MySafeProxy
Posted: September 24, 2014
Threat Metric
The following fields listed on the Threat Meter containing a specific value, are explained in detail below:
Threat Level: The threat level scale goes from 1 to 10 where 10 is the highest level of severity and 1 is the lowest level of severity. Each specific level is relative to the threat's consistent assessed behaviors collected from SpyHunter's risk assessment model.
Detection Count: The collective number of confirmed and suspected cases of a particular malware threat. The detection count is calculated from infected PCs retrieved from diagnostic and scan log reports generated by SpyHunter.
Volume Count: Similar to the detection count, the Volume Count is specifically based on the number of confirmed and suspected threats infecting systems on a daily basis. High volume counts usually represent a popular threat but may or may not have infected a large number of systems. High detection count threats could lay dormant and have a low volume count. Criteria for Volume Count is relative to a daily detection count.
Trend Path: The Trend Path, utilizing an up arrow, down arrow or equal symbol, represents the level of recent movement of a particular threat. Up arrows represent an increase, down arrows represent a decline and the equal symbol represent no change to a threat's recent movement.
% Impact (Last 7 Days): This demonstrates a 7-day period change in the frequency of a malware threat infecting PCs. The percentage impact correlates directly to the current Trend Path to determine a rise or decline in the percentage.
Ranking: | 17,091 |
---|---|
Threat Level: | 1/10 |
Infected PCs: | 38,818 |
First Seen: | September 24, 2014 |
---|---|
Last Seen: | August 13, 2023 |
OS(es) Affected: | Windows |
MySafeProxy is an add-on for Internet Explorer that claims that MySafeProxy provides security and privacy-enhancing browser functions, although malware experts have yet to validate these claims. Because of MySafeProxy finances itself as a product via the display of potentially unsafe advertising content, MySafeProxy is categorized as adware and a Potentially Unwanted Program.
Web-Browsing Safety at a Questionable Cost
MySafeProxy markets itself as a proxy server that can obfuscate your IP address, allow you renewed access to websites blocked by third parties or provide protection from advertising-tracking agents. Ironically, while malware researchers found minimal indications of MySafeProxy add-ons having any security benefits, they have noted that MySafeProxy injects automatic advertising content. By modifying unrelated Web pages and displaying these third-party advertisements automatically, MySafeProxy may cause some of the same problems that MySafeProxy claims to prevent, while simultaneously ignoring most standard advertisement-blocking functions.
As usual for adware of a similar stripe, MySafeProxy explicitly disclaims any responsibility towards the consequences of being exposed to these third-party advertisements. Based on circumstantial evidence, its advertisement content may include attempts to distribute other PUPs or threats through fake download updates and similar tactics.
While the extra search results, pop-ups and any other content MySafeProxy provides are not guaranteed to harm your PC, malware experts also came across additional risks from some MySafeProxy variants. A minority of MySafeProxy variants, frequently installed automatically, also have displayed excessive system resource usage, particularly for the affected machines' graphics cards. This symptom may be associated with BitCoin miners, which may permanently damage your hardware and cause general system instability.
Getting Rid of the Go-Between Between You and Your Browser
Although using well-selected security add-ons can make your browser safer than its default state, malware experts always advise researching any permanent-use add-ons carefully. MySafeProxy, in its turn, shows most of the hallmarks of conducting a standard adware campaign that generates advertising profits without providing significant benefits to its users. Meanwhile, variants of MySafeProxy that include digital currency miners always must be treated as nothing less than direct threats to your computer's health.
If they're using updated threat databases, competent anti-adware programs or security programs with anti-adware functions should be capable of uninstalling MySafeProxy safely. However, in light of the association of MySafeProxy adware with actual threatening software, you also may wish to run a full anti-malware scan afterward. As usual, typical methods of deleting MySafeProxy that would remove any benign software may fail to delete this add-on, despite its claims of being just a standard security product.
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
The following files were created in the system:C:\Drive[C]\AdwCleaner\Quarantine\C\Program Files (x86)\XTRM Group\MySafeProxy\Bin\MySafeProxyMonitor.exe.vir
File name: MySafeProxyMonitor.exe.virSize: 1.3 MB (1308664 bytes)
MD5: 0ac7b45dda06d7bfbc6dded6753dda14
Detection count: 11,371
Mime Type: unknown/vir
Path: C:\Drive[C]\AdwCleaner\Quarantine\C\Program Files (x86)\XTRM Group\MySafeProxy\Bin\MySafeProxyMonitor.exe.vir
Group: Malware file
Last Updated: October 12, 2022
C:\Program Files (x86)\XTRM Group\MySafeProxy\Bin\MySafeProxyMonitor.exe
File name: MySafeProxyMonitor.exeSize: 1.35 MB (1355768 bytes)
MD5: 68732069d7be181c0dcd5582fd0f1d00
Detection count: 8,314
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\XTRM Group\MySafeProxy\Bin\MySafeProxyMonitor.exe
Group: Malware file
Last Updated: January 29, 2023
%PROGRAMFILES%\XTRM Group\MySafeProxy\Bin\MySafeProxyMonitor.exe
File name: MySafeProxyMonitor.exeSize: 1.3 MB (1306104 bytes)
MD5: 6c10c0f7ec05ee9a24a6cce4bea1272c
Detection count: 4,295
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\XTRM Group\MySafeProxy\Bin
Group: Malware file
Last Updated: August 31, 2020
%PROGRAMFILES%\XTRM Group\MySafeProxy\Bin\worker\MySafeProxyWorker.exe
File name: MySafeProxyWorker.exeSize: 856.84 KB (856841 bytes)
MD5: a7572d016f0555e6f225a07952846cca
Detection count: 2,073
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\XTRM Group\MySafeProxy\Bin\worker
Group: Malware file
Last Updated: March 20, 2020
C:\Program Files\Panda Security\Panda Security Protection\OggettiSmarriti\MySafeProxyMonitor.exe
File name: MySafeProxyMonitor.exeSize: 1.31 MB (1311736 bytes)
MD5: e90f9e39b142b6df903314b891721c72
Detection count: 806
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files\Panda Security\Panda Security Protection\OggettiSmarriti\MySafeProxyMonitor.exe
Group: Malware file
Last Updated: April 9, 2023
C:\Program Files (x86)\XTRM Group\MySafeProxy\Bin\worker\MySafeProxyWorker.exe
File name: MySafeProxyWorker.exeSize: 216.59 KB (216590 bytes)
MD5: fcbfd50db64c026bc0a63e6bece8d1f8
Detection count: 700
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\XTRM Group\MySafeProxy\Bin\worker\MySafeProxyWorker.exe
Group: Malware file
Last Updated: April 22, 2022
C:\Program Files\XTRM Group\MySafeProxy\Bin\MySafeProxyBroker.exe
File name: MySafeProxyBroker.exeSize: 342.52 KB (342520 bytes)
MD5: 2a2a62f1f811fa77e914b59bb75ae1b9
Detection count: 365
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files\XTRM Group\MySafeProxy\Bin\MySafeProxyBroker.exe
Group: Malware file
Last Updated: October 10, 2021
C:\Program Files (x86)\XTRM Group\MySafeProxy\Bin\MySafeProxyBroker.exe
File name: MySafeProxyBroker.exeSize: 342 KB (342008 bytes)
MD5: 7d0354c98f8336803c6d6c9bd8fde475
Detection count: 342
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\XTRM Group\MySafeProxy\Bin\MySafeProxyBroker.exe
Group: Malware file
Last Updated: August 27, 2022
%WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.9.0\AddonBUBUK-541065aba19f3.exe
File name: AddonBUBUK-541065aba19f3.exeSize: 355.86 KB (355863 bytes)
MD5: f2b6acab059d1b99a43e184c145af1fa
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.9.0
Group: Malware file
Last Updated: October 1, 2014
%WINDIR%\TEMP\XTRM Group Ltd\MySafeProxy\1.0.9.0\AddonHDQUS-5407778e31912.exe
File name: AddonHDQUS-5407778e31912.exeSize: 9.58 MB (9583560 bytes)
MD5: 84815e0218a3ad121113e07778eab4ab
Detection count: 62
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP\XTRM Group Ltd\MySafeProxy\1.0.9.0
Group: Malware file
Last Updated: October 1, 2014
%WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.9.0\AddonCNMUS-5414372c54065.exe
File name: AddonCNMUS-5414372c54065.exeSize: 660.48 KB (660480 bytes)
MD5: 121969abf6d7c243d36edb162898285d
Detection count: 60
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.9.0
Group: Malware file
Last Updated: October 1, 2014
%PROGRAMFILES(x86)%\XTRM Group\MySafeProxy\Bin\worker\MySafeProxyWorker.exe
File name: MySafeProxyWorker.exeSize: 856.84 KB (856841 bytes)
MD5: 0b7d433bf10e2d210075aaa9b838c4fd
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\XTRM Group\MySafeProxy\Bin\worker
Group: Malware file
Last Updated: October 1, 2014
%PROGRAMFILES%\XTRM Group\MySafeProxy\Bin\MySafeProxyMonitor.exe
File name: MySafeProxyMonitor.exeSize: 1.3 MB (1308664 bytes)
MD5: c04f9d5745cf291dc0fbfad1532bbc07
Detection count: 43
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\XTRM Group\MySafeProxy\Bin
Group: Malware file
Last Updated: October 1, 2014
C:\Windows\Temp\XTRM Group Ltd\MySafeProxy\1.0.10.0\AddonMYA-5405c72244bc0.exe
File name: AddonMYA-5405c72244bc0.exeSize: 292.65 KB (292656 bytes)
MD5: a4e979eb193fc09927f2acea53dab434
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\Temp\XTRM Group Ltd\MySafeProxy\1.0.10.0\AddonMYA-5405c72244bc0.exe
Group: Malware file
Last Updated: September 14, 2021
%WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.10.0\AddonHDQUK-5407782528145.exe
File name: AddonHDQUK-5407782528145.exeSize: 9.57 MB (9576824 bytes)
MD5: 10f4dfc1d7c3a9c3cbe273aa60e09ae4
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.10.0
Group: Malware file
Last Updated: October 1, 2014
C:\Copia_disco_30-04-2018\AdwCleaner\Quarantine\C\Archivos de programa\XTRM Group\MySafeProxy\Bin\MySafeProxy32.dll.vir
File name: MySafeProxy32.dll.virSize: 365.56 KB (365560 bytes)
MD5: c2f115c9c512d5c6793162a282b0298e
Detection count: 21
Mime Type: unknown/vir
Path: C:\Copia_disco_30-04-2018\AdwCleaner\Quarantine\C\Archivos de programa\XTRM Group\MySafeProxy\Bin\MySafeProxy32.dll.vir
Group: Malware file
Last Updated: October 12, 2022
%WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.8.0\AddonHQ-RU.exe
File name: AddonHQ-RU.exeSize: 9.56 MB (9569688 bytes)
MD5: cdd41fb24005d8c05f2ec46877373d4a
Detection count: 15
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.8.0
Group: Malware file
Last Updated: October 1, 2014
C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTRM Group\MySafeProxy\Bin\MySafeProxy64.dll.vir
File name: MySafeProxy64.dll.virSize: 411.12 KB (411128 bytes)
MD5: 22b123d7d823ad645f2d8d3267a3aa2b
Detection count: 9
Mime Type: unknown/vir
Path: C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTRM Group\MySafeProxy\Bin\MySafeProxy64.dll.vir
Group: Malware file
Last Updated: October 12, 2022
%WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.9.0\AddonHDQIT-540778d25e356.exe
File name: AddonHDQIT-540778d25e356.exeSize: 9.61 MB (9610040 bytes)
MD5: 85a5026053d28843ad70699d8da08ad0
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.9.0
Group: Malware file
Last Updated: January 29, 2020
%WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.9.0\AddonINFRU-541697ffa8997.exe
File name: AddonINFRU-541697ffa8997.exeSize: 64.87 KB (64878 bytes)
MD5: ce021ed0e1196d82422227556113d83a
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.9.0
Group: Malware file
Last Updated: November 3, 2019
%WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.9.0\AddonHDQES-5407783e6cb87.exe
File name: AddonHDQES-5407783e6cb87.exeSize: 9.59 MB (9593912 bytes)
MD5: f537f278c88d574483bc6f6c1d364485
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.9.0
Group: Malware file
Last Updated: November 3, 2019
More files
Registry Modifications
CLSID{51420F88-4D4A-4042-9509-8D4E1307910E}HKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\MySafeProxy.MySafeProxySOFTWARE\Classes\MySafeProxy.MySafeProxy.1SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{51420F88-4D4A-4042-9509-8D4E1307910E}SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{51420F88-4D4A-4042-9509-8D4E1307910E}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{51420F88-4D4A-4042-9509-8D4E1307910E}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{51420F88-4D4A-4042-9509-8D4E1307910E}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{51420F88-4D4A-4042-9509-8D4E1307910E}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{51420F88-4D4A-4042-9509-8D4E1307910E}SOFTWARE\Wow6432Node\XTRM Group Ltd.\MySafeProxySOFTWARE\XTRM Group Ltd.\MySafeProxySYSTEM\ControlSet001\services\MySafeProxyMonitorSYSTEM\ControlSet002\services\MySafeProxyMonitorSYSTEM\CurrentControlSet\services\MySafeProxyMonitorHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{2535ED3F-5ADD-4A65-B07F-82F04C7358E7}
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.