Free PC Performance Scan

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Resolved] surf sidekick 3 help plz

[Fixed] Hijackthis! Logs - [Resolved] surf sidekick 3 help plz posted in the Security & Safety forums; hey i am jon. i am new to the forum. it seems like everybody is really nice here and seem to be able to help a lot of people. so ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 01-21-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 6
snides84 - See this Members User comments on their Profile page
Default [Resolved] surf sidekick 3 help plz

hey

i am jon. i am new to the forum. it seems like everybody is really nice here and seem to be able to help a lot of people. so i was wondering if anyone could help me with surf sidekick 3. i have tried to remove everything i can but i cant get rid of it all. it keeps coming back. here is my log. if anyone could help me out i would appreciate it. thanks.
Attached Files
File Type: log hijackthis.log (8.1 KB, 0 views)


  #2  
Old 01-21-2006
double_a_ron's Avatar
Elite Member
My PC
 
Join Date: Sep 2005
Location: Canada
Posts: 901
PC Experience: Very Experienced
double_a_ron - See this Members User comments on their Profile page double_a_ron - See this Members User comments on their Profile page double_a_ron - See this Members User comments on their Profile page double_a_ron - See this Members User comments on their Profile page double_a_ron - See this Members User comments on their Profile page double_a_ron - See this Members User comments on their Profile page double_a_ron - See this Members User comments on their Profile page double_a_ron - See this Members User comments on their Profile page double_a_ron - See this Members User comments on their Profile page double_a_ron - See this Members User comments on their Profile page double_a_ron - See this Members User comments on their Profile page
Default

Hi Snides84,

Welcome to the PC Help Forum.

We have an excellent tea of tech and security experts who will be glad to help you out.

Could you please follow the instructions in the *Prework* link in my signature and then post a new hijack this log?

Hang tight and one of our secuity analysts will go to town on it.


__________________
//Prework\\\///PCHF RULES\\\///Did we help? Please Donate\\\

CompTIA A+ Certified, MCDST



Did we help? Please hit that Thanks button.
  #3  
Old 01-21-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 6
snides84 - See this Members User comments on their Profile page
Default

thank you for helping. here is the logs i have taken after following the steps you told me. let me know what i should do next. thanks
Attached Files
File Type: log hijackthis.log (8.2 KB, 1 views)
File Type: txt Scan report_20060120.txt.txt (1.2 KB, 1 views)


  #4  
Old 01-21-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hya Snides84.


Make sure you have system restore still disabled and hidded files set to show. Also make sure you still have Ccleaner.

Download:
- Unlocker

And install it.

Download:
-SSKfixXP

Using and or Remove Programs in the Control Panel uninstall the following if present:
Surfsidekick
Surfsidekick 2
Surfsidekick 3


if SurfSideKick is not in Add or Remove Programs, go to:



Start -> Run

Type "C:\Program Files\SurfSideKick 3\ssk.exe" /u -> ENTER.

Enter the given security code (generated automatically by the uninstaller) > OK
Click on YES at the reboot prompt.

Make sure PC boots in Safe Mode afterwards.


Open Windows Explorer and browse to:

c:\windows\system32 or c:\winnt\system32


Look for all instances of repairs.dll file, once located, right-click > Unlocker > Unlock All
Note: In newer versions of the SurfSideKick 3 infections the name has changed to repairs302972940.dll
If repairs.dllor repairs302972940.dllcan not be found then search for both files on the local hard drive using the search function in the Start Menu.


Immediately afterwards delete all instances of repairs.dll and/or repairs302972940.dll



Now run SSKfixXP.exe (towards the end of the process it might boot your PC if that occurs, make sure you keep tapping on the F8 key to boot back in Safe Mode). Run the fix again to complete the process.


Run HijackThis and fix the following lines

O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
O20 - AppInit_DLLs: repairs.dll (file missing)
And delete C:\Program Files\SurfSideKick 3 if still present.

Run CCLeaner .


And do you know what this is from?

O18 - Filter: text/html - {2F6E85DC-8D2D-4896-8A4F-7DF8A7B1749D} - C:\PROGRA~1\Jalmp\jalmp.dll

If not then please upload the file in bold to this site and report back the result:

http://www.virustotal.com/flash/index_en.html

And post a new hjt log when youre done.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Last edited by joe5; 01-21-2006 at 11:44 AM.
  #5  
Old 01-21-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 6
snides84 - See this Members User comments on their Profile page
Default

hey

i did everything that you said. one thing i noticed is that when i run sskxpfix.exe tea timer says that the change was denide. tea timer also blocks a few surf side kick files that try to run everytime windows loads. i have a log file after i ran sskxpfix.exe in safe mode and a log file after i rebooted into windows. i dont know what that other files is so i have the results for that. the log file after reboot is the latest one.
Attached Files
File Type: log hijackthis after reboot.log (8.2 KB, 1 views)
File Type: log hijackthis safe mode.log (5.9 KB, 1 views)


  #6  
Old 01-21-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 6
snides84 - See this Members User comments on their Profile page
Default

here is the jalmp result. i would have put it in a file but the file size was to big for the forum upload rules.
Attached Files
File Type: txt log.txt (1.3 KB, 1 views)



Last edited by Hengis; 01-21-2006 at 09:08 PM.
  #7  
Old 01-21-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Looking pretty good , but boot in safemode again and look for an uninstaller for "Jalmp" in add/remove programs and uninstall it if present.

Then fix this one with hjt if still present:

O18 - Filter: text/html - {2F6E85DC-8D2D-4896-8A4F-7DF8A7B1749D} - C:\PROGRA~1\Jalmp\jalmp.dll
and delete the folder in bold.

Then run the SSKfixXP.exe again , but first disable spybot's teatimer temporary.

You should be clean after that. :smiley:


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
[Fixed] Cant remove SP2 cant surf web cyberjan [Fixed] Hijackthis! Logs 17 07-14-2005 03:31 PM

All times are GMT +1. The time now is 05:45 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top