Adware

Adware.BrowseFox.317 (B) removal guide

Malware Removal

The Adware.BrowseFox.317 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.BrowseFox.317 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Collects and encrypts information about the computer likely to send to C2 server

How to determine Adware.BrowseFox.317 (B)?


File Info:

name: C0FB2FA3ACFB5EC44DE8.mlw
path: /opt/CAPEv2/storage/binaries/2ae74684f6d602d74e4ebba21ae56d63bf089193510762e898a174d4a32f3a29
crc32: A6684FD4
md5: c0fb2fa3acfb5ec44de87593ec91f8ff
sha1: 0897ba77861e95aeefac1ba268b5fb3e16c3a666
sha256: 2ae74684f6d602d74e4ebba21ae56d63bf089193510762e898a174d4a32f3a29
sha512: e6fb0e4e50cc87dac8853e28f0356230b3f8761b2db154bb985a18bfdf153dc54947601a55658ee196f7ba065faa5a50cf3354c7a70369863a138d73f0834af0
ssdeep: 49152:i3tUIGYnJ61iGbOVIzGbe/FZb//GGMzwPdHC1s2vHaffZnLyH/G1Tff5+5:EtU5EJ+iiOeCbe/7GVkF3ffJLyH/x5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T183063902938C5BADF26220B6D0A87D3718E41D39134F48FBC3C69DD79590AD066B9F9B
sha3_384: c755b3d7e0c08434645baa9a827ba613836849868a5ea24a2bd2ecdab4b45f2727973af4c34fc1a64ee66344e149f6dc
ep_bytes: e811230100e97ffeffff558bec568b75
timestamp: 2022-02-01 15:36:57

Version Info:

FileVersion: 1.0.8067.13701
ProductVersion: 1.0.8067.13701
Translation: 0x0409 0x04b0

Adware.BrowseFox.317 (B) also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Adware.BrowseFox.317
FireEyeGeneric.mg.c0fb2fa3acfb5ec4
ALYacGen:Variant.Adware.BrowseFox.317
CylanceUnsafe
SangforRansom.Win32.Gandcrab_60.se2
K7AntiVirusAdware ( 00543fd21 )
AlibabaAdWare:Win32/BrowseFox.d6c3f55e
K7GWAdware ( 00543fd21 )
Cybereasonmalicious.3acfb5
BitDefenderThetaGen:NN.ZexaF.34212.Hx1@amluwNni
CyrenW32/S-21e2153e!Eldorado
SymantecPUA.Yontoo
ESET-NOD32a variant of Win32/Adware.BrowseFox.BZ
TrendMicro-HouseCallTROJ_GEN.R002C0PB422
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderGen:Variant.Adware.BrowseFox.317
AvastWin32:AdwareX-gen [Adw]
TencentAdware.Win32.Browsefox.c
Ad-AwareGen:Variant.Adware.BrowseFox.317
EmsisoftGen:Variant.Adware.BrowseFox.317 (B)
TrendMicroTROJ_GEN.R002C0PB422
McAfee-GW-EditionBehavesLike.Win32.BrowseFox.wh
SophosGeneric PUA AI (PUA)
IkarusTrojan.Dropper
GDataGen:Variant.Adware.BrowseFox.317
AviraADWARE/BrowseFox.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3522E01
ArcabitTrojan.Adware.BrowseFox.317
ViRobotAdware.Browsefox.3686428.C
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.BrowseFox.R216431
Acronissuspicious
McAfeePUP-XDW-LI
MAXmalware (ai score=66)
VBA32BScope.Adware.Foxiebro
MalwarebytesAdware.Yontoo
APEXMalicious
RisingPUF.BrowseFox!8.82 (CLOUD)
YandexTrojan.GenAsa!bO40VYgZFQQ
SentinelOneStatic AI – Malicious PE
FortinetAdware/BrowseFox
AVGWin32:AdwareX-gen [Adw]
PandaTrj/Genetic.gen
CrowdStrikewin/grayware_confidence_90% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Adware.BrowseFox.317 (B)?

Adware.BrowseFox.317 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment