Videos.exe virus

Posted on 2008-11-19
Last Modified: 2013-12-09
My system is infected with virus.  I am not sure the nmae of the virus as the anti virus program is not detecting the virus.    What i noticed is that files videos.exe and new folder.exe is present plus a number of other executable.  The students are unable to logout and the virus is spreading.  You can see attached file for example.
Question by:rwhittle
    LVL 1

    Expert Comment

    Go to the Run Command (Start->Run) Type msconfig, press Enter. Go to the Startup tab and look down the Items. See if anything such as the Video.exe or NewFolder.exe is running. Uncheck the box, then hit apply. It will ask for a restart, so go ahead. This should disable the programs from starting up, in turn allowing you to delete the folders. After deleting, run several different anti-virus programs. One program alone usually doesn't fix the problem. AVG free is a good free program ( or CCleaner ( They require you to create an account, and it gives you a 30 day trial on the CCleaner. Hope this helps!
    LVL 1

    Expert Comment

    by:hybridrocknroll also has a removal tool if you're having the symptoms that won't let you access your Run command.

    Author Comment

    still not working. For some reason when I check registry path I don't see any of the keys that are suggested.

    Author Comment

    This is another image of the malware or virus

    Author Comment

    When I check processes I realize that a lsass.exe file if running from c:\winnt\db5d\lsass.exe also services.exe is running from the same path likewise csrss.exe.  I have Mcafee on my system ver 8 fully updated and it is running over the file and no recognizing them as malware/virus/trojans.
    LVL 47

    Expert Comment


    Run Flash_Disinfector.exe or Combofix:
    1. Download and run this tool and follow the prompts:

    2.  Please download ComboFix by sUBs:
    You must download it to and run it from your Desktop
    Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
    Double click combofix.exe & follow the prompts.
    When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
    Re-enable all the programs that were disabled during the running of ComboFix..

    Do not mouse-click combofix's window while it is running. That may cause it to stall.
    CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

    You can also try Malwarebytes
    Download Malwarebytes' Anti-Malware to your desktop. check for Updates before scanning.
    LVL 10

    Expert Comment

    You might also want to download and run HijackThis, and post the log file here.


    Accepted Solution

    I captured the virus and sent it to Mcafee, in which they gave me an extra.dat file that fixed the problem.  The virus was key logger.

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    How your wiki can always stay up-to-date

    Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
    - Increase transparency
    - Onboard new hires faster
    - Access from mobile/offline

    Ever notice how you can't use a new drive in Windows without having Windows assigning a Disk Signature?  Ever have a signature collision problem (especially with Virtual Machines?)  This article is intended to help you understand what's going on and…
    This is an article about Leadership and accepting and adapting to new challenges. It focuses mostly on upgrading to Windows 10.
    Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…
    The Task Scheduler is a powerful tool that is built into Windows. It allows you to schedule tasks (actions) on a recurring basis, such as hourly, daily, weekly, monthly, at log on, at startup, on idle, etc. This video Micro Tutorial is a brief intro…

    761 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    14 Experts available now in Live!

    Get 1:1 Help Now