Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Apr 25, 2016 | Updated Jan 31, 2018

BrowserModifier:Win32/Riccietex

Detected by Microsoft Defender Antivirus

Aliases: Adware AdPlugin.QRH (AVG)

Summary

Microsoft Defender Antivirus detects and removes this unwanted software.

This browser modifier is distributed as an installer for different applications. When launched, it displays an installation interface for the packaged application.

While installing software, this malware modifies shortcuts (.lnk files) for different web browsers, including Google Chrome, Internet Explorer, and Mozilla Firefox as well as popular Chinese browsers like UC Browser, QQ Browser, and Baidu Browser.

Opening a modified shortcut opens the browser and directs it to the following website:

hao.360.cn

Although this malware is known to install legitimate software and the website it points browsers to is legitimate, its behavior of modifying shortcuts in the background generally constitutes unexpected and unwanted behavior.

This threat is an unwanted software. An unwanted software is a program that alters your Windows experience without your consent or control. We use a set of evaluation criteria to determine what programs are classified as unwanted software. As the software ecosystem evolves, so do our evaluation criteria. To learn more, read these blog entries:

 

To restore an affected shorcut, modify the shortcut property under Target. You can also delete the affected shortcut and recreate it.

Use the following free Microsoft software to detect and remove this threat:

You should also run a full scan. A full scan might find hidden threats.

Get more help

You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help.

If you’re using Windows XP, see our Windows XP end of support page.

Follow us