exo-api.tf Malwarebytes Edge Alert: Meaning and Cleanup

Brendan Smith
Brendan Smith - Cybersecurity Analyst
13 Min Read
Microsoft Edge connection to exo-api.tf stopped by a block barrier
Microsoft Edge reaches a blocked exo-api.tf destination while the browser itself remains intact.

An outbound alert for exo-api.tf should stay blocked. If Malwarebytes lists C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe as the application, that means an Edge process made the network request; it does not prove the Microsoft-signed browser file itself is infected. The trigger may be a tab, site permission, extension, synced profile setting, background Edge task, unwanted app, or Windows persistence. Do not add the domain to an allow list. Isolate the trigger, remove it, and confirm the alert does not return.

What the exo-api.tf Malwarebytes alert means

A web-protection alert has three different parts: the application that opened the connection, the destination it contacted, and the security product’s category. In this case, msedge.exe is the requesting application, exo-api.tf is the destination, and RiskWare is Malwarebytes’ warning category.

The distinction matters. A legitimate browser routinely creates many child processes for tabs, extensions, notifications, service workers, downloads, and background activity. When one of those components requests a blocked domain, the alert can name the normal Edge executable. Deleting or renaming msedge.exe is not the fix.

Current evidence supports treating the destination as untrusted. The Gridinsoft Website Reputation Checker report for exo-api.tf classifies it as suspicious and records 19 provider warnings. A public ANY.RUN task analyzed a specific exo-api.tf URL on May 15, 2026 and returned a malicious-activity verdict with loader behavior. That sandbox result applies to the analyzed path and session; it does not prove that every request to the domain delivers the same payload.

Gridinsoft Website Reputation Checker report for exo-api.tf showing a suspicious verdict and 19 provider warnings
The Gridinsoft Website Reputation Checker report for exo-api.tf records a suspicious verdict, a 1/100 trust score, and 19 provider warnings. Checked March 17, 2026.

What to do first

  1. Keep the connection blocked. Do not click Allow, Restore, Exclude, or Ignore for the domain while you are still investigating it.
  2. Save the alert details. Record the time, full domain or URL, application path, category, and whether Edge was visibly open.
  3. Close Edge completely. Open Task Manager and end remaining Edge windows and processes only after saving work.
  4. Restart Windows. Note whether the alert returns before you deliberately open Edge, immediately after Edge starts, or only after visiting a particular page.
  5. Do not sign into sensitive accounts until recurring alerts, unexpected tabs, extensions, or downloads have been resolved.
What you observed Risk and next step
You visited a page once; the request was blocked and does not return Lower exposure. Clear that site’s data, close the tab, and watch for recurrence. A blocked request alone does not prove code ran.
The alert returns while Edge is closed Check Edge background mode, startup boost, notifications, Startup Apps, scheduled tasks, and recently installed software.
The alert stops in a clean profile or InPrivate window The normal profile is the likely source. Review extensions, site permissions, startup pages, search settings, sync, and site data.
The alert continues with every extension disabled Do not declare the extensions clean yet, but widen the check to notifications, service workers/site data, policy, shortcuts, proxy, DNS, apps, and Windows persistence.
You downloaded or ran a file before the alerts started Treat it as a possible system compromise. Remove the download, scan the device, inspect persistence, and recover accounts only after cleanup.

Isolate the trigger inside Microsoft Edge

1. Test a clean browser state

Start with an InPrivate window or a new local Edge profile that is not signed into sync. Do not revisit the page that preceded the alert. If the connection stays quiet in the clean state but returns in the usual profile, focus on that profile rather than reinstalling the whole browser.

If Edge is creating tabs or windows by itself, use the broader automatic tab troubleshooting flow to map the trigger to sign-in, reboot, a click, a notification, or a scheduled launch.

2. Disable every extension, then remove suspicious ones

Open edge://extensions, turn off every extension, restart Edge, and test again. Review extensions you do not recognize, items installed shortly before the first alert, add-ons with access to all sites, and anything marked as managed or installed by policy. Microsoft documents the normal disable and removal controls for Edge extensions; a managed item that cannot be removed needs a policy or companion-app check rather than repeated clicks.

Google ChromeSafariMozilla FirefoxMicrosoft EdgeBraveOpera
Google Chrome
Extension Manager
  1. Launch Chrome.
  2. Click the three dots (...) in the top right corner.
  3. Select Extensions > Manage Extensions.
  4. Click Remove next to the extension you want to delete.

Quick Access: Type chrome://extensions/ in the address bar.

Safari
Settings > Extensions
  1. Open Safari.
  2. In the menu bar, click Safari and select Settings (or Preferences).
  3. Click on the Extensions tab.
  4. Select the extension and click Uninstall.
Mozilla Firefox
Add-ons and Themes
  1. Click the menu button, select Add-ons and themes.
  2. Go to the Extensions tab.
  3. Click the three dots (...) next to the extension and select Remove.

Quick Access: Type about:addons in the address bar.

Microsoft Edge
Browser Extensions
  1. Launch Microsoft Edge.
  2. Click the three dots (...) in the top right corner.
  3. Select Extensions.
  4. Find the extension and click Remove.

Quick Access: Type edge://extensions/ in the address bar.

Brave
Shields and Extensions
  1. Launch Brave browser.
  2. Click the menu icon > Extensions.
  3. Find the extension and click Remove.

Quick Access: Type brave://extensions/ in the address bar.

Opera
Extension Management
  1. Launch Opera.
  2. Click the Opera logo in the top left corner.
  3. Select Extensions > Extensions.
  4. Click the X or Remove button next to the extension.

Quick Access: Type opera://extensions/ in the address bar.

Open Extensions/Add-ons again and remove any entry linked to exo-api.tf or clearly out of place.

If an extension disappears and then returns, pause browser sync and follow the extension reinstallation checklist. Sync, an enterprise-style policy, a scheduled task, or a bundled Windows app can restore it.

3. Revoke notifications and clear site data

Open edge://settings/content/notifications and remove or block unknown sites in the Allow list. Microsoft notes that website notifications can appear even when Edge is closed, so a background alert does not automatically mean a hidden browser window is open. Also review recent permissions for pop-ups, redirects, automatic downloads, and background sync.

If exo-api.tf keeps showing unwanted pop-ups, you likely granted it permission to send notifications. To stop them, you need to revoke that permission in your browser settings.

Google ChromeSafariMozilla FirefoxMicrosoft EdgeBraveOpera
Google Chrome
  1. Copy and paste this into the address bar: chrome://settings/content/notifications
  2. Scroll down to the Allowed to send notifications list.
  3. Find exo-api.tf.
  4. Click the three dots (...) next to it and select Remove (or Block).
Safari
  1. Open Safari and go to Settings (or Preferences).
  2. Click the Websites tab and select Notifications on the left.
  3. Find exo-api.tf in the list on the right.
  4. Select it and click Remove (or change "Allow" to "Deny").
Mozilla Firefox
  1. Copy and paste this into the address bar: about:preferences#privacy
  2. Scroll down to Permissions and click Settings... next to Notifications.
  3. Type exo-api.tf in the search bar or find it in the list.
  4. Select the site and click Remove Website.
Microsoft Edge
  1. Copy and paste this into the address bar: edge://settings/content/notifications
  2. Look under the Allow section.
  3. Find exo-api.tf.
  4. Click the three dots (...) next to it and select Remove (or Block).
Brave
  1. Copy and paste this into the address bar: brave://settings/content/notifications
  2. Scroll to the Allowed to send notifications list.
  3. Find exo-api.tf.
  4. Click the three dots (...) and select Remove (or Block).
Opera
  1. Copy and paste this into the address bar: opera://settings/content/notifications
  2. Check the Allowed to send notifications list.
  3. Find exo-api.tf.
  4. Click the three dots next to it and select Remove.

Next, open edge://settings/content/all, search for the suspicious domain and any unfamiliar site seen at the same time, and delete its stored data. This can remove cookies, local storage, and registered site state. Do not clear everything immediately if preserving the exact trigger matters; start with the named site and recent unknown entries.

4. Check startup pages, shortcuts, sync, and policy

  • Open edge://settings/onStartup and remove pages you did not choose.
  • Check the default search engine, new-tab behavior, and homepage for changes.
  • Open edge://policy. On a personal PC, unexpected policies that force extensions, startup URLs, or proxy settings deserve investigation. Do not remove legitimate school or work policies.
  • Inspect desktop, Start-menu, and taskbar shortcuts. The Target field should end with the Edge executable, not an added URL after the closing quote.
  • Temporarily turn off “Continue running background extensions and apps when Microsoft Edge is closed” and startup boost under edge://settings/system while testing.
  • If the problem returns only after signing into Edge, pause sync until the profile is clean.

If exo-api.tf keeps returning

When the alert survives a clean-profile test, returns before you open Edge, or reappears after a reboot, widen the investigation to Windows. The browser may only be the visible network client. A bundled app, startup entry, scheduled task, service, browser policy, or loader can launch Edge or feed it a URL again.

  1. Review installed apps. In Settings → Apps → Installed apps, sort by install date and investigate software added just before the alert. Remove only software you can identify as unwanted.
  2. Review startup items. Check Task Manager → Startup apps and the suspicious startup-app checklist. Disable unknown launchers for testing before deleting files.
  3. Inspect Task Scheduler. Look for recent logon, startup, or repeating tasks that open Edge, a script, PowerShell, Command Prompt, or a URL. Record a task’s trigger, action, author, and file path before removing it.
  4. Check proxy and DNS settings. In Windows Settings → Network & internet → Proxy, disable an unknown manual proxy or setup script only if your organization or VPN did not configure it. Review the active adapter’s DNS servers for unexpected addresses.
  5. Scan the full device. A browser reset cannot remove a Windows task, companion app, loader, or policy writer.

If you see exo-api.tf or other suspicious applications that you don't remember installing, you should remove them as well.

WindowsMacAndroid
Windows 10/11
  1. Right-click the Start button and select Installed Apps (or Apps & Features).
  2. Scroll through the list to find exo-api.tf or any other unfamiliar program.
  3. Click the three dots (...) next to it and select Uninstall.
Mac OS
  1. Open Finder and go to the Applications folder.
  2. Locate exo-api.tf or any app you don't recognize.
  3. Drag it to the Trash.
  4. Empty the trash to remove it permanently.
Android 11+
  1. Go to Settings > Apps > See all apps.
  2. Find exo-api.tf or any suspicious app in the list.
  3. Tap on it and select Uninstall.

After manual browser cleanup, run a full Gridinsoft Anti-Malware scan and remove confirmed detections. Reboot, then scan again if the connection returns. The scan is useful here because it checks beyond the visible tab for bundled apps, hidden files, startup entries, scheduled tasks, browser changes, and other persistence; it cannot prove that no exposure occurred or recover credentials already entered on an unsafe page.

Find what restores the browser changes.

If redirects, notifications, extensions, homepage changes, or managed policies return after browser cleanup, the source is often outside the browser: an installed app, policy, scheduled task, or startup entry.

Scan for the recurring trigger

How to confirm the cleanup worked

  1. Reboot Windows and wait a few minutes before opening Edge.
  2. Open Edge first in the clean profile, then the cleaned normal profile.
  3. Verify that no unknown extension, policy, notification permission, startup page, proxy, or scheduled task has returned.
  4. Keep the block in place and watch the security history through at least one normal browsing session and another reboot.
  5. If the alert returns, compare its time and full URL with Task Scheduler history, startup launches, and Edge activity instead of repeating the same reset.

Repairing Edge can help with damaged browser files, but it is not a substitute for finding the component that requested the domain. Resetting the entire PC is a last resort for confirmed or persistent compromise after backups and ordinary cleanup fail—not the first response to one blocked connection.

FAQ

Is msedge.exe a virus in this alert?

Not by itself. The normal path C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe is where Microsoft Edge is commonly installed. The alert says that an Edge process requested a blocked destination. Check the file’s Microsoft signature and path, but investigate the tab, profile, extension, permission, policy, app, or task that caused the request.

Is exo-api.tf a false positive?

The current evidence is strong enough to keep it blocked: Gridinsoft records multiple provider warnings, and a public sandbox observed malicious loader activity on a specific path at the domain. Those findings do not identify the trigger on your PC, so the right response is block plus source isolation—not an assumption that every request is identical.

Why does the alert appear when Edge is closed?

Edge can continue background activity for extensions and apps, and website notifications can appear after the window closes. Windows startup items, scheduled tasks, shortcuts, or unwanted software can also launch Edge without an obvious window.

Will resetting or reinstalling Edge remove exo-api.tf?

Only if the trigger is limited to browser state that the reset actually removes. Sync, policy, a companion app, startup entry, scheduled task, proxy, or loader can recreate the request after a reset or reinstall.

Should I change my passwords?

Change important passwords from a clean device if you entered credentials on a suspicious page, installed or ran a download, allowed a broad-access extension, or see account alerts. One blocked outbound request alone does not prove password theft.

References

  1. ANY.RUN. “Malware analysis: exo-api.tf/Stb/Retev.php.” ANY.RUN public sandbox report, analyzed May 15, 2026; accessed July 23, 2026. any.run report.
  2. Microsoft. “Manage website notifications in Microsoft Edge.” Microsoft Support, accessed July 23, 2026. support.microsoft.com.
  3. Microsoft. “Add, turn off, or remove extensions in Microsoft Edge.” Microsoft Support, accessed July 23, 2026. support.microsoft.com.
Share This Article
Cybersecurity Analyst
Follow:
Brendan Smith has spent over 15 years knee-deep in cybersecurity, chasing down malware from the gritty reverse-engineering of old-school trojans all the way to wrangling full-blown incident responses for small-to-medium businesses that couldn’t afford a full-blown breach. Over at Gridinsoft, he’s the guy piecing together those double-checked guides on nasty stuff like AsyncRAT ransomware—take last year, for instance, when his breakdowns caught more than 200 sneaky variants right in live scans, knocking user cleanup jobs down by a solid 40% and saving folks hours of headache.
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?