blockandsurfj.exe

The application blockandsurfj.exe has been detected as adware by 25 anti-malware scanners. This is part of the Revizer line of web browser extensions that inject 3rd-party advertisements in the user's web browser as well as setup a proxy server for the browser in order to track behaviors and display context based-ads from various partners (mostly adware).
MD5:
1f153de6096aa5d8fa0ee5b0274cb48d

SHA-1:
4bafdbcac3bc18da50f887fae8ccdfc99b5120f7

Scanner detections:
25 / 68

Status:
Adware

Analysis date:
4/19/2024 9:07:46 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Generic.642623
920

Agnitum Outpost
PUA.Agent
7.1.1

Avira AntiVirus
SPR/Tool.105472.2
7.11.152.222

avast!
Win32:Adware-gen [Adw]
2014.9-140730

AVG
Generic5
2015.0.3398

Baidu Antivirus
Adware.Win32.AddLyrics
4.0.3.14730

Bitdefender
Application.Generic.642623
1.0.20.1055

Comodo Security
Application.Win32.Adware.WDUnlocker.A
18428

Emsisoft Anti-Malware
Gen:Variant.Adware.AddLyrics.10
8.14.07.30.04

ESET NOD32
Win32/AdWare.AddLyrics.AO application
8.7.0.302.0

Fortinet FortiGate
Adware/Agent
9/10/2014

F-Secure
Application.Generic.642623
11.2014-30-07_4

G Data
Application.Generic.642623
14.7.24

herdProtect (fuzzy)
2014.9.10.6

Kaspersky
not-a-virus:AdWare.Win32.Agent
14.0.0.3484

McAfee
Artemis!F5196E42C60D
5600.7054

MicroWorld eScan
Application.Generic.642623
15.0.0.633

NANO AntiVirus
Riskware.Win32.Agent.dabcfo
0.28.0.60253

Panda Antivirus
Trj/OCJ.F
14.07.30.04

Qihoo 360 Security
Win32/Virus.Adware.3bf
1.0.0.1015

Reason Heuristics
Adware.Revizer.N
14.7.30.4

Sophos
Generic PUA BF
4.98

Trend Micro House Call
TROJ_GEN.R047H07F214
7.2.211

Vba32 AntiVirus
AdWare.Agent
3.12.26.0

VIPRE Antivirus
Threat.4150696
29800

File size:
103.5 KB (105,984 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\blockandsurf-soft\blockandsurfj.exe

File PE Metadata
Compilation timestamp:
6/1/2014 7:51:10 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
1536:zb0F6Y5a21SSxHX8V+WiVJiLKK99Rd/5cdY3sWjcdCyE+Mslqhi:zb0FawpfpmzgY4g+Mslqhi

Entry address:
0x5D0A

Entry point:
E8, 9E, 3F, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 83, 25, FC, 72, 41, 00, 00, 83, EC, 10, 53, 33, DB, 43, 09, 1D, 48, 60, 41, 00, 6A, 0A, E8, F8, 70, 00, 00, 85, C0, 0F, 84, 0E, 01, 00, 00, 33, C9, 8B, C3, 89, 1D, FC, 72, 41, 00, 0F, A2, 56, 8B, 35, 48, 60, 41, 00, 57, 8D, 7D, F0, 83, CE, 02, 89, 07, 89, 5F, 04, 89, 4F, 08, 89, 57, 0C, F7, 45, F8, 00, 00, 10, 00, 89, 35, 48, 60, 41, 00, 74, 13, 83, CE, 04, C7, 05, FC, 72, 41, 00, 02, 00, 00, 00, 89, 35, 48, 60, 41, 00, F7, 45, F8, 00, 00, 00, 10, 74, 13...
 
[+]

Entropy:
5.7417

Code size:
53 KB (54,272 bytes)

Remove blockandsurfj.exe - Powered by Reason Core Security