Related Products Sidebar Malware Adware

So it seems all our macs at home at infected with adware/ malware.


OS 10.11.4


I posted this in Safari, but it also affected Chrome, but not my legacy version of Firefox.


Both MacBooks had different causes but the same symptom, a sidebar pop-up titled "Related Products", also random redirects to a fake Apple Support site, MacKeeper, Expired virus software warnings, etc.


Both Macbook issues were found in LaunchDaemons in:

/Library/LauchDaemons


In my case it was the following:

com.Optibuy.agent.plist

com.SurfBuyer.agent.plist


I also suspect that these are culprits, but unsure:

com.My-Soft-Update.agent.plist

com.My-SoftUpdate.agent.plist

com.MySoftUpdate.agent.plist


NOTE: If you have a lot of Daemons in here, sort by date if your issues started recently, the problematic ones will be dated recently.


User uploaded file

MacBook Pro, OS X El Capitan (10.11.2)

Posted on May 21, 2017 2:02 PM

Reply
21 replies

May 22, 2017 10:59 AM in response to smitsc05

smitsc05 wrote:


Optibuy agent came back - which is infuriating, as it requires a sudo password to delete, you'd think it needed permission to install.


Looks like the above opportunists might be right, time to try an anti-virus solution.

Most AV products are not worth the bytes their coded with. As already suggested in this thread, try Malwarebytes. And no, I don't work for that company, either. Like macjack, I know from years of experience that its reliable, easy to use and has, unlike most AV programs, no negative impact on your system.

May 22, 2017 10:08 PM in response to IdrisSeabright

smitsc05 - you're right it came back for me too - particularly the com.Optibuy.agent.plist - I've been leaving open my /Library/LaunchDaemons and watching it - some how it keeps installing, I found these in console:


5/22/17 7:52:57.265 PM com.apple.xpc.launchd[1]: (com.OptiBuy.agent) Unknown key for string: Version

5/22/17 7:52:57.265 PM com.apple.xpc.launchd[1]: (com.OptiBuy.agent) The EnableGlobbing key is no longer respected. Please remove it.

5/22/17 7:52:57.265 PM com.apple.xpc.launchd[1]: (com.OptiBuy.agent) This service is defined to be constantly running and is inherently inefficient.

5/22/17 7:52:57.265 PM com.apple.xpc.launchd[1]: (com.OptiBuy.agent) This key does not do anything: OnDemand


Doing more research - ugh.

May 24, 2017 5:31 AM in response to TampaWolverine

TampaWolverine wrote:


It just keeps coming back!


Please try removing this using Malwarebytes for Mac, as some of the other folks have suggested. It's a free download, no need to purchase anything.


I'm particularly interested in finding out whether that solves the problem or not, as this is not behavior that I have previously seen with this particular adware (Crossrider). I believe it should, but if it doesn't, please let me know so I can investigate.


Thomas Reed

Director of Mac Offerings, Malwarebytes

May 29, 2017 9:01 AM in response to macjedi117

As Apple CSR suggested, I installed the Malwarebytes and scanned my iMac. I get the message that my system is clean. But in Safari browser, especially when I use Yahoo & Yahoo mail, I still get the Flash update request, automatic redirection to weird websites....Do not know how to solve this issue...Seems like even the Malwarebytes does not work for me

Jun 7, 2017 9:57 AM in response to macjedi117

I went through this Optibuy / MacKeeper / Megabackup agony for 3-4 hours last night. Never happened before on my Mac. Only Chrome was infected, not Safari. I think it all started with a (fake) Flash Update notice. Pretty clever, since one is familiar with the real one popping up occasionally and harmlessly. What is really vicious about this is that if you google these words, you get dozens of results that look like scammer sites that will probably only prolong or worsen the situation. Try searching for optibuy and look at the URLs of the websites that come up. Someone put a great deal of thought into this and acquired a lot of domain names like howtoremove.guide and pcrisk.com and it-help.info etc. etc. almost endlessly. Gresham's law at work on our beautiful internet. Truly sad. I already knew about and trusted Malwarebytes from the Windows world, and that did take care of it. But I had to run it, restart, and run it again a couple of times. It found other junk the first time, and then found optibuy the second time. For those that Malwarebytes did not seem to help, this may be useful. Some of the fake popups are just coming from the fake "help" sites. Close them and don't go there again. It's possible to find a few serious discussions online, but be VERY selective.

Jun 16, 2017 12:11 PM in response to thomas_r.

Hi Thomas,


Could you help me with my problem. Whenever I click a link on chrome or Safari, It opens a new opo-up where the address keeps changing. Some of the instances are:- goodmacfaster.club; spotscenered.info; securefastmac. But all the pages the heading is usually MacKeeper and eventually the pop-up shows another pop-up dialog saying that my mac is infected and requires cleaning and closing the window is not advised.

I have tried every possible solution that is out there. Scanning with malwarebytes has not yielded any result. I have reset Chrome to default settings. Changed the home page address [which strangely was search.conduit.], uninstalled chrome and installed again. Deleted all extensions on both Chrome and Safari. Cleared cache and history. But the problem still persists. Please help me.

Jul 14, 2017 4:18 AM in response to lzafeer

In Malwarebytes, choose Contact Support from the Help menu, and describe the problem in the e-mail. This will send some info privately about what's on your system, and I or someone else at Malwarebytes will take a look. That will let us see if there's something new out there that you might be infected with, or if it's likely to be caused by something else.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Related Products Sidebar Malware Adware

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.