Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » msmr32g.exe trojan?
Search Topic:
Uniqs:
446
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Why am I failing the GRC Shieldsup test with ZAP 5 »
« New ver of wu5 to allow pirated keys after all?  
AuthorAll Replies

ktronic

join:2003-06-06
Keswick, ON

msmr32g.exe trojan?

Does anyone know what this process is? I googled it and can't find anything. I have run updated versions of spybot, a squared, adaware, and the full version of panda without much luck. Running ad aware in safe mode found some items but when it goes to quaranteen them the program hangs (even in safe mode). I get popups in internet explorer (ive been using firefox which is fine) but that isn't my main concern- whenever I find msmr32g.exe running my dumeter (bandwidth monitor) shows a constant upload of data that I can't track to any app or user. Over the last few weeks whenever I caught it it was at 10k/sec and it stops as soon as I end the process. What scares me is after leaving my computer on last night I came back to it uploading at over 600k/sec!! The dumeter totals for todays date show almost 15GB uploaded! I have never seen speeds like this I have regular rogers highpeed and always uploaded at about 45k/sec - where I assumed its capped. Iam not hooked up to a LAN or wireless network. Once again I ended msmr32g.exe and the stream stopped. Any help with what this is or how I can figure out what files exactly they are taking would be appreciated.


Kayrac
Premium
join:2001-09-29
Madison, WI

sounds like it could be, i'd suggest going to start, run, type in msconfig......click the startup tab, find that msmr32g.exe, uncheck it(so it won't startup)
and then following the steps in this link
»Security »I think my computer is infected or hijacked. What should I do?
if it can't startup atleast it can't do anything


Kayrac
Premium
join:2001-09-29
Madison, WI


1 edit
also found it in this link
»www.security-forums.com/forum/vi···p=111662
"hey um i did the fix again with hijack i did a scan with trend, it doesnt find anything, but with mcfee it sound anotehr virus:

List of Infected Files
File Name Virus Name
C:\WINDOWS\system32\hetagt.exe W32/Sdbot.worm.gen.j
C:\WINDOWS\system32\lreesx.exe W32/Sdbot.worm.gen.j
C:\WINDOWS\system32\msmr32g.exe W32/Sdbot.worm.gen.g
C:\WINDOWS\system32\msrtwd.exe Morphine
C:\WINDOWS\system32\TFTP3236 W32/Sdbot.worm.gen.j "

looks like an sdbot version, so probably is a trojan

for a second opinion you should goto this site
»virusscan.jotti.dhs.org/
all you gotta do is click browse and find the file, and that site will scan it through quite a few virus scanners
a very good site by the way
again i'd definitely use msconfig(which i showed in my earlier reply) and uncheck it so it can't startup
Forums » Up and Running » Security » SecurityWhy am I failing the GRC Shieldsup test with ZAP 5 »
« New ver of wu5 to allow pirated keys after all?  


Thursday, 02-Sep 11:49:22 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 11 years online! © 1999-2010 dslreports.com.
page compression OFF
Most commented news this week
· [101] U.S. Consumers Continue To Hate Offshore Support
· [79] Apple TV Mark II
· [66] AT&T U-Verse Pulls Plug On Hallmark Channel
· [64] Sorry Debunkers, Cord Cutters Are Very Real
· [49] Google Prepping Pay-Per-View Films
· [48] Verizon 15 Mbps Could Be 'Last Copper Upgrade'
· [46] Verizon Bumps Max DSL Speeds To 15 Mbps
· [46] T-Mobile HSPA+ Upgrades Keep On Rolling
· [36] T-Mobile Confirms 42 Mbps In 2011
· [29] Hulu Well Aware Hulu Plus Is Underwhelming
Most people now reading
· We may be getting DDOSd right now.... [TekSavvy]
· Has anyone gotten the $40 unlimited deal? [cover,3595]
· [Rant] Citibank [Rants, Raves, and Praise]
· Have you thought of Hiring more people to answer the phone!! [TekSavvy]
· Switching to Vonage. [TekSavvy]
· Pointing the gun at your own foot is not the gun's fault [Security]
· DIR:655 - Virtual Server broadcast address in 1.31 [D-Link]
· How do you manager your End User PST Files? [No, I Will Not Fix Your #@$!! Computer]