Jump to content

Welcome to Geeks to Go
Geeks to Go Welcome
Create Account Login to Account
Photo

Removal instructions for SafetySearch

- - - - -

  • Please log in to reply
No replies to this topic

#1
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 31,942 posts
Content is republished with permission from Malwarebytes.

What is SafetySearch?

The Malwarebytes research team has determined that SafetySearch is a browser hijacker. These so-called "hijackers" alter your startpage or searchscopes so that the effected browser visits their site or one of their choice. This one also displays advertisements.

How do I know if my computer is affected by SafetySearch?

This is how the start-page looks:

main.png

And you may see these add-ons:

warning1.png

warning2.png

or this entry in your list of installed programs:

warning4.png

You will find this icon in your taskbar:

icons.png

How did SafetySearch get on my computer?

Browser hijackers use different methods for distributing themselves. This particular one was offered as web security software.

How do I remove SafetySearch?

Our program Malwarebytes Anti-Malware can detect and remove this potentially unwanted application.
  • Please download Malwarebytes Anti-Malware to your desktop.
  • Double-click mbam-setup-version.exe and follow the prompts to install the program.
  • At the end, be sure a check-mark is placed next to the following:
    • Enable free trial of Malwarebytes Anti-Malware Premium
    • Launch Malwarebytes Anti-Malware
  • Then click Finish.
  • If an update is found, you will be prompted to download and install the latest version.
  • Once the program has loaded, select Scan now. Or select the Threat Scan from the Scan menu.
  • When the scan is complete , make sure that everything is set to "Quarantine", and click Apply Actions.
  • Reboot your computer if prompted.
Is there anything else I need to do to get rid of SafetySearch?
  • No, Malwarebytes' Anti-Malware removes SafetySearch completely.
How would the full version of Malwarebytes Anti-Malware help protect me?

We hope our application and this guide have helped you eradicate this hijacker.

As you can see below the full version of Malwarebytes Anti-Malware would have protected you against the SafetySearch rogue. It would have warned you before the rogue could install itself, giving you a chance to stop it before it became too late.


protection1.png

Technical details for experts

Signs in a HijackThis log:
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:3128
O1 - Hosts: 54.225.95.126 fjnoekdlmmjagmmlchagfonjgbioomoo
O2 - BHO: SafetySearch BHO - {1EDE0D83-B129-4ABC-923B-725D5B0C0DAC} - C:\Program Files\SafetySearch\FrameworkBHO.dll
O4 - HKLM\..\Run: [BService] C:\Program Files\Bench\BService\1.1\bservice.exe
O4 - HKLM\..\Run: [Wd] C:\Program Files\Bench\Wd\wd.exe
O4 - HKLM\..\Run: [Bench Communicator Watcher] C:\Program Files\Bench\Proxy\pwdg.exe
O4 - HKLM\..\Run: [Bench Settings Cleaner] C:\Program Files\Bench\Proxy\cl.exe
O4 - HKLM\..\RunOnce: [SafetySearch-repairJob] wscript.exe "C:\Users\{username}\AppData\Local\SafetySearch\repair.js" "SafetySearch-repairJob"
Alterations made by the installer:
File system details  
---------------------------------------------
    Adds the folder C:\Program Files\Bench\BService\1.1
       Adds the file bhelper.dll"="5/29/2014 8:35 PM, 53248 bytes, A
       Adds the file bservice.exe"="6/24/2014 6:57 PM, 52736 bytes, A
    Adds the folder C:\Program Files\Bench\NmHost
       Adds the file manifest.json"="7/13/2014 10:30 AM, 215 bytes, A
       Adds the file nmhost.exe"="5/29/2014 8:35 PM, 165376 bytes, A
    Adds the folder C:\Program Files\Bench\NmHost\data\installer
       Adds the file fjnoekdlmmjagmmlchagfonjgbioomoo"="7/13/2014 10:30 AM, 954 bytes, A
    Adds the folder C:\Program Files\Bench\Proxy
       Adds the file cl.exe"="6/17/2014 5:44 PM, 55296 bytes, A
       Adds the file icon.ico"="6/26/2014 10:07 AM, 32038 bytes, A
       Adds the file proc.exe"="6/17/2014 5:44 PM, 422912 bytes, A
       Adds the file pwdg.exe"="6/17/2014 5:44 PM, 113152 bytes, A
    Adds the folder C:\Program Files\Bench\Updater
       Adds the file products.xml"="7/13/2014 10:30 AM, 377 bytes, A
       Adds the file updater.exe"="5/29/2014 8:35 PM, 69120 bytes, A
    Adds the folder C:\Program Files\Bench\Updater\1.7.0.0
       Adds the file updater.exe"="5/29/2014 8:35 PM, 468480 bytes, A
    Adds the folder C:\Program Files\Bench\Wd
       Adds the file wd.exe"="6/17/2014 5:44 PM, 92672 bytes, A
    Adds the folder C:\Program Files\SafetySearch
       Adds the file background.html"="6/26/2014 10:07 AM, 157 bytes, A
       Adds the file config.xml"="6/26/2014 10:07 AM, 2242 bytes, A
       Adds the file extension_info.json"="7/13/2014 10:30 AM, 2370 bytes, A
       Adds the file FrameworkBHO.dll"="6/26/2014 10:07 AM, 471600 bytes, A
       Adds the file FrameworkBHO64.dll"="6/26/2014 10:07 AM, 492880 bytes, A
       Adds the file FrameworkEngine.exe"="6/26/2014 10:07 AM, 264752 bytes, A
    Adds the folder C:\Program Files\SafetySearch\AppFramework
       Adds the file appAPI_bg.js"="6/26/2014 10:07 AM, 2582 bytes, A
       Adds the file appAPI_browseraction.js"="6/26/2014 10:07 AM, 799 bytes, A
       Adds the file appAPI_common.js"="6/26/2014 10:07 AM, 9871 bytes, A
       Adds the file appAPI_content.js"="6/26/2014 10:07 AM, 1247 bytes, A
       Adds the file appAPI_settings.js"="6/26/2014 10:07 AM, 83 bytes, A
       Adds the file appAPI_webrequest.js"="6/26/2014 10:07 AM, 138 bytes, A
       Adds the file jquery.min.js"="6/26/2014 10:07 AM, 93548 bytes, A
    Adds the folder C:\Program Files\SafetySearch\CanvasFramework
       Adds the file canvas_bg.js"="6/26/2014 10:07 AM, 5651 bytes, A
       Adds the file canvasscript_engine.js"="6/26/2014 10:07 AM, 437 bytes, A
       Adds the file md5.js"="6/26/2014 10:07 AM, 3264 bytes, A
       Adds the file registry.js"="6/26/2014 10:07 AM, 908 bytes, A
       Adds the file webrequest.js"="6/26/2014 10:07 AM, 4005 bytes, A
    Adds the folder C:\Program Files\SafetySearch\framework
       Adds the file backgroundscript_engine.js"="6/26/2014 10:07 AM, 1872 bytes, A
       Adds the file base.js"="6/26/2014 10:07 AM, 2933 bytes, A
       Adds the file browser.js"="6/26/2014 10:07 AM, 11200 bytes, A
       Adds the file console.js"="6/26/2014 10:07 AM, 489 bytes, A
       Adds the file framework.js"="6/26/2014 10:07 AM, 3542 bytes, A
       Adds the file global.js"="6/26/2014 10:07 AM, 1850 bytes, A
       Adds the file i18n.js"="6/26/2014 10:07 AM, 1661 bytes, A
       Adds the file initialize.js"="6/26/2014 10:07 AM, 316 bytes, A
       Adds the file invoke_async.js"="6/26/2014 10:07 AM, 2312 bytes, A
       Adds the file io.js"="6/26/2014 10:07 AM, 1308 bytes, A
       Adds the file json2.js"="6/26/2014 10:07 AM, 2791 bytes, A
       Adds the file lang.js"="6/26/2014 10:07 AM, 1633 bytes, A
       Adds the file legacy.js"="6/26/2014 10:07 AM, 1270 bytes, A
       Adds the file message_target.js"="6/26/2014 10:07 AM, 854 bytes, A
       Adds the file messaging.js"="6/26/2014 10:07 AM, 1507 bytes, A
       Adds the file storage.js"="6/26/2014 10:07 AM, 3603 bytes, A
       Adds the file timer.js"="6/26/2014 10:07 AM, 409 bytes, A
       Adds the file updater.js"="6/26/2014 10:07 AM, 2417 bytes, A
       Adds the file userscript_client.js"="6/26/2014 10:07 AM, 310 bytes, A
       Adds the file userscript_engine.js"="6/26/2014 10:07 AM, 3062 bytes, A
       Adds the file utils.js"="6/26/2014 10:07 AM, 2492 bytes, A
       Adds the file xhr.js"="6/26/2014 10:07 AM, 3081 bytes, A
    Adds the folder C:\Program Files\SafetySearch\framework-ui
       Adds the file browser_button.js"="6/26/2014 10:07 AM, 5135 bytes, A
       Adds the file context_menu.js"="6/26/2014 10:07 AM, 738 bytes, A
       Adds the file context_menu_item_handler.html"="6/26/2014 10:07 AM, 225 bytes, A
       Adds the file framework_api.js"="6/26/2014 10:07 AM, 1589 bytes, A
       Adds the file notification.html"="6/26/2014 10:07 AM, 6591 bytes, A
       Adds the file notifications.js"="6/26/2014 10:07 AM, 2409 bytes, A
       Adds the file options.js"="6/26/2014 10:07 AM, 660 bytes, A
       Adds the file ui_base.js"="6/26/2014 10:07 AM, 1788 bytes, A
    Adds the folder C:\Program Files\SafetySearch\framework-ui\theme\bubble
       Adds the file bottom-left.png"="6/26/2014 10:07 AM, 316 bytes, A
       Adds the file bottom-middle.png"="6/26/2014 10:07 AM, 240 bytes, A
       Adds the file bottom-right.png"="6/26/2014 10:07 AM, 311 bytes, A
       Adds the file middle-left.png"="6/26/2014 10:07 AM, 235 bytes, A
       Adds the file middle-right.png"="6/26/2014 10:07 AM, 234 bytes, A
       Adds the file tail-bottom.png"="6/26/2014 10:07 AM, 315 bytes, A
       Adds the file tail-left.png"="6/26/2014 10:07 AM, 307 bytes, A
       Adds the file tail-right.png"="6/26/2014 10:07 AM, 304 bytes, A
       Adds the file tail-top.png"="6/26/2014 10:07 AM, 315 bytes, A
       Adds the file top-left.png"="6/26/2014 10:07 AM, 310 bytes, A
       Adds the file top-middle.png"="6/26/2014 10:07 AM, 240 bytes, A
       Adds the file top-right.png"="6/26/2014 10:07 AM, 308 bytes, A
    Adds the folder C:\Program Files\SafetySearch\icons
       Adds the file button.png"="6/26/2014 10:07 AM, 517 bytes, A
       Adds the file icon100.png"="6/26/2014 10:07 AM, 3526 bytes, A
       Adds the file icon128.png"="6/26/2014 10:07 AM, 4559 bytes, A
       Adds the file icon32.png"="6/26/2014 10:07 AM, 1095 bytes, A
       Adds the file icon48.png"="6/26/2014 10:07 AM, 1633 bytes, A
    Adds the folder C:\Users\{username}\AppData\Local\BenchUpdater
       Adds the file products.xml"="7/13/2014 10:30 AM, 442 bytes, A
    Adds the folder C:\Users\{username}\AppData\Local\SafetySearch
       Adds the file chrome_gp_update.js"="5/29/2014 8:35 PM, 2348 bytes, A
       Adds the file chrome_installer.js"="6/24/2014 6:57 PM, 6304 bytes, A
       Adds the file clear_cache.js"="6/17/2014 5:44 PM, 522 bytes, A
       Adds the file common.js"="6/24/2014 6:57 PM, 13550 bytes, A
       Adds the file firefox_installer.js"="6/17/2014 5:44 PM, 6848 bytes, A
       Adds the file gpedit.exe"="6/24/2014 6:57 PM, 95744 bytes, A
       Adds the file icon.ico"="6/26/2014 10:07 AM, 32038 bytes, A
       Adds the file ie_installer.js"="6/17/2014 5:44 PM, 3685 bytes, A
       Adds the file installer.js"="6/24/2014 6:57 PM, 799 bytes, A
       Adds the file main_installer.js"="5/29/2014 8:35 PM, 1567 bytes, A
       Adds the file migrate.js"="5/29/2014 8:35 PM, 4746 bytes, A
       Adds the file projectInstaller.js"="5/29/2014 8:35 PM, 3004 bytes, A
       Adds the file repair.js"="5/29/2014 8:35 PM, 1735 bytes, A
       Adds the file repair_data.json"="7/13/2014 10:30 AM, 2972 bytes, A
       Adds the file SoftwareDetector.exe"="6/24/2014 6:57 PM, 78848 bytes, A
       Adds the file sqlite3.exe"="5/29/2014 8:35 PM, 492544 bytes, A
       Adds the file storageedit.exe"="5/29/2014 8:35 PM, 75264 bytes, A
       Adds the file uninstall.exe"="7/13/2014 10:30 AM, 148173 bytes, A
    Adds the folder C:\Users\{username}\AppData\Local\SafetySearch\firefox
       Adds the file background.html"="6/26/2014 10:07 AM, 157 bytes, A
       Adds the file bootstrap.js"="6/26/2014 10:07 AM, 2857 bytes, A
       Adds the file chrome.manifest"="6/26/2014 10:07 AM, 57 bytes, A
       Adds the file extension_info.json"="6/26/2014 10:07 AM, 1687 bytes, A
       Adds the file install.rdf"="6/26/2014 10:07 AM, 1204 bytes, A
    Adds the folder C:\Users\{username}\AppData\Local\SafetySearch\firefox\AppFramework
       Adds the file appAPI_bg.js"="6/26/2014 10:07 AM, 2582 bytes, A
       Adds the file appAPI_browseraction.js"="6/26/2014 10:07 AM, 799 bytes, A
       Adds the file appAPI_common.js"="6/26/2014 10:07 AM, 9871 bytes, A
       Adds the file appAPI_content.js"="6/26/2014 10:07 AM, 1247 bytes, A
       Adds the file appAPI_settings.js"="6/26/2014 10:07 AM, 83 bytes, A
       Adds the file appAPI_webrequest.js"="6/26/2014 10:07 AM, 138 bytes, A
       Adds the file jquery.min.js"="6/26/2014 10:07 AM, 83059 bytes, A
    Adds the folder C:\Users\{username}\AppData\Local\SafetySearch\firefox\CanvasFramework
       Adds the file canvas_bg.js"="6/26/2014 10:07 AM, 5651 bytes, A
       Adds the file canvasscript_engine.js"="6/26/2014 10:07 AM, 437 bytes, A
       Adds the file md5.js"="6/26/2014 10:07 AM, 3264 bytes, A
       Adds the file registry.js"="6/26/2014 10:07 AM, 796 bytes, A
       Adds the file webrequest.js"="6/26/2014 10:07 AM, 5575 bytes, A
    Adds the folder C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework
       Adds the file backgroundscript_engine.js"="6/26/2014 10:07 AM, 1580 bytes, A
       Adds the file base.js"="6/26/2014 10:07 AM, 2933 bytes, A
       Adds the file browser.js"="6/26/2014 10:07 AM, 12801 bytes, A
       Adds the file chrome_windows.js"="6/26/2014 10:07 AM, 2627 bytes, A
       Adds the file console.js"="6/26/2014 10:07 AM, 540 bytes, A
       Adds the file content_proxy.js"="6/26/2014 10:07 AM, 502 bytes, A
       Adds the file framework.js"="6/26/2014 10:07 AM, 4381 bytes, A
       Adds the file i18n.js"="6/26/2014 10:07 AM, 1601 bytes, A
       Adds the file invoke_async.js"="6/26/2014 10:07 AM, 2312 bytes, A
       Adds the file io.js"="6/26/2014 10:07 AM, 976 bytes, A
       Adds the file lang.js"="6/26/2014 10:07 AM, 3080 bytes, A
       Adds the file legacy.js"="6/26/2014 10:07 AM, 1270 bytes, A
       Adds the file message_target.js"="6/26/2014 10:07 AM, 854 bytes, A
       Adds the file messaging.js"="6/26/2014 10:07 AM, 1507 bytes, A
       Adds the file storage.js"="6/26/2014 10:07 AM, 6156 bytes, A
       Adds the file timer.js"="6/26/2014 10:07 AM, 977 bytes, A
       Adds the file uninstall.js"="6/26/2014 10:07 AM, 73 bytes, A
       Adds the file userscript_client.js"="6/26/2014 10:07 AM, 310 bytes, A
       Adds the file userscript_engine.js"="6/26/2014 10:07 AM, 3062 bytes, A
       Adds the file utils.js"="6/26/2014 10:07 AM, 2492 bytes, A
       Adds the file xhr.js"="6/26/2014 10:07 AM, 2155 bytes, A
    Adds the folder C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui
       Adds the file browser_button.js"="6/26/2014 10:07 AM, 9099 bytes, A
       Adds the file content_notifications.js"="6/26/2014 10:07 AM, 9098 bytes, A
       Adds the file contentNotification.tmpl"="6/26/2014 10:07 AM, 836 bytes, A
       Adds the file contentNotificationStyle.tmpl"="6/26/2014 10:07 AM, 3729 bytes, A
       Adds the file context_menu.js"="6/26/2014 10:07 AM, 2144 bytes, A
       Adds the file framework_api.js"="6/26/2014 10:07 AM, 1627 bytes, A
       Adds the file notifications.js"="6/26/2014 10:07 AM, 3542 bytes, A
       Adds the file options.js"="6/26/2014 10:07 AM, 934 bytes, A
       Adds the file ui_base.js"="6/26/2014 10:07 AM, 1788 bytes, A
    Adds the folder C:\Users\{username}\AppData\Local\SafetySearch\firefox\icons
       Adds the file button.png"="6/26/2014 10:07 AM, 517 bytes, A
       Adds the file icon100.png"="6/26/2014 10:07 AM, 3526 bytes, A
       Adds the file icon128.png"="6/26/2014 10:07 AM, 4559 bytes, A
       Adds the file icon32.png"="6/26/2014 10:07 AM, 1095 bytes, A
       Adds the file icon48.png"="6/26/2014 10:07 AM, 1633 bytes, A
    Adds the folder C:\Users\{username}\AppData\LocalLow\Protect\Blocker
       Adds the file 212e90ffa529f5c99c44dc574c6f9a16"="7/13/2014 10:30 AM, 630176 bytes, A
       Adds the file 661d2a49ae9c29fdbdb0e735f567c5cf"="7/13/2014 10:30 AM, 106 bytes, A
       Adds the file 8d3f613ded3421026a6b47abd4042139"="7/13/2014 10:30 AM, 8 bytes, A
       Adds the file b24f88eb229178ba93accf228dc5b280"="7/13/2014 10:30 AM, 70 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SafetySearch
       Adds the file SafetySearch Settings.url"="7/13/2014 10:30 AM, 123 bytes, A
       Adds the file SafetySearch.lnk"="7/13/2014 10:30 AM, 1966 bytes, A
       Adds the file Uninstall.lnk"="7/13/2014 10:30 AM, 1076 bytes, A
    In the existing folder C:\Windows\System32\drivers\etc
       Alters the file hosts
        6/10/2009 11:39 PM, 824 bytes, A ==> 7/13/2014 10:30 AM, 872 bytes, A
    In the existing folder C:\Windows\System32\Tasks
       Adds the file bench-S-1-5-21-4016700205-1717049133-1125222536-1001"="7/13/2014 10:30 AM, 3234 bytes, A
       Adds the file bench-sys"="7/13/2014 10:30 AM, 3242 bytes, A
    In the existing folder C:\Windows\Tasks
       Adds the file bench-S-1-5-21-4016700205-1717049133-1125222536-1001.job"="7/13/2014 10:30 AM, 346 bytes, A
       Adds the file bench-sys.job"="7/13/2014 10:30 AM, 346 bytes, A

Registry details  
------------------------------------------
    [HKEY_LOCAL_MACHINE\SOFTWARE]
       "38989"="REG_SZ", "SafetySearch"
    [HKEY_LOCAL_MACHINE\SOFTWARE\AdvertisingSupport]
       "Existing"="REG_SZ", "0"
       "Seen"="REG_SZ", "1"
       "SeenDate"="REG_SZ", "1405240203"
       "SystemId"="REG_SZ", "619bdd98c7140d14e62a62d4922b6abd"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Bench\BService]
       "Path"="REG_SZ", "C:\Program Files\Bench\BService\1.1"
       "Version"="REG_SZ", "1.1"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Bench\BService\38989]
       "(Default)"="REG_SZ", ""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Bench\InstalledExtensions]
       "38989"="REG_SZ", ""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Bench\NmHost]
       "(Default)"="REG_SZ", "C:\Program Files\Bench\NmHost\nmhost.exe"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Bench\NmHost\38989]
       "(Default)"="REG_SZ", ""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Bench\Updater]
       "path"="REG_SZ", "C:\Program Files\Bench\Updater\updater.exe"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Bench\Updater\38989]
       "(Default)"="REG_SZ", ""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}]
       "(Default)"="REG_SZ", "SafetySearch BHO"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}\Implemented Categories\{59FB2056-D625-48D0-A944-1A85B5AB2640}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}\InprocServer32]
       "(Default)"="REG_SZ", "C:\Program Files\SafetySearch\FrameworkBHO.dll"
       "ThreadingModel"="REG_SZ", "Apartment"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}\Programmable]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}\TypeLib]
       "(Default)"="REG_SZ", "{B5D3A0F0-0BFE-429A-A322-95F076081845}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}\Version]
       "(Default)"="REG_SZ", "1.0"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7782DBE4-75A1-453D-B9FD-643F752E4532}]
       "(Default)"="REG_SZ", "SafetySearch"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7782DBE4-75A1-453D-B9FD-643F752E4532}\Implemented Categories\{59FB2056-D625-48D0-A944-1A85B5AB2640}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7782DBE4-75A1-453D-B9FD-643F752E4532}\InprocServer32]
       "(Default)"="REG_SZ", "C:\Program Files\SafetySearch\FrameworkBHO.dll"
       "ThreadingModel"="REG_SZ", "Apartment"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7782DBE4-75A1-453D-B9FD-643F752E4532}\Programmable]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7782DBE4-75A1-453D-B9FD-643F752E4532}\TypeLib]
       "(Default)"="REG_SZ", "{B5D3A0F0-0BFE-429A-A322-95F076081845}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7782DBE4-75A1-453D-B9FD-643F752E4532}\Version]
       "(Default)"="REG_SZ", "1.0"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92CECA0E-1DCB-4F42-BA4C-368094400351}]
       "(Default)"="REG_SZ", "SafetySearch"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92CECA0E-1DCB-4F42-BA4C-368094400351}\LocalServer32]
       "(Default)"="REG_SZ", ""C:\Program Files\SafetySearch\FrameworkEngine.exe""
       "ServerExecutable"="REG_SZ", "C:\Program Files\SafetySearch\FrameworkEngine.exe"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92CECA0E-1DCB-4F42-BA4C-368094400351}\Programmable]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92CECA0E-1DCB-4F42-BA4C-368094400351}\TypeLib]
       "(Default)"="REG_SZ", "{13FFE26E-E2A4-4AC8-9E82-FFC1A3C3578A}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92CECA0E-1DCB-4F42-BA4C-368094400351}\Version]
       "(Default)"="REG_SZ", "1.0"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1EE70D1D-B150-4ACF-8498-4C5DE80CEAAC}]
       "(Default)"="REG_SZ", "IKangoBHO"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1EE70D1D-B150-4ACF-8498-4C5DE80CEAAC}\ProxyStubClsid]
       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1EE70D1D-B150-4ACF-8498-4C5DE80CEAAC}\ProxyStubClsid32]
       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1EE70D1D-B150-4ACF-8498-4C5DE80CEAAC}\TypeLib]
       "(Default)"="REG_SZ", "{B5D3A0F0-0BFE-429A-A322-95F076081845}"
       "Version"="REG_SZ", "1.0"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7720DB57-7561-457F-B689-D03FB72E3932}]
       "(Default)"="REG_SZ", "IKangoToolbar"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7720DB57-7561-457F-B689-D03FB72E3932}\ProxyStubClsid]
       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7720DB57-7561-457F-B689-D03FB72E3932}\ProxyStubClsid32]
       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7720DB57-7561-457F-B689-D03FB72E3932}\TypeLib
       "(Default)"="REG_SZ", "{B5D3A0F0-0BFE-429A-A322-95F076081845}"
       "Version"="REG_SZ", "1.0"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{92ADCA6E-1D8C-4F50-BEBF-1480FD408251}]
       "(Default)"="REG_SZ", "IKangoEngine"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{92ADCA6E-1D8C-4F50-BEBF-1480FD408251}\ProxyStubClsid]
       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{92ADCA6E-1D8C-4F50-BEBF-1480FD408251}\ProxyStubClsid32]
       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{92ADCA6E-1D8C-4F50-BEBF-1480FD408251}\TypeLib]
       "(Default)"="REG_SZ", "{13FFE26E-E2A4-4AC8-9E82-FFC1A3C3578A}"
       "Version"="REG_SZ", "1.0"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{13FFE26E-E2A4-4AC8-9E82-FFC1A3C3578A}\1.0]
       "(Default)"="REG_SZ", "EngineLib"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{13FFE26E-E2A4-4AC8-9E82-FFC1A3C3578A}\1.0\0\win32]
       "(Default)"="REG_SZ", "C:\Program Files\SafetySearch\FrameworkEngine.exe"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{13FFE26E-E2A4-4AC8-9E82-FFC1A3C3578A}\1.0\FLAGS]
       "(Default)"="REG_SZ", "0"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{13FFE26E-E2A4-4AC8-9E82-FFC1A3C3578A}\1.0\HELPDIR]
       "(Default)"="REG_SZ", "C:\Program Files\SafetySearch"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{B5D3A0F0-0BFE-429A-A322-95F076081845}\1.0]
       "(Default)"="REG_SZ", "Framework 1.0 Type Library"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{B5D3A0F0-0BFE-429A-A322-95F076081845}\1.0\0\win32]
       "(Default)"="REG_SZ", "C:\Program Files\SafetySearch\FrameworkBHO.dll"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{B5D3A0F0-0BFE-429A-A322-95F076081845}\1.0\FLAGS]
       "(Default)"="REG_SZ", "0"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{B5D3A0F0-0BFE-429A-A322-95F076081845}\1.0\HELPDIR]
       "(Default)"="REG_SZ", "C:\Program Files\SafetySearch"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.bench.nmhost]
       "(Default)"="REG_SZ", "C:\Program Files\Bench\NmHost\manifest.json"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}]
       "(Default)"="REG_SZ", "SafetySearch BHO"
       "NoExplorer"="REG_DWORD", 1
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
       "Bench Communicator Watcher"="REG_SZ", "C:\Program Files\Bench\Proxy\pwdg.exe"
       "Bench Settings Cleaner"="REG_SZ", "C:\Program Files\Bench\Proxy\cl.exe"
       "BService"="REG_SZ", "C:\Program Files\Bench\BService\1.1\bservice.exe"
       "Wd"="REG_SZ", "C:\Program Files\Bench\Wd\wd.exe"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
       "SafetySearch"="REG_SZ", ""
       "SafetySearch-repairJob"="REG_SZ", "wscript.exe "C:\Users\{username}\AppData\Local\SafetySearch\repair.js" "SafetySearch-repairJob""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\38989_SafetySearch]
       "DisplayIcon"="REG_SZ", "C:\Users\{username}\AppData\Local\SafetySearch/icon.ico"
       "DisplayName"="REG_SZ", "SafetySearch"
       "DisplayVersion"="REG_SZ", "1.0"
       "InstallLocation"="REG_SZ", "C:\Users\{username}\AppData\Local\SafetySearch"
       "NoModify"="REG_DWORD", 1
       "NoRepair"="REG_DWORD", 1
       "Publisher"="REG_SZ", "Exciting Apps"
       "UninstallString"="REG_SZ", "C:\Users\{username}\AppData\Local\SafetySearch\uninstall.exe "
    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist]
       "1"="REG_SZ", "fjnoekdlmmjagmmlchagfonjgbioomoo;http://fjnoekdlmmjagmmlchagfonjgbioomoo/check/.eJwNyU0KgCAQQOG7zFqitl4mTEdT5wfUIojunsv3vReG6xUs-LMpIxi4sfWsMmlb1tlZ-nBE2MCOdqEBfMaew_yxiGINxFxcYiZ_uhRVSjqyKqvC9wPfWyFM.t27mdaCQFGhlnavJHDQywkB4OJ4"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Proxy]
       "AutoConfigURL"="REG_SZ", ""
       "ProxyEnable"="REG_DWORD", 0
       "ProxyServer"="REG_SZ", ""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Proxy\Installations\SafetySearch]
       "aoi"="REG_SZ", "1405247403"
       "domain"="REG_SZ", "safetysearch-a.akamaihd.net"
       "ext"="REG_SZ", "SafetySearch"
       "format"="REG_SZ", "//{domain}/loaders/{pid}/l.js?pid={pid}&systemid={systemid}&ext={ext}&aoi={aoi}&zoneid={zoneid}&crr={crr}&type=p"
       "pid"="REG_SZ", "2031"
       "protect_redirect_url"="REG_SZ", "http://safetysearch.net/warning.php?%blocked_url%"
       "settings_url"="REG_SZ", "http://safetysearch.net/settings.php"
       "system_black_list_url"="REG_SZ", "http://safetysearch-a.akamaihd.net/protect/rules.json"
       "zoneid"="REG_SZ", "622410"
    [HKEY_LOCAL_MACHINE\SOFTWARE\SafetySearch]
       "(Default)"="REG_SZ", "C:\Users\{username}\AppData\Local\SafetySearch"
       "AllowProxy"="REG_SZ", "1"
       "CDN"="REG_SZ", "safetysearch-a.akamaihd.net"
       "InstallTime"="REG_SZ", "1405247403"
       "Pid"="REG_SZ", "2031"
       "Seen"="REG_SZ", "1"
       "SeenDate"="REG_SZ", "1405240203"
       "SystemId"="REG_SZ", "619bdd98c7140d14e62a62d4922b6abd"
       "UTCInstallTime"="REG_SZ", "1405240203"
       "ZoneId"="REG_SZ", "622410"
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}]
       "Flags"="REG_DWORD", 1024
       "VerCache"="REG_BINARY, ......................
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
       "ProxyEnable
        REG_DWORD, 0 ==> REG_DWORD, 1
       "ProxyServer"="REG_SZ", "http=127.0.0.1:3128"
    [HKEY_CURRENT_USER\Software\Proxy\installations\SafetySearch]
       "czoneid"="REG_SZ", "673316"



Malwarebytes Anti-Malware log:
Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 7/13/2014
Scan Time: 10:39:35 AM
Logfile: mbamSafetySearch.txt
Administrator: Yes

Version: 2.00.2.1012
Malware Database: v2014.07.13.01
Rootkit Database: v2014.07.09.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: Malwarebytes

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 239831
Time Elapsed: 2 min, 44 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 5
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\FrameworkEngine.exe, 8768, Delete-on-Reboot, [20e5c5dabac1a195d4bab404df23cc34]
PUP.Optional.Bench.A, C:\Program Files\Bench\Wd\wd.exe, 9736, Delete-on-Reboot, [cf36d2cd88f357df7846d10832d029d7]
PUP.Optional.Bench.A, C:\Program Files\Bench\Proxy\pwdg.exe, 9916, Delete-on-Reboot, [6e97623d81faab8bb79b9d2d39c99f61]
PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bservice.exe, 9756, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d]
PUP.Optional.Bench.A, C:\Program Files\Bench\Proxy\proc.exe, 9260, Delete-on-Reboot, [11f4dac502791b1b385d565554ae857b]

Modules: 9
PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bhelper.dll, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], 
PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bhelper.dll, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], 
PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bhelper.dll, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], 
PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bhelper.dll, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], 
PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bhelper.dll, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], 
PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bhelper.dll, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], 
PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bhelper.dll, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], 
PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bhelper.dll, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], 
PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bhelper.dll, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], 

Registry Keys: 33
PUP.Optional.SafetySearch.A, HKLM\SOFTWARE\CLASSES\CLSID\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}, Quarantined, [cd38c3dc235854e2857078d88a786997], 
PUP.Optional.SafetySearch.A, HKLM\SOFTWARE\CLASSES\CLSID\{7782DBE4-75A1-453D-B9FD-643F752E4532}, Quarantined, [cd38c3dc235854e2857078d88a786997], 
PUP.Optional.SafetySearch.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{B5D3A0F0-0BFE-429A-A322-95F076081845}, Quarantined, [cd38c3dc235854e2857078d88a786997], 
PUP.Optional.SafetySearch.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{1EE70D1D-B150-4ACF-8498-4C5DE80CEAAC}, Quarantined, [cd38c3dc235854e2857078d88a786997], 
PUP.Optional.SafetySearch.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{7720DB57-7561-457F-B689-D03FB72E3932}, Quarantined, [cd38c3dc235854e2857078d88a786997], 
PUP.Optional.SafetySearch.A, HKLM\SOFTWARE\CLASSES\CLSID\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}\INPROCSERVER32, Quarantined, [cd38c3dc235854e2857078d88a786997], 
PUP.Optional.SafetySearch.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}, Quarantined, [cd38c3dc235854e2857078d88a786997], 
PUP.Optional.SafetySearch.A, HKU\S-1-5-21-4016700205-1717049133-1125222536-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}, Quarantined, [cd38c3dc235854e2857078d88a786997], 
PUP.Optional.SafetySearch.A, HKU\S-1-5-21-4016700205-1717049133-1125222536-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}, Quarantined, [cd38c3dc235854e2857078d88a786997], 
PUP.Optional.ExcitingApps.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\38989_SafetySearch, Quarantined, [13f22877601b93a350c99dfdb74ad030], 
PUP.Optional.SafetySearch.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{13FFE26E-E2A4-4AC8-9E82-FFC1A3C3578A}, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{92ADCA6E-1D8C-4F50-BEBF-1480FD408251}, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.Bench.A, HKLM\SOFTWARE\BENCH\BService, Quarantined, [28ddc6d95e1d9e98f42e6c597b8741bf], 
PUP.Optional.Bench.A, HKLM\SOFTWARE\BENCH\InstalledExtensions, Quarantined, [4fb627789cdf8da933f0f7ce17ebde22], 
PUP.Optional.Bench.A, HKLM\SOFTWARE\BENCH\NmHost, Quarantined, [c73ebfe0a4d743f3a57fa5200df5eb15], 
PUP.Optional.Bench.A, HKLM\SOFTWARE\BENCH\Updater, Quarantined, [699c8c1393e882b462c3d1f456ac966a], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\GLOBALUPDATE\UPDATE, Quarantined, [f1141b849fdc9e98706a6c4c17ebb64a], 
PUP.Optional.Bench.A, HKLM\SOFTWARE\GOOGLE\CHROME\NATIVEMESSAGINGHOSTS\com.bench.nmhost, Quarantined, [10f5c9d6b5c663d35bb442cdca3a16ea], 
PUP.Optional.SafetySearch.A, HKLM\SOFTWARE\PROXY\INSTALLATIONS\SafetySearch, Quarantined, [fc098b1490eb26100b816157cc363ac6], 
PUP.Optional.SafetySearch.A, HKU\S-1-5-21-4016700205-1717049133-1125222536-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\PROXY\INSTALLATIONS\SafetySearch, Quarantined, [5ca99f00710ac86e008dd9df8181d22e], 
PUP.Optional.GlobalUpdate.T, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\globalUpdate, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], 
PUP.Optional.GlobalUpdate.T, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\globalUpdatem, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.OneClickCtrl.10, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.Update3WebControl.4, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], 

Registry Values: 7
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\GLOBALUPDATE\UPDATE|path, C:\Program Files\globalUpdate\Update\GoogleUpdate.exe, Quarantined, [f1141b849fdc9e98706a6c4c17ebb64a]
PUP.Optional.Bench.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Wd, C:\Program Files\Bench\Wd\wd.exe, Quarantined, [cf36d2cd88f357df7846d10832d029d7]
PUP.Optional.Bench.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Bench Communicator Watcher, C:\Program Files\Bench\Proxy\pwdg.exe, Quarantined, [6e97623d81faab8bb79b9d2d39c99f61]
PUP.Optional.Bench.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Bench Settings Cleaner, C:\Program Files\Bench\Proxy\cl.exe, Quarantined, [ff06bde256250e28da793892837fae52]
PUP.Optional.SmartApps, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE|SafetySearch-repairJob, wscript.exe "C:\Users\{username}\AppData\Local\SafetySearch\repair.js" "SafetySearch-repairJob", Quarantined, [c144613ecfac0036b51c61ae06fef40c]
PUM.Bad.Proxy, HKU\S-1-5-21-4016700205-1717049133-1125222536-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|ProxyServer, http=127.0.0.1:3128, Quarantined, [dc29fca346358caa12c6b90a2cd628d8]
PUP.Optional.Bench.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|BService, C:\Program Files\Bench\BService\1.1\bservice.exe, Quarantined, [f213efb03348e3538776851c9e64d32d]

Registry Data: 0
(No malicious items detected)

Folders: 32
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch, Delete-on-Reboot, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\AppFramework, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\CanvasFramework, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\icons, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.BenchUpdater, C:\Program Files\Bench\NmHost, Quarantined, [50b5f9a67605d363a299459cb1516799], 
PUP.Optional.BenchUpdater, C:\Program Files\Bench\NmHost\data, Quarantined, [50b5f9a67605d363a299459cb1516799], 
PUP.Optional.BenchUpdater, C:\Program Files\Bench\NmHost\data\installer, Quarantined, [50b5f9a67605d363a299459cb1516799], 
PUP.Optional.BenchUpdater.A, C:\Users\{username}\AppData\Local\BenchUpdater, Quarantined, [df26cad5d4a7a294d27819c9c33fd32d], 
PUP.Optional.AdwarePlugin, C:\Program Files\Bench\Updater, Quarantined, [2fd659468eed1e1861b51e81ba481be5], 
PUP.Optional.AdwarePlugin, C:\Program Files\Bench\Updater\1.7.0.0, Quarantined, [2fd659468eed1e1861b51e81ba481be5], 
PUP.Optional.Bench.A, C:\Program Files\Bench\BService, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], 
PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], 
PUP.Optional.Bench.A, C:\Program Files\Bench\Wd, Delete-on-Reboot, [2cd99a05ed8ea0966e90a8f93dc5af51], 
PUP.Optional.Bench.A, C:\Program Files\Bench\Proxy, Delete-on-Reboot, [11f4dac502791b1b385d565554ae857b], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Download, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Install, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Offline, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Offline\{9DB71709-E211-41A5-994F-F15E83C89F59}, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624, Quarantined, [44c1a9f605761026bf646a4ee81ac040], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch, Delete-on-Reboot, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\AppFramework, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\CanvasFramework, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\icons, Quarantined, [986d633cd8a373c3206996224eb4cb35], 

Files: 180
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\FrameworkBHO.dll, Quarantined, [cd38c3dc235854e2857078d88a786997], 
PUP.Optional.ExcitingApps.A, C:\Users\{username}\Desktop\SafetySearch_2606-d82f5459.exe, Quarantined, [8d78564932498aac6dac1486847db14f], 
PUP.Optional.InstallCore, C:\Users\{username}\Downloads\googleupdatersetup.exe, Quarantined, [8c7988170e6d81b5c4319cf3c63e8c74], 
PUP.Optional.ExcitingApps.A, C:\Users\{username}\AppData\Local\SafetySearch\uninstall.exe, Quarantined, [13f22877601b93a350c99dfdb74ad030], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\background.html, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\config.xml, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\extension_info.json, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\FrameworkBHO64.dll, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\FrameworkEngine.exe, Delete-on-Reboot, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\AppFramework\appAPI_bg.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\AppFramework\appAPI_browseraction.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\AppFramework\appAPI_common.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\AppFramework\appAPI_content.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\AppFramework\appAPI_settings.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\AppFramework\appAPI_webrequest.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\AppFramework\jquery.min.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\CanvasFramework\canvasscript_engine.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\CanvasFramework\canvas_bg.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\CanvasFramework\md5.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\CanvasFramework\registry.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\CanvasFramework\webrequest.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\backgroundscript_engine.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\base.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\browser.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\console.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\framework.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\global.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\i18n.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\initialize.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\invoke_async.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\io.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\json2.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\lang.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\legacy.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\message_target.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\messaging.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\storage.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\timer.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\updater.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\userscript_client.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\userscript_engine.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\utils.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\xhr.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\browser_button.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\context_menu.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\context_menu_item_handler.html, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\framework_api.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\notification.html, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\notifications.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\options.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\ui_base.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\bottom-left.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\bottom-middle.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\bottom-right.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\middle-left.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\middle-right.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\tail-bottom.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\tail-left.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\tail-right.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\tail-top.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\top-left.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\top-middle.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\top-right.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\icons\button.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\icons\icon100.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\icons\icon128.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\icons\icon32.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\icons\icon48.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], 
PUP.Optional.BenchUpdater.A, C:\Windows\System32\Tasks\bench-S-1-5-21-4016700205-1717049133-1125222536-1001, Quarantined, [28ddb5ea37448aacd4bdefce6f936a96], 
PUP.Optional.BenchUpdater.A, C:\Windows\System32\Tasks\bench-sys, Quarantined, [c93c3b644d2e092d9af735881ae828d8], 
PUP.Optional.BenchUpdater, C:\Program Files\Bench\NmHost\nmhost.exe, Quarantined, [50b5f9a67605d363a299459cb1516799], 
PUP.Optional.BenchUpdater, C:\Program Files\Bench\NmHost\manifest.json, Quarantined, [50b5f9a67605d363a299459cb1516799], 
PUP.Optional.BenchUpdater, C:\Program Files\Bench\NmHost\data\installer\fjnoekdlmmjagmmlchagfonjgbioomoo, Quarantined, [50b5f9a67605d363a299459cb1516799], 
PUP.Optional.BenchUpdater.A, C:\Windows\Tasks\bench-S-1-5-21-4016700205-1717049133-1125222536-1001.job, Quarantined, [897c9708cfac7abce762558d34ce1fe1], 
PUP.Optional.BenchUpdater.A, C:\Windows\Tasks\bench-sys.job, Quarantined, [44c18a151e5d94a2ee5b02e0837fd62a], 
PUP.Optional.BenchUpdater.A, C:\Users\{username}\AppData\Local\BenchUpdater\products.xml, Quarantined, [df26cad5d4a7a294d27819c9c33fd32d], 
PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job, Quarantined, [ae57fda2f88301356f2c31e6739110f0], 
PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore, Quarantined, [fa0b7926daa160d6306c809747bda15f], 
PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job, Quarantined, [c441f1ae532837ffe4b9cc4be61ec040], 
PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA, Quarantined, [cf36b5ea512ab680ecb2f126ba4aad53], 
PUP.Optional.Bench.A, C:\Program Files\Bench\Wd\wd.exe, Delete-on-Reboot, [cf36d2cd88f357df7846d10832d029d7], 
PUP.Optional.Bench.A, C:\Program Files\Bench\Proxy\pwdg.exe, Delete-on-Reboot, [6e97623d81faab8bb79b9d2d39c99f61], 
PUP.Optional.Bench.A, C:\Program Files\Bench\Proxy\cl.exe, Quarantined, [ff06bde256250e28da793892837fae52], 
PUP.Optional.SmartApps, C:\Users\{username}\AppData\Local\SafetySearch\repair.js, Quarantined, [c144613ecfac0036b51c61ae06fef40c], 
PUP.Optional.AdwarePlugin, C:\Program Files\Bench\Updater\products.xml, Quarantined, [2fd659468eed1e1861b51e81ba481be5], 
PUP.Optional.AdwarePlugin, C:\Program Files\Bench\Updater\updater.exe, Quarantined, [2fd659468eed1e1861b51e81ba481be5], 
PUP.Optional.AdwarePlugin, C:\Program Files\Bench\Updater\1.7.0.0\updater.exe, Quarantined, [2fd659468eed1e1861b51e81ba481be5], 
PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bhelper.dll, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], 
PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bservice.exe, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], 
PUP.Optional.Bench.A, C:\Program Files\Bench\Proxy\icon.ico, Quarantined, [11f4dac502791b1b385d565554ae857b], 
PUP.Optional.Bench.A, C:\Program Files\Bench\Proxy\proc.exe, Delete-on-Reboot, [11f4dac502791b1b385d565554ae857b], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\GoogleUpdate.exe, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateHelper.msi, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\goopdate.dll, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\goopdateres_en.dll, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\psmachine.dll, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\psuser.dll, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624\GoogleCrashHandler.exe, Quarantined, [44c1a9f605761026bf646a4ee81ac040], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624\GoogleUpdate.exe, Quarantined, [44c1a9f605761026bf646a4ee81ac040], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624\GoogleUpdateBroker.exe, Quarantined, [44c1a9f605761026bf646a4ee81ac040], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624\GoogleUpdateHelper.msi, Quarantined, [44c1a9f605761026bf646a4ee81ac040], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624\GoogleUpdateOnDemand.exe, Quarantined, [44c1a9f605761026bf646a4ee81ac040], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624\goopdate.dll, Quarantined, [44c1a9f605761026bf646a4ee81ac040], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624\goopdateres_en.dll, Quarantined, [44c1a9f605761026bf646a4ee81ac040], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624\npGoogleUpdate4.dll, Quarantined, [44c1a9f605761026bf646a4ee81ac040], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624\psmachine.dll, Quarantined, [44c1a9f605761026bf646a4ee81ac040], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624\psuser.dll, Quarantined, [44c1a9f605761026bf646a4ee81ac040], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\chrome_gp_update.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\chrome_installer.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\clear_cache.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\common.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox_installer.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\gpedit.exe, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\icon.ico, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\ie_installer.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\installer.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\main_installer.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\migrate.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\projectInstaller.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\repair_data.json, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\SoftwareDetector.exe, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\sqlite3.exe, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\storageedit.exe, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\background.html, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\bootstrap.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\chrome.manifest, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\extension_info.json, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\install.rdf, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\AppFramework\appAPI_bg.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\AppFramework\appAPI_browseraction.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\AppFramework\appAPI_common.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\AppFramework\appAPI_content.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\AppFramework\appAPI_settings.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\AppFramework\appAPI_webrequest.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\AppFramework\jquery.min.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\CanvasFramework\canvasscript_engine.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\CanvasFramework\canvas_bg.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\CanvasFramework\md5.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\CanvasFramework\registry.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\CanvasFramework\webrequest.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\backgroundscript_engine.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\base.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\browser.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\chrome_windows.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\console.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\content_proxy.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\framework.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\i18n.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\invoke_async.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\io.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\lang.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\legacy.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\message_target.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\messaging.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\storage.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\timer.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\uninstall.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\userscript_client.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\userscript_engine.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\utils.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\xhr.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui\browser_button.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui\contentNotification.tmpl, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui\contentNotificationStyle.tmpl, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui\content_notifications.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui\context_menu.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui\framework_api.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui\notifications.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui\options.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui\ui_base.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\icons\button.png, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\icons\icon100.png, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\icons\icon128.png, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\icons\icon32.png, Quarantined, [986d633cd8a373c3206996224eb4cb35], 
PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\icons\icon48.png, Quarantined, [986d633cd8a373c3206996224eb4cb35], 

Physical Sectors: 0
(No malicious items detected)


(end)
As mentioned before the full version of Malwarebytes Anti-Malware could have protected your computer against this threat.
We use different ways of protecting your computer(s):
  • Dynamically Blocks Malware Sites & Servers
  • Malware Execution Prevention
Save yourself the hassle and get protected.
  • 0

Advertisements





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

featured
Malware Removal How to Guides Windows 7 System Building Download Files Register welcome

Never used a forum? Learn how.