The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    Suspicious msnmsgr.exe

    Discussion in 'Security and Anti-Virus Software' started by holymoly, Jan 14, 2011.

  1. holymoly

    holymoly Notebook Geek

    Reputations:
    20
    Messages:
    88
    Likes Received:
    0
    Trophy Points:
    15
    I was doing some cleanup today, and i noticed something fishy is going on, for one, in CCleaner i have a new startup program msnmsgr.exe, i dont use MSN and never did, and it is in a strange location C:\Users\\AppData\Roaming\....\.....\1.3.8.1474\msnmsgr.exe, the folder also contains another file called user32.dll, the "...." are random letters, MD5 or something, both file are hidden. nothing was picked up by MSE and the exe was not running in the task manager, so im just wondering what you guys think about this

    I also got a email from a forum that i havn't used in ages to tell me that im banned there for posting something, seems strange, but my password was like 123456 and the account is of no importance, but it could be related to what i found today

    should i be running more scans with other tools or is it time for me to start change all the passwords and stuff? lol
     
  2. RWUK

    RWUK Notebook Evangelist

    Reputations:
    254
    Messages:
    591
    Likes Received:
    0
    Trophy Points:
    30
    Any Windows executable outside its original location is reason to be suspicious, if not an outright problem. An MD5 is a checksum file used to see if a download is incomplete or corrupt.

    What you describe sounds like virus/malware activity.

    Can you disable it from startup in CCLeaner?
    I'd suggest downloading MBAM free and running a scan in safe mode.
    Malwarebytes

    That sucks MSE didn't pick up on it.