Safe Finder
Posted: August 4, 2015
Threat Metric
The following fields listed on the Threat Meter containing a specific value, are explained in detail below:
Threat Level: The threat level scale goes from 1 to 10 where 10 is the highest level of severity and 1 is the lowest level of severity. Each specific level is relative to the threat's consistent assessed behaviors collected from SpyHunter's risk assessment model.
Detection Count: The collective number of confirmed and suspected cases of a particular malware threat. The detection count is calculated from infected PCs retrieved from diagnostic and scan log reports generated by SpyHunter.
Volume Count: Similar to the detection count, the Volume Count is specifically based on the number of confirmed and suspected threats infecting systems on a daily basis. High volume counts usually represent a popular threat but may or may not have infected a large number of systems. High detection count threats could lay dormant and have a low volume count. Criteria for Volume Count is relative to a daily detection count.
Trend Path: The Trend Path, utilizing an up arrow, down arrow or equal symbol, represents the level of recent movement of a particular threat. Up arrows represent an increase, down arrows represent a decline and the equal symbol represent no change to a threat's recent movement.
% Impact (Last 7 Days): This demonstrates a 7-day period change in the frequency of a malware threat infecting PCs. The percentage impact correlates directly to the current Trend Path to determine a rise or decline in the percentage.
Ranking: | 1,801 |
---|---|
Threat Level: | 5/10 |
Infected PCs: | 1,211,500 |
First Seen: | August 8, 2014 |
---|---|
Last Seen: | October 16, 2023 |
OS(es) Affected: | Windows |
Safe Finder is a Potentially Unwanted Program that provides various in-browser features, but also may redirect your browser to unwanted sites. Along with its browser hijacking traits, Safe Finder also may be installed automatically, and may exploit formats that may make its deletion unnecessarily difficult. Standard PC security solutions should be capable of removing Safe Finder while scanning your computer, after which malware analysts advise resetting all browser settings back to their original, safe values.
The Risks of Finding Your Search Results with Safe Finder
Safe Finder's website claims to provide Web-simplifying features that allow you to find and access desirable sites more safely than normal, but, like similar browser add-ons, offers drawbacks in equal measure with its benefits. In addition to all of its marketed features, Safe Finder also may lock your default browser to a sub-domain of its personal website (frequently its Yahoo Search-based search engine). These functions have been confirmed for Chrome and most other Windows browsers, although other OSes may or may not be similarly compatible with Safe Finder's changes.
At this time, malware analysts found no indications of Safe Finder using its website to promote harmful content, including online hoaxes or threat-related attacks. However, Safe Finder does reset your browser's settings even after any attempts to reset them are made, preventing PC owners from reversing its browser hijacking 'feature.' Some versions of Safe Finder also may install themselves without all appropriate, visible extension entries allowing for their easy deletion. These characteristics are equally common in threatening software, although, for now, Safe Finder remains classified as a PUP (Potentially Unwanted Program).
Finding Your Way to a Browser Unaltered by Safe Finder
While Safe Finder may use its search features to deliver advertising links or other, affiliated content, having your browser hijacked by Safe Finder isn't equivalent to being redirected towards a threatening website. In spite of that, malware analysts never find any security or accessibility advantages from allowing an external program to control your Web browsing settings. Such applications should be uninstalled for your browser's safety, with any hijacked settings reverted after the uninstall process is finished. Web surfers should note that deleting the affected Web browser may avoid the symptoms of a Safe Finder installation, such as search redirects, but will not remove the actual extension from your PC.
While you may find Safe Finder on its website, most PC users are likely to install Safe Finder unintentionally through its bundling with another application. Free installers distributed at general download sites, along with piracy-oriented networks, are two of the most common, non-consensual distribution tactics used by browser hijackers and other PUPs. You can scan downloads that could be carrying installers with unwanted add-ons for the presence of well-known threats, such as bundle installation platforms. In some situations, they also may give you the opportunity to decline any installation 'extras' like Safe Finder.
Aliases
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
The following files were created in the system:C:\Program Files\ProductUI\Startup.exe
File name: Startup.exeSize: 177.66 KB (177664 bytes)
MD5: a104635bb5e26259a8847c1f5e224b60
Detection count: 8,764
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files\ProductUI\Startup.exe
Group: Malware file
Last Updated: June 18, 2022
C:\Program Files (x86)\ProductUI\Startup.exe
File name: Startup.exeSize: 169.47 KB (169472 bytes)
MD5: c4b90082814700cc47783f1843ffd5df
Detection count: 6,595
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\ProductUI\Startup.exe
Group: Malware file
Last Updated: November 4, 2021
c:\Users\<username>\appdata\local\rgmservice\rgmupdater.exe
File name: rgmupdater.exeSize: 85.5 KB (85504 bytes)
MD5: c069c1bd3b37556cda040807f416aa4f
Detection count: 3,120
File type: Executable File
Mime Type: unknown/exe
Path: c:\Users\<username>\appdata\local\rgmservice\rgmupdater.exe
Group: Malware file
Last Updated: January 10, 2023
%SYSTEMDRIVE%\Users\<username>\Desktop\_MEGA\51d2eb7c4d53caea2a1ad30f154dad582c4c17b3b1f044b562d171a0cb4c99d8.exe
File name: 51d2eb7c4d53caea2a1ad30f154dad582c4c17b3b1f044b562d171a0cb4c99d8.exeSize: 49.85 KB (49859 bytes)
MD5: 13d4ee06fe8476e0464a3602ec01f5f9
Detection count: 1,672
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\Desktop\_MEGA\51d2eb7c4d53caea2a1ad30f154dad582c4c17b3b1f044b562d171a0cb4c99d8.exe
Group: Malware file
Last Updated: September 4, 2023
%PROGRAMFILES(x86)%\ProductUI\Startup.exe
File name: Startup.exeSize: 169.47 KB (169472 bytes)
MD5: 85084201ba44f6907a2f6272eeb0a4aa
Detection count: 656
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\ProductUI
Group: Malware file
Last Updated: March 23, 2016
%LOCALAPPDATA%\Smartbar\Application\SafeFinder.exe
File name: SafeFinder.exeSize: 27.43 KB (27432 bytes)
MD5: ae11f4b5cd3196cfafb8febecdac4618
Detection count: 316
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\Smartbar\Application
Group: Malware file
Last Updated: October 1, 2020
%SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Program Files (x86)\ProductUI\Startup.exe.vir
File name: Startup.exe.virSize: 78.84 KB (78848 bytes)
MD5: 505f414ea2c85f39c3b8a260a2556099
Detection count: 138
Mime Type: unknown/vir
Path: %SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Program Files (x86)\ProductUI\Startup.exe.vir
Group: Malware file
Last Updated: May 2, 2023
%PROGRAMFILES(x86)%\ProductUI\Startup.exe
File name: Startup.exeSize: 20.48 KB (20480 bytes)
MD5: 31e064c4cbf59d02c8fb58f07ec6a88e
Detection count: 124
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\ProductUI\Startup.exe
Group: Malware file
Last Updated: August 13, 2022
%LOCALAPPDATA%\Smartbar\Application\SafeFinder.exe
File name: SafeFinder.exeSize: 20.76 KB (20760 bytes)
MD5: 0f19c3851ad1171b4b201510ebaaa319
Detection count: 93
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\Smartbar\Application
Group: Malware file
Last Updated: August 8, 2014
%PROGRAMFILES%\ProductUI\Startup.exe
File name: Startup.exeSize: 205.31 KB (205312 bytes)
MD5: 4362dc4194a1b9b9de2881f568abc312
Detection count: 46
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\ProductUI
Group: Malware file
Last Updated: March 23, 2016
%LOCALAPPDATA%\Smartbar\Application\SafeFinder.exe
File name: SafeFinder.exeSize: 28.95 KB (28952 bytes)
MD5: 1c43e26d63c4c7f7e5728181d5c3a09a
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\Smartbar\Application
Group: Malware file
Last Updated: August 8, 2014
%LOCALAPPDATA%\Smartbar\Application\SafeFinder.exe
File name: SafeFinder.exeSize: 28.95 KB (28952 bytes)
MD5: 5e94dfe7de36e4de80f759ed1405063f
Detection count: 10
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\Smartbar\Application
Group: Malware file
Last Updated: August 8, 2014
C:\Users\<username>\appdata\Local\smartbar\application\browserhelper.exe
File name: C:\Users\<username>\appdata\Local\smartbar\application\browserhelper.exeMD5: c5768f028a5521c1ee77ffef812d1022
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Registry Modifications
CLSID{9EB324CA-1466-4907-8392-92C9F653A229}{EDF23B0E-D735-3964-B81F-0BF003A3EC3B}File name without pathhttp_search.cubokit.com_0.localstoragehttp_search.cubokit.com_0.localstorage-journalhttp_search.safefinder.com_0.localstoragehttp_search.safefinder.com_0.localstorage-journalsearch.safefinder[1].xmlRegexp file mask%LOCALAPPDATA%\Stocktouch.exeHKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{9EB324CA-1466-4907-8392-92C9F653A229}Software\Microsoft\Internet Explorer\DOMStorage\safefinder.comSoftware\Microsoft\Internet Explorer\DOMStorage\search.safefinder.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\safefinder.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\search.safefinder.comSoftware\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\SafeFinder.exeSOFTWARE\Microsoft\Internet Explorer\Toolbar\{9eb324ca-1466-4907-8392-92c9f653a229}SOFTWARE\Microsoft\Tracing\Hayzumflex_RASAPI32SOFTWARE\Microsoft\Tracing\Hayzumflex_RASMANCSSOFTWARE\Microsoft\Tracing\Quoteex_RASAPI32SOFTWARE\Microsoft\Tracing\Quoteex_RASMANCSSOFTWARE\Microsoft\Tracing\SafeFinder_RASAPI32SOFTWARE\Microsoft\Tracing\SafeFinder_RASMANCSSOFTWARE\Microsoft\Tracing\UltimateSecurityPackage_RASAPI32SOFTWARE\Microsoft\Tracing\UltimateSecurityPackage_RASMANCSSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SafeFinder.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UltimateSecurityPackage.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Hayzumflex.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Quoteex.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\UltimateSecurityPackage.exeSOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\HayzumflexUSOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Stpro.exeSOFTWARE\mtHayzumflexSoftware\mtSafeFinderSOFTWARE\mtUltimateSecurityPackageSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{9eb324ca-1466-4907-8392-92c9f653a229}SOFTWARE\WOW6432Node\Microsoft\Tracing\Hayzumflex_RASAPI32SOFTWARE\WOW6432Node\Microsoft\Tracing\Hayzumflex_RASMANCSSOFTWARE\WOW6432Node\Microsoft\Tracing\Quoteex_RASAPI32SOFTWARE\WOW6432Node\Microsoft\Tracing\Quoteex_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\SafeFinder_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\SafeFinder_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\UltimateSecurityPackage_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\UltimateSecurityPackage_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SafeFinder.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UltimateSecurityPackage.exeSOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Hayzumflex.exeSOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Quoteex.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\UltimateSecurityPackage.exeSOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\HayzumflexUSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\Stpro.exeSOFTWARE\WOW6432Node\mtHayzumflexSOFTWARE\Wow6432Node\mtUltimateSecurityPackageSYSTEM\ControlSet001\services\HayzumflexSYSTEM\ControlSet002\services\HayzumflexSYSTEM\CurrentControlSet\services\HayzumflexHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{B685D7F1-BAC8-4318-8137-A774268BBD39}{UltimateSecurityPackage}
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.