CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

What if shimgvw.dll is listed 4 times by a filesearch?
Goto page Previous  1, 2
 
This forum is locked you cannot post, reply to or edit topics   This topic is locked you cannot edit posts or make replies       All -> FavForums -> Hexblog [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Mister2

SRT Team Lead
SRT Team Lead
Premium Member

Joined: Oct 28, 2004
Posts: 7329

Moderators MVP Premium SRT Team F@H

PostPosted: Thu Feb 23, 2006 9:41 pm    Post subject:
Reply with quote

Hi AeyhHyon,

What were the results of following the Castlecops MRP (from the link posted by Ikeb above)?

Also, please post a link to your HiJackThis log - I can't seem to find it in the HJT forum.

What firewall are you using? You should be able to block communications between your system and an IP address in your firewall settings.


_________________
Never stop learning
Back to top
View users profile Send private message
IP: 62.31.*.*

Guest






PostPosted: Thu Mar 09, 2006 3:53 am    Post subject: Re: Spyware found on my computer so far
Reply with quote

AeyhHyon wrote:
This is what I found with anti spyware prior to my computer crashing:
PeopleOnPage.Apropos.media
NavExcel
Viewpoint Toolbar

This is what my antispyware program found after my computer was repaired:
1) WebTrends
user@statse.webtrendslive[2].txt

2) Advertising.com/Teknosurf
user@advertising[1].txt

3) Hitbox.com
user@hitbox[2].txt

4) Mediaplex.com [author]
user@mediaplex[1].txt

5) QuestionMarket.com
user@questionmarket[1].txt

6) AtlasDMT.com
user@atdmt[2].txt

7) Servedby.Advertising.com
user@servedby.advertising[1].txt

Cool TribalFusion.com
user@tribalfusion[2].txt

9) 2o7.net
Onmiture Inc (author)
user@2o7[2].txt

10) Citi.Bridgetrack
user@citi.bridgetrack[1].txt

11) Edge.ru4
user@edge.ru4[1].txt

12) Server-Sys
user@server-sys[2].txt

My Firewall program has not been operating from Jan 21 till today, Jan 25.

Back to top
AeyhHyon

Trooper
Trooper


Joined: Dec 21, 2005
Posts: 15
Location: USA

PostPosted: Mon Mar 27, 2006 2:28 am    Post subject: What is msmsg.exe, backdoor.simali?
Reply with quote

I found msmsg.exe to be active (Verizon Internet Security Suite) even though I was not even on the internet ( my modem was not powered on). Securityresponse.symantec.com listed msmsg.exe as a trojan horse nicknamed backdoor.simali as of April 2003. I think this is what is causing the unsolicited VOIP to occur even though I have never even signed up for free VOIP, VONAGE, SKYPE or any type of VOIP, computer to phone whatever. I'm not sure what to do except to notify my phone and DSL provider as well as file a complaint to the FCC and FTC.

Back to top
View users profile Send private message
Mister2

SRT Team Lead
SRT Team Lead
Premium Member

Joined: Oct 28, 2004
Posts: 7329

Moderators MVP Premium SRT Team F@H

PostPosted: Mon Mar 27, 2006 5:39 am    Post subject:
Reply with quote

That's a sneaky one - msmsgs.exe is a valid Windows file, msmsg.exe is a baddie.

Have you removed the infection?


_________________
Never stop learning
Back to top
View users profile Send private message
AeyhHyon

Trooper
Trooper


Joined: Dec 21, 2005
Posts: 15
Location: USA

PostPosted: Thu Jul 27, 2006 12:19 am    Post subject:
Reply with quote

Okay. Just what does msmsg.exe do?

There is one computer worm? virus again on my computer:

• C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b0544029296256eb4be343af6cab8e73_3b78d46a-d7fa-43b2-a5d5-24cbee5e4641

What does this one do?

Back to top
View users profile Send private message
Mister2

SRT Team Lead
SRT Team Lead
Premium Member

Joined: Oct 28, 2004
Posts: 7329

Moderators MVP Premium SRT Team F@H

PostPosted: Thu Jul 27, 2006 4:34 am    Post subject:
Reply with quote

Hi AeyhHyon,

msmsg.exe could do anything, but generally it seems to be associated with providing an unauthorised access point to your system.

Earlier in this thread you have been requested 5 times to run through our Malware and Removal Procedure . You have 3 other threads relating to this problem which have been locked in order that we can keep our assistance confined to one thread (this thread).

here you stated on 29th December that you had submitted your HJT log, yet in this thread on 7th January you claimed you didn't know how to post a log. A full HJT log has never been posted on this site.

Once again, I ask you to run through the MRP . You should follow Step 1, miss out Steps 2 & 3, then run through Steps 4 to 10. Step 10 has clear instructions telling you how to post a HiJackThis log and lists all the information our experts will need to assist you. To post a link to this thread, simply highlight and copy this - CastleCops Link/postlite143250-.html - then paste it into your post in the HiJackThis forum.

If you find you still cannot submit a log then post back here and we will sort that out. The MRP will clean out many things on your system but I still feel it is important to have your log read.

Mister2


_________________
Never stop learning
Back to top
View users profile Send private message
Display posts from previous:   
This forum is locked you cannot post, reply to or edit topics   This topic is locked you cannot edit posts or make replies       All -> FavForums -> Hexblog All times are GMT
Goto page Previous  1, 2
Page 2 of 2

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer