Home Malware Programs Adware Adware.FrameFox

Adware.FrameFox

Posted: December 23, 2013

Threat Metric

Ranking: 10,945
Threat Level: 2/10
Infected PCs: 51,709
First Seen: December 23, 2013
Last Seen: October 16, 2023
OS(es) Affected: Windows

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\$Recycle.Bin\S-1-5-21-1788207478-340930373-1749900118-1000\$RWA9VJ1\Quarantine\C\Program Files (x86)\FrameFox\Extensions\InternetExplorer\framefox.exe.vir File name: framefox.exe.vir
Size: 287.21 KB (287216 bytes)
MD5: 6017ca94be482bcb527d92c6d481b2cc
Detection count: 39,282
Mime Type: unknown/vir
Path: C:\$Recycle.Bin\S-1-5-21-1788207478-340930373-1749900118-1000\$RWA9VJ1\Quarantine\C\Program Files (x86)\FrameFox\Extensions\InternetExplorer\framefox.exe.vir
Group: Malware file
Last Updated: April 27, 2022
%PROGRAMFILES(x86)%\FrameFox\Extensions\InternetExplorer\framefox.exe File name: framefox.exe
Size: 224.24 KB (224240 bytes)
MD5: 789eb0eee66f46947f695331a1ca58c5
Detection count: 2,984
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\FrameFox\Extensions\InternetExplorer
Group: Malware file
Last Updated: May 4, 2020
%PROGRAMFILES(x86)%\FrameFox\Extensions\InternetExplorer\framefox.exe File name: framefox.exe
Size: 287.21 KB (287216 bytes)
MD5: 01eca800662eb1df26f897944a8ff5d4
Detection count: 951
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\FrameFox\Extensions\InternetExplorer
Group: Malware file
Last Updated: February 11, 2020
%PROGRAMFILES(x86)%\FrameFox\Extensions\InternetExplorer\framefox.exe File name: framefox.exe
Size: 224.24 KB (224240 bytes)
MD5: 9f1f6f9b13e8458c60907180d15c83c2
Detection count: 396
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\FrameFox\Extensions\InternetExplorer
Group: Malware file
Last Updated: December 23, 2013
%PROGRAMFILES(x86)%\FrameFox\Extensions\InternetExplorer\framefox.exe File name: framefox.exe
Size: 128.56 KB (128568 bytes)
MD5: dedd918c18d31163e2dae134a0538348
Detection count: 368
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\FrameFox\Extensions\InternetExplorer
Group: Malware file
Last Updated: December 23, 2013
%PROGRAMFILES%\FrameFox\Extensions\InternetExplorer\framefox.exe File name: framefox.exe
Size: 223.8 KB (223800 bytes)
MD5: 894413ff7f6ded5aae568c9adaf72102
Detection count: 171
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\FrameFox\Extensions\InternetExplorer
Group: Malware file
Last Updated: December 23, 2013
%TEMP%\n1399\FrameFox_1909-357c9206.exe File name: FrameFox_1909-357c9206.exe
Size: 492.23 KB (492232 bytes)
MD5: f69ab43eb987667d54518527148c5528
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\n1399
Group: Malware file
Last Updated: November 2, 2020
%TEMP%\framefoxsetup.exe File name: framefoxsetup.exe
Size: 492.23 KB (492232 bytes)
MD5: cfdfb01c8f4cc858dd098aaea145c5e1
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: December 23, 2013
%PROGRAMFILES%\FrameFox\Extensions\InternetExplorer\framefox.exe File name: framefox.exe
Size: 151.76 KB (151769 bytes)
MD5: 112c2f2558abf9fb8dd77881b8f865ac
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\FrameFox\Extensions\InternetExplorer
Group: Malware file
Last Updated: December 23, 2013

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\Installer\Features\098CCE33084C42149BB5AB630E521B02SOFTWARE\Classes\Installer\Products\098CCE33084C42149BB5AB630E521B02SOFTWARE\Duuqu\FrameFoxSOFTWARE\Duuqu\Update\Clients\{AC14D5E8-02B7-4849-B31E-35E81F72D121}SOFTWARE\FrameFoxSOFTWARE\Microsoft\Windows\CurrentVersion\Run\FrameFox ExtensionsSOFTWARE\Wow6432Node\Duuqu\FrameFoxSOFTWARE\Wow6432Node\Duuqu\Update\Clients\{AC14D5E8-02B7-4849-B31E-35E81F72D121}SOFTWARE\Wow6432Node\FrameFoxSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\FrameFox ExtensionsHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{010BE806-614F-48F2-B83A-29DF45E6AC7D}{33ECC890-C480-4124-B95B-BA36E025B120}

Additional Information

The following directories were created:
%ProgramFiles%\FrameFox%ProgramFiles(x86)%\FrameFox%Windir%\Installer\{33ECC890-C480-4124-B95B-BA36E025B120}
The following URL's were detected:
FrameFox
Loading...