{
  "family": "favadd",
  "sample_count": 1,
  "category": "trojan",
  "description": "<h3>Executive Summary</h3>\nFavadd (often detected as Adware.Favadd or Trojan.Favadd) is a class of Adware and Potentially Unwanted Programs (PUP) prevalent during the era of heavy browser hijacking. Its primary objective is aggressive and unauthorized monetization by forcefully altering a user's web browser settings, specifically by injecting hundreds of unsolicited, sponsored bookmarks (\"favorites\") and changing the default homepage to redirect traffic to affiliate marketing sites or fraudulent search portals.\n\n<h3>Infection Vector and Technical Capabilities</h3>\nFavadd is predominantly distributed via software bundling. Users typically encounter this threat when downloading \"free\" utilities, media players, or browser extensions from untrustworthy third-party download portals.\n\nUpon execution, the adware operates by directly modifying browser configurations:\n<ul>\n<li><strong>Bookmark Injection:</strong> Favadd aggressively modifies the configuration files and registry keys associated with major web browsers (Internet Explorer, Firefox, older versions of Chrome). It adds dozens of bookmarks leading to online casinos, fake tech support pages, and aggressive affiliate marketing sites.</li>\n<li><strong>Browser Hijacking:</strong> The malware often alters the browser's default homepage, new tab page, and default search engine provider to force the user's web traffic through a monetization gateway controlled by the adware authors.</li>\n<li><strong>Persistence:</strong> To prevent the user from simply deleting the bookmarks, Favadd often utilizes a background service or a persistent browser helper object (BHO) that automatically restores the malicious bookmarks upon every system reboot or browser launch.</li>\n</ul>\n\n<h3>Threat Assessment</h3>\nWhile Favadd is generally classified as Adware and does not typically encrypt files or steal banking credentials, it represents a significant degradation of the user experience and poses a severe privacy risk. The aggressive redirection often exposes users to secondary, far more severe malware infections via \"malvertising\" networks.\n\n<h3>Remediation and Eradication</h3>\n<ul>\n<li><strong>Application Removal:</strong> The first step is to identify and uninstall the core adware application via the Windows Control Panel, looking for recently installed, suspicious \"free\" utilities or toolbars.</li>\n<li><strong>Browser Reset:</strong> Because Favadd deeply alters browser configurations, the most effective remediation is a complete reset of all installed web browsers to their factory default settings, which automatically clears malicious extensions, BHOs, and injected bookmarks.</li>\n<li><strong>Anti-Malware Sweep:</strong> Run a comprehensive scan using a reputable anti-malware solution specifically tuned to detect and remove Potentially Unwanted Programs (PUPs) and lingering registry keys left behind by the adware.</li>\n</ul>",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "Adware.Favadd",
    "Trojan.Favadd",
    "PUP.Favadd"
  ],
  "enrichment_level": "insufficient_information",
  "faq": [],
  "faq_count": 0,
  "mitre_attack": [
    "T1185",
    "T1176",
    "T1546.015"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-07-01T17:23:59Z",
  "type": "Adware / Browser Hijacker",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}