video.exe - morpheus

Discussion in 'Malware Help (A Specialist Will Reply)' started by cokeman, Jun 27, 2007.

  1. cokeman

    cokeman Private E-2

    Help!! Please!
    I downloaded a zip file (Super Natural 7) which contained a file video.exe. It passed virus check twice , zipped and unzipped. When I ran the exe , nothing happened, so I thought. Then a min later Bearshare,Morpheus,and Shareaza all came up. If I close them all , 10-15 sec later they start again. When this happens a file is create that my virus program detects and deletes (C:program files/uy.exe) this is just a decoy
    CA Antivirus list it as Rbot/GZK and will delete it, but its not the main root of the problem. Will HiJackThis! help me in this case?
    Also Ctrl+Alt+Delete is disabled so I cant see the Task window

    Windows XP , CA AntiTrust Suite, and last 2 days AVG v7.5
    Any advice or help truely appreciated
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Hi...my name is Tim and I will be helping you.

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. cokeman

    cokeman Private E-2

    Thanks Tim

    I think I have it fixed. I ran the scans in Read First..etc., or the ones I could get to run and Bitdefender seemed to clean it up . Here is the log for that one. It was something named Backdoor.Genlot.KK

    Thanks a million for the help with what scans to do and where to find them
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It did remove a lot ....however, it never removes it all!!

    To be sure you are free of malware, I would suggest that you attach logs for:
    ShowNew
    GetRun
    HJT
     
  5. cokeman

    cokeman Private E-2

    Ok Tim ,
    I have run the scans and here are the 3 files you asked me to upload.

    Btw, I guess your right. My system still doesnt seem quite right. Another systom or maybe something all together different is that my browser keep no history or autoform infomation. Might be due to some of this , or could be something else , I dont know.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 2"
    J2SE Runtime Environment 5.0 Update 4"
    J2SE Runtime Environment 5.0 Update 6
    MarketResearch

    Reboot and install:
    Java Runtime 6

    Spytech SpyAgent ---- I assume you installed this.

    Do you know what these are (delete them if you don't):
    C:\Program Files\a.ico
    C:\Program Files\a.zip
    C:\Program Files\b.ico
    C:\Program Files\b.zip
    C:\Program Files\c.zip
    C:\ss
    C:\Windows\AgentSS

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking fix, exit HJT.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. BUT Reboot in Safe Mode.

    The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.

    Now reboot into normal mode and attach this new rapport.txt log here.
    Now attach new logs from:

    * GetRunKey
    * ShowNew
    * HJT

    How are things working now?
     
  7. cokeman

    cokeman Private E-2

    ok first I couldnt remove the j2se runtime environment 5.0 updates.
    it would say wait while initializing, then tell me to remove them in add/remove (which is where I was) and then end with a install error message.

    So, I installed the Java 6 and continued on with your instructions.

    Here is the first rapport.txt file you wanting me to attached

    The rest to follow in next reply
     

    Attached Files:

  8. cokeman

    cokeman Private E-2

    I removed the programs in C:\program files\ . Those are the ones that the virus kept creating.

    I did install spyagent on purpose, to monitor activity on my computer when I not home.

    did HJT , fixed reg, then run smitfraudfix twice , one normal and one safe mode.

    Rebooted did the 3 scans again and here are the logs.


    I now humble await you reply and opinion.
     

    Attached Files:

  9. cokeman

    cokeman Private E-2

    Sorry , I just looked over your directions again and realized I forget to post the newest HJT log.

    Here it is
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Success ....Your logs look clean. You may uninstall any programs we had you download (including Counterspy).

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds