Home Malware Programs Adware Browser Warden

Browser Warden

Posted: July 17, 2014

Threat Metric

Ranking: 16,439
Threat Level: 2/10
Infected PCs: 2,668
First Seen: July 17, 2014
Last Seen: January 3, 2025
OS(es) Affected: Windows


BrowserWarden markets itself as a website blocker, but also may include numerous functions more appropriate to adware than to a security product. Its information monitoring and advertising features may harm your browser's performance, and all adware programs of a similar nature may run the risk of unintentionally loading content that could harm your PC, such as vulnerability-exploiting scripts. When experiencing any problems with this software, most PC users should consider removing BrowserWarden with good anti-adware applications.

BrowserWarden and a Web Browser Imprisoned with Advertisements

BrowserWarden is a 2014 adware product developed, in theory, to block known hostile websites from loading into your browser. Along with this legitimately beneficial function, BrowserWarden also may finance itself by collecting data about its users and displaying advertisements. BrowserWarden advertisements are designed to include:

  • Shopping 'coupons' for popular e-retailers.
  • Website links inserted into contextual text.
  • Pop-ups.
  • Banners injected into unrelated sites.
  • Interstitial advertisements – or full-page advertisements that load before your intended Web destination.
  • Additional, sponsored search results.

Although BrowserWarden does give options for disabling its coupons on a site-by-site basis, malware researchers found no equivalent functions for disabling its other advertising offers. In addition to its adware functions, BrowserWarden also may monitor and transmits some non-confidential information, including which sites you visit, some system specifications and general geolocation details. Together, these features may destabilize your browser or reduce some aspects of its performance, such as how quickly it may load websites.

An Escape from Advertising Prison

BrowserWarden is compatible with multiple Windows browsers, as well as with OS X's Safari. Other Unix-based systems are awaiting verification for any possible compatibilities. During its installation process, BrowserWarden also may modify more than one browser simultaneously. Common anti-adware heuristics should be capable of undoing most settings changes that allow BrowserWarden's advertisements to display at the same time as you remove BrowserWarden. Keeping any contact with these advertisements to bare minimums also may prevent your PC from being exposed to the attacks that may exploit adware-abused advertising networks, such as common Web misleading tactics.

For those interested in doing so, BrowserWarden may be installed from its primary website. On the other hand, most adware products normally are installed along with other software, either through a bundle or the efforts of threats. Assuming you don't carelessly download and install files from threatening sources, any PC protected by competent security solutions should have minimal vulnerability to either of these distribution methods.

Recent installation methods for BrowserWarden sometimes include non-visible installations that may modify your browser without any detectable components of BrowserWarden. These relatively surreptitious variants of BrowserWarden should continue to be detectable by good anti-adware products, although there aren't necessarily any visible symptoms to go with it.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES(x86)%\Browser Warden\FrameworkEngine.exe File name: FrameworkEngine.exe
Size: 264.93 KB (264936 bytes)
MD5: a7c5f1ffeac132973ead1f34c7839fcc
Detection count: 77
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Browser Warden
Group: Malware file
Last Updated: July 18, 2014
%LOCALAPPDATA%\Browser Warden\uninstall.exe File name: uninstall.exe
Size: 201.05 KB (201055 bytes)
MD5: 3b598b87a490b1e6d098272e774a597a
Detection count: 53
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\Browser Warden
Group: Malware file
Last Updated: July 18, 2014
%PROGRAMFILES(x86)%\Browser Warden\FrameworkBHO64.dll File name: FrameworkBHO64.dll
Size: 576.33 KB (576336 bytes)
MD5: 3e25e4100de4073953e198a630f71f0f
Detection count: 12
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Browser Warden
Group: Malware file
Last Updated: July 18, 2014
%PROGRAMFILES%\Browser Warden\FrameworkBHO.dll File name: FrameworkBHO.dll
Size: 355.42 KB (355424 bytes)
MD5: 02a5c671bc336006cc4105f8024a231a
Detection count: 7
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Browser Warden
Group: Malware file
Last Updated: July 18, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{1F165007-8086-434B-9499-9A7DC65D1AD2}{2C09954F-CDA8-4BD1-8794-1D543E050378}{2CE7951D-CD50-4BCF-8498-4C54E805EA78}{9C9242E6-4B6B-4E40-B532-5279636F4918}{D920E957-7261-417F-B689-D0E8B7053925}{D9D6E931-72E0-418A-90C2-06E86D059E25}{ED045727-C541-4D1C-8949-3BCC878EEA8D}{EDAD576E-C58C-4D50-BEBF-14CCFD8E828D}HKEY..\..\..\..{RegistryKeys}SOFTWARE\39012SOFTWARE\Browser WardenSoftware\Microsoft\Internet Explorer\DOMStorage\browserwarden.comSOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1F165007-8086-434B-9499-9A7DC65D1AD2}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2C09954F-CDA8-4BD1-8794-1D543E050378}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2C09954F-CDA8-4BD1-8794-1D543E050378}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{2C09954F-CDA8-4BD1-8794-1D543E050378}Software\Proxy\installations\Browser WardenSOFTWARE\Wow6432Node\39012SOFTWARE\Wow6432Node\Browser WardenSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1F165007-8086-434B-9499-9A7DC65D1AD2}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{2C09954F-CDA8-4BD1-8794-1D543E050378}SOFTWARE\Wow6432Node\Proxy\Installations\Browser Warden

Additional Information

The following directories were created:
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Browser Warden%APPDATA%\{2C09954F-CDA8-4BD1-8794-1D543E050378}%LOCALAPPDATA%\Browser Warden%PROGRAMFILES%\Browser Warden%PROGRAMFILES(x86)%\Browser Warden%USERPROFILE%\AppData\LocalLow\{2C09954F-CDA8-4BD1-8794-1D543E050378}
Loading...