RightSurf

RightSurf Description

RightSurf is adware that may show random pop-up ads and messages carrying discounts, offers and coupons when PC users are visiting online shopping or other similar websites. RightSurf may be embedded into Internet Explorer, Mozilla Firefox and Google Chrome Web browser without a computer user's approval. RightSurf may commonly propagate packed with freeware that PC users can download from the Internet. When the PC user decides to download and install a specific free program, it may carry extra toolbars, browser plug-ins and add-ons inserted into the installation wizard. These extra tools, specifically, RightSurf may be marked as optional apps, but if the PC user does not unmark a check box to embed them, he may end up facing undesired system modifications on the computer system. RightSurf may trace the PC user's browsing activity and transfer collected information to third-parties for the purpose of targeted advertising.

Aliases: a variant of Win32/BrowseFox.G, Trojan/Win32.Zapchast [AhnLab-V3], TROJ_GEN.F47V0125, Artemis!5215978785A6 [McAfee], a variant of Win32/BrowseFox.F, Win32.Troj.Agent.ah.(kcloud), AdWare/Win32.Agent [Antiy-AVL], Generic PUA PP [Sophos], Application.Win32.Altbrowse.AK [Comodo], not-a-virus:AdWare.Win32.Agent.ahbx [Kaspersky], TROJ_GEN.F47V0123, Riskware.Win32.Agent.crkvek and PUP.Optional.RightSurf.A.

Technical Information

File System Details

RightSurf creates the following file(s):
# File Name Size MD5 Detection Count
1 system32\drivers\wStLib64.sys 61,112 19f3aa4ab1fc1dd459422c30ade6310a 3,562
2 %WINDIR%\System32\drivers\wStLibG.sys 52,920 885f98228654316c8fbb53ce3d71c335 2,451
3 %WINDIR%\System32\drivers\tStLibG.sys 55,224 fb53cf4dc88f5264030bcaa29ee8e548 2,042
4 %WINDIR%\System32\drivers\tStLib.sys 55,224 d035871f2339c43d0af7ae9ffb73dfef 1,791
5 %PROGRAMFILES(x86)%\RightSurf\bin\FilterApp_C64.exe 287,008 cfb902dbe33f51294c4fcbdb061a5b7a 1,101
6 %PROGRAMFILES%\RightSurf\bin\FilterApp_C.exe 238,880 10ed03837ae22188cdf10b9fbd68fbc0 825
7 %PROGRAMFILES(x86)%\RightSurf\bin\RightSurf.BrowserAdapter.exe 95,520 97f1d9ad4f09939b1ae9d2af25644855 517
8 %PROGRAMFILES(x86)%\RightSurf\updateRightSurf.exe 97,056 4f59c31f94a05093e3c355823c9d42ef 453
9 %PROGRAMFILES%\RightSurf\bin\utilRightSurf.exe 97,056 ed7d64d4b503155abfe12b7f6661739d 269
10 %PROGRAMFILES(x86)%\RightSurf\bin\XTLSApp.exe 78,624 a8ea010e0885c649625a53aef35d957d 186
11 %TEMP%\is357113909\2984868_stp\RightSurfSetup.exe 231,744 7b6eeba32a72b72f92c55d7ac6f4a3bd 54
12 %PROGRAMFILES(x86)%\RightSurf\RightSurf.FirstRun.exe 1,088,800 a43dcd01e262e70bf802666f7e902512 47
13 %TEMP%\RightSurf\RightSurf_Setup.exe 2,172,872 2b450c618b761e76e2c3d752e0b77e88 8
14 %PROGRAMFILES%\RightSurf\RightSurfbho.dll 249,632 a21837181ae19d18aba97cd81bdf3d8f 1
15 %PROGRAMFILES%\RightSurf\RightSurfuninstall.exe 241,288 af8f3986ec529b59e5a1bb73d56a8a7f 1
More files

Registry Details

RightSurf creates the following registry entry or registry entries:
Registry key
SOFTWARE\Google\Chrome\Extensions\ajjpgnlpolfpnebjjaciccmmjnmjfjkl
Software\Microsoft\Internet Explorer\Approved Extensions\{88BE1AA9-6740-461C-9E3E-F35EB8FA741C}
SOFTWARE\Microsoft\Tracing\RightSurf_RASAPI32
SOFTWARE\Microsoft\Tracing\RightSurf_RASMANCS
SOFTWARE\Microsoft\Tracing\updateRightSurf_RASAPI32
SOFTWARE\Microsoft\Tracing\updateRightSurf_RASMANCS
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{88be1aa9-6740-461c-9e3e-f35eb8fa741c}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{88BE1AA9-6740-461C-9E3E-F35EB8FA741C}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{88BE1AA9-6740-461C-9E3E-F35EB8FA741C}
Software\RightSurf
SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ajjpgnlpolfpnebjjaciccmmjnmjfjkl
SOFTWARE\Wow6432Node\Microsoft\Tracing\RightSurf_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\RightSurf_RASMANCS
SOFTWARE\Wow6432Node\Microsoft\Tracing\updateRightSurf_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\updateRightSurf_RASMANCS
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{88be1aa9-6740-461c-9e3e-f35eb8fa741c}
SOFTWARE\Wow6432Node\RightSurf
SYSTEM\ControlSet001\services\eventlog\Application\Update RightSurf
SYSTEM\ControlSet001\services\Update RightSurf
SYSTEM\ControlSet001\Services\Util RightSurf
SYSTEM\ControlSet002\Services\Util RightSurf
SYSTEM\CurrentControlSet\services\eventlog\Application\Update RightSurf
SYSTEM\CurrentControlSet\services\Update RightSurf
SYSTEM\CurrentControlSet\Services\Util RightSurf
Uninstaller
RightSurf
File name without path
chrome-extension_ajjpgnlpolfpnebjjaciccmmjnmjfjkl_0.localstorage
chrome-extension_ajjpgnlpolfpnebjjaciccmmjnmjfjkl_0.localstorage-journal
Directory
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\ajjpgnlpolfpnebjjaciccmmjnmjfjkl
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Local Extension Settings\ajjpgnlpolfpnebjjaciccmmjnmjfjkl
%PROGRAMFILES%\RightSurf
%PROGRAMFILES(x86)%\RightSurf
CLSID
{88be1aa9-6740-461c-9e3e-f35eb8fa741c}
{A4F32137-598E-41B6-B601-9965084C8F08}
{C64BA349-1F34-4BFC-8D23-A317279D0CB9}

Site Disclaimer

Enigmasoftware.com is not associated, affiliated, sponsored or owned by the malware creators or distributors mentioned on this article. This article should NOT be mistaken or confused in being associated in any way with the promotion or endorsement of malware. Our intent is to provide information that will educate computer users on how to detect, and ultimately remove, malware from their computer with the help of SpyHunter and/or manual removal instructions provided on this article.

This article is provided "as is" and to be used for educational information purposes only. By following any instructions on this article, you agree to be bound by the disclaimer. We make no guarantees that this article will help you completely remove the malware threats on your computer. Spyware changes regularly; therefore, it is difficult to fully clean an infected machine through manual means.

Leave a Reply

Please DO NOT use this comment system for support or billing questions. For SpyHunter technical support requests, please contact our technical support team directly by opening a customer support ticket via your SpyHunter. For billing issues, please refer to our "Billing Questions or Problems?" page. For general inquiries (complaints, legal, press, marketing, copyright), visit our "Inquiries and Feedback" page.