installed by organizations with a need to manage Macs deployed in institutional corporate or educational environments (for example), but have also been exploited by adware creators and similar malcontents. If any Profiles are installed on your Mac an icon like this will appear in System Preferences:



If you see that icon in System Preferences, select it. To remove a Profile, select it, then click the [—] (minus) button and authenticate.


Remaining in System Preferences, open Users & Groups. Select your User Account's Login Items. You may or may not find those Applications in its list. If you do, select them then click the [—] (minus) button to remove them from Login Items.


You can then restart your Mac and log in as usual. Evaluate its operation and ensure everything is working as you expect it should.


Next: if you want to eradicate all remaining adware remnants post a screenshot of the following folder, in the same manner as you did earlier:


~/Library/Application Support


It is normal for that folder to contain many items, but anything associated with the above adware may contain identical names. If you find a folder or folders bearing those names, drag those folders to the Trash. Without the files you already removed or the reintroduction of similar malware, they can do nothing but occupy space. These can be removed if you wish, but again don't remove anything if you are uncertain.


Finally: If any of the above actions result in abnormal operation or if something else stops working, the easiest way to recover would be to restore the Time Machine backup you created as a prerequisite, so the importance of that fundamental step cannot be overemphasized.

Jun 10, 2020 1:04 PM in response to Janet 547

Janet 547 wrote:

I've seen suggestions about using Malwarebytes but given that a lot of these viruses promote "cleaning" software which may cause even more problems, am hesitant to introduce anything else to my machine.


You don't need to install anything. To ascertain the cause so that you can eliminate it, start by inspecting the contents of the following folder:


~/Library/LaunchAgents


To open that folder, copy the entire line above and paste it in the Finder's Go menu > Go to Folder... field. Make it look like this:



... and click the Go button.


A Finder window will open. Make sure all its file names are readable by selecting View > as List or other selection that shows that folder's complete contents. Then, take a screenshot of that Finder window.



Often, there is nothing in that Launch Agents folder so don't be surprised to find it empty.


In the same manner as the above, navigate to this next folder:


/Library/LaunchDaemons


The Finder's Go menu > Go to Folder... field should look like this:



... and click the Go button once again.


Once again ensure all its files and their names are readable and capture a screenshot.


Then, repeat that exercise with the following folder:


/Library/LaunchAgents


Notice its pathname is different than the other two. The Finder's Go menu > Go to Folder... field should look like this:



In the end, you will have captured the contents of the following three separate folders:


~/Library/LaunchAgents

/Library/LaunchDaemons

/Library/LaunchAgents


All three will be saved to your Mac's Desktop with names "Screen Shot... " followed by the date and time they were captured. Please be sure to include or otherwise indicate the name of the folder that corresponds to each screenshot, so that you and I can keep track of which ones they are.


Post the entire contents of all three windows, one at a time, using the "picture" icon that appears below your reply text:


Jun 11, 2020 6:42 AM in response to Janet 547

Janet 547 wrote:

.... Interesting to note that one of the sites that promotes a "cleaner" after walking you through steps to check various folders neglected to include the ~/Library/LaunchAgents folder. Probably not an oversight, right?


Right. Excerpted from Effective defenses against malware and other threats:


  • Don't rely upon Internet search engines to obtain technical support assistance:
  • ...
  • The overwhelming majority of web search results seeking instructions to remove unwanted software (for example) are just advertisements for even more unwanted software. Their "instructions" are designed to be difficult to follow, won't work, will make things worse, or all the above.


Jun 10, 2020 12:29 PM in response to paarthS8

Hi thanks I have already tried everything in the article you mentioned. No "suspicious" apps to uninstall, no extensions, popups blocked, browser is set to Google (was set to Yahoo and same thing) and have restarted a couple times since the redirects (not separate popups) started happening. I am now being redirected to Bing with every search instead of SearchBaron or SearchMarquis. And this all happened right after an update????


I've seen suggestions about using Malwarebytes but given that a lot of these viruses promote "cleaning" software which may cause even more problems, am hesitant to introduce anything else to my machine.

Jun 11, 2020 6:30 AM in response to John Galt

I will tell others how to prevent it but unfortunately sometimes you just get caught...happened to me after a very long day at the laptop when defences were down.... Interesting to note that one of the sites that promotes a "cleaner" after walking you through steps to check various folders neglected to include the ~/Library/LaunchAgents folder. Probably not an oversight, right? In any case I hope anyone else who clicks "I have this question" will follow John Galt's instructions for relief!

SearchBaron and SearchMarquis

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.