You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Safe Finder Malware virus Infected Safari and will not go away

I have tried everything I could find online in many sites/blogs/threads/forums/videos/articles. It actually was gone, and then when I logged into computer this morning it had re infected Safari!!!


Here is what I had done yesterday:


Deleted "safefinder app in applications folder"


Deleted All Safari Extensions


Cleared Safari History & Cache & Cookies


Checked for System Preferences profiles


Checked that the SOCKS PROXY was not on


deleted various .plist in system folders (all the various ones applicationsupport,daemon launch, and a few others I can't remember but it was mostly .plists


did a scan with malware bytes (found nothing)


Did a scan with Bitdefender (found 7 things, and was able to remove 5) not sure if the ones removed or the ones stayed had anything to do with safe finder.)


Did a scan with combo cleaner, and it found 2 things so far in scan, but that is $65 and I cant afford that.


At this point I would totally format my computer and do a restore from my time machine backup, but I assume if this malware has weasled its way in here that it still is not able to be removed then its also in my various settings etc in my backup, so I would simply restore everything in its current state.




iMac 27″, macOS 10.15

Posted on Mar 27, 2021 3:50 PM

Reply
Question marked as Top-ranking reply

Posted on Mar 28, 2021 11:06 AM

ITS FIXED!!! OMMMMMGGGG! WHEEEEEEHW


So what I did was shut down and restart the mac in safe mode. Then went into safari settings and it allowed me to change the homepage URL. And Set new window to open to home page. Then I shut down and did a normal restart, and went into safari and it went to the new home page. Fingers crossed this is permanent, as I had it working before and then it reverted after logging in and out of my user account. But I think it Is permanent since I just restarted and logged in just now.


So to sum it up, I think I did technically remove safe finder, with all these instructions some time ago over the course of the last few days. But It was something in the settings that just needed to be reset, and I think booting up in safe mode, and changing the settings there, may have caused that for whatever reason.


Thx Dominic , and hopefully this will help the next person...





Similar questions

11 replies
Question marked as Top-ranking reply

Mar 28, 2021 11:06 AM in response to dominic23

ITS FIXED!!! OMMMMMGGGG! WHEEEEEEHW


So what I did was shut down and restart the mac in safe mode. Then went into safari settings and it allowed me to change the homepage URL. And Set new window to open to home page. Then I shut down and did a normal restart, and went into safari and it went to the new home page. Fingers crossed this is permanent, as I had it working before and then it reverted after logging in and out of my user account. But I think it Is permanent since I just restarted and logged in just now.


So to sum it up, I think I did technically remove safe finder, with all these instructions some time ago over the course of the last few days. But It was something in the settings that just needed to be reset, and I think booting up in safe mode, and changing the settings there, may have caused that for whatever reason.


Thx Dominic , and hopefully this will help the next person...





Mar 28, 2021 8:58 AM in response to PaulNosty

   Remove unknown profiles if present.


  1 . System Preferences > Profile

      Open System Preferences,  select “General and click  the “Profiles” icon ( a checkmark on a gear) .

      When Profiles pane opens, select the unknown profile and click the minus button at the bottom.

      Section: Remove a configuration profile from your Mac

      Profiles: https://support.apple.com/guide/mac-help/configuration-profiles-standardize-settings-mh35561/mac



  2. Remove unknown extensions:  Safari > Preferences > Extensions

      https://support.apple.com/guide/safari/use-safari-extensions-sfri32508/mac

Mar 27, 2021 7:27 PM in response to PaulNosty

You have adware/malware installed. Use  Malwarebytes Anti-Malware for Mac. It may be necessary to run more than one scan. After scanning a couple of times, restart the computer and test. If necessary, follow the manual instructions.  Do not download any other programs that are listed in the articles.  


Safe Finder Uninstall


Safe Finder Uninstall (2)


Safe Finder Uninstall (3)

Mar 28, 2021 6:23 AM in response to brbo

Safe finder is very different than that one, I actually know someone that had the one you mentioned, they just ignored the message and restarted the computer. Nothing was downloaded or installed or permanent, they just went to a wrong URL.


Safe finder is downloaded malware, that infects any browser. It then redirects your home page to this new search engine. It locks the settings so you cannot change the homepage. That in itself wouldn't be the end of the world for the time being, but I don't feel any of my information and data is safe using safari.


THX for the suggestion


Mar 28, 2021 7:41 AM in response to Eric Root

Eric Root,


Thanks for your post, I have actually found your instructions in a previous post to another user. But will go through ea one again, and share my results.


STEP 1 - Malwarebytes

I have now down 4 scans total, and it is not showing anything. We can consider it not effective in this case.


LINK #1,


I am not going to re list each step, but you can trust me that I followed every single step. (the majority I had done already previously as I have found some of these sites, and some of your posts before posting myself)


Followed every step, does not work. As I said, these instructions are from 2018, and I doubt that the way this malware works, has maybe not evolved in the last 3-4 years. Because I do wonder, why would these instructions not work for me or others.



Link #2


I installed SpyHunter, as suggested in the link, it did not find any malware, but some other items, which I need to wait 48 hours for the trial period to allow 1 time removal. Did all other steps with no success. There are 30 files listed that one should remove, I search each one, and it did find 1 set out of all 30 searches, and I deleted them, but that did not remove anything.


Link # 3


just takes me to goggle search results.


I wonder if these guides are legit, or if they are some generic instructions copy and pasted, so that one can advertise a few virus/malware programs. Because the instructions and programs both are not working against safefinder. (there are 2 other programs recommended, but after actually failing with a handful of actual critically acclaimed virus/malware programs, I am doubtful that this is a solution) And I have read 5-10 blogs/articles and they all have more or less similar instructions and programs offered.


I am making a post on various threads, to hopefully has some experience and knowledge with this particular malware, and can work with me 1 on 1, step by step to eradicate it.


Hopefully you have can help, now that I spent a few hours following the standard advice on removal.









Mar 28, 2021 9:03 AM in response to dominic23

Thanks dominic,


These are steps that I have already completed. There were no profiles.


I can't remember if there was an extension, and I deleted it, or if there never was one at all. Either way, there is no extension now, and that did not solve it.


Most likely any suggestions that someone will have, I have done already as this has been an issue for 6 months.


It is so frustrating, I have spent the last 3 days non stop on it. I am ready to give up, and simply use a different browser. I just really wanted safari to work, since it syncs with safari on all my other devices like ipads, iphones.


Real shame. In theory I don't need a homepage, I can use the start page, but my concern is if safe finder has this type of control over Safari, is any of my information inside safari even safe? My passwords, browsing history etc. I don't trust safari, when it is being over riden in this type of way.

Mar 28, 2021 9:09 AM in response to PaulNosty

  Check proxies. SOCKS?


 System Preferences > Network > Advanced > Proxies

 Deselect   any  proxies if selected.   

Restart the Mac. Relaunch Safari holding the Shift key down. 


     Download EtreCheck: https://etrecheck.com/,run it and post the report here.

     Click  “Free Download” button,    

     Open Downloads folder, click on it to open, and then select ”Open”.

     “Choose a problem” from the popup menu box, and then “Start EtreCheck” in the dialog.

     Click “Share Report” button in the toolbar, select “Copy report” .

     Paste the report when you reply. This is a diagnostic test.

Mar 28, 2021 12:09 PM in response to PaulNosty

Great. That was the last suggestion I would have posted.

In fact, thomas_r, the developer of Malwarebytes for Mac, suggested this changing Homepage.


If Safari's home page is stuck

In some cases, after being changed by adware or malware, Safari's home page can become stuck. You will be able to edit the Homepage field in Safari's preferences, but the change will not stick. This appears to be a bug, and there is an odd workaround. Try this:


1. In Safari, choose Preferences from the Safari menu.

2. In the window that opens, click the General icon (if necessary)

3. Enter your desired home page in the "Homepage" field, but DO NOT press return!

4. At the top of the window, click any of the other icons (eg, Tabs, AutoFill, etc).

5. You may see a prompt asking for confirmation for changing the home page. If so, confirm.

6. Switch back to the General page and check to make sure the home page has been changed.


Credit: thomas_r

https://forums.malwarebytes.com/topic/236261-how-to-remove-weknow-malware-and-others/


With macOS 11 Big Sur, safari.plist is not user removable.




Safe Finder Malware virus Infected Safari and will not go away

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.