SoftwareTipsandTricks Forum

Go Back   SoftwareTipsandTricks Forum > Operating Systems > Windows XP
User Name
Password


Hacked by vj

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes

  #1  
Old 11-23-2007, 08:12 AM
dimmy84 Offline
Registered User
 
Join Date: Nov 2007
Posts: 11
Hacked by vj

my internet explorer header says - Hacked by vj.

what do i do?

i have tried some virus scanners which have been unsuccessful

i have listed my Hijack this log below.


Logfile of HijackThis v1.99.1
Scan saved at 12:26:14 AM, on 24/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\WINDOWS\System32\WScript.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\User\Local Settings\Temp\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.footballnews.com.au/forum
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Hacked by vj
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
O4 - HKLM\..\Run: [MAAgent] C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [MS32DLL] C:\WINDOWS\MS32DLL.dll.vbs
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{FAA24228-8050-48B4-ADE8-011D00A4FC2C}: NameServer = 203.194.27.57 203.194.56.150
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Reply With Quote

  #2  
Old 11-23-2007, 09:43 AM
Generator's Avatar
Generator Offline
Registered User
 
Join Date: Aug 2007
Location: London UK
Posts: 369
get SpyBot Search and Destroy v1.4 or a spy sweeper that should remove.. its not a virus its more of maleware,,if that dont work do a google and see what apps kills it. your registry seting on ie name has been changed..by hacked by vj..your need to go into reg edit and change the name..do a google on this. its listed in your hijack this file R1 HKCU\etc
__________________
AMD Phenom 64 9850 quad core 2.5 gig Artic 64 cooler HS/F
4 gig DDR2 ram
Nvidia 9600 GT 1gb gigabyte silent PCI-E (upgraded)
sata 360gb HDD 7200
M-audio 2496
Dell silver 22 " widescreen mon
500 watt psu (upgraded) zalman silent PSU
windows xp SP3
windows vista ultimate SP1

internet connection
24 mb D/L LLU 1.5 mb U/L

Last edited by Generator : 11-23-2007 at 10:00 AM.
Reply With Quote

  #3  
Old 11-23-2007, 11:11 PM
dimmy84 Offline
Registered User
 
Join Date: Nov 2007
Posts: 11
Thankyou for your help, i have downloaded spybot and it did not remove it.

i changed the registry key setting also as per some info i found on google but it reappeared.

also i can not access my c drive which is my main driver.
Reply With Quote

  #4  
Old 11-24-2007, 05:21 AM
Generator's Avatar
Generator Offline
Registered User
 
Join Date: Aug 2007
Location: London UK
Posts: 369
http://housecall.trendmicro.com/ ok go here if you can do a online scan for virues and maleware it should detect the virus and remove ,,make sure you do a full scan for viruses and maleware.
__________________
AMD Phenom 64 9850 quad core 2.5 gig Artic 64 cooler HS/F
4 gig DDR2 ram
Nvidia 9600 GT 1gb gigabyte silent PCI-E (upgraded)
sata 360gb HDD 7200
M-audio 2496
Dell silver 22 " widescreen mon
500 watt psu (upgraded) zalman silent PSU
windows xp SP3
windows vista ultimate SP1

internet connection
24 mb D/L LLU 1.5 mb U/L
Reply With Quote

  #5  
Old 11-25-2007, 06:26 PM
dimmy84 Offline
Registered User
 
Join Date: Nov 2007
Posts: 11
Thanks Generator, this seems to have worked and now also allows me to access my C Drive.

Thankyou,
Reply With Quote
Reply




Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
hotmail email account hacked mahra Internet 4 09-19-2006 11:30 PM
Am i hacked? Rooted?? (Windows XP Pro) Anderson Windows XP 0 11-24-2005 08:49 PM
Cracked or hacked!? lwp_iname Windows XP 2 05-19-2005 10:32 PM
Email account has been hacked? mshussain76 Internet 3 04-09-2005 01:25 PM
got hacked, need help restoring admin *DEAD* Windows XP 1 04-02-2005 05:43 AM



All times are GMT -5. The time now is 04:18 PM.


Designed by eXtremepixels. Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 2.3.2 © 2005, Crawlability, Inc.