PDA

View Full Version : Manual Removal Guide for BetterSurf



Friday
2014-10-09, 09:19
The following instructions have been created to help you to get rid of "BetterSurf" manually.
Use this guide at your own risk; software should usually be better suited to remove malware, since it is able to look deeper.

If this guide was helpful to you, please consider donating towards this site (http://www.safer-networking.org/index.php?page=donate).

Threat Details:

Categories:
adware
bho

Links (be careful!):

: etterSurf displays advertisement in browsers and creates advertising pop-ups while the user is surfing.
Removal Instructions:

Installed Software List:

You can try to uninstall products with the names listed below; for items identified by other properties or to avoid malware getting active again on uninstallation, use Spybot-S&D (http://www.safer-networking.org/index.php?page=spybotsd) or RunAlyzer (http://www.safer-networking.org/index.php?page=runalyzer) to locate and get rid of these entries.

Products that have a key or property named "Better Surf Plus".

Files:

Please use Windows Explorer or another file manager of your choice to locate and delete these files.

The file at "<$PROGRAMFILES>\BetterSurf\BetterSurfPlus\ch\BetterSurfPlus.crx".
The file at "<$PROGRAMFILES>\BetterSurf\BetterSurfPlus\ie\BetterSrf.dll".
The file at "<$PROGRAMFILES>\BetterSurf\ie\BetterSurf.dll".
Make sure you set your file manager to display hidden and system files. If BetterSurf uses rootkit technologies, use the rootkit scanner integrated into Spybot-S&D (http://www.safer-networking.org/index.php?page=spybotsd) 2.x or our Total Commander anti-rootkit plugins (http://forums.spybot.info/downloads.php?id=3).
You will have to use a global search for files without a name specified. Be extra careful, because just the name might not be enough to identify files!

Important: There are more files that cannot be safely described in simple words. Please use Spybot-S&D (http://www.safer-networking.org/index.php?page=spybotsd) to remove them.

Folders:

Please use Windows Explorer or another file manager of your choice to locate and delete these folders.

The directory at "<$PROGRAMFILES>\BetterSurf\BetterSurfPlus\ch".
The directory at "<$PROGRAMFILES>\BetterSurf\BetterSurfPlus\ff\chrome\content\icons\default".
The directory at "<$PROGRAMFILES>\BetterSurf\BetterSurfPlus\ff\chrome\content\icons".
The directory at "<$PROGRAMFILES>\BetterSurf\BetterSurfPlus\ff\chrome\content\utils".
The directory at "<$PROGRAMFILES>\BetterSurf\BetterSurfPlus\ff\chrome\content".
The directory at "<$PROGRAMFILES>\BetterSurf\BetterSurfPlus\ff\chrome".
The directory at "<$PROGRAMFILES>\BetterSurf\BetterSurfPlus\ff".
The directory at "<$PROGRAMFILES>\BetterSurf\BetterSurfPlus\ie".
The directory at "<$PROGRAMFILES>\BetterSurf\BetterSurfPlus".
The directory at "<$PROGRAMFILES>\BetterSurf\ch".
The directory at "<$PROGRAMFILES>\BetterSurf\ff\chrome\content".
The directory at "<$PROGRAMFILES>\BetterSurf\ff\chrome".
The directory at "<$PROGRAMFILES>\BetterSurf\ff".
The directory at "<$PROGRAMFILES>\BetterSurf\ie".
The directory at "<$PROGRAMFILES>\BetterSurf".
Make sure you set your file manager to display hidden and system files. If BetterSurf uses rootkit technologies, use our RootAlyzer (http://forums.spybot.info/downloads.php?id=8) or our Total Commander anti-rootkit plugins (http://forums.spybot.info/downloads.php?id=3).
You will have to use a global search for files without a name specified. Be extra careful, because just the name might not be enough to identify folders!

Registry:

You can use regedit.exe (included in Windows) to locate and delete these registry entries.

Delete the registry key "{0113A098-06EA-4776-A011-D75590778F1E}" at "HKEY_CLASSES_ROOT\TypeLib\".
Delete the registry key "{1824FF90-C98E-48A6-838F-E3B6572B0C77}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{1824FF90-C98E-48A6-838F-E3B6572B0C77}" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\".
Delete the registry key "{462862BE-9A5C-49A5-9CBD-A649EAC63645}" at "HKEY_CLASSES_ROOT\Interface\".
Delete the registry key "{6E3C6B04-08FE-43BC-8E50-F90285024DEA}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{6E3C6B04-08FE-43BC-8E50-F90285024DEA}" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\".
Delete the registry key "{881E49A1-8325-4B19-AE6F-B889A40D073A}" at "HKEY_CLASSES_ROOT\Interface\".
Delete the registry key "{DD3A66B9-8A7C-4C3C-8D60-DB225A60D69C}" at "HKEY_CLASSES_ROOT\TypeLib\".
Delete the registry key "Better Surf Plus" at "HKEY_LOCAL_MACHINE\SOFTWARE\".
Delete the registry key "BetterSurf" at "HKEY_LOCAL_MACHINE\SOFTWARE\".
Delete the registry value "{1824FF90-C98E-48A6-838F-E3B6572B0C77}" at "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Approved Extensions\".
Delete the registry value "ext@bettersurfplus.com" at "HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions\".
If BetterSurf uses rootkit technologies, use our RegAlyzer (http://www.safer-networking.org/index.php?page=regalyzer), RootAlyzer (http://forums.spybot.info/downloads.php?id=8) or our Total Commander anti-rootkit plugins (http://forums.spybot.info/downloads.php?id=3).

Final Words:

If neither Spybot-S&D nor self help did resolve the issue or you would prefer one on one help,
Please read these instructions (http://forums.spybot.info/showthread.php?t=288) before requesting assistance,
Then start your own thread in the Malware Removal Forum (http://forums.spybot.info/forumdisplay.php?f=22) where a volunteer analyst will advise you as soon as available.