Home Malware Programs Adware ConstaSurf

ConstaSurf

Posted: April 7, 2014

Threat Metric

Ranking: 10,005
Threat Level: 2/10
Infected PCs: 5,066
First Seen: April 7, 2014
Last Seen: October 9, 2023
OS(es) Affected: Windows


ConstaSurf is known to be adware that may display pop-up advertisements including discount coupons, offers, deals and sponsored links via a pop-up box on social networking and online shopping websites, or other legitimate websites that might have been hijacked by adware or browser hijackers. The pop-up ads and banners of ConstaSurf may be displayed as boxes, which may contain a variety of discount coupons and offers, which, when clicked, may show additional pop-up advertisements and banners that may claim to allegedly come to the PC user from ConstaSurf. ConstaSurf might be created specifically to generate advertising income from clicks on pop-up ads and messages. ConstaSurf may also boost web traffic by unwillingly redirecting PC users to questionable websites that may be designed for commercial purposes. ConstaSurf may add an unwanted browser extension, add-on or plug-in in the Web browsers such as Internet Explorer, Mozilla Firefox and Google Chrome when the computer user installs other free programs from unidentified download websites that might have bundled into their installation ConstaSurf.

Aliases

AdWare.SpadeCast [Ikarus]Consurf [AVG]BrowseSmart [Sophos]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



c:\windows\system32\drivers\{0782648b-1717-4fef-ac58-8cb3ce03adb3}t64.sys File name: {0782648b-1717-4fef-ac58-8cb3ce03adb3}t64.sys
Size: 60.09 KB (60096 bytes)
MD5: 33edf0cba7e71dcc256491ca4db6307f
Detection count: 14
File type: System file
Mime Type: unknown/sys
Path: c:\windows\system32\drivers\{0782648b-1717-4fef-ac58-8cb3ce03adb3}t64.sys
Group: Malware file
Last Updated: December 13, 2020

Registry Modifications

The following newly produced Registry Values are:

CLSID{41E2BE59-5C34-46AB-B743-6678BC94F42C}{52654F2B-3A13-4569-AB52-EF4201F79221}{96cf2cbe-b6d5-454a-a62a-84bcda86ef1d}{C530E227-8152-41CF-B66A-2CF085772FF6}{d7356335-81bf-4769-bfbd-2e2889138641}Regexp file mask%SystemRoot%\system32\drivers\{0782648b-1717-4fef-ac58-8cb3ce03adb3}[RANDOM CHARACTERS]HKEY..\..\..\..{RegistryKeys}SOFTWARE\ConstaSurfSoftware\Microsoft\Internet Explorer\Approved Extensions\{16d8ee0f-209a-465d-9b55-1a07848109d5}Software\Microsoft\Internet Explorer\Approved Extensions\{6fb4473c-b0d0-42d9-9909-6d3d0a72f6c9}Software\Microsoft\Internet Explorer\Approved Extensions\{96CF2CBE-B6D5-454A-A62A-84BCDA86EF1D}SOFTWARE\Microsoft\Tracing\ConstaSurf_RASAPI32SOFTWARE\Microsoft\Tracing\ConstaSurf_RASMANCSSOFTWARE\Microsoft\Tracing\updateConstaSurf_RASAPI32SOFTWARE\Microsoft\Tracing\updateConstaSurf_RASMANCSSOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{d7356335-81bf-4769-bfbd-2e2889138641}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D7356335-81BF-4769-BFBD-2E2889138641}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D7356335-81BF-4769-BFBD-2E2889138641}Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{d7356335-81bf-4769-bfbd-2e2889138641}SOFTWARE\Wow6432Node\ConstaSurfSOFTWARE\Wow6432Node\Microsoft\Tracing\ConstaSurf_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\ConstaSurf_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\updateConstaSurf_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updateConstaSurf_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{d7356335-81bf-4769-bfbd-2e2889138641}SYSTEM\ControlSet001\services\eventlog\Application\Update ConstaSurfSYSTEM\ControlSet001\services\Update ConstaSurfSYSTEM\ControlSet001\Services\Util ConstaSurfSYSTEM\ControlSet002\Services\Util ConstaSurfSYSTEM\CurrentControlSet\services\eventlog\Application\Update ConstaSurfSYSTEM\CurrentControlSet\services\Update ConstaSurfSYSTEM\CurrentControlSet\Services\Util ConstaSurfHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}ConstaSurf

Additional Information

The following directories were created:
%PROGRAMFILES%\ConstaSurf%PROGRAMFILES(x86)%\ConstaSurf%TEMP%\ConstaSurf
The following URL's were detected:
ConstaSurf
Loading...