Help with Malware – msgrap.exe

August 2nd, 2013

Hello,
Since two days, my system has been infected with malware, Ainton.AA worm, I used Malwarebytes free version, it didn’t remove it all, my NOD32 identified the worms, but wasn’t able to remove them as they were running in the process.
1. ntdlr.exe – which later I manually deleted in safe mode. NOTE: It was taking 50% of the CPU usage and after deleting it, the usage was freed.
2. msgrap.exe – this still runs in processes and gains 50% of the CPU usage, I upgraded my NOD32 4 Security Essential to NOD32 5 Security Essential, but it failed to detected any virus or worm.
and this msgrap.exe still is in my processes under my user and not under SYSTEM, I have to manually end process tree for my system to work efficiently.
Any suggestions on how to identify this worm/trojan and how to get rid of it??
Google fails to provide any information on msgrap.exe!
I’ll be looking forward to something pertinent.

Answer #1
Download and run UnHackMe
Answer #2
on it!
Answer #3
http://www.bleepingcomputer.com/tutorials/how-to-remove-a-trojan-virus-worm-or-malware/
Use this program to identify the malicious program.
http://technet.microsoft.com/en-us/sysinternals/bb963902
Answer #4
Use process explorer, Determine where it’s running from, And mark it for deletion after reboot using this tool:
http://www.bleepingcomputer.com/files/killbox.php
Answer #5
Open task manager and end process manually. Right click->goto process->end process tree.

 

| Sitemap |