Threat Database Adware ConstaSurf

ConstaSurf

By GoldSparrow in Adware

Threat Scorecard

Ranking: 10,244
Threat Level: 20 % (Normal)
Infected Computers: 2,162
First Seen: April 7, 2014
Last Seen: September 17, 2023
OS(es) Affected: Windows

ConstaSurf is an adware threat that may show pop-up ads carrying deals, offers, sponsored links and discount coupons via a pop-up box on social networking and shopping-related websites, or other genuine websites that might have been compromised by adware or browser hijackers. ConstaSurf's pop-up advertisements and messages may be shown as boxes, which may include numerous discount coupons and deals which, when clicked, may display intrusive pop-up ads and banners on the computer system that may declare to be supposedly sent to the computer user by ConstaSurf. ConstaSurf might be produced particularly to generate advertising revenue from ad and banner clicks. ConstaSurf may raise website traffic by continuously diverting computer users to suspicious websites that may be commercial. ConstaSurf may insert a browser extension, plug-in or add-on for Internet Explorer, Mozilla Firefox and Google Chrome Web browsers when the PC user installs other free applications from the Internet that might have packaged into their installation ConstaSurf.

Aliases

3 security vendors flagged this file as malicious.

Anti-Virus Software Detection
Ikarus AdWare.SpadeCast
AVG Consurf
Sophos BrowseSmart

SpyHunter Detects & Remove ConstaSurf

File System Details

ConstaSurf may create the following file(s):
# File Name MD5 Detections
1. {0782648b-1717-4fef-ac58-8cb3ce03adb3}t64.sys 33edf0cba7e71dcc256491ca4db6307f 6

Registry Details

ConstaSurf may create the following registry entry or registry entries:
CLSID
{41E2BE59-5C34-46AB-B743-6678BC94F42C}
{52654F2B-3A13-4569-AB52-EF4201F79221}
{96cf2cbe-b6d5-454a-a62a-84bcda86ef1d}
{C530E227-8152-41CF-B66A-2CF085772FF6}
{d7356335-81bf-4769-bfbd-2e2889138641}
Regexp file mask
%SystemRoot%\system32\drivers\{0782648b-1717-4fef-ac58-8cb3ce03adb3}[RANDOM CHARACTERS]
SOFTWARE\ConstaSurf
Software\Microsoft\Internet Explorer\Approved Extensions\{16d8ee0f-209a-465d-9b55-1a07848109d5}
Software\Microsoft\Internet Explorer\Approved Extensions\{6fb4473c-b0d0-42d9-9909-6d3d0a72f6c9}
Software\Microsoft\Internet Explorer\Approved Extensions\{96CF2CBE-B6D5-454A-A62A-84BCDA86EF1D}
SOFTWARE\Microsoft\Tracing\ConstaSurf_RASAPI32
SOFTWARE\Microsoft\Tracing\ConstaSurf_RASMANCS
SOFTWARE\Microsoft\Tracing\updateConstaSurf_RASAPI32
SOFTWARE\Microsoft\Tracing\updateConstaSurf_RASMANCS
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{d7356335-81bf-4769-bfbd-2e2889138641}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D7356335-81BF-4769-BFBD-2E2889138641}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D7356335-81BF-4769-BFBD-2E2889138641}
Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{d7356335-81bf-4769-bfbd-2e2889138641}
SOFTWARE\Wow6432Node\ConstaSurf
SOFTWARE\Wow6432Node\Microsoft\Tracing\ConstaSurf_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\ConstaSurf_RASMANCS
SOFTWARE\Wow6432Node\Microsoft\Tracing\updateConstaSurf_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\updateConstaSurf_RASMANCS
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{d7356335-81bf-4769-bfbd-2e2889138641}
SYSTEM\ControlSet001\services\eventlog\Application\Update ConstaSurf
SYSTEM\ControlSet001\services\Update ConstaSurf
SYSTEM\ControlSet001\Services\Util ConstaSurf
SYSTEM\ControlSet002\Services\Util ConstaSurf
SYSTEM\CurrentControlSet\services\eventlog\Application\Update ConstaSurf
SYSTEM\CurrentControlSet\services\Update ConstaSurf
SYSTEM\CurrentControlSet\Services\Util ConstaSurf

Directories

ConstaSurf may create the following directory or directories:

%PROGRAMFILES%\ConstaSurf
%PROGRAMFILES(x86)%\ConstaSurf
%TEMP%\ConstaSurf

URLs

ConstaSurf may call the following URLs:

ConstaSurf

Trending

Most Viewed

Loading...