Apple Event: May 7th at 7 am PT

Safari on my Mac, has been affected by the Search Marquis malware. How can I get rid of it?

Safari on my Mac, has been affected by the Search Marquis malware.

I’ve watched a few videos on YouTube, about trying to get rid of it, but they seem to be presented by guys trying to sell different versions of software. (E.g. CleanMyMac X), then when I read the comments below the videos, some people are commenting that the software doesn’t get rid of Search Marquis.

I’ve tried the manual method described in the videos…. Emptied Caches; Cleared all Cookies; Cleared all History…. I can’t find anything in Library that looks suspicious, and nothing at all in Extensions.

The final step says to open Activity Monitor, and Stop any startup activities that look suspicious, but doesn’t give any examples, so it’s no help whatsoever.

Does anyone know how to get rid of this malware from a Mac?

iMac 21.5″, macOS 13.3

Posted on Apr 19, 2023 9:21 AM

Reply

Similar questions

19 replies

Apr 20, 2023 3:23 PM in response to Joebloggs1574

Joebloggs1574, please follow the instructions below. All the problematic files are in the first screenshot, while all the other ones are ok. Just be sure to read everything that follows to make sure nothing gets missed.



First, ensure you have a reliable backup of your Mac, in case something should go wrong with continued troubleshooting. To learn how to do that, please read Back up your Mac with Time Machine.


  • A backup is a fundamental prerequisite regardless of whatever method you may choose uninstall adware, and would apply even if your Mac were running perfectly well. Do not overlook this fundamental requirement. It's important.


Next: This step will prevent the scam products from loading so that they can be removed while they are inactive. Restart in "Safe Mode", and log in: Use safe mode to isolate issues with your Mac. Starting in Safe Mode takes longer than usual so let it finish. The rogue processes affecting that Mac are inoperative in "Safe Mode".


The following files and / or folders need to be deleted while using your Mac in "Safe Mode":


First screenshot:


  • Drag all the files in that folder to the Trash.


Nothing needs to be deleted from the folders in the other two screenshots.


Drag those selections of files to the Trash. You may be asked to authenticate. Confirm they are no longer present in that folder. Leave all the others alone for now.


Next: open Safari and select the Safari menu > Preferences... > Extensions. If you see any Safari Extensions that you do not recognize or understand, simply click the Uninstall button and they will be gone. No Safari Extensions are required for normal operation. Then, select the General pane and review your Homepage selection. Repeat those equivalent actions for any other browser you may use (Brave, Firefox, or Opera for example).


There may also be adware-associated app icons in your Mac's Applications folder. Open it and examine its contents. Any unwanted or mysterious app icons should be obvious to you, but again please don't remove anything if you are uncertain—ask first. Identify any suspicious apps by name, or post another screenshot.


Next: In an abundance of caution, examine System Preferences > Extensions. Determine if there are any System Extensions that may have been installed without your knowledge. Ask if you're uncertain.


Remaining in System Preferences, check for the presence of any Profiles. Profiles are installed by organizations with a need to manage Macs deployed in institutional corporate or educational environments (for example), but have also been exploited by adware creators and similar malcontents. If any Profiles are installed on your Mac an icon like this will appear in System Preferences:



If you see that icon in System Preferences, select it. To remove a Profile, select it, then click the [—] (minus) button and authenticate.


Remaining in System Preferences, open Users & Groups. Select your User Account's Login Items. You may or may not find those Applications in its list. If you do, select them then click the [—] (minus) button to remove them from Login Items.


You can then restart your Mac and log in as usual. Evaluate its operation and ensure everything is working as you expect it should.


Next: if you want to eradicate all remaining adware remnants post a screenshot of the following folder, in the same manner as you did earlier:


~/Library/Application Support


It is normal for that folder to contain many items, but anything associated with the above adware may contain identical names. If you find a folder or folders bearing those names, drag those folders to the Trash. Without the files you already removed or the reintroduction of similar malware, they can do nothing but occupy space. These can be removed if you wish, but again don't remove anything if you are uncertain.


Finally: If any of the above actions result in abnormal operation or if something else stops working, the easiest way to recover would be to restore the Time Machine backup you created as a prerequisite, so the importance of that fundamental step cannot be overemphasized.

May 12, 2023 5:05 PM in response to F.A. Assad

F.A. Assad, please follow the instructions below.



First, ensure you have a reliable backup of your Mac, in case something should go wrong with continued troubleshooting. To learn how to do that, please read Back up your Mac with Time Machine.


  • A backup is a fundamental prerequisite regardless of whatever method you may choose uninstall adware, and would apply even if your Mac were running perfectly well. Do not overlook this fundamental requirement. It's important.


Next: This step will prevent the scam products from loading so that they can be removed while they are inactive. Restart in "Safe Mode", and log in: How to use safe mode on your Mac - Apple Support. Starting in Safe Mode takes longer than usual so let it finish. The rogue processes affecting that Mac are inoperative in "Safe Mode".


The following files and / or folders need to be deleted while using your Mac in "Safe Mode":


First screenshot:



Nothing needs to be deleted from the folders in the other two screenshots.


Drag those selections of files to the Trash. You may be asked to authenticate. Confirm they are no longer present in that folder. Leave all the others alone for now.


Next: open Safari and select the Safari menu > Preferences... > Extensions. If you see any Safari Extensions that you do not recognize or understand, simply click the Uninstall button and they will be gone. No Safari Extensions are required for normal operation. Then, select the General pane and review your Homepage selection. Then, select the Search pane and confirm your desired Search Engine. Repeat those equivalent actions for any other browser you may use (Brave, Firefox, or Opera for example).


There may also be adware-associated app icons in your Mac's Applications folder. Open it and examine its contents. Any unwanted or mysterious app icons should be obvious to you, but again please don't remove anything if you are uncertain—ask first. Identify any suspicious apps by name, or post another screenshot.


Next: In an abundance of caution, examine System Preferences > Extensions. Determine if there are any System Extensions that may have been installed without your knowledge. Ask if you're uncertain.


Remaining in System Preferences, check for the presence of any Profiles. Profiles are installed by organizations with a need to manage Macs deployed in institutional corporate or educational environments (for example), but have also been exploited by adware creators and similar malcontents. If any Profiles are installed on your Mac an icon like this will appear in System Preferences:



If you see that icon in System Preferences, select it. To remove a Profile, select it, then click the [—] (minus) button and authenticate.


Remaining in System Preferences, open Users & Groups. Select your User Account's Login Items. You may or may not find those Applications in its list. If you do, select them then click the [—] (minus) button to remove them from Login Items.


You can then restart your Mac and log in as usual. Evaluate its operation and ensure everything is working as you expect it should.


Next: if you want to eradicate all remaining adware remnants post a screenshot of the following folder, in the same manner as you did earlier:


~/Library/Application Support


It is normal for that folder to contain many items, but anything associated with the above adware may contain identical names. If you find a folder or folders bearing those names, drag those folders to the Trash. Without the files you already removed or the reintroduction of similar malware, they can do nothing but occupy space. These can be removed if you wish, but again don't remove anything if you are uncertain.


Note: The software from "Aviata, Inc" is not directly associated with the "Search Marquis" redirection problem. It appears to be installed as a consequence of installing the Fuji "ScanSnap" software. However, it is not required and has been known to cause undesirable effects in the past with printers or scanners from other manufacturers (example). It is my opinion that anything that does not convey direct, tangible benefits to you as the user of that Mac should be removed. If you have reason to believe otherwise, by all means leave those two files alone.


Finally: If any of the above actions result in abnormal operation or if something else stops working, the easiest way to recover would be to restore the Time Machine backup you created as a prerequisite, so the importance of that fundamental step cannot be overemphasized.

Nov 11, 2023 10:35 AM in response to ashna145

ashna145, please follow the instructions below.



First, ensure you have a reliable backup of your Mac, in case something should go wrong with continued troubleshooting. To learn how to do that, please read Back up your Mac with Time Machine.


  • A backup is a fundamental prerequisite regardless of whatever method you may choose uninstall adware, and would apply even if your Mac were running perfectly well. Do not overlook this fundamental requirement. It's important.


Next: This step will prevent the scam products from loading so that they can be removed while they are inactive. Restart in "Safe Mode", and log in: Use safe mode on your Mac - Apple Support. Starting in Safe Mode takes longer than usual so let it finish. The rogue processes affecting that Mac are inoperative in "Safe Mode".


The following files and / or folders need to be deleted while using your Mac in "Safe Mode":


First screenshot:


  • Drag all the files in that folder to the Trash.


Nothing needs to be deleted from the folders in the other two screenshots.


Drag those selections of files to the Trash. You may be asked to authenticate. Confirm they are no longer present in that folder. Leave all the others alone for now.


Next: open Safari and select the Safari menu > Preferences... (or Settings) > Extensions. If you see any Safari Extensions that you do not recognize or understand, simply click the Uninstall button and they will be gone. No Safari Extensions are required for normal operation. Then, select the General pane and review your Homepage selection. Then, select the Search pane and confirm your desired Search Engine. Repeat those equivalent actions for any other browser you may use (Brave, Firefox, or Opera for example).


There may also be adware-associated app icons in your Mac's Applications folder. Open it and examine its contents. Any unwanted or mysterious app icons should be obvious to you, but again please don't remove anything if you are uncertain—ask first. Identify any suspicious apps by name, or post another screenshot.


Next: In an abundance of caution, examine System Preferences... (or Settings) > Extensions. Determine if there are any System Extensions that may have been installed without your knowledge. Ask if you're uncertain.


Remaining in System Preferences, check for the presence of any Profiles. Profiles are installed by organizations with a need to manage Macs deployed in institutional corporate or educational environments (for example), but have also been exploited by adware creators and similar malcontents. If any Profiles are installed on your Mac an icon like this will appear in System Preferences:



If you see that icon in System Preferences, select it. To remove a Profile, select it, then click the [—] (minus) button and authenticate.


Remaining in System Preferences, open Users & Groups. Select your User Account's Login Items. You may or may not find those Applications in its list. If you do, select them then click the [—] (minus) button to remove them from Login Items.


You can then restart your Mac and log in as usual. Evaluate its operation and ensure everything is working as you expect it should.


Next: if you want to eradicate all remaining adware remnants post a screenshot of the following folder, in the same manner as you did earlier:


~/Library/Application Support


It is normal for that folder to contain many items, but anything associated with the above adware may contain identical names. If you find a folder or folders bearing those names, drag those folders to the Trash. Without the files you already removed or the reintroduction of similar malware, they can do nothing but occupy space. These can be removed if you wish, but again don't remove anything if you are uncertain.


Finally: If any of the above actions result in abnormal operation or if something else stops working, the easiest way to recover would be to restore the Time Machine backup you created as a prerequisite, so the importance of that fundamental step cannot be overemphasized.


Nov 15, 2023 6:29 AM in response to poseidon_123

poseidon_123, please follow the instructions below.



First, ensure you have a reliable backup of your Mac, in case something should go wrong with continued troubleshooting. To learn how to do that, please read Back up your Mac with Time Machine.


  • A backup is a fundamental prerequisite regardless of whatever method you may choose uninstall adware, and would apply even if your Mac were running perfectly well. Do not overlook this fundamental requirement. It's important.


Next: This step will prevent the scam products from loading so that they can be removed while they are inactive. Restart in "Safe Mode", and log in: Use safe mode on your Mac - Apple Support. Starting in Safe Mode takes longer than usual so let it finish. The rogue processes affecting that Mac are inoperative in "Safe Mode".


The following files and / or folders need to be deleted while using your Mac in "Safe Mode":


Third screenshot:



Nothing needs to be deleted from the folders in the other two screenshots.


Drag those selections of files to the Trash. You may be asked to authenticate. Confirm they are no longer present in that folder. Leave all the others alone for now.


Next: open Safari and select the Safari menu > Preferences... (or Settings) > Extensions. If you see any Safari Extensions that you do not recognize or understand, simply click the Uninstall button and they will be gone. No Safari Extensions are required for normal operation. Then, select the General pane and review your Homepage selection. Then, select the Search pane and confirm your desired Search Engine. Repeat those equivalent actions for any other browser you may use (Brave, Firefox, or Opera for example).


There may also be adware-associated app icons in your Mac's Applications folder. Open it and examine its contents. Any unwanted or mysterious app icons should be obvious to you, but again please don't remove anything if you are uncertain—ask first. Identify any suspicious apps by name, or post another screenshot.


Next: In an abundance of caution, examine System Preferences... (or Settings) > Extensions. Determine if there are any System Extensions that may have been installed without your knowledge. Ask if you're uncertain.


Remaining in System Preferences, check for the presence of any Profiles. Profiles are installed by organizations with a need to manage Macs deployed in institutional corporate or educational environments (for example), but have also been exploited by adware creators and similar malcontents. If any Profiles are installed on your Mac an icon like this will appear in System Preferences:



If you see that icon in System Preferences, select it. To remove a Profile, select it, then click the [—] (minus) button and authenticate.


Remaining in System Preferences, open Users & Groups. Select your User Account's Login Items. You may or may not find those Applications in its list. If you do, select them then click the [—] (minus) button to remove them from Login Items.


You can then restart your Mac and log in as usual. Evaluate its operation and ensure everything is working as you expect it should.


Next: if you want to eradicate all remaining adware remnants post a screenshot of the following folder, in the same manner as you did earlier:


~/Library/Application Support


It is normal for that folder to contain many items, but anything associated with the above adware may contain identical names. If you find a folder or folders bearing those names, drag those folders to the Trash. Without the files you already removed or the reintroduction of similar malware, they can do nothing but occupy space. These can be removed if you wish, but again don't remove anything if you are uncertain.


Finally: If any of the above actions result in abnormal operation or if something else stops working, the easiest way to recover would be to restore the Time Machine backup you created as a prerequisite, so the importance of that fundamental step cannot be overemphasized.

Apr 19, 2023 3:47 PM in response to Joebloggs1574

You do not need to download or run anything. Even if you were to do that, it may not work, and then you're stuck with even more potentially harmful junk.


Specific instructions are here: Removing "Search Marquis" / "Search Baron" / etc on your own - Apple Community. At your option capture and post the three screenshots it describes in a reply to this Discussion.

Nov 17, 2023 9:22 AM in response to John Galt

Hi John- Thank you for looking at the screenshots. I followed all the steps above yet when I open safari I am still redirected to search-alpha. Here are updated screenshots of the 3 folders in question. Can you please advise on next steps? I also deleted files from 'application support' that you highlighted in previous comments. Thank you very much.

Safari on my Mac, has been affected by the Search Marquis malware. How can I get rid of it?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.