I got hit bad by something. Have messages that regedit, task manager have been disabled by admin. Control panel is missing. VIRUS ALERT! is in taskbar and directory Here is HJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:49:57 PM, on 7/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [SW CfgWiz] "C:\Program Files\Common Files\Symantec Shared\OPC\{31011D49-D90C-4da0-878B-78D28AD507AF}\cfgwiz.exe" /GUID {E90B1832-3097-4d1c-93D1-D5332BA287A0} /MODE CfgWiz /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\RunServicesOnce: [washindex] C:\Program Files\Cookie Washer\washidx.exe "Lenore"
O4 - HKUS\S-1-5-18\..\Run: [Symantec NetDriver Warning] C:\PROGRA~1\SYMNET~1\SNDWarn.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Symantec NetDriver Warning] C:\PROGRA~1\SYMNET~1\SNDWarn.exe (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks Basic Edition\Norton Cleanup\WCQuick.lnk
O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks Basic Edition\Norton Cleanup\WCQuick.lnk
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: 6th Street Omaha Poker by pogo -
O16 - DPF: Aces Up! by pogo -
O16 - DPF: Addiction by pogo - http://game3.pogo.com/v/9.0.4.16/applet/addiction/addiction-en_US.cab
O16 - DPF: Ali Baba Slots TM by pogo -
O16 - DPF: Animal Ark by pogo -
O16 - DPF: Backgammon by pogo -
O16 - DPF: Battle Phlinx by pogo -
O16 - DPF: Blackjack by pogo -
O16 - DPF: Blackjack Carnival by pogo -
O16 - DPF: Blooop by pogo - http://game3.pogo.com/v/9.0.1.14/applet/cascade/cascade-en_US.cab
O16 - DPF: Bowling by pogo -
O16 - DPF: Buckaroo Blackjack TM by pogo -
O16 - DPF: Canasta by pogo -
O16 - DPF: Checkers by pogo -
O16 - DPF: Chess by pogo -
O16 - DPF: Cribbage by pogo -
O16 - DPF: Dice City Roller by pogo -
O16 - DPF: Dice Derby by pogo -
O16 - DPF: Dice Derby by pogo.com -
O16 - DPF: Dominoes by pogo -
O16 - DPF: Double Deuce Poker by pogo -
O16 - DPF: Euchre by pogo -
O16 - DPF: EZ Win Bingo by pogo -
O16 - DPF: First Class Solitaire by pogo -
O16 - DPF: Fortune Bingo by pogo -
O16 - DPF: Golf Solitaire by pogo -
O16 - DPF: Greenback Bayou by pogo -
O16 - DPF: Greenback Bayou by pogo.com -
O16 - DPF: Hangman Hijinks by pogo -
O16 - DPF: Harvest Mania by pogo -
O16 - DPF: Hearts by pogo -
O16 - DPF: High Stakes Poker by pogo -
O16 - DPF: High Stakes Pool by pogo -
O16 - DPF: Hog Heaven Slots by pogo -
O16 - DPF: Jigsaw Detective by pogo -
O16 - DPF: Jokers Wild Poker by pogo -
O16 - DPF: Jungle Gin by pogo -
O16 - DPF: Jungle Gin by pogo.com -
O16 - DPF: Keno by pogo -
O16 - DPF: KenoPop! by pogo -
O16 - DPF: Lost Temple Poker by pogo -
O16 - DPF: Lottso by pogo -
O16 - DPF: Mah Jong Garden by pogo -
O16 - DPF: Mahjong Safari by Pogo - http://game3.pogo.com/v/9.0.3.15/applet/safari/safari-en_US.cab
O16 - DPF: Makeover Madness by pogo -
O16 - DPF: Multiline Slots by pogo -
O16 - DPF: Pai Gow by pogo -
O16 - DPF: Payday FreeCell by pogo -
O16 - DPF: Payday Freecell Solitaire by pogo -
O16 - DPF: Penguin Blocks by pogo -
O16 - DPF: Perfect Pair Solitaire by pogo -
O16 - DPF: Phlinx by pogo - http://game3.pogo.com/v/9.0.1.7/applet/flinger/flinger-en_US.cab
O16 - DPF: Pinochle by pogo -
O16 - DPF: Pirate's Gold by pogo -
O16 - DPF: Pop Fu by pogo -
O16 - DPF: Pop Fu by pogo.com -
O16 - DPF: PoppaZoppa by pogo -
O16 - DPF: Poppit by pogo -
O16 - DPF: Poppit TM by pogo -
O16 - DPF: Quick Quack by pogo -
O16 - DPF: QWERTY by pogo -
O16 - DPF: Ride The Tide by pogo -
O16 - DPF: Showbiz Slots by pogo -
O16 - DPF: Shuffle Bump by pogo -
O16 - DPF: Spades 2 by pogo - http://game3.pogo.com/v/9.0.2.13/applet/spades2/spades2-en_US.cab
O16 - DPF: Spades by pogo -
O16 - DPF: Spider Solitaire by pogo -
O16 - DPF: Spooky Slots -
O16 - DPF: Squelchies by pogo -
O16 - DPF: Squelchies by pogo.com -
O16 - DPF: Stax by pogo -
O16 - DPF: Stellar Sweeper by pogo -
O16 - DPF: Super Dominoes by pogo -
O16 - DPF: Sweet Tooth 2 by Pogo - http://game3.pogo.com/v/9.0.1.7/applet/sweettooth2/sweettooth2-en_US.cab
O16 - DPF: Sweet Tooth TM by pogo -
O16 - DPF: Texas Hold'em Poker by pogo -
O16 - DPF: Thousand Island Solitaire by pogo - http://game3.pogo.com/v/9.0.1.10/applet/millbrae/millbrae-en_US.cab
O16 - DPF: Tornado 21 -
O16 - DPF: Tri-Peaks by pogo -
O16 - DPF: Tumble Bees by pogo -
O16 - DPF: Turbo 21 TM by pogo -
O16 - DPF: Turbo 21 v2 by pogo -
O16 - DPF: Vaults of Atlantis Slots by pogo -
O16 - DPF: Video Poker by pogo -
O16 - DPF: Wonderland Memories by pogo -
O16 - DPF: Word Craft by pogo -
O16 - DPF: Word Search Daily by pogo -
O16 - DPF: Word Whomp by pogo -
O16 - DPF: Word Whomp Whackdown by pogo -
O16 - DPF: Word Whomp Whackdown by pogo.com -
O16 - DPF: WordJong by pogo -
O16 - DPF: World Class Solitaire by pogo - http://game3.pogo.com/v/9.0.1.7/applet/worldclass/worldclass-en_US.cab
O16 - DPF: Yahoo! Canasta -
O16 - DPF: Yahoo! Chat -
O16 - DPF: Yahoo! Dice -
O16 - DPF: Yahoo! Gin -
O16 - DPF: Yahoo! Go Fish -
O16 - DPF: Yahoo! Graffiti -
O16 - DPF: Yahoo! Hearts -
O16 - DPF: Yahoo! MahJong -
O16 - DPF: Yahoo! Pool 2 -
O16 - DPF: Yahoo! Sheepshead -
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
O16 - DPF: {19520A33-EB3A-4515-9185-C5734587891A} (PlanView Portfolio Control v7.4.1) -
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://gsn.worldwinner.com/games/v46/shared/FunGamesLoader.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) -
O16 - DPF: {2C52AF58-B9B1-11D5-9DF6-00508B755B44} (AXClientUtil2 Control) -
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) -
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) -
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) -
O16 - DPF: {5EE92643-21CE-4949-903F-39439DCC3944} (Shapetris Control) - http://mirror.worldwinner.com/games/v42/shape/shape.cab
O16 - DPF: {62969CF2-0F7A-433B-A221-FD8818C06C2F} (Blockwerx Control) - http://mirror.worldwinner.com/games/v42/blockwerx/blockwerx.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) -
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} -
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) -
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.2) -
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} (Cubis Control) -
O16 - DPF: {9D8D7672-93FF-417E-9024-C16AD141C50C} (Haunted Control) -
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) -
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
O16 - DPF: {FA13A9FA-CA9B-11D2-9780-00104B242EA3} -
O21 - SSODL: axrfgvek - {3AA1CF0B-64D6-4250-A16A-6B39D719FB95} - C:\WINDOWS\axrfgvek.dll
O21 - SSODL: okmdepgb - {7A2046A5-4F19-4F1B-8709-686B7F246392} - C:\WINDOWS\okmdepgb.dll
O21 - SSODL: KbdService - {30763b26-3dc2-40cd-a724-a05a1317bd28} - C:\WINDOWS\Resources\KbdService.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--
End of file - 21222 bytes

Dani AI

Generated

The symptoms reported (registry editor and Task Manager blocked, Control Panel missing, a persistent “VIRUS ALERT!” UI and the scan output) point to an active, persistent infection rather than a one-off file. This builds on the practical starting points already suggested by (an initial on-demand removal scan, then a deeper removal tool) and the observation from that the scan contains SSODL-style, randomly named DLLs in the Windows folder. Immediate priority is containment and data preservation.

Containment and backup: disconnect the PC from the network to prevent data exfiltration or further spread. Make a copy of personal data (documents, pictures, mail stores, browser bookmarks) from an offline environment—either by booting a trusted live‑CD/USB or by attaching the drive to a clean machine—and scan that backup from a known-clean system before restoring. If possible, create a full disk image first so recovery options remain available.

Cleaning strategy (safe, repeatable sequence): run a trusted on-demand antimalware scan and a dedicated rootkit check while in Safe Mode; follow with an offline rescue scan from a reputable vendor’s bootable media so the malware can be examined and removed outside the running OS. Because registry editing is disabled, perform any registry or COM cleanup from an offline environment (repair or mount the registry hive from rescue media) before deleting randomly named DLLs in the Windows folder and removing their Run/services/SSODL entries. Reboot and re-run full scans until nothing else is found.

Post-clean steps and risk mitigation: after confirmed cleaning, delete infected restore points and create a fresh, clean restore point; change all online passwords from a clean device; install up-to-date security software on a supported OS. If system stability or integrity remains questionable, a full OS reinstall is the safest outcome. When requesting further help, include the full logs from the scans used so responders can verify that the SSODL artifacts were removed.

Recommended Answers

All 3 Replies

Hi, the first tool will remove an obvious infection, the second will check further and disclose some info I would like to see. Please run them both in the order given/
==Please download Malwarebytes' Anti-Malware
from: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html
or: http://www.besttechie.net/tools/mbam-setup.exe
=Dclick that file to install the application and ensure that it is set to update and start, else start it via the icon.
Select "Perform Full Scan", then click Scan; the application will guide you through the remaining steps.
Make sure that everything is checked, and click Remove Selected.
Post the Notepad log [it is also saved under Logs tab in MBAM].
==Download this file to your desktop:
- to run it dclick combofix.exe and follow the prompts to start it. When finished, it will produce a log, C:\Combofix.txt - post that log in your next reply.
A word of caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs reboot to restore the desktop.
So, two logs in total, please.

O21 - SSODL: axrfgvek - {3AA1CF0B-64D6-4250-A16A-6B39D719FB95} - C:\WINDOWS\axrfgvek.dll
O21 - SSODL: okmdepgb - {7A2046A5-4F19-4F1B-8709-686B7F246392} - C:\WINDOWS\okmdepgb.dll

These two entries ought not to be there. These are confirmed class *B* threats and are known to cause computer dysfunction.

As to the Regedit problem, you can do this:

Start -> Run -> gpedit.msc -> User Configuration -> Administrative Templates -> System -> Prevent access to registry editing tools -> Right Click Properties -> Disabled

For the 'control panel missing' part of the question, you can download SDFix from here. It will do a scan like the one HiJack This does and it will enable all disabled components.

Goodluck

Thankyou both for your input. I will attempt to get to these suggestions this evening.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.