HELP! Hijacked? Virus? Start Menu / Date/Time & Admin effected

Reply

Join Date: Jun 2008
Posts: 2
Reputation: namelessism is an unknown quantity at this point 
Solved Threads: 0
namelessism namelessism is offline Offline
Newbie Poster

HELP! Hijacked? Virus? Start Menu / Date/Time & Admin effected

 
-1
  #1
Jun 22nd, 2008
I downloaded some pirate software on Friday night, and must have hit a virus. Here are the symptoms and the actions I've taken:

*The computer is a new USED machine which had no anti-virus software installed

Sat night - Start menu programs dissappeared, no access to control panel, no access to taskmanager (the computer administrator has disabled this feature). The DATE/Time section says the time in military time, then VIRUS ALERT! so all referance to time now also includes the words VIRUS ALERT!

Any attempt to use firefox or IE took me to about:blank.

Steps taken: Downloaded Windows Defender, found errors and deleted them. Downloaded Service Pack 3 and security updates. Downloaded AVAST! Antivirus and ran thorough scan. found errors, put in chest then deleted (file name was Vapsup)

Got into Computer Manager and selected "disable" on the options for blocking out the user from the start menu, taskmanager etc. Deleted all other users.

Ran DiskCleanup, Ran DiskDefrag. Ran Sys Restore to a checkpoint last week but had no effect.

*Remaining issues include the Date/Time still says VIRUS ALERT! - Avast does not find any other harmful files.

*Also, from MY COMPUTER I cannot see the C: drive.

*Also, from SYSTEM Its says Dell, and below it VIRUS ALERT!

*Also, my Start Menu still does not show all the programs installed on the computer. I was able to get it to show some, but they come up on the left side as links instead of menu items.

**I have a registered copy of Windows XP, but I dont have a disc for recovery. What can I do? I'd be okay with formatting the drive and reinstalling everything, but no Windows!

Can anyone help???????
Last edited by namelessism; Jun 22nd, 2008 at 2:41 pm.
Reply With Quote Quick reply to this message  
Join Date: Jun 2007
Posts: 2,462
Reputation: zandiago is on a distinguished road 
Solved Threads: 25
Featured Poster
zandiago's Avatar
zandiago zandiago is offline Offline
Nearly a Posting Maven

Re: HELP! Hijacked? Virus? Start Menu / Date/Time & Admin effected

 
0
  #2
Jun 23rd, 2008
Have you tried scanning with Spybot Search & destroy? Additionally, we would appreciate if you could post a copy of your hi-jack log.
I shot the sheriff....but I didn't shoot the deputy
Reply With Quote Quick reply to this message  
Join Date: Jun 2008
Posts: 2
Reputation: namelessism is an unknown quantity at this point 
Solved Threads: 0
namelessism namelessism is offline Offline
Newbie Poster

Re: HELP! Hijacked? Virus? Start Menu / Date/Time & Admin effected

 
0
  #3
Jun 23rd, 2008
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:30: VIRUS ALERT!, on 6/22/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\M-Audio Ozone\Install\Ozinst.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\Creative\Shared Files\CTSched.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Entertainment Center\EAXLoadr.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\M-Audio Ozone\OZTask.exe
C:\Program Files\Creative\ShareDLL\CADI\NotiMan.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\mmc.exe
C:\Documents and Settings\XP\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: IE ext - {2FF811E6-8925-4084-A649-C159955E67E8} - C:\WINDOWS\system32\dapol.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {E4A847F1-5B48-43FE-ACA3-6C0ED65EA4EC} - (no file)
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [RCSystem] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" RCSystem * -Startup
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [CreativeTaskScheduler] "C:\Program Files\Creative\Shared Files\CTSched.exe" /logon
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Global Startup: M-Audio Ozone Control Panel Launcher.lnk = C:\Program Files\M-Audio Ozone\OZTask.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O21 - SSODL: xvorfwbd - {631793D4-8F77-434D-A7ED-C1DBB87E4533} - C:\WINDOWS\xvorfwbd.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Ozone Installer (OzoneInstallerService) - Nemesis - C:\Program Files\M-Audio Ozone\Install\Ozinst.exe

--
End of file - 7702 bytes


Originally Posted by zandiago View Post
Have you tried scanning with Spybot Search & destroy? Additionally, we would appreciate if you could post a copy of your hi-jack log.
Reply With Quote Quick reply to this message  
Join Date: Jun 2007
Posts: 2,462
Reputation: zandiago is on a distinguished road 
Solved Threads: 25
Featured Poster
zandiago's Avatar
zandiago zandiago is offline Offline
Nearly a Posting Maven

Re: HELP! Hijacked? Virus? Start Menu / Date/Time & Admin effected

 
0
  #4
Jun 24th, 2008
So...did you use spybot search & destroy?
I shot the sheriff....but I didn't shoot the deputy
Reply With Quote Quick reply to this message  
Join Date: May 2008
Posts: 52
Reputation: camthalion95 has a little shameless behaviour in the past 
Solved Threads: 0
camthalion95's Avatar
camthalion95 camthalion95 is offline Offline
Junior Poster in Training

Re: HELP! Hijacked? Virus? Start Menu / Date/Time & Admin effected

 
0
  #5
Jun 27th, 2008
use SUPER Antispyware PRO.
gagemarshall.bravehost.com
gagemarshall.shopmania.biz
Reply With Quote Quick reply to this message  
Join Date: Jul 2008
Posts: 1
Reputation: Mel Robinson is an unknown quantity at this point 
Solved Threads: 0
Mel Robinson Mel Robinson is offline Offline
Newbie Poster

Re: HELP! Hijacked? Virus? Start Menu / Date/Time & Admin effected

 
0
  #6
Jul 10th, 2008
Originally Posted by namelessism View Post
I downloaded some pirate software on Friday night, and must have hit a virus. Here are the symptoms and the actions I've taken:

*The computer is a new USED machine which had no anti-virus software installed

Sat night - Start menu programs dissappeared, no access to control panel, no access to taskmanager (the computer administrator has disabled this feature). The DATE/Time section says the time in military time, then VIRUS ALERT! so all referance to time now also includes the words VIRUS ALERT!

Any attempt to use firefox or IE took me to about:blank.

Steps taken: Downloaded Windows Defender, found errors and deleted them. Downloaded Service Pack 3 and security updates. Downloaded AVAST! Antivirus and ran thorough scan. found errors, put in chest then deleted (file name was Vapsup)

Got into Computer Manager and selected "disable" on the options for blocking out the user from the start menu, taskmanager etc. Deleted all other users.

Ran DiskCleanup, Ran DiskDefrag. Ran Sys Restore to a checkpoint last week but had no effect.

*Remaining issues include the Date/Time still says VIRUS ALERT! - Avast does not find any other harmful files.

*Also, from MY COMPUTER I cannot see the C: drive.

*Also, from SYSTEM Its says Dell, and below it VIRUS ALERT!

*Also, my Start Menu still does not show all the programs installed on the computer. I was able to get it to show some, but they come up on the left side as links instead of menu items.

**I have a registered copy of Windows XP, but I dont have a disc for recovery. What can I do? I'd be okay with formatting the drive and reinstalling everything, but no Windows!

Can anyone help???????
Were you ever able to get rid of the military time and the VIRUS ALERT!? I am experiencing the same problems.
Reply With Quote Quick reply to this message  
Join Date: Jun 2007
Posts: 2,462
Reputation: zandiago is on a distinguished road 
Solved Threads: 25
Featured Poster
zandiago's Avatar
zandiago zandiago is offline Offline
Nearly a Posting Maven

Re: HELP! Hijacked? Virus? Start Menu / Date/Time & Admin effected

 
0
  #7
Jul 10th, 2008
Ok a few things. You'll need to install an anti-virus. I recommend AVG, you'll need to scan your computer with spybot search & destroy. Also, try be careful when downloading items from P2P & pirate/torrent sites. After you've done the above, We'll provide you with the registry fix to set your computer back to normal.
I shot the sheriff....but I didn't shoot the deputy
Reply With Quote Quick reply to this message  
Join Date: Aug 2008
Posts: 2
Reputation: mrdoubtfirs is an unknown quantity at this point 
Solved Threads: 0
mrdoubtfirs mrdoubtfirs is offline Offline
Newbie Poster

Re: HELP! Hijacked? Virus? Start Menu / Date/Time & Admin effected

 
0
  #8
Aug 22nd, 2008
This happened to me too. What is the registry fix?
Reply With Quote Quick reply to this message  
Join Date: Aug 2008
Posts: 2
Reputation: mrdoubtfirs is an unknown quantity at this point 
Solved Threads: 0
mrdoubtfirs mrdoubtfirs is offline Offline
Newbie Poster

Re: HELP! Hijacked? Virus? Start Menu / Date/Time & Admin effected

 
0
  #9
Aug 22nd, 2008
I used Spybot and it said it deleted a lot of stuff but the time still shows military and "VIRUS ALERT" and I still can't see my start menu or anything in my C: drive. I hope the registry fix will bring this all back. Please let me know what to do next.
Reply With Quote Quick reply to this message  
Join Date: Feb 2008
Posts: 462
Reputation: tiger86 is an unknown quantity at this point 
Solved Threads: 10
tiger86's Avatar
tiger86 tiger86 is offline Offline
Posting Pro in Training

Re: HELP! Hijacked? Virus? Start Menu / Date/Time & Admin effected

 
0
  #10
Aug 23rd, 2008
I have no sympathy for you, I am actually glad you caught a virus cause you were as you said downloading pirated software and downloading anything without virus protection is a big no no!
If I helped you I would appreciate it if you would give me some reputation.
read my actionscript to english blog
Currently developing what should be social network 2.0 offline.
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC