SurfSideKick removal help (followed faq already)

Discussion in 'Malware Help (A Specialist Will Reply)' started by Aks123, May 4, 2006.

  1. Aks123

    Aks123 Private E-2

    I tried the steps for removing surfsidekick, but on the particular step where it asks to remove the "repairs**.dll" files, I cannot find such files (even through the windows search utility). I've attached the hijackthis.log file.

    Please help! Trying to remove this program from my computer has turned into a nightmare for me. Thanks.
     

    Attached Files:

  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Remove:

    R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
    O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet7_22.dll
    O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBarBHO.dll
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O4 - HKLM\..\Run: [webHancer Survey Companion] C:\Program Files\webHancer\Programs\whsurvey.exe
    O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll
    (Description: ViewPoint toolbar)

    Reboot your computer
    Uninstall NewDotNet and delete the folder C:\Program Files\NewDotNet\
    Delete the C:\Program Files\Viewpoint\ folder.
    Delete the folder C:\Program Files\webHancer\

    Let me know.
     
  3. Aks123

    Aks123 Private E-2

    Thanks alot, major attitude. The pop-ups during my web browsing seem to have disappeared now. However, I have another problem: every time I start up my computer, my viruscan program detects a file called "wallpap.exe" and deletes it (but this file just shows up again the next time I reboot). What should I do about this?

    Thanks again
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have a few other issues that I see in your logs that need to be fixed. However first run MSconfig and select Normal Startup. Then reboot your PC in normal mode and obtain a new HijackThis log and attach it to your next message. Then we should be able to work thru the rest of the fixes.
     
  5. Aks123

    Aks123 Private E-2

    Here's the new log (attached). On startup, I am still getting the wallpap.exe problem, and in addition I am also getting a message "brsvc01.exe has encountered an error and needs to be shut down". Should I delete these files?
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do not delete brsvc01.exe It is for your Brother printer!

    It may be difficult to get all of your problems removed since you did not run the required cleaning procedure in the READ & RUN ME FIRST Before Asking for Support sticky thread. Thus we don't have all the info we should have. However, I'll give it a try and we will see how far we get.

    First look in Add/Remove programs for anything related to Zeno and uninstall if found.

    Make sure viewing of hidden files is enabled (per READ & RUN ME tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\mousepad17.exe
    C:\windows\system32\podsregs.exe
    C:\WINDOWS\system32\qwinpqaf.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
    O4 - HKLM\..\Run: [keyboard] C:\windows\keyboard17.exe
    O4 - HKLM\..\Run: [mousepad] C:\\mousepad17.exe
    O4 - HKLM\..\Run: [newname] C:\\newname17.exe
    O4 - HKLM\..\Run: [{B6-6E-E4-4C-ZN}] C:\windows\system32\podsregs.exe CORN004
    O4 - HKLM\..\Run: [BrowserUpdateSched] C:\WINDOWS\system32\qwinpqaf.exe CORN004
    O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\qwinpqaf.exe
    O4 - Startup: Z_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\dwdsregt.exe
    C:\windows\system32\podsregs.exe
    C:\WINDOWS\system32\qwinpqaf.exe
    C:\windows\newname17.exe <--- delete any files using the starting with the text newname and ending in .exe (like newname1.exe, newname2.exe...etc)
    C:\windows\mousepad17.EXE <--- delete any files using the starting with the text mousepad and ending in .exe (like mousepad1.exe, mousepad2.exe...etc)
    C:\windows\KEYBOARD17.EXE <--- delete any files using the starting with the text KEYBOARD and ending in .exe (like KEYBOARD1.exe, KEYBOARD2.exe...etc)
    C:\windows\GIMMYSMILEYS17.EXE <--- delete any files using the starting with the text GIMMYSMILEYS and ending in .exe (like GIMMYSMILEYS1.exe, GIMMYSMILEYS2.exe...etc)
    Now also look in c:\ for any of the newnameX, mousepadX, keyboardX, GIMMYSMILEYSX files and delete them too (for example you do have C:\windows\keyboard17.exe , C:\mousepad17.exe , C:\newname17.exe )


    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  7. Aks123

    Aks123 Private E-2

    Finally, I'm not getting any error or "virus found" messages on startup anymore! I've deleted the newname.exe, mousepad.exe, keyboard.exe files (gimmysmileys files weren't there). Should I also delete the .DAT files like "c:\windows\newname.dat", "c:\windows\keyboard171.dat"? Here's a new HJT log.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes, delete those files too!

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  9. Aks123

    Aks123 Private E-2

    Thank you, chaslang and major attitude, for your help. You've been extremely helpful and I greatly appreciate it!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds