Spyware...Help me get rid of it

Discussion in 'System Security & Infection Support' started by demuthp, Feb 19, 2005.

  1. demuthp

    demuthp

    Joined:
    Feb 18, 2005
    Messages:
    8
    Likes Received:
    0
    Location:
    Denmark
    Please look at this hijackthis log file and help me find out what to fix.
    Logfile of HijackThis v1.99.0
    Scan saved at 18:24:55, on 19-02-2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Programmer\Network Associates\Common Framework\FrameworkService.exe
    C:\Programmer\Network Associates\VirusScan\Mcshield.exe
    C:\Programmer\Network Associates\VirusScan\VsTskMgr.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Programmer\Java\j2re1.4.2_03\bin\jusched.exe
    C:\windows\system\hpsysdrv.exe
    C:\WINDOWS\system32\hphmon06.exe
    C:\HP\KBD\KBD.EXE
    C:\Programmer\Fælles filer\InstallShield\UpdateService\issch.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\ALCXMNTR.EXE
    C:\Programmer\Network Associates\VirusScan\SHSTAT.EXE
    C:\Programmer\Network Associates\Common Framework\UpdaterUI.exe
    C:\Programmer\Fælles filer\Network Associates\TalkBack\TBMon.exe
    C:\Programmer\QuickTime\qttask.exe
    C:\Programmer\iTunes\iTunesHelper.exe
    C:\Programmer\iPod\bin\iPodService.exe
    C:\Programmer\Messenger\msmsgs.exe
    C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Programmer\Spywareguard\sgmain.exe
    C:\Programmer\RMClient\PMCTray.exe
    C:\Programmer\Spywareguard\sgbhp.exe
    C:\Programmer\Internet Explorer\iexplore.exe
    C:\Programmer\Spywareguard\Microsoftspyware\gcasDtServ.exe
    C:\Programmer\Spywareguard\Microsoftspyware\gcasServ.exe
    C:\Programmer\SpyKiller\spykiller.exe
    C:\Programmer\BestPopupKiller\BestPopupKiller.exe
    C:\WINDOWS\system32\msiexec.exe
    C:\Programmer\HiJackThis\HijackThis.exe
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=DA_DK&c=Q105&bd=pavilion&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=DA_DK&c=Q105&bd=pavilion&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=DA_DK&c=Q105&bd=pavilion&pf=desktop
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=DA_DK&c=Q105&bd=pavilion&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=DA_DK&c=Q105&bd=pavilion&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=DA_DK&c=Q105&bd=pavilion&pf=desktop
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Programmer\SpywareGuard\dlprotect.dll
    O3 - Toolbar: HP-visning - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Programmer\HP\Digital Imaging\bin\HPDTLK02.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\j2re1.4.2_03\bin\jusched.exe
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HPHUPD06] c:\Programmer\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
    O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FLLESF~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Programmer\Fælles filer\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
    O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
    O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
    O4 - HKLM\..\Run: [ShStatEXE] "C:\Programmer\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
    O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Programmer\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
    O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Programmer\Fælles filer\Network Associates\TalkBack\TBMon.exe"
    O4 - HKLM\..\Run: [test.exe] C:\WINDOWS\system32\test.exe
    O4 - HKLM\..\Run: [ysbinstall_1002648_3.exe] C:\WINDOWS\system32\ysbinstall_1002648_3.exe
    O4 - HKLM\..\Run: [JobHisInit] C:\Programmer\RMClient\JobHisInit.exe
    O4 - HKLM\..\Run: [MplSetUp] C:\Programmer\RMClient\MplSetUp.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] C:\Programmer\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [gcasServ] "C:\Programmer\Spywareguard\Microsoftspyware\gcasServ.exe"
    O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [BestPopUpKiller] C:\Programmer\BestPopUpKiller\BestPopupKiller.exe /startup
    O4 - Startup: SpywareGuard.lnk = C:\Programmer\Spywareguard\sgmain.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: SmartDeviceMonitor for Client.lnk = C:\Programmer\RMClient\PMClient.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\j2re1.4.2_03\bin\npjpi142_03.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\j2re1.4.2_03\bin\npjpi142_03.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe
    O23 - Service: McAfee Framework Service - Network Associates, Inc. - C:\Programmer\Network Associates\Common Framework\FrameworkService.exe
    O23 - Service: Network Associates McShield - Network Associates, Inc. - C:\Programmer\Network Associates\VirusScan\Mcshield.exe
    O23 - Service: Network Associates Task Manager - Network Associates, Inc. - C:\Programmer\Network Associates\VirusScan\VsTskMgr.exe
    O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
     
    demuthp, Feb 19, 2005
    #1
    1. Advertisements

  2. demuthp

    James Photojournalist

    Joined:
    Dec 24, 2002
    Messages:
    6,662
    Likes Received:
    35
    See if this helps at all.

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
    O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
    O4 - HKLM\..\Run: [JobHisInit] C:\Programmer\RMClient\JobHisInit.exe
    O4 - HKLM\..\Run: [MplSetUp] C:\Programmer\RMClient\MplSetUp.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] C:\Programmer\iTunes\iTunesHelper.exe
     
    James, Feb 20, 2005
    #2
    1. Advertisements

  3. demuthp

    demuthp

    Joined:
    Feb 18, 2005
    Messages:
    8
    Likes Received:
    0
    Location:
    Denmark
    Didn't help

    Unfortunately it didn't help. It is still there.
     
    demuthp, Feb 20, 2005
    #3
  4. demuthp

    Bubba Gump XBL: John Voda VIP Member

    Joined:
    Dec 12, 2003
    Messages:
    764
    Likes Received:
    5
    Location:
    Minnesota
    Have you run Adaware or MS Antispyware?
     
    Bubba Gump, Feb 20, 2005
    #4
  5. demuthp

    demuthp

    Joined:
    Feb 18, 2005
    Messages:
    8
    Likes Received:
    0
    Location:
    Denmark
    I have run all the antispyware programs that I found in the handy tools link. Doesn't help. But I know that it is possible to get rid of it. A boy got help getting rid of it I think he is called possuman72, but since my hijackthis log file isn't totally the same I'm not sure on which files i can delete, and not destroy my computer.
     
    demuthp, Feb 20, 2005
    #5
  6. demuthp

    James Photojournalist

    Joined:
    Dec 24, 2002
    Messages:
    6,662
    Likes Received:
    35
    Try removing these items in Safe Mode... When you here your BIOS beep, hit F8 and select Safe Mode.
     
    James, Feb 20, 2005
    #6
  7. demuthp

    demuthp

    Joined:
    Feb 18, 2005
    Messages:
    8
    Likes Received:
    0
    Location:
    Denmark
    Which items?
     
    demuthp, Feb 21, 2005
    #7
  8. demuthp

    Dave601 Web Guru VIP Member

    Joined:
    Jan 27, 2004
    Messages:
    1,017
    Likes Received:
    22
    Location:
    St. Paul, MN
    The items he posted earlier.

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
    O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
    O4 - HKLM\..\Run: [JobHisInit] C:\Programmer\RMClient\JobHisInit.exe
    O4 - HKLM\..\Run: [MplSetUp] C:\Programmer\RMClient\MplSetUp.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] C:\Programmer\iTunes\iTunesHelper.exe
     
    Dave601, Feb 21, 2005
    #8
  9. demuthp

    demuthp

    Joined:
    Feb 18, 2005
    Messages:
    8
    Likes Received:
    0
    Location:
    Denmark
    It hasn't helped that I removed these files. Maybe I should tell you what the problem is. Whenever I start windows a window pops up and say something about a sitebar add-in to internet explorer, and asks you to install.
     
    demuthp, Feb 24, 2005
    #9
    1. Advertisements

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments (here). After that, you can post your question and our members will help you out.