What is SafetySearch?
The Malwarebytes research team has determined that SafetySearch is a browser hijacker. These so-called "hijackers" alter your startpage or searchscopes so that the effected browser visits their site or one of their choice. This one also displays advertisements.
How do I know if my computer is affected by SafetySearch?
This is how the start-page looks:

And you may see these add-ons:


or this entry in your list of installed programs:

You will find this icon in your taskbar:

How did SafetySearch get on my computer?
Browser hijackers use different methods for distributing themselves. This particular one was offered as web security software.
How do I remove SafetySearch?
Our program Malwarebytes Anti-Malware can detect and remove this potentially unwanted application.
- Please download Malwarebytes Anti-Malware to your desktop.
- Double-click mbam-setup-version.exe and follow the prompts to install the program.
- At the end, be sure a check-mark is placed next to the following:
- Enable free trial of Malwarebytes Anti-Malware Premium
- Launch Malwarebytes Anti-Malware
- Then click Finish.
- If an update is found, you will be prompted to download and install the latest version.
- Once the program has loaded, select Scan now. Or select the Threat Scan from the Scan menu.
- When the scan is complete , make sure that everything is set to "Quarantine", and click Apply Actions.
- Reboot your computer if prompted.
- No, Malwarebytes' Anti-Malware removes SafetySearch completely.
We hope our application and this guide have helped you eradicate this hijacker.
As you can see below the full version of Malwarebytes Anti-Malware would have protected you against the SafetySearch rogue. It would have warned you before the rogue could install itself, giving you a chance to stop it before it became too late.
Signs in a HijackThis log:
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:3128 O1 - Hosts: 54.225.95.126 fjnoekdlmmjagmmlchagfonjgbioomoo O2 - BHO: SafetySearch BHO - {1EDE0D83-B129-4ABC-923B-725D5B0C0DAC} - C:\Program Files\SafetySearch\FrameworkBHO.dll O4 - HKLM\..\Run: [BService] C:\Program Files\Bench\BService\1.1\bservice.exe O4 - HKLM\..\Run: [Wd] C:\Program Files\Bench\Wd\wd.exe O4 - HKLM\..\Run: [Bench Communicator Watcher] C:\Program Files\Bench\Proxy\pwdg.exe O4 - HKLM\..\Run: [Bench Settings Cleaner] C:\Program Files\Bench\Proxy\cl.exe O4 - HKLM\..\RunOnce: [SafetySearch-repairJob] wscript.exe "C:\Users\{username}\AppData\Local\SafetySearch\repair.js" "SafetySearch-repairJob"Alterations made by the installer:
File system details --------------------------------------------- Adds the folder C:\Program Files\Bench\BService\1.1 Adds the file bhelper.dll"="5/29/2014 8:35 PM, 53248 bytes, A Adds the file bservice.exe"="6/24/2014 6:57 PM, 52736 bytes, A Adds the folder C:\Program Files\Bench\NmHost Adds the file manifest.json"="7/13/2014 10:30 AM, 215 bytes, A Adds the file nmhost.exe"="5/29/2014 8:35 PM, 165376 bytes, A Adds the folder C:\Program Files\Bench\NmHost\data\installer Adds the file fjnoekdlmmjagmmlchagfonjgbioomoo"="7/13/2014 10:30 AM, 954 bytes, A Adds the folder C:\Program Files\Bench\Proxy Adds the file cl.exe"="6/17/2014 5:44 PM, 55296 bytes, A Adds the file icon.ico"="6/26/2014 10:07 AM, 32038 bytes, A Adds the file proc.exe"="6/17/2014 5:44 PM, 422912 bytes, A Adds the file pwdg.exe"="6/17/2014 5:44 PM, 113152 bytes, A Adds the folder C:\Program Files\Bench\Updater Adds the file products.xml"="7/13/2014 10:30 AM, 377 bytes, A Adds the file updater.exe"="5/29/2014 8:35 PM, 69120 bytes, A Adds the folder C:\Program Files\Bench\Updater\1.7.0.0 Adds the file updater.exe"="5/29/2014 8:35 PM, 468480 bytes, A Adds the folder C:\Program Files\Bench\Wd Adds the file wd.exe"="6/17/2014 5:44 PM, 92672 bytes, A Adds the folder C:\Program Files\SafetySearch Adds the file background.html"="6/26/2014 10:07 AM, 157 bytes, A Adds the file config.xml"="6/26/2014 10:07 AM, 2242 bytes, A Adds the file extension_info.json"="7/13/2014 10:30 AM, 2370 bytes, A Adds the file FrameworkBHO.dll"="6/26/2014 10:07 AM, 471600 bytes, A Adds the file FrameworkBHO64.dll"="6/26/2014 10:07 AM, 492880 bytes, A Adds the file FrameworkEngine.exe"="6/26/2014 10:07 AM, 264752 bytes, A Adds the folder C:\Program Files\SafetySearch\AppFramework Adds the file appAPI_bg.js"="6/26/2014 10:07 AM, 2582 bytes, A Adds the file appAPI_browseraction.js"="6/26/2014 10:07 AM, 799 bytes, A Adds the file appAPI_common.js"="6/26/2014 10:07 AM, 9871 bytes, A Adds the file appAPI_content.js"="6/26/2014 10:07 AM, 1247 bytes, A Adds the file appAPI_settings.js"="6/26/2014 10:07 AM, 83 bytes, A Adds the file appAPI_webrequest.js"="6/26/2014 10:07 AM, 138 bytes, A Adds the file jquery.min.js"="6/26/2014 10:07 AM, 93548 bytes, A Adds the folder C:\Program Files\SafetySearch\CanvasFramework Adds the file canvas_bg.js"="6/26/2014 10:07 AM, 5651 bytes, A Adds the file canvasscript_engine.js"="6/26/2014 10:07 AM, 437 bytes, A Adds the file md5.js"="6/26/2014 10:07 AM, 3264 bytes, A Adds the file registry.js"="6/26/2014 10:07 AM, 908 bytes, A Adds the file webrequest.js"="6/26/2014 10:07 AM, 4005 bytes, A Adds the folder C:\Program Files\SafetySearch\framework Adds the file backgroundscript_engine.js"="6/26/2014 10:07 AM, 1872 bytes, A Adds the file base.js"="6/26/2014 10:07 AM, 2933 bytes, A Adds the file browser.js"="6/26/2014 10:07 AM, 11200 bytes, A Adds the file console.js"="6/26/2014 10:07 AM, 489 bytes, A Adds the file framework.js"="6/26/2014 10:07 AM, 3542 bytes, A Adds the file global.js"="6/26/2014 10:07 AM, 1850 bytes, A Adds the file i18n.js"="6/26/2014 10:07 AM, 1661 bytes, A Adds the file initialize.js"="6/26/2014 10:07 AM, 316 bytes, A Adds the file invoke_async.js"="6/26/2014 10:07 AM, 2312 bytes, A Adds the file io.js"="6/26/2014 10:07 AM, 1308 bytes, A Adds the file json2.js"="6/26/2014 10:07 AM, 2791 bytes, A Adds the file lang.js"="6/26/2014 10:07 AM, 1633 bytes, A Adds the file legacy.js"="6/26/2014 10:07 AM, 1270 bytes, A Adds the file message_target.js"="6/26/2014 10:07 AM, 854 bytes, A Adds the file messaging.js"="6/26/2014 10:07 AM, 1507 bytes, A Adds the file storage.js"="6/26/2014 10:07 AM, 3603 bytes, A Adds the file timer.js"="6/26/2014 10:07 AM, 409 bytes, A Adds the file updater.js"="6/26/2014 10:07 AM, 2417 bytes, A Adds the file userscript_client.js"="6/26/2014 10:07 AM, 310 bytes, A Adds the file userscript_engine.js"="6/26/2014 10:07 AM, 3062 bytes, A Adds the file utils.js"="6/26/2014 10:07 AM, 2492 bytes, A Adds the file xhr.js"="6/26/2014 10:07 AM, 3081 bytes, A Adds the folder C:\Program Files\SafetySearch\framework-ui Adds the file browser_button.js"="6/26/2014 10:07 AM, 5135 bytes, A Adds the file context_menu.js"="6/26/2014 10:07 AM, 738 bytes, A Adds the file context_menu_item_handler.html"="6/26/2014 10:07 AM, 225 bytes, A Adds the file framework_api.js"="6/26/2014 10:07 AM, 1589 bytes, A Adds the file notification.html"="6/26/2014 10:07 AM, 6591 bytes, A Adds the file notifications.js"="6/26/2014 10:07 AM, 2409 bytes, A Adds the file options.js"="6/26/2014 10:07 AM, 660 bytes, A Adds the file ui_base.js"="6/26/2014 10:07 AM, 1788 bytes, A Adds the folder C:\Program Files\SafetySearch\framework-ui\theme\bubble Adds the file bottom-left.png"="6/26/2014 10:07 AM, 316 bytes, A Adds the file bottom-middle.png"="6/26/2014 10:07 AM, 240 bytes, A Adds the file bottom-right.png"="6/26/2014 10:07 AM, 311 bytes, A Adds the file middle-left.png"="6/26/2014 10:07 AM, 235 bytes, A Adds the file middle-right.png"="6/26/2014 10:07 AM, 234 bytes, A Adds the file tail-bottom.png"="6/26/2014 10:07 AM, 315 bytes, A Adds the file tail-left.png"="6/26/2014 10:07 AM, 307 bytes, A Adds the file tail-right.png"="6/26/2014 10:07 AM, 304 bytes, A Adds the file tail-top.png"="6/26/2014 10:07 AM, 315 bytes, A Adds the file top-left.png"="6/26/2014 10:07 AM, 310 bytes, A Adds the file top-middle.png"="6/26/2014 10:07 AM, 240 bytes, A Adds the file top-right.png"="6/26/2014 10:07 AM, 308 bytes, A Adds the folder C:\Program Files\SafetySearch\icons Adds the file button.png"="6/26/2014 10:07 AM, 517 bytes, A Adds the file icon100.png"="6/26/2014 10:07 AM, 3526 bytes, A Adds the file icon128.png"="6/26/2014 10:07 AM, 4559 bytes, A Adds the file icon32.png"="6/26/2014 10:07 AM, 1095 bytes, A Adds the file icon48.png"="6/26/2014 10:07 AM, 1633 bytes, A Adds the folder C:\Users\{username}\AppData\Local\BenchUpdater Adds the file products.xml"="7/13/2014 10:30 AM, 442 bytes, A Adds the folder C:\Users\{username}\AppData\Local\SafetySearch Adds the file chrome_gp_update.js"="5/29/2014 8:35 PM, 2348 bytes, A Adds the file chrome_installer.js"="6/24/2014 6:57 PM, 6304 bytes, A Adds the file clear_cache.js"="6/17/2014 5:44 PM, 522 bytes, A Adds the file common.js"="6/24/2014 6:57 PM, 13550 bytes, A Adds the file firefox_installer.js"="6/17/2014 5:44 PM, 6848 bytes, A Adds the file gpedit.exe"="6/24/2014 6:57 PM, 95744 bytes, A Adds the file icon.ico"="6/26/2014 10:07 AM, 32038 bytes, A Adds the file ie_installer.js"="6/17/2014 5:44 PM, 3685 bytes, A Adds the file installer.js"="6/24/2014 6:57 PM, 799 bytes, A Adds the file main_installer.js"="5/29/2014 8:35 PM, 1567 bytes, A Adds the file migrate.js"="5/29/2014 8:35 PM, 4746 bytes, A Adds the file projectInstaller.js"="5/29/2014 8:35 PM, 3004 bytes, A Adds the file repair.js"="5/29/2014 8:35 PM, 1735 bytes, A Adds the file repair_data.json"="7/13/2014 10:30 AM, 2972 bytes, A Adds the file SoftwareDetector.exe"="6/24/2014 6:57 PM, 78848 bytes, A Adds the file sqlite3.exe"="5/29/2014 8:35 PM, 492544 bytes, A Adds the file storageedit.exe"="5/29/2014 8:35 PM, 75264 bytes, A Adds the file uninstall.exe"="7/13/2014 10:30 AM, 148173 bytes, A Adds the folder C:\Users\{username}\AppData\Local\SafetySearch\firefox Adds the file background.html"="6/26/2014 10:07 AM, 157 bytes, A Adds the file bootstrap.js"="6/26/2014 10:07 AM, 2857 bytes, A Adds the file chrome.manifest"="6/26/2014 10:07 AM, 57 bytes, A Adds the file extension_info.json"="6/26/2014 10:07 AM, 1687 bytes, A Adds the file install.rdf"="6/26/2014 10:07 AM, 1204 bytes, A Adds the folder C:\Users\{username}\AppData\Local\SafetySearch\firefox\AppFramework Adds the file appAPI_bg.js"="6/26/2014 10:07 AM, 2582 bytes, A Adds the file appAPI_browseraction.js"="6/26/2014 10:07 AM, 799 bytes, A Adds the file appAPI_common.js"="6/26/2014 10:07 AM, 9871 bytes, A Adds the file appAPI_content.js"="6/26/2014 10:07 AM, 1247 bytes, A Adds the file appAPI_settings.js"="6/26/2014 10:07 AM, 83 bytes, A Adds the file appAPI_webrequest.js"="6/26/2014 10:07 AM, 138 bytes, A Adds the file jquery.min.js"="6/26/2014 10:07 AM, 83059 bytes, A Adds the folder C:\Users\{username}\AppData\Local\SafetySearch\firefox\CanvasFramework Adds the file canvas_bg.js"="6/26/2014 10:07 AM, 5651 bytes, A Adds the file canvasscript_engine.js"="6/26/2014 10:07 AM, 437 bytes, A Adds the file md5.js"="6/26/2014 10:07 AM, 3264 bytes, A Adds the file registry.js"="6/26/2014 10:07 AM, 796 bytes, A Adds the file webrequest.js"="6/26/2014 10:07 AM, 5575 bytes, A Adds the folder C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework Adds the file backgroundscript_engine.js"="6/26/2014 10:07 AM, 1580 bytes, A Adds the file base.js"="6/26/2014 10:07 AM, 2933 bytes, A Adds the file browser.js"="6/26/2014 10:07 AM, 12801 bytes, A Adds the file chrome_windows.js"="6/26/2014 10:07 AM, 2627 bytes, A Adds the file console.js"="6/26/2014 10:07 AM, 540 bytes, A Adds the file content_proxy.js"="6/26/2014 10:07 AM, 502 bytes, A Adds the file framework.js"="6/26/2014 10:07 AM, 4381 bytes, A Adds the file i18n.js"="6/26/2014 10:07 AM, 1601 bytes, A Adds the file invoke_async.js"="6/26/2014 10:07 AM, 2312 bytes, A Adds the file io.js"="6/26/2014 10:07 AM, 976 bytes, A Adds the file lang.js"="6/26/2014 10:07 AM, 3080 bytes, A Adds the file legacy.js"="6/26/2014 10:07 AM, 1270 bytes, A Adds the file message_target.js"="6/26/2014 10:07 AM, 854 bytes, A Adds the file messaging.js"="6/26/2014 10:07 AM, 1507 bytes, A Adds the file storage.js"="6/26/2014 10:07 AM, 6156 bytes, A Adds the file timer.js"="6/26/2014 10:07 AM, 977 bytes, A Adds the file uninstall.js"="6/26/2014 10:07 AM, 73 bytes, A Adds the file userscript_client.js"="6/26/2014 10:07 AM, 310 bytes, A Adds the file userscript_engine.js"="6/26/2014 10:07 AM, 3062 bytes, A Adds the file utils.js"="6/26/2014 10:07 AM, 2492 bytes, A Adds the file xhr.js"="6/26/2014 10:07 AM, 2155 bytes, A Adds the folder C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui Adds the file browser_button.js"="6/26/2014 10:07 AM, 9099 bytes, A Adds the file content_notifications.js"="6/26/2014 10:07 AM, 9098 bytes, A Adds the file contentNotification.tmpl"="6/26/2014 10:07 AM, 836 bytes, A Adds the file contentNotificationStyle.tmpl"="6/26/2014 10:07 AM, 3729 bytes, A Adds the file context_menu.js"="6/26/2014 10:07 AM, 2144 bytes, A Adds the file framework_api.js"="6/26/2014 10:07 AM, 1627 bytes, A Adds the file notifications.js"="6/26/2014 10:07 AM, 3542 bytes, A Adds the file options.js"="6/26/2014 10:07 AM, 934 bytes, A Adds the file ui_base.js"="6/26/2014 10:07 AM, 1788 bytes, A Adds the folder C:\Users\{username}\AppData\Local\SafetySearch\firefox\icons Adds the file button.png"="6/26/2014 10:07 AM, 517 bytes, A Adds the file icon100.png"="6/26/2014 10:07 AM, 3526 bytes, A Adds the file icon128.png"="6/26/2014 10:07 AM, 4559 bytes, A Adds the file icon32.png"="6/26/2014 10:07 AM, 1095 bytes, A Adds the file icon48.png"="6/26/2014 10:07 AM, 1633 bytes, A Adds the folder C:\Users\{username}\AppData\LocalLow\Protect\Blocker Adds the file 212e90ffa529f5c99c44dc574c6f9a16"="7/13/2014 10:30 AM, 630176 bytes, A Adds the file 661d2a49ae9c29fdbdb0e735f567c5cf"="7/13/2014 10:30 AM, 106 bytes, A Adds the file 8d3f613ded3421026a6b47abd4042139"="7/13/2014 10:30 AM, 8 bytes, A Adds the file b24f88eb229178ba93accf228dc5b280"="7/13/2014 10:30 AM, 70 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SafetySearch Adds the file SafetySearch Settings.url"="7/13/2014 10:30 AM, 123 bytes, A Adds the file SafetySearch.lnk"="7/13/2014 10:30 AM, 1966 bytes, A Adds the file Uninstall.lnk"="7/13/2014 10:30 AM, 1076 bytes, A In the existing folder C:\Windows\System32\drivers\etc Alters the file hosts 6/10/2009 11:39 PM, 824 bytes, A ==> 7/13/2014 10:30 AM, 872 bytes, A In the existing folder C:\Windows\System32\Tasks Adds the file bench-S-1-5-21-4016700205-1717049133-1125222536-1001"="7/13/2014 10:30 AM, 3234 bytes, A Adds the file bench-sys"="7/13/2014 10:30 AM, 3242 bytes, A In the existing folder C:\Windows\Tasks Adds the file bench-S-1-5-21-4016700205-1717049133-1125222536-1001.job"="7/13/2014 10:30 AM, 346 bytes, A Adds the file bench-sys.job"="7/13/2014 10:30 AM, 346 bytes, A Registry details ------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE] "38989"="REG_SZ", "SafetySearch" [HKEY_LOCAL_MACHINE\SOFTWARE\AdvertisingSupport] "Existing"="REG_SZ", "0" "Seen"="REG_SZ", "1" "SeenDate"="REG_SZ", "1405240203" "SystemId"="REG_SZ", "619bdd98c7140d14e62a62d4922b6abd" [HKEY_LOCAL_MACHINE\SOFTWARE\Bench\BService] "Path"="REG_SZ", "C:\Program Files\Bench\BService\1.1" "Version"="REG_SZ", "1.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Bench\BService\38989] "(Default)"="REG_SZ", "" [HKEY_LOCAL_MACHINE\SOFTWARE\Bench\InstalledExtensions] "38989"="REG_SZ", "" [HKEY_LOCAL_MACHINE\SOFTWARE\Bench\NmHost] "(Default)"="REG_SZ", "C:\Program Files\Bench\NmHost\nmhost.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Bench\NmHost\38989] "(Default)"="REG_SZ", "" [HKEY_LOCAL_MACHINE\SOFTWARE\Bench\Updater] "path"="REG_SZ", "C:\Program Files\Bench\Updater\updater.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Bench\Updater\38989] "(Default)"="REG_SZ", "" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}] "(Default)"="REG_SZ", "SafetySearch BHO" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}\Implemented Categories\{59FB2056-D625-48D0-A944-1A85B5AB2640}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}\InprocServer32] "(Default)"="REG_SZ", "C:\Program Files\SafetySearch\FrameworkBHO.dll" "ThreadingModel"="REG_SZ", "Apartment" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}\Programmable] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}\TypeLib] "(Default)"="REG_SZ", "{B5D3A0F0-0BFE-429A-A322-95F076081845}" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}\Version] "(Default)"="REG_SZ", "1.0" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7782DBE4-75A1-453D-B9FD-643F752E4532}] "(Default)"="REG_SZ", "SafetySearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7782DBE4-75A1-453D-B9FD-643F752E4532}\Implemented Categories\{59FB2056-D625-48D0-A944-1A85B5AB2640}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7782DBE4-75A1-453D-B9FD-643F752E4532}\InprocServer32] "(Default)"="REG_SZ", "C:\Program Files\SafetySearch\FrameworkBHO.dll" "ThreadingModel"="REG_SZ", "Apartment" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7782DBE4-75A1-453D-B9FD-643F752E4532}\Programmable] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7782DBE4-75A1-453D-B9FD-643F752E4532}\TypeLib] "(Default)"="REG_SZ", "{B5D3A0F0-0BFE-429A-A322-95F076081845}" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7782DBE4-75A1-453D-B9FD-643F752E4532}\Version] "(Default)"="REG_SZ", "1.0" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92CECA0E-1DCB-4F42-BA4C-368094400351}] "(Default)"="REG_SZ", "SafetySearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92CECA0E-1DCB-4F42-BA4C-368094400351}\LocalServer32] "(Default)"="REG_SZ", ""C:\Program Files\SafetySearch\FrameworkEngine.exe"" "ServerExecutable"="REG_SZ", "C:\Program Files\SafetySearch\FrameworkEngine.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92CECA0E-1DCB-4F42-BA4C-368094400351}\Programmable] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92CECA0E-1DCB-4F42-BA4C-368094400351}\TypeLib] "(Default)"="REG_SZ", "{13FFE26E-E2A4-4AC8-9E82-FFC1A3C3578A}" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92CECA0E-1DCB-4F42-BA4C-368094400351}\Version] "(Default)"="REG_SZ", "1.0" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1EE70D1D-B150-4ACF-8498-4C5DE80CEAAC}] "(Default)"="REG_SZ", "IKangoBHO" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1EE70D1D-B150-4ACF-8498-4C5DE80CEAAC}\ProxyStubClsid] "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1EE70D1D-B150-4ACF-8498-4C5DE80CEAAC}\ProxyStubClsid32] "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1EE70D1D-B150-4ACF-8498-4C5DE80CEAAC}\TypeLib] "(Default)"="REG_SZ", "{B5D3A0F0-0BFE-429A-A322-95F076081845}" "Version"="REG_SZ", "1.0" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7720DB57-7561-457F-B689-D03FB72E3932}] "(Default)"="REG_SZ", "IKangoToolbar" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7720DB57-7561-457F-B689-D03FB72E3932}\ProxyStubClsid] "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7720DB57-7561-457F-B689-D03FB72E3932}\ProxyStubClsid32] "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7720DB57-7561-457F-B689-D03FB72E3932}\TypeLib "(Default)"="REG_SZ", "{B5D3A0F0-0BFE-429A-A322-95F076081845}" "Version"="REG_SZ", "1.0" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{92ADCA6E-1D8C-4F50-BEBF-1480FD408251}] "(Default)"="REG_SZ", "IKangoEngine" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{92ADCA6E-1D8C-4F50-BEBF-1480FD408251}\ProxyStubClsid] "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{92ADCA6E-1D8C-4F50-BEBF-1480FD408251}\ProxyStubClsid32] "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{92ADCA6E-1D8C-4F50-BEBF-1480FD408251}\TypeLib] "(Default)"="REG_SZ", "{13FFE26E-E2A4-4AC8-9E82-FFC1A3C3578A}" "Version"="REG_SZ", "1.0" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{13FFE26E-E2A4-4AC8-9E82-FFC1A3C3578A}\1.0] "(Default)"="REG_SZ", "EngineLib" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{13FFE26E-E2A4-4AC8-9E82-FFC1A3C3578A}\1.0\0\win32] "(Default)"="REG_SZ", "C:\Program Files\SafetySearch\FrameworkEngine.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{13FFE26E-E2A4-4AC8-9E82-FFC1A3C3578A}\1.0\FLAGS] "(Default)"="REG_SZ", "0" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{13FFE26E-E2A4-4AC8-9E82-FFC1A3C3578A}\1.0\HELPDIR] "(Default)"="REG_SZ", "C:\Program Files\SafetySearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{B5D3A0F0-0BFE-429A-A322-95F076081845}\1.0] "(Default)"="REG_SZ", "Framework 1.0 Type Library" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{B5D3A0F0-0BFE-429A-A322-95F076081845}\1.0\0\win32] "(Default)"="REG_SZ", "C:\Program Files\SafetySearch\FrameworkBHO.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{B5D3A0F0-0BFE-429A-A322-95F076081845}\1.0\FLAGS] "(Default)"="REG_SZ", "0" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{B5D3A0F0-0BFE-429A-A322-95F076081845}\1.0\HELPDIR] "(Default)"="REG_SZ", "C:\Program Files\SafetySearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.bench.nmhost] "(Default)"="REG_SZ", "C:\Program Files\Bench\NmHost\manifest.json" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}] "(Default)"="REG_SZ", "SafetySearch BHO" "NoExplorer"="REG_DWORD", 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Bench Communicator Watcher"="REG_SZ", "C:\Program Files\Bench\Proxy\pwdg.exe" "Bench Settings Cleaner"="REG_SZ", "C:\Program Files\Bench\Proxy\cl.exe" "BService"="REG_SZ", "C:\Program Files\Bench\BService\1.1\bservice.exe" "Wd"="REG_SZ", "C:\Program Files\Bench\Wd\wd.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "SafetySearch"="REG_SZ", "" "SafetySearch-repairJob"="REG_SZ", "wscript.exe "C:\Users\{username}\AppData\Local\SafetySearch\repair.js" "SafetySearch-repairJob"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\38989_SafetySearch] "DisplayIcon"="REG_SZ", "C:\Users\{username}\AppData\Local\SafetySearch/icon.ico" "DisplayName"="REG_SZ", "SafetySearch" "DisplayVersion"="REG_SZ", "1.0" "InstallLocation"="REG_SZ", "C:\Users\{username}\AppData\Local\SafetySearch" "NoModify"="REG_DWORD", 1 "NoRepair"="REG_DWORD", 1 "Publisher"="REG_SZ", "Exciting Apps" "UninstallString"="REG_SZ", "C:\Users\{username}\AppData\Local\SafetySearch\uninstall.exe " [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist] "1"="REG_SZ", "fjnoekdlmmjagmmlchagfonjgbioomoo;http://fjnoekdlmmjagmmlchagfonjgbioomoo/check/.eJwNyU0KgCAQQOG7zFqitl4mTEdT5wfUIojunsv3vReG6xUs-LMpIxi4sfWsMmlb1tlZ-nBE2MCOdqEBfMaew_yxiGINxFxcYiZ_uhRVSjqyKqvC9wPfWyFM.t27mdaCQFGhlnavJHDQywkB4OJ4" [HKEY_LOCAL_MACHINE\SOFTWARE\Proxy] "AutoConfigURL"="REG_SZ", "" "ProxyEnable"="REG_DWORD", 0 "ProxyServer"="REG_SZ", "" [HKEY_LOCAL_MACHINE\SOFTWARE\Proxy\Installations\SafetySearch] "aoi"="REG_SZ", "1405247403" "domain"="REG_SZ", "safetysearch-a.akamaihd.net" "ext"="REG_SZ", "SafetySearch" "format"="REG_SZ", "//{domain}/loaders/{pid}/l.js?pid={pid}&systemid={systemid}&ext={ext}&aoi={aoi}&zoneid={zoneid}&crr={crr}&type=p" "pid"="REG_SZ", "2031" "protect_redirect_url"="REG_SZ", "http://safetysearch.net/warning.php?%blocked_url%" "settings_url"="REG_SZ", "http://safetysearch.net/settings.php" "system_black_list_url"="REG_SZ", "http://safetysearch-a.akamaihd.net/protect/rules.json" "zoneid"="REG_SZ", "622410" [HKEY_LOCAL_MACHINE\SOFTWARE\SafetySearch] "(Default)"="REG_SZ", "C:\Users\{username}\AppData\Local\SafetySearch" "AllowProxy"="REG_SZ", "1" "CDN"="REG_SZ", "safetysearch-a.akamaihd.net" "InstallTime"="REG_SZ", "1405247403" "Pid"="REG_SZ", "2031" "Seen"="REG_SZ", "1" "SeenDate"="REG_SZ", "1405240203" "SystemId"="REG_SZ", "619bdd98c7140d14e62a62d4922b6abd" "UTCInstallTime"="REG_SZ", "1405240203" "ZoneId"="REG_SZ", "622410" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}] "Flags"="REG_DWORD", 1024 "VerCache"="REG_BINARY, ...................... [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "ProxyEnable REG_DWORD, 0 ==> REG_DWORD, 1 "ProxyServer"="REG_SZ", "http=127.0.0.1:3128" [HKEY_CURRENT_USER\Software\Proxy\installations\SafetySearch] "czoneid"="REG_SZ", "673316"Malwarebytes Anti-Malware log:
Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 7/13/2014 Scan Time: 10:39:35 AM Logfile: mbamSafetySearch.txt Administrator: Yes Version: 2.00.2.1012 Malware Database: v2014.07.13.01 Rootkit Database: v2014.07.09.01 License: Free Malware Protection: Disabled Malicious Website Protection: Disabled Self-protection: Disabled OS: Windows 7 Service Pack 1 CPU: x86 File System: NTFS User: Malwarebytes Scan Type: Threat Scan Result: Completed Objects Scanned: 239831 Time Elapsed: 2 min, 44 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 5 PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\FrameworkEngine.exe, 8768, Delete-on-Reboot, [20e5c5dabac1a195d4bab404df23cc34] PUP.Optional.Bench.A, C:\Program Files\Bench\Wd\wd.exe, 9736, Delete-on-Reboot, [cf36d2cd88f357df7846d10832d029d7] PUP.Optional.Bench.A, C:\Program Files\Bench\Proxy\pwdg.exe, 9916, Delete-on-Reboot, [6e97623d81faab8bb79b9d2d39c99f61] PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bservice.exe, 9756, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d] PUP.Optional.Bench.A, C:\Program Files\Bench\Proxy\proc.exe, 9260, Delete-on-Reboot, [11f4dac502791b1b385d565554ae857b] Modules: 9 PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bhelper.dll, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bhelper.dll, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bhelper.dll, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bhelper.dll, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bhelper.dll, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bhelper.dll, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bhelper.dll, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bhelper.dll, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bhelper.dll, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], Registry Keys: 33 PUP.Optional.SafetySearch.A, HKLM\SOFTWARE\CLASSES\CLSID\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}, Quarantined, [cd38c3dc235854e2857078d88a786997], PUP.Optional.SafetySearch.A, HKLM\SOFTWARE\CLASSES\CLSID\{7782DBE4-75A1-453D-B9FD-643F752E4532}, Quarantined, [cd38c3dc235854e2857078d88a786997], PUP.Optional.SafetySearch.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{B5D3A0F0-0BFE-429A-A322-95F076081845}, Quarantined, [cd38c3dc235854e2857078d88a786997], PUP.Optional.SafetySearch.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{1EE70D1D-B150-4ACF-8498-4C5DE80CEAAC}, Quarantined, [cd38c3dc235854e2857078d88a786997], PUP.Optional.SafetySearch.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{7720DB57-7561-457F-B689-D03FB72E3932}, Quarantined, [cd38c3dc235854e2857078d88a786997], PUP.Optional.SafetySearch.A, HKLM\SOFTWARE\CLASSES\CLSID\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}\INPROCSERVER32, Quarantined, [cd38c3dc235854e2857078d88a786997], PUP.Optional.SafetySearch.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}, Quarantined, [cd38c3dc235854e2857078d88a786997], PUP.Optional.SafetySearch.A, HKU\S-1-5-21-4016700205-1717049133-1125222536-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}, Quarantined, [cd38c3dc235854e2857078d88a786997], PUP.Optional.SafetySearch.A, HKU\S-1-5-21-4016700205-1717049133-1125222536-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}, Quarantined, [cd38c3dc235854e2857078d88a786997], PUP.Optional.ExcitingApps.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\38989_SafetySearch, Quarantined, [13f22877601b93a350c99dfdb74ad030], PUP.Optional.SafetySearch.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{13FFE26E-E2A4-4AC8-9E82-FFC1A3C3578A}, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{92ADCA6E-1D8C-4F50-BEBF-1480FD408251}, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.Bench.A, HKLM\SOFTWARE\BENCH\BService, Quarantined, [28ddc6d95e1d9e98f42e6c597b8741bf], PUP.Optional.Bench.A, HKLM\SOFTWARE\BENCH\InstalledExtensions, Quarantined, [4fb627789cdf8da933f0f7ce17ebde22], PUP.Optional.Bench.A, HKLM\SOFTWARE\BENCH\NmHost, Quarantined, [c73ebfe0a4d743f3a57fa5200df5eb15], PUP.Optional.Bench.A, HKLM\SOFTWARE\BENCH\Updater, Quarantined, [699c8c1393e882b462c3d1f456ac966a], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\GLOBALUPDATE\UPDATE, Quarantined, [f1141b849fdc9e98706a6c4c17ebb64a], PUP.Optional.Bench.A, HKLM\SOFTWARE\GOOGLE\CHROME\NATIVEMESSAGINGHOSTS\com.bench.nmhost, Quarantined, [10f5c9d6b5c663d35bb442cdca3a16ea], PUP.Optional.SafetySearch.A, HKLM\SOFTWARE\PROXY\INSTALLATIONS\SafetySearch, Quarantined, [fc098b1490eb26100b816157cc363ac6], PUP.Optional.SafetySearch.A, HKU\S-1-5-21-4016700205-1717049133-1125222536-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\PROXY\INSTALLATIONS\SafetySearch, Quarantined, [5ca99f00710ac86e008dd9df8181d22e], PUP.Optional.GlobalUpdate.T, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\globalUpdate, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\globalUpdatem, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.OneClickCtrl.10, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.Update3WebControl.4, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], Registry Values: 7 PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\GLOBALUPDATE\UPDATE|path, C:\Program Files\globalUpdate\Update\GoogleUpdate.exe, Quarantined, [f1141b849fdc9e98706a6c4c17ebb64a] PUP.Optional.Bench.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Wd, C:\Program Files\Bench\Wd\wd.exe, Quarantined, [cf36d2cd88f357df7846d10832d029d7] PUP.Optional.Bench.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Bench Communicator Watcher, C:\Program Files\Bench\Proxy\pwdg.exe, Quarantined, [6e97623d81faab8bb79b9d2d39c99f61] PUP.Optional.Bench.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Bench Settings Cleaner, C:\Program Files\Bench\Proxy\cl.exe, Quarantined, [ff06bde256250e28da793892837fae52] PUP.Optional.SmartApps, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE|SafetySearch-repairJob, wscript.exe "C:\Users\{username}\AppData\Local\SafetySearch\repair.js" "SafetySearch-repairJob", Quarantined, [c144613ecfac0036b51c61ae06fef40c] PUM.Bad.Proxy, HKU\S-1-5-21-4016700205-1717049133-1125222536-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|ProxyServer, http=127.0.0.1:3128, Quarantined, [dc29fca346358caa12c6b90a2cd628d8] PUP.Optional.Bench.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|BService, C:\Program Files\Bench\BService\1.1\bservice.exe, Quarantined, [f213efb03348e3538776851c9e64d32d] Registry Data: 0 (No malicious items detected) Folders: 32 PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch, Delete-on-Reboot, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\AppFramework, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\CanvasFramework, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\icons, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.BenchUpdater, C:\Program Files\Bench\NmHost, Quarantined, [50b5f9a67605d363a299459cb1516799], PUP.Optional.BenchUpdater, C:\Program Files\Bench\NmHost\data, Quarantined, [50b5f9a67605d363a299459cb1516799], PUP.Optional.BenchUpdater, C:\Program Files\Bench\NmHost\data\installer, Quarantined, [50b5f9a67605d363a299459cb1516799], PUP.Optional.BenchUpdater.A, C:\Users\{username}\AppData\Local\BenchUpdater, Quarantined, [df26cad5d4a7a294d27819c9c33fd32d], PUP.Optional.AdwarePlugin, C:\Program Files\Bench\Updater, Quarantined, [2fd659468eed1e1861b51e81ba481be5], PUP.Optional.AdwarePlugin, C:\Program Files\Bench\Updater\1.7.0.0, Quarantined, [2fd659468eed1e1861b51e81ba481be5], PUP.Optional.Bench.A, C:\Program Files\Bench\BService, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], PUP.Optional.Bench.A, C:\Program Files\Bench\Wd, Delete-on-Reboot, [2cd99a05ed8ea0966e90a8f93dc5af51], PUP.Optional.Bench.A, C:\Program Files\Bench\Proxy, Delete-on-Reboot, [11f4dac502791b1b385d565554ae857b], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Download, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Install, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Offline, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Offline\{9DB71709-E211-41A5-994F-F15E83C89F59}, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624, Quarantined, [44c1a9f605761026bf646a4ee81ac040], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch, Delete-on-Reboot, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\AppFramework, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\CanvasFramework, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\icons, Quarantined, [986d633cd8a373c3206996224eb4cb35], Files: 180 PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\FrameworkBHO.dll, Quarantined, [cd38c3dc235854e2857078d88a786997], PUP.Optional.ExcitingApps.A, C:\Users\{username}\Desktop\SafetySearch_2606-d82f5459.exe, Quarantined, [8d78564932498aac6dac1486847db14f], PUP.Optional.InstallCore, C:\Users\{username}\Downloads\googleupdatersetup.exe, Quarantined, [8c7988170e6d81b5c4319cf3c63e8c74], PUP.Optional.ExcitingApps.A, C:\Users\{username}\AppData\Local\SafetySearch\uninstall.exe, Quarantined, [13f22877601b93a350c99dfdb74ad030], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\background.html, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\config.xml, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\extension_info.json, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\FrameworkBHO64.dll, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\FrameworkEngine.exe, Delete-on-Reboot, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\AppFramework\appAPI_bg.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\AppFramework\appAPI_browseraction.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\AppFramework\appAPI_common.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\AppFramework\appAPI_content.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\AppFramework\appAPI_settings.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\AppFramework\appAPI_webrequest.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\AppFramework\jquery.min.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\CanvasFramework\canvasscript_engine.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\CanvasFramework\canvas_bg.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\CanvasFramework\md5.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\CanvasFramework\registry.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\CanvasFramework\webrequest.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\backgroundscript_engine.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\base.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\browser.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\console.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\framework.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\global.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\i18n.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\initialize.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\invoke_async.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\io.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\json2.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\lang.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\legacy.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\message_target.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\messaging.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\storage.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\timer.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\updater.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\userscript_client.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\userscript_engine.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\utils.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\xhr.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\browser_button.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\context_menu.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\context_menu_item_handler.html, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\framework_api.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\notification.html, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\notifications.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\options.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\ui_base.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\bottom-left.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\bottom-middle.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\bottom-right.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\middle-left.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\middle-right.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\tail-bottom.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\tail-left.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\tail-right.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\tail-top.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\top-left.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\top-middle.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\top-right.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\icons\button.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\icons\icon100.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\icons\icon128.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\icons\icon32.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\icons\icon48.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.BenchUpdater.A, C:\Windows\System32\Tasks\bench-S-1-5-21-4016700205-1717049133-1125222536-1001, Quarantined, [28ddb5ea37448aacd4bdefce6f936a96], PUP.Optional.BenchUpdater.A, C:\Windows\System32\Tasks\bench-sys, Quarantined, [c93c3b644d2e092d9af735881ae828d8], PUP.Optional.BenchUpdater, C:\Program Files\Bench\NmHost\nmhost.exe, Quarantined, [50b5f9a67605d363a299459cb1516799], PUP.Optional.BenchUpdater, C:\Program Files\Bench\NmHost\manifest.json, Quarantined, [50b5f9a67605d363a299459cb1516799], PUP.Optional.BenchUpdater, C:\Program Files\Bench\NmHost\data\installer\fjnoekdlmmjagmmlchagfonjgbioomoo, Quarantined, [50b5f9a67605d363a299459cb1516799], PUP.Optional.BenchUpdater.A, C:\Windows\Tasks\bench-S-1-5-21-4016700205-1717049133-1125222536-1001.job, Quarantined, [897c9708cfac7abce762558d34ce1fe1], PUP.Optional.BenchUpdater.A, C:\Windows\Tasks\bench-sys.job, Quarantined, [44c18a151e5d94a2ee5b02e0837fd62a], PUP.Optional.BenchUpdater.A, C:\Users\{username}\AppData\Local\BenchUpdater\products.xml, Quarantined, [df26cad5d4a7a294d27819c9c33fd32d], PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job, Quarantined, [ae57fda2f88301356f2c31e6739110f0], PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore, Quarantined, [fa0b7926daa160d6306c809747bda15f], PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job, Quarantined, [c441f1ae532837ffe4b9cc4be61ec040], PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA, Quarantined, [cf36b5ea512ab680ecb2f126ba4aad53], PUP.Optional.Bench.A, C:\Program Files\Bench\Wd\wd.exe, Delete-on-Reboot, [cf36d2cd88f357df7846d10832d029d7], PUP.Optional.Bench.A, C:\Program Files\Bench\Proxy\pwdg.exe, Delete-on-Reboot, [6e97623d81faab8bb79b9d2d39c99f61], PUP.Optional.Bench.A, C:\Program Files\Bench\Proxy\cl.exe, Quarantined, [ff06bde256250e28da793892837fae52], PUP.Optional.SmartApps, C:\Users\{username}\AppData\Local\SafetySearch\repair.js, Quarantined, [c144613ecfac0036b51c61ae06fef40c], PUP.Optional.AdwarePlugin, C:\Program Files\Bench\Updater\products.xml, Quarantined, [2fd659468eed1e1861b51e81ba481be5], PUP.Optional.AdwarePlugin, C:\Program Files\Bench\Updater\updater.exe, Quarantined, [2fd659468eed1e1861b51e81ba481be5], PUP.Optional.AdwarePlugin, C:\Program Files\Bench\Updater\1.7.0.0\updater.exe, Quarantined, [2fd659468eed1e1861b51e81ba481be5], PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bhelper.dll, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bservice.exe, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], PUP.Optional.Bench.A, C:\Program Files\Bench\Proxy\icon.ico, Quarantined, [11f4dac502791b1b385d565554ae857b], PUP.Optional.Bench.A, C:\Program Files\Bench\Proxy\proc.exe, Delete-on-Reboot, [11f4dac502791b1b385d565554ae857b], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\GoogleUpdate.exe, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateHelper.msi, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\goopdate.dll, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\goopdateres_en.dll, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\psmachine.dll, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\psuser.dll, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624\GoogleCrashHandler.exe, Quarantined, [44c1a9f605761026bf646a4ee81ac040], PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624\GoogleUpdate.exe, Quarantined, [44c1a9f605761026bf646a4ee81ac040], PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624\GoogleUpdateBroker.exe, Quarantined, [44c1a9f605761026bf646a4ee81ac040], PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624\GoogleUpdateHelper.msi, Quarantined, [44c1a9f605761026bf646a4ee81ac040], PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624\GoogleUpdateOnDemand.exe, Quarantined, [44c1a9f605761026bf646a4ee81ac040], PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624\goopdate.dll, Quarantined, [44c1a9f605761026bf646a4ee81ac040], PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624\goopdateres_en.dll, Quarantined, [44c1a9f605761026bf646a4ee81ac040], PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624\npGoogleUpdate4.dll, Quarantined, [44c1a9f605761026bf646a4ee81ac040], PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624\psmachine.dll, Quarantined, [44c1a9f605761026bf646a4ee81ac040], PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624\psuser.dll, Quarantined, [44c1a9f605761026bf646a4ee81ac040], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\chrome_gp_update.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\chrome_installer.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\clear_cache.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\common.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox_installer.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\gpedit.exe, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\icon.ico, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\ie_installer.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\installer.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\main_installer.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\migrate.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\projectInstaller.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\repair_data.json, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\SoftwareDetector.exe, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\sqlite3.exe, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\storageedit.exe, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\background.html, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\bootstrap.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\chrome.manifest, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\extension_info.json, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\install.rdf, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\AppFramework\appAPI_bg.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\AppFramework\appAPI_browseraction.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\AppFramework\appAPI_common.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\AppFramework\appAPI_content.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\AppFramework\appAPI_settings.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\AppFramework\appAPI_webrequest.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\AppFramework\jquery.min.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\CanvasFramework\canvasscript_engine.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\CanvasFramework\canvas_bg.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\CanvasFramework\md5.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\CanvasFramework\registry.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\CanvasFramework\webrequest.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\backgroundscript_engine.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\base.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\browser.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\chrome_windows.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\console.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\content_proxy.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\framework.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\i18n.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\invoke_async.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\io.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\lang.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\legacy.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\message_target.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\messaging.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\storage.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\timer.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\uninstall.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\userscript_client.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\userscript_engine.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\utils.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\xhr.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui\browser_button.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui\contentNotification.tmpl, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui\contentNotificationStyle.tmpl, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui\content_notifications.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui\context_menu.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui\framework_api.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui\notifications.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui\options.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui\ui_base.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\icons\button.png, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\icons\icon100.png, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\icons\icon128.png, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\icons\icon32.png, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\icons\icon48.png, Quarantined, [986d633cd8a373c3206996224eb4cb35], Physical Sectors: 0 (No malicious items detected) (end)As mentioned before the full version of Malwarebytes Anti-Malware could have protected your computer against this threat.
We use different ways of protecting your computer(s):
- Dynamically Blocks Malware Sites & Servers
- Malware Execution Prevention