msascui.exe iexplore virus

July 1st, 2017

I put one one mine friends infected pd,after that when ever I connect any device it copies it self on it and is running on mine pc.Even if remove it start-up,it start ups again.
Please tell me the solution.

Answer #1
have you updated your anti virus program and scanned your computer for this as of yet??
Answer #2
Malwarebytes, Combofix, Hitman Pro???
Answer #3
it’s not a virus, it’s part of windows defender. http://www.bleepingcomputer.com/startups/MSASCui.exe-14484.html
Answer #4
it's not a virus, it's part of windows defender. http://www.bleepingcomputer.com/startups/MSASCui.exe-14484.html
Windows defender also has same file name,but defender doesn’t keep always running in back ground and in its description it shows Internet Explorer and it also has IE’s icon.
Answer #5
it's not a virus, it's part of windows defender. http://www.bleepingcomputer.com/startups/MSASCui.exe-14484.html
Windows defender also has same file name,but defender doesn't keep always running in back ground and in its description it shows Internet Explorer and it also has IE's icon.
if you have a 64 bit system, it should be in C:\Program Files\Windows Defender\en-US if you have an x86 system, it should be in the x86 folder and nowhere else. try restarting in safe mode, then delete any other occurrences of it. you can look in your registry too. start/run/ and enter regedit in the box. will get you to the registry editor. then you can look for the startup for MSASCui.exe which is NOT in the windows defender folder. and delete it there, too. only delete the name MSASCui.exe though.. this uses the same exe file, maybe this info will help..http://www.404techsupport.com/2010/03/xp-internet-security-2010-an-ongoing-current-attack/ it’s possible you have a new variant, which may not have a fix yet..
Answer #6
it's not a virus, it's part of windows defender. http://www.bleepingcomputer.com/startups/MSASCui.exe-14484.html
Windows defender also has same file name,but defender doesn't keep always running in back ground and in its description it shows Internet Explorer and it also has IE's icon.
if you have a 64 bit system, it should be in C:\Program Files\Windows Defender\en-US if you have an x86 system, it should be in the x86 folder and nowhere else. try restarting in safe mode, then delete any other occurrences of it. you can look in your registry too. start/run/ and enter regedit in the box. will get you to the registry editor. then you can look for the startup for MSASCui.exe which is NOT in the windows defender folder. and delete it there, too. only delete the name MSASCui.exe though.. this uses the same exe file, maybe this info will help..http://www.404techsupport.com/2010/03/xp-internet-security-2010-an-ongoing-current-attack/ it's possible you have a new variant, which may not have a fix yet..

Yeah I think its a new variant because there is also iexplore also continually running.Tried cleaning registry,killing with process explorer but it just won’t go.Its like damn cockroach.
Answer #7
I’ve replied to a similar topic just a few days ago:
http://www.google.com?p=72055951#72055951
Bottom line – You’ll never be safe unless you reinstall your OS!
Answer #8
So,at the last I have to format the account.
Answer #9
So,at the last I have to format the account. well, possibly, but not if a disinfection routine is made, and you find an antivirus etc. that will disinfect it. you can submit the bogus MSASCui.exe to virustotal. https://www.virustotal.com/en/ then install whichever antivirus detects it, then it will disinfect your computer. this is a new variant, since your antivirus didn’t remove it. btw, you do have UAC enabled, right? that should prevent any unknown process from running..

 

| Sitemap |