Caution scammer !!!
After downloading the surfbar and launching it, an executable file is added to the autoload. After that, this program begins to replace the Bitcoin addresses in your clipboard. You will send money to this scammer without knowing it.
It is good that I noticed it in time and did not manage to send anything to false addresses.
I checked everything several times - the file in autoload appears only after launching their surfbar! Bypass this site and do not download anything from it! Antiviruses do not see the file and do not react in any way.
If someone has already encountered this problem: the name of the file at startup is startup.exe
The process name in the task manager: startup.exe - live translator
i can also confirm that i had the same thing happen when sandboxed, and it also keeps running another program in the background that is added to the program's folder called config.bat. it used to be called synchronize.exe and still has the old name hidden within it. it will keep running when you close the surf bar and send data somewhere with a lot of cpu usage but it is not clear what is being sent or why. more info can also be found on
https://www.virustotal.com/#/file/a2177cc734a4c7d15fe696bf57e07cc7b4ca2aef2f37539a4596aab0ca5d7625/detailsto fully close the app you will have to close synchronize.exe too through the task manager
okay, so i found it opens and tries to send the following files
C:\DOCUME~1\~1\LOCALS~1\Temp\~DF6A7E.tmp
C:\conf.dat
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\1025\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\1025\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\1025\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\1028\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\1028\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\1028\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\1031\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\1031\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\1031\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\1033\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\1033\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\1033\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\1037\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\1037\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\1037\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\1041\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\1041\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\1041\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\1042\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\1042\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\1042\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\1054\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\1054\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\1054\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\2052\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\2052\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\2052\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\3076\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\3076\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\3076\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\3com_dmi\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\3com_dmi\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\3com_dmi\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\CatRoot\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\CatRoot\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\CatRoot\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\CatRoot2\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\CatRoot2\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\CatRoot2\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\Com\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\Com\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\Com\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\config\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\config\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\config\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\dhcp\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\dhcp\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\dhcp\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\DirectX\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\DirectX\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\DirectX\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\drivers\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\drivers\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\drivers\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\DRVSTORE\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\DRVSTORE\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\DRVSTORE\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\en\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\en\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\en\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\en-US\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\en-US\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\en-US\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\export\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\export\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\export\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\ias\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\ias\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\ias\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\icsxml\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\icsxml\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\icsxml\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\IME\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\IME\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\IME\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\inetsrv\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\inetsrv\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\inetsrv\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\Macromed\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\Macromed\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\Macromed\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\Microsoft\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\Microsoft\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\Microsoft\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\MsDtc\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\MsDtc\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\MsDtc\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\mui\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\mui\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\mui\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\npp\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\npp\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\npp\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\oobe\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\oobe\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\oobe\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\ras\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\ras\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\ras\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\ReinstallBackups\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\ReinstallBackups\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\ReinstallBackups\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\Restore\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\Restore\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\Restore\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\scripting\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\scripting\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\scripting\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\Setup\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\Setup\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\Setup\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\ShellExt\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\ShellExt\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\ShellExt\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\SoftwareDistribution\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\SoftwareDistribution\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\SoftwareDistribution\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\spool\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\spool\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\spool\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\usmt\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\usmt\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\usmt\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\wbem\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\wbem\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\wbem\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\wins\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\wins\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\wins\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\xircom\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\xircom\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\xircom\key4.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\XPSViewer\logins.json
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\XPSViewer\key3.db
C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\C:\WINDOWS\system32\XPSViewer\key4.db
C:\WINDOWS\Registration\R000000000007.clb
i am not sure if the links in it are broken or that is just how it is reported in sandbox mode but logins.json holds encrypted usernames and passwords and key4.db is the decryption key for them so it is trying to access anything in firefox and send it to the hacker. it downloads the payload through terminal and also hooks into user32.dll with this
"Ad2Bitcoin.exe" wrote bytes "71115d007a3b5c00ab8b02007f950200fc8c0200729602006cc805001ecd59007d265900" to virtual address "0x76FF07E4" (part of module "USER32.DLL")