Jump to content

RightCoupon issues!

Recommended Posts

Hey, I am having real trouble getting rid of this poxy thing!  I have used Malwarebytes, which got rid of another one that I had.  But this RightCoupon just doesn't seem to want to go. 


I have followed every guide I can find by googling and it simply will not shift.  It even has a settings option to turn it off and it still hangs around like a ball bag!


It only appears on sites such as eBay, Amazon etc.  Shopping sites.  


Can anyone help me?  I wouldn't half mind if it offered me decent gear but it's all stuff anyway haha!


Thanks in advance.

Link to post
Share on other sites

  • Staff



Is this happening in one specific browser and not in any others? Or is it happening in all browsers?


Can you send a system snapshot taken with Malwarebytes Anti-Malware for Mac? To do so, open Malwarebytes Anti-Malware for Mac and choose Take System Snapshot from the Scanner menu. Then, in the window that opens, select all the text (Edit → Select All), copy it and paste into a reply to this message.

Link to post
Share on other sites

Thanks for taking the time to look at this guys!


It was happening in both Safari and Chrome.  I don't really use Safari much, but I followed the steps I found on Apple forums and it fixed the issue on Safari but remains a problem in Chrome which is my main browser.  It basically happens on any shopping site.  Amazon, eBay, MyProtein etc.


Snapshot below.


Malwarebytes Anti-Malware system report - 19 January 2016 19:24:33 GMT

Mac OS X version Version 10.10.5 (Build 14F1509)

System uptime: 0d 00:08:37


Safari extensions





Chrome extensions



    "Name: Google Slides",

    "Modified: 2015-10-21 18:15:37 +0000",

    "/Users/Dean/Library/Application Support/Google/Chrome/Default/Extensions/aapocclcgogkmnckokdopfmhonfmgoek",

    "Name: Google Sheets",

    "Modified: 2015-10-21 18:15:36 +0000",

    "/Users/Dean/Library/Application Support/Google/Chrome/Default/Extensions/felcaaldnbdncclmgdcncolpebgiejap",

    "Name: Google Docs Offline",

    "Modified: 2015-11-19 22:19:21 +0000",

    "/Users/Dean/Library/Application Support/Google/Chrome/Default/Extensions/ghbmnnjooekpmoecnnnilnnbdlolhkhi",

    "Name: AdBlock",

    "Modified: 2016-01-13 20:47:16 +0000",

    "/Users/Dean/Library/Application Support/Google/Chrome/Default/Extensions/gighmmpiobklfepjocnamgkkbiglidom",

    "Name: Avast Online Security",

    "Modified: 2016-01-15 23:32:22 +0000",

    "/Users/Dean/Library/Application Support/Google/Chrome/Default/Extensions/gomekmidlodglbbmalcneegieacbdmki",

    "Name: Facebook Invite All Friends PRO 2016",

    "Modified: 2016-01-05 22:27:17 +0000",

    "/Users/Dean/Library/Application Support/Google/Chrome/Default/Extensions/jjgfeibcphdoepjnmplpgbnpkngnmdmn",

    "Name: [unknown Chrome extension format]",

    "Modified: 2016-01-15 21:54:44 +0000",

    "/Users/Dean/Library/Application Support/Google/Chrome/External Extensions/ddokeinkhjjkiehmaanleebfomemminh.json",

    "Name: [unknown Chrome extension format]",

    "Modified: 2016-01-15 23:14:25 +0000",

    "/Users/Dean/Library/Application Support/Google/Chrome/External Extensions/gomekmidlodglbbmalcneegieacbdmki.json",

    "Name: [unknown Chrome extension format]",

    "Modified: 2016-01-15 21:54:45 +0000",

    "/Users/Dean/Library/Application Support/Google/Chrome/External Extensions/oghpjbnnbligjpjgojilaelgonehgnie.json"



Firefox extensions





Login items






System startup items





User launch agents










System launch agents











System launch daemons















Kernel extensions


























































































































































































    "/System/Library/Extensions/Dont Steal Mac OS X.kext",
























































































































































































launchd.conf contents




Hosts file



# Host Database


# localhost is used to configure the loopback interface

# when the system is booting.  Do not change this entry.

## localhost broadcasthost

::1             localhost 



Scan log


2016-01-15 22:21:20 :  

2016-01-15 22:21:20 : ----- Scan Started -----

2016-01-15 22:21:20 : Scanning with signatures version 44 (2016-1-4)

2016-01-15 22:21:20 : Adware.Spigot : /Users/Dean/Library/LaunchAgents/com.spigot.ApplicationManager.plist

2016-01-15 22:21:20 : Adware.Spigot : /Users/Dean/Library/Application Support/Spigot/

2016-01-15 22:21:29 : *** scan time: 0d 00:00:08 ***

2016-01-15 22:21:29 : ------ Scan Ended ------

2016-01-15 22:21:39 : ---- File Removal Started ----

2016-01-15 22:21:39 : ===========================================

2016-01-15 22:21:39 : REMOVING ITEM: Adware.Spigot

2016-01-15 22:21:39 : >> Removing file item: /Users/Dean/Library/LaunchAgents/com.spigot.ApplicationManager.plist

2016-01-15 22:21:39 : ===========================================

2016-01-15 22:21:39 : REMOVING ITEM: Adware.Spigot

2016-01-15 22:21:39 : >> Removing file item: /Users/Dean/Library/Application Support/Spigot/

2016-01-15 22:21:39 : ---- File Removal Complete ----

2016-01-15 22:21:50 : ===== Attempting restart =====

2016-01-15 22:23:58 :  

2016-01-15 22:23:58 : ----- Scan Started -----

2016-01-15 22:23:58 : Scanning with signatures version 44 (2016-1-4)

2016-01-15 22:24:06 : *** scan time: 0d 00:00:07 ***

2016-01-15 22:24:06 : ------ Scan Ended ------

2016-01-15 22:30:35 :  

2016-01-15 22:30:35 : ----- Scan Started -----

2016-01-15 22:30:35 : Scanning with signatures version 44 (2016-1-4)

2016-01-15 22:30:43 : *** scan time: 0d 00:00:07 ***

2016-01-15 22:30:43 : ------ Scan Ended ------

2016-01-17 20:16:06 :  

2016-01-17 20:16:06 : ----- Scan Started -----

2016-01-17 20:16:06 : Scanning with signatures version 44 (2016-1-4)

2016-01-17 20:16:20 : *** scan time: 0d 00:00:13 ***

2016-01-17 20:16:20 : ------ Scan Ended ------

2016-01-19 19:23:28 :  

2016-01-19 19:23:28 : ----- Scan Started -----

2016-01-19 19:23:28 : Scanning with signatures version 44 (2016-1-4)

2016-01-19 19:23:41 : *** scan time: 0d 00:00:12 ***

2016-01-19 19:23:41 : ------ Scan Ended ------

Link to post
Share on other sites

  • Staff

Sorry, for some reason I didn't get notification that this topic had been updated! (Normally I get e-mail alerts, but sometimes that seems to fail.)


I don't see anything suspicious in your system snapshot. Just to confirm, try restarting in recovery mode (hold down command-R at startup). You should end up at a screen with four options, one of which is Get Help Online. Click that option, which will open a fresh copy of Safari, running on a clean system. Then do some browsing, visiting the same sites that are normally affected.


If, as I suspect, the problem continues to happen in Safari in recovery mode, it's a network issue, rather than a problem with your computer. In this case, the most likely possibility is hacked network hardware:




If the problem does not happen while in recovery mode, let me know.

Link to post
Share on other sites

  • Staff

Ahh, yes, I didn't read carefully enough. You said that it was happening in both Safari and Chrome, but then said the problem was now fixed in Safari.


Since it's just happening in Chrome, that narrows things down quite a bit. It's got to be due to one of your Chrome extensions. See:




I see that you have one called "Facebook Invite All Friends PRO 2016" - this may be a new variant of something we already detect, or it may be a simple coincidence in naming. Try disabling that one. If that fixes the problem, I'd love to get a copy of that extension from you. I'll give you some instructions if that works.

Link to post
Share on other sites

Thomas.....I could kiss you.  I disabled the "Facebook Invite All Friends PRO 2016" (which incidentally, I had to bloody pay for) and it's all fine.....no more pop ups!!!


What do you need from me in regards to that extension?  I'm guessing you wanna put it in the bank of possible problems for future reference?

Link to post
Share on other sites

  • Staff

If you have just disabled it, and not deleted it yet, go to the Finder and choose Go to Folder from the Go menu. In the window that opens, paste in the following path:


~/Library/Application Support/Google/Chrome/Default/Extensions/


Then click the Go button.


In the folder that opens, there will be a lot of folders with long, random names. Find the one named "jjgfeibcphdoepjnmplpgbnpkngnmdmn" and move it to your desktop.


Next, control-click that "jjgfeibcphdoepjnmplpgbnpkngnmdmn" folder on your desktop and choose the Compress "jjgfeibcphdoepjnmplpgbnpkngnmdmn" item from the contextual menu. This will create a file named "jjgfeibcphdoepjnmplpgbnpkngnmdmn.zip" on your desktop.


Now, click my name at the top of this message to access my profile, then click the "Send me a message" button, then click the Use Full Editor button. You should be able to attach that .zip file to that message and send it to me.


Once I've let you know that I've got it, you can delete both "jjgfeibcphdoepjnmplpgbnpkngnmdmn" items. If the Facebook Invite All Friends PRO 2016 extension still shows up in Chrome's extensions list (which sometimes happens when you delete a Chrome extension from the Finder), you can delete it from there.

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.