Wel I cant find C:\ drive and taskbar shows VIRUS ALERT!
Here is the Logfile of HijackThis v1.99.1
Scan saved at 13:07: VIRUS ALERT!, on 6/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Hi! Welcome to the forums.
My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient.
Firstly, you are using an out of date version of HijackThis. Please remove that first, then follow these instructions.
Download Deckard's System Scanner (DSS) to your Desktop. Note: You must be logged onto an account with administrator privileges.
Close all applications and windows.
Double-click on dss.exe to run it, and follow the prompts.
For Vista users, right-click DSS and select Run As Administrator
If asked to install HijackThis click on Yes
When the scan is complete, two text files will open - main.txt<- this one will be maximized and extra.txt<-this one will be minimized
Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and the extra.txt in your next reply
ALLUSERSPROFILE=C:\Documents and Settings\All Users.WINDOWS
APPDATA=C:\Documents and Settings\Anirudh\Application Data
CLASSPATH=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=RATHI
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Anirudh
LOGONSERVER=\\RATHI
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\WBEM;C:\Program Files\QuickTime\QTSystem;;C:\PROGRA~1\COMMON~1\MUVEET~1\030625;C:\Program Files\Common Files\Nero\Lib\;C:\Program Files\Common Files\Nero\Lib\;C:\Program Files\Common Files\Nero\Lib\
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 15 Stepping 13, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0f0d
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\QuickTime\QTSystem\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\Anirudh\LOCALS~1\Temp
TMP=C:\DOCUME~1\Anirudh\LOCALS~1\Temp
USERDOMAIN=RATHI
USERNAME=Anirudh
USERPROFILE=C:\Documents and Settings\Anirudh
windir=C:\WINDOWS
__COMPAT_LAYER=EnableNXShowUI
– User Profiles —————————————————————
Anirudh (admin)
– Add/Remove Programs ———————————————————
–> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
–> C:\Program Files\Nero\Nero8\\nero\uninstall\UNNERO.exe /UNINSTALL
–> C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
–> C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
–> C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
–> C:\WINDOWS\UNNeroVision.exe /UNINSTALL
–> C:\WINDOWS\UNRecode.exe /UNINSTALL
–> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
µTorrent –> "C:\Program Files\uTorrent\uTorrent.exe" /UNINSTALL
Adobe Flash Player ActiveX –> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin –> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 8.1.2 –> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
ADSL USB Driver 2.0.1 –> "C:\Program Files\ADSL Router\unins000.exe"
Apple Mobile Device Support –> MsiExec.exe /I{44734179-8A79-4DEE-BB08-73037F065543}
Apple Software Update –> MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
Bonjour –> MsiExec.exe /I{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}
Free Ipod Video Converter V 2.4 –> "C:\Program Files\Ipod Video Converter\unins000.exe"
Google Talk (remove only) –> "C:\Program Files\Google\Google Talk\uninstall.exe"
Google Toolbar for Internet Explorer –> regsvr32 /u /s "c:\program files\google\googletoolbar2.dll"
Hijackthis 1.99.1 –> "C:\Program Files\Hijackthis\unins000.exe"
HijackThis 1.99.1 –> C:\Program Files\Hijackthis\HijackThis.exe /uninstall
Horoscope Explorer Pro –> "C:\Program Files\PublicSoft\HoroExPro\unins000.exe"
iDump (Backing up your iPod) –> C:\Program Files\iDump\uninstall.exe
Intel® Graphics Media Accelerator Driver –> C:\WINDOWS\system32\igxpun.exe -uninstall
iTunes –> MsiExec.exe /I{585776BC-4BD6-4BD2-A19A-1D6CB44A403B}
J2SE Runtime Environment 5.0 Update 3 –> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150030}
Java™ 6 Update 5 –> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java™ 6 Update 6 –> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160060}
Keil µVision3 –> C:\Keil\Uninstall.exe
LimeWire PRO 4.12.3 –> "C:\Program Files\LimeWire\uninstall.exe"
LiveUpdate 3.2 (Symantec Corporation) –> "C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
Magic ISO Maker v5.4 (build 0239) –> C:\PROGRA~1\MagicISO\UNWISE.EXE C:\PROGRA~1\MagicISO\INSTALL.LOG
Magic ISO Maker v5.4 (build 0256) –> C:\PROGRA~1\MagicISO\UNWISE.EXE C:\PROGRA~1\MagicISO\INSTALL.LOG
MagicDisc 2.7.97 –> C:\PROGRA~1\MAGICD~1\UNWISE.EXE C:\PROGRA~1\MAGICD~1\INSTALL.LOG
MakeTorrent v2.1 –> "C:\Program Files\Maketorrent 2\uninstall.exe"
Microsoft Expression Web –> "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall WEBDESIGNER /dll ESETUP.DLL
Microsoft Expression Web –> MsiExec.exe /X{90120000-0026-0000-0000-0000000FF1CE}
Microsoft Expression Web MUI (English) –> MsiExec.exe /X{90120000-0026-0409-0000-0000000FF1CE}
Microsoft Office Access MUI (English) 2007 –> MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
Microsoft Office Access Setup Metadata MUI (English) 2007 –> MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
Microsoft Office Enterprise 2007 –> "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007 –> MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (English) 2007 –> MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office Groove MUI (English) 2007 –> MsiExec.exe /X{90120000-00BA-0409-0000-0000000FF1CE}
Microsoft Office Groove Setup Metadata MUI (English) 2007 –> MsiExec.exe /X{90120000-0114-0409-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (English) 2007 –> MsiExec.exe /X{90120000-0044-0409-0000-0000000FF1CE}
Microsoft Office OneNote MUI (English) 2007 –> MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}
Microsoft Office Outlook MUI (English) 2007 –> MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007 –> MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office Project MUI (English) 2007 –> MsiExec.exe /X{90120000-00B4-0409-0000-0000000FF1CE}
Microsoft Office Project Professional 2007 –> "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PRJPRO /dll OSETUP.DLL
Microsoft Office Project Professional 2007 –> MsiExec.exe /X{90120000-003B-0000-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007 –> MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007 –> MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007 –> MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007 –> MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Publisher MUI (English) 2007 –> MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007 –> MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007 –> MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Visio MUI (English) 2007 –> MsiExec.exe /X{90120000-0054-0409-0000-0000000FF1CE}
Microsoft Office Visio Professional 2007 –> "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall VISPRO /dll OSETUP.DLL
Microsoft Office Visio Professional 2007 –> MsiExec.exe /X{90120000-0051-0000-0000-0000000FF1CE}
Microsoft Office Word MUI (English) 2007 –> MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft Visual C++ 2005 Redistributable –> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Mozilla Firefox (2.0.0.14) –> C:\PROGRA~1\Mozilla Firefox\uninstall\helper.exe
Need for Speed™ Carbon –> C:\Program Files\Electronic Arts\Need for Speed Carbon\EAUninstall.exe
Nero 8 –> MsiExec.exe /X{8AEA4BE2-2B52-41C0-BB7D-9F2D17AF1033}
Nero PhotoShow Express 5 –> "C:\Program Files\Nero\PhotoShow 5\data\Xtras\Uninstall.exe"
OpenOffice.org Installer 1.0 –> MsiExec.exe /X{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}
Picasa 2 –> "C:\Program Files\Picasa2\Uninstall.exe"
QuickTime –> MsiExec.exe /I{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD}
RealPlayer –> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
REALTEK GbE & FE Ethernet PCI-E NIC Driver –> C:\Program Files\InstallShield Installation Information\{C9BED750-1211-4480-B1A5-718A3BE15525}\setup.exe -runfromtemp -l0x0009 -removeonly
Realtek High Definition Audio Driver –> RtlUpd.exe -r -m
Skype 3.0 –> "C:\Program Files\Skype\Phone\unins000.exe"
Skype add-on for IE –> rundll32 "C:\Program Files\Skype\Phone\IEPlugin\SkypeIEPlugin.dll",FriendlyUnregisterServer 0
Skype Plugin Manager –> MsiExec.exe /I{3D5E5C0A-5B36-4F98-99A7-287F7DBDCE03}
SUPERAntiSpyware Professional –> MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
VideoLAN VLC media player 0.8.6d –> C:\Program Files\VideoLAN\VLC\uninstall.exe
Videora iPod Converter 3.07 –> C:\Program Files\Red Kawa\Video Converter 3\uninstaller.exe
WinZip 11.2 –> MsiExec.exe /X{CD95F661-A5C4-44F5-A6AA-ECDD91C240B6}
WinZip E-Mail Companion –> "C:\Program Files\WinZip E-Mail Companion\uninst.exe"
Yahoo! Messenger –> C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
– Application Event Log ——————————————————-
Event Record #/Type1534 / Error
Event Submitted/Written: 06/07/2008 07:59:36 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application uv3.exe, version 3.12.6.1, faulting module uv3.exe, version 3.12.6.1, fault address 0x0011d80d.
Processing media-specific event for [uv3.exe!ws!]
Event Record #/Type1500 / Error
Event Submitted/Written: 06/07/2008 04:43:04 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application nfsc.exe, version 0.0.0.0, faulting module nfsc.exe, version 0.0.0.0, fault address 0x00330b2f.
Processing media-specific event for [nfsc.exe!ws!]
Event Record #/Type1488 / Error
Event Submitted/Written: 06/07/2008 04:30:09 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application firefox.exe, version 1.8.20080.40413, faulting module nss3.dll, version 3.11.5.0, fault address 0x000306df.
Processing media-specific event for [firefox.exe!ws!]
Event Record #/Type1486 / Error
Event Submitted/Written: 06/07/2008 02:48:03 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application nfsc.exe, version 0.0.0.0, faulting module nfsc.exe, version 0.0.0.0, fault address 0x0033099f.
Processing media-specific event for [nfsc.exe!ws!]
Event Record #/Type1474 / Error
Event Submitted/Written: 06/07/2008 02:39:33 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application nfsc.exe, version 0.0.0.0, faulting module nfsc.exe, version 0.0.0.0, fault address 0x0033099f.
Processing media-specific event for [nfsc.exe!ws!]
– Security Event Log ———————————————————-
No Errors/Warnings found.
– System Event Log ————————————————————
Event Record #/Type249 / Warning
Event Submitted/Written: 06/08/2008 10:17:53 AM
Event ID/Source: 4226 / Tcpip
Event Description:
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
Event Record #/Type245 / Warning
Event Submitted/Written: 06/08/2008 07:20:37 AM
Event ID/Source: 36 / W32Time
Event Description:
The time service has not been able to synchronize the system time
for 49152 seconds because none of the time providers has been able to
provide a usable time stamp. The system clock is unsynchronized.
Event Record #/Type241 / Warning
Event Submitted/Written: 06/08/2008 03:00:55 AM
Event ID/Source: 4226 / Tcpip
Event Description:
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
Event Record #/Type233 / Warning
Event Submitted/Written: 06/07/2008 11:36:30 PM
Event ID/Source: 1073 / USER32
Event Description:
The attempt to reboot RATHI failed
Event Record #/Type232 / Warning
Event Submitted/Written: 06/07/2008 11:22:27 PM
Event ID/Source: 4226 / Tcpip
Event Description:
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
– End of Deckard's System Scanner: finished at 2008-06-08 11:36:28 ————
I'm afraid I have unpleasant news for you. You have a Dangerous infection on this machine.
The infection is delivered by a Backdoor Trojan.
It allows outsiders COMPLETE access to every keystroke, account, and password you use while on this machine, and complete access to any other data present… IF this computer has been used for any kind of important data, my best recommendation is to Disconnect from Internet, Re-Format the entire drive and re-install your Operating system and Applications.
We can likely clean the infected files off the computer, and if you wish we will attempt to do so, but we cannot be sure that the infection didn't do something to your system to reduce the system security. In that instance, even after removal of the infection, you could be subject to another attack or takeover as soon as you re-connect to the Internet.
The Decision Whether to ReFormat or Not should be based on:
The use of the computer - this is the primary factor in the decision whether to re-format and re-install, or just disinfect.
The variety of malware - this influences the decision on whether to re-format and re-install, or just disinfect.
If the Computer has been used for any important data, you are strongly advised to do the following, immediately:
Disconnect the infected computer from the internet and from any networked computers until the computer can be cleaned.
Back up all important data on the machine. Do not back up any Applications (programs). Those should be re-installed from the original source CDs or websites.
If you have ever used this computer for shopping, banking, or any transactions relating to your financial well being:
Call all of your banks, credit card companies, and financial institutions, informing them that you may be a victim of identity theft, and to put a watch on your accounts or change all your account numbers.
From a clean computer, change ALL your online passwords – for ISP login, email, banks, financial accounts, PayPal, eBay, online companies, and any online forums or groups you belong to.
DO NOT change passwords or do any transactions while using the infected computer because the attacker will get the new password and transaction information.
Take any other steps you think appropriate for an attempted identity theft.
While you are deciding whether to ReFormat and Re-Install, a useful link is here: http://www.dslreports.com/faq/10063
Please let me know what you decide.