Home Malware Programs Adware Surf Safely Ads

Surf Safely Ads

Posted: July 15, 2014

Threat Metric

Ranking: 14,805
Threat Level: 2/10
Infected PCs: 1,302
First Seen: July 14, 2014
Last Seen: October 1, 2023
OS(es) Affected: Windows


Surf Safely is adware that may sneak into your PC unnoticed when you install software bundles. Surf Safely may attach towards all Web clients that you have, including Google Chrome, Mozilla Firefox and Internet Explorer. The primary function of Surf Safely is to inject various commercial materials, which may take the shape of pop-ups, banners, interstitial ads or embedded videos. Clicking on these new ads will transfer you to partner pages, some of which may be e-commerce platforms. The developers of Surf Safely have financial incentives to cause redirections to the affiliated domains. In most cases, the PC users don't benefit from this adware because the majority of promoted sites may be unreliable or untrustworthy. The presence of the commercial materials may cause you annoyance. They may contain vivid colors or eye-catching and blinking elements, which may distract you. What is more, some marketing elements may be placed in such a way that they may cover page buttons. This questionable extension may consume much of the available RAM for its processes, which may trouble the loading of the sites or cause browser freezes. Your whole PC may start running sluggishly. Surf Safely nay try to make the coupons and exclusive offers suitable for you. The adware records your browsing and searching histories to determine your interests. Even if you decide that some ad is worth your attention, you should be careful not to install some compromised software. Surf Safely may come as an addition towards other freeware. Its description doesn't provide adequate information about the adware characteristics of this application. Instead, its developers promote Surf Safely as a security tool that can block harmful pages. However, Surf Safely cannot shield you from parasites. It is advisable to install a renowned anti-malware tool and use it to delete Surf Safely.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES(x86)%\Surf Safely\FrameworkEngine.exe File name: FrameworkEngine.exe
Size: 263.77 KB (263776 bytes)
MD5: ca04cdf0e289d2f2e5c5f6ad7741c9cf
Detection count: 84
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Surf Safely
Group: Malware file
Last Updated: July 14, 2014
%PROGRAMFILES%\Surf Safely\FrameworkEngine.exe File name: FrameworkEngine.exe
Size: 264.01 KB (264016 bytes)
MD5: dbb9a1fe2a66ff9fa8691d51eed9bd58
Detection count: 84
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Surf Safely
Group: Malware file
Last Updated: July 14, 2014
%PROGRAMFILES(x86)%\Surf Safely\FrameworkEngine.exe File name: FrameworkEngine.exe
Size: 264.01 KB (264016 bytes)
MD5: 939ba457a662dcd13e9c18bf02693e1d
Detection count: 55
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Surf Safely
Group: Malware file
Last Updated: July 14, 2014
%PROGRAMFILES%\Surf Safely\FrameworkEngine.exe File name: FrameworkEngine.exe
Size: 264.93 KB (264936 bytes)
MD5: d2edb8bcac7d3614547fe2902738eb71
Detection count: 46
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Surf Safely
Group: Malware file
Last Updated: July 14, 2014
%PROGRAMFILES%\Surf Safely\FrameworkEngine.exe File name: FrameworkEngine.exe
Size: 264.93 KB (264936 bytes)
MD5: f751b88f74cd4adab3abb65c1b40aa0d
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Surf Safely
Group: Malware file
Last Updated: July 14, 2014
%PROGRAMFILES(x86)%\Surf Safely\FrameworkEngine.exe File name: FrameworkEngine.exe
Size: 264.01 KB (264016 bytes)
MD5: c38ac6adb4cb97275ccf197188a0cfed
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Surf Safely
Group: Malware file
Last Updated: July 14, 2014
%PROGRAMFILES%\Surf Safely\FrameworkEngine.exe File name: FrameworkEngine.exe
Size: 264.93 KB (264936 bytes)
MD5: e07aad279dd7b0fcf13552538d7e7b31
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Surf Safely
Group: Malware file
Last Updated: July 14, 2014
%PROGRAMFILES(x86)%\Surf Safely\FrameworkEngine.exe File name: FrameworkEngine.exe
Size: 264.75 KB (264752 bytes)
MD5: 971a1ec6822dd4ad033b37b001c0e2ff
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Surf Safely
Group: Malware file
Last Updated: July 14, 2014
%PROGRAMFILES(x86)%\Surf Safely\FrameworkEngine.exe File name: FrameworkEngine.exe
Size: 263.77 KB (263776 bytes)
MD5: c923229ea5a58dece4ab9809f8d4f4ad
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Surf Safely
Group: Malware file
Last Updated: July 14, 2014
%PROGRAMFILES(x86)%\Surf Safely\FrameworkBHO64.dll File name: FrameworkBHO64.dll
Size: 577.07 KB (577072 bytes)
MD5: 21c28f4e5fbcd1d2331477ecea3634dd
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Surf Safely
Group: Malware file
Last Updated: July 14, 2014
%PROGRAMFILES%\Surf Safely\FrameworkBHO.dll File name: FrameworkBHO.dll
Size: 356.58 KB (356584 bytes)
MD5: a6ead8b48272bb0528f9db0b3cac8ad1
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Surf Safely
Group: Malware file
Last Updated: July 14, 2014
%PROGRAMFILES(x86)%\Surf Safely\FrameworkBHO64.dll File name: FrameworkBHO64.dll
Size: 492.64 KB (492640 bytes)
MD5: 7a9eb341e31cc9484a8eb28262a54f8b
Detection count: 3
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Surf Safely
Group: Malware file
Last Updated: July 14, 2014

Registry Modifications

The following newly produced Registry Values are:

CLSID{2139705E-FE4C-492C-B08C-77EBD02CD897}{48B32EA3-DCF8-4C2A-9649-EEB6809AFF66}{4920DE57-8B61-417F-B689-D0F3B74B3981}{49EADED5-8B21-418B-9084-91F3E94BC481}{6C85A1C9-0F93-4B46-BE67-D409D64C7E67}{6CE7A11D-0F50-4BCF-8498-4C09E84CEA67}{8167D7E6-93D6-4499-A3CF-6DDF9A716826}{81ADD76E-938C-4450-BEBF-14DFFD718226}HKEY..\..\..\..{RegistryKeys}SOFTWARE\38986SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{48B32EA3-DCF8-4C2A-9649-EEB6809AFF66}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6C85A1C9-0F93-4B46-BE67-D409D64C7E67}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6C85A1C9-0F93-4B46-BE67-D409D64C7E67}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{6C85A1C9-0F93-4B46-BE67-D409D64C7E67}Software\Proxy\installations\Surf SafelySOFTWARE\Surf SafelySOFTWARE\Wow6432Node\38986SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{48B32EA3-DCF8-4C2A-9649-EEB6809AFF66}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{6C85A1C9-0F93-4B46-BE67-D409D64C7E67}SOFTWARE\Wow6432Node\Proxy\Installations\Surf SafelySOFTWARE\Wow6432Node\Surf SafelyHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}38986_Surf Safely

Additional Information

The following directories were created:
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Surf Safely%APPDATA%\{6C85A1C9-0F93-4B46-BE67-D409D64C7E67}%LOCALAPPDATA%\Surf Safely%PROGRAMFILES%\Surf Safely%PROGRAMFILES(x86)%\Surf Safely%USERPROFILE%\AppData\LocalLow\{6C85A1C9-0F93-4B46-BE67-D409D64C7E67}
Loading...