Forums » Air Combat & Civil Aviation » European Air War » OT// I wasted 3 hours due to msa.exe web dropper


Topic Options
Rate This Topic
Hop to:
#2901550 - 11/15/09 07:11 PM OT// I wasted 3 hours due to msa.exe web dropper
RAF_Roy Offline
EAW Codegruppe Bodger
Senior Member

Registered: 08/04/02
Posts: 2579
Loc: So. California - U.S.A.
Hi all,

Just a head's up if you do like I did and stupidly download something from an unknown and then allow it to run in hopes of getting an expired software to work:

The scenario a Dell machine with Vista x64 like new, not mine.
2 days ago I download a 'patch' (yeah you know the real word I just don't like to say it)
I open the file and let it run and authorize via Vista too quickly to realize it made a mutated .exe file first (whoops).
I thought something was up but then nothing happened for awhile, while surfing internet.
Then I get seperate brower window open a pop-up.. hmmm.. after awhile another..
so I shut it down, took it offline.

Meanwhile I use my laptop

After that I got next time I ran the machine, I get these pop-ups - no not the normal, more like the old style I haven't seen in years usually made from javascript got from wares sites.
So I figure np, root out the temp and temp internet files, etc. right?
Wrong!
Now this machine has McAfee antivirus , but no detect.
Next I go through the usual regimen of things to do - as you all know I am not unexperienced in PC and software technical.
But to no avail.
mutants keep spawning and grabbing javascipts and so forth.
I download Avira Antivir which has never failed me in 3 + years. No detect.
So then Superantispyware, which detects it as trojan.dropper/win NV connected to msa.exe and the 87 cookies it just downloaded (again), cleans it but it comes back.
I turn off all browser scripting, etc.
Finally a lot more cleaning, turn of system restore, reboots, etc. and then term the process msa.exe from taskmanager (again)
and delete the file from C;\Windows.

Finally Gone.

3 hours, and almost about to make a whole backup of the documents on the machine but didn't for fear code mutated hiding in them.

Fortunately it was a non-lethal product.

So the short story look to the taskmanager for msa.exe , if you have it and above symptoms term it, lock it down and delete first then clean up after, I could have saved myself 2 hours!

duckhunter


Edited by RAF_Roy (11/15/09 07:12 PM)
_________________________
~ Celebrating 10 Years of EAW ~
Roy's
|| WebRing site
|| TallyHo pages ||

Top
#2901565 - 11/15/09 07:41 PM Re: OT// I wasted 3 hours due to msa.exe web dropper [Re: RAF_Roy]
RAF_Roy Offline
EAW Codegruppe Bodger
Senior Member

Registered: 08/04/02
Posts: 2579
Loc: So. California - U.S.A.
oh I forgot to mention the a.exe , b.exe and c.exe are spawned from the intial download run also, and b.exe tends to run in taskmanager also, but first remove msa.exe

meanwhile I have to say blocking attempted connections from shanghai , florida and cyber cafe's in no. california seem to be unrelated, but at the time I was not sure..
lol
_________________________
~ Celebrating 10 Years of EAW ~
Roy's
|| WebRing site
|| TallyHo pages ||

Top
#2902358 - 11/16/09 07:56 PM Re: OT// I wasted 3 hours due to msa.exe web dropper [Re: RAF_Roy]
Brit44 'Aldo' Offline
Every Human is Unique
Member

Registered: 01/26/06
Posts: 601
the only safe surfing is abstinence
_________________________
TPA who TWI

Top
#2902484 - 11/17/09 02:41 AM Re: OT// I wasted 3 hours due to msa.exe web dropper [Re: Brit44 'Aldo']
Skoynay Offline
Junior Member

Registered: 11/17/09
Posts: 1
Loc: Hungary
I use Virustotal, upload suspicious files - not just exes - there before running.

Top
Topic Options
Rate This Topic
Hop to:

Moderator:  Avimimus, sandbagger 

Forum Use Agreement | Privacy Statement | SimHQ Staff
Copyright 1997-2012, SimHQ Inc. All Rights Reserved.