Home Malware Programs Potentially Unwanted Programs (PUPs) Safer Browser

Safer Browser

Posted: March 30, 2015

Threat Metric

Ranking: 2,115
Threat Level: 1/10
Infected PCs: 540,695
First Seen: January 26, 2015
Last Seen: October 17, 2023
OS(es) Affected: Windows

Safer Browser is typical an adware infection that promotes third-party sites. The Potentially Unwanted Program (PUP) enters in secrecy with the help of freeware or shareware. After that, the suspicious application hijacks the detected web browsers, including Google Chrome, Mozilla Firefox and Internet Explorer. The user may notice that his default homepage is replaced by an alternative search engine such as maxwebsearch.com. It is not to be trusted because the top results may not correspond to the search queries as they are also ads. In addition, the person will likely see various pop-ups, coupons or banners every time he starts his browser. This behavior may be very annoying, but the ads may have even more negative consequences. Some of the sponsored pages may not be safe and may try to load malware to the visitor's PC. To avoid this and remove the irritating ads, users should think about removing Safer Browser with a reputable anti-malware tool.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

File name without pathSafer Browser.lnkRegexp file mask%WINDIR%\System32\Tasks\SaferBrowserProtectTask%WINDIR%\System32\Tasks\SaferUpdateTaskMachineCore%WINDIR%\System32\Tasks\SaferUpdateTaskMachineUA%WINDIR%\Tasks\SaferUpdateTaskMachineCore.job%WINDIR%\Tasks\SaferUpdateTaskMachineUA.jobHKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\AppID\SaferUpdate.exeSOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\{9E357C12-4CA8-43F1-8EEC-7B65F6F532E3}SOFTWARE\Classes\Safer.OneClickCtrl.9SOFTWARE\Classes\Safer.Update3WebControl.3SOFTWARE\Classes\SaferHTMLSOFTWARE\Classes\SaferUpdate.CoCreateAsyncSOFTWARE\Classes\SaferUpdate.CoreClassSOFTWARE\Classes\SaferUpdate.CoreClass.1SOFTWARE\Classes\SaferUpdate.CoreMachineClassSOFTWARE\Classes\SaferUpdate.CoreMachineClass.1SOFTWARE\Classes\SaferUpdate.CredentialDialogMachineSOFTWARE\Classes\SaferUpdate.CredentialDialogMachine.1.0SOFTWARE\Classes\SaferUpdate.OnDemandCOMClassMachineSOFTWARE\Classes\SaferUpdate.OnDemandCOMClassMachine.1.0SOFTWARE\Classes\SaferUpdate.OnDemandCOMClassMachineFallbackSOFTWARE\Classes\SaferUpdate.OnDemandCOMClassMachineFallback.1.0SOFTWARE\Classes\Technologies.OneClickProcessLauncherMachineSOFTWARE\Classes\Technologies.OneClickProcessLauncherMachine.1.0SOFTWARE\Clients\StartMenuInternet\Safer BrowserSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaferUpdate.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SaferBrowserProtectTaskSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SaferUpdateTaskMachineCoreSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SaferUpdateTaskMachineUASOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\safer.exeSoftware\Microsoft\Windows\CurrentVersion\Run\SaferBrowserIsDefaultSOFTWARE\MozillaPlugins\@update.safer.com/Safer Update;version=3SOFTWARE\MozillaPlugins\@update.safer.com/Safer Update;version=9SOFTWARE\RegisteredApplications\Safer BrowserSOFTWARE\Safer TechnologiesSoftware\Safer Technologies\Safer BrowserSOFTWARE\Wow6432Node\Classes\AppID\SaferUpdate.exeSOFTWARE\Wow6432Node\Clients\StartMenuInternet\Safer BrowserSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaferUpdate.exeSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\safer.exeSOFTWARE\Wow6432Node\MozillaPlugins\@update.safer.com/Safer Update;version=3SOFTWARE\Wow6432Node\MozillaPlugins\@update.safer.com/Safer Update;version=9SOFTWARE\Wow6432Node\Safer TechnologiesSOFTWARE\Wow6432Node\Safer Technologies\Safer BrowserHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Safer Browser

Additional Information

The following directories were created:
%LOCALAPPDATA%\Safer Technologies%PROGRAMFILES%\Safer Technologies%UserProfile%\Local Settings\Application Data\Safer Technologies
The following URL's were detected:
//search2.search

Related Posts

Loading...