Home Malware Programs Adware RightSurf

RightSurf

Posted: December 17, 2013

Threat Metric

Ranking: 6,797
Threat Level: 2/10
Infected PCs: 10,635
First Seen: December 18, 2013
Last Seen: October 15, 2023
OS(es) Affected: Windows

RightSurf is adware that may display unwanted pop-up advertisements, coupons, offers and deals when PC users are shopping online or visiting various other websites. RightSurf may install itself on Internet Explorer, Mozilla Firefox and Google Chrome without a PC user's authorization. RightSurf may be usually delivered bundled with free software that computer users download from the Web. When the computer user chooses to install a free app, it may encompass additional toolbars, browser extensions, add-ons or plug-ins added to the installation wizard. These additional free programs, in this case, RightSurf, may be marked as optional software, but if the computer user does not uncheck a box to add them, he may end up with unwanted system changes on the computer. RightSurf may keep track of the computer user's surfing routine and send collected data to third-parties for targeted advertising purposes.

Aliases

Trojan/Win32.Zapchast [AhnLab-V3]Artemis!5215978785A6 [McAfee]AdWare/Win32.Agent [Antiy-AVL]Generic PUA PP [Sophos]Application.Win32.Altbrowse.AK [Comodo]not-a-virus:AdWare.Win32.Agent.ahbx [Kaspersky]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\RightSurf\RightSurfuninstall.exe File name: RightSurfuninstall.exe
Size: 241.28 KB (241288 bytes)
MD5: af8f3986ec529b59e5a1bb73d56a8a7f
Detection count: 80
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\RightSurf
Group: Malware file
Last Updated: February 11, 2014
%PROGRAMFILES%\RightSurf\RightSurfbho.dll File name: RightSurfbho.dll
Size: 249.63 KB (249632 bytes)
MD5: a21837181ae19d18aba97cd81bdf3d8f
Detection count: 73
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\RightSurf
Group: Malware file
Last Updated: February 5, 2014
%PROGRAMFILES%\RightSurf\updateRightSurf.exe File name: updateRightSurf.exe
Size: 102.17 KB (102176 bytes)
MD5: d9c22a9774afc752d04c5a7fcaf2460a
Detection count: 71
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\RightSurf
Group: Malware file
Last Updated: February 5, 2014
%PROGRAMFILES(x86)%\RightSurf\bin\utilRightSurf.exe File name: utilRightSurf.exe
Size: 24.68 KB (24680 bytes)
MD5: 40c8a3ddbe48f737f80f941add4d27e3
Detection count: 64
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\RightSurf\bin
Group: Malware file
Last Updated: February 11, 2014
%PROGRAMFILES%\RightSurf\RightSurf.FirstRun.exe File name: RightSurf.FirstRun.exe
Size: 1.08 MB (1088800 bytes)
MD5: 945ce6325c66b1eb94391b15a1809cf2
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\RightSurf
Group: Malware file
Last Updated: July 15, 2020
%PROGRAMFILES(x86)%\RightSurf\bin\utilRightSurf.exe File name: utilRightSurf.exe
Size: 100.28 KB (100280 bytes)
MD5: 07c785ba12d6d40cb76dff15daad5813
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\RightSurf\bin
Group: Malware file
Last Updated: February 5, 2014
%PROGRAMFILES%\RightSurf\bin\utilRightSurf.exe File name: utilRightSurf.exe
Size: 43.34 KB (43342 bytes)
MD5: c9ef89bb46da0459660fa2978cc765b0
Detection count: 11
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\RightSurf\bin
Group: Malware file
Last Updated: February 5, 2014
%PROGRAMFILES(x86)%\RightSurf\updateRightSurf.exe File name: updateRightSurf.exe
Size: 102.17 KB (102176 bytes)
MD5: 1a3e1e4fe13a362822c527e26c63d726
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\RightSurf
Group: Malware file
Last Updated: February 5, 2014
%PROGRAMFILES%\RightSurf\bin\utilRightSurf.exe File name: utilRightSurf.exe
Size: 80.16 KB (80160 bytes)
MD5: 3455b6ced920b335b9179fdb02a60618
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\RightSurf\bin
Group: Malware file
Last Updated: February 11, 2014
%PROGRAMFILES%\RightSurf\bin\utilRightSurf.exe File name: utilRightSurf.exe
Size: 89.21 KB (89216 bytes)
MD5: b2d5ec76af5bdcf8e292609f0edba070
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\RightSurf\bin
Group: Malware file
Last Updated: February 5, 2014
%PROGRAMFILES%\RightSurf\updateRightSurf.exe File name: updateRightSurf.exe
Size: 103.2 KB (103200 bytes)
MD5: 0ab0b67e0ec6e6316b085d80d8a78032
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\RightSurf
Group: Malware file
Last Updated: February 5, 2014
%PROGRAMFILES%\RightSurf\bin\utilRightSurf.exe File name: utilRightSurf.exe
Size: 74.23 KB (74230 bytes)
MD5: 120e4e558913b6f7264a4bd7a475fad2
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\RightSurf\bin
Group: Malware file
Last Updated: February 11, 2014

Registry Modifications

The following newly produced Registry Values are:

CLSID{88be1aa9-6740-461c-9e3e-f35eb8fa741c}{A4F32137-598E-41B6-B601-9965084C8F08}{C64BA349-1F34-4BFC-8D23-A317279D0CB9}HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{88BE1AA9-6740-461C-9E3E-F35EB8FA741C}SOFTWARE\Microsoft\Tracing\RightSurf_RASAPI32SOFTWARE\Microsoft\Tracing\RightSurf_RASMANCSSOFTWARE\Microsoft\Tracing\updateRightSurf_RASAPI32SOFTWARE\Microsoft\Tracing\updateRightSurf_RASMANCSSOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{88be1aa9-6740-461c-9e3e-f35eb8fa741c}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{88BE1AA9-6740-461C-9E3E-F35EB8FA741C}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{88BE1AA9-6740-461C-9E3E-F35EB8FA741C}Software\RightSurfSOFTWARE\Wow6432Node\Microsoft\Tracing\RightSurf_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\RightSurf_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\updateRightSurf_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updateRightSurf_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{88be1aa9-6740-461c-9e3e-f35eb8fa741c}SOFTWARE\Wow6432Node\RightSurfSYSTEM\ControlSet001\services\eventlog\Application\Update RightSurfSYSTEM\ControlSet001\services\Update RightSurfSYSTEM\ControlSet001\Services\Util RightSurfSYSTEM\ControlSet002\Services\Util RightSurfSYSTEM\CurrentControlSet\services\eventlog\Application\Update RightSurfSYSTEM\CurrentControlSet\services\Update RightSurfSYSTEM\CurrentControlSet\Services\Util RightSurfHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}RightSurf

Additional Information

The following directories were created:
%PROGRAMFILES%\RightSurf%PROGRAMFILES(x86)%\RightSurf
Loading...