Recommended Driver Scanner

Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Resolved] "Surfsidekick" and other issues

[Fixed] Hijackthis! Logs - [Resolved] "Surfsidekick" and other issues posted in the Security & Safety forums; A friend of mine came over the other night and was on my computer while I was sleeping. I wake up the next morning and he says "Yo, I don't ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 04-05-2006
Bronze Member
 
Join Date: Apr 2006
Posts: 3
eb1920 - See this Members User comments on their Profile page
Default [Resolved] "Surfsidekick" and other issues

A friend of mine came over the other night and was on my computer while I was sleeping.
I wake up the next morning and he says "Yo, I don't know what happened but I was watching videos and talking to this chick on myspace when all of a sudden I got all these popups and now your computer's like this..."
I got this new icon I haven't gone into on my desktop called "TagASaurus" and a new "game" in my start menu called "Yazzle Sodoku".
I ran spybot and it comes up with "wwwcoolsearch" and also "SurfSideKick".
I choose to fix all and it gives me an error on the "Surfsidekick" saying it is still in memory so it can't delete it.
It even does this when I set spybot to scan on system startup.

On normal startup when I Control/Alt/Delete it shows a ton of things under applications and when I close one it just reopens itself

I'll restart my pc after this post and get someone of names of these.

I managed to download "Hijack This" and it tells me to post the log at some forums before "fixing" anything but I couldn't get those forums to load so I came here.

This is the logfile if it helps.

Please do not post HJT Logs in your post, but add them as an attachement.
I've done that this time for you. (Bluefish)
Attached Files
File Type: txt hjt.txt (7.4 KB, 3 views)



Last edited by Bluefish; 04-05-2006 at 10:46 AM.
  #2  
Old 04-05-2006
Bronze Member
 
Join Date: Apr 2006
Posts: 3
eb1920 - See this Members User comments on their Profile page
Default

These are the programs under the Ctl/Alt/Delete "Applications".
I'm unsure if there were other programs because it wouldn't let me scroll up and down.

wuauclt.exe
e9c5.tmp
nowby.exe
logopod.exe
xegwyu.exe
spoolsv.exe
naigjc32.exe
wmiprvse.exe
shellbn.exe


  #3  
Old 04-05-2006
Bluefish's Avatar
Elite Member
My PC
 
Join Date: Jan 2005
Location: Holland
Posts: 2,169
Bluefish - See this Members User comments on their Profile page Bluefish - See this Members User comments on their Profile page
Default

Hi eb1920!

As mentioned, please do not post HJT Logs in your post.
Please wait until on of our Security Team members is online to take a look at your Log

Blue


__________________
PCHF Rules - You're Welcome!
What's inside my PC? - Prework
  #4  
Old 04-05-2006
Bronze Member
 
Join Date: Apr 2006
Posts: 3
eb1920 - See this Members User comments on their Profile page
Default

Spybot says "Surfsidekick" is still running.
And when I try and close things in Ctl/Alt/Dlt it just reopens


  #5  
Old 04-05-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hya Eb1920 , welcome to PCHF.

I highly doubt that you are being honest here.. This pc is infected with dozens infections and no AV , no firewall , and no service packs installed...

Please follow the SSK removal instructions here:

http://www.bleepingcomputer.com/forums/topic9549.html

Then do a Panda AV scan here:

http://www.pandasoftware.com/products/activescan

And save the log from it , post that later.

Download Smitrem to your desktop:
http://noahdfear.geekstogo.com/click...click.php?id=1
Run the installer and then press Start to Extract the
files to the desktop, Do not run it yet.

Reboot into safe mode (Reboot and keep tapping F8 , then
choose safe mode from the list)

Run SmitRem:
Open the SmitRem folder and double click the "RunThis.bat" file to start the tool. Follow the prompts on screen , wait for the tool to complete , and disk cleanup to finish.

The tool will create a log named smitfiles.txt on the drive that you ran Smitrem on, eg; "C:\smitfiles.txt" , or the partition where your operating system is installed on.
Please attach this log to your next reply.

Note: XP users using the XP theme may ex-perience a change to the Classic Windows theme. This can be changed on the themes tab of desktop properties.


You will need to reload your wallpaper as the SmitRem
tool will reset it, you can do this by right clicking
desktop and choosing properties, First check Theme and
set it to Windows XP then click the Desktop tab and
choose the one you want to use and press apply.

Then follow the instructions in the "Prework" link below and when done post the Ewido log , the Smitrem log , the Panda log , and a new Hjt log.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 11:04 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top