Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.


Hi there,

I bought a new macbook air 2 weeks ago, all has been well and good (new to mac products, always for android, still am).

Safari has also been good, as well as chrome, but as of recently, this whole "MacKeeper", "Zeobit.com" **** is completely taking over my search engines etc, problems including:

- Clean up mac ads everywhere, as well as the typical "Get a new iPhone 5' rubbish

- When clicking on links, my top sites tab shows up as well as the typical "MacKeeper" download page in another. I can only open links by pressing command to open in new tabs, however my top sites tab opens as well as the Mackeeper download page, along with it's fling annoying ads

- Ads as well before relevant google search links, like "Pages related to...." With zeobit.com on every inch of my ******* screen

Note that:

- I HAVE NOT downloaded anything to do with mackeeper, so uninstalling programs etc is unnecessary information - purely mackeeper tab and popup annoyances

- I have TRIED to 'restart' safari and remove cache, nothing works

- I have done the whole system preferences, privacy, remove all website data (which this zeobit.com **** is listed), and I remove zeobit.com but it just goes back on the list when I go through this process again

- Yes I have 'block popup ads' ticked

Can someone give me a solution to removing these popups with anything to do with zeobit.com and fling mackeeper which doesn't require me to read a long page of information? I'm about to smash my screen in here.

Posted on Jul 10, 2014 4:48 AM

341 replies

Jan 12, 2015 8:13 AM in response to chickashnaz

I have tried the things given in this thread, but no luck. so i began digging in the settings of my macbook. I had downloaded the Adware Media program and scanned my pc, found some result the the problem kept existing.

When looking at the DNS server i noticed something weird. There was a third DNS-number entered. (from what i know about it there are allways 2) I clicked on the ( + ) symbol to add my own DNS-servers, i added the google-DNS ( and and clicked apply.

Now i dont have the anoying tab-popups anymore. Its not a perfect fix but it works for me (for now) The virus/malware is still on my computer (or server at work) but it doesn't affect me anymore. Really hate this kind of stuff and hope that the people behind that rdsrv - virus/malware get a taste of their own medicine

Hopes this helps some other people to 🙂

Jan 13, 2015 4:19 AM in response to Repsac11

Dear Linc

This is an amazing piece of work you did, but unfortunately it did not work for me. The first step didn't open -

"Triple-click anywhere in the line below on this page to select it:


Right-click or control-click the line and select

Services Reveal in Finder (or just Reveal)

from the contextual menu.* A folder should open with an item selected. Drag the selected item to the Trash. You may be prompted for your administrator login password."

And nor did the asterisked variation:

"*If you don't see the contextual menu item, copy the selected text to the Clipboard by pressing the key combination command-C. In the Finder, select

Go Go to Folder...

from the menu bar and paste into the box that opens by pressing command-V. You won't see what you pasted because a line break is included. Press return."

I looked through the rest of your advice, and couldn't find any other way of getting started.

Eventually I downloaded the AdwareMedic software - which was free - and so far it appears to have worked, and stopped the infernal pop-ups.

I believe my machine may have been infected when I tried downloading a couple of pieces of software which enable you to download videos or audio tracks from YouTube. There was something a bit suspicious about one of them - I will be (much) more careful next time.

Best regards.

Jan 13, 2015 12:08 PM in response to thomas_r.

made an account on here just to thank you for your amazing program. my computer is running much faster, all ads are GONE, and my old macbook pro is even running at a considerably lower temperature. I will definitely be donating-- thanks so much! Highly recommended, everyone-- cleared up my mackeeper/detox my mac issues with one quick scan, removal, and restart!

Jan 13, 2015 5:21 PM in response to Linc Davis

Can you please give me any help?

Start time: 19:09:07 01/13/15

Model Identifier: MacBookAir6,2

System Version: OS X 10.10.1 (14B25)

Kernel Version: Darwin 14.0.0

Time since boot: 23:17

Diagnostic reports

2014-12-17 com.apple.WebKit.Plugin.64 crash

2015-01-04 discoveryd crash

2015-01-08 discoveryd crash


Jan 7 22:25:44 PM notification timeout (pid 160, com.apple.ifdrea)

Jan 8 17:57:05 PM notification timeout (pid 160, com.apple.ifdrea)

Jan 8 18:15:06 PM notification timeout (pid 160, com.apple.ifdrea)

Jan 8 18:57:00 PM notification timeout (pid 160, com.apple.ifdrea)

Jan 8 23:40:50 PM notification timeout (pid 160, com.apple.ifdrea)

Jan 9 02:06:32 PM notification timeout (pid 160, com.apple.ifdrea)

Jan 9 17:29:46 PM notification timeout (pid 160, com.apple.ifdrea)

Jan 9 20:36:06 PM notification timeout (pid 160, com.apple.ifdrea)

Jan 10 02:29:02 PM notification timeout (pid 160, com.apple.ifdrea)

Jan 10 03:14:46 PM notification timeout (pid 160, com.apple.ifdrea)

Jan 10 13:26:20 process com.apple.WebKit[6805] caught causing excessive wakeups. EXC_RESOURCE supressed due to audio playback

Jan 11 21:36:26 PM notification timeout (pid 160, com.apple.ifdrea)

Jan 11 21:45:04 PM notification timeout (pid 160, com.apple.ifdrea)

Jan 11 22:01:14 PM notification timeout (pid 160, com.apple.ifdrea)

Jan 11 22:41:30 PM notification timeout (pid 160, com.apple.ifdrea)

Jan 12 19:52:11 com.apple.iTunesHelper.50584: Service exited with abnormal code: 1

Jan 12 19:52:40 com.apple.xpc.launchd.domain.pid.om.apple.photostream-agent.260: Path not allowed in target domain: type = pid, path = /Applications/iPhoto.app/Contents/Frameworks/PhotoFoundation.framework/Versions /A/XPCServices/com.apple.PhotoApps.DevicePropertyReader.xpc error = 147: The specified service did not ship in the requestor's bundle, origin = /Applications/iPhoto.app/Contents/Library/LoginItems/PhotoStreamAgent.app

Jan 12 19:52:40 com.apple.xpc.launchd.domain.pid.om.apple.photostream-agent.260: Path not allowed in target domain: type = pid, path = /Applications/iPhoto.app/Contents/Frameworks/PhotoFoundation.framework/Versions /A/XPCServices/com.apple.PhotoApps.DevicePropertyReader.xpc error = 147: The specified service did not ship in the requestor's bundle, origin = /Applications/iPhoto.app/Contents/Library/LoginItems/PhotoStreamAgent.app

Jan 13 18:43:31 com.zeobit.MacKeeper.Helper: Service setup event to handle failure and will not launch until it fires.

Jan 13 19:05:14 com.apple.xpc.launchd.domain.pid.quicklookd.725: Path not allowed in target domain: type = pid, path = /Library/Frameworks/iTunesLibrary.framework/Versions/A/XPCServices/com.apple.iT unesLibraryService.xpc error = 147: The specified service did not ship in the requestor's bundle, origin = /System/Library/Frameworks/QuickLook.framework/Versions/A/Resources/quicklookd. app

Swap (MiB): 1199












/Library/Internet Plug-Ins/AdobePDFViewer.plugin

- com.adobe.acrobat.pdfviewer

/Library/Internet Plug-Ins/AdobePDFViewerNPAPI.plugin

- com.adobe.acrobat.pdfviewerNPAPI

/Library/Internet Plug-Ins/Flash Player.plugin

- N/A

/Library/PreferencePanes/Flash Player.prefPane

- com.adobe.flashplayerpreferences



Contents of /Library/LaunchAgents/com.heizenberg.agent.plist (checksum 603885961)

<?xml version="1.0" encoding="UTF-8"?>

<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

<plist version="1.0">








<string>/Library/Application Support/heizenberg/Agent/agent.app/Contents/MacOS/agent</string>












Contents of /Library/LaunchDaemons/com.heizenberg.daemon.plist (checksum 718796932)

<?xml version="1.0" encoding="UTF-8"?>

<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

<plist version="1.0">










<string>/Library/Application Support/heizenberg/Agent/agent.app/Contents/MacOS/agent</string>











Contents of /Library/LaunchDaemons/com.heizenberg.helper.plist (checksum 3051251653)

<?xml version="1.0" encoding="UTF-8"?>

<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

<plist version="1.0">








<string>/Library/Application Support/heizenberg/Agent/agent.app/Contents/MacOS/agent</string>











Contents of Library/LaunchAgents/com.adobe.ARM.UUID.plist (checksum 394026997)

<?xml version="1.0" encoding="UTF-8"?>

<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

<plist version="1.0">






<string>/Applications/Adobe Reader.app/Contents/MacOS/Updater/Adobe Reader Updater Helper.app/Contents/MacOS/Adobe Reader Updater Helper</string>









Contents of Library/LaunchAgents/com.google.keystone.agent.plist (checksum 3955816640)

<?xml version="1.0" encoding="UTF-8"?>

<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

<plist version="1.0">








<string>/Users/USER/Library/Google/GoogleSoftwareUpdate/GoogleSoftwareUpdate.bu ndle/Contents/Resources/GoogleSoftwareUpdateAgent.app/Contents/MacOS/GoogleSoftw areUpdateAgent</string>














Contents of Library/LaunchAgents/com.spotify.webhelper.plist (checksum 3937736025)

<?xml version="1.0" encoding="UTF-8"?>

<!DOCTYPE plist PUBLIC "-//Apple Computer//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

<plist version="1.0">












<string>/Users/USER/Library/Application Support/Spotify/SpotifyWebHelper</string>





link auth: wpa-psk

User login items


- /Applications/iTunes.app/Contents/MacOS/iTunesHelper.app


- /Applications/Adobe Reader.app/Contents/Support/AdobeResourceSynchronizer.app

Restricted files: 46

Elapsed time (s): 175

Jan 13, 2015 7:12 PM in response to StormTheCastle

You installed a variant of the "VSearch" trojan. Remove it as follows.

This malware has many variants. Anyone else finding this comment should not expect it to be applicable.

Back up all data before proceeding.

Triple-click anywhere in the line below on this page to select it:


Right-click or control-click the line and select

Services Reveal in Finder (or just Reveal)

from the contextual menu.* A folder should open with an item selected. Drag the selected item to the Trash. You may be prompted for your administrator login password.

Repeat with each of these lines:


Restart the computer and empty the Trash. Then delete the following items in the same way:

/Library/Application Support/heizenberg

The problem may have started when you downloaded and ran an application called "MPlayerX." That's the name of a legitimate free movie player, but the name is also used fraudulently to distribute VSearch. If there is an item with that name in the Applications folder, delete it, and if you wish, replace it with the genuine article from mplayerx.org.

This trojan is often found on illegal websites that traffic in pirated content such as movies. If you, or anyone else who uses the computer, visit such sites and follow prompts to install software, you can expect more of the same, and worse, to follow. Never install any software that you downloaded from a bittorrent, or that was downloaded by someone else from an unknown source.

In the Security & Privacy pane of System Preferences, select the General tab. The radio button marked Anywhere should not be selected. If it is, click the lock icon to unlock the settings, then select one of the other buttons. After that, don't ignore a warning that you are about to run or install an application from an unknown developer.

Then, still in System Preferences, open the App Store or Software Update pane and check the box marked

Install system data files and security updates (OS X 10.10 or later)


Download updates automatically (OS X 10.9 or earlier)

if it's not already checked.

*If you don't see the contextual menu item, copy the selected text to the Clipboard by pressing the key combination command-C. In the Finder, select

Go Go to Folder...

from the menu bar and paste into the box that opens by pressing command-V. You won't see what you pasted because a line break is included. Press return.

Jan 13, 2015 11:31 PM in response to Linc Davis

Thanks, Linc.

Here is the log after running the scripts.

Start time: 23:15:46 01/13/15

Model Identifier: MacBookAir6,2

System Version: OS X 10.9.5 (13F34)

Kernel Version: Darwin 13.4.0

Time since boot: 13 days 8:18


Jan 7 22:23:17 com.apple.aslmanager: Throttling respawn: Will start in 8 seconds

Jan 7 22:28:16 disk logger: failed to open output file /Volumes/Seagate Expansion Drive/.fseventsd/fc00759d4409e9ab (No such file or directory). mount point /Volumes/Seagate Expansion Drive/.fseventsd

Jan 7 22:28:16 disk logger: failed to open output file /Volumes/Seagate Expansion Drive/.fseventsd/fc00759d4409e9ab (No such file or directory). mount point /Volumes/Seagate Expansion Drive/.fseventsd

Jan 9 20:38:42 com.apple.newsyslog: Throttling respawn: Will start in 2 seconds

Jan 9 20:38:42 com.apple.logsyswritesd: Throttling respawn: Will start in 2 seconds

Jan 9 20:38:42 com.apple.bsd.dirhelper: Throttling respawn: Will start in 2 seconds

Jan 9 20:38:49 com.apple.aslmanager: Throttling respawn: Will start in 3 seconds

Jan 9 23:30:00 com.apple.newsyslog: Throttling respawn: Will start in 10 seconds

Jan 10 08:29:03 com.apple.newsyslog: Throttling respawn: Will start in 5 seconds

Jan 10 17:49:18 com.apple.newsyslog: Throttling respawn: Will start in 5 seconds

Jan 10 18:00:31 process com.apple.WebKit[3937] caught causing excessive wakeups. Observed wakeups rate (per sec): 184; Maximum permitted wakeups rate (per sec): 150; Observation period: 300 seconds; Task lifetime number of wakeups: 80048

Jan 10 18:38:15 process com.apple.WebKit[4072] caught causing excessive wakeups. EXC_RESOURCE supressed due to audio playback

Jan 10 22:39:13 com.apple.newsyslog: Throttling respawn: Will start in 5 seconds

Jan 11 00:47:25 process com.apple.WebKit[4197] caught causing excessive wakeups. Observed wakeups rate (per sec): 229; Maximum permitted wakeups rate (per sec): 150; Observation period: 300 seconds; Task lifetime number of wakeups: 100876

Jan 11 18:52:52 com.apple.newsyslog: Throttling respawn: Will start in 5 seconds

Jan 11 19:12:36 process com.apple.WebKit[4560] caught causing excessive wakeups. Observed wakeups rate (per sec): 168; Maximum permitted wakeups rate (per sec): 150; Observation period: 300 seconds; Task lifetime number of wakeups: 185009

Jan 11 23:53:53 process com.apple.WebKit[4626] thread 576487 caught burning CPU! It used more than 50% CPU (Actual recent usage: 60%) over 180 seconds. thread lifetime cpu usage 279.974460 seconds, (214.784328 user, 65.190132 system) ledger info: balance: 90004849325 credit: 277041175240 debit: 187036325915 limit: 90000000000 (50%) period: 180000000000 time since last refill (ns): 147998454900

Jan 12 00:22:23 IOPPF: Sent cpu-plimit-notification last value 4 (rounded time weighted average 4)

Jan 12 20:54:19 com.apple.aslmanager: Throttling respawn: Will start in 5 seconds

Jan 12 23:39:47 process com.apple.WebKit[4879] thread 602487 caught burning CPU! It used more than 50% CPU (Actual recent usage: 86%) over 180 seconds. thread lifetime cpu usage 610.931698 seconds, (513.168999 user, 97.762699 system) ledger info: balance: 90005221141 credit: 586106481220 debit: 496101260079 limit: 90000000000 (50%) period: 180000000000 time since last refill (ns): 104488723935

Jan 12 23:39:49 process com.apple.WebKit[4879] caught causing excessive wakeups. Observed wakeups rate (per sec): 3482; Maximum permitted wakeups rate (per sec): 150; Observation period: 300 seconds; Task lifetime number of wakeups: 2230033

Jan 13 00:00:05 com.apple.aslmanager: Throttling respawn: Will start in 5 seconds

Jan 13 01:41:45 process com.apple.WebKit[5150] caught causing excessive wakeups. Observed wakeups rate (per sec): 257; Maximum permitted wakeups rate (per sec): 150; Observation period: 300 seconds; Task lifetime number of wakeups: 54199

Jan 13 20:28:10 com.apple.newsyslog: Throttling respawn: Will start in 4 seconds

Jan 13 22:35:43 process com.apple.WebKit[5370] caught causing excessive wakeups. Observed wakeups rate (per sec): 224; Maximum permitted wakeups rate (per sec): 150; Observation period: 300 seconds; Task lifetime number of wakeups: 90687

Swap (MiB): 10453









/Applications/CoronaSDK/Corona Simulator.app

- com.coronalabs.Corona_Simulator


- org.niltsh.MPlayerX

/Applications/Utilities/Adobe Flash Player Install Manager.app

- com.adobe.flashplayer.installmanager


- com.icopybot.ibackupbot

/Library/Application Support/bingo/Agent/agent.app

- com.someproduct.agent


- net.washboardabs.boxer



- null


/Library/PreferencePanes/Flash Player.prefPane

- com.adobe.flashplayerpreferences


/Library/Internet Plug-Ins/Flash Player.plugin

- com.macromedia.Flash



Contents of /Library/LaunchAgents/com.bingo.agent.plist

- mod date: Dec 28 10:38:59 2014

- checksum: 2345383136

<?xml version="1.0" encoding="UTF-8"?>

<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

<plist version="1.0">








<string>/Library/Application Support/bingo/Agent/agent.app/Contents/MacOS/agent</string>












Contents of /Library/LaunchDaemons/com.bingo.daemon.plist

- mod date: Dec 28 10:38:59 2014

- checksum: 4070751674

<?xml version="1.0" encoding="UTF-8"?>

<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

<plist version="1.0">










<string>/Library/Application Support/bingo/Agent/agent.app/Contents/MacOS/agent</string>











Contents of /Library/LaunchDaemons/com.bingo.helper.plist

- mod date: Dec 28 10:38:59 2014

- checksum: 3649463980

<?xml version="1.0" encoding="UTF-8"?>

<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

<plist version="1.0">








<string>/Library/Application Support/bingo/Agent/agent.app/Contents/MacOS/agent</string>











DNS: (static)

User login items


- /Applications/iTunes.app/Contents/MacOS/iTunesHelper.app

Restricted files: 209

Lockfiles: 4

Elapsed time (s): 236

Jan 13, 2015 11:41 PM in response to Mrbeandaddy

You installed a variant of the "VSearch" trojan. Remove it as follows.

This malware has many variants. Anyone else finding this comment should not expect it to be applicable.

Back up all data before proceeding.

Triple-click anywhere in the line below on this page to select it:


Right-click or control-click the line and select

Services Reveal in Finder (or just Reveal)

from the contextual menu.* A folder should open with an item selected. Drag the selected item to the Trash. You may be prompted for your administrator login password.

Repeat with each of these lines:


Restart the computer and empty the Trash. Then delete the following items in the same way:

/Library/Application Support/bingo

The problem may have started when you downloaded and ran an application called "MPlayerX." That's the name of a legitimate free movie player, but the name is also used fraudulently to distribute VSearch. If there is an item with that name in the Applications folder, delete it, and if you wish, replace it with the genuine article from mplayerx.org.

This trojan is often found on illegal websites that traffic in pirated content such as movies. If you, or anyone else who uses the computer, visit such sites and follow prompts to install software, you can expect more of the same, and worse, to follow. Never install any software that you downloaded from a bittorrent, or that was downloaded by someone else from an unknown source.

In the Security & Privacy pane of System Preferences, select the General tab. The radio button marked Anywhere should not be selected. If it is, click the lock icon to unlock the settings, then select one of the other buttons. After that, don't ignore a warning that you are about to run or install an application from an unknown developer.

Then, still in System Preferences, open the App Store or Software Update pane and check the box marked

Install system data files and security updates (OS X 10.10 or later)


Download updates automatically (OS X 10.9 or earlier)

if it's not already checked.

*If you don't see the contextual menu item, copy the selected text to the Clipboard by pressing the key combination command-C. In the Finder, select

Go Go to Folder...

from the menu bar and paste into the box that opens by pressing command-V. You won't see what you pasted because a line break is included. Press return.

Jan 14, 2015 5:12 AM in response to h1r23

h1r23 wrote:

Linc, do you have an updated solution as this no longer works?

The problem is, Linc's directions only work for people who have a specific variant of this adware installed, and requires each individual to wait for a personal response from him.

Try my Adware Removal Guide instead. This should help you remove the adware on your own, and if it doesn't, just e-mail me or post back here.

(Fair disclosure: I may receive compensation from links to my sites, TheSafeMac.com and AdwareMedic.com, in the form of buttons allowing for donations. Donations are not required to use my site or software.)

Jan 14, 2015 7:24 AM in response to chickashnaz

A feature you will come to love for preventing tricky malware downloads is 'Force Quit' under the Apple menu.

The only way to prevent malware is to use the 'Force Quit' when MacClean and the like pop up.

And most of us know what sites have them, so.......snicker.

You have some malware now, most likely, from clicking either Yes or Cancel from one of those popups.

They are designed to download with either click, so again, go straight to 'Force Quit' when they present.

So, as sugessted, get a good virus protection program and run it....every day.

My personal choice is ClamXav. Shareware


Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.