How can I remove the searchbaron virus from chrome?

Joined
Jan 8, 2021
Messages
23
Reaction score
0
Points
1
Hi everyone,

I have this dreaded searchbaron virus and cant get rid of it.I have reset the browser, used cleanmymac and malwarebytes to no avail.I have found no suspicious looking apps.The free version of combocleaner found 4 infected files (see sceenshot) but I am not sure if they are the culprit, maybe someone does..?Not looking to but another cleaner that wont do the job...

Also, I cant remove the searchbaron file

tp://www.searchbaron.com/v1/hostedsearch?aid=&data=aWlkPTIyJnVpZD0xNTIzNzEwNjk=&sto=1&keyword=%s (outdated link removed)

from the default browser (see screenshot) but can edit it, possibly someone would know what to replace it with..?

Thanks to all for your time and effort and happy new year!
 

Attachments

  • Screen Shot 2021-01-08 at 05.06.03.png
    Screen Shot 2021-01-08 at 05.06.03.png
    106.1 KB · Views: 30
  • Screen Shot 2021-01-08 at 05.08.01.png
    Screen Shot 2021-01-08 at 05.08.01.png
    32.1 KB · Views: 25

chscag

Well-known member
Staff member
Admin
Joined
Jan 23, 2008
Messages
65,248
Reaction score
1,833
Points
113
Location
Keller, Texas
Your Mac's Specs
2017 27" iMac, 10.5" iPad Pro, iPhone 8, iPhone 11, iPhone 12 Mini, Numerous iPods, Monterey
Welcome to our forums.

Read the following article and follow directions:

 
OP
T
Joined
Jan 8, 2021
Messages
23
Reaction score
0
Points
1
Btw, I ran cleanmymac several times and it did not remove the malware..is that program overrated?
 

chscag

Well-known member
Staff member
Admin
Joined
Jan 23, 2008
Messages
65,248
Reaction score
1,833
Points
113
Location
Keller, Texas
Your Mac's Specs
2017 27" iMac, 10.5" iPad Pro, iPhone 8, iPhone 11, iPhone 12 Mini, Numerous iPods, Monterey
Yes, Clean My Mac 2 and previous versions are overrated in our opinion. The app does what your Mac already does during sleeping hours. Besides that, the OnyX app is free and provides most of what CMM does.

As for getting rid of the malware you have, try the free version of "DetectX Swift":


Also the free version of VirusBarrier Scanner which you can find in the Mac App Store:

 
OP
T
Joined
Jan 8, 2021
Messages
23
Reaction score
0
Points
1
Thanks for the info, I am installing Mac internet security x9 but the installation seems to be stuck on running package scripts for an hour indicating it will take only one more minute, is this normal?
 

IWT


Joined
Jan 23, 2009
Messages
10,290
Reaction score
2,230
Points
113
Location
Born Scotland. Worked all over UK. Live in Wales
Your Mac's Specs
M2 Max Studio Extra, 32GB memory, 4TB, Sonoma 14.4.1 Apple 5K Retina Studio Monitor
is this normal?

No; it's not. In the past, I've use the full paid-for system and it always installed within a minute or two. As this is the "lightweight" version, it should install almost instantaneously. Something is awry.

I cannot identify the problem, but I am concerned that you've used "Clean My Mac" "several times". This can cause issues at all levels on the Mac. I'm not saying it did, only that it is well known that it can.

Perhaps you could try aborting the installation, then remove any remnants of it and try again.

Ian
 
OP
T
Joined
Jan 8, 2021
Messages
23
Reaction score
0
Points
1
I cant use the uninstaller and have the software mounted in my top display but its not in the application folder so I dont know where to look for it to erase it! Any help?
 
OP
T
Joined
Jan 8, 2021
Messages
23
Reaction score
0
Points
1
Now I get the picture below for 20 minutes but the blue ray is moving...
 

Attachments

  • Screen Shot 2021-01-09 at 00.48.05.png
    Screen Shot 2021-01-09 at 00.48.05.png
    95.5 KB · Views: 32

Rod


Joined
Jun 12, 2011
Messages
9,703
Reaction score
1,891
Points
113
Location
Melbourne, Australia and Ubud, Bali, Indonesia
Your Mac's Specs
2021 M1 MacBook Pro 14" macOS 14.4.1, Mid 2010MacBook 13" iPhone 13 Pro max, iPad 6, Apple Watch SE.
Maybe it could cause problems running the apps concerned but the operating system is more relevant, you don't say what macOS you have or which browser you are using.
CMM is not very good at removing malware, its really just window dressing. If the automated removal apps fail for whatever reason you can always just search for the components of searchbaron and remove them manually. EasyFind is a good free search app for that purpose.
If you are using a third party browser like Firefox or Chrome you could just delete it and reinstall. I have had success with that method in the past and it's one of the reasons I don't use Safari as my primary browser.
 
OP
T
Joined
Jan 8, 2021
Messages
23
Reaction score
0
Points
1
Ok, I was able to install virus barrier, scanned my macbook, found and deleted 42 infected files but searchbaron ist still there...I am using mac os 10.11.6 and chrome 87.0.4280.88
 
OP
T
Joined
Jan 8, 2021
Messages
23
Reaction score
0
Points
1
Maybe it could cause problems running the apps concerned but the operating system is more relevant, you don't say what macOS you have or which browser you are using.
CMM is not very good at removing malware, its really just window dressing. If the automated removal apps fail for whatever reason you can always just search for the components of searchbaron and remove them manually. EasyFind is a good free search app for that purpose.
If you are using a third party browser like Firefox or Chrome you could just delete it and reinstall. I have had success with that method in the past and it's one of the reasons I don't use Safari as my primary browser.

I now installed easyfind, what file names should I look for? searchbaron or marquis didnt yield results...
 

Rod


Joined
Jun 12, 2011
Messages
9,703
Reaction score
1,891
Points
113
Location
Melbourne, Australia and Ubud, Bali, Indonesia
Your Mac's Specs
2021 M1 MacBook Pro 14" macOS 14.4.1, Mid 2010MacBook 13" iPhone 13 Pro max, iPad 6, Apple Watch SE.
Wow! Well let Virus Barrier quarantine them but don't delete them just yet. Just in case they turn out to be necessary for something. After a month or so if there are no problems you can just delete the contents of the quarantine folder.
As you are using Chrome you could just uninstall it. That should get rid of any associated files including searchbaron. Here you could use Clean My Mac on Uninstall. It does quite a good job of uninstalling apps.
Are you logged in on Chrome with a Google ID? If so you can safely erase/uninstall it after logging out. When you reinstall it just login again and your data and preferences should be restored.
 
OP
T
Joined
Jan 8, 2021
Messages
23
Reaction score
0
Points
1
Next hicup, I tried the virus scanner again it found 25 infected files stating them as quarantined but if I open the quarantine section, its empty...
 
OP
T
Joined
Jan 8, 2021
Messages
23
Reaction score
0
Points
1
Wow! Well let Virus Barrier quarantine them but don't delete them just yet. Just in case they turn out to be necessary for something. After a month or so if there are no problems you can just delete the contents of the quarantine folder.
As you are using Chrome you could just uninstall it. That should get rid of any associated files including searchbaron. Here you could use Clean My Mac on Uninstall. It does quite a good job of uninstalling apps.
Are you logged in on Chrome with a Google ID? If so you can safely erase/uninstall it after logging out. When you reinstall it just login again and your data and preferences should be restored.

Unfortunately, I am not the greatest mac technician and I hate to be fiddling around with all my bookmarks ending up losing them when I erase chrome...nothing else I could try..?Nothing I can enter in the default browser section..?
 
OP
T
Joined
Jan 8, 2021
Messages
23
Reaction score
0
Points
1
Unfortunately, I am not the greatest mac technician and I hate to be fiddling around with all my bookmarks ending up losing them when I erase chrome...nothing else I could try..?Nothing I can enter in the default browser section..?
How can it be that there is no cleaner that really works??
 
Joined
Feb 1, 2011
Messages
4,434
Reaction score
2,152
Points
113
Location
Sacramento, California
I've never heard of "Search Baron" prior to just now. Suspiciously, there is no mention of it from any of the established anti-virus companies or folks who usually track such things closely. I've managed to find three Web sites that mention "how to remove it" (including the one that "chscag" cited in this very thread) and all three are shill sites that want to sell you very questionable software.

The situation sounds very similar to the recent CrossRider adware that was going around:
https://blog.malwarebytes.com/threa...iant-installs-configuration-profiles-on-macs/

Since just about all malware and adware for the macintosh is due to a Trojan Horse, it's almost certain that whatever Search Baron is, you got it by downloading and launching software. Possibly a fake Adobe installer or uninstaller, or possibly it came as part of an otherwise legitmate software bundle deal.

Folks got hit by CrossRider, they ran various anti-malware and anti-adware utilities and couldn't get rid of it, then they went to the Web and found suspicious shill Web sites offering to fix the problem if only they bought and downloaded very suspicious software. I WOULDN"T DOWNLOAD ANY SOFTWARE FROM SUCH A WEB SITE! It's likely to make matters much worse.

Try this: Go into System Preferences. See if there is a preference pane for "Profiles". If there is open it and delete all profiles. Then I'd run DetectX again, just for good measure. Let us know if that fixes the problem.

If it doesn't, then you are going to have to wait until one or more of the well regarded anti-virus companies, such as Intego, analyze this piece of adware and either push out an update to their product to delete it, or give instructions on how to manually delete it. Or...

You can try to manually find and eliminate the adware:
Or...

You can contact Intego to work with them to fix the problem if they haven't seen Search Baron before:
 

Shop Amazon


Shop for your Apple, Mac, iPhone and other computer products on Amazon.
We are a participant in the Amazon Services LLC Associates Program, an affiliate program designed to provide a means for us to earn fees by linking to Amazon and affiliated sites.
Top