need help! removing "surfbar" spy/adware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by S0mE0nEsMiNd, Aug 31, 2003.

  1. S0mE0nEsMiNd

    S0mE0nEsMiNd Private E-2

    Somehow this annoying junk got on my comp, adaware with latest reference file cant get it tried searching coudnt find it. Iintegreates itself into internet explorer and also does random popups....any help this is a MUST or i swear I will reformat
     
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Got it

    Download Hijack This, which I just discovered was updated a few days back. That should fix you up. It is called Surferbar (AdPlus.AdBar) It appears to be brand new and not in the 2 most popular spyware programs, Spybot and Ad-Aware, so I posted this to the front page to help others learn from our experience.

    http://www.majorgeeks.com/download.php?det=3155


    --------------------------------------------------------------------------------------


    Heres my reference from Spybot forums if interested:

    Have Hijack This fix the following by placing a check in the appropriate boxes and hitting fix checked. Make sure all browser and all Windows Explorer windows are closed before fixing.

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.surferbar.com/

    O1 - Hosts: www.surferbar.com localhost That is really nasty... it redirects everything that points to localhost to surferbar....

    O3 - Toolbar: (no name) - {FE6BC4EF-5676-484B-88AE-883323913256} - (no file)
    O3 - Toolbar: SurferBar - {FF7FD490-34E7-4FA1-927A-F5799E6AAD7B} - c:\PROGRA~1\win32.dll

    O4 - HKLM\..\Run: [JWEO] D:\WINDOWS\JWEO.exe


    Reboot when done. Then find and delete:

    D:\WINDOWS\JWEO.exe


    http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi?;act=ST;f=32;t=5489
     
    Last edited: Aug 31, 2003
  3. S0mE0nEsMiNd

    S0mE0nEsMiNd Private E-2

    Thanks! I forgot how good Spybot S&D was too. That is VERY nasty like it says, you dont have to approve anything, and adaware and spybot havent found it yet.
     
  4. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Looks like they are aware of it now, I just edited my post to tell you that they dont have it in their current definition files for Ad-Aware or Spybot, its apparently that new :) I would assume it will be added within a day or two.


    For anyone else reading, its been my experience that the average computer user who has not scanned their computer in a month or two for spyware will usually find over 100 spyware items (I have seen it go over 400) which includes registry entries, folders and files, many that spy on you without you even knowing it.


    Ad-Aware:
    http://www.majorgeeks.com/download.php?det=506

    Spybot S&D:
    http://www.majorgeeks.com/download.php?det=2471

    Update before scanning, both programs offer web updaters built in. This updates the program to recognize the latest spyware, just like your anti virus program does.
     
    Last edited: Aug 31, 2003
  5. Maxwell

    Maxwell Folgers

    In addition to the scanners (AdAware and Spybot S&D) you could use SpywareBlaster 2.6 and SpywareGuard 2.1 to prevent a number of spyware objects from being installed in the first place.

    I've tried the first and it does leave AdAware and Spybot S&D with little to do.
     
  6. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Well, for me Ad-Aware was here before all these guys and on the cutting edge of finding and telling people about Spyware along with GRC, and saved me quite a few times, so since it was available for as cheap as 9.95, I bought the Plus version and it works excellent.
     
  7. razor

    razor Private E-2

    I used Hijack This and got rid of most of it :) , but ...surferbar.com keeps coming up as my start-page. and when I try to change it, the change doesn't stick even if I press Apply. Also it keep resetting my "view" options on all new pages :(
     
  8. razor

    razor Private E-2

  9. S0mE0nEsMiNd

    S0mE0nEsMiNd Private E-2

    razor-change your homepage to whatever you want...FIRST! then, remove it again with hijackthis
     
  10. razor

    razor Private E-2

    Thanks Some, I think I' m rid of it now !:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds