Jump to content

Identification of possible malware


Ingmar

Recommended Posts

Hi everyone,

every now and then (and always after a restart), MalwareBytes detects a possible threat. I have tried to find what it could be, but in vain.

No virusscanner nor any other malware detection program finds anything. The MSA.EXE file is not there, even before I click "Quarantine".

I have looked for other symptoms of MSAntivirus (which is what this is according to a bit of Googling), but there simply are no other symptoms.

Any help is appreciated in identifying this issue.

BTW: It is not annoying is it occurs only once every week or so (or after restart).

Below is the detection log (after restart) from MalwareBytes.

00:00:00 Ingmar DETECTION C:\Windows\msa.exe Trojan.Agent DENY

01:00:00 Ingmar DETECTION C:\Windows\msa.exe Trojan.Agent DENY

02:00:00 Ingmar DETECTION C:\Windows\msa.exe Trojan.Agent DENY

03:00:00 Ingmar DETECTION C:\Windows\msa.exe Trojan.Agent DENY

04:00:00 Ingmar DETECTION C:\Windows\msa.exe Trojan.Agent DENY

05:00:00 Ingmar DETECTION C:\Windows\msa.exe Trojan.Agent DENY

06:00:00 Ingmar DETECTION C:\Windows\msa.exe Trojan.Agent DENY

07:00:00 Ingmar DETECTION C:\Windows\msa.exe Trojan.Agent DENY

08:00:00 Ingmar DETECTION C:\Windows\msa.exe Trojan.Agent DENY

08:42:40 Ingmar MESSAGE Protection started successfully

08:42:44 Ingmar MESSAGE IP Protection started successfully

09:01:38 Ingmar DETECTION C:\Windows\msa.exe Trojan.Agent QUARANTINE

09:01:39 Ingmar ERROR Quarantine failed: UtilityReadFile failed with error code 2

09:02:15 Ingmar MESSAGE IP Protection stopped

09:02:23 Ingmar MESSAGE Database updated successfully

09:02:24 Ingmar MESSAGE IP Protection started successfully

Link to post
Share on other sites

Hi,

Download ComboFix from one of these locations:

Link 1

Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Here is a guide on how to disable them:
    Click me
    If you can't disable them then just continue on.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

RcAuto1.gif

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

whatnext.png

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.

Link to post
Share on other sites

  • 2 weeks later...

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.