Jump to content

Removal instructions for SafetySearch


Recommended Posts

  • Staff

What is SafetySearch?

The Malwarebytes research team has determined that SafetySearch is a browser hijacker. These so-called "hijackers" alter your startpage or searchscopes so that the effected browser visits their site or one of their choice. This one also displays advertisements.

How do I know if my computer is affected by SafetySearch?

This is how the start-page looks:

main.png

And you may see these add-ons:

warning1.png

warning2.png

or this entry in your list of installed programs:

warning4.png

You will find this icon in your taskbar:

icons.png

How did SafetySearch get on my computer?

Browser hijackers use different methods for distributing themselves. This particular one was offered as web security software.

How do I remove SafetySearch?

Our program Malwarebytes Anti-Malware can detect and remove this potentially unwanted application.

  • Please download Malwarebytes Anti-Malware to your desktop.
  • Double-click mbam-setup-version.exe and follow the prompts to install the program.
  • At the end, be sure a check-mark is placed next to the following:
    • Enable free trial of Malwarebytes Anti-Malware Premium
    • Launch Malwarebytes Anti-Malware
  • Then click Finish.
  • If an update is found, you will be prompted to download and install the latest version.
  • Once the program has loaded, select Scan now. Or select the Threat Scan from the Scan menu.
  • When the scan is complete , make sure that everything is set to "Quarantine", and click Apply Actions.
  • Reboot your computer if prompted.
Is there anything else I need to do to get rid of SafetySearch?
  • No, Malwarebytes' Anti-Malware removes SafetySearch completely.
How would the full version of Malwarebytes Anti-Malware help protect me?

We hope our application and this guide have helped you eradicate this hijacker.

As you can see below the full version of Malwarebytes Anti-Malware would have protected you against the SafetySearch rogue. It would have warned you before the rogue could install itself, giving you a chance to stop it before it became too late.

protection1.png

Technical details for experts

Signs in a HijackThis log:

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:3128O1 - Hosts: 54.225.95.126 fjnoekdlmmjagmmlchagfonjgbioomooO2 - BHO: SafetySearch BHO - {1EDE0D83-B129-4ABC-923B-725D5B0C0DAC} - C:\Program Files\SafetySearch\FrameworkBHO.dllO4 - HKLM\..\Run: [BService] C:\Program Files\Bench\BService\1.1\bservice.exeO4 - HKLM\..\Run: [Wd] C:\Program Files\Bench\Wd\wd.exeO4 - HKLM\..\Run: [Bench Communicator Watcher] C:\Program Files\Bench\Proxy\pwdg.exeO4 - HKLM\..\Run: [Bench Settings Cleaner] C:\Program Files\Bench\Proxy\cl.exeO4 - HKLM\..\RunOnce: [SafetySearch-repairJob] wscript.exe "C:\Users\{username}\AppData\Local\SafetySearch\repair.js" "SafetySearch-repairJob"
Alterations made by the installer:

File system details  ---------------------------------------------    Adds the folder C:\Program Files\Bench\BService\1.1       Adds the file bhelper.dll"="5/29/2014 8:35 PM, 53248 bytes, A       Adds the file bservice.exe"="6/24/2014 6:57 PM, 52736 bytes, A    Adds the folder C:\Program Files\Bench\NmHost       Adds the file manifest.json"="7/13/2014 10:30 AM, 215 bytes, A       Adds the file nmhost.exe"="5/29/2014 8:35 PM, 165376 bytes, A    Adds the folder C:\Program Files\Bench\NmHost\data\installer       Adds the file fjnoekdlmmjagmmlchagfonjgbioomoo"="7/13/2014 10:30 AM, 954 bytes, A    Adds the folder C:\Program Files\Bench\Proxy       Adds the file cl.exe"="6/17/2014 5:44 PM, 55296 bytes, A       Adds the file icon.ico"="6/26/2014 10:07 AM, 32038 bytes, A       Adds the file proc.exe"="6/17/2014 5:44 PM, 422912 bytes, A       Adds the file pwdg.exe"="6/17/2014 5:44 PM, 113152 bytes, A    Adds the folder C:\Program Files\Bench\Updater       Adds the file products.xml"="7/13/2014 10:30 AM, 377 bytes, A       Adds the file updater.exe"="5/29/2014 8:35 PM, 69120 bytes, A    Adds the folder C:\Program Files\Bench\Updater\1.7.0.0       Adds the file updater.exe"="5/29/2014 8:35 PM, 468480 bytes, A    Adds the folder C:\Program Files\Bench\Wd       Adds the file wd.exe"="6/17/2014 5:44 PM, 92672 bytes, A    Adds the folder C:\Program Files\SafetySearch       Adds the file background.html"="6/26/2014 10:07 AM, 157 bytes, A       Adds the file config.xml"="6/26/2014 10:07 AM, 2242 bytes, A       Adds the file extension_info.json"="7/13/2014 10:30 AM, 2370 bytes, A       Adds the file FrameworkBHO.dll"="6/26/2014 10:07 AM, 471600 bytes, A       Adds the file FrameworkBHO64.dll"="6/26/2014 10:07 AM, 492880 bytes, A       Adds the file FrameworkEngine.exe"="6/26/2014 10:07 AM, 264752 bytes, A    Adds the folder C:\Program Files\SafetySearch\AppFramework       Adds the file appAPI_bg.js"="6/26/2014 10:07 AM, 2582 bytes, A       Adds the file appAPI_browseraction.js"="6/26/2014 10:07 AM, 799 bytes, A       Adds the file appAPI_common.js"="6/26/2014 10:07 AM, 9871 bytes, A       Adds the file appAPI_content.js"="6/26/2014 10:07 AM, 1247 bytes, A       Adds the file appAPI_settings.js"="6/26/2014 10:07 AM, 83 bytes, A       Adds the file appAPI_webrequest.js"="6/26/2014 10:07 AM, 138 bytes, A       Adds the file jquery.min.js"="6/26/2014 10:07 AM, 93548 bytes, A    Adds the folder C:\Program Files\SafetySearch\CanvasFramework       Adds the file canvas_bg.js"="6/26/2014 10:07 AM, 5651 bytes, A       Adds the file canvasscript_engine.js"="6/26/2014 10:07 AM, 437 bytes, A       Adds the file md5.js"="6/26/2014 10:07 AM, 3264 bytes, A       Adds the file registry.js"="6/26/2014 10:07 AM, 908 bytes, A       Adds the file webrequest.js"="6/26/2014 10:07 AM, 4005 bytes, A    Adds the folder C:\Program Files\SafetySearch\framework       Adds the file backgroundscript_engine.js"="6/26/2014 10:07 AM, 1872 bytes, A       Adds the file base.js"="6/26/2014 10:07 AM, 2933 bytes, A       Adds the file browser.js"="6/26/2014 10:07 AM, 11200 bytes, A       Adds the file console.js"="6/26/2014 10:07 AM, 489 bytes, A       Adds the file framework.js"="6/26/2014 10:07 AM, 3542 bytes, A       Adds the file global.js"="6/26/2014 10:07 AM, 1850 bytes, A       Adds the file i18n.js"="6/26/2014 10:07 AM, 1661 bytes, A       Adds the file initialize.js"="6/26/2014 10:07 AM, 316 bytes, A       Adds the file invoke_async.js"="6/26/2014 10:07 AM, 2312 bytes, A       Adds the file io.js"="6/26/2014 10:07 AM, 1308 bytes, A       Adds the file json2.js"="6/26/2014 10:07 AM, 2791 bytes, A       Adds the file lang.js"="6/26/2014 10:07 AM, 1633 bytes, A       Adds the file legacy.js"="6/26/2014 10:07 AM, 1270 bytes, A       Adds the file message_target.js"="6/26/2014 10:07 AM, 854 bytes, A       Adds the file messaging.js"="6/26/2014 10:07 AM, 1507 bytes, A       Adds the file storage.js"="6/26/2014 10:07 AM, 3603 bytes, A       Adds the file timer.js"="6/26/2014 10:07 AM, 409 bytes, A       Adds the file updater.js"="6/26/2014 10:07 AM, 2417 bytes, A       Adds the file userscript_client.js"="6/26/2014 10:07 AM, 310 bytes, A       Adds the file userscript_engine.js"="6/26/2014 10:07 AM, 3062 bytes, A       Adds the file utils.js"="6/26/2014 10:07 AM, 2492 bytes, A       Adds the file xhr.js"="6/26/2014 10:07 AM, 3081 bytes, A    Adds the folder C:\Program Files\SafetySearch\framework-ui       Adds the file browser_button.js"="6/26/2014 10:07 AM, 5135 bytes, A       Adds the file context_menu.js"="6/26/2014 10:07 AM, 738 bytes, A       Adds the file context_menu_item_handler.html"="6/26/2014 10:07 AM, 225 bytes, A       Adds the file framework_api.js"="6/26/2014 10:07 AM, 1589 bytes, A       Adds the file notification.html"="6/26/2014 10:07 AM, 6591 bytes, A       Adds the file notifications.js"="6/26/2014 10:07 AM, 2409 bytes, A       Adds the file options.js"="6/26/2014 10:07 AM, 660 bytes, A       Adds the file ui_base.js"="6/26/2014 10:07 AM, 1788 bytes, A    Adds the folder C:\Program Files\SafetySearch\framework-ui\theme\bubble       Adds the file bottom-left.png"="6/26/2014 10:07 AM, 316 bytes, A       Adds the file bottom-middle.png"="6/26/2014 10:07 AM, 240 bytes, A       Adds the file bottom-right.png"="6/26/2014 10:07 AM, 311 bytes, A       Adds the file middle-left.png"="6/26/2014 10:07 AM, 235 bytes, A       Adds the file middle-right.png"="6/26/2014 10:07 AM, 234 bytes, A       Adds the file tail-bottom.png"="6/26/2014 10:07 AM, 315 bytes, A       Adds the file tail-left.png"="6/26/2014 10:07 AM, 307 bytes, A       Adds the file tail-right.png"="6/26/2014 10:07 AM, 304 bytes, A       Adds the file tail-top.png"="6/26/2014 10:07 AM, 315 bytes, A       Adds the file top-left.png"="6/26/2014 10:07 AM, 310 bytes, A       Adds the file top-middle.png"="6/26/2014 10:07 AM, 240 bytes, A       Adds the file top-right.png"="6/26/2014 10:07 AM, 308 bytes, A    Adds the folder C:\Program Files\SafetySearch\icons       Adds the file button.png"="6/26/2014 10:07 AM, 517 bytes, A       Adds the file icon100.png"="6/26/2014 10:07 AM, 3526 bytes, A       Adds the file icon128.png"="6/26/2014 10:07 AM, 4559 bytes, A       Adds the file icon32.png"="6/26/2014 10:07 AM, 1095 bytes, A       Adds the file icon48.png"="6/26/2014 10:07 AM, 1633 bytes, A    Adds the folder C:\Users\{username}\AppData\Local\BenchUpdater       Adds the file products.xml"="7/13/2014 10:30 AM, 442 bytes, A    Adds the folder C:\Users\{username}\AppData\Local\SafetySearch       Adds the file chrome_gp_update.js"="5/29/2014 8:35 PM, 2348 bytes, A       Adds the file chrome_installer.js"="6/24/2014 6:57 PM, 6304 bytes, A       Adds the file clear_cache.js"="6/17/2014 5:44 PM, 522 bytes, A       Adds the file common.js"="6/24/2014 6:57 PM, 13550 bytes, A       Adds the file firefox_installer.js"="6/17/2014 5:44 PM, 6848 bytes, A       Adds the file gpedit.exe"="6/24/2014 6:57 PM, 95744 bytes, A       Adds the file icon.ico"="6/26/2014 10:07 AM, 32038 bytes, A       Adds the file ie_installer.js"="6/17/2014 5:44 PM, 3685 bytes, A       Adds the file installer.js"="6/24/2014 6:57 PM, 799 bytes, A       Adds the file main_installer.js"="5/29/2014 8:35 PM, 1567 bytes, A       Adds the file migrate.js"="5/29/2014 8:35 PM, 4746 bytes, A       Adds the file projectInstaller.js"="5/29/2014 8:35 PM, 3004 bytes, A       Adds the file repair.js"="5/29/2014 8:35 PM, 1735 bytes, A       Adds the file repair_data.json"="7/13/2014 10:30 AM, 2972 bytes, A       Adds the file SoftwareDetector.exe"="6/24/2014 6:57 PM, 78848 bytes, A       Adds the file sqlite3.exe"="5/29/2014 8:35 PM, 492544 bytes, A       Adds the file storageedit.exe"="5/29/2014 8:35 PM, 75264 bytes, A       Adds the file uninstall.exe"="7/13/2014 10:30 AM, 148173 bytes, A    Adds the folder C:\Users\{username}\AppData\Local\SafetySearch\firefox       Adds the file background.html"="6/26/2014 10:07 AM, 157 bytes, A       Adds the file bootstrap.js"="6/26/2014 10:07 AM, 2857 bytes, A       Adds the file chrome.manifest"="6/26/2014 10:07 AM, 57 bytes, A       Adds the file extension_info.json"="6/26/2014 10:07 AM, 1687 bytes, A       Adds the file install.rdf"="6/26/2014 10:07 AM, 1204 bytes, A    Adds the folder C:\Users\{username}\AppData\Local\SafetySearch\firefox\AppFramework       Adds the file appAPI_bg.js"="6/26/2014 10:07 AM, 2582 bytes, A       Adds the file appAPI_browseraction.js"="6/26/2014 10:07 AM, 799 bytes, A       Adds the file appAPI_common.js"="6/26/2014 10:07 AM, 9871 bytes, A       Adds the file appAPI_content.js"="6/26/2014 10:07 AM, 1247 bytes, A       Adds the file appAPI_settings.js"="6/26/2014 10:07 AM, 83 bytes, A       Adds the file appAPI_webrequest.js"="6/26/2014 10:07 AM, 138 bytes, A       Adds the file jquery.min.js"="6/26/2014 10:07 AM, 83059 bytes, A    Adds the folder C:\Users\{username}\AppData\Local\SafetySearch\firefox\CanvasFramework       Adds the file canvas_bg.js"="6/26/2014 10:07 AM, 5651 bytes, A       Adds the file canvasscript_engine.js"="6/26/2014 10:07 AM, 437 bytes, A       Adds the file md5.js"="6/26/2014 10:07 AM, 3264 bytes, A       Adds the file registry.js"="6/26/2014 10:07 AM, 796 bytes, A       Adds the file webrequest.js"="6/26/2014 10:07 AM, 5575 bytes, A    Adds the folder C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework       Adds the file backgroundscript_engine.js"="6/26/2014 10:07 AM, 1580 bytes, A       Adds the file base.js"="6/26/2014 10:07 AM, 2933 bytes, A       Adds the file browser.js"="6/26/2014 10:07 AM, 12801 bytes, A       Adds the file chrome_windows.js"="6/26/2014 10:07 AM, 2627 bytes, A       Adds the file console.js"="6/26/2014 10:07 AM, 540 bytes, A       Adds the file content_proxy.js"="6/26/2014 10:07 AM, 502 bytes, A       Adds the file framework.js"="6/26/2014 10:07 AM, 4381 bytes, A       Adds the file i18n.js"="6/26/2014 10:07 AM, 1601 bytes, A       Adds the file invoke_async.js"="6/26/2014 10:07 AM, 2312 bytes, A       Adds the file io.js"="6/26/2014 10:07 AM, 976 bytes, A       Adds the file lang.js"="6/26/2014 10:07 AM, 3080 bytes, A       Adds the file legacy.js"="6/26/2014 10:07 AM, 1270 bytes, A       Adds the file message_target.js"="6/26/2014 10:07 AM, 854 bytes, A       Adds the file messaging.js"="6/26/2014 10:07 AM, 1507 bytes, A       Adds the file storage.js"="6/26/2014 10:07 AM, 6156 bytes, A       Adds the file timer.js"="6/26/2014 10:07 AM, 977 bytes, A       Adds the file uninstall.js"="6/26/2014 10:07 AM, 73 bytes, A       Adds the file userscript_client.js"="6/26/2014 10:07 AM, 310 bytes, A       Adds the file userscript_engine.js"="6/26/2014 10:07 AM, 3062 bytes, A       Adds the file utils.js"="6/26/2014 10:07 AM, 2492 bytes, A       Adds the file xhr.js"="6/26/2014 10:07 AM, 2155 bytes, A    Adds the folder C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui       Adds the file browser_button.js"="6/26/2014 10:07 AM, 9099 bytes, A       Adds the file content_notifications.js"="6/26/2014 10:07 AM, 9098 bytes, A       Adds the file contentNotification.tmpl"="6/26/2014 10:07 AM, 836 bytes, A       Adds the file contentNotificationStyle.tmpl"="6/26/2014 10:07 AM, 3729 bytes, A       Adds the file context_menu.js"="6/26/2014 10:07 AM, 2144 bytes, A       Adds the file framework_api.js"="6/26/2014 10:07 AM, 1627 bytes, A       Adds the file notifications.js"="6/26/2014 10:07 AM, 3542 bytes, A       Adds the file options.js"="6/26/2014 10:07 AM, 934 bytes, A       Adds the file ui_base.js"="6/26/2014 10:07 AM, 1788 bytes, A    Adds the folder C:\Users\{username}\AppData\Local\SafetySearch\firefox\icons       Adds the file button.png"="6/26/2014 10:07 AM, 517 bytes, A       Adds the file icon100.png"="6/26/2014 10:07 AM, 3526 bytes, A       Adds the file icon128.png"="6/26/2014 10:07 AM, 4559 bytes, A       Adds the file icon32.png"="6/26/2014 10:07 AM, 1095 bytes, A       Adds the file icon48.png"="6/26/2014 10:07 AM, 1633 bytes, A    Adds the folder C:\Users\{username}\AppData\LocalLow\Protect\Blocker       Adds the file 212e90ffa529f5c99c44dc574c6f9a16"="7/13/2014 10:30 AM, 630176 bytes, A       Adds the file 661d2a49ae9c29fdbdb0e735f567c5cf"="7/13/2014 10:30 AM, 106 bytes, A       Adds the file 8d3f613ded3421026a6b47abd4042139"="7/13/2014 10:30 AM, 8 bytes, A       Adds the file b24f88eb229178ba93accf228dc5b280"="7/13/2014 10:30 AM, 70 bytes, A    Adds the folder C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SafetySearch       Adds the file SafetySearch Settings.url"="7/13/2014 10:30 AM, 123 bytes, A       Adds the file SafetySearch.lnk"="7/13/2014 10:30 AM, 1966 bytes, A       Adds the file Uninstall.lnk"="7/13/2014 10:30 AM, 1076 bytes, A    In the existing folder C:\Windows\System32\drivers\etc       Alters the file hosts        6/10/2009 11:39 PM, 824 bytes, A ==> 7/13/2014 10:30 AM, 872 bytes, A    In the existing folder C:\Windows\System32\Tasks       Adds the file bench-S-1-5-21-4016700205-1717049133-1125222536-1001"="7/13/2014 10:30 AM, 3234 bytes, A       Adds the file bench-sys"="7/13/2014 10:30 AM, 3242 bytes, A    In the existing folder C:\Windows\Tasks       Adds the file bench-S-1-5-21-4016700205-1717049133-1125222536-1001.job"="7/13/2014 10:30 AM, 346 bytes, A       Adds the file bench-sys.job"="7/13/2014 10:30 AM, 346 bytes, ARegistry details  ------------------------------------------    [HKEY_LOCAL_MACHINE\SOFTWARE]       "38989"="REG_SZ", "SafetySearch"    [HKEY_LOCAL_MACHINE\SOFTWARE\AdvertisingSupport]       "Existing"="REG_SZ", "0"       "Seen"="REG_SZ", "1"       "SeenDate"="REG_SZ", "1405240203"       "SystemId"="REG_SZ", "619bdd98c7140d14e62a62d4922b6abd"    [HKEY_LOCAL_MACHINE\SOFTWARE\Bench\BService]       "Path"="REG_SZ", "C:\Program Files\Bench\BService\1.1"       "Version"="REG_SZ", "1.1"    [HKEY_LOCAL_MACHINE\SOFTWARE\Bench\BService\38989]       "(Default)"="REG_SZ", ""    [HKEY_LOCAL_MACHINE\SOFTWARE\Bench\InstalledExtensions]       "38989"="REG_SZ", ""    [HKEY_LOCAL_MACHINE\SOFTWARE\Bench\NmHost]       "(Default)"="REG_SZ", "C:\Program Files\Bench\NmHost\nmhost.exe"    [HKEY_LOCAL_MACHINE\SOFTWARE\Bench\NmHost\38989]       "(Default)"="REG_SZ", ""    [HKEY_LOCAL_MACHINE\SOFTWARE\Bench\Updater]       "path"="REG_SZ", "C:\Program Files\Bench\Updater\updater.exe"    [HKEY_LOCAL_MACHINE\SOFTWARE\Bench\Updater\38989]       "(Default)"="REG_SZ", ""    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}]       "(Default)"="REG_SZ", "SafetySearch BHO"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}\Implemented Categories\{59FB2056-D625-48D0-A944-1A85B5AB2640}]    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}\InprocServer32]       "(Default)"="REG_SZ", "C:\Program Files\SafetySearch\FrameworkBHO.dll"       "ThreadingModel"="REG_SZ", "Apartment"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}\Programmable]    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}\TypeLib]       "(Default)"="REG_SZ", "{B5D3A0F0-0BFE-429A-A322-95F076081845}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}\Version]       "(Default)"="REG_SZ", "1.0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7782DBE4-75A1-453D-B9FD-643F752E4532}]       "(Default)"="REG_SZ", "SafetySearch"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7782DBE4-75A1-453D-B9FD-643F752E4532}\Implemented Categories\{59FB2056-D625-48D0-A944-1A85B5AB2640}]    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7782DBE4-75A1-453D-B9FD-643F752E4532}\InprocServer32]       "(Default)"="REG_SZ", "C:\Program Files\SafetySearch\FrameworkBHO.dll"       "ThreadingModel"="REG_SZ", "Apartment"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7782DBE4-75A1-453D-B9FD-643F752E4532}\Programmable]    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7782DBE4-75A1-453D-B9FD-643F752E4532}\TypeLib]       "(Default)"="REG_SZ", "{B5D3A0F0-0BFE-429A-A322-95F076081845}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7782DBE4-75A1-453D-B9FD-643F752E4532}\Version]       "(Default)"="REG_SZ", "1.0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92CECA0E-1DCB-4F42-BA4C-368094400351}]       "(Default)"="REG_SZ", "SafetySearch"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92CECA0E-1DCB-4F42-BA4C-368094400351}\LocalServer32]       "(Default)"="REG_SZ", ""C:\Program Files\SafetySearch\FrameworkEngine.exe""       "ServerExecutable"="REG_SZ", "C:\Program Files\SafetySearch\FrameworkEngine.exe"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92CECA0E-1DCB-4F42-BA4C-368094400351}\Programmable]    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92CECA0E-1DCB-4F42-BA4C-368094400351}\TypeLib]       "(Default)"="REG_SZ", "{13FFE26E-E2A4-4AC8-9E82-FFC1A3C3578A}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92CECA0E-1DCB-4F42-BA4C-368094400351}\Version]       "(Default)"="REG_SZ", "1.0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1EE70D1D-B150-4ACF-8498-4C5DE80CEAAC}]       "(Default)"="REG_SZ", "IKangoBHO"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1EE70D1D-B150-4ACF-8498-4C5DE80CEAAC}\ProxyStubClsid]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1EE70D1D-B150-4ACF-8498-4C5DE80CEAAC}\ProxyStubClsid32]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1EE70D1D-B150-4ACF-8498-4C5DE80CEAAC}\TypeLib]       "(Default)"="REG_SZ", "{B5D3A0F0-0BFE-429A-A322-95F076081845}"       "Version"="REG_SZ", "1.0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7720DB57-7561-457F-B689-D03FB72E3932}]       "(Default)"="REG_SZ", "IKangoToolbar"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7720DB57-7561-457F-B689-D03FB72E3932}\ProxyStubClsid]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7720DB57-7561-457F-B689-D03FB72E3932}\ProxyStubClsid32]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7720DB57-7561-457F-B689-D03FB72E3932}\TypeLib       "(Default)"="REG_SZ", "{B5D3A0F0-0BFE-429A-A322-95F076081845}"       "Version"="REG_SZ", "1.0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{92ADCA6E-1D8C-4F50-BEBF-1480FD408251}]       "(Default)"="REG_SZ", "IKangoEngine"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{92ADCA6E-1D8C-4F50-BEBF-1480FD408251}\ProxyStubClsid]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{92ADCA6E-1D8C-4F50-BEBF-1480FD408251}\ProxyStubClsid32]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{92ADCA6E-1D8C-4F50-BEBF-1480FD408251}\TypeLib]       "(Default)"="REG_SZ", "{13FFE26E-E2A4-4AC8-9E82-FFC1A3C3578A}"       "Version"="REG_SZ", "1.0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{13FFE26E-E2A4-4AC8-9E82-FFC1A3C3578A}\1.0]       "(Default)"="REG_SZ", "EngineLib"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{13FFE26E-E2A4-4AC8-9E82-FFC1A3C3578A}\1.0\0\win32]       "(Default)"="REG_SZ", "C:\Program Files\SafetySearch\FrameworkEngine.exe"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{13FFE26E-E2A4-4AC8-9E82-FFC1A3C3578A}\1.0\FLAGS]       "(Default)"="REG_SZ", "0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{13FFE26E-E2A4-4AC8-9E82-FFC1A3C3578A}\1.0\HELPDIR]       "(Default)"="REG_SZ", "C:\Program Files\SafetySearch"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{B5D3A0F0-0BFE-429A-A322-95F076081845}\1.0]       "(Default)"="REG_SZ", "Framework 1.0 Type Library"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{B5D3A0F0-0BFE-429A-A322-95F076081845}\1.0\0\win32]       "(Default)"="REG_SZ", "C:\Program Files\SafetySearch\FrameworkBHO.dll"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{B5D3A0F0-0BFE-429A-A322-95F076081845}\1.0\FLAGS]       "(Default)"="REG_SZ", "0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{B5D3A0F0-0BFE-429A-A322-95F076081845}\1.0\HELPDIR]       "(Default)"="REG_SZ", "C:\Program Files\SafetySearch"    [HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.bench.nmhost]       "(Default)"="REG_SZ", "C:\Program Files\Bench\NmHost\manifest.json"    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}]       "(Default)"="REG_SZ", "SafetySearch BHO"       "NoExplorer"="REG_DWORD", 1    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]       "Bench Communicator Watcher"="REG_SZ", "C:\Program Files\Bench\Proxy\pwdg.exe"       "Bench Settings Cleaner"="REG_SZ", "C:\Program Files\Bench\Proxy\cl.exe"       "BService"="REG_SZ", "C:\Program Files\Bench\BService\1.1\bservice.exe"       "Wd"="REG_SZ", "C:\Program Files\Bench\Wd\wd.exe"    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]       "SafetySearch"="REG_SZ", ""       "SafetySearch-repairJob"="REG_SZ", "wscript.exe "C:\Users\{username}\AppData\Local\SafetySearch\repair.js" "SafetySearch-repairJob""    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\38989_SafetySearch]       "DisplayIcon"="REG_SZ", "C:\Users\{username}\AppData\Local\SafetySearch/icon.ico"       "DisplayName"="REG_SZ", "SafetySearch"       "DisplayVersion"="REG_SZ", "1.0"       "InstallLocation"="REG_SZ", "C:\Users\{username}\AppData\Local\SafetySearch"       "NoModify"="REG_DWORD", 1       "NoRepair"="REG_DWORD", 1       "Publisher"="REG_SZ", "Exciting Apps"       "UninstallString"="REG_SZ", "C:\Users\{username}\AppData\Local\SafetySearch\uninstall.exe "    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist]       "1"="REG_SZ", "fjnoekdlmmjagmmlchagfonjgbioomoo;http://fjnoekdlmmjagmmlchagfonjgbioomoo/check/.eJwNyU0KgCAQQOG7zFqitl4mTEdT5wfUIojunsv3vReG6xUs-LMpIxi4sfWsMmlb1tlZ-nBE2MCOdqEBfMaew_yxiGINxFxcYiZ_uhRVSjqyKqvC9wPfWyFM.t27mdaCQFGhlnavJHDQywkB4OJ4"    [HKEY_LOCAL_MACHINE\SOFTWARE\Proxy]       "AutoConfigURL"="REG_SZ", ""       "ProxyEnable"="REG_DWORD", 0       "ProxyServer"="REG_SZ", ""    [HKEY_LOCAL_MACHINE\SOFTWARE\Proxy\Installations\SafetySearch]       "aoi"="REG_SZ", "1405247403"       "domain"="REG_SZ", "safetysearch-a.akamaihd.net"       "ext"="REG_SZ", "SafetySearch"       "format"="REG_SZ", "//{domain}/loaders/{pid}/l.js?pid={pid}&systemid={systemid}&ext={ext}&aoi={aoi}&zoneid={zoneid}&crr={crr}&type=p"       "pid"="REG_SZ", "2031"       "protect_redirect_url"="REG_SZ", "http://safetysearch.net/warning.php?%blocked_url%"       "settings_url"="REG_SZ", "http://safetysearch.net/settings.php"       "system_black_list_url"="REG_SZ", "http://safetysearch-a.akamaihd.net/protect/rules.json"       "zoneid"="REG_SZ", "622410"    [HKEY_LOCAL_MACHINE\SOFTWARE\SafetySearch]       "(Default)"="REG_SZ", "C:\Users\{username}\AppData\Local\SafetySearch"       "AllowProxy"="REG_SZ", "1"       "CDN"="REG_SZ", "safetysearch-a.akamaihd.net"       "InstallTime"="REG_SZ", "1405247403"       "Pid"="REG_SZ", "2031"       "Seen"="REG_SZ", "1"       "SeenDate"="REG_SZ", "1405240203"       "SystemId"="REG_SZ", "619bdd98c7140d14e62a62d4922b6abd"       "UTCInstallTime"="REG_SZ", "1405240203"       "ZoneId"="REG_SZ", "622410"    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}]       "Flags"="REG_DWORD", 1024       "VerCache"="REG_BINARY, ......................    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]       "ProxyEnable        REG_DWORD, 0 ==> REG_DWORD, 1       "ProxyServer"="REG_SZ", "http=127.0.0.1:3128"    [HKEY_CURRENT_USER\Software\Proxy\installations\SafetySearch]       "czoneid"="REG_SZ", "673316"
Malwarebytes Anti-Malware log:

Malwarebytes Anti-Malwarewww.malwarebytes.orgScan Date: 7/13/2014Scan Time: 10:39:35 AMLogfile: mbamSafetySearch.txtAdministrator: YesVersion: 2.00.2.1012Malware Database: v2014.07.13.01Rootkit Database: v2014.07.09.01License: FreeMalware Protection: DisabledMalicious Website Protection: DisabledSelf-protection: DisabledOS: Windows 7 Service Pack 1CPU: x86File System: NTFSUser: MalwarebytesScan Type: Threat ScanResult: CompletedObjects Scanned: 239831Time Elapsed: 2 min, 44 secMemory: EnabledStartup: EnabledFilesystem: EnabledArchives: EnabledRootkits: DisabledHeuristics: EnabledPUP: EnabledPUM: EnabledProcesses: 5PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\FrameworkEngine.exe, 8768, Delete-on-Reboot, [20e5c5dabac1a195d4bab404df23cc34]PUP.Optional.Bench.A, C:\Program Files\Bench\Wd\wd.exe, 9736, Delete-on-Reboot, [cf36d2cd88f357df7846d10832d029d7]PUP.Optional.Bench.A, C:\Program Files\Bench\Proxy\pwdg.exe, 9916, Delete-on-Reboot, [6e97623d81faab8bb79b9d2d39c99f61]PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bservice.exe, 9756, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d]PUP.Optional.Bench.A, C:\Program Files\Bench\Proxy\proc.exe, 9260, Delete-on-Reboot, [11f4dac502791b1b385d565554ae857b]Modules: 9PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bhelper.dll, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bhelper.dll, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bhelper.dll, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bhelper.dll, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bhelper.dll, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bhelper.dll, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bhelper.dll, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bhelper.dll, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bhelper.dll, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], Registry Keys: 33PUP.Optional.SafetySearch.A, HKLM\SOFTWARE\CLASSES\CLSID\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}, Quarantined, [cd38c3dc235854e2857078d88a786997], PUP.Optional.SafetySearch.A, HKLM\SOFTWARE\CLASSES\CLSID\{7782DBE4-75A1-453D-B9FD-643F752E4532}, Quarantined, [cd38c3dc235854e2857078d88a786997], PUP.Optional.SafetySearch.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{B5D3A0F0-0BFE-429A-A322-95F076081845}, Quarantined, [cd38c3dc235854e2857078d88a786997], PUP.Optional.SafetySearch.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{1EE70D1D-B150-4ACF-8498-4C5DE80CEAAC}, Quarantined, [cd38c3dc235854e2857078d88a786997], PUP.Optional.SafetySearch.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{7720DB57-7561-457F-B689-D03FB72E3932}, Quarantined, [cd38c3dc235854e2857078d88a786997], PUP.Optional.SafetySearch.A, HKLM\SOFTWARE\CLASSES\CLSID\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}\INPROCSERVER32, Quarantined, [cd38c3dc235854e2857078d88a786997], PUP.Optional.SafetySearch.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}, Quarantined, [cd38c3dc235854e2857078d88a786997], PUP.Optional.SafetySearch.A, HKU\S-1-5-21-4016700205-1717049133-1125222536-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}, Quarantined, [cd38c3dc235854e2857078d88a786997], PUP.Optional.SafetySearch.A, HKU\S-1-5-21-4016700205-1717049133-1125222536-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{1EDE0D83-B129-4ABC-923B-725D5B0C0DAC}, Quarantined, [cd38c3dc235854e2857078d88a786997], PUP.Optional.ExcitingApps.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\38989_SafetySearch, Quarantined, [13f22877601b93a350c99dfdb74ad030], PUP.Optional.SafetySearch.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{13FFE26E-E2A4-4AC8-9E82-FFC1A3C3578A}, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{92ADCA6E-1D8C-4F50-BEBF-1480FD408251}, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.Bench.A, HKLM\SOFTWARE\BENCH\BService, Quarantined, [28ddc6d95e1d9e98f42e6c597b8741bf], PUP.Optional.Bench.A, HKLM\SOFTWARE\BENCH\InstalledExtensions, Quarantined, [4fb627789cdf8da933f0f7ce17ebde22], PUP.Optional.Bench.A, HKLM\SOFTWARE\BENCH\NmHost, Quarantined, [c73ebfe0a4d743f3a57fa5200df5eb15], PUP.Optional.Bench.A, HKLM\SOFTWARE\BENCH\Updater, Quarantined, [699c8c1393e882b462c3d1f456ac966a], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\GLOBALUPDATE\UPDATE, Quarantined, [f1141b849fdc9e98706a6c4c17ebb64a], PUP.Optional.Bench.A, HKLM\SOFTWARE\GOOGLE\CHROME\NATIVEMESSAGINGHOSTS\com.bench.nmhost, Quarantined, [10f5c9d6b5c663d35bb442cdca3a16ea], PUP.Optional.SafetySearch.A, HKLM\SOFTWARE\PROXY\INSTALLATIONS\SafetySearch, Quarantined, [fc098b1490eb26100b816157cc363ac6], PUP.Optional.SafetySearch.A, HKU\S-1-5-21-4016700205-1717049133-1125222536-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\PROXY\INSTALLATIONS\SafetySearch, Quarantined, [5ca99f00710ac86e008dd9df8181d22e], PUP.Optional.GlobalUpdate.T, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\globalUpdate, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\globalUpdatem, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.OneClickCtrl.10, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.Update3WebControl.4, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], Registry Values: 7PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\GLOBALUPDATE\UPDATE|path, C:\Program Files\globalUpdate\Update\GoogleUpdate.exe, Quarantined, [f1141b849fdc9e98706a6c4c17ebb64a]PUP.Optional.Bench.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Wd, C:\Program Files\Bench\Wd\wd.exe, Quarantined, [cf36d2cd88f357df7846d10832d029d7]PUP.Optional.Bench.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Bench Communicator Watcher, C:\Program Files\Bench\Proxy\pwdg.exe, Quarantined, [6e97623d81faab8bb79b9d2d39c99f61]PUP.Optional.Bench.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Bench Settings Cleaner, C:\Program Files\Bench\Proxy\cl.exe, Quarantined, [ff06bde256250e28da793892837fae52]PUP.Optional.SmartApps, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE|SafetySearch-repairJob, wscript.exe "C:\Users\{username}\AppData\Local\SafetySearch\repair.js" "SafetySearch-repairJob", Quarantined, [c144613ecfac0036b51c61ae06fef40c]PUM.Bad.Proxy, HKU\S-1-5-21-4016700205-1717049133-1125222536-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|ProxyServer, http=127.0.0.1:3128, Quarantined, [dc29fca346358caa12c6b90a2cd628d8]PUP.Optional.Bench.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|BService, C:\Program Files\Bench\BService\1.1\bservice.exe, Quarantined, [f213efb03348e3538776851c9e64d32d]Registry Data: 0(No malicious items detected)Folders: 32PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch, Delete-on-Reboot, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\AppFramework, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\CanvasFramework, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\icons, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.BenchUpdater, C:\Program Files\Bench\NmHost, Quarantined, [50b5f9a67605d363a299459cb1516799], PUP.Optional.BenchUpdater, C:\Program Files\Bench\NmHost\data, Quarantined, [50b5f9a67605d363a299459cb1516799], PUP.Optional.BenchUpdater, C:\Program Files\Bench\NmHost\data\installer, Quarantined, [50b5f9a67605d363a299459cb1516799], PUP.Optional.BenchUpdater.A, C:\Users\{username}\AppData\Local\BenchUpdater, Quarantined, [df26cad5d4a7a294d27819c9c33fd32d], PUP.Optional.AdwarePlugin, C:\Program Files\Bench\Updater, Quarantined, [2fd659468eed1e1861b51e81ba481be5], PUP.Optional.AdwarePlugin, C:\Program Files\Bench\Updater\1.7.0.0, Quarantined, [2fd659468eed1e1861b51e81ba481be5], PUP.Optional.Bench.A, C:\Program Files\Bench\BService, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], PUP.Optional.Bench.A, C:\Program Files\Bench\Wd, Delete-on-Reboot, [2cd99a05ed8ea0966e90a8f93dc5af51], PUP.Optional.Bench.A, C:\Program Files\Bench\Proxy, Delete-on-Reboot, [11f4dac502791b1b385d565554ae857b], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Download, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Install, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Offline, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Offline\{9DB71709-E211-41A5-994F-F15E83C89F59}, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624, Quarantined, [44c1a9f605761026bf646a4ee81ac040], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch, Delete-on-Reboot, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\AppFramework, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\CanvasFramework, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\icons, Quarantined, [986d633cd8a373c3206996224eb4cb35], Files: 180PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\FrameworkBHO.dll, Quarantined, [cd38c3dc235854e2857078d88a786997], PUP.Optional.ExcitingApps.A, C:\Users\{username}\Desktop\SafetySearch_2606-d82f5459.exe, Quarantined, [8d78564932498aac6dac1486847db14f], PUP.Optional.InstallCore, C:\Users\{username}\Downloads\googleupdatersetup.exe, Quarantined, [8c7988170e6d81b5c4319cf3c63e8c74], PUP.Optional.ExcitingApps.A, C:\Users\{username}\AppData\Local\SafetySearch\uninstall.exe, Quarantined, [13f22877601b93a350c99dfdb74ad030], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\background.html, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\config.xml, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\extension_info.json, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\FrameworkBHO64.dll, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\FrameworkEngine.exe, Delete-on-Reboot, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\AppFramework\appAPI_bg.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\AppFramework\appAPI_browseraction.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\AppFramework\appAPI_common.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\AppFramework\appAPI_content.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\AppFramework\appAPI_settings.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\AppFramework\appAPI_webrequest.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\AppFramework\jquery.min.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\CanvasFramework\canvasscript_engine.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\CanvasFramework\canvas_bg.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\CanvasFramework\md5.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\CanvasFramework\registry.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\CanvasFramework\webrequest.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\backgroundscript_engine.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\base.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\browser.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\console.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\framework.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\global.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\i18n.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\initialize.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\invoke_async.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\io.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\json2.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\lang.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\legacy.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\message_target.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\messaging.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\storage.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\timer.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\updater.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\userscript_client.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\userscript_engine.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\utils.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework\xhr.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\browser_button.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\context_menu.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\context_menu_item_handler.html, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\framework_api.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\notification.html, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\notifications.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\options.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\ui_base.js, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\bottom-left.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\bottom-middle.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\bottom-right.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\middle-left.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\middle-right.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\tail-bottom.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\tail-left.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\tail-right.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\tail-top.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\top-left.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\top-middle.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\framework-ui\theme\bubble\top-right.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\icons\button.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\icons\icon100.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\icons\icon128.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\icons\icon32.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.SafetySearch.A, C:\Program Files\SafetySearch\icons\icon48.png, Quarantined, [20e5c5dabac1a195d4bab404df23cc34], PUP.Optional.BenchUpdater.A, C:\Windows\System32\Tasks\bench-S-1-5-21-4016700205-1717049133-1125222536-1001, Quarantined, [28ddb5ea37448aacd4bdefce6f936a96], PUP.Optional.BenchUpdater.A, C:\Windows\System32\Tasks\bench-sys, Quarantined, [c93c3b644d2e092d9af735881ae828d8], PUP.Optional.BenchUpdater, C:\Program Files\Bench\NmHost\nmhost.exe, Quarantined, [50b5f9a67605d363a299459cb1516799], PUP.Optional.BenchUpdater, C:\Program Files\Bench\NmHost\manifest.json, Quarantined, [50b5f9a67605d363a299459cb1516799], PUP.Optional.BenchUpdater, C:\Program Files\Bench\NmHost\data\installer\fjnoekdlmmjagmmlchagfonjgbioomoo, Quarantined, [50b5f9a67605d363a299459cb1516799], PUP.Optional.BenchUpdater.A, C:\Windows\Tasks\bench-S-1-5-21-4016700205-1717049133-1125222536-1001.job, Quarantined, [897c9708cfac7abce762558d34ce1fe1], PUP.Optional.BenchUpdater.A, C:\Windows\Tasks\bench-sys.job, Quarantined, [44c18a151e5d94a2ee5b02e0837fd62a], PUP.Optional.BenchUpdater.A, C:\Users\{username}\AppData\Local\BenchUpdater\products.xml, Quarantined, [df26cad5d4a7a294d27819c9c33fd32d], PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job, Quarantined, [ae57fda2f88301356f2c31e6739110f0], PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore, Quarantined, [fa0b7926daa160d6306c809747bda15f], PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job, Quarantined, [c441f1ae532837ffe4b9cc4be61ec040], PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA, Quarantined, [cf36b5ea512ab680ecb2f126ba4aad53], PUP.Optional.Bench.A, C:\Program Files\Bench\Wd\wd.exe, Delete-on-Reboot, [cf36d2cd88f357df7846d10832d029d7], PUP.Optional.Bench.A, C:\Program Files\Bench\Proxy\pwdg.exe, Delete-on-Reboot, [6e97623d81faab8bb79b9d2d39c99f61], PUP.Optional.Bench.A, C:\Program Files\Bench\Proxy\cl.exe, Quarantined, [ff06bde256250e28da793892837fae52], PUP.Optional.SmartApps, C:\Users\{username}\AppData\Local\SafetySearch\repair.js, Quarantined, [c144613ecfac0036b51c61ae06fef40c], PUP.Optional.AdwarePlugin, C:\Program Files\Bench\Updater\products.xml, Quarantined, [2fd659468eed1e1861b51e81ba481be5], PUP.Optional.AdwarePlugin, C:\Program Files\Bench\Updater\updater.exe, Quarantined, [2fd659468eed1e1861b51e81ba481be5], PUP.Optional.AdwarePlugin, C:\Program Files\Bench\Updater\1.7.0.0\updater.exe, Quarantined, [2fd659468eed1e1861b51e81ba481be5], PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bhelper.dll, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], PUP.Optional.Bench.A, C:\Program Files\Bench\BService\1.1\bservice.exe, Delete-on-Reboot, [f213efb03348e3538776851c9e64d32d], PUP.Optional.Bench.A, C:\Program Files\Bench\Proxy\icon.ico, Quarantined, [11f4dac502791b1b385d565554ae857b], PUP.Optional.Bench.A, C:\Program Files\Bench\Proxy\proc.exe, Delete-on-Reboot, [11f4dac502791b1b385d565554ae857b], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\GoogleUpdate.exe, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateHelper.msi, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\goopdate.dll, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\goopdateres_en.dll, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\psmachine.dll, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\psuser.dll, Quarantined, [8b7a445b9edd41f526e1e0d835cd40c0], PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624\GoogleCrashHandler.exe, Quarantined, [44c1a9f605761026bf646a4ee81ac040], PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624\GoogleUpdate.exe, Quarantined, [44c1a9f605761026bf646a4ee81ac040], PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624\GoogleUpdateBroker.exe, Quarantined, [44c1a9f605761026bf646a4ee81ac040], PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624\GoogleUpdateHelper.msi, Quarantined, [44c1a9f605761026bf646a4ee81ac040], PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624\GoogleUpdateOnDemand.exe, Quarantined, [44c1a9f605761026bf646a4ee81ac040], PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624\goopdate.dll, Quarantined, [44c1a9f605761026bf646a4ee81ac040], PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624\goopdateres_en.dll, Quarantined, [44c1a9f605761026bf646a4ee81ac040], PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624\npGoogleUpdate4.dll, Quarantined, [44c1a9f605761026bf646a4ee81ac040], PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624\psmachine.dll, Quarantined, [44c1a9f605761026bf646a4ee81ac040], PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.316624\psuser.dll, Quarantined, [44c1a9f605761026bf646a4ee81ac040], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\chrome_gp_update.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\chrome_installer.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\clear_cache.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\common.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox_installer.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\gpedit.exe, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\icon.ico, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\ie_installer.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\installer.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\main_installer.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\migrate.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\projectInstaller.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\repair_data.json, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\SoftwareDetector.exe, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\sqlite3.exe, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\storageedit.exe, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\background.html, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\bootstrap.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\chrome.manifest, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\extension_info.json, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\install.rdf, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\AppFramework\appAPI_bg.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\AppFramework\appAPI_browseraction.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\AppFramework\appAPI_common.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\AppFramework\appAPI_content.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\AppFramework\appAPI_settings.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\AppFramework\appAPI_webrequest.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\AppFramework\jquery.min.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\CanvasFramework\canvasscript_engine.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\CanvasFramework\canvas_bg.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\CanvasFramework\md5.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\CanvasFramework\registry.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\CanvasFramework\webrequest.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\backgroundscript_engine.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\base.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\browser.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\chrome_windows.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\console.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\content_proxy.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\framework.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\i18n.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\invoke_async.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\io.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\lang.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\legacy.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\message_target.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\messaging.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\storage.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\timer.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\uninstall.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\userscript_client.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\userscript_engine.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\utils.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework\xhr.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui\browser_button.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui\contentNotification.tmpl, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui\contentNotificationStyle.tmpl, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui\content_notifications.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui\context_menu.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui\framework_api.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui\notifications.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui\options.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\framework-ui\ui_base.js, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\icons\button.png, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\icons\icon100.png, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\icons\icon128.png, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\icons\icon32.png, Quarantined, [986d633cd8a373c3206996224eb4cb35], PUP.Optional.SafetySearch.A, C:\Users\{username}\AppData\Local\SafetySearch\firefox\icons\icon48.png, Quarantined, [986d633cd8a373c3206996224eb4cb35], Physical Sectors: 0(No malicious items detected)(end)
As mentioned before the full version of Malwarebytes Anti-Malware could have protected your computer against this threat.

We use different ways of protecting your computer(s):

  • Dynamically Blocks Malware Sites & Servers
  • Malware Execution Prevention
Save yourself the hassle and get protected.
Link to post
Share on other sites

 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.