File changed into .exe & .dll due to virus

Solved/Closed
vikas651 - Mar 6, 2010 at 12:04 AM
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 - Mar 10, 2010 at 10:07 AM
Hello,
I'm on a bad problem, when I took data from memory card, then that partition of the folder's properties changed into .exe & some other into .dll . That part is not open any folder(open as like 'dos') the folder size 24 KB is visible. Partition size while ago looks like,after restart my pc then all folders hid to the another partition of the disk.What I will be able to find my data again ? Please help me,I'll be your forever grateful.thanks.specify all possibility about recover my data.thanks again.
your sincerely
Mr. Vikas Mehta (Patna,India)
Related:

8 responses

Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,172
Mar 6, 2010 at 06:00 AM
Hello Vikas,

This is more complex situation than any other virus. In order to help you I really need to identify the virus which could be a USB type virus.

To help me identify the virus ans prescribe the proper remedy, please download, install and run Hyjackthis. From Hyjackthis' main page request a scan and save log. When the scan is over a log will automatically open. PLease copy the log and paste it here.

Hyjackthis gives a picture of the processes that are running as well as of the registry entries susceptible of hiding a virus.

Here is the link to Hyjackthis:

http://free.antivirus.com/hijackthis/

Best regards

Ambucias
Shawinigan, Quebec
1
vikas651 Posts 9 Registration date Saturday March 6, 2010 Status Member Last seen March 10, 2010
Mar 6, 2010 at 08:26 AM
i paste below the hijackthis log file.i am very happy about ur kind work.For this noble cause you I will thank you wholeheartedly, I hope that you my solution to this serious problem must Lengen. I'm waiting to your trust, certainly now that you are trying I will get rid of this crisis.thanks,
your faithfully
Vikas Kumar Mehta



Logfile of Trend Micro HijackThis v2.0.3 (BETA)
Scan saved at 7:28:46 PM, on 3/6/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Micromax\MMX300G\WirelessCard.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wpabaln.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKCU\..\Run: [MyWirelessCard] C:\Program Files\Micromax\MMX300G\WirelessCard.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{8EA4F85F-375B-4A09-890F-36ECE30BC7E5}: NameServer = 218.248.255.161 218.248.240.180
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
0
vikas651 Posts 9 Registration date Saturday March 6, 2010 Status Member Last seen March 10, 2010
Mar 6, 2010 at 08:41 AM
I'm worried about this problem whole day, and I formatted the C Drive, is still producing the problem, currently I am using windows xp home edition os,
0