Home Malware Programs Adware MySafeProxy

MySafeProxy

Posted: September 24, 2014

Threat Metric

Threat Level: 1/10
Infected PCs: 38,851
First Seen: September 24, 2014
Last Seen: November 12, 2024
OS(es) Affected: Windows


MySafeProxy is an add-on for Internet Explorer that claims that MySafeProxy provides security and privacy-enhancing browser functions, although malware experts have yet to validate these claims. Because of MySafeProxy finances itself as a product via the display of potentially unsafe advertising content, MySafeProxy is categorized as adware and a Potentially Unwanted Program.

Web-Browsing Safety at a Questionable Cost

MySafeProxy markets itself as a proxy server that can obfuscate your IP address, allow you renewed access to websites blocked by third parties or provide protection from advertising-tracking agents. Ironically, while malware researchers found minimal indications of MySafeProxy add-ons having any security benefits, they have noted that MySafeProxy injects automatic advertising content. By modifying unrelated Web pages and displaying these third-party advertisements automatically, MySafeProxy may cause some of the same problems that MySafeProxy claims to prevent, while simultaneously ignoring most standard advertisement-blocking functions.

As usual for adware of a similar stripe, MySafeProxy explicitly disclaims any responsibility towards the consequences of being exposed to these third-party advertisements. Based on circumstantial evidence, its advertisement content may include attempts to distribute other PUPs or threats through fake download updates and similar tactics.

While the extra search results, pop-ups and any other content MySafeProxy provides are not guaranteed to harm your PC, malware experts also came across additional risks from some MySafeProxy variants. A minority of MySafeProxy variants, frequently installed automatically, also have displayed excessive system resource usage, particularly for the affected machines' graphics cards. This symptom may be associated with BitCoin miners, which may permanently damage your hardware and cause general system instability.

Getting Rid of the Go-Between Between You and Your Browser

Although using well-selected security add-ons can make your browser safer than its default state, malware experts always advise researching any permanent-use add-ons carefully. MySafeProxy, in its turn, shows most of the hallmarks of conducting a standard adware campaign that generates advertising profits without providing significant benefits to its users. Meanwhile, variants of MySafeProxy that include digital currency miners always must be treated as nothing less than direct threats to your computer's health.

If they're using updated threat databases, competent anti-adware programs or security programs with anti-adware functions should be capable of uninstalling MySafeProxy safely. However, in light of the association of MySafeProxy adware with actual threatening software, you also may wish to run a full anti-malware scan afterward. As usual, typical methods of deleting MySafeProxy that would remove any benign software may fail to delete this add-on, despite its claims of being just a standard security product.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Drive[C]\AdwCleaner\Quarantine\C\Program Files (x86)\XTRM Group\MySafeProxy\Bin\MySafeProxyMonitor.exe.vir File name: MySafeProxyMonitor.exe.vir
Size: 1.3 MB (1308664 bytes)
MD5: 0ac7b45dda06d7bfbc6dded6753dda14
Detection count: 11,371
Mime Type: unknown/vir
Path: C:\Drive[C]\AdwCleaner\Quarantine\C\Program Files (x86)\XTRM Group\MySafeProxy\Bin\MySafeProxyMonitor.exe.vir
Group: Malware file
Last Updated: October 12, 2022
C:\Program Files (x86)\XTRM Group\MySafeProxy\Bin\MySafeProxyMonitor.exe File name: MySafeProxyMonitor.exe
Size: 1.35 MB (1355768 bytes)
MD5: 68732069d7be181c0dcd5582fd0f1d00
Detection count: 8,319
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\XTRM Group\MySafeProxy\Bin\MySafeProxyMonitor.exe
Group: Malware file
Last Updated: January 23, 2024
%WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.9.0\AddonBUBUK-541065aba19f3.exe File name: AddonBUBUK-541065aba19f3.exe
Size: 355.86 KB (355863 bytes)
MD5: f2b6acab059d1b99a43e184c145af1fa
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.9.0
Group: Malware file
Last Updated: October 1, 2014
%WINDIR%\TEMP\XTRM Group Ltd\MySafeProxy\1.0.9.0\AddonHDQUS-5407778e31912.exe File name: AddonHDQUS-5407778e31912.exe
Size: 9.58 MB (9583560 bytes)
MD5: 84815e0218a3ad121113e07778eab4ab
Detection count: 62
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP\XTRM Group Ltd\MySafeProxy\1.0.9.0
Group: Malware file
Last Updated: October 1, 2014
%WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.9.0\AddonCNMUS-5414372c54065.exe File name: AddonCNMUS-5414372c54065.exe
Size: 660.48 KB (660480 bytes)
MD5: 121969abf6d7c243d36edb162898285d
Detection count: 60
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.9.0
Group: Malware file
Last Updated: October 1, 2014
C:\Windows\Temp\XTRM Group Ltd\MySafeProxy\1.0.10.0\AddonMYA-5405c72244bc0.exe File name: AddonMYA-5405c72244bc0.exe
Size: 292.65 KB (292656 bytes)
MD5: a4e979eb193fc09927f2acea53dab434
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\Temp\XTRM Group Ltd\MySafeProxy\1.0.10.0\AddonMYA-5405c72244bc0.exe
Group: Malware file
Last Updated: September 14, 2021
%WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.10.0\AddonHDQUK-5407782528145.exe File name: AddonHDQUK-5407782528145.exe
Size: 9.57 MB (9576824 bytes)
MD5: 10f4dfc1d7c3a9c3cbe273aa60e09ae4
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.10.0
Group: Malware file
Last Updated: October 1, 2014
C:\Copia_disco_30-04-2018\AdwCleaner\Quarantine\C\Archivos de programa\XTRM Group\MySafeProxy\Bin\MySafeProxy32.dll.vir File name: MySafeProxy32.dll.vir
Size: 365.56 KB (365560 bytes)
MD5: c2f115c9c512d5c6793162a282b0298e
Detection count: 21
Mime Type: unknown/vir
Path: C:\Copia_disco_30-04-2018\AdwCleaner\Quarantine\C\Archivos de programa\XTRM Group\MySafeProxy\Bin\MySafeProxy32.dll.vir
Group: Malware file
Last Updated: October 12, 2022
%WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.8.0\AddonHQ-RU.exe File name: AddonHQ-RU.exe
Size: 9.56 MB (9569688 bytes)
MD5: cdd41fb24005d8c05f2ec46877373d4a
Detection count: 15
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.8.0
Group: Malware file
Last Updated: October 1, 2014
C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTRM Group\MySafeProxy\Bin\MySafeProxy64.dll.vir File name: MySafeProxy64.dll.vir
Size: 411.12 KB (411128 bytes)
MD5: 22b123d7d823ad645f2d8d3267a3aa2b
Detection count: 9
Mime Type: unknown/vir
Path: C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTRM Group\MySafeProxy\Bin\MySafeProxy64.dll.vir
Group: Malware file
Last Updated: October 12, 2022
%WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.9.0\AddonHDQIT-540778d25e356.exe File name: AddonHDQIT-540778d25e356.exe
Size: 9.61 MB (9610040 bytes)
MD5: 85a5026053d28843ad70699d8da08ad0
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.9.0
Group: Malware file
Last Updated: January 29, 2020
%WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.9.0\AddonINFRU-541697ffa8997.exe File name: AddonINFRU-541697ffa8997.exe
Size: 64.87 KB (64878 bytes)
MD5: ce021ed0e1196d82422227556113d83a
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.9.0
Group: Malware file
Last Updated: January 23, 2024
%WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.9.0\AddonHDQES-5407783e6cb87.exe File name: AddonHDQES-5407783e6cb87.exe
Size: 9.59 MB (9593912 bytes)
MD5: f537f278c88d574483bc6f6c1d364485
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP\XTRM Group Ltd.\MySafeProxy\1.0.9.0
Group: Malware file
Last Updated: November 3, 2019

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{51420F88-4D4A-4042-9509-8D4E1307910E}HKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\MySafeProxy.MySafeProxySOFTWARE\Classes\MySafeProxy.MySafeProxy.1SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{51420F88-4D4A-4042-9509-8D4E1307910E}SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{51420F88-4D4A-4042-9509-8D4E1307910E}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{51420F88-4D4A-4042-9509-8D4E1307910E}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{51420F88-4D4A-4042-9509-8D4E1307910E}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{51420F88-4D4A-4042-9509-8D4E1307910E}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{51420F88-4D4A-4042-9509-8D4E1307910E}SOFTWARE\Wow6432Node\XTRM Group Ltd.\MySafeProxySOFTWARE\XTRM Group Ltd.\MySafeProxySYSTEM\ControlSet001\services\MySafeProxyMonitorSYSTEM\ControlSet002\services\MySafeProxyMonitorSYSTEM\CurrentControlSet\services\MySafeProxyMonitorHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{2535ED3F-5ADD-4A65-B07F-82F04C7358E7}

Additional Information

The following directories were created:
%TEMP%\XTRM Group Ltd\MySafeProxy
Loading...