safefind
Hi, my pc got infected with this "safefind" malware. I managed to remove it and clean my pc from it, and I notices it spread to chrome and internet explorer. After extensive cleaning a problem still persists is that when I close the browser so any case by clicking "x" and reopen it, it does not retain opened pages that i kept before closing and it runs as if i have the don't keep pages from last session is switched off. now the problem spread to chrome and ie too and i thought some kind of a windows problem until i synced my fire fox account to my Macbook and the problem popped up.
Any help would be appriciated. thank you.
Additional System Details
Installed Plug-ins
- Shockwave Flash 26.0 r0
Application
- Firefox 55.0.3
- User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:55.0) Gecko/20100101 Firefox/55.0
- Support URL: https://support.mozilla.org/1/firefox/55.0.3/Darwin/en-US/
Extensions
- 1-Click YouTube Video Downloader 3.0.4 (YoutubeDownloader@PeterOlayev.com)
- Ad Blocker for Facebook™ 1.3.2 ({d403ee9c-3bd2-41d3-b1e9-27698babf097})
- Ad-blocker for Gmail 2.8.3.1-signed.1-signed (jid0-AocRXUCRsLTCYvn6bgJERnwfuqw@jetpack)
- AdBlock 3.4.1 (jid1-NIfFY2CA8fy1tg@jetpack)
- AdBlocker for YouTube™ 0.2.7 (jid1-q4sG8pYhq8KGHs@jetpack)
- Adobe Acrobat DC - Create PDF 15.01.04 (web2pdfextension@web2pdf.adobedotcom)
- FlashGot 1.5.6.14 ({19503e42-ca3c-4c27-b1e2-9cdb2170ee34})
- GoogAlexa 1.3 (googalexa@rank.it)
- Hoxx VPN Proxy 2.2.2 (@hoxx-vpn)
Javascript
- incrementalGCEnabled: True
Graphics
- adapterDescription:
- adapterDeviceID: 0x0166
- adapterDrivers:
- adapterRAM:
- adapterVendorID: 0x8086
- crashGuards: []
- currentAudioBackend: audiounit
- driverDate:
- driverVersion:
- featureLog: {u'fallbacks': [], u'features': [{u'status': u'available', u'description': u'Compositing', u'log': [{u'status': u'available', u'type': u'default'}], u'name': u'HW_COMPOSITING'}, {u'status': u'available', u'description': u'OpenGL Compositing', u'log': [{u'status': u'available', u'type': u'default'}], u'name': u'OPENGL_COMPOSITING'}, {u'status': u'unavailable', u'description': u'WebRender', u'log': [{u'status': u'opt-in', u'message': u'WebRender is an opt-in feature', u'type': u'default'}, {u'status': u'unavailable', u'message': u"Build doesn't include WebRender", u'type': u'runtime'}], u'name': u'WEBRENDER'}]}
- info: {u'TileHeight': 512, u'TileWidth': 512, u'AzureFallbackCanvasBackend': u'none', u'AzureCanvasAccelerated': 1, u'AzureCanvasBackend': u'skia', u'AzureContentBackend': u'skia'}
- numAcceleratedWindows: 2
- numTotalWindows: 2
- webgl1DriverExtensions: GL_ARB_color_buffer_float GL_ARB_depth_buffer_float GL_ARB_depth_clamp GL_ARB_depth_texture GL_ARB_draw_buffers GL_ARB_draw_elements_base_vertex GL_ARB_draw_instanced GL_ARB_fragment_program GL_ARB_fragment_program_shadow GL_ARB_fragment_shader GL_ARB_framebuffer_object GL_ARB_framebuffer_sRGB GL_ARB_half_float_pixel GL_ARB_half_float_vertex GL_ARB_instanced_arrays GL_ARB_multisample GL_ARB_multitexture GL_ARB_occlusion_query GL_ARB_pixel_buffer_object GL_ARB_point_parameters GL_ARB_point_sprite GL_ARB_provoking_vertex GL_ARB_seamless_cube_map GL_ARB_shader_objects GL_ARB_shader_texture_lod GL_ARB_shading_language_100 GL_ARB_shadow GL_ARB_sync GL_ARB_texture_border_clamp GL_ARB_texture_compression GL_ARB_texture_compression_rgtc GL_ARB_texture_cube_map GL_ARB_texture_env_add GL_ARB_texture_env_combine GL_ARB_texture_env_crossbar GL_ARB_texture_env_dot3 GL_ARB_texture_float GL_ARB_texture_mirrored_repeat GL_ARB_texture_non_power_of_two GL_ARB_texture_rectangle GL_ARB_texture_rg GL_ARB_transpose_matrix GL_ARB_vertex_array_bgra GL_ARB_vertex_blend GL_ARB_vertex_buffer_object GL_ARB_vertex_program GL_ARB_vertex_shader GL_ARB_window_pos GL_EXT_abgr GL_EXT_bgra GL_EXT_blend_color GL_EXT_blend_equation_separate GL_EXT_blend_func_separate GL_EXT_blend_minmax GL_EXT_blend_subtract GL_EXT_clip_volume_hint GL_EXT_debug_label GL_EXT_debug_marker GL_EXT_draw_buffers2 GL_EXT_draw_range_elements GL_EXT_fog_coord GL_EXT_framebuffer_blit GL_EXT_framebuffer_multisample GL_EXT_framebuffer_multisample_blit_scaled GL_EXT_framebuffer_object GL_EXT_framebuffer_sRGB GL_EXT_geometry_shader4 GL_EXT_gpu_program_parameters GL_EXT_gpu_shader4 GL_EXT_multi_draw_arrays GL_EXT_packed_depth_stencil GL_EXT_packed_float GL_EXT_provoking_vertex GL_EXT_rescale_normal GL_EXT_secondary_color GL_EXT_separate_specular_color GL_EXT_shadow_funcs GL_EXT_stencil_two_side GL_EXT_stencil_wrap GL_EXT_texture_array GL_EXT_texture_compression_dxt1 GL_EXT_texture_compression_s3tc GL_EXT_texture_env_add GL_EXT_texture_filter_anisotropic GL_EXT_texture_integer GL_EXT_texture_lod_bias GL_EXT_texture_rectangle GL_EXT_texture_shared_exponent GL_EXT_texture_sRGB GL_EXT_texture_sRGB_decode GL_EXT_timer_query GL_EXT_transform_feedback GL_EXT_vertex_array_bgra GL_APPLE_aux_depth_stencil GL_APPLE_client_storage GL_APPLE_element_array GL_APPLE_fence GL_APPLE_float_pixels GL_APPLE_flush_buffer_range GL_APPLE_flush_render GL_APPLE_object_purgeable GL_APPLE_packed_pixels GL_APPLE_pixel_buffer GL_APPLE_rgb_422 GL_APPLE_row_bytes GL_APPLE_specular_vector GL_APPLE_texture_range GL_APPLE_transform_hint GL_APPLE_vertex_array_object GL_APPLE_vertex_array_range GL_APPLE_vertex_point_size GL_APPLE_vertex_program_evaluators GL_APPLE_ycbcr_422 GL_ATI_separate_stencil GL_ATI_texture_env_combine3 GL_ATI_texture_float GL_ATI_texture_mirror_once GL_IBM_rasterpos_clip GL_NV_blend_square GL_NV_conditional_render GL_NV_depth_clamp GL_NV_fog_distance GL_NV_light_max_exponent GL_NV_texgen_reflection GL_NV_texture_barrier GL_SGIS_generate_mipmap GL_SGIS_texture_edge_clamp GL_SGIS_texture_lod
- webgl1Extensions: ANGLE_instanced_arrays EXT_blend_minmax EXT_color_buffer_half_float EXT_frag_depth EXT_sRGB EXT_shader_texture_lod EXT_texture_filter_anisotropic MOZ_debug OES_element_index_uint OES_standard_derivatives OES_texture_float OES_texture_float_linear OES_texture_half_float OES_texture_half_float_linear OES_vertex_array_object WEBGL_color_buffer_float WEBGL_compressed_texture_s3tc WEBGL_compressed_texture_s3tc_srgb WEBGL_debug_renderer_info WEBGL_debug_shaders WEBGL_depth_texture WEBGL_draw_buffers WEBGL_lose_context MOZ_WEBGL_lose_context MOZ_WEBGL_compressed_texture_s3tc MOZ_WEBGL_depth_texture
- webgl1Renderer: Intel Inc. -- Intel HD Graphics 4000 OpenGL Engine
- webgl1Version: 2.1 INTEL-10.25.17
- webgl1WSIInfo: CGL
- webgl2DriverExtensions: GL_ARB_blend_func_extended GL_ARB_draw_buffers_blend GL_ARB_draw_indirect GL_ARB_ES2_compatibility GL_ARB_explicit_attrib_location GL_ARB_gpu_shader_fp64 GL_ARB_gpu_shader5 GL_ARB_instanced_arrays GL_ARB_internalformat_query GL_ARB_occlusion_query2 GL_ARB_sample_shading GL_ARB_sampler_objects GL_ARB_separate_shader_objects GL_ARB_shader_bit_encoding GL_ARB_shader_subroutine GL_ARB_shading_language_include GL_ARB_tessellation_shader GL_ARB_texture_buffer_object_rgb32 GL_ARB_texture_cube_map_array GL_ARB_texture_gather GL_ARB_texture_query_lod GL_ARB_texture_rgb10_a2ui GL_ARB_texture_storage GL_ARB_texture_swizzle GL_ARB_timer_query GL_ARB_transform_feedback2 GL_ARB_transform_feedback3 GL_ARB_vertex_attrib_64bit GL_ARB_vertex_type_2_10_10_10_rev GL_ARB_viewport_array GL_EXT_debug_label GL_EXT_debug_marker GL_EXT_framebuffer_multisample_blit_scaled GL_EXT_texture_compression_s3tc GL_EXT_texture_filter_anisotropic GL_EXT_texture_sRGB_decode GL_APPLE_client_storage GL_APPLE_container_object_shareable GL_APPLE_flush_render GL_APPLE_object_purgeable GL_APPLE_rgb_422 GL_APPLE_row_bytes GL_APPLE_texture_range GL_ATI_texture_mirror_once GL_NV_texture_barrier
- webgl2Extensions: EXT_color_buffer_float EXT_texture_filter_anisotropic EXT_disjoint_timer_query MOZ_debug OES_texture_float_linear WEBGL_compressed_texture_s3tc WEBGL_debug_renderer_info WEBGL_debug_shaders WEBGL_lose_context MOZ_WEBGL_lose_context MOZ_WEBGL_compressed_texture_s3tc
- webgl2Renderer: Intel Inc. -- Intel HD Graphics 4000 OpenGL Engine
- webgl2Version: 4.1 INTEL-10.25.17
- webgl2WSIInfo: CGL
- windowLayerManagerRemote: True
- windowLayerManagerType: OpenGL
Modified Preferences
Misc
- User JS: No
- Accessibility: No
Helpful Reply
First, let's make sure the system is clean.
You may have ad/mal-ware. Further information can be found in this article; https://support.mozilla.org/en-US/kb/troubleshoot-firefox-issues-caused-malware?cache=no
Run most or all of the listed malware scanners. Each works differently. If one program misses something, another may pick it up.
Question owner
I used clean my mac, adware remover, and few other apps can't recall at the moment, same result.
A friend sent me this link; https://howtoremove.guide/how-to-remove-safe-finder-mac/
Modified
Question owner
Yeah I tried it. didn't work before. :/
Would you please take a look at this :
http://macsecurity.net/view/124/
You've already run all those scans, but have you also done this :
Go to the 3-bar menu => Addons => Extensions and look for any unfamiliar or suspicious looking extensions, like e.g.:
SafeSearch Incognito SearchAssist Incognito
When you find any : remove them.
Also look in : 3-bar menu (or 'Tools') => Options => Advanced => Network tab => Under : 'Offline Web Content and User Data'
However : most malware will be 'hiding' somewhere , hence the malware scans.
Especially for Mac : https://www.malwarebytes.com/mac/
Modified