Home Malware Programs Adware BrowseFox

BrowseFox

Posted: August 28, 2013

Threat Metric

Ranking: 8,981
Threat Level: 2/10
Infected PCs: 6,256
First Seen: August 28, 2013
Last Seen: October 4, 2023
OS(es) Affected: Windows

BrowseFox Screenshot 1BrowseFox is a Potentially Unwanted Program and adware that modifies your browser to display advertisements. Most installations of BrowseFox occur without the PC user's consent using a variety of methods, such as browser redirects to unsafe Web pages hosting drive-by-downloads. Like any typical adware program, BrowseFox's advertisements usually are not unsafe but include the possibility of harmful Web content like phishing attacks, and SpywareRemove.com malware researchers consider removing BrowseFox to be a basic point of Web browser security. Since its installation usually takes place without your permission, deleting BrowseFox, likewise, is a process that shouldn't require BrowseFox's permission, although anti-malware programs usually will be required.

BrowseFox: Mutating Firefox into an Advertising-Fox

BrowseFox is an adware program that, so far, appears to be specific to Mozilla's Firefox browser (although BrowseFox is not affiliated with that company). Although BrowseFox lacks a distinctive Web presence or even a functional website, as far as malware experts can determine, BrowseFox does have something of a history online for its delivery of advertisements. BrowseFox advertisements are not certain to be harmful to your computer but sometimes may include potentially harmful content, of which the following should be considered particularly probable:

  • BrowseFox may alter Web pages by injecting advertising content, including text links or insterstitials.
  • BrowseFox may trigger pop-up windows arbitrarily.
  • BrowseFox may redirect you from one website to an unrelated one.
  • Lastly, homepage and search engine settings may be hijacked, forcing your searches and default homepage to load sites of BrowseFox's specifications.

Browsing Your Way Out of a BrowseFox Infection

Because BrowseFox's installation is non-consensual and usually may make browser changes that are difficult to reverse, SpywareRemove.com malware research team recommends anti-malware programs for deleting BrowseFox as a matter of course – or, if possible, blocking BrowseFox's installation in the first place. As noted before, BrowseFox usually is only a security issue for users of Firefox, but very similar adware programs have been spotted for almost every browser for all major operating systems. Active anti-malware protection for your browser and basic Web-safety habits that keep your browser from loading threatening sites both are necessary for feminizing any unnecessary contact with BrowseFox-related infection vectors.

Some installation methods for BrowseFox infections also abuse secondary PC threats, such as browser hijackers that perform automatic redirects from popular media sites like YouTube. These PC threats also should be exterminated ASAP, particularly since they have the possibility to assist with the installation of threats more troubling than BrowseFox.
Depending on the type of anti-malware product used to detect BrowseFox, BrowseFox may be identified as adware or a Potentially Unwanted Program (PUP). The exact name used to detect BrowseFox does not affect its functions, which always lack any advantages for your browser and should be considered tantamount to attacks against your PC.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES(x86)%\Web Layers\WebLayersopc.exe File name: WebLayersopc.exe
Size: 222.2 KB (222208 bytes)
MD5: 6a8a8679f958cf62a3747bffb125e51c
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Web Layers
Group: Malware file
Last Updated: January 13, 2014
C:\Users\<username>\AppData\Local\Temp\9r0pN\xrc.exe File name: xrc.exe
Size: 50.68 KB (50688 bytes)
MD5: 2329102649753d1de56f6a3dde275ef2
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\9r0pN\xrc.exe
Group: Malware file
Last Updated: February 18, 2021
%PROGRAMFILES(x86)%\Web Layers\opc.exe File name: opc.exe
Size: 222.2 KB (222208 bytes)
MD5: 623578b48b26768f0af4e1c8e9acaefd
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Web Layers
Group: Malware file
Last Updated: January 13, 2014

Registry Modifications

The following newly produced Registry Values are:

CLSID{006232F7-DBD6-4631-84E8-66EA161B43C4}{b9507101-e464-4b3b-a4cb-291aaedd94f2}{BB9817CA-9B43-41EB-8706-44847957338D}Regexp file mask%WINDIR%\System32\Tasks\Clusckghapele MonitorHKEY..\..\..\..{RegistryKeys}Software\BrowseFoxSOFTWARE\Microsoft\Tracing\updateBrowseFox_RASAPI32SOFTWARE\Microsoft\Tracing\updateBrowseFox_RASMANCSSOFTWARE\Microsoft\Tracing\utilbrowsefox_RASAPI32SOFTWARE\Microsoft\Tracing\utilbrowsefox_RASMANCSSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Clusckghapele MonitorSOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{b9507101-e464-4b3b-a4cb-291aaedd94f2}SOFTWARE\Wow6432Node\browsefoxSOFTWARE\Wow6432Node\Microsoft\Tracing\updateBrowseFox_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updateBrowseFox_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\utilbrowsefox_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\utilbrowsefox_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{b9507101-e464-4b3b-a4cb-291aaedd94f2}SYSTEM\ControlSet001\services\clsmntServiceSYSTEM\ControlSet001\services\eventlog\Application\Update BrowseFoxSYSTEM\ControlSet001\services\eventlog\Application\Util browsefoxSYSTEM\ControlSet001\services\Update BrowseFoxSYSTEM\ControlSet002\services\clsmntServiceSYSTEM\ControlSet002\services\eventlog\Application\Update BrowseFoxSYSTEM\ControlSet002\services\eventlog\Application\Util browsefoxSYSTEM\ControlSet002\services\Update BrowseFoxSYSTEM\CurrentControlSet\services\clsmntServiceSYSTEM\CurrentControlSet\services\eventlog\Application\Util browsefoxSYSTEM\CurrentControlSet\services\Update BrowseFoxHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}BrowseFox

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\2e372a36-cec5-4b4a-9817-c305662b61d6%ALLUSERSPROFILE%\3c022f79-33eb-49e6-81b8-ddaa369645b1%ALLUSERSPROFILE%\Application Data\a96ed9e8-b4db-48e1-82c2-51a1109acc39%ALLUSERSPROFILE%\a96ed9e8-b4db-48e1-82c2-51a1109acc39%APPDATA%\BrowseFox%COMMONPROGRAMFILES%\3c022f79-33eb-49e6-81b8-ddaa369645b1%COMMONPROGRAMFILES%\a96ed9e8-b4db-48e1-82c2-51a1109acc39%COMMONPROGRAMFILES(x86)%\3c022f79-33eb-49e6-81b8-ddaa369645b1%COMMONPROGRAMFILES(x86)%\a96ed9e8-b4db-48e1-82c2-51a1109acc39%ProgramFiles%\BrowseFox%ProgramFiles%\Clusckghapele%ProgramFiles(x86)%\BrowseFox%ProgramFiles(x86)%\Clusckghapele
The following URL's were detected:
BrowseFoxUpdatequalitink.exe

Related Posts

Loading...