| I just had an identical problem, by downloadind a file using Shareaza (like Limeware, but not quite as good). Here's a report I just sent to Symantec and TrendMicro, with the fix I used. (If all else fails, and you're using Windows XP, try using a system restore from a time period before the problem occurred.)
12/10/05, Apparent virus with msMovie file ------------------------------------------
SOURCE OF VIRUS: 1. Downloaded a zip file, with an innocuous name, containing one file: video.exe. 2. Unzipped the file and launched video.exe.
SYMPTOMS OF VIRUS: 1. An executable file named MsMovies.exe runs automatically on startup (and apparently locks up Task Manager). 2. Prevents user from running Task Manager, by either using Ctrl-Alt-Del keys or running TaskMgr in the Run dialog.
CHANGES MADE BY VIRUS: 1. Creates these files: a. c:/0.exe b. c:/Program Files/msmovie, a hidden folder containing these files: v.tmp MsMovies.exe p.zip, containing the same file as the one in the original download: video.exe Adds many, many other zip files, all containing MsMovies.exe 2. Adds the following register keys: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MsMovies"="C:\\Program Files\\MsMovies\\MsMovies.exe /auto" [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache] "C:\\Program Files\\MsMovies\\MsMovies.exe"="Windows Media Video"
OTHER NOTES: 1. Virus scanner will detect a virus in c:/0.exe. 2. Even with the file c:/0.exe deleted, MsMovies.exe still runs and locks up Task Manager. 3. MsMovies.exe can't easily be terminated by user. 4. If a firewall is used and running, it can be used to terminate MsMovies.exe. 5. MsMovies.exe will still start on next start-up however.
FIX: 1. Delete register entries, above, using regedit. 2. Delete c:/0.exe, if an anti-virus program hasn't already deleted it. 3. Delete c:/Program Files/msmovie folder and it's content (you may have to set explorer to see hidden folders and files).
Ken Kuhns Computronics
|