Home Malware Programs Adware MySafeProxy

MySafeProxy

Posted: September 24, 2014

Threat Metric

Ranking: 17,091
Threat Level: 1/10
Infected PCs: 38,818
First Seen: September 24, 2014
Last Seen: August 13, 2023
OS(es) Affected: Windows


MySafeProxy is an add-on for Internet Explorer that claims that MySafeProxy provides security and privacy-enhancing browser functions, although malware experts have yet to validate these claims. Because of MySafeProxy finances itself as a product via the display of potentially unsafe advertising content, MySafeProxy is categorized as adware and a Potentially Unwanted Program.

Web-Browsing Safety at a Questionable Cost

MySafeProxy markets itself as a proxy server that can obfuscate your IP address, allow you renewed access to websites blocked by third parties or provide protection from advertising-tracking agents. Ironically, while malware researchers found minimal indications of MySafeProxy add-ons having any security benefits, they have noted that MySafeProxy injects automatic advertising content. By modifying unrelated Web pages and displaying these third-party advertisements automatically, MySafeProxy may cause some of the same problems that MySafeProxy claims to prevent, while simultaneously ignoring most standard advertisement-blocking functions.

As usual for adware of a similar stripe, MySafeProxy explicitly disclaims any responsibility towards the consequences of being exposed to these third-party advertisements. Based on circumstantial evidence, its advertisement content may include attempts to distribute other PUPs or threats through fake download updates and similar tactics.

While the extra search results, pop-ups and any other content MySafeProxy provides are not guaranteed to harm your PC, malware experts also came across additional risks from some MySafeProxy variants. A minority of MySafeProxy variants, frequently installed automatically, also have displayed excessive system resource usage, particularly for the affected machines' graphics cards. This symptom may be associated with BitCoin miners, which may permanently damage your hardware and cause general system instability.

Getting Rid of the Go-Between Between You and Your Browser

Although using well-selected security add-ons can make your browser safer than its default state, malware experts always advise researching any permanent-use add-ons carefully. MySafeProxy, in its turn, shows most of the hallmarks of conducting a standard adware campaign that generates advertising profits without providing significant benefits to its users. Meanwhile, variants of MySafeProxy that include digital currency miners always must be treated as nothing less than direct threats to your computer's health.

If they're using updated threat databases, competent anti-adware programs or security programs with anti-adware functions should be capable of uninstalling MySafeProxy safely. However, in light of the association of MySafeProxy adware with actual threatening software, you also may wish to run a full anti-malware scan afterward. As usual, typical methods of deleting MySafeProxy that would remove any benign software may fail to delete this add-on, despite its claims of being just a standard security product.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Drive[C]\AdwCleaner\Quarantine\C\Program Files (x86)\XTRM Group\MySafeProxy\Bin\MySafeProxyMonitor.exe.vir File name: MySafeProxyMonitor.exe.vir
Size: 1.3 MB (1308664 bytes)
MD5: 0ac7b45dda06d7bfbc6dded6753dda14
Detection count: 11,371
Mime Type: unknown/vir
Path: C:\Drive[C]\AdwCleaner\Quarantine\C\Program Files (x86)\XTRM Group\MySafeProxy\Bin\MySafeProxyMonitor.exe.vir
Group: Malware file
Last Updated: October 12, 2022
C:\Program Files (x86)\XTRM Group\MySafeProxy\Bin\MySafeProxyMonitor.exe File name: MySafeProxyMonitor.exe
Size: 1.35 MB (1355768 bytes)
MD5: 68732069d7be181c0dcd5582fd0f1d00
Detection count: 8,314
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\XTRM Group\MySafeProxy\Bin\MySafeProxyMonitor.exe
Group: Malware file
Last Updated: January 29, 2023
%PROGRAMFILES%\XTRM Group\MySafeProxy\Bin\MySafeProxyMonitor.exe File name: MySafeProxyMonitor.exe
Size: 1.3 MB (1306104 bytes)
MD5: 6c10c0f7ec05ee9a24a6cce4bea1272c
Detection count: 4,295
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\XTRM Group\MySafeProxy\Bin
Group: Malware file
Last Updated: August 31, 2020
%PROGRAMFILES%\XTRM Group\MySafeProxy\Bin\worker\MySafeProxyWorker.exe File name: MySafeProxyWorker.exe
Size: 856.84 KB (856841 bytes)
MD5: a7572d016f0555e6f225a07952846cca
Detection count: 2,073
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\XTRM Group\MySafeProxy\Bin\worker
Group: Malware file
Last Updated: March 20, 2020
C:\Program Files\Panda Security\Panda Security Protection\OggettiSmarriti\MySafeProxyMonitor.exe File name: MySafeProxyMonitor.exe
Size: 1.31 MB (1311736 bytes)
MD5: e90f9e39b142b6df903314b891721c72
Detection count: 806
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files\Panda Security\Panda Security Protection\OggettiSmarriti\MySafeProxyMonitor.exe
Group: Malware file
Last Updated: April 9, 2023
C:\Program Files (x86)\XTRM Group\MySafeProxy\Bin\worker\MySafeProxyWorker.exe File name: MySafeProxyWorker.exe
Size: 216.59 KB (216590 bytes)
MD5: fcbfd50db64c026bc0a63e6bece8d1f8
Detection count: 700
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\XTRM Group\MySafeProxy\Bin\worker\MySafeProxyWorker.exe
Group: Malware file
Last Updated: April 22, 2022
C:\Program Files\XTRM Group\MySafeProxy\Bin\MySafeProxyBroker.exe File name: MySafeProxyBroker.exe
Size: 342.52 KB (342520 bytes)
MD5: 2a2a62f1f811fa77e914b59bb75ae1b9
Detection count: 365
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files\XTRM Group\MySafeProxy\Bin\MySafeProxyBroker.exe
Group: Malware file
Last Updated: October 10, 2021
C:\Program Files (x86)\XTRM Group\MySafeProxy\Bin\MySafeProxyBroker.exe File name: MySafeProxyBroker.exe
Size: 342 KB (342008 bytes)
MD5: 7d0354c98f8336803c6d6c9bd8fde475
Detection count: 342
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\XTRM Group\MySafeProxy\Bin\MySafeProxyBroker.exe
Group: Malware file
Last Updated: August 27, 2022
%WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.9.0\AddonBUBUK-541065aba19f3.exe File name: AddonBUBUK-541065aba19f3.exe
Size: 355.86 KB (355863 bytes)
MD5: f2b6acab059d1b99a43e184c145af1fa
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.9.0
Group: Malware file
Last Updated: October 1, 2014
%WINDIR%\TEMP\XTRM Group Ltd\MySafeProxy\1.0.9.0\AddonHDQUS-5407778e31912.exe File name: AddonHDQUS-5407778e31912.exe
Size: 9.58 MB (9583560 bytes)
MD5: 84815e0218a3ad121113e07778eab4ab
Detection count: 62
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP\XTRM Group Ltd\MySafeProxy\1.0.9.0
Group: Malware file
Last Updated: October 1, 2014
%WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.9.0\AddonCNMUS-5414372c54065.exe File name: AddonCNMUS-5414372c54065.exe
Size: 660.48 KB (660480 bytes)
MD5: 121969abf6d7c243d36edb162898285d
Detection count: 60
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.9.0
Group: Malware file
Last Updated: October 1, 2014
%PROGRAMFILES(x86)%\XTRM Group\MySafeProxy\Bin\worker\MySafeProxyWorker.exe File name: MySafeProxyWorker.exe
Size: 856.84 KB (856841 bytes)
MD5: 0b7d433bf10e2d210075aaa9b838c4fd
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\XTRM Group\MySafeProxy\Bin\worker
Group: Malware file
Last Updated: October 1, 2014
%PROGRAMFILES%\XTRM Group\MySafeProxy\Bin\MySafeProxyMonitor.exe File name: MySafeProxyMonitor.exe
Size: 1.3 MB (1308664 bytes)
MD5: c04f9d5745cf291dc0fbfad1532bbc07
Detection count: 43
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\XTRM Group\MySafeProxy\Bin
Group: Malware file
Last Updated: October 1, 2014
C:\Windows\Temp\XTRM Group Ltd\MySafeProxy\1.0.10.0\AddonMYA-5405c72244bc0.exe File name: AddonMYA-5405c72244bc0.exe
Size: 292.65 KB (292656 bytes)
MD5: a4e979eb193fc09927f2acea53dab434
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\Temp\XTRM Group Ltd\MySafeProxy\1.0.10.0\AddonMYA-5405c72244bc0.exe
Group: Malware file
Last Updated: September 14, 2021
%WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.10.0\AddonHDQUK-5407782528145.exe File name: AddonHDQUK-5407782528145.exe
Size: 9.57 MB (9576824 bytes)
MD5: 10f4dfc1d7c3a9c3cbe273aa60e09ae4
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.10.0
Group: Malware file
Last Updated: October 1, 2014
C:\Copia_disco_30-04-2018\AdwCleaner\Quarantine\C\Archivos de programa\XTRM Group\MySafeProxy\Bin\MySafeProxy32.dll.vir File name: MySafeProxy32.dll.vir
Size: 365.56 KB (365560 bytes)
MD5: c2f115c9c512d5c6793162a282b0298e
Detection count: 21
Mime Type: unknown/vir
Path: C:\Copia_disco_30-04-2018\AdwCleaner\Quarantine\C\Archivos de programa\XTRM Group\MySafeProxy\Bin\MySafeProxy32.dll.vir
Group: Malware file
Last Updated: October 12, 2022
%WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.8.0\AddonHQ-RU.exe File name: AddonHQ-RU.exe
Size: 9.56 MB (9569688 bytes)
MD5: cdd41fb24005d8c05f2ec46877373d4a
Detection count: 15
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.8.0
Group: Malware file
Last Updated: October 1, 2014
C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTRM Group\MySafeProxy\Bin\MySafeProxy64.dll.vir File name: MySafeProxy64.dll.vir
Size: 411.12 KB (411128 bytes)
MD5: 22b123d7d823ad645f2d8d3267a3aa2b
Detection count: 9
Mime Type: unknown/vir
Path: C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTRM Group\MySafeProxy\Bin\MySafeProxy64.dll.vir
Group: Malware file
Last Updated: October 12, 2022
%WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.9.0\AddonHDQIT-540778d25e356.exe File name: AddonHDQIT-540778d25e356.exe
Size: 9.61 MB (9610040 bytes)
MD5: 85a5026053d28843ad70699d8da08ad0
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.9.0
Group: Malware file
Last Updated: January 29, 2020
%WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.9.0\AddonINFRU-541697ffa8997.exe File name: AddonINFRU-541697ffa8997.exe
Size: 64.87 KB (64878 bytes)
MD5: ce021ed0e1196d82422227556113d83a
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.9.0
Group: Malware file
Last Updated: November 3, 2019
%WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.9.0\AddonHDQES-5407783e6cb87.exe File name: AddonHDQES-5407783e6cb87.exe
Size: 9.59 MB (9593912 bytes)
MD5: f537f278c88d574483bc6f6c1d364485
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.9.0
Group: Malware file
Last Updated: November 3, 2019

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{51420F88-4D4A-4042-9509-8D4E1307910E}HKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\MySafeProxy.MySafeProxySOFTWARE\Classes\MySafeProxy.MySafeProxy.1SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{51420F88-4D4A-4042-9509-8D4E1307910E}SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{51420F88-4D4A-4042-9509-8D4E1307910E}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{51420F88-4D4A-4042-9509-8D4E1307910E}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{51420F88-4D4A-4042-9509-8D4E1307910E}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{51420F88-4D4A-4042-9509-8D4E1307910E}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{51420F88-4D4A-4042-9509-8D4E1307910E}SOFTWARE\Wow6432Node\XTRM Group Ltd.\MySafeProxySOFTWARE\XTRM Group Ltd.\MySafeProxySYSTEM\ControlSet001\services\MySafeProxyMonitorSYSTEM\ControlSet002\services\MySafeProxyMonitorSYSTEM\CurrentControlSet\services\MySafeProxyMonitorHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{2535ED3F-5ADD-4A65-B07F-82F04C7358E7}

Additional Information

The following directories were created:
%TEMP%\XTRM Group Ltd\MySafeProxy
Loading...