Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
I have the video.exe virus - help
   
BullGuard Antivirus Forum > Virus Removal > Removal Tools > I have the video.exe virus - help  
Forum Quick Jump
 
New Topic Locked Topic Printable version of : I have the video.exe virus - help
[ << Previous Thread | Next Thread >> ]

rjmsmith
New Member


Date Joined Jun 2008
Total Posts : 10
 
   Posted 7-18-2008 5:44 (GMT +1)    Quote: I have the video.exe virus - helpAlert an admin about: I have the video.exe virus - help
Hi Guys,

I have the video.exe virus on my new computer, which is blocking Internet access. I am using a dial-up line on my old computer, and it is v-e-r-y slow. Too slow for even this forum! Can anyone advise me of what I can do to get rid of the virus? You'll have to take me step by step as I know nothing about viruses, after being in IT for 45 years!

Thanks Guys, Roger.
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13642
 
   Posted 7-18-2008 6:10 (GMT +1)    Quote: I have the video.exe virus - helpAlert an admin about: I have the video.exe virus - help
Hello smile
 
 
 
1. Get this version of Hijackthis from http://danborg.org/spy/hjt/alternativ.exe
 
2
Save it in a permanent folder of your choice, such as C:\HJT\. To create this specific folder on your hard drive: Double click the 'My Computer' icon on your desktop, then under the category hard disk drives: double click Local Disk:, then select file->New -> Folder and name it HJT
3 Run hijackthis.  (alternativ exe).

Choose the "Do a system scan and save a log file" option to perform your scan.
HijackThis will analyze your system, and automatically open a notepad textfile containing the HijackThis log when the scan is finished.
Open the text files containing the logs with a text editor and click Edit -> Select All, followed by Edit -> Copy.
From within the browser window and with the message body text box selected, click Edit -> Paste.
Post  hijackthis log here


Do NOT post your problem in someone elses thread.
Member of - Alliance of Security Analysis Professionals
Please do NOT PM me any logs. They will be deleted

Back to Top
 

rjmsmith
New Member


Date Joined Jun 2008
Total Posts : 10
 
   Posted 7-18-2008 6:19 (GMT +1)    Quote: I have the video.exe virus - helpAlert an admin about: I have the video.exe virus - help
Hi Touch,

After copying the HijacKThis program onto a CD, I ran Hijack This on the new computer and got the message in the header "HijackThis - v1.99.1 (Not Responding)". It performed satisfactorily and produced a list which I could not access. I ran it again with the same result. And again.

What do I do next?

Regards, Roger.
Back to Top
 

rjmsmith
New Member


Date Joined Jun 2008
Total Posts : 10
 
   Posted 7-19-2008 10:34 (GMT +1)    Quote: I have the video.exe virus - helpAlert an admin about: I have the video.exe virus - help
Hi again Touch,

The message is the same, but there is another in the gray line - "023 - NT Services" in red. I don't know if this will help.

My computer is misbehaving: Ctrl-Alt-Del does not work, I can't fire-up Paint Shop Pro or I could have sent you a screen print, and it doesn't terminate normally when I hit the STOP button - I have to physically switch off.

By the way, I'm in Goa, India. The locals have a solution - wipe the disk of everything, & re-install XP. Problem is, I have about 300 apps for my website building business. I can always use PC mover to restore them, but it takes 12 hours or so, and there are frequent power cuts. This is the monsoon. Even my UPS only gives me 2 hours.

Regards, Roger.
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13642
 
   Posted 7-19-2008 10:42 (GMT +1)    Quote: I have the video.exe virus - helpAlert an admin about: I have the video.exe virus - help
Ok. See if you can run this -
 
Please download Malwarebytes' Anti-Malware:
 
 to your desktop.
 
Double-click mbam-setup.exe and follow the prompts to install the program.
                     
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch

Malwarebytes' Anti-Malware, then click Finish.
                     
If an update is found, it will download and install the latest version.
                     
Once the program has loaded, select Perform full scan, then click Scan.
                     
When the scan is complete, click OK, then Show Results to view the results.
 
Be sure that everything is checked, and click Remove Selected.
 
When completed, a log will open in Notepad. Please save it to a convenient location.
 
Copy and Paste that log into your next reply.


Do NOT post your problem in someone elses thread.
Member of - Alliance of Security Analysis Professionals
Please do NOT PM me any logs. They will be deleted

Back to Top
 

rjmsmith
New Member


Date Joined Jun 2008
Total Posts : 10
 
   Posted 7-21-2008 5:57 (GMT +1)    Quote: I have the video.exe virus - helpAlert an admin about: I have the video.exe virus - help
Hi Touch,

I ran mbam-setup on the new computer. The boxes were already ticked (update and launch). The update failed because I do not have access to the Internet. The program switched automatically to scanning mode. I selected Perform Full Scan, then clicked scan. The scan did not complete: it is now hanging on the scan screen with "Objects scanned:0 Objects infected:0 Time elapsed: 1 second(s). Currently scanning: Preparing for the scan". I am about to abort the scan.

Regards, Roger.
Back to Top
 

rjmsmith
New Member


Date Joined Jun 2008
Total Posts : 10
 
   Posted 7-21-2008 6:03 (GMT +1)    Quote: I have the video.exe virus - helpAlert an admin about: I have the video.exe virus - help
Touch,
I have just had a message from David Crone, but every time I try to reply I get a postmaster message saying the message has failed. The message reads :

"Hello rjmsmith,
You are receiving this e-mail since you subscribed to the thread titled "I have the video.exe virus - help" on the BullGuard Antivirus Forum forum and Touch just posted a new reply.

You will not receive another message regarding additional posts on this thread until you view this thread again. "

My reply:

"Hi David,

I've been checking the thread three time a day! I've seen Touch's 2nd reply to my post.
I have seen three icons on the heading, have tried all of them, and don't see any others.
How do I mark the items as read?

Regards, Roger."
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13642
 
   Posted 7-21-2008 1:54 (GMT +1)    Quote: I have the video.exe virus - helpAlert an admin about: I have the video.exe virus - help
See if you can run Malwarebytes' Anti-Malware from safe mode


Do NOT post your problem in someone elses thread.
Member of - Alliance of Security Analysis Professionals
Please do NOT PM me any logs. They will be deleted

Back to Top
 

rjmsmith
New Member


Date Joined Jun 2008
Total Posts : 10
 
   Posted 7-22-2008 6:46 (GMT +1)    Quote: I have the video.exe virus - helpAlert an admin about: I have the video.exe virus - help
Hi Touch,

Success at last! I ran Malware in Safe mode, and include the log file here. I also ran HijackThis, and include the log file after Malware. Thanks.

Malware Log file:
Malwarebytes' Anti-Malware 1.21
Database version: 966
Windows 5.1.2600 Service Pack 2

09:39:39 22/07/2008
mbam-log-7-22-2008 (09-39-31).txt

Scan type: Full Scan (C:\|)
Objects scanned: 142918
Time elapsed: 29 minute(s), 0 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 13
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 13

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2eff3cf7-99c1-4c29-bc2b-68e057e22340} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{a6573479-9075-4a65-98a6-19fd29cf7374} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{3c0c31a2-70a2-11d1-b69e-444553540000} (Spyware.Comet.Cursor) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CbEvtSvc (Trojan.MyDoom) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Comet (Spyware.Comet.Cursor) -> No action taken.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\StartMenuLogOff (Hijack.StartMenu) -> Bad: (1) Good: (0) -> No action taken.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Program Files\MSN Messenger\msimg32.dll (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MSN Messenger\riched20.dll (Adware.MyWeb.FunWeb) -> No action taken.
C:\System Volume Information\_restore{FCE6E9DA-16AE-4CD2-A8D9-8F4A5F18AA8D}\RP182\A0023333.dll (Adware.MyWebSearch) -> No action taken.
C:\System Volume Information\_restore{FCE6E9DA-16AE-4CD2-A8D9-8F4A5F18AA8D}\RP186\A0061824.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{FCE6E9DA-16AE-4CD2-A8D9-8F4A5F18AA8D}\RP187\A0065197.exe (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\CbEvtSvc.exe (Trojan.Downloader) -> No action taken.
C:\WINDOWS\system32\lphcvl1j0e53g.exe (Trojan.Agent) -> No action taken.
C:\WINDOWS\rundll32.exe (Backdoor.Bot) -> No action taken.
C:\WINDOWS\NET.EXE (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\blphcvl1j0e53g.scr (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\phcvl1j0e53g.bmp (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\TASKMON.EXE (Proxy.Agent) -> No action taken.
C:\WINDOWS\SERVICES.TXT (Heuristics.Reserved.Word.Exploit) -> No action taken.

HijackThis Log
Logfile of HijackThis v1.99.1
Scan saved at 09:50:24, on 22/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\HJT\alternativ.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/fsc/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/fuji/defaults/su/*http://www.yahoo.com
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [avast! Web Scanner] C:\PROGRA~1\ALWILS~1\Avast4\ashWebSv.exe
O4 - HKLM\..\RunServices: [avast!] C:\Program Files\Alwil Software\Avast4\ashServ.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE

Regards, Roger.
Back to Top
 

rjmsmith
New Member


Date Joined Jun 2008
Total Posts : 10
 
   Posted 7-23-2008 3:44 (GMT +1)    Quote: I have the video.exe virus - helpAlert an admin about: I have the video.exe virus - help
Hi Touch,

How are you doing with the video.exe virus?

Regards, Roger.
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13642
 
   Posted 7-23-2008 5:09 (GMT +1)    Quote: I have the video.exe virus - helpAlert an admin about: I have the video.exe virus - help
Sorry, I´ve missed you
 
 
Run  Malwarebytes' Anti-Malware again, and make sure to remove selected as desbribed here ->
 
When the scan is complete, click OK, then Show Results to view the results.
 
Be sure that everything is checked, and click Remove Selected.
 
 
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
 
 
And tell if you stil have video.exe ?


Do NOT post your problem in someone elses thread.
Member of - Alliance of Security Analysis Professionals
Please do NOT PM me any logs. They will be deleted

Back to Top
 

rjmsmith
New Member


Date Joined Jun 2008
Total Posts : 10
 
   Posted 7-24-2008 12:03 (GMT +1)    Quote: I have the video.exe virus - helpAlert an admin about: I have the video.exe virus - help
Hi Touch,

I ran Malware again, in Safe Mode, quite successfully. But, there were 14 infections the first time, and only 4 the next. I switched to normal Mode and my connection was there. I have accessed the Internet.

Thanks a million for your help, I really appreciate it. I couldn't have done it without you.

Regards, Roger.
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13642
 
   Posted 7-24-2008 12:42 (GMT +1)    Quote: I have the video.exe virus - helpAlert an admin about: I have the video.exe virus - help
That´s good news, and I was glad to help yeah
 
 
Please  read Tony Klein's excellent article  about how to prevent against  spyware/hijackers in the future
http://www.castlecops.com/t7736-So_how_did_I_get_infected_in_the_first_place.html   
 
Since your problem appears to be resolved, this thread will now be closed.
If you need this topic reopened, please PM a Moderator and we will reopen it for you
 


Do NOT post your problem in someone elses thread.
Member of - Alliance of Security Analysis Professionals
Please do NOT PM me any logs. They will be deleted

Back to Top
 
New Topic Locked Topic Printable version of : I have the video.exe virus - help
 
Forum Information
Currently it is Saturday, November 22, 2008 2:57 PM (GMT +1)
There are a total of 64.053 posts in 15.836 threads.
In the last 3 days there were 26 new threads and 156 reply posts. View Active Threads
Who's Online
This forum has 27198 registered members. Please welcome our newest member, shahed.
49 Guest(s), 2 Registered Member(s) are currently online.  Details
r1ch1e, traceyd31
5 Latest Threads
HELP I AM GOING MAD (6)22-11-2008 13:54:37 (traceyd31)
Redirecting virus? (7)22-11-2008 13:42:54 (r1ch1e)
Antivirus trigger is now the threat or what? (6)22-11-2008 13:01:06 (thegascomp)
Generic.PWS.WoW.B7078E0 (16)22-11-2008 11:55:15 (Behram)
Help please!!! (15)22-11-2008 10:05:45 (Touch)