Home Malware Programs Adware SafetySearch

SafetySearch

Posted: September 26, 2014

Threat Metric

Ranking: 12,389
Threat Level: 2/10
Infected PCs: 2,754
First Seen: July 14, 2014
Last Seen: September 26, 2023
OS(es) Affected: Windows

SafetySearch is classified as a Browser Helper Object (BHO) when it comes to Internet Explorer and a browser extension for Mozilla Firefox and Google Chrome designed by Intriguing Apps. This extension may display pop-ups and advertisements, which may slow down your browsing and interfere with search results. These ads are created to send web traffic to third parties. Adware may be considered risky for your browser's health; this is why computer specialists advise users to be cautious when downloading free software. Moreover, mind that this type of adware is distributed by bundling with freeware, and it is often that the user simply fails to notice how it got on the machine.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES(x86)%\SafetySearch\FrameworkBHO64.dll File name: FrameworkBHO64.dll
Size: 492.88 KB (492880 bytes)
MD5: e21d761c973a004a7e98595bceae756e
Detection count: 525
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\SafetySearch
Group: Malware file
Last Updated: April 28, 2020
%PROGRAMFILES(x86)%\SafetySearch\FrameworkEngine.exe File name: FrameworkEngine.exe
Size: 264.75 KB (264752 bytes)
MD5: c495e75b47bdb5525259742878571c60
Detection count: 363
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\SafetySearch
Group: Malware file
Last Updated: April 28, 2020
%PROGRAMFILES(x86)%\SafetySearch\FrameworkEngine.exe File name: FrameworkEngine.exe
Size: 264.93 KB (264936 bytes)
MD5: 695f3482db703f66c88e813d1bd4b8a0
Detection count: 67
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\SafetySearch
Group: Malware file
Last Updated: July 14, 2014
%PROGRAMFILES(x86)%\SafetySearch\FrameworkBHO64.dll File name: FrameworkBHO64.dll
Size: 577.25 KB (577256 bytes)
MD5: aff7cceffbec8dba3fdbf1526aa423f4
Detection count: 66
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\SafetySearch
Group: Malware file
Last Updated: July 14, 2014

Registry Modifications

The following newly produced Registry Values are:

CLSID{13FFE26E-E2A4-4AC8-9E82-FFC1A3C3578A}{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}{1EE70D1D-B150-4ACF-8498-4C5DE80CEAAC}{7720DB57-7561-457F-B689-D03FB72E3932}{7782DBE4-75A1-453D-B9FD-643F752E4532}{92ADCA6E-1D8C-4F50-BEBF-1480FD408251}{92CECA0E-1DCB-4F42-BA4C-368094400351}{B5D3A0F0-0BFE-429A-A322-95F076081845}HKEY..\..\..\..{RegistryKeys}SOFTWARE\38989Software\Microsoft\Internet Explorer\DOMStorage\safetysearch.netSOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{13FFE26E-E2A4-4AC8-9E82-FFC1A3C3578A}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}Software\Proxy\installations\SafetySearchSOFTWARE\SafetySearchSOFTWARE\Wow6432Node\38989SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{13FFE26E-E2A4-4AC8-9E82-FFC1A3C3578A}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}SOFTWARE\Wow6432Node\SafetySearchHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}38989_SafetySearch

Additional Information

The following directories were created:
%APPDATA%\Microsoft\Windows\Start Menu\Programs\SafetySearch%APPDATA%\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}%LOCALAPPDATA%\SafetySearch%PROGRAMFILES%\SafetySearch%PROGRAMFILES(x86)%\SafetySearch%USERPROFILE%\AppData\LocalLow\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}
Loading...