Spyware/pop up/trojan problems.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by aladude85, Apr 11, 2005.

  1. aladude85

    aladude85 Private E-2

    I have tried everything listed in the sticky thread and still can't get rid of these pop-ups. =( one of my scans showed a trojan, but couldn't get rid of it (not even in safe mode). I guess thats what I get for downloading Grokster. =\ Please let me know what I should do.

    thanks in advance,
    aladude85
     
  2. aladude85

    aladude85 Private E-2

    I think my problem is with a program called surfsidekick, I can't seem to delete the file with any program (even in safe mode). Any help would be appreciated.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have run ALL of the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal and you still have a problem, follow the steps below.


    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  4. aladude85

    aladude85 Private E-2

    Here is my Hijack file. I did the scans earlier today, I hope they still show up. =\
     

    Attached Files:

  5. aladude85

    aladude85 Private E-2

    I think I might have done the Hijack file think wrong, here is another one.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Still incorrect. Please read the instructions again!

    - No browsers should be running - - C:\Program Files\Internet Explorer\iexplore.exe
    - You are running HijackThis exactly where we requested you not put it:
    C:\Documents and Settings\Owner\Desktop\HijackThis.exe

    Please fix this before we can continue.
     
  7. aladude85

    aladude85 Private E-2

    Ok, lets try this again. I am not sure why IE is showing up as running. I have it closed out when I do the scan.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are these juno.com lines valid?
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://my.juno.com/s/search?r=minisearch
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://my.juno.com/s/search?r=minisearch
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.juno.com/s/search?r=minisearch
    R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.juno.com/s/search?r=minisearch

    First look in Add/Remove programs for the below and uninstall if found:
    SurfSideKick 2

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).
    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\system32\picsvr\picsvr.exe
    C:\WINDOWS\system32\nsvsvc\nsvsvc.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - URLSearchHook: (no name) - {CA0E28FA-1AFD-4C21-A8DC-70EB5BE2F076} - C:\Program Files\SurfSideKick 2\SskBho.dll
    O3 - Toolbar: (no name) - {BDF6CE3D-F5C5-4462-9814-3C8EAC330CA8} - (no file)
    O4 - HKLM\..\Run: [picsvr] C:\WINDOWS\system32\picsvr\picsvr.exe
    O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\system32\nsvsvc\nsvsvc.exe
    O4 - HKLM\..\Run: [SurfSideKick 2] C:\Program Files\SurfSideKick 2\Ssk.exe
    O4 - HKCU\..\Run: [SurfSideKick 2] C:\Program Files\SurfSideKick 2\Ssk.exe
    O20 - AppInit_DLLs: repairs.dll

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\picsvr <--- the whole folder
    C:\WINDOWS\system32\nsvsvc <--- the whole folder
    C:\Program Files\SurfSideKick 2 <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST).
    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  9. aladude85

    aladude85 Private E-2

    I think it might be gone.
    Updated log:
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  11. aladude85

    aladude85 Private E-2

    Thanks for the help. =D I learned my lesson, DO NOT DOWNLOAD GROKSTER!!! lol
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


    Better lesson.....do not download any P2P program! They are all dangerous and some include loads of malware with them. But if you must, make sure you see this first:

    http://www.spywareinfo.com/articles/p2p/
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds