Safe Finder

Posted: August 4, 2015
Threat Metric
Threat Level: 5/10
Infected PCs 1,111,144

Safe Finder Description

Safe Finder is a Potentially Unwanted Program that provides various in-browser features, but also may redirect your browser to unwanted sites. Along with its browser hijacking traits, Safe Finder also may be installed automatically, and may exploit formats that may make its deletion unnecessarily difficult. Standard PC security solutions should be capable of removing Safe Finder while scanning your computer, after which malware analysts advise resetting all browser settings back to their original, safe values.

The Risks of Finding Your Search Results with Safe Finder

Safe Finder's website claims to provide Web-simplifying features that allow you to find and access desirable sites more safely than normal, but, like similar browser add-ons, offers drawbacks in equal measure with its benefits. In addition to all of its marketed features, Safe Finder also may lock your default browser to a sub-domain of its personal website (frequently its Yahoo Search-based search engine). These functions have been confirmed for Chrome and most other Windows browsers, although other OSes may or may not be similarly compatible with Safe Finder's changes.

At this time, malware analysts found no indications of Safe Finder using its website to promote harmful content, including online hoaxes or threat-related attacks. However, Safe Finder does reset your browser's settings even after any attempts to reset them are made, preventing PC owners from reversing its browser hijacking 'feature.' Some versions of Safe Finder also may install themselves without all appropriate, visible extension entries allowing for their easy deletion. These characteristics are equally common in threatening software, although, for now, Safe Finder remains classified as a PUP (Potentially Unwanted Program).

Finding Your Way to a Browser Unaltered by Safe Finder

While Safe Finder may use its search features to deliver advertising links or other, affiliated content, having your browser hijacked by Safe Finder isn't equivalent to being redirected towards a threatening website. In spite of that, malware analysts never find any security or accessibility advantages from allowing an external program to control your Web browsing settings. Such applications should be uninstalled for your browser's safety, with any hijacked settings reverted after the uninstall process is finished. Web surfers should note that deleting the affected Web browser may avoid the symptoms of a Safe Finder installation, such as search redirects, but will not remove the actual extension from your PC.

While you may find Safe Finder on its website, most PC users are likely to install Safe Finder unintentionally through its bundling with another application. Free installers distributed at general download sites, along with piracy-oriented networks, are two of the most common, non-consensual distribution tactics used by browser hijackers and other PUPs. You can scan downloads that could be carrying installers with unwanted add-ons for the presence of well-known threats, such as bundle installation platforms. In some situations, they also may give you the opportunity to decline any installation 'extras' like Safe Finder.

Aliases


Riskware/Toolbar_Linkury [Fortinet]a variant of Win32/Toolbar.Linkury.APUP/LinkUry [Panda]Adware.Linkury.B (B)Adware.Linkury.1 [DrWeb]PUA.Toolbar.Linkury!Win32:SmartBar-A [PUP] [Avast]Suspicious_GEN.F47V0612Adware.Linkury (fs)Artemis!447953059FC9 [McAfee]Adware.Linkury.B

Use SpyHunter to Detect and Remove PC Threats

If you are concerned that malware or PC threats similar to Safe Finder may have infected your computer, we recommend you start an in-depth system scan with SpyHunter. SpyHunter is an advanced malware protection and remediation application that offers subscribers a comprehensive method for protecting PCs from malware, in addition to providing one-on-one technical support service.

Download SpyHunter's Malware Scanner

Note: SpyHunter's free version is only for malware detection. If SpyHunter detects malware on your PC, you will need to purchase SpyHunter's malware tool to remove the malware threats. Learn more on SpyHunter. If you would like to uninstall SpyHunter for any reason, please follow these uninstall instructions. To learn more about our policies and practices, visit our EULA, Privacy Policy and Threat Assessment Criteria.

Why can't I open any program including SpyHunter? You may have a malware file running in memory that kills any programs that you try to launch on your PC. Tip: Download SpyHunter from a clean computer, copy it to a USB thumb drive, DVD or CD, then install it on the infected PC and run SpyHunter's malware scanner.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SystemDrive%\Users\NATHI NATHA\AppData\Local\RGMService\RGMUpdater.exe File name: RGMUpdater.exe
Size: 85.5 KB (85504 bytes)
MD5: c069c1bd3b37556cda040807f416aa4f
Detection count: 2,970
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\NATHI NATHA\AppData\Local\RGMService\
Group: Malware file
Last Updated: September 21, 2020
%SYSTEMDRIVE%\Users\user\Desktop\_MEGA\51d2eb7c4d53caea2a1ad30f154dad582c4c17b3b1f044b562d171a0cb4c99d8.exe\51d2eb7c4d53caea2a1ad30f154dad582c4c17b3b1f044b562d171a0cb4c99d8.exe File name: 51d2eb7c4d53caea2a1ad30f154dad582c4c17b3b1f044b562d171a0cb4c99d8.exe
Size: 49.85 KB (49859 bytes)
MD5: 13d4ee06fe8476e0464a3602ec01f5f9
Detection count: 1,103
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\user\Desktop\_MEGA\51d2eb7c4d53caea2a1ad30f154dad582c4c17b3b1f044b562d171a0cb4c99d8.exe\
Group: Malware file
Last Updated: September 30, 2020
%PROGRAMFILES(x86)%\ProductUI\Startup.exe File name: Startup.exe
Size: 169.47 KB (169472 bytes)
MD5: 85084201ba44f6907a2f6272eeb0a4aa
Detection count: 656
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\ProductUI\
Group: Malware file
Last Updated: March 23, 2016
%SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Program Files (x86)\ProductUI\Startup.exe.vir\Startup.exe.vir File name: Startup.exe.vir
Size: 78.84 KB (78848 bytes)
MD5: 505f414ea2c85f39c3b8a260a2556099
Detection count: 124
Mime Type: unknown/vir
Path: %SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Program Files (x86)\ProductUI\Startup.exe.vir\
Group: Malware file
Last Updated: September 10, 2020
%LOCALAPPDATA%\Smartbar\Application\SafeFinder.exe File name: SafeFinder.exe
Size: 28.95 KB (28952 bytes)
MD5: 5e94dfe7de36e4de80f759ed1405063f
Detection count: 10
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\Smartbar\Application\
Group: Malware file
Last Updated: August 8, 2014
C:\users\user\appdata\Local\smartbar\application\browserhelper.exe File name: C:\users\user\appdata\Local\smartbar\application\browserhelper.exe
MD5: c5768f028a5521c1ee77ffef812d1022
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

More files

Registry Modifications


The following newly produced Registry Values are:

Directory%ALLUSERSPROFILE%\Application Data\Hayzumflex%ALLUSERSPROFILE%\Application Data\holdtam%ALLUSERSPROFILE%\Application Data\holdtams%ALLUSERSPROFILE%\Application Data\Kolnixo%ALLUSERSPROFILE%\Application Data\Kolnixos%ALLUSERSPROFILE%\Application Data\lamzap%ALLUSERSPROFILE%\Application Data\quoteex%ALLUSERSPROFILE%\Application Data\SafeFinder%ALLUSERSPROFILE%\Application Data\utatity%ALLUSERSPROFILE%\Hayzumflex%ALLUSERSPROFILE%\Hayzumflexs%ALLUSERSPROFILE%\holdtam%ALLUSERSPROFILE%\holdtams%ALLUSERSPROFILE%\Kolnixo%ALLUSERSPROFILE%\Kolnixos%ALLUSERSPROFILE%\konksolex%ALLUSERSPROFILE%\lamzap%ALLUSERSPROFILE%\quoteex%ALLUSERSPROFILE%\SafeFinder%ALLUSERSPROFILE%\SafeFinders%ALLUSERSPROFILE%\Saophase%ALLUSERSPROFILE%\Saophases%ALLUSERSPROFILE%\statdex%ALLUSERSPROFILE%\UltimateSecurityPackages%COMMONPROGRAMFILES%\Anflex%COMMONPROGRAMFILES%\Apeco%COMMONPROGRAMFILES%\Applus%COMMONPROGRAMFILES%\Blackin%COMMONPROGRAMFILES%\BlackTrax%COMMONPROGRAMFILES%\Canbam%COMMONPROGRAMFILES%\Coffan%COMMONPROGRAMFILES%\Dingfind%commonprogramfiles%\Donex%COMMONPROGRAMFILES%\Dongcof%COMMONPROGRAMFILES%\DoubleJob%COMMONPROGRAMFILES%\Doubletough%COMMONPROGRAMFILES%\Doublewarm%COMMONPROGRAMFILES%\Ecotam%COMMONPROGRAMFILES%\Faselex%COMMONPROGRAMFILES%\Finla%COMMONPROGRAMFILES%\Freeair%COMMONPROGRAMFILES%\Freetrax%COMMONPROGRAMFILES%\Freshex%COMMONPROGRAMFILES%\FreshTech%COMMONPROGRAMFILES%\Geojob%COMMONPROGRAMFILES%\Goldtough%COMMONPROGRAMFILES%\Goodtop%COMMONPROGRAMFILES%\Greenfix%COMMONPROGRAMFILES%\Groovelex%COMMONPROGRAMFILES%\Hattough%COMMONPROGRAMFILES%\Haywarm%COMMONPROGRAMFILES%\Holdtom%COMMONPROGRAMFILES%\Homelax%COMMONPROGRAMFILES%\Hotair%COMMONPROGRAMFILES%\Hotex%COMMONPROGRAMFILES%\Hotfind%COMMONPROGRAMFILES%\Hotity%COMMONPROGRAMFILES%\Hotstring%COMMONPROGRAMFILES%\Icetom%COMMONPROGRAMFILES%\Infind%COMMONPROGRAMFILES%\Insoft%COMMONPROGRAMFILES%\Isflex%COMMONPROGRAMFILES%\Itplus%COMMONPROGRAMFILES%\Jaycom%COMMONPROGRAMFILES%\Jaycore%COMMONPROGRAMFILES%\Jaydox%COMMONPROGRAMFILES%\Jayhome%COMMONPROGRAMFILES%\K-ron%COMMONPROGRAMFILES%\Kayin%COMMONPROGRAMFILES%\Keykix%COMMONPROGRAMFILES%\Kintough%COMMONPROGRAMFILES%\Kon-Dox%COMMONPROGRAMFILES%\Konkfind%COMMONPROGRAMFILES%\KonkSing%COMMONPROGRAMFILES%\Labity%COMMONPROGRAMFILES%\Latcore%COMMONPROGRAMFILES%\Lexicom%COMMONPROGRAMFILES%\Lightstrong%COMMONPROGRAMFILES%\Lighttouch%COMMONPROGRAMFILES%\Medhold%COMMONPROGRAMFILES%\Movetop%COMMONPROGRAMFILES%\Namfax%COMMONPROGRAMFILES%\Newtax%COMMONPROGRAMFILES%\Opedex%COMMONPROGRAMFILES%\Overlax%COMMONPROGRAMFILES%\OverTough%COMMONPROGRAMFILES%\OzerPhase%COMMONPROGRAMFILES%\Ozersoft%COMMONPROGRAMFILES%\Quotelab%COMMONPROGRAMFILES%\Randax%COMMONPROGRAMFILES%\Raning%COMMONPROGRAMFILES%\Ranklux%COMMONPROGRAMFILES%\Redhome%COMMONPROGRAMFILES%\Rontax%COMMONPROGRAMFILES%\Roundtam%COMMONPROGRAMFILES%\Runcom%COMMONPROGRAMFILES%\Saillight%COMMONPROGRAMFILES%\SailSanis%COMMONPROGRAMFILES%\Saltit%COMMONPROGRAMFILES%\Saltzap%COMMONPROGRAMFILES%\San-Fan%COMMONPROGRAMFILES%\Sancom%COMMONPROGRAMFILES%\Saneco%COMMONPROGRAMFILES%\Sanhome%COMMONPROGRAMFILES%\SanStrong%COMMONPROGRAMFILES%\ScotFresh%COMMONPROGRAMFILES%\Silflex%COMMONPROGRAMFILES%\Singleair%COMMONPROGRAMFILES%\Solfind%COMMONPROGRAMFILES%\Solkix%COMMONPROGRAMFILES%\Solo-Eco%COMMONPROGRAMFILES%\Solola%COMMONPROGRAMFILES%\Stanron%COMMONPROGRAMFILES%\StatFresh%COMMONPROGRAMFILES%\StimDom%COMMONPROGRAMFILES%\Stimity%COMMONPROGRAMFILES%\StringIty%COMMONPROGRAMFILES%\Strong-Hold%COMMONPROGRAMFILES%\Subphase%COMMONPROGRAMFILES%\Sunlight%COMMONPROGRAMFILES%\Suntax%COMMONPROGRAMFILES%\TamLux%COMMONPROGRAMFILES%\Tamtech%COMMONPROGRAMFILES%\Taning%COMMONPROGRAMFILES%\Tempdox%COMMONPROGRAMFILES%\Tempit%COMMONPROGRAMFILES%\Tinin%COMMONPROGRAMFILES%\Touchit%COMMONPROGRAMFILES%\TouchLax%commonprogramfiles%\Transplus%COMMONPROGRAMFILES%\Transwarm%COMMONPROGRAMFILES%\Treeing%COMMONPROGRAMFILES%\Tripplecom%COMMONPROGRAMFILES%\Trippleron%COMMONPROGRAMFILES%\Trislab%COMMONPROGRAMFILES%\truetrax%COMMONPROGRAMFILES%\U--Ex%COMMONPROGRAMFILES%\UltimateSecurityPackage%COMMONPROGRAMFILES%\Unacom%COMMONPROGRAMFILES%\Unatouch%COMMONPROGRAMFILES%\Vaiacof%COMMONPROGRAMFILES%\Vaiahome%commonprogramfiles%\Ventoplus%COMMONPROGRAMFILES%\ViaEx%COMMONPROGRAMFILES%\Villatop%COMMONPROGRAMFILES%\Voling%COMMONPROGRAMFILES%\Voya-Ing%COMMONPROGRAMFILES%\Warmfresh%COMMONPROGRAMFILES%\Warmtrax%COMMONPROGRAMFILES%\X-Light%COMMONPROGRAMFILES%\Zaam-It%COMMONPROGRAMFILES%\Zaamcom%COMMONPROGRAMFILES%\Zaamlam%COMMONPROGRAMFILES%\Zaamstring%COMMONPROGRAMFILES%\Zathkix%COMMONPROGRAMFILES%\Zathlab%COMMONPROGRAMFILES%\Zentrax%COMMONPROGRAMFILES%\Zottouch%COMMONPROGRAMFILES%\Zummatouch%COMMONPROGRAMFILES(x86)%\Airlex%COMMONPROGRAMFILES(x86)%\Airtop%COMMONPROGRAMFILES(x86)%\Alphaqvostock%COMMONPROGRAMFILES(x86)%\Anflex%COMMONPROGRAMFILES(x86)%\Apeco%COMMONPROGRAMFILES(x86)%\Applus%COMMONPROGRAMFILES(x86)%\Blackin%COMMONPROGRAMFILES(x86)%\Blacktip%COMMONPROGRAMFILES(x86)%\BlackTrax%COMMONPROGRAMFILES(x86)%\Can-It%COMMONPROGRAMFILES(X86)%\Canbam%COMMONPROGRAMFILES(x86)%\Coffan%COMMONPROGRAMFILES(x86)%\Dingfind%COMMONPROGRAMFILES(x86)%\DomQuadtop%commonprogramfiles(x86)%\Donex%COMMONPROGRAMFILES(x86)%\Dongcof%COMMONPROGRAMFILES(x86)%\DoubleJob%COMMONPROGRAMFILES(x86)%\Doubletough%COMMONPROGRAMFILES(x86)%\Doublewarm%COMMONPROGRAMFILES(x86)%\Driptintrax%COMMONPROGRAMFILES(x86)%\Ecotam%COMMONPROGRAMFILES(x86)%\Fase-Dex%COMMONPROGRAMFILES(x86)%\Faselex%COMMONPROGRAMFILES(x86)%\Finla%COMMONPROGRAMFILES(x86)%\Freeair%COMMONPROGRAMFILES(x86)%\FreeGohold%COMMONPROGRAMFILES(x86)%\Freetrax%COMMONPROGRAMFILES(x86)%\Freshex%COMMONPROGRAMFILES(x86)%\FreshTech%COMMONPROGRAMFILES(x86)%\Geo-Fresh%COMMONPROGRAMFILES(x86)%\Geojob%COMMONPROGRAMFILES(x86)%\Geonamtrax%COMMONPROGRAMFILES(x86)%\Goldtough%COMMONPROGRAMFILES(x86)%\GoodSing%COMMONPROGRAMFILES(X86)%\Goodtop%COMMONPROGRAMFILES(x86)%\Greenfix%COMMONPROGRAMFILES(x86)%\Groovelex%COMMONPROGRAMFILES(x86)%\Hattough%COMMONPROGRAMFILES(x86)%\Haywarm%COMMONPROGRAMFILES(x86)%\Holdtom%COMMONPROGRAMFILES(x86)%\Homelax%COMMONPROGRAMFILES(x86)%\Hotair%COMMONPROGRAMFILES(x86)%\Hotex%COMMONPROGRAMFILES(x86)%\Hotfind%COMMONPROGRAMFILES(x86)%\Hotity%COMMONPROGRAMFILES(x86)%\Hotstring%COMMONPROGRAMFILES(x86)%\Icetom%COMMONPROGRAMFILES(x86)%\Indigotough%COMMONPROGRAMFILES(X86)%\Infind%COMMONPROGRAMFILES(x86)%\Insoft%COMMONPROGRAMFILES(x86)%\Isflex%COMMONPROGRAMFILES(x86)%\Itplus%COMMONPROGRAMFILES(X86)%\Jaycom%COMMONPROGRAMFILES(x86)%\Jaycore%COMMONPROGRAMFILES(x86)%\Jaydox%COMMONPROGRAMFILES(x86)%\Jayhome%COMMONPROGRAMFILES(x86)%\K--Lex%COMMONPROGRAMFILES(x86)%\K-ron%COMMONPROGRAMFILES(X86)%\Kankix%COMMONPROGRAMFILES(x86)%\Kaycore%COMMONPROGRAMFILES(x86)%\Kayin%COMMONPROGRAMFILES(x86)%\Kaylight%COMMONPROGRAMFILES(x86)%\KaySankix%COMMONPROGRAMFILES(x86)%\Keykix%COMMONPROGRAMFILES(x86)%\Keyron%COMMONPROGRAMFILES(x86)%\Kintough%COMMONPROGRAMFILES(x86)%\Konkfind%COMMONPROGRAMFILES(x86)%\KonkSing%COMMONPROGRAMFILES(x86)%\La-Trax%COMMONPROGRAMFILES(X86)%\Labity%COMMONPROGRAMFILES(x86)%\Latcore%COMMONPROGRAMFILES(x86)%\Lexicom%COMMONPROGRAMFILES(x86)%\Lightstrong%COMMONPROGRAMFILES(x86)%\Lighttouch%COMMONPROGRAMFILES(x86)%\Med-Stock%COMMONPROGRAMFILES(X86)%\Medhold%COMMONPROGRAMFILES(x86)%\Medlatis%COMMONPROGRAMFILES(x86)%\Movetop%COMMONPROGRAMFILES(x86)%\Namfax%COMMONPROGRAMFILES(x86)%\Newtax%COMMONPROGRAMFILES(x86)%\Opedex%COMMONPROGRAMFILES(x86)%\Overlax%COMMONPROGRAMFILES(x86)%\OverTough%COMMONPROGRAMFILES(X86)%\OzerPhase%COMMONPROGRAMFILES(x86)%\Ozersoft%COMMONPROGRAMFILES(x86)%\Quotelab%COMMONPROGRAMFILES(X86)%\Randax%COMMONPROGRAMFILES(x86)%\Raning%COMMONPROGRAMFILES(x86)%\Ranklux%COMMONPROGRAMFILES(x86)%\Red-Job%COMMONPROGRAMFILES(x86)%\Redhome%COMMONPROGRAMFILES(x86)%\Redron%COMMONPROGRAMFILES(x86)%\Ronfix%COMMONPROGRAMFILES(x86)%\Rontax%COMMONPROGRAMFILES(x86)%\Roundtam%COMMONPROGRAMFILES(x86)%\Runcom%COMMONPROGRAMFILES(x86)%\S-stock%COMMONPROGRAMFILES(x86)%\Saillight%COMMONPROGRAMFILES(x86)%\Sailtouch%COMMONPROGRAMFILES(x86)%\Saltit%COMMONPROGRAMFILES(x86)%\Saltzap%COMMONPROGRAMFILES(x86)%\San-Fan%COMMONPROGRAMFILES(x86)%\Sancom%COMMONPROGRAMFILES(x86)%\Saneco%COMMONPROGRAMFILES(x86)%\Sanhome%COMMONPROGRAMFILES(x86)%\SanStrong%COMMONPROGRAMFILES(x86)%\Saotop%COMMONPROGRAMFILES(x86)%\ScotFresh%COMMONPROGRAMFILES(X86)%\Silflex%COMMONPROGRAMFILES(x86)%\Silverron%COMMONPROGRAMFILES(x86)%\Singleair%COMMONPROGRAMFILES(x86)%\Singlelamlam%COMMONPROGRAMFILES(x86)%\Solfind%COMMONPROGRAMFILES(x86)%\Solkix%COMMONPROGRAMFILES(x86)%\Solo-Eco%COMMONPROGRAMFILES(x86)%\Solola%COMMONPROGRAMFILES(x86)%\Stanron%COMMONPROGRAMFILES(x86)%\StatFresh%COMMONPROGRAMFILES(x86)%\StimDom%COMMONPROGRAMFILES(x86)%\Stimity%COMMONPROGRAMFILES(x86)%\Stock-Home%COMMONPROGRAMFILES(x86)%\StringIty%COMMONPROGRAMFILES(x86)%\Strong-Hold%COMMONPROGRAMFILES(x86)%\Subphase%COMMONPROGRAMFILES(x86)%\Sun-Warm%COMMONPROGRAMFILES(x86)%\Sunlight%COMMONPROGRAMFILES(x86)%\Suntax%COMMONPROGRAMFILES(x86)%\TamLux%COMMONPROGRAMFILES(x86)%\Tamtech%COMMONPROGRAMFILES(x86)%\Taning%COMMONPROGRAMFILES(x86)%\Tempdox%COMMONPROGRAMFILES(x86)%\Tempit%COMMONPROGRAMFILES(x86)%\Tin-Light%COMMONPROGRAMFILES(x86)%\Tinin%COMMONPROGRAMFILES(x86)%\Toucheco%COMMONPROGRAMFILES(x86)%\Touchit%COMMONPROGRAMFILES(x86)%\TouchLax%COMMONPROGRAMFILES(x86)%\Touchsing%COMMONPROGRAMFILES(x86)%\Tran-Tough%commonprogramfiles(x86)%\Transplus%COMMONPROGRAMFILES(x86)%\Transwarm%COMMONPROGRAMFILES(x86)%\Treeing%COMMONPROGRAMFILES(x86)%\Tripplecom%COMMONPROGRAMFILES(x86)%\Trippleron%COMMONPROGRAMFILES(x86)%\Tris-Phase%COMMONPROGRAMFILES(x86)%\Trislab%COMMONPROGRAMFILES(x86)%\truetrax%COMMONPROGRAMFILES(x86)%\U--Ex%COMMONPROGRAMFILES(X86)%\UltimateSecurityPackage%COMMONPROGRAMFILES(x86)%\Unacom%COMMONPROGRAMFILES(x86)%\Unatouch%COMMONPROGRAMFILES(x86)%\Vaiacof%COMMONPROGRAMFILES(x86)%\Vaiahome%commonprogramfiles(x86)%\Ventoplus%COMMONPROGRAMFILES(x86)%\ViaEx%COMMONPROGRAMFILES(X86)%\Villatop%COMMONPROGRAMFILES(x86)%\Voling%COMMONPROGRAMFILES(x86)%\Voya-Ing%COMMONPROGRAMFILES(x86)%\Warmfresh%COMMONPROGRAMFILES(X86)%\Warmtrax%COMMONPROGRAMFILES(x86)%\X-Light%COMMONPROGRAMFILES(x86)%\Zaam-It%COMMONPROGRAMFILES(x86)%\Zaamcom%COMMONPROGRAMFILES(x86)%\Zaamlam%COMMONPROGRAMFILES(x86)%\Zaamstring%COMMONPROGRAMFILES(x86)%\Zathkix%COMMONPROGRAMFILES(x86)%\Zathlab%COMMONPROGRAMFILES(x86)%\Zentrax%COMMONPROGRAMFILES(x86)%\Zernimtone%COMMONPROGRAMFILES(x86)%\ZimLa%COMMONPROGRAMFILES(x86)%\Zoneis%COMMONPROGRAMFILES(x86)%\Zonetough%COMMONPROGRAMFILES(x86)%\Zottouch%COMMONPROGRAMFILES(x86)%\Zummatouch%COMMONPROGRAMFILES(x86)%\ZunRon%PROGRAMFILES%\ProductUI%PROGRAMFILES(x86)%\ProductUI%PROGRAMFILES(x86)%\safefinderCookiessearch.safefinder.comRegexp file mask%LOCALAPPDATA%\Stocktouch.exeRegistry keySoftware\Microsoft\Internet Explorer\Approved Extensions\{9EB324CA-1466-4907-8392-92C9F653A229}Software\Microsoft\Internet Explorer\DOMStorage\safefinder.comSoftware\Microsoft\Internet Explorer\DOMStorage\search.safefinder.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\safefinder.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\search.safefinder.comSoftware\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\SafeFinder.exeSOFTWARE\Microsoft\Internet Explorer\Toolbar\{9eb324ca-1466-4907-8392-92c9f653a229}SOFTWARE\Microsoft\Tracing\Hayzumflex_RASAPI32SOFTWARE\Microsoft\Tracing\Hayzumflex_RASMANCSSOFTWARE\Microsoft\Tracing\Quoteex_RASAPI32SOFTWARE\Microsoft\Tracing\Quoteex_RASMANCSSOFTWARE\Microsoft\Tracing\SafeFinder_RASAPI32SOFTWARE\Microsoft\Tracing\SafeFinder_RASMANCSSOFTWARE\Microsoft\Tracing\UltimateSecurityPackage_RASAPI32SOFTWARE\Microsoft\Tracing\UltimateSecurityPackage_RASMANCSSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SafeFinder.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UltimateSecurityPackage.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Hayzumflex.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Quoteex.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\UltimateSecurityPackage.exeSOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\HayzumflexUSOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Stpro.exeSOFTWARE\mtHayzumflexSoftware\mtSafeFinderSOFTWARE\mtUltimateSecurityPackageSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{9eb324ca-1466-4907-8392-92c9f653a229}SOFTWARE\WOW6432Node\Microsoft\Tracing\Hayzumflex_RASAPI32SOFTWARE\WOW6432Node\Microsoft\Tracing\Hayzumflex_RASMANCSSOFTWARE\WOW6432Node\Microsoft\Tracing\Quoteex_RASAPI32SOFTWARE\WOW6432Node\Microsoft\Tracing\Quoteex_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\SafeFinder_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\SafeFinder_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\UltimateSecurityPackage_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\UltimateSecurityPackage_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SafeFinder.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UltimateSecurityPackage.exeSOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Hayzumflex.exeSOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Quoteex.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\UltimateSecurityPackage.exeSOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\HayzumflexUSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\Stpro.exeSOFTWARE\WOW6432Node\mtHayzumflexSOFTWARE\Wow6432Node\mtUltimateSecurityPackageSYSTEM\ControlSet001\services\HayzumflexSYSTEM\ControlSet002\services\HayzumflexSYSTEM\CurrentControlSet\services\HayzumflexHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{B685D7F1-BAC8-4318-8137-A774268BBD39}{UltimateSecurityPackage}File name without pathhttp_search.cubokit.com_0.localstoragehttp_search.cubokit.com_0.localstorage-journalhttp_search.safefinder.com_0.localstoragehttp_search.safefinder.com_0.localstorage-journalsearch.safefinder[1].xmlCLSID{9EB324CA-1466-4907-8392-92C9F653A229}{EDF23B0E-D735-3964-B81F-0BF003A3EC3B}

Additional Information

The following cookies were detected:
search.safefinder.com
The following URL's were detected:
www.linkury.com

Leave a Reply

Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter. If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.