Results 1 to 2 of 2

Thread: Suspicious file => msmapi32.exe

  1. #1
    Junior Member
    Join Date
    Oct 2006
    Location
    Michigan
    Posts
    1

    Default Suspicious file => msmapi32.exe

    I'm just posting a recent experience with a friends infected computer.

    In summary, I could not get rid of the infection mentioned by others on this forum, including the systray notification about "antispyware update needed" etc., even after doing everything posted in the threads on this forum.

    I noticed the file c:\Windows\System32\msmapi32.exe . When I renamed and moved this file, I was able to disinfect the machine for the first time. This file was missed by SpyBot, Ad-Aware, CWshredder, Avast antivirus, BHODemon, etc. (all with updated definitions, then the most thorough scan modes in safe mode).

    I also ran Activescan (pandasoftware) and Housecall (TrendMicro).

    More detail:

    Bottom line is I could completely "clean" the machine in safe mode using all of these programs, but when I would re-boot into standard WindowsXP, exactly 9 instinces of coolwwwsearch variants (CWShredder), 39 BHOs (BHODemon), and numerous SpyBot S&D, Ad-Aware, and Avast files found WITHOUT even being connected to the internet! Renaming/moving msmapi32.exe solved the issue. Note that I first had to kill the process msmapi32.exe before I could rename/move it.

    Thanks, and I hope this helps the team,

    MadScientist

  2. #2
    Senior Member Yodama's Avatar
    Join Date
    Oct 2005
    Location
    Buchenheim
    Posts
    1,110

    Default

    thanks for reporting, I have found 3 variants of this file and I am going to add it to our detection database.
    born in the shadow to die in the shadow, that is the fate of the shinobi

    Spybot S&D Downloads

    Please help us improve Spybot and download our distributed testing client.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •