Go Back   Cyber Tech Help Support Forums > Operating Systems > Windows NT, 2000, 2003

Notices

Reply
 
Topic Tools
  #1  
Old June 21st, 2003, 05:38 AM
ECO ECO is offline
New Member
 
Join Date: Aug 2002
Posts: 13
Question What is efes.exe

A few days ago a file named efes.exe showed up on my comp, in the All Users\Start Menu\Programs\Startup folder under Documents & Settings, which I have no idea of its purpose or danger. It also seemed to show up on my bro's comp the same day.
Reply With Quote
  #2  
Old June 21st, 2003, 06:51 AM
AnnMarie's Avatar
AnnMarie AnnMarie is offline
Cyber Tech Help Moderator
 
Join Date: Oct 2001
Location: New Zealand
Posts: 48,434
Hi Eco - rightclick on the file and choose Properties. What does it say?

I ran a search but I cannot find any mention of this file so it might be a good idea if had a look at your startups. Go here and download and run Startup List. It will generate a log file. Copy the log and paste it back into this thread.
__________________
Moderator: Vista Forum

Microsoft MVP - Windows Desktop Experience 2004-2008

If we have helped you, please consider supporting Cyber Tech Help with a subscription

Please do not send me Emails or Private Messages for personal support. Last time I checked, there were still only 24 hours in a day. Thank you.

How to help prevent re-infection
Reply With Quote
  #3  
Old June 22nd, 2003, 10:41 PM
ECO ECO is offline
New Member
 
Join Date: Aug 2002
Posts: 13
I guess I should have mentioned that it runs in the background when Windows boots and everytime I delete the file it seems to recreate itself somehow, but not instantaneously.

Do you still need to see a log of my startup list?
Reply With Quote
  #4  
Old June 22nd, 2003, 10:48 PM
tb525 tb525 is offline
Hijack Advisor
 
Join Date: Sep 2002
O/S: Windows Vista
Posts: 3,132
Yes, Please post the StartupList log.
Reply With Quote
  #5  
Old June 22nd, 2003, 10:55 PM
ECO ECO is offline
New Member
 
Join Date: Aug 2002
Posts: 13
Post

My startuplist is attached.
Attached Files
File Type: txt startuplist.txt (6.3 KB, 4 views)
Reply With Quote
  #6  
Old June 23rd, 2003, 01:07 AM
ECO ECO is offline
New Member
 
Join Date: Aug 2002
Posts: 13
Angry

I found out that it's a polymorphic virus named W32.BugBear.B@mm !!

It is fairly serious because it allows the virus author to control your PC, start or stop process, etc. etc. and it's also a keylogger which sends off all you typings to one of many predefined email addressed every 2 hours. It is treatable since the June 5th, 2003 Norton Anti-Virus update.
Reply With Quote
  #7  
Old June 23rd, 2003, 01:16 AM
AnnMarie's Avatar
AnnMarie AnnMarie is offline
Cyber Tech Help Moderator
 
Join Date: Oct 2001
Location: New Zealand
Posts: 48,434
You have a couple of registry entries that I cannot identify. Have you installed Morgan M-JPEG codec V3?

I cannot see any antivirus software running on your PC so I think if might be a good idea to run an online scan here. Please post back the log.

Also, because you are running Win2K, Go here and download and run a scan with Hijack This. Dont make any changes, just click on Save Log, copy it and post it back in this thread. We can use this program make any registry changes necessary without having to access the registry.
__________________
Moderator: Vista Forum

Microsoft MVP - Windows Desktop Experience 2004-2008

If we have helped you, please consider supporting Cyber Tech Help with a subscription

Please do not send me Emails or Private Messages for personal support. Last time I checked, there were still only 24 hours in a day. Thank you.

How to help prevent re-infection
Reply With Quote
  #8  
Old June 23rd, 2003, 01:22 AM
AnnMarie's Avatar
AnnMarie AnnMarie is offline
Cyber Tech Help Moderator
 
Join Date: Oct 2001
Location: New Zealand
Posts: 48,434
Looks like we cross posted. OK, go here and download and run the Bugbear B removal tool. Follow the instructions on the site.

When you have finished, please refer to my earlier post and run the RAV scan and post the logs.
__________________
Moderator: Vista Forum

Microsoft MVP - Windows Desktop Experience 2004-2008

If we have helped you, please consider supporting Cyber Tech Help with a subscription

Please do not send me Emails or Private Messages for personal support. Last time I checked, there were still only 24 hours in a day. Thank you.

How to help prevent re-infection
Reply With Quote
  #9  
Old June 23rd, 2003, 01:25 AM
TonyKlein's Avatar
TonyKlein TonyKlein is offline
MVP
 
Join Date: Oct 2001
Location: Netherlands
Posts: 289
Quote:
Originally posted by AnnMarie
I cannot see any antivirus software running on your PC so I think if might be a good idea to run an online scan here. Please post back the log.

Well, one of the things that BugBear does, is attempt to terminate anti-virus and security programs, and this could be exactly what happened: after all a NAV browser plugin is in evidence.

Maybe ECO was running NAV, but got infected before the updated definitions had been installed.

If that's the case, after running the removal tool and an online scan, be sure to uninstall and reinstall your antivirus.
__________________
Tony < - > CLSID List
Reply With Quote
Reply

Bookmarks

Topic Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT +1. The time now is 07:37 AM.

[ RSS ]