Re: ssk.exe surfsidekick




"HarryHydro" <harryhydro@xxxxxxxxxxx> wrote in message
news:1126295878.627372.27100@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
> Hi Folks:
> I'm working on a laptop. It 'had' LOADS of virii, adware,
> spyware, you name it, it had it. Using MS Antispy, Trendmicro, Spybot
> I think he installed, Ive seem to gotten down to one program, SSK.EXE.
> I can't start in SAFEMODE because the password doesn't work. SAFEMODE
> with NETWORKING logs in, but SSK.EXE is running already by this time.
> I don't see it in the Task Manager, and almost everything else in Task
> Manager can't be stopped. There isn't alot of stuff.. One is
> KEEPSAFE that looks suspicious.
> If logged in, even via Safemode/Networking, and Network Jack
> plugged in (on the net), it eventually loads more adware junk. I've
> used MSCONFIG to disable everything in Startup and Services, SSK still
> runs. It keeps coming back in the registry. I'm assuming it's changing
> the registry back on shutdown. MSAntiSpy keeps finding it, but it
> can't delete it. I can see it trying, 3 times ort so, but no go. I
> can't stand this *** virus/adware! Sucks! Glad it's not my
> machine.
>
> He said he uses the internal WiFi to browse at home, and watched
> it load all kinds of stuff he couldn't keep up with.
>
> I'm assuming something with Networking is loading this. I tried
> installing IE6 from the MS site. Doesn't work. Gives excuses..
> any help appreciated. You guys are great!
> Take Care!
> Harry
>

It loads from the registry attached to some other process. Maybe winlogon,
but I'm not sure. If you don't kill it from the registry, you'll never get
rid of it, though. And it seems to sometimes come back on the 3rd reboot, so
even when you think it's clean, you need to reboot a couple times to be
sure.

If you do a search, there are some specific tools to get rid of that one.
There's one I have that's a .reg file that works most of the time, but that
miserable thing has a few variations, so none of the fixes are 100%. If you
can't find that .reg file fix or you want me to email it to you, I can. But
a search on Google should turn it up, and probably a newer version.


.