Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Safe Finder took over my computer - now can't remove it or change homepages

I have moved Safe Finder to the trash and emptied the trash, but this malware has still taken over Safari homepage and greyed it out. It also took over Chrome. I don't dare open Firefox! I downloaded and ran EtreCheck but it found nothing. I have deleted the "Profiles" in System Preferences. Running Mojave 14.4 (The apparent origin of my problems) Please help! Thanks

iMac 21.5", macOS 10.14

Posted on Mar 31, 2019 6:40 AM

Reply

Similar questions

20 replies

Mar 31, 2019 7:20 AM in response to rswc90

  1.  Use  the latest release of Malwarebytes for Mac to remove malware/adware, if installed on your Mac.

     For instructions:  Install Malwarebytes for Mac          Uninstall Malwarebytes for Mac

     Click the “Scan Now” button. Once done, quit Malwarebytes for Mac.

     Restart the computer and relaunch Safari holding the shift key down.


2. Remove unknown Login item.

       System Preferences > Users & Groups > Login items

       Authenticate and unlock the lock.

       Highlight the unknown login item and click the “-“ button at the bottom left to remove it. 


3. Homepage:  Ref: https://https://support.apple.com/guide/safari/customize-your-search-ibrwe75c2a3c/mac


4. Remove unknown extensions:  Safari > Preferences > Extensions

https://support.apple.com/guide/safari/use-safari-extensions-sfri32508/mac


5. Reset search engine:    https://support.apple.com/guide/safari/customize-your-search-ibrwe75c2a3c/mac

Mar 31, 2019 3:08 PM in response to rswc90

1. Remove unknown profiles, if any.

System Preferences > Profiles

Open System Preferences, click the “Profiles” icon ( a checkmark on a gear) .

When Profiles pane opens, select the unknown profile and click the minus button at the bottom.


2 SafeFinder will store a cookie in your bookmarks folder.

Manage cookies and website data in Safari on Mac


Please read.    

  Ref: https://forums.malwarebytes.com/topic/236261-how-to-remove-weknow-malware-and-others/

Apr 1, 2019 4:51 PM in response to rswc90

If you're still seeing sysinfo.plist detections that are appearing on their own, not in response to something you're trying to install, please submit a support ticket here:

  • https://support.malwarebytes.com/community/consumer/pages/contact-us
  • Be sure to select Malwarebytes for Mac as the product
  • Download and run the Get System Profile script below and attach the file it creates to your support request
  • Do not post the output of that script directly here, as it may contain information that you don't want made public; this is why I suggest that you submit via a support ticket instead


Get System Profile.zip

https://forums.malwarebytes.com/applications/core/interface/file/attachment.php?id=242661

Mar 31, 2019 10:41 AM in response to dominic23

There are no logins that are connected to anything unknown

Also, this is now showing up in my quarantined malware for MalwareBytes:

sisinfo.plist

<?xml version="1.0" encoding="UTF-8"?>

<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

<plist version="1.0">

<dict>

<key>isExist</key>

<string>YES</string>

</dict>

</plist>



And this shows that there are no extensions in Safari:


And finally, This shows the Greyed out homepage...




Mar 31, 2019 9:44 AM in response to dominic23

Thx for the instructions, but I had run the Makware program before I posted this text. It didn’t even find Safe Finder. It was the latest version that I downloaded to find the Malware. I have the trial 14 day version running and it still doesn’t find it. Etre check did not find it either. When I open chrome it opens with safe finder although it has been moved to trash and the trach emptied. Safari opens and a Blank window but the homepage is grayed out and it goes to an e-click ad site. I have also cleared out my history and all the websites and the cache for cookies. I also restarted the whole computer and the started Safari holding the Shift key down.


Safe Finder is still in Chrome and Safari is still being held captive by this malware :-(

Mar 31, 2019 1:45 PM in response to rswc90

I have walked through all the manual instructions on how to remove Safe Finder. I continue to get the same file quarantined by MalwareBytes sisinfo.plist. This is the 15th one today. But Safe Finder is still there --


It's NOT in my Apps and it's not in any of the extensions. It does not "show up" anywhere except the browsers... Here is the plist:


<?xml version="1.0" encoding="UTF-8"?>

<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

<plist version="1.0">

<dict>

<key>isExist</key>

<string>YES</string>

</dict>

</plist>

Mar 31, 2019 5:30 PM in response to dominic23

As I said in my previous posts, and I certainly understand that you don’t necessarily read all of them, I have done all of the things that you have suggested. There are no other profiles. I have cleaned out my cachet. I have emptied my history. I have deleted all my cookies. I emptied my trash. I ran etrecheck and it found nothing. Malwarebyes quarentines only one file. I have been on the phone with Apple and they can’t seem to help me yet. I am to call them again tomorrow. I have gone through Malwarebytes and actually even tried to contact them but their website continues to freeze when I fill out the “contact us” form. I have gone through all the suggested manual deletes. I have deleted the profile in my systems preferences that came up as an unknown circle with a checkmark in it. There are no extensions in my Safari or my chrome browsers . I found a yahoo browser hidden in my computer users specific HD applications and I deleted that. Still this is in my system hiding someplace.


I do thank you for your suggestions though. I have already done them.

Apr 1, 2019 4:42 AM in response to dominic23

Under Macintosh HD/user/computer/library/preferences I found a series of questionable plist files. I searched the name of the hijacked homepage and found files with the names in them. Also I found this.


www.homesweeklies.com/homepage/ or some file called "key chain reauthorize" seems to be in most of these folders. There’s also a "keyboard tracking" wording on the keyboard file. See below For chrome, I think.


"KeychainReauthorizeInAppSpring2017_!NSNavPanelExpandedSizeForSaveMode_"NSNavPanelExpandedStateForSaveMode_!NSNavPanelExpandedSizeForOpenMode_NSNavLastRootDirectory_)KeychainReauthorizeInAppSpring2017Success_NewTabPageLocation_LastRunAppBundlePath_(NSNavLastUserSetHideExtensionButtonState[{1390, 730} Z{704, 459}Y~/Desktop _whttp://search.getstranto.club/newTab/8080/1391/00549/195/UnitedStates/US/08688437/B15F64C9-8034-5AF5-8166-454FCB4D6009_/Applications/Google Chrome.app@dâ≠∆ÚIKWXcmnË


Apr 1, 2019 6:07 AM in response to rswc90

Section: Nuke Chrome

   Ref: https://forums.malwarebytes.com/topic/236261-how-to-remove-weknow-malware-and-others/

I have zero experience with Chrome.

This looks like something fishy going on, but I am not sure.

These malware vendors are always one step ahead of users like us.

As a member of Malwarebytes forum, I will contact them for help.

Thomas Reed, developer of Malwarebytes for Mac can have a look at it.


Best.



Apr 3, 2019 11:41 AM in response to dominic23

Maybe I need a new plan of action. Apple seems unable to assist me so far. I have a tech person who has to check with her supervisor after each question I pose. I have sent several files where I see the malware hiding. Malwarebytes is not picking it up. It does pick up one file (I included previously here).


I have walked through the getting-rid-of-malware processes a few times.


I tried to RESTORE Safari from TimeMachine from the day before all this started, but I am unable to restore any of the Apple products.


Safari is still unable to allow for resetting the homepage, although I must have deleted one of the plists because now it does not have the "homesweeklies.com" as the greyed out homepage.


I have found suspect files in Launch Agents, Launch Daemon and several plists.


I uninstalled and reinstalled Chrome - I can now at least open with about:blank and get a blank page.


When I restarted my computer, I got 143 items dumped onto the desktop seemingly copied from Trash, Dropbox, Google Drive.


I am wondering if I have to wipe my system clean and then hope that time machine can reinstall from the day before all this occurred. Does this look like the only thing that will help?


Again, thank you for this community!


Apr 3, 2019 5:56 PM in response to rswc90

I see you are in discussions with the developer in their Forum now, rather than opening a ticket with Customer Support as I suggested. That's OK, but as I mentioned they need information from you that is best not posted publicly as it could contain privacy information. Please send a Direct Message (DM) to @treed and be prepared to upload the information gathered by the software I suggested you download and run yesterday

Safe Finder took over my computer - now can't remove it or change homepages

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.