Outerinfo.com, Sidekick keeps Spawning

Discussion in 'Malware Help (A Specialist Will Reply)' started by JHMarshIII, Aug 23, 2005.

  1. JHMarshIII

    JHMarshIII Private E-2

    Picking up on thread http://forums.majorgeeks.com/showthread.php?t=69391&highlight=outerinfo.com (I couldn't quote or post to it) I have this infection too and see the uninstall option (OIN) in Add/Remove and am reluctant to try it. Does anybody know if it is safe? I just completed all the steps in the Do this first post and including running Ewido. Should I post my Hiijack This log now? Further, I keep killing the 04 entry for Sidekick and it comes back with two entries when I run it again.

    Weary..
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Read the announcement at the top of the forum page: New policy on Malware Fighters
    and you will learn why you cannot post in other threads.

    That user never followed up on trying to complete the cleanup so we have little info to go on.
    So you have two choices
    - try their uninstall process and see what happens
    - try following the procedure that I gave in message # 4 of that thread and we will see if we can manually remove it. It sounds like you may have run the READ ME FIRST. Make sure you ran ALL of it and then follow the directions in that message # 4 and post your HJT log as an attachment.
     
  3. JHMarshIII

    JHMarshIII Private E-2

    Thank you chaslang, I did run the OIN uninstall. Things did get a little better. I still have left, SurfSideKick, PokerParty, and WinFix. I've tryied killing the O4 entries through HiJack This, but they respawn. I've attaced my HiJack This log.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do not have HijackThis installed properly. In fact you have it running from exactly one of the locations we request it not to be installed. Your Desktop!

    C:\Documents and Settings\JHMarshIII\Desktop\DI Support Tools\HijackThis.exe

    Please fix this before continuing.

    Look in Add/Remove Programs for SurfSideKick 3 and uninstall if found.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to Command Service (if not found, look for cmdService) Then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, open up HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Command Service

    If not found, use the short name: cmdService

    Now exit HijackThis. It will probably tell you that you need to reboot to complete this fix. Do not reboot yet. We will reboot later.


    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\System32\n?lookup.exe
    C:\Program Files\ihwr\obut.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.myseachexplorer.com/sp2.php
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
    R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
    O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
    O4 - HKCU\..\Run: [Soen] C:\Program Files\ihwr\obut.exe
    O4 - HKCU\..\Run: [Fzk] C:\WINDOWS\System32\n?lookup.exe
    O4 - HKCU\..\Run: [Zws9Rja3Q] dwwhnd.exe
    O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
    O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
    O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O20 - AppInit_DLLs: repairs.dll
    The below line does not seem to be normal for Lavasoft's Vx2cleaner. Let's fix this too!
    O20 - Winlogon Notify: LavasoftStartupCleaner - C:\WINDOWS\vx2cleaner.dlx
    The below may already be gone. If not, fix it too.
    O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\U29ueSBVc2VydAAA\command.exe (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\SurfSideKick 3 <--- the whole folder
    C:\Program Files\ihwr <--- the whole folder
    c:\windows\dwwhnd.exe or c:\windows\system32\dwwhnd.exe
    c:\windows\repairs.dll or c:\windows\system32\repairs.dll
    C:\WINDOWS\System32\n?lookup.exe <--- DO NOT delete nslookup.exe which is valid. Look for something else with a similar name. If not sure, do not delete anything. Just tell me what you see matching this. The ? could be anything.

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds