Remove SurferBar. Description and removal instructions

 
Title: SurferBar

Type: Trojans
Severity scale:SurferBar severity is 69  (69 / 100)
 
Surferbar is an Internet Explorer toolbar that might be associated with a new version of a trojan horse program called AFlooder. This Trojan program usually arrives as an embedded malicious script in a specially crafted HTML-based email or Web site. It sets your homepage to their website, and also displays pop-ups.


SurferBar properties:
• Changes browser settings
• Shows commercial adverts
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic SurferBar removal:

remover for SurferBar

SurferBar manual removal:

Kill processes:
winsrv32.exe, wins32.exe
Delete registry values:
Browse to the key:
HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Run \ Once
Delete the entry 'c:\program files\winsrv32.exe' or 'c:\program files\wins32.exe'
Delete files:
win32.dll, winsrv32.exe, drg.exe, wins32.exe, sfbar.exe

Other programs to remove SurferBar:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 19/03/04
Information updated: 20/04/04

Additional resources related to SurferBar:

Attention: If you know or you have a website or page about SurferBar removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about SurferBar parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:


Comments from visitors:


1. by Just user. 2004-03-01 09:46:50
- The old homepage at surferbar.com seems to have died.
- The new AFlooder variant is an irc trojan/spybot that uses worm techniques to spread to machines via web pages. It is apparently coded to have qualities of remote access trojans, IRC bots, keyloggers, and even seems to have the capability to carry out DDoS attacks if the owner orders it to. It uses an exploit to write and execute its' injector program to machines without the user's acceptance or knowledge, then it uses NTFS's alternate file streams to hide itself where there's very little chance of finding it -- in the actual windows folder system32.


Latest spyware news:
Similar parasites: