Help me out with a error message...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by BlackZ2401, Sep 18, 2005.

  1. BlackZ2401

    BlackZ2401 Private E-2

    Allright heres the deal.

    I am very computer literate and I do some in home work for people and do alot of virus/spyware removal. The thing is I have been having a problem over the past few months that I can't seem to find a fix for. Im now looking for answers now as this is getting rather fustrating. I've found quite a few good threads on here and Im hoping someone has encountered this problem before.

    After doing some spyware/virus removal on a customers computer a select few seem to have a problem after (what I believe is the cause of the problem) surfsidekick is removed.

    After doing some scans using HJT/Spysweeper/Adaware/Spybot/Ewido (just ot start) and removing all items in msconfig in safe mode, I boot back to regular mode and find I have a error message after the start-up items load that reads something to the effect of:

    "Internet Explorer has ecountered an error and needs to close...". The thing is there is no "send" / "dont send" / details. on the message box. Just the option to close. After you close it comes right back.

    Now mind you I have already ran and removed a bunch of spyware, viruses, trojans, etc and have removed the unwanted items in HJT (unless Im missing something but I doubt it). I ran the ABI removal tool, deleted temp files, ran reg cleaners, ran sfc, reinstalled ie, performed a soft install of xp and none of this seems to work. The only thing that works is a full fledged restore of the system.

    So I KNOW there has got to be a way to fix this stupid thing. Its really fustrating spending a solid hour removing stuff only to find out its all for nothing and having to format the drive.

    Anyone seen this before and successfully removed it? Thanks.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All though your message is fairly long there is not enough information on what the real problems are and what malware you have been finding. The only item mentioned was SurfSidekick. You did mention you were computer illiterate. If this is true, you should not be deleting items on your own and you should definitely not be using HijackThis on your own and you should not be working on a customers computer. Why would you even think of doing that.

    You also said:
    If you really did remove ALL items in msconfig, you are asking for trouble. Some things loading at startup are needed.

    If you have already done a System Restore or a format of the system, and have no problems, what is the reason for this post. If you still have problems follow the steps below, but whose computer are you working on (yours or a customers)?

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. BlackZ2401

    BlackZ2401 Private E-2

    Umm no...

    I said I was computer LITERATE ... no IL in the front.

    What I meant by diabling all in msconfig is disabling all the crap thats not needed. I know what is, and what isnt...

    Also I said before I already ran HJT and removed what wasnt needed so thats not working

    I do virus/spyware removal for people at their homes on a daily basis so I know what Im doing. Its just this problem is getting the better of me.

    Also I am not 100% sure thats it SSK, but it has been on the few machines that I've noticed this problem on. Sorry the message was long, didnt think that was a problem.

    The reason for this post is because Im trying to AVOID the system restore as that kind of defeats the purpose of me coming to someones house and removing all the crap on their system. I have been doing this for quite some time and I know what Im doing... I have asked other people and they are stumped with this error message as well.

    I didnt know I would need more information... I figure since its apparently a common problem and it occurs after the removal of spyware that someone would know what the cause is.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry I misread your message.

    Long messages are not a problem. But specific details are more important. Also we prefer that msconfig is not used to stop loading processes because all that does is prevent us from seeing them and most tricky malware will get around that anyway.

    In reality is is nor a common problem after removal of malware to have IE cause errors. It does happen sometimes though especially if required system files have been damage or deleted. Since we do not know the specifics of what you have been doing, it is rather difficult to answer a question on what it wrong. System Restore is rarely required but it is an alternative in some cases.

    Do you have the PC now and does it currently have problems? If so, follow the steps in my previous message.
     
  5. BlackZ2401

    BlackZ2401 Private E-2

    Its not a problem, its late and it happens.

    No I do not have hte PC now, it is a customers and I performed a restore earlier in the day.

    System restore was turned off prior to any removal of viruses/spyware.

    I know the specifics are kind of vague but I was hoping that someone has had this problem before. This is the 3rd computer is 2 days that I have seen this problem on... so maybe its just common for me lol.

    If system files were damaged, the sfc or the soft install should have taken care of that correct? I think its still some remnents of the spyware causing it.

    Is there a really thourough (sp) surfsidekick removal tool?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In most cases sfc does help. But there are many cases where it just does not know that the file has been damage. For example SmitFraud causes problems in wininet.dll and goes totally undetected and it cannot be repaired by sfc. That's just one case. There is no specific tool written to remove SurfSideKick. Sometime the problems related to it go away pretty easy. We have had a few cases where it was pretty stubborn. Sometimes this is due to interactions with other malware. It has had three versions too.
     
  7. BlackZ2401

    BlackZ2401 Private E-2


    Damn...

    Oh forgot to mention in each case there was a "repairs.dll" file in the system32 dir. Friggin stubborn SOB. I had to go to the recovery console to delete it. Still the error persisted. Other then that I dunno what else is causing this problem. I guess I'll just have to do some more research on it.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! That is one of the files that can be stubborn sometimes. It shows on an O20 line of HJT. A typical cleanup may look like:

    Uninstall if found:
    Surf Sidekick
    Surf Sidekick 2
    Surf Sidekick 3

    Fix the below using HJT:
    R3 - URLSearchHook: (no name) - {000AB005-FF12-42C2-8DF5-39E12E5F9C91} - (no file)
    R3 - URLSearchHook: (no name) - {000AB005-FF12-42C2-8DF5-39E12E5F9C91} - C:\Program Files\SurfSideKick\SskBho.dll
    O4 - HKLM\..\Run: [SurfSideKick] C:\Program Files\SurfSideKick\Ssk.exe
    O4 - HKCU\..\Run: [SurfSideKick] C:\Program Files\SurfSideKick\Ssk.exe
    O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
    Delete the below files and folders (in safe mode):
    C:\PROGRAM FILES\SurfSideKick
    C:\Program Files\SurfSideKick 3\

    Search for the below and delete:
    Sskknwrd.dll
    Ssk.log
    SskUpdater.exe
    repairs.dll (usually in the system32 folder)

    Merge the below patch into the registry:
    REGEDIT4
    [-HKEY_CURRENT_USER\Software\SurfSideKick]
    [-HKEY_CLASSES_ROOT\CLSID\{000AB005-FF12-42C2-8DF5-39E12E5F9C91}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Surf Sidekick_is1]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SurfSideKick]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{000AB005-FF12-42C2-8DF5-39E12E5F9C91}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\SurfSideKick]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks\{000AB005-FF12-42C2-8DF5-39E12E5F9C91}]
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"=""
     
  9. BlackZ2401

    BlackZ2401 Private E-2

    Yea there was also a folder in "program files" called "dns" which is supposed to be related as well. I know I got hte main "Surfsidekick" folders and files. Ill have to check if I got all those reg entries, pretty sure I did get all the ones with ssk in em though.

    I guess I'll have to keep you updated (Ill try and get some more info or logs next time this happens). If I find a fix Ill let ya know.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I said, some are easy and some are not. But we have managed to fix all of them here eventually.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also one other note I forgot to mention, SurfSideKick's own website does say it can be removed using Add/Remove programs. Look for a program named “SurfSidekick” or “BTS Media”. But who knows if you can trust them.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds