Adware

Win32/Adware.BrowseFox.DC removal

Malware Removal

The Win32/Adware.BrowseFox.DC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.BrowseFox.DC virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Scheduled file move on reboot detected
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Steals private information from local Internet browsers
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Anomalous binary characteristics

How to determine Win32/Adware.BrowseFox.DC?


File Info:

name: D3D0CDA7C213CF677D4D.mlw
path: /opt/CAPEv2/storage/binaries/cd2592c66fdbfa84ca4918502d10e5819827edab5f60fb91eff4f952dfa8d199
crc32: B7A52330
md5: d3d0cda7c213cf677d4decaa6dae906b
sha1: cc0d3f98b71abd3efec76ed2c82bd839ce874dc8
sha256: cd2592c66fdbfa84ca4918502d10e5819827edab5f60fb91eff4f952dfa8d199
sha512: 7fe5ccf7d772332529ab621da6a17cfb59a6e4eb7f9e68ce705d319b49e85f3e94e50b15d6e3e620d71a390a522fac1be14d852e80cc8c6c262a08f2b503e7a8
ssdeep: 3072:fLk395hYXJ3HDoMn3FkS9XPcCZT9anH7l1m/GqMHJGUL8jML:fQqJHsa3FkGPPhYnH7nm/G/Hc6L
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B62412522BF0E43BD0A7A3B03953EF15D37A93869399C79F73550E7AE52408397212A3
sha3_384: 073ec090c1ef557747c534732a9cda64d52938f1ff12dcdab03c8b1d672d728c6fe06a16bb7c3a9e571aad1e0aa0abf6
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:41

Version Info:

0: [No Data]

Win32/Adware.BrowseFox.DC also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.Siggen6.31097
CAT-QuickHealPua.Browsefox.S2540
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusRiskware ( 0040eff71 )
AlibabaAdWare:Win32/Kranet.5865fce7
K7GWRiskware ( 0040eff71 )
ESET-NOD32Win32/Adware.BrowseFox.DC
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:AdWare.Win32.Kranet.gen
NANO-AntivirusTrojan.Win32.TrjGen.droatj
SUPERAntiSpywareTrojan.Agent/Gen-Agent
AvastNSIS:BrowseFox-E [PUP]
RisingTrojan.Generic@ML.87 (RDMK:4tAbcjiNsoMqmK02s2wT+Q)
SophosGeneric ML PUA (PUA)
ComodoApplication.Win32.BrowseFox.I@73k5u2
F-SecureAdware.ADWARE/BrowseFox.Gen7
TrendMicroPUA_BROWSEFOX.SMC
McAfee-GW-EditionBehavesLike.Win32.Dropper.dc
EmsisoftApplication.BrowserExt (A)
GDataWin32.Adware.Kranet.A
JiangminAdWare.Kranet.ur
AviraTR/BrowserFox.A
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftBrowserModifier:Win32/Foxiebro
CynetMalicious (score: 99)
McAfeeGeneric PUP.jv
VBA32Adware.Kranet
MalwarebytesPUP.Optional.BrowseFox
TrendMicro-HouseCallPUA_BROWSEFOX.SMC
TencentTrojan.Win32.BitCoinMiner.la
YandexRiskware.Agent!vSpgaMcIb0s
SentinelOneStatic AI – Suspicious PE
FortinetAdware/Kranet
AVGNSIS:BrowseFox-E [PUP]
PandaPUP/BrowserFox
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Adware.BrowseFox.DC?

Win32/Adware.BrowseFox.DC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment