| View previous topic :: View next topic |
| Author |
Message |
Mister2
SRT Team Lead
 Premium Member
 Joined: Oct 28, 2004 Posts: 7329
|
Posted: Thu Feb 23, 2006 9:41 pm Post subject: |
|
|
Hi AeyhHyon,
What were the results of following the Castlecops MRP (from the link posted by Ikeb above)?
Also, please post a link to your HiJackThis log - I can't seem to find it in the HJT forum.
What firewall are you using? You should be able to block communications between your system and an IP address in your firewall settings. _________________ Never stop learning
|
|
| Back to top |
|
 |
IP: 62.31.*.*
Guest
|
Posted: Thu Mar 09, 2006 3:53 am Post subject: Re: Spyware found on my computer so far |
|
|
| AeyhHyon wrote: | This is what I found with anti spyware prior to my computer crashing:
PeopleOnPage.Apropos.media
NavExcel
Viewpoint Toolbar
This is what my antispyware program found after my computer was repaired:
1) WebTrends
user@statse.webtrendslive[2].txt
2) Advertising.com/Teknosurf
user@advertising[1].txt
3) Hitbox.com
user@hitbox[2].txt
4) Mediaplex.com [author]
user@mediaplex[1].txt
5) QuestionMarket.com
user@questionmarket[1].txt
6) AtlasDMT.com
user@atdmt[2].txt
7) Servedby.Advertising.com
user@servedby.advertising[1].txt
TribalFusion.com
user@tribalfusion[2].txt
9) 2o7.net
Onmiture Inc (author)
user@2o7[2].txt
10) Citi.Bridgetrack
user@citi.bridgetrack[1].txt
11) Edge.ru4
user@edge.ru4[1].txt
12) Server-Sys
user@server-sys[2].txt
My Firewall program has not been operating from Jan 21 till today, Jan 25. |
|
|
| Back to top |
|
 |
AeyhHyon
Trooper

 Joined: Dec 21, 2005 Posts: 15 Location: USA
|
Posted: Mon Mar 27, 2006 2:28 am Post subject: What is msmsg.exe, backdoor.simali? |
|
|
I found msmsg.exe to be active (Verizon Internet Security Suite) even though I was not even on the internet ( my modem was not powered on). Securityresponse.symantec.com listed msmsg.exe as a trojan horse nicknamed backdoor.simali as of April 2003. I think this is what is causing the unsolicited VOIP to occur even though I have never even signed up for free VOIP, VONAGE, SKYPE or any type of VOIP, computer to phone whatever. I'm not sure what to do except to notify my phone and DSL provider as well as file a complaint to the FCC and FTC.
|
|
| Back to top |
|
 |
Mister2
SRT Team Lead
 Premium Member
 Joined: Oct 28, 2004 Posts: 7329
|
Posted: Mon Mar 27, 2006 5:39 am Post subject: |
|
|
That's a sneaky one - msmsgs.exe is a valid Windows file, msmsg.exe is a baddie.
Have you removed the infection? _________________ Never stop learning
|
|
| Back to top |
|
 |
AeyhHyon
Trooper

 Joined: Dec 21, 2005 Posts: 15 Location: USA
|
Posted: Thu Jul 27, 2006 12:19 am Post subject: |
|
|
Okay. Just what does msmsg.exe do?
There is one computer worm? virus again on my computer:
• C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b0544029296256eb4be343af6cab8e73_3b78d46a-d7fa-43b2-a5d5-24cbee5e4641
What does this one do?
|
|
| Back to top |
|
 |
Mister2
SRT Team Lead
 Premium Member
 Joined: Oct 28, 2004 Posts: 7329
|
Posted: Thu Jul 27, 2006 4:34 am Post subject: |
|
|
Hi AeyhHyon,
msmsg.exe could do anything, but generally it seems to be associated with providing an unauthorised access point to your system.
Earlier in this thread you have been requested 5 times to run through our Malware and Removal Procedure . You have 3 other threads relating to this problem which have been locked in order that we can keep our assistance confined to one thread (this thread).
here you stated on 29th December that you had submitted your HJT log, yet in this thread on 7th January you claimed you didn't know how to post a log. A full HJT log has never been posted on this site.
Once again, I ask you to run through the MRP . You should follow Step 1, miss out Steps 2 & 3, then run through Steps 4 to 10. Step 10 has clear instructions telling you how to post a HiJackThis log and lists all the information our experts will need to assist you. To post a link to this thread, simply highlight and copy this - /postlite143250-.html - then paste it into your post in the HiJackThis forum.
If you find you still cannot submit a log then post back here and we will sort that out. The MRP will clean out many things on your system but I still feel it is important to have your log read.
Mister2 _________________ Never stop learning
|
|
| Back to top |
|
 |
|
|