Logfile of HijackThis v1.99.0Scan saved at 5:18:20 PM, on 2/3/2005Platform: Windows 2000 SP4 (WinNT 5.00.2195)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINNT\System32\smss.exeC:\WINNT\system32\winlogon.exeC:\WINNT\system32\services.exeC:\WINNT\system32\lsass.exeC:\WINNT\system32\svchost.exeC:\WINNT\system32\spoolsv.exeC:\WINNT\System32\svchost.exeC:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXEC:\WINNT\system32\nvsvc32.exeC:\WINNT\system32\regsvc.exeC:\WINNT\system32\MSTask.exeC:\WINNT\system32\stisvc.exeC:\WINNT\System32\WBEM\WinMgmt.exeC:\WINNT\system32\svchost.exeC:\WINNT\System32\svchost.exeC:\Program Files\HP\HP Software Update\HPWuSchd2.exeC:\Program Files\HP\hpcoretech\hpcmpmgr.exeC:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe

Select one of the detected files, then press either the End Task or the End Process button, depending on the version of Windows on your system. Therefore, it is strongly recommended to remove all traces of SurfSideKick from your computer. This means running a scan for malware, cleaning your hard drive using cleanmgr and sfc /scannow, uninstalling programs that you no longer need, checking for Autostart programs (using msconfig) and enabling Select the Safe Mode option and press Enter.To return to normal mode just restart your computer as you normally would.Please remove these entries from Add/Remove Programs in the Control Panel(if present):SurfSideKickPlease

SurfSideKick, as well as other spyware, can re-install itself even after it appears to have been removed. HKLM\SOFTWARE\SurfSideKick? Remove SurfSideKick manually Another method to remove SurfSideKick is to manually delete SurfSideKick files in your system. When TVMedia is installed the following files may be created: \VCClient \VCClient\ClientUpdater.bat \VCClient\ICSharpCode.SharpZipLib.dll \VCClient\SS1001.exe \VCClient\temp.txt \VCClient\VCClient.exe \VCClient\VCClient.exe.config \VCClient\VCMain.exe \VCClient\VCUpdate.exe \VCClient\VCUpdate.exe.config

Detect and remove the following SurfSideKick files: Processes ssk.exesskupdater.exebk.exeSurfSidekick.exesskb5[1].exe DLLs sskcore.dllsskbho.dllrepairs303169590.dllSskknwrd.dllSskuknwrd.dll Other Files SurfSideKick 3SurfSideKick 2 Registry Keys HKEY_CURRENT_USERSoftwareSurfSideKick[XVS]HKEY_LOCAL_MACHINESOFTWARESurfSideKick[XVS]000AB0005-FF12-42C2-8DF5-39E12E5F9C9102EE5B04-F144-47BB-83FB-A60BD91B74A9CA0E28FA-1AFD-4C21-A8DC-70EB5BE2F076HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunSurfSideKickHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunSurfSideKickHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallSurfSidekickHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallSurfSidekick_is1Software\Microsoft\Internet Explorer\URLSearchHooks\02EE5B04-F144-47BB-83FB-A60BD91B74A9Software\Microsoft\Internet Explorer\UrlSearchHooks\_CA0E28FA-1AFD-4C21-A8DC-70EB5BE2F076Software\Microsoft\Internet Explorer\UrlSearchHooks\CA0E28FA-1AFD-4C21-A8DC-70EB5BE2F076SurfSideKick3Microsoft\Windows\CurrentVersion\App Management\ARPCache\Surf SideKickSurfSideKick2 External links If you believe your computer Sophos Home Free protection for home computers. SurfSideKick is not likely to be removed through a convenient "uninstall" feature. Besides offering improved security, alternate browers supply many new features.

SurfSideKick installs on your computer through a trojan and may infect your system without your knowledge or consent. Close the Add/Remove Programs window, and the Control Panel window.

In the Named input box, type: Ssk.exe SskBho.dll SskCore.dll %Program Files%\SurfSideKick 2 In the Look In drop-down list, select the drive that contains Windows, then press Enter.

For example, if the path of a registry value is HKEY_LOCAL_MACHINE\software\FolderA\FolderB\KeyName2,valueC= sequentially expand the HKEY_LOCAL_MACHINE, software, FolderA and FolderB folders and select the KeyName2 key to display the valueC value in Additional Windows ME/XP Cleaning Instructions Users running Windows ME and XP must disable System Restore to allow full scanning of infected systems. Solution: TREND MICRO SOLUTION Minimum scan engine version needed: 7.100 TMAPTN version needed: 216.02 DCE version needed: 3.8 MANUAL REMOVAL INSTRUCTIONS Identifying the Adware Program Download the latest adware pattern file Great job!

It collects information regarding the following: Web pages viewed by the user while surfing the Internet users response to advertisements encountered on the Internet system information (e.g.

In the left panel, double-click the following: HKEY_LOCAL_MACHINE>Software>Microsoft> Windows>CurrentVersion>Run In the right panel, locate and delete the entry: SurfSideKick 2="%Program Files%\SurfSideKick 2\Ssk.exe" (Note: %Program Files% is the default Program Files folder, If you think you may already be infected with SurfSideKick, use this SpyHunter Spyware dectection tool to detect SurfSideKick and other common Spyware infections. Follow the instructions on the dialog box that appears. SophosLabs Behind the scene of our 24/7 security.

Free Tools Try out tools for use at home. It is best to use both of these wonderful programs in tandem so that you maximize the detection capabilities.SpywareBlaster - SpywareBlaster offers real-time protection against malicious ActiveX controls. It then drops the following files in the newly created folder: Ssk.exe SskBho.dll SskCore.dll It creates the following registry entries to ensure its execution every system start-up: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunSurfSideKick 2="%Program Files%\SurfSideKick 2\Ssk.exe" Ad-Watch can be re-activated once your HijackThis log is clean.

Description created: Mar 24, 2005 TECHNICAL DETAILS Initial samples received on: Feb 1, 2005 SOLUTION Spyware pattern version needed :0.619.00 Pattern release date: Mar 18,

