Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

Loa

macrumors 68000
Original poster
May 5, 2003
1,732
79
Québec
Hello,

For the past couple of months, I get random redirects to webpages, but I can't find anything that could cause it: no strange login item, extension or app.

Any idea where I could look?

Thanks
 
Hello,

For the past couple of months, I get random redirects to webpages, but I can't find anything that could cause it: no strange login item, extension or app.

Any idea where I could look?

Thanks
I imagine a virus or malware would be redirecting you to specific web sites. What macOS version and what browser and version are you using?
 
  • Like
Reactions: Loa
Sounds like malvertising to me, where a bad ad is redirecting you. Try using an ad blocker. Sometimes clearing the browser's cache and cookies can help as well.
 
  • Like
Reactions: Loa
I'm on 14.6.1, using the latest Chrome.
Ran MalwareByts but sadly it didn't find anything.
Cleared the browser and I'll see how it goes (it's an intermittent problem).

Thanks for the suggestions.
 
I'm on 14.6.1, using the latest Chrome.
Ran MalwareByts but sadly it didn't find anything.
Cleared the browser and I'll see how it goes (it's an intermittent problem).

Thanks for the suggestions.
It’s possible that malicious software has modified your network configuration, causing these redirects. You should check your DNS and proxy settings.

For DNS settings:
  • On macOS, go to System Preferences > Network > Advanced > DNS and make sure you're using a trusted DNS like Google (8.8.8.8) or Cloudflare (1.1.1.1) or your ISP.
  • On Windows, open Control Panel > Network and Internet > Network Connections, right-click your connection, select Properties, then IPv4, and verify the DNS settings.
For proxy settings:
  • On macOS, go to System Preferences > Network > Advanced > Proxies and check that no unknown proxies are listed.
  • On Windows, go to Settings > Network & Internet > Proxy and make sure there’s nothing unusual configured.
Does issue only occur on Chrome BTW?

Check the following locations for anything sus..
  1. ~/Library/LaunchAgents and /Library/LaunchAgents
    These folders can contain scripts or apps that run at login. Check for sus or unknown files.
  2. ~/Library/LaunchDaemons and /Library/LaunchDaemons
    Similar to LaunchAgents, but these run at the system level. Look for anything unfamiliar or that doesn’t match software you’ve installed.
  3. ~/Library/Preferences
    Configuration files for apps are stored here. Sometimes malware will drop files with odd names. Be cautious when deleting, as legitimate apps use this folder too.
  4. ~/Library/Application Support
    Applications store their supporting files here. Check for unknown folders or files that don’t match your installed apps.
  5. ~/Library/Caches
    Cached data from apps and browsers is stored here. Clearing caches for your browser might help if the issue is browser-related.
 
Thanks for the very detailed information. DNS and proxy were fine, as were the launch agents and deamons. But there are a LOT of files in the last 3 folders and after a cursory look I didn't find anything suspicious.

And yes, it only happens in Chrome. Hasn't happened since yesterday morning though.
 
  • Like
Reactions: The Clark
Thanks for the very detailed information. DNS and proxy were fine, as were the launch agents and deamons. But there are a LOT of files in the last 3 folders and after a cursory look I didn't find anything suspicious.

And yes, it only happens in Chrome. Hasn't happened since yesterday morning though.
If you'd like to take a screenshot I could have a look.
I work in cyber security for the gov and do a lot of analysis like this every day.

Happy to hear it hasn't happened since yesterday though, that's a great sign.
 
  • Like
Reactions: Loa
Have you checked the extensions or plug-ins for Chrome, to see if something has been installed there?

See if the problem occurs in a brand new user account -- if not, then the problem is somewhere in your old user Library. If it is still there, the problem is at the root /Library level.

And yes, it only happens in Chrome
No one was ever worse off for not using Chrome. 😆 Plenty of other Chromium-based browsers have better security, privacy, and efficiency.
 
The problem seems to have stopped. Guess clearing the caches and cookies, etc... fixed it. Thanks all.
 
  • Like
Reactions: aihpcfl
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.