RightSurf
What is RightSurf?
RightSurf is software application developed by Yontoo Technology, Inc.. It is most commonly found on computers running Windows 7 with nearly 61.03% of installations running this operating system. RightSurf's installer is typically 1.00 MB in size and installs around 11 files. The most common release is 2014.02.01.021226 with 18.60% of all installations currently using this version.
RightSurf is most popular in the United States with 30.17% of installations residing in this country.
About RightSurf?
RightSurf is a web browser extension designed to serve various types of advertisements, including popups and banners, and modify the user's browser settings. These ads aim to promote the installation of additional software in order to generate pay-per-click revenue for the publisher. Potential symptoms of infection with RightSurf may include hyperlinks appearing in random web page text, pop-up ads with red "click here" buttons, and the installation of unwanted adware programs without the user's knowledge. Browser popups recommending fake updates or other software may also appear, and web pages may become slow to download due to the presence of multiple ads. Please note that RightSurf may have evolved since this description was last updated, and it is important to stay informed about the latest developments in adware and malware.
Multiple virus scanners have detected malware in RightSurf.
Scanner Software | Version | Result |
---|---|---|
Lavasoft Ad-Aware | 12.0.163.0 | Adware.SwiftBrowse.V |
AhnLab-V3 | 2015.04.02.00 | Win-PUP/BrowseFox.Gen |
ALYac | 1.0.1.4 | Adware.SwiftBrowse.V |
Antiy-AVL | 1.0.0.1 | Trojan/Win32.TSGeneric |
avast! | 8.0.1489.320 | Win32:BrowseFox-DQ [PUP] |
AVG | 15.0.0.4321 | Generic.5CD |
Avira | 3.6.1.96 | ADWARE/BrowseFox.apk |
AVware | 1.5.0.21 | Yontoo (fs) |
Baidu-International | 3.5.1.41473 | Adware.MSIL.BrowseFox.H |
Bitdefender | 7.2 | Adware.SwiftBrowse.V |
Bkav FE | 1.3.0.6379 | W32.HfsAdware.6B89 |
Comodo Security | 21611 | UnclassifiedMalware |
Cyren | 5.4.16.7 | W32/S-7b6eb46a!Eldorado |
Dr.Web | 7.0.12.3050 | Trojan.Yontoo.1741 |
Emsisoft Anti-Malware | 3.0.0.600 | Adware.SwiftBrowse.V (B) |
ESET-NOD32 | 11410 | a variant of MSIL/BrowseFox.H potentially unwanted |
F-Prot | 4.7.1.166 | W32/S-7b6eb46a!Eldorado |
F-Secure | 11.0.19100.45 | Adware.SwiftBrowse.V |
G Data | 25 | Adware.SwiftBrowse.V |
IKARUS anti.virus | T3.1.8.9.0 | PUA.MSIL.BrowseFox |
K7 AntiVirus | 9.202.15452 | Unwanted-Program ( 0040f96c1 ) |
K7GW | 9.202.15451 | Unwanted-Program ( 0040f96c1 ) |
Malwarebytes | 1.75.0.1 | PUP.Optional.RightSurf.A |
McAfee | 6.0.5.614 | BrowseFox-FSL |
McAfee-GW-Edition | v2015 | BrowseFox-FSL |
MicroWorld-eScan | 12.0.250.0 | Adware.SwiftBrowse.V |
NANO AntiVirus | 0.30.8.659 | Riskware.Win32.BPlug.djpkri |
nProtect | 2015-04-01.01 | Adware.SwiftBrowse.V |
Panda Antivirus | 4.6.4.2 | Generic Suspicious |
Sophos | 4.98.0 | RightSurf |
Symantec | 20141.2.0.56 | Trojan.Gen.2 |
Tencent | 1.0.0.1 | Trojan.Win32.Qudamah.Gen.18 |
Trend Micro | 9.740.0.1012 | TROJ_GEN.R0C1C0EL114 |
TrendMicro-HouseCall | 9.700.0.1001 | TROJ_GEN.R0C1C0EL114 |
VIPRE Antivirus | 38960 | Yontoo (fs) |
Scanner Software | Version | Result |
---|---|---|
Antiy-AVL | 2.0.3.7 | AdWare/Win32.Agent |
Comodo Security | 17662 | Application.Win32.Altbrowse.AK |
ESET-NOD32 | 8.9329 | a variant of Win32/BrowseFox.F |
Kaspersky | 14.0.0.4406 | not-a-virus:AdWare.Win32.Agent |
Kingsoft AntiVirus | 331020.49267 | Win32.Troj.Agent.ah.(kcloud) |
Malwarebytes | v2014.01.26.09 | PUP.Optional.RightSurf.A |
NANO AntiVirus | 0.28.0.57380 | Riskware.Win32.Agent.crkvek |
Sophos | 4.97 | Generic PUA PP |
TrendMicro-HouseCall | 7.2.26 | TROJ_GEN.F47V0123 |
Lavasoft Ad-Aware | 12.0.163.0 | Adware.SwiftBrowse.V |
AhnLab-V3 | 2015.04.02.00 | Win-PUP/BrowseFox.Gen |
ALYac | 1.0.1.4 | Adware.SwiftBrowse.V |
avast! | 8.0.1489.320 | Win32:BrowseFox-DQ [PUP] |
AVG | 15.0.0.4321 | Generic.5CD |
Avira | 3.6.1.96 | ADWARE/BrowseFox.apk |
AVware | 1.5.0.21 | Yontoo (fs) |
Baidu-International | 3.5.1.41473 | Adware.MSIL.BrowseFox.H |
Bitdefender | 7.2 | Adware.SwiftBrowse.V |
Bkav FE | 1.3.0.6379 | W32.HfsAdware.6B89 |
Cyren | 5.4.16.7 | W32/S-7b6eb46a!Eldorado |
Dr.Web | 7.0.12.3050 | Trojan.Yontoo.1741 |
Emsisoft Anti-Malware | 3.0.0.600 | Adware.SwiftBrowse.V (B) |
F-Prot | 4.7.1.166 | W32/S-7b6eb46a!Eldorado |
F-Secure | 11.0.19100.45 | Adware.SwiftBrowse.V |
G Data | 25 | Adware.SwiftBrowse.V |
IKARUS anti.virus | T3.1.8.9.0 | PUA.MSIL.BrowseFox |
K7 AntiVirus | 9.202.15452 | Unwanted-Program ( 0040f96c1 ) |
K7GW | 9.202.15451 | Unwanted-Program ( 0040f96c1 ) |
McAfee | 6.0.5.614 | BrowseFox-FSL |
McAfee-GW-Edition | v2015 | BrowseFox-FSL |
MicroWorld-eScan | 12.0.250.0 | Adware.SwiftBrowse.V |
nProtect | 2015-04-01.01 | Adware.SwiftBrowse.V |
Panda Antivirus | 4.6.4.2 | Generic Suspicious |
Symantec | 20141.2.0.56 | Trojan.Gen.2 |
Tencent | 1.0.0.1 | Trojan.Win32.Qudamah.Gen.18 |
Trend Micro | 9.740.0.1012 | TROJ_GEN.R0C1C0EL114 |
VIPRE Antivirus | 38960 | Yontoo (fs) |
Software Behaviors
- Services:
-
- updateRightSurf.exe runs as a service named 'Update RightSurf' (Update RightSurf).
Software Details
- URL:
- https://rightsurf.info/support
- Support:
- https://mailto:
- Installation path:
- C:\Program Files\RightSurf
- Uninstaller:
- C:\Program Files\RightSurf\RightSurfuninstall.exe
- Size:
- 1.00 MB
- Language:
- English
RightSurf Executable Details
- Primary executable:
- RightSurfBHO.dll
- Name:
- RightSurf
- Path:
- C:\Program Files\RightSurf\RightSurfBHO.dll
- MD5:
- 526da03eed21c16f38fd35320a9b99ce
- SHA-1:
- –
- SHA-256:
- –
File Type | Filename | MD5 |
---|---|---|
EXE
|
c3b44da13a8e972809780c2f64c6683a | |
EXE
|
0b86536bba2a922f5f32ad1792d8a03b | |
EXE
|
updateRightSurf.exe
Malware
|
9f1ef46545971a4d9abab76cbe2c9dda |
DLL
|
RightSurfBHO.dll
Malware
|
526da03eed21c16f38fd35320a9b99ce |
EXE
|
0a675632ae68f54c25c3d5b5b7af4b8d | |
EXE
|
50d1b7300fba7522f4a6a202401e327d | |
DLL
|
8cf18ff2070b57a2cf0f7efd9a1f3303 | |
EXE
|
1b27ba116b519bb3bac1cf09c63823f8 | |
EXE
|
3334119ccdc37f2f1a897bb0862547d5 | |
CRX
|
785852859122a08d1c4e3d9fa37ec252 |