Re: Mysterious programs found -Any ideas of what they are?

From: John McGaw (nowhere_at_inparticu.lar)
Date: 12/09/03


Date: Mon, 8 Dec 2003 20:38:57 -0500

Each of these executables will come up if you search for them at Google. And
all three are malware/worms/virii. Symantec has removal instructions for one
of them from what I can tell. It really looks like you need to start taking
some security precautions with your machine. Allowing even one infection is
a bad sign.

All the usual recommendations: a working firewall (Zone Alarme Free is
workable), a constantly updated anti-virus program (Grisoft's AVG free is
OK), don't ever run or open anything anybody sends you unless you asked for
it and then remain wary, download AdAware and Sybot Search & Destroy (both
free) and install/run both of them after updating them from their sites.

Programs that are removed and "always returns" aren't magical. Either
something else is on your system which is re-activating it or somehow or
other you are allowing the install from the outside.

Good luck. I fear you are going to need all of it that you can get at this
stage.

-- 
John McGaw
[Knoxville, TN, USA]
Return address will not work. Please
reply in group or through my website:
http://johnmcgaw.com
"Athelstan" <anonymous@discussions.microsoft.com> wrote in message
news:0aaa01c3bde6$254d8170$a001280a@phx.gbl...
> Before doing a de-frag of my hard disk this a.m. I went
> into the Windows (98) folder:
>
> program files/ system tools/system info
>
> pulled up 'software environment', then clicked on 'running
> tasks'. Along with other programs I recognized were
> three 'mysterious' ones, by which I mean not identified by
> normal version, or manufacturer, or having any description.
>
> They are, as follows:
>
> 1) Istsvc.exe (no version, no manuf., no description-
> blanks across the field)
>
> 2) Slmss.exe (version: 1,0,0,31) and vertical pipe symbols
> given in place of manufacturer and description)
>
> 3) Mwsvm.exe (version: 3, 0,2,228 and ditto as Slmss.exe
> for other info).
>
> (1) has been removed before via 'Hijack This' spykiller
> program, but it always returns. The other two don't show
> up at all.
>
> Does anyone have any ideas what I'm dealing with and
> whether these may be security related files? (Say like
> hijackers, or worse?) If so, how to deal with them?
>


Relevant Pages

  • Re: Mysterious programs found -Any ideas of what they are?
    ... George Hester ... > program files/ system tools/system info ... > normal version, or manufacturer, or having any description. ... > has been removed before via 'Hijack This' spykiller ...
    (microsoft.public.security)
  • Mysterious programs found -Any ideas of what they are?
    ... program files/ system tools/system info ... pulled up 'software environment', then clicked on 'running ... normal version, or manufacturer, or having any description. ... has been removed before via 'Hijack This' spykiller ...
    (microsoft.public.security)
  • Re: Mysterious programs found -Any ideas of what they are?
    ... Download "Hijack This!" ... or download direct: ... > program files/ system tools/system info ... > normal version, or manufacturer, or having any description. ...
    (microsoft.public.security)
  • Re: Pop ups
    ... For the general hijack case, the best way to start is to get Ad-Aware 6.0, ... UPDATE (even on your first install/run) and run this regularly to get rid of ... program of this type that I can recommend is StartMan, free, here: ... there's a new class of hijacker using Window's Messenger Service (not ...
    (microsoft.public.windows.inetexplorer.ie6.browser)

Quantcast