ConstaSurf

ConstaSurf

Known Adware

by Yontoo Technology, Inc.

What is ConstaSurf?

ConstaSurf is software application developed by Yontoo Technology, Inc.. It is most commonly found on computers running Windows 7 with nearly 59.47% of installations running this operating system. ConstaSurf's installer is typically 2.00 MB in size and installs around 41 files. The most common release is 2014.06.13.224637 with 1.54% of all installations currently using this version.

ConstaSurf is most popular in the United States with 46.11% of installations residing in this country.

About ConstaSurf?

ConSurf is a browser extension designed to inject advertising and redirect web searches. It operates as a Browser Helper Object in Internet Explorer and is known to hijack advertising on non-associated websites. The add-in injects advertising in the form of contextual link ads, banner ads, popups, and pop-overs, including on well-known ad serving sites. This adware is often bundled with unwanted third-party applications and distributed through web browser exploits. Its functionality includes injecting advertising in the form of contextual ads, links, and pop-ups.

Multiple virus scanners have detected malware in ConstaSurf.

updateConstaSurf.exe (MD5: dfb0f3e9bc199415e9de334b3dc06f0c) has been flagged by 41 scanners:
Scanner Software Result
Lavasoft Ad-Aware Adware.SwiftBrowse.N
Agnitum Outpost Riskware.Agent!
AhnLab-V3 PUP/Win32.Generic
Antiy-AVL GrayWare[AdWare:not-a-virus,HEUR]/MSIL.Kranet
avast! Win32:BrowseFox-AC [PUP]
AVG Consurf
Avira ADWARE/BrowseFox.Gen7
AVware Yontoo (fs)
Baidu-International Adware.Win32.BrowseFox.BI
Bitdefender Adware.SwiftBrowse.N
CAT-QuickHeal AdWare.MSIL.r3 (Not a Virus)
Comodo Security ApplicUnwnt
Dr.Web Trojan.BPlug.250
Emsisoft Anti-Malware Adware.SwiftBrowse.N (B)
ESET-NOD32 a variant of Win32/BrowseFox.H
Fortinet FortiGate Adware/Kranet
F-Secure Adware.SwiftBrowse.N
G Data Adware.SwiftBrowse.N
IKARUS anti.virus PUA.BrowseFox
K7 AntiVirus Trojan ( 0049f7ad1 )
K7GW Trojan ( 0049f7ad1 )
Kaspersky not-a-virus:HEUR:AdWare.MSIL.Kranet.heur
Malwarebytes PUP.Optional.ConstaSurf.A
McAfee BrowseFox.c
McAfee-GW-Edition BrowseFox.c
MicroWorld-eScan Adware.SwiftBrowse.N
nProtect Adware.SwiftBrowse.N
Panda Antivirus Trj/Chgt.G
Qihoo-360 Win32/Virus.Adware.708
Sophos Browse Fox
Symantec Trojan.Gen.2
Tencent Win32.Trojan.Falsesign.Wwea
Trend Micro TROJ_GEN.R047C0EJH14
TrendMicro-HouseCall TROJ_GEN.R047C0EJH14
VIPRE Antivirus Yontoo (fs)
Zillya Backdoor.PePatch.Win32.46235
Avira AntiVir APPL/BrowseFox.Gen2
Kingsoft AntiVirus Win32.Troj.Agent.ah.(kcloud)
NANO AntiVirus Riskware.Win32.Agent.cqycvd
SUPERAntiSpyware Adware.BrowseFox/Variant
Vba32 AntiVirus AdWare.Agent
ConstaSurfBHO.dll (MD5: 52cf76ff95902cf8f4b0992e8b2290a5) has been flagged by 49 scanners:
Scanner Software Result
Lavasoft Ad-Aware Adware.SwiftBrowse.N
Agnitum Outpost Riskware.Agent!
AhnLab-V3 PUP/Win32.BrowseFox
ALYac Adware.SwiftBrowse.N
Arcabit Adware.SwiftBrowse.N
avast! Win32:BrowseFox-AC [PUP]
AVG AdPlugin.DIY
Avira ADWARE/BrowseFox.apf
AVware Yontoo (fs)
Baidu-International Adware.Win32.BrowseFox.AE
Bitdefender Adware.SwiftBrowse.N
Bkav FE W32.BrowseFoxAC.Adware
CAT-QuickHeal PUA.Constasurf.Gen
Clam AntiVirus Win.Adware.Agent-48082
Comodo Security ApplicUnwnt
Cyren W32/S-304afd20!Eldorado
Dr.Web Trojan.Yontoo.1734
Emsisoft Anti-Malware Adware.SwiftBrowse.N (B)
ESET-NOD32 a variant of Win32/BrowseFox.AE potentially unwanted
Fortinet FortiGate Adware/BrowseFox
F-Prot W32/S-304afd20!Eldorado
F-Secure Adware.SwiftBrowse.N
G Data Adware.SwiftBrowse.N
IKARUS anti.virus PUA.BrowseFox
Jiangmin AdWare/SwiftBrowse.dxt
K7 AntiVirus Adware ( 004b8df51 )
K7GW Adware ( 004b8df51 )
Malwarebytes PUP.Optional.ConstaSurf.A
McAfee BrowseFox
McAfee-GW-Edition BrowseFox
MicroWorld-eScan Adware.SwiftBrowse.N
NANO AntiVirus Trojan.Win32.Yontoo.dnkubo
nProtect Adware.SwiftBrowse.N
Panda Antivirus Trj/CI.A
Qihoo-360 Win32/Virus.Adware.4f7
Rising Antivirus PE:Trojan.Win32.Generic.180AB115!403353877
Sophos Browse Fox (PUA)
SUPERAntiSpyware Adware.Riskware/Variant
Symantec PUA.Yontoo.C
Trend Micro TROJ_GEN.R00UC0EBB15
Vba32 AntiVirus AdWare.MSIL.Agent
VIPRE Antivirus Yontoo (fs)
Zillya Adware.BrowseFox.Win32.8717
Antiy-AVL GrayWare[AdWare:not-a-virus,HEUR]/MSIL.Kranet
Kaspersky not-a-virus:HEUR:AdWare.MSIL.Kranet.heur
Tencent Win32.Trojan.Falsesign.Wwea
TrendMicro-HouseCall TROJ_GEN.R047C0EJH14
Avira AntiVir APPL/BrowseFox.Gen2
Kingsoft AntiVirus Win32.Troj.Agent.ah.(kcloud)
71A8372B-B4E5-4463-B982-39E380902274.dll (MD5: 0924f3764acf7efd13df34bb9dee8fd4) has been flagged by 49 scanners:
Scanner Software Result
Lavasoft Ad-Aware Adware.SwiftBrowse.N
Agnitum Outpost PUA.Agent
Avira AntiVir APPL/BrowseFox.Gen2
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.Agent
AVG BrowseFox.F
Baidu-International Adware.Win32.BrowseFox.bF
Bitdefender Adware.SwiftBrowse.N
Comodo Security Application.Win32.Altbrowse.AK
Dr.Web Trojan.BPlug.17
Emsisoft Anti-Malware Adware.SwiftBrowse.N
ESET-NOD32 a variant of Win32/BrowseFox.F
Fortinet FortiGate Adware/Agent
G Data Adware.SwiftBrowse
IKARUS anti.virus not-a-virus:AdWare.Win32.Agent
K7 AntiVirus Unwanted-Program
K7GW Unwanted-Program ( 00454f261 )
Kaspersky not-a-virus:AdWare.Win32.Agent
Kingsoft AntiVirus Win32.Troj.Agent.ah.(kcloud)
Malwarebytes PUP.Optional.ConstaSurf.A
McAfee Artemis!0924F3764ACF
McAfee-GW-Edition Artemis!0924F3764ACF
MicroWorld-eScan Adware.SwiftBrowse.N
NANO AntiVirus Riskware.Win32.Agent.cqycvd
nProtect Adware.SwiftBrowse.N
Panda Antivirus Trj/CI.A
Sophos Generic PUA IF
SUPERAntiSpyware Adware.BrowseFox/Variant
TrendMicro-HouseCall Suspicious_GEN.F47V0614
Vba32 AntiVirus AdWare.Agent
VIPRE Antivirus Yontoo (fs)
AhnLab-V3 PUP/Win32.BrowseFox
ALYac Adware.SwiftBrowse.N
Arcabit Adware.SwiftBrowse.N
avast! Win32:BrowseFox-AC [PUP]
Avira ADWARE/BrowseFox.apf
AVware Yontoo (fs)
Bkav FE W32.BrowseFoxAC.Adware
CAT-QuickHeal PUA.Constasurf.Gen
Clam AntiVirus Win.Adware.Agent-48082
Cyren W32/S-304afd20!Eldorado
F-Prot W32/S-304afd20!Eldorado
F-Secure Adware.SwiftBrowse.N
Jiangmin AdWare/SwiftBrowse.dxt
Qihoo-360 Win32/Virus.Adware.4f7
Rising Antivirus PE:Trojan.Win32.Generic.180AB115!403353877
Symantec PUA.Yontoo.C
Trend Micro TROJ_GEN.R00UC0EBB15
Zillya Adware.BrowseFox.Win32.8717
Tencent Win32.Trojan.Falsesign.Wwea
6B4ED544-12FB-4E23-8808-29BE760D57FD.dll (MD5: 5a64be16e215a39032ce1f7b5266bcfb) has been flagged by 33 scanners:
Scanner Software Result
Lavasoft Ad-Aware Adware.SwiftBrowse.N
Agnitum Outpost PUA.Agent!
Avira AntiVir APPL/BrowseFox.Gen2
AVG BrowseFox.F
Baidu-International Adware.Win32.Agent.APX
Bitdefender Adware.SwiftBrowse.N
Comodo Security Application.Win32.Altbrowse.AK
Dr.Web Trojan.BPlug.17
Emsisoft Anti-Malware Adware.SwiftBrowse.N (B)
ESET-NOD32 a variant of Win32/BrowseFox.F
Fortinet FortiGate Adware/Agent
F-Secure Adware.SwiftBrowse.N
G Data Adware.SwiftBrowse.N
IKARUS anti.virus not-a-virus:AdWare.Win32.Agent
K7 AntiVirus Unwanted-Program ( 00454f261 )
K7GW Unwanted-Program ( 00454f261 )
Kaspersky not-a-virus:AdWare.Win32.Agent.ahbx
Kingsoft AntiVirus Win32.Troj.Agent.ah.(kcloud)
Malwarebytes PUP.Optional.ConstaSurf.A
McAfee Artemis!5A64BE16E215
McAfee-GW-Edition Artemis!5A64BE16E215
MicroWorld-eScan Adware.SwiftBrowse.N
NANO AntiVirus Riskware.Win32.Agent.cqycvd
nProtect Adware.SwiftBrowse.N
Panda Antivirus Trj/CI.A
Qihoo-360 Win32/Trojan.Adware.5a2
Sophos Generic PUA CD
SUPERAntiSpyware Adware.BrowseFox/Variant
TrendMicro-HouseCall Suspicious_GEN.F47V0610
Vba32 AntiVirus AdWare.Agent
VIPRE Antivirus Yontoo (fs)
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.Agent
CAT-QuickHeal AdWare.Agent.r5 (Not a Virus)
6580EF5E-A748-4AD0-998E-01DFE09286D2.dll (MD5: c7985194e9c9646b0569e1ce4c9b0f52) has been flagged by 30 scanners:
Scanner Software Result
Lavasoft Ad-Aware Adware.SwiftBrowse.N
Agnitum Outpost PUA.Agent!
Avira AntiVir APPL/BrowseFox.Gen2
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.Agent
AVG BrowseFox.F
Bitdefender Adware.SwiftBrowse.N
CAT-QuickHeal AdWare.Agent.r5 (Not a Virus)
Comodo Security Application.Win32.Altbrowse.AK
Dr.Web Trojan.BPlug.17
Emsisoft Anti-Malware Adware.SwiftBrowse.N (B)
ESET-NOD32 a variant of Win32/BrowseFox.F
Fortinet FortiGate Adware/Agent
F-Secure Adware.SwiftBrowse.N
G Data Adware.SwiftBrowse.N
IKARUS anti.virus not-a-virus:AdWare.Win32.Agent
K7 AntiVirus Unwanted-Program ( 00454f261 )
K7GW Unwanted-Program ( 00454f261 )
Kaspersky not-a-virus:AdWare.Win32.Agent.ahbx
Kingsoft AntiVirus Win32.Troj.Agent.ah.(kcloud)
Malwarebytes PUP.Optional.ConstaSurf.A
McAfee Artemis!C7985194E9C9
McAfee-GW-Edition Artemis!C7985194E9C9
MicroWorld-eScan Adware.SwiftBrowse.N
NANO AntiVirus Riskware.Win32.Agent.cqycvd
Panda Antivirus Trj/CI.A
Sophos Generic PUA AK
SUPERAntiSpyware Adware.BrowseFox/Variant
TrendMicro-HouseCall TROJ_GEN.F47V0501
Vba32 AntiVirus AdWare.Agent
VIPRE Antivirus Yontoo (fs)

Software Behaviors

Services:
  • updateConstaSurf.exe runs as a service named 'Util ConstaSurf' (Util ConstaSurf).

Software Details

URL:
https://constasurf.info/support
Support:
https://mailto:
Installation path:
C:\Program Files\ConstaSurf
Uninstaller:
C:\Program Files\ConstaSurf\ConstaSurfuninstall.exe
Size:
2.00 MB
Language:
English

ConstaSurf Executable Details

Name:
ConstaSurf
Path:
C:\Program Files\ConstaSurf\71A8372B-B4E5-4463-B982-39E380902274.dll
MD5:
0924f3764acf7efd13df34bb9dee8fd4
SHA-1:
–
SHA-256:
–
Files installed by ConstaSurf
File Type Filename MD5
EXE
e92604e043f51c604b6d1ac3bcd3a202
EXE
c5bc3d856c77bc50fb4f06591205e1b1
EXE
dfb0f3e9bc199415e9de334b3dc06f0c
CRX
3d2fb6d853fa0e98ed42454077eb7e02
EXE
7d5e6d0d91ced70580de6594f84c153b
EXE
3579ec208d243217d4ae82a6db3874d5
EXE
501b92eda26cfda868440baf613468bc
DLL
9c336c994072742ec48799745ae16dac
DLL
5a64be16e215a39032ce1f7b5266bcfb
DLL
ecf9187e7c24e3585ff9b690808e8c38