Home Possibly Unwanted Program Crxbro Browser

Crxbro Browser

Posted: January 12, 2016

Threat Metric

Ranking: 10,481
Threat Level: 1/10
Infected PCs: 11,689
First Seen: January 12, 2016
Last Seen: October 10, 2023
OS(es) Affected: Windows


The Crxbro Browser is a Potentially Unwanted Program (PUP) that may duplicate the features and utility of the Google's Chrome browser, but may include additional, unwanted functions. Because of the invasive installation methods promoting this browser, malware experts advise uninstalling the Crxbro Browser and taking steps for protecting any sensitive browser-transferred data, such as passwords. PC users attentive to their default browser's behavior should be able to identify a Crxbro Browser issue from its symptoms, alone.

A New Generation of Chrome Installing Itself

While Chrome is a major platform for the developers of adware and questionable extensions, these software developer teams restrict themselves to 'improving' an already-installed browser. In the Crxbro Browser campaign, malware researchers have seen a clear case of software developers taking a more invasive route by replacing the user's browser in its entirety. The Crxbro Browser merely is a recompiled version of Chrome and includes no user-beneficial features not found in that browser, albeit potentially with additional functions not yet identified.

This campaign began showing clear evidence of activity in the last month of 2015, before which malware researchers saw no signs of the Crxbro Browser installing itself through unorthodox methods. In December, Chrome users reported of experiencing the Crxbro Browser installing itself automatically, replacing Chrome's default associations and shortcuts. All known targeted users also report of Chrome crashing during the process, which could indicate that a drive-by-download is transferring itself through a hijacked update or a compromised website. There are no identified links between these unwanted Crxbro Browser installations and consensual downloads, including plugins or extensions.

Besides the obvious swapping of browser names, computer users also can identify this threat from the change in their default homepage, which sets itself to a Google login page. This default setting could be an attempt by the Crxbro Browser's maintainers to phish for login details, such as passwords. Alternately, the Crxbro Browser may be being used as an advertisement-based revenue source by providing sponsored content automatically.

Getting Back to the Shine of the Chrome You Chose

Although the Crxbro Browser outwardly is identical to a standard Chrome installation, its delivery method leaves little doubt that its maintainers are unlikely to have their users' best interests at heart. However, malware experts currently have found too limited evidence for placing the Crxbro Browser in the same category as threatening software, such as spyware and Trojans. For the time being, the Crxbro Browser is classified as a Potentially Unwanted Program or a PUP.

Even PUPs with no intentionally harmful features may be net security drawbacks, and you never should tolerate any software that makes automatic, invasive system changes. PC users needing to remove a Crxbro Browser should scan their machines with appropriate security utilities from Safe Mode, which will potentially prevent interfering processes from running. They also should stay aware of the likelihood of the Crxbro Browser installing itself along with other PUPs, such as WinZipper.

Although there is no clear evidence outlining the Crxbro Browser's current distribution methods, current sources point to Chinese developers being responsible for this campaign.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



c:\program files (x86)\crxbro browser\crxbro\bin\browserserver.exe File name: browserserver.exe
Size: 505.98 KB (505984 bytes)
MD5: b9f9043d9dde41923c0aa466a88be1f1
Detection count: 4,178
File type: Executable File
Mime Type: unknown/exe
Path: c:\program files (x86)\crxbro browser\crxbro\bin\browserserver.exe
Group: Malware file
Last Updated: May 29, 2023
C:\Program Files (x86)\crxbro Browser\crxbro\chrome.exe File name: chrome.exe
Size: 872.57 KB (872576 bytes)
MD5: 7b15e5a164c79d114c648c185dad63ff
Detection count: 3,574
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\crxbro Browser\crxbro\chrome.exe
Group: Malware file
Last Updated: May 29, 2023
C:\Program Files (x86)\crxbro Browser\47.5.2526.80.updated197799595\bin197799158\browserServer.exe197799143 File name: browserServer.exe197799143
Size: 470.4 KB (470400 bytes)
MD5: b8fdb35c45a5fca1754a3ffff496b345
Detection count: 126
Mime Type: unknown/exe197799143
Path: C:\Program Files (x86)\crxbro Browser\47.5.2526.80.updated197799595\bin197799158\browserServer.exe197799143
Group: Malware file
Last Updated: November 27, 2021
%PROGRAMFILES(x86)%\crxbro Browser\crxbro\bin\browserServer.exe File name: browserServer.exe
Size: 468.78 KB (468784 bytes)
MD5: 56fb107967e66a0b17fa726103fa3e84
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\crxbro Browser\crxbro\bin
Group: Malware file
Last Updated: November 18, 2019

Additional Information

The following directories were created:
%LOCALAPPDATA%\crxbro%PROGRAMFILES%\crxbro Browser%PROGRAMFILES(x86)%\crxbro Browser%PUBLIC%\Documents\crxbro%UserProfile%\Local Settings\Application Data\crxbro
Loading...