PDA

View Full Version : SurfSide 3 infestation



djeXo
2006-06-23, 05:07
hey guys, well this came onto the comp due to it being allowed through teatimer by accident. Now, I couldn't find a few to undo that exception from the blacklist so I reinstall spybot (bad move) so now my history is gone, I also deleted the Spybot folder under All users thinking it would've given it a clean slate. Well it kinda has, some queuries I'm being asked again which is good but I've noticed it autoallows SurfSide adware through even though it's a clean install. I know you guys say that it's not stored anywhere else for blacklist changes but that doesn't seem to be the case as regardless it's still autoallowing the change I don't want through even WITH a clean install.

Is there another way I can manually clean the list so that when I re-run IE or FireFox it won't autoallow the surf adware cr4p through and actually ask me whether I want to allow it.
I'm using v1.4 with the latest and greatest updates.

I tried the manual remove process of this adware but as soon as I spawn the browsers it comes back so I'm just wanting to slow the progress of it.

tashi
2006-06-23, 05:37
Hello.

As most of the SurfSide infections I have seen recently have been on a computor infected with other nasties, it would be best if we saw a HJT log in the malware removal forum.

Please follow the instructions in this sticky topic:
BEFORE you post and who will advise you. Preliminary Steps (http://forums.spybot.info/showthread.php?t=288)

Start your own topic here:
Malware Forum (http://forums.spybot.info/forumdisplay.php?f=22[/url)

A helper will then take a look at the system and assist you as soon as available.

Cheers. :)

djeXo
2006-06-23, 06:18
Excellent, I'll chase that up tonight. I too have noticed that this adware allows other adware to install as I've repeatedly run the cleanup process and noticed it lets them all slip through shortly after its set itself up.
Just to slow it down in the meantime I removed all permissions 'Run' in HKLM and have managed to manually delete teh files that it runs, but of course it's never that easy. I'll run the tool tonight and post it into the Malware forum.