TechSpot

riddled with spyware :)

By taylor99
Oct 24, 2006
  1. Hi everyone firstly thank you for your service.
    i have a trojan on my pc and have tried numerous ways to kill it but it keeps coming back , please see attached HJ file and can some one help please, (this seems to be the price to pay for having teenagers :) )
     
  2. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Hello and welcome to Techspot.

    Go and read the Trojan Pakes and other nasties preliminary removal instructions. Follow all the instructions exactly.

    Post fresh HJT and AVG Antispyware logs as attachments into this thread, only after doing the above.


    Regards Howard :wave: :wave:


    This thread is for the use of taylor99 only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  3. taylor99

    taylor99 TS Rookie Topic Starter

    Log files attached

    hi Howard
    please see attached log files the AVG scan came up no virus so i didnt attach them
    regards Stephen Taylor
     
  4. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Run HJT with no other programmes open. Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(if there).

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}

    O2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll

    O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll

    O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll

    O4 - HKLM\..\Run: [GPClientMonitor] C:\Program Files\GalleryPlayer\Player\GPClientMonitor.exe

    O4 - HKLM\..\Run: [GPDownloadManager] C:\Program Files\GalleryPlayer\Player\GPDownloadManager.exe

    O4 - HKLM\..\Run: [VF0060 STISvc] RunDLL32.exe V0060Pin.dll,RunDLL32EP 513

    O8 - Extra context menu item: &Define - file://C:\Program Files\IEToys\Webster.htm

    O8 - Extra context menu item: &Delete Images - file://C:\Program Files\IEToys\CleanDom.htm

    O8 - Extra context menu item: &Highlighter - file://C:\Program Files\IEToys\Highlighter.htm

    O8 - Extra context menu item: Access&Keys - file://C:\Program Files\IEToys\AccessKeys.htm

    O8 - Extra context menu item: Encyclopedia &Lookup - file://C:\Program Files\IEToys\WebEncyc.htm

    O8 - Extra context menu item: HTML So&urce - file://C:\Program Files\IEToys\HTMLSrc.htm

    O8 - Extra context menu item: I&mage List - file://C:\Program Files\IEToys\ImageList.htm

    O8 - Extra context menu item: Linkif&y && Open - file://C:\Program Files\IEToys\Linkify.htm

    O8 - Extra context menu item: StumbleUpon: &Blog This - res://StumbleUponIEBar.dll/blogimage

    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL

    O15 - Trusted Zone: *.stumbleupon.com

    O16 - DPF: {8BC53B30-32E4-4ED3-BEF9-DB761DB77453} (CInstallLPCtrl Object) - http://u3.sandisk.com/download/apps/LPInstaller.CAB

    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Skype\toolbars\Shared\Skype4ComAPI.dll

    Click on the fix checked button.

    Close HJT.

    Reboot your computer and post a fresh HJT log.

    Let me know if you`re still having any problems.

    Regards Howard :)

    This thread is for the use of taylor99 only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  5. taylor99

    taylor99 TS Rookie Topic Starter

    By jove i think its worked

    Hi Howard
    Well it seems to be back to normal without all the problems etc now can you fix teenagers the same way ???
    Thank You
     
  6. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Your HJT log looks clean.

    Can you tell me what this programme is for?

    C:\Program Files\GalleryPlayer Did you intentionally install it?

    Regards Howard :)

    This thread is for the use of taylor99 only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  7. taylor99

    taylor99 TS Rookie Topic Starter

    Gallery player

    Hi Howard
    thank you for the help, yes the gallery player is an enhanced screensaver , it shows lakes and greenery and as i am in the desert in the middle east its soothing to see civilisation
    regards Stephen taylor
     
  8. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Ah I see.

    Thanks for letting me know.

    If you have any further virus/spyware problems, please post in this thread.

    Regards Howard :)

    This thread is for the use of taylor99 only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...