Threat Database Adware Adware.BrowSecX.C

Adware.BrowSecX.C

By CagedTech in Adware

Threat Scorecard

Threat Level: 20 % (Normal)
Infected Computers: 16
First Seen: December 1, 2022
Last Seen: November 14, 2025
OS(es) Affected: Windows

The detection of Adware.BrowSecX.C on your system indicates a potential security threat that requires immediate attention. Adware is a type of malware that is designed to display unwanted advertisements on a user's device, often in the form of pop-ups, banners, or sponsored content. In this report, we will provide an overview of Adware.BrowSecX.C, its operating methods, symptoms of infection, and steps to remove it from your system.

What Is Adware.BrowSecX.C?

Adware.BrowSecX.C is a type of adware that is designed to compromise a user's browsing experience by displaying unwanted advertisements. The name itself does not indicate a specific malware family, but rather a detection label assigned by security software. Adware.BrowSecX.C may be bundled with other software or downloaded from the internet, often without the user's knowledge or consent.

How Adware.BrowSecX.C Operates

Adware.BrowSecX.C operates by infiltrating a user's system and modifying browser settings to display unwanted advertisements. This can include pop-ups, banners, and sponsored content that may be distracting or malicious. The adware may also collect user data, such as browsing history and search queries, to deliver targeted advertisements. In some cases, Adware.BrowSecX.C may also install additional malware or software on the user's system, further compromising security.

Symptoms of Infection

Symptoms of Adware.BrowSecX.C infection may include an increase in unwanted advertisements, slow browser performance, and unexpected changes to browser settings. Users may also experience pop-ups or redirects to suspicious websites, or notice that their search results are being hijacked. In some cases, the adware may also cause system crashes or freezes, or display fake alerts or warnings.

  • Unwanted advertisements or pop-ups
  • Slow browser performance
  • Unexpected changes to browser settings
  • Redirects to suspicious websites
  • System crashes or freezes
  • Fake alerts or warnings

How to Remove Adware.BrowSecX.C

  1. Boot your system in Safe Mode with Networking to prevent the adware from loading.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove Adware.BrowSecX.C and any related malware.
  3. Uninstall any suspicious programs or software that may be related to the adware.
  4. Reset your browser settings to their default values, including Chrome, Firefox, and Edge.
  5. Reboot your system and perform a follow-up scan to ensure that the adware has been completely removed.

Conclusion

Removing Adware.BrowSecX.C from your system requires a combination of technical expertise and caution. By following the steps outlined in this report, you can help to ensure that your system is free from the adware and any related malware. It is also important to practice safe browsing habits, such as avoiding suspicious downloads and keeping your software up to date, to prevent future infections. If you are unsure about any aspect of the removal process, it is recommended that you seek the assistance of a qualified IT professional.

Analysis Report

General information

Family Name: Adware.BrowSecX.C
Signature status: No Signature

Known Samples

MD5: 2db39d6e80496ea48e97a306d52ce800
SHA1: 4de835572cf16ee5c2282c0f4df21fce6a73195e
SHA256: 52D3933B68D8C6A7BCE4176CAB506D56E47CB431BCE33B1005DFE6B8464FC255
File Size: 913.92 KB, 913920 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • dll
  • HighEntropy
  • x86

Block Information

Total Blocks: 2,996
Potentially Malicious Blocks: 483
Whitelisted Blocks: 2,493
Unknown Blocks: 20

Visual Map

1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 2 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x x x 0 0 x 0 x 0 0 x x x ? x x 0 x 0 x x x 0 0 x 0 0 0 x 0 x 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x 0 1 0 x x 0 x x 0 x x x x 1 0 x x 0 0 0 0 x 0 ? x ? x x x ? 0 x 0 x x 0 x x x 0 x 0 x 0 0 x x 0 0 x 0 0 x x x x x x x x 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 0 x x x 1 0 x 1 x x x x x x 1 0 x x 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x 1 x x x x x x x x x ? x x 0 0 0 0 0 0 0 0 x x x ? 0 x 0 0 0 0 x x 0 0 0 0 0 0 x 0 0 0 0 x 0 x x x x x x x 0 0 0 x 0 0 0 x 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 x x x x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x x x x 0 0 x 0 x 0 0 0 x 0 x 1 0 0 x 0 0 x 0 1 0 0 x x 0 x x x x 0 x x 1 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 0 0 x 0 0 0 0 0 x x x x x x x x x x x 0 x 0 0 x x 0 0 0 0 1 0 0 0 0 0 0 x x x x x 0 ? x ? 0 x 0 x 0 0 1 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 ? 0 x ? 0 0 0 x 0 ? 0 0 0 0 0 0 0 0 0 x 0 ? x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 1 0 0 0 0 0 0 0 0 0 x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x x ? ? 0 0 0 x x x x ? 0 ? x 1 x x 0 0 0 x x x 0 x 0 x 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 x 0 0 1 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 x 0 x x 0 0 x x x x 0 0 x x 0 x x x 0 x 0 x 0 0 x 0 x x x x 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x x 0 0 0 0 x x x 0 x 0 x x 0 x 0 0 0 x 0 x 0 0 0 0 0 x 0 x x 0 0 x x x 0 0 0 0 0 x x x 0 0 0 0 x x 0 0 x 0 x 0 0 x 0 0 x x 0 x x x x 0 x x x x x x x x x 0 x 0 0 0 x 0 0 x x x 0 0 0 0 x x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 x 0 0 x 0 x 0 x 0 0 x 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 x x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x 0 x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 x 0 x x x x x 0 0 0 0 0 0 0 0 0 0 x x x 0 x 0 0 0 0 x 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 x x x x 0 0 0 0 0 0 0 x x x 0 x x x 0 x x 0 x 0 0 0 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 x 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 x 0 0 x 0 0 0 0 0 0 x 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 x x 0 x 0 0 0 0 x x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x 0 x 0 0 0 x 0 x 0 x 0 0 0 0 0 x x x 0 0 0 0 x x 0 0 0 0 0 0 0 x 0 x x 0 0 x 0 x x 0 0 x 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 x x 0 x x 0 0 0 x 0 0 0 0 x x 0 0 0 0 0 x 0 0 x x 0 x 0 0 0 0 x x 0 0 0 0 0 x x x x x 0 0 0 0 0 0 0 0 x 0 x x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x 0 0 0 x 0 x x x 0 0 0 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 1 1 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 x 0 1 0 1 0 x 0 x x x x x 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 2 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 2 0 1 0 1 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • BrowSecX.C
  • Outbrowse.CD
  • Outbrowse.CE
  • Outbrowse.CG

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\4de835572cf16ee5c2282c0f4df21fce6a73195e_0000913920.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...