New Pornstar Interviews - [more]
Little Puck Interview

"I’m a woman of varied tastes. I can get off to a lot of different things. I enjoy switching it up."
All Forums > Tech Talk > Tech Talk Forum Page 48 > Watch Out For "msiexec.exe"
AuthorPost
BigBobxxx
Senior Member


2681 Posts
5/04
Posted - Jul 31 2005 : 11:38PM
I'm posting this here because it probably attacked my computer as a result of a link and/or a website linked to from ADT.

Read this.

I first thought something was wrong because my software firewall asked me if it was OK for "msiexec .exe" to connect to the Internet because it had "changed since I last opened it." I was suspicious, so I said NO.

I then ran a backtrack from my firewall's security log and found that it was really trying to connect to "whois.uwhois.com" (which turns out to be one of those annoying "register a domain" sites we often get linked to).

I ran Spybot, and it detected two registry changes. One was a "FirewallOverride." The other was a "AntiVirusOverride." I deleted them and rebooted my computer.

Upon reboot, I got a warning that Windows did not detect any firewall or virus protection. I ran Spybot again and the two registry changes had re-installed themselves!
So, I wrote down the actual names of the registry changes, ran "Run" from Start Menu and ran "regedit." I then deleted the two offending registry values by hand.

Note: These two overrides were disabling the Windows firewall and anti-virus functions. Since I use my own firewall and anti-virus programs, I was never actually compromised :)

After reading the article I linked to above, I then ran "Search" from the Start Menu and searched for "msiexec .exe". I found several references to "msiexec .exe" (which is not surprising since the true msiexec .exe is a valid Windows process). However, one of the items I found looked real odd because it was a prefetch file. It's name was followed by some numbers (like "msiexec .exe -12345.pf") so I deleted it.

Rebooted again.
This time Spybot did not find the offending registry values. I did get the Windows warning that Windows did not detect any firewall or virus protection. So, I went back in and told Windows that I had my own firewall and anti-virus solutions that I was monitoring myself and it is happy again.

Again, I'm SURE that I encountered this while surfing through links and websites that all of us perverts travel through, so heads up!

FYI, I run Spybot, Ad-Aware, Crap Cleaner and my own firewall and anti-virus programs (which I keep all definitions up-to-date). In addition, I have a default hardware firewall as a result of my router.

Be careful. And, if you have the time, run a search to see if you picked-up any weird "msiexec .exe" references. Once it gets "approval" from your firewall, it will start dialing out without your knowledge and your computer will soon be infected.

And the world calls US the perverts.

Edited by - BigBobxxx on Jul 31 2005

Edited by - BigBobxxx on Aug 1 2005

PL
Senior Member

God hates us all, you know it's true, God hates this place. - Slayer
1726 Posts
10/03
Posted - Aug 1 2005 : 7:46AM
I deal with this crap every day

I know your pain.... I'm glad you got it worked out.

This is a very good reason for people to see why it's good to NOT rely on the shoddy MS firewall.

Thanks for the heads up!

BigBobxxx
Senior Member

2681 Posts
5/04
Posted - Aug 1 2005 : 11:00AM
Update...

Everything I posted about the "msiexec .exe" is correct.

The part about the two Registry changes turns out to be a coincidence. The latest update to Spybot has triggered these two warnings. Basically, if you have disabled the Windows Firewall or Anti-Virus yourself (presumably because you are running your own programs that Windows doesn't detect and you were tired of getting warned), Spybot is now alerting you to the fact that the default Windows security settings have been overriden.

Spybot now says:

Company: Microsoft
Product: Windows Security Center
Threat: Changed Security Center Settings

Company product URL:
http://forums.net-integration.net/index.php?showtopic=32260

Functionality
This entry only wants to bring to your attention that "someone" has disabled one or more notifications in the Windows security centre.
If you’ve changed the settings yourself you can safely tell Spybot to exclude those detections from further searches. In order to do this please right click on each in turn, then click "exclude this detection from future searches". That way, should any other part of security center settings change Spybot will still detect those. For more information please visit our forum linked above.

maquiavelli
Member

90 Posts
4/05
Posted - Aug 2 2005 : 3:07AM
BigBob, thank you for alerting us. I saw this problem once while running Spybot and found that one of the registry keys which is concering the security center was changed or so. I deleted it and now the thing always showed in my taskbar alerting me that "automatic updates is set to download and update only after checking with me and that my Norton anti virus is active but its status is unkown.




Jump To: