Apple Event: May 7th at 7 am PT

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Zeobit Mackeeper Vsearch Pop Up Browser Hijack

Ok, after spending about 2 days figuring out to get my browsers back, I say that because both Safari and Chrome were rendered unusable by this 'virus'. My searches where hijacked, pop up videos and ads were appearing out of no where and of course Mackeeper popped up every time I tried to open a new page. As a side note the people who run Mackeeper need a **** punch of epic proportions for the crap they pull. Feeling absolutely powerless because someone hijacked your computer is downright evil. These Mackeeper Terrorists all need to get *** cancer and die.


But I digress. I believe I figured out a relatively simple solution to this problem, but before I get started I just want to say that too many responses I got from my earlier inquires were from people who had a lot of knowledge about macs unfortunately they didn't know how to communicate that knowledge. When trying to help people please try to dumb things down as much as possible which is what I'm going to try and do right now.


What I did to get rid of this nasty little 'virus' is to first download the app EasyFind https://itunes.apple.com/us/app/easyfind/id411673888?mt=12

from the apple app store. Since you are downloading it from the Apple Store you know it's safe. There are so many 'recommendations' for programs to help with this problem that actually make things worse. Call me paranoid but I think people working for some of these unethical companies post to the support sites in order to push people to them whether or not their program helps or not.


EasyFind is the same as the Finder program already on your Mac. The difference between the two however is that EasyFind does a much better job finding files hidden files. Finder did not and will not find the files you need to delete. Manual searching also won't work or will just take too much time. You also want to make sure that you get rid of every single one of these files otherwise you might not solve the problem completely.


Before starting EasyFinder shut down everything and close all browsers. After Opening EasyFind you will get a search type window. Below the magnifying glass near the top right you will choose where you want to search. I chose to search the entire hard drive which should be for obvious reasons. On the left hand side of EasyFind below 'Search For:' choose 'Files and Folders', 'Any Word', 'Ignore case', 'Package content', and finally 'Invisible Files and Folders'.


It seems that previously the files you needed to be concerned about were zeobit, or mackeeper files, however the file name that was giving me the trouble was 'vsearch' files. My browser was being directed to zeobit and mackeeper even though my EasyFind search came up with no zeobit or mackeeper files or apps. I would still recommend you search for all three files since it's easy to do and it won't hurt.


Once you run your search you will get numerous files, some you don't want to delete however. For example I had 'Pvsearch' files which have nothing to do with this problem. Since the search parameters are very loose other files are bound to come up but I would rather have more than miss files that need to be deleted.

I recommend sending to the trash any file you find in the search that has zeobit, Mackeeper or vsearch on the line. Just don't delete other files with similar names. For example library/launchagent/vsearch you want to send to trash, however don't trash library/launchagent/pvsearch...... EasyFind will also allow you to view the file in Finder. You can always use that to check when the file was added to your computer. If would just added then likely it's a file you want to get rid of.


Easyfind has two file removal options. You and either send to the trash or 'Destroy' the file. It's likely that Destroy won't work so just move all the files to the trash. You may also have to give administrator password when trashing these files depending on you security settings. Once in the trash I suggest using the 'Secure Empty Trash' option to get rid of the files instead of simply just emptying the trash. This is because when you hit empty trash you may get a alert that says certain files cannot be deleted because they are in use or the need another file, etc.... That's part of the reason I suggest closing all programs, but even after closing all programs there were still files I could simply get rid of by emptying the trash. I had to choose the Secure Empty Trash option in order to delete them.


That's pretty much it. I would ask for feedback, there may be things that I missed however my browsers are working perfect again. It doesn't hurt to go into your browser preferences and press the reset to browser defaults option, however I'm not sure if that is a must. I actually did that before I deleted all these files and it didn't help at all. I suppose if you do what I tell you and you are still having issues you may want to try that to see if it helps. I would just ask that you come back here and let me know if resetting your browser preferences to default was needed so I can update my recommendations.


I really hoped this helped, I know how frustrating and time consuming these problems can be especially for people who don't know a lot about computers.


T

MacBook Air, OS X Mavericks (10.9.4)

Posted on Aug 31, 2014 12:27 AM

Reply
29 replies

Aug 31, 2014 9:06 PM in response to TildeBee

I'm sorry that some of you got the impression that I didn't trust Thomas or his site. What I was stating earlier on in this thread was the fact that for people who don't know a lot about these things it's hard to tell who to trust and who not to trust. Based on everything I've now heard I have 100% confidence in Thomas's website and the product he sells, however he is the exception to the rule.


Like the old saying goes, "***, gas, or grass, no one rides for free...." Anytime I get an offer for something that's free I ask myself Why??

Is the product that crappy that it's not worth anything?? Are they trying to steal or farm my information by getting their foot into the door of my computer??

Regardless, there is almost always a catch.


That's really why Thomas should be charging something for his work even if it's nominal like $5 bucks. We tend to devalue things that are free whether or not they are good, and so people who don't know Thomas will think that his program can't work because it's free.


My point about getting things from the App store is based on the fact that the vast majority of people are computer illiterate to say the least. Even people such as myself who know a few things still don't posses the knowledge that you and your collegues have. Knowing who to trust on the internet is tough therefore these people including myself are better off sticking to the app store for things. The likely hood of malware or getting ripped off are extremely small. The downside is that there might be better non App Store programs, but trading security and safety for performance is a tradeoff that for many people is acceptable.

Sep 1, 2014 1:53 AM in response to tandrewsdds

Anytime I get an offer for something that's free I ask myself Why??

In Thomas' case the 'why' is because he is passionate about all things Mac, and he wants to protect the Mac environment, and it's users - from the under belly of this world. He does a great job of it, and asks nothing in return. I applaud him.

I also applaud your philosophy of not trusting anything until it's proven it's worth. Good on you! And keep asking "why"!

Oct 10, 2014 12:39 PM in response to tandrewsdds

For years I thought Mackeeper would help. I didn't have much trouble until today when got infected by so much ad malware. I renewed my Mackeeper account and problem remained. Then I found this article, got easyfind, cleared out all zeobit, mackeeper, and pvsearch files and my Mac is now running better than I can remember.


Of course, I've also written a message to contact@detoxmymac.com:

"In reference to https://discussions.apple.com/thread/6513611 I've realized that Mackeeper is part of the problem I've had all along thinking your product was helping me. I can't believe that after I just cleaned out and destroyed all Mackeeper files my Mac now runs and displays my typing REAL TIME - you're product was ruining my Mac's performance and my time and productivity.

I demand a refund for orders: CP2XVE74 and BL5LQYWE. I will dispute if necessary. I have posted this testimony at the link I've provided."

Oct 31, 2014 11:50 AM in response to vrwired

vrwired wrote:


For years I thought Mackeeper would help. I didn't have much trouble until today when got infected by so much ad malware. I renewed my Mackeeper account and problem remained. Then I found this article, got easyfind, cleared out all zeobit, mackeeper, and pvsearch files and my Mac is now running better than I can remember.


Mackeeper has absolutely nothing to do with malware and vsearch. We have carefully examined the case described in this thread. Mackeeper application (as many others) uses Safari's engine. Most likely the reason for this are third-party browser toolbars which are in come cases not authorized and contain adware (most people are not even aware of such installs).



Of course, I've also written a message to ******

"In reference to https://discussions.apple.com/thread/6513611 I've realized that Mackeeper is part of the problem I've had all along thinking your product was helping me. I can't believe that after I just cleaned out and destroyed all Mackeeper files my Mac now runs and displays my typing REAL TIME - you're product was ruining my Mac's performance and my time and productivity.

I demand a refund for orders: CP2XVE74 and BL5LQYWE. I will dispute if necessary. I have posted this testimony at the link I've provided."

Why have you sent this message to Detoxmymac instead of solving this issue directly with dedicated Mackeeper support personnel or contacting ******? This statement is based on pure assumptions and false claims. Please contact me immediately using this email in order to solve this problem and discontinue this conduct.

<Edited by Host>

Nov 23, 2014 8:03 PM in response to mailhelp

mailhelp wrote:


I Did get the easy find app, but after finding the files, I was not able to delete them. It just doos not delete.

You must be logged in to an admin account in order to remove the files. And you won't be able to empty the trash until you reboot.


The fastest, most effective way to identify and optionally remove all currently known adware is by using AdwareMedic, developed by thomas_r. this Forum's malware guru, owner of TheSafeMac and a colleague of mine.


If it turns out to be the Downlite adware, then they have managed to block your access to that site and you will need to use an alternate technique as described in About the Downlite adware.

Nov 24, 2014 3:35 AM in response to tandrewsdds

tandrewsdds wrote:


I'm sorry that some of you got the impression that I didn't trust Thomas or his site. What I was stating earlier on in this thread was the fact that for people who don't know a lot about these things it's hard to tell who to trust and who not to trust.


I didn't see this back when it was active - at that time, I was working frantically on AdwareMedic and spending no time here. Hopefully you'll still see my response here, but if not, perhaps my response can clarify something for others who may be thinking the same things.


I just wanted to chime in and say you're absolutely right! Trust is a difficult thing to achieve online, and it absolutely should not be given away. It must be earned. I'm very thankful for all the folks who have posted in support of me, but if it weren't for them, I'd just be another anonymous stranger online. It's for this reason that I also provide manual removal instructions. Those can be used to remove everything that my software would remove.


Of course, there are other sites that provide manual removal instructions in conjunction with some kind of scam removal software. This is mostly in the Windows world, as I'm not actually aware of any other full-fledged adware removal programs for the Mac. But, it certainly does make things difficult in this arena. Thus the importance of checking out your source thoroughly before downloading anything.


Anytime I get an offer for something that's free I ask myself Why??

[...]

That's really why Thomas should be charging something for his work even if it's nominal like $5 bucks.


Well, you make some good points there. However, to me, it's important to keep it free so that everyone can use it. I have provided assistance to people here since 2006. I started The Safe Mac about a year ago with the same philosophy, after running the blog from my personal domain for several years before that. Keeping Mac users safe from malware, adware and other security issues is important to me. Unfortunately, without some form of payments, I was going to have to seriously scale back on that less than a year from now, for financial reasons. Thus the donations.


There are problems with keeping it freeware or "donationware", but there are also problems with charging for things. If I charge for adware removal, for example, I could easily come off like the MacKeeper folks, who show you all kinds of scary "problems" with your Mac and then make you buy the software to fix those problems. In addition, charging for the software can cause folks to question my motivations. Even with the "donationware" model, I've had a couple long-time participants here question my motivations and accuse me of profiting from other people's misfortunes. Imagine how that perception would expand if I required people to pay to remove the adware!


Long story short, I know that I undoubtedly could charge for the software, but keeping it free is important to me for a variety of reasons, and I feel it's the best option.


My point about getting things from the App store [...]


I agree with you, I'd like for my software to be available in the App Store. Unfortunately, the old Adware Removal Tool that you were referring to and my current AdwareMedic app simply cannot be in the App Store. Due to sandboxing restrictions imposed on App Store apps, these programs simply would not have been able to do their jobs. They need to be able to look in - and remove files from - dark corners of the system where App Store apps are not allowed to go.

Zeobit Mackeeper Vsearch Pop Up Browser Hijack

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.