Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Malwarebytes download for removing searchbaron on MacBook Pro safari and Chrome

I've tried everything to manually remove the searchbaron/searchmarquis malware that has hijacked my browser. People have mentioned Malwarebytes download as an automatic way of removing the problem. Is Malwarebytes an approved download? If so, show me where apple has given this approval.

thank you.


MacBook Pro 13″, macOS 10.15

Posted on Nov 11, 2020 7:27 PM

Reply
Question marked as Best reply

Posted on Nov 12, 2020 7:04 AM

Getting rid of "Search Marquis" is easy and you don't need to install anything.


To ascertain the cause so that you can eliminate it, start by inspecting the contents of the following folder:


~/Library/LaunchAgents


To open that folder, copy the entire line above and paste it in the Finder's Go menu > Go to Folder... field. Make it look like this:



... and click the Go button.


A Finder window will open. Make sure all its file names are readable by selecting View > as List or other selection that shows that folder's complete contents. Then, take a screenshot of that Finder window.



Often, there is nothing in that Launch Agents folder so don't be surprised to find it empty.


In the same manner as the above, navigate to this next folder:


/Library/LaunchDaemons


The Finder's Go menu > Go to Folder... field should look like this:



... and click the Go button once again.


Once again ensure all its files and their names are readable and capture a screenshot.


Then, repeat that exercise with the following folder:


/Library/LaunchAgents


Notice its pathname is different than the other two. The Finder's Go menu > Go to Folder... field should look like this:



In the end, you will have captured the contents of the following three separate folders:


~/Library/LaunchAgents

/Library/LaunchDaemons

/Library/LaunchAgents


All three will be saved to your Mac's Desktop with names "Screen Shot... " followed by the date and time they were captured. Please be sure to include or otherwise indicate the name of the folder that corresponds to each screenshot, so that you and I can keep track of which ones they are.


Post the entire contents of all three windows, one at a time, using the "picture" icon that appears below your reply text:


Similar questions

11 replies
Question marked as Best reply

Nov 12, 2020 7:04 AM in response to ResetR

Getting rid of "Search Marquis" is easy and you don't need to install anything.


To ascertain the cause so that you can eliminate it, start by inspecting the contents of the following folder:


~/Library/LaunchAgents


To open that folder, copy the entire line above and paste it in the Finder's Go menu > Go to Folder... field. Make it look like this:



... and click the Go button.


A Finder window will open. Make sure all its file names are readable by selecting View > as List or other selection that shows that folder's complete contents. Then, take a screenshot of that Finder window.



Often, there is nothing in that Launch Agents folder so don't be surprised to find it empty.


In the same manner as the above, navigate to this next folder:


/Library/LaunchDaemons


The Finder's Go menu > Go to Folder... field should look like this:



... and click the Go button once again.


Once again ensure all its files and their names are readable and capture a screenshot.


Then, repeat that exercise with the following folder:


/Library/LaunchAgents


Notice its pathname is different than the other two. The Finder's Go menu > Go to Folder... field should look like this:



In the end, you will have captured the contents of the following three separate folders:


~/Library/LaunchAgents

/Library/LaunchDaemons

/Library/LaunchAgents


All three will be saved to your Mac's Desktop with names "Screen Shot... " followed by the date and time they were captured. Please be sure to include or otherwise indicate the name of the folder that corresponds to each screenshot, so that you and I can keep track of which ones they are.


Post the entire contents of all three windows, one at a time, using the "picture" icon that appears below your reply text:


Nov 12, 2020 4:08 PM in response to ResetR

Getting rid of adware is easy and doesn't require installing anything else. To fix it follow the instructions below. To learn how not to make that mistake again, please read How to install adware.



First, ensure you have a reliable backup of your Mac, in case something should go wrong with continued troubleshooting. To learn how to do that, please read Back up your Mac with Time Machine.


  • A backup is a fundamental prerequisite regardless of whatever method you may choose uninstall adware, and would apply even if your Mac were running perfectly well. Do not overlook this fundamental requirement. It's important.


Next: Uninstall the "McAfee" product in accordance with its instructions. It's junk that did nothing to prevent you from installing adware. Its continued presence will prevent your Mac from functioning normally.


Next: This step will prevent the scam products from loading so that they can be removed while they are inactive. Restart in "Safe Mode", and log in: Use safe mode to isolate issues with your Mac. Starting in Safe Mode takes longer than usual so let it finish. The rogue processes affecting that Mac are inoperative in "Safe Mode".


The following files and / or folders need to be deleted while using your Mac in "Safe Mode":


  • Delete all files in those three screenshots except those with Adobe, Google, or Microsoft in their names.


Drag those selections of files to the Trash. You may be asked to authenticate. Confirm they are no longer present in each of those folders.


Next: open Safari and select the Safari menu > Preferences... > Extensions. If you see any Safari Extensions that you do not recognize or understand, simply click the Uninstall button and they will be gone. No Safari Extensions are required for normal operation. Then, select the General pane and review your Homepage selection. Repeat those equivalent actions for any other browser you may use (Brave, Firefox, or Opera for example).


There may also be adware-associated app icons in your Mac's Applications folder. Open it and examine its contents. Any unwanted or mysterious app icons should be obvious to you, but again please don't remove anything if you are uncertain—ask first. Identify any suspicious apps by name, or post another screenshot.


Next: In an abundance of caution, examine System Preferences > Extensions. Determine if there are any System Extensions that may have been installed without your knowledge. Ask if you're uncertain.


Remaining in System Preferences, check for the presence of any Profiles. Profiles are installed by organizations with a need to manage Macs deployed in institutional corporate or educational environments (for example), but have also been exploited by adware creators and similar malcontents. If any Profiles are installed on your Mac an icon like this will appear in System Preferences:



If you see that icon in System Preferences, select it. To remove a Profile, select it, then click the [—] (minus) button and authenticate.


Remaining in System Preferences, open Users & Groups. Select your User Account's Login Items. You may or may not find those Applications in its list. If you do, select them then click the [—] (minus) button to remove them from Login Items.


You can then restart your Mac and log in as usual. Evaluate its operation and ensure everything is working as you expect it should.


Next: if you want to eradicate all remaining adware remnants post a screenshot of the following folder, in the same manner as you did earlier:


~/Library/Application Support


It is normal for that folder to contain many items, but anything associated with the above adware may contain identical names. If you find a folder or folders bearing those names, drag those folders to the Trash. Without the files you already removed or the reintroduction of similar malware, they can do nothing but occupy space. These can be removed if you wish, but again don't remove anything if you are uncertain.


Finally: If any of the above actions result in abnormal operation or if something else stops working, the easiest way to recover would be to restore the Time Machine backup you created as a prerequisite, so the importance of that fundamental step cannot be overemphasized.

Nov 23, 2020 5:41 PM in response to ResetR

The subject dialog always takes this form, as described in Safely open apps on your Mac:



Move to Trash is the correct response. When that message becomes persistent though, the cause is always the same: one or more files that spawn the process resulting in its appearance.


General instructions applicable to all similarly categorized malware are as follows:



The folders to be examined are these three:


~/Library/LaunchAgents

/Library/LaunchDaemons

/Library/LaunchAgents


There should only be few files, if any, in each of the above folders. You should have a passing familiarity with what they are and the reason you need them. If you're unsure, ask.


Legitimate products that deposit system-altering components in those folders commonly include Adobe, Amazon, Citrix, Dropbox, Google and Microsoft, including its product Skype. Teamviewer also, assuming you really need it. Less common but equally legitimate products include Steam (games), various non-Apple "cloud backup" products that don't work very well, and device drivers for external hardware such as printers and non-Apple input devices. It's incumbent upon every Mac user to know the products they install on your Mac, so the files they deposit in those folders will never come as a surprise.


Illegitimate products notorious for causing trouble include any non-Apple product that claims to "clean", "enhance", "optimize", "protect", or "scan" your Mac. Anything in that broad category of junk should be uninstalled according to their instructions and never reinstalled, ever again.


Everything else should be regarded as suspicious. Some malware will litter those folders with hundreds of randomly named files in a pathetic attempt to obscure itself. For one particularly egregious example refer to notice unysgar.app, but if you have no explanation for any particular file in those folders you need to investigate.


Among a few examples are files containing the following in their names:


calculator

cleaner

combo

confcloud

copypaste

date

fixer

helper

hlpr

mafntask

moniter 🙄

pcv

scan

search

systemExtr

spigot

techyutil

time

updService

util

utilty

vlm

... files containing nothing but a random string of long alphanumeric text


... among a few others, but deleting those is a good place to start.


Then, reset your desired Search Engine, uninstall any strange Extensions, remove any unwanted Login Items, delete any unwanted apps, examine System Preferences for the existence of any Profiles, and finally restart your Mac (normally; not Safe Mode).


Then, evaluate its operation. If something still isn't right re-examine those three folders and determine if you overlooked anything. If something really gets messed up you have Time Machine to fall back on, so keep that important fact in mind.



That in a nutshell is how you get rid of adware, on your own, without having to install some sketchy tool or even ask anyone else for help. If you prefer individual attention specifically tailored to your needs though, then by all means please post a new Discussion. To do that click the Post link above right, and choose Discussion from the dropdown menu.

Nov 15, 2020 4:31 PM in response to ResetR

Confirm all files in those three screenshots except those with Adobe, Google, or Microsoft in their names are gone. In your case there should be one and only one Adobe file in the first screenshot. The other two folders can be left unchanged.


Then, confirm no Profiles are present on that Mac:



If you see that icon in System Preferences, select it. To remove a Profile, select it, then click the [—] (minus) button and authenticate.

Nov 23, 2020 8:18 AM in response to John Galt

JG,

I originally forgot to delete files from one of the screen shots, and now all of the browsers are back to normal. No more search baron/marquis malware. Thank you.


This was an easy fix, and didn't require downloading any malware program. I hope others will get this thread and do the same.


Thanks once again.

Rick



Nov 23, 2020 5:35 PM in response to ResetR

👍


My pleasure. Thanks for the update.


This was an easy fix, and didn't require downloading any malware program. I hope others will get this thread and do the same.


By all means tell them about it. "Search Baron" and its ilk go by different names but they all work the same way. If you're interested, I will post a general purpose eradication method that you can pass along as you see fit. Of course everyone is welcome to post their own Discussion describing their own circumstances.

Malwarebytes download for removing searchbaron on MacBook Pro safari and Chrome

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.