Go Back   TechArena Community > Technical Support > Computer Help > Windows Security
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags: ,

Sponsored Links



Unknown process trying to hijack IE

Windows Security


Reply
 
Thread Tools Search this Thread
  #1  
Old 14-11-2009
RDT
 
Posts: n/a
Unknown process trying to hijack IE

At first I got these messages when I opened Firefox so I uninstalled it. Now
I get it whenever the computer boots up AND when I open IE.

“Network shield: blocked access to malicious site
files.messangerupdate.net/conf/msgutil84.dll” and
“Network shield: blocked access to malicious site
files.messangerupdate.net/conf/msgasst84.dll”. I think something is now in
the startup that is trying to access these sites but avast only blocks the
access, it didn’t find the file that’s doing it. Any suggestions?

Thanks

Reply With Quote
  #2  
Old 14-11-2009
MowGreen
 
Posts: n/a
Re: Unknown process trying to hijack IE

RDT wrote:

> At first I got these messages when I opened Firefox so I uninstalled it. Now
> I get it whenever the computer boots up AND when I open IE.
>
> “Network shield: blocked access to malicious site
> files.messangerupdate.net/conf/msgutil84.dll” and
> “Network shield: blocked access to malicious site
> files.messangerupdate.net/conf/msgasst84.dll”. I think something is now in
> the startup that is trying to access these sites but avast only blocks the
> access, it didn’t find the file that’s doing it. Any suggestions?
>
> Thanks
>


msgutil84.dll is indicative of a Vundo infection and it's
*** irrelevant *** as to which browser you use.

The Windows Software Malicious Removal tool, released monthly, has
targeted this specific malware since March 2008, but you refused to
install it, right ?


Download, install, and update -

Malwarebytes Anti-malware
http://www.malwarebytes.org

Click the 'Download free version' button.
*Save* mbam-setup.exe
When the download is finished close all open programs and browsers.
Now install MBAM and allow it to update it's definitions during it's
installation.

Once MBAM is installed and updated, boot to Safe Mode:
# Restart the computer.
# As the computer starts, press the F8 key.
# Use the arrow keys to choose Safe Mode, and then press ENTER.

Open MBAM. Do a Quick scan of the system.
When the scan is done click the Show results button
Ensure everything detected is checked, then click the Remove selected
button.

If you need further assistance suggest you post to a reputable
anti-malware forum.
*Please* read the guidelines of the forum of your choice prior to posting. -

http://www.atribune.org/forums/index.php?showforum=9
http://aumha.net/viewforum.php?f=30
http://www.bleepingcomputer.com/forums/forum22.html
http://www.dslreports.com/forum/cleanup
http://www.cybertechhelp.com/forums/...splay.php?f=25
http://www.geekstogo.com/forum/Malwa..._Here-f37.html
http://gladiator-antivirus.com/forum...?showforum=170
http://spywarehammer.com/simplemachi...php?board=10.0
http://spywarewarrior.com/viewforum.php?f=5

MowGreen
===============
*-343-* FDNY
Never Forgotten
===============

banthecheck.com
"Security updates should *never* have *non-security content* prechecked"
Reply With Quote
  #3  
Old 14-11-2009
RDT
 
Posts: n/a
Re: Unknown process trying to hijack IE

This has been a great place for info and tips and I appreciate your advice
but your criticism is uncalled for and off base. Auto update has installed
everything Microsoft put up. You have no reason to be arrogant.

"MowGreen" wrote:

> RDT wrote:
>
> > At first I got these messages when I opened Firefox so I uninstalled it. Now
> > I get it whenever the computer boots up AND when I open IE.
> >
> > “Network shield: blocked access to malicious site
> > files.messangerupdate.net/conf/msgutil84.dll” and
> > “Network shield: blocked access to malicious site
> > files.messangerupdate.net/conf/msgasst84.dll”. I think something is now in
> > the startup that is trying to access these sites but avast only blocks the
> > access, it didn’t find the file that’s doing it. Any suggestions?
> >
> > Thanks
> >

>
> msgutil84.dll is indicative of a Vundo infection and it's
> *** irrelevant *** as to which browser you use.
>
> The Windows Software Malicious Removal tool, released monthly, has
> targeted this specific malware since March 2008, but you refused to
> install it, right ?
>
>
> Download, install, and update -
>
> Malwarebytes Anti-malware
> http://www.malwarebytes.org
>
> Click the 'Download free version' button.
> *Save* mbam-setup.exe
> When the download is finished close all open programs and browsers.
> Now install MBAM and allow it to update it's definitions during it's
> installation.
>
> Once MBAM is installed and updated, boot to Safe Mode:
> # Restart the computer.
> # As the computer starts, press the F8 key.
> # Use the arrow keys to choose Safe Mode, and then press ENTER.
>
> Open MBAM. Do a Quick scan of the system.
> When the scan is done click the Show results button
> Ensure everything detected is checked, then click the Remove selected
> button.
>
> If you need further assistance suggest you post to a reputable
> anti-malware forum.
> *Please* read the guidelines of the forum of your choice prior to posting. -
>
> http://www.atribune.org/forums/index.php?showforum=9
> http://aumha.net/viewforum.php?f=30
> http://www.bleepingcomputer.com/forums/forum22.html
> http://www.dslreports.com/forum/cleanup
> http://www.cybertechhelp.com/forums/...splay.php?f=25
> http://www.geekstogo.com/forum/Malwa..._Here-f37.html
> http://gladiator-antivirus.com/forum...?showforum=170
> http://spywarehammer.com/simplemachi...php?board=10.0
> http://spywarewarrior.com/viewforum.php?f=5
>
> MowGreen
> ===============
> *-343-* FDNY
> Never Forgotten
> ===============
>
> banthecheck.com
> "Security updates should *never* have *non-security content* prechecked"
> .
>

Reply With Quote
  #4  
Old 14-11-2009
PA Bear [MS MVP]
 
Posts: n/a
Re: Unknown process trying to hijack IE

I found nothing arrogant in BroMow's post.

RDT wrote:
> This has been a great place for info and tips and I appreciate your advice
> but your criticism is uncalled for and off base. Auto update has installed
> everything Microsoft put up. You have no reason to be arrogant.
>
> "MowGreen" wrote:
>
>> RDT wrote:
>>
>>> At first I got these messages when I opened Firefox so I uninstalled it.
>>> Now I get it whenever the computer boots up AND when I open IE.
>>>
>>> “Network shield: blocked access to malicious site
>>> files.messangerupdate.net/conf/msgutil84.dll” and
>>> “Network shield: blocked access to malicious site
>>> files.messangerupdate.net/conf/msgasst84.dll”. I think something is now
>>> in
>>> the startup that is trying to access these sites but avast only blocks
>>> the
>>> access, it didn’t find the file that’s doing it. Any suggestions?
>>>
>>> Thanks
>>>

>>
>> msgutil84.dll is indicative of a Vundo infection and it's
>> *** irrelevant *** as to which browser you use.
>>
>> The Windows Software Malicious Removal tool, released monthly, has
>> targeted this specific malware since March 2008, but you refused to
>> install it, right ?
>>
>>
>> Download, install, and update -
>>
>> Malwarebytes Anti-malware
>> http://www.malwarebytes.org
>>
>> Click the 'Download free version' button.
>> *Save* mbam-setup.exe
>> When the download is finished close all open programs and browsers.
>> Now install MBAM and allow it to update it's definitions during it's
>> installation.
>>
>> Once MBAM is installed and updated, boot to Safe Mode:
>> # Restart the computer.
>> # As the computer starts, press the F8 key.
>> # Use the arrow keys to choose Safe Mode, and then press ENTER.
>>
>> Open MBAM. Do a Quick scan of the system.
>> When the scan is done click the Show results button
>> Ensure everything detected is checked, then click the Remove selected
>> button.
>>
>> If you need further assistance suggest you post to a reputable
>> anti-malware forum.
>> *Please* read the guidelines of the forum of your choice prior to
>> posting.
>> -
>>
>> http://www.atribune.org/forums/index.php?showforum=9
>> http://aumha.net/viewforum.php?f=30
>> http://www.bleepingcomputer.com/forums/forum22.html
>> http://www.dslreports.com/forum/cleanup
>> http://www.cybertechhelp.com/forums/...splay.php?f=25
>> http://www.geekstogo.com/forum/Malwa..._Here-f37.html
>> http://gladiator-antivirus.com/forum...?showforum=170
>> http://spywarehammer.com/simplemachi...php?board=10.0
>> http://spywarewarrior.com/viewforum.php?f=5
>>
>> MowGreen
>> ===============
>> *-343-* FDNY
>> Never Forgotten
>> ===============
>>
>> banthecheck.com
>> "Security updates should *never* have *non-security content* prechecked"
>> .


Reply With Quote
  #5  
Old 18-11-2009
RDT
 
Posts: n/a
Re: Unknown process trying to hijack IE

I haven't got around to checking out the links you posted but the
malwarebytes program worked great! It found 65 items that adaware and avast
did not find. Thanks again.

"MowGreen" wrote:

> RDT wrote:
>
> > At first I got these messages when I opened Firefox so I uninstalled it. Now
> > I get it whenever the computer boots up AND when I open IE.
> >
> > “Network shield: blocked access to malicious site
> > files.messangerupdate.net/conf/msgutil84.dll” and
> > “Network shield: blocked access to malicious site
> > files.messangerupdate.net/conf/msgasst84.dll”. I think something is now in
> > the startup that is trying to access these sites but avast only blocks the
> > access, it didn’t find the file that’s doing it. Any suggestions?
> >
> > Thanks
> >

>
> msgutil84.dll is indicative of a Vundo infection and it's
> *** irrelevant *** as to which browser you use.
>
> The Windows Software Malicious Removal tool, released monthly, has
> targeted this specific malware since March 2008, but you refused to
> install it, right ?
>
>
> Download, install, and update -
>
> Malwarebytes Anti-malware
> http://www.malwarebytes.org
>
> Click the 'Download free version' button.
> *Save* mbam-setup.exe
> When the download is finished close all open programs and browsers.
> Now install MBAM and allow it to update it's definitions during it's
> installation.
>
> Once MBAM is installed and updated, boot to Safe Mode:
> # Restart the computer.
> # As the computer starts, press the F8 key.
> # Use the arrow keys to choose Safe Mode, and then press ENTER.
>
> Open MBAM. Do a Quick scan of the system.
> When the scan is done click the Show results button
> Ensure everything detected is checked, then click the Remove selected
> button.
>
> If you need further assistance suggest you post to a reputable
> anti-malware forum.
> *Please* read the guidelines of the forum of your choice prior to posting. -
>
> http://www.atribune.org/forums/index.php?showforum=9
> http://aumha.net/viewforum.php?f=30
> http://www.bleepingcomputer.com/forums/forum22.html
> http://www.dslreports.com/forum/cleanup
> http://www.cybertechhelp.com/forums/...splay.php?f=25
> http://www.geekstogo.com/forum/Malwa..._Here-f37.html
> http://gladiator-antivirus.com/forum...?showforum=170
> http://spywarehammer.com/simplemachi...php?board=10.0
> http://spywarewarrior.com/viewforum.php?f=5
>
> MowGreen
> ===============
> *-343-* FDNY
> Never Forgotten
> ===============
>
> banthecheck.com
> "Security updates should *never* have *non-security content* prechecked"
> .
>

Reply With Quote
Reply

  TechArena Community > Technical Support > Computer Help > Windows Security


Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads for: "Unknown process trying to hijack IE"
Thread Thread Starter Forum Replies Last Post
help with hijack this ttenneB Networking & Security 1 08-02-2011 11:44 AM
IE 8 hijack I.N. Galidakis AntiVirus Software 10 27-08-2010 04:47 AM
Dragon Age DLC Error - Process manifest failed (unknown type) Anyone-4-CS Video Games 4 15-07-2010 05:29 PM
Unknown Process is Accessing Internet Balamohan Operating Systems 3 16-06-2009 06:52 PM
WMP 11 Unknown album/song(unknown file) krillar Windows Software 2 18-01-2008 10:59 PM


All times are GMT +5.5. The time now is 02:55 AM.