Possible Virus - msmscfg.exe hosts

  • Thread starter Thread starter Mitch Evans
  • Start date Start date
M

Mitch Evans

We got hit with some type of virus on 4/13/04. It is on
all our XP machines. We have the latest patches and
virus updates. A file named msmscfg.exe is dropped in
the c:\windows\system32 directory as well as in the
registry. All the major virus scanners will not detect
this either. Once dropped the hosts file is modified,
and redirects all requests to the major virus software
vendors back to the local machine. It also will not
allow regedit to be run. It will also disable the real
time virus scanners for Norton, Mcaffee, Computer
Associates etc. If you delete it from the registry and
hard drive, it will come right back, usually after you
see three dos screens flas accros the screen. We have
reported this and have no luck in a solution at this
time. It has infected over 100 of our Windows XP and
2000 machines, and all are patched with the latest
patches.
 
I too was infected by a similar virus. But it wasn't in the folder of C:\Windows\System32, and called something else. It was called msiesh.dll and act like it was a program. I unstall it, even though I never install it into my computer. I also have Win XP, but Home Edition
 
Some worms copy themelves as a random filename and they also disable or
hinder a/v programs so they go undetected. Start in Safe Mode and then
run your a/v scans.

Steve
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Back
Top