Home  ::  Search  ::  Downloads  ::  Your Account  ::  Forums  ::  Top 10
  Create an account
::  Random Quotes  ::
He was the kind of man who was not ashamed to show affection. I guess that's what I hated about him.
-- Deep Thoughts by Jack Handey
::  Main Menu  ::
 Home
· HFT Support Forums
· My Online Journal
 General
 All Articles!
 Content
Accès réservé aux membres Downloads
 Encyclopedia
 FAQ
 Feedback
 Legal_Notices
 PCS Photo Gallery
 Recommend Us
 Search
 Stories Archive
Accès réservé aux membres Submit News!
 Topics
 Trend_Virus_Info
 Web Links
 Members
Accès réservé aux membres Members List
Accès réservé aux membres Private Messages
Accès réservé aux membres Profile
 Your Account
 Interact!
Accès réservé aux membres Chat
 Forums
Accès réservé aux membres Journal
 Surveys
 Webmastering
 MetaMaker
 Web_Tips
 Web_Design
 Webmastering Tools
 Statistics
 Site Statistics
 Top 10
 Games
 BlackJack
 Flash_Games
 Hangman
::  Site Visitors  ::
User login:

Nickname:
Password:
Security Code: Security Code
Type Security Code Here:

Members List Membership:
Latest: Wstarfox
New Today: 0
New Yesterday: 3
Overall: 210

People Online:
Guests: 36
Members: 1
Total: 37


You are an anonymous user. You can register for free by clicking here
::  Top 10 Downloads  ::
· 1: SpyBot-Search & Destroy
· 2: W32.Blaster.Worm Removal Tool
· 3: AdShield
· 4: Klez Removal Tool
· 5: Fresh UI
· 6: Ultimate Boot CD
· 7: G-Lock Temp Cleaner
· 8: ieSpell
· 9: Exposed!
· 10: AIDA32
::  Top 10 Viruses  ::
Sophos Top Ten

::  Free Virus Scans  ::

Free Online Virus Scan

Free Online Virus Scan

Scan your PC on-line for viruses and trojans!

::  Total Hits  ::
We received
113796
page views since February 2003
::  Tech Newsletters  ::

Surferbar: A Nasty New Hijacker





A nasty new browser hijacker/trojan has been discovered and is spreading across the web at a rapid pace. Dozens of threads have sprung up at the support forums started by people infected with the Surferbar hijacker.

There are two known variants of this hijacker currently, which I'll call Surferbar.a and Surferbar.AFlooder. Both variants hijack Internet Explorer's start page to www.surferbar.com.

Surferbar.a is a simple browser hijacker and can be cleaned up easily using HijackThis (download). Look for the following entries in HijackThis and have it remove them:

O4 - HKCU\..\RunOnce: [win32] c:\program files\winsrv32.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.surferbar.com/
O3 - Toolbar: SurferBar - {FF7FD490-34E7-4FA1-927A-F5799E6AAD7B} - c:\PROGRA~1\win32.dll

When you have done that, find and delete c:\program files\winsrv32.exe.

A few victims are convinced they received Surferbar.a after downloading and installing Kazaa Lite K++. I haven't had a chance to clarify if they meant the software itself installed the hijack, if a pop up ad on a mirror site installed it, or if they both used the same download mirror. Presently, this information is very much unconfirmed. However, I recommend staying away from Kazaa Lite even without this problem, as it's an unauthorized cracked version of the real Kazaa.

Surferbar.AFlooder is rather more complicated. In addition to hijacking the start page and adding an unwanted toolbar, this variant appears also to be either a keylogger or a remote access trojan (or both), and possibly an SMTP proxy for spammers to use to relay spam.

Surferbar.AFlooder uses an obscure method of writing data to an NTFS-formatted hard drive to embed itself directly into your system32 folder. Not inside the folder, actually embedded within the folder itself. It sounds nuts, but the NT File System allows that to happen using something called "Alternate Data Streaming" (ADS).

ADS allows you to store information "under the hood" of the file system, where normally you cannot see or manipulate it. Think of ADS information as metadata, similar to track/artist/title information that can be stored in an MP3. Unfortunately, Microsoft has provided no way to view or manipulate this ADS information without the use of third-party tools.

Fortunately, this parasite includes a not-so-secret uninstall command, which is revealed in a string of text within the file. If you or someone you are helping has been hijacked to surferbar.com, but you do not have the winsrv32.exe startup entry, then you probably have the AFlooder variant. Your HijackThis results will be similar to this:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.surferbar.com/
O3 - Toolbar: SurferBar - {FF7FD490-34E7-4FA1-927A-F5799E6AAD7B} - c:\PROGRA~2\win32.dll
O4 - HKLM\..\Run: [tywsmhd] rundll32 C:\WINDOWS\System32:tywsmhd.dll,Init 1

Removing these entries with HijackThis is of no use. A program running in the background immediately will reinstall any entries that are removed. Even booting to safe mode won't help with this.

Pay attention to the path of the dll file, C:\WINDOWS\System32:tywsmhd.dll in the example above. The exact name of the dll will be different each time. Click the "Start" menu, select "Run", and type: rundll32 C:\WINDOWS\System32:tywsmhd.dll,Uninstall. Remember to change the name of dll file to match that found on your computer. Click on "OK", and that should uninstall the parasite completely.

Those of you reading this online, please bear in mind that is information was written on September 2, 2003, and may be out of date by the time you read this. If these instructions do not help you remove this parasite, please ask for assistance at our support forums.


~Spyware Weekly Newsletter








Published on: 2003-09-04 (491 reads)

[ Go Back ]
This site is best viewed with a browser.

All logos and trademarks in this site are property of their respective owner. The comments are property of their posters, all the rest © 2003 by PC Sympathy.
Web site engine's code is Copyright © 2002 by PHP-Nuke.

You can syndicate our news using the file backend.php or ultramode.txt