mIRC Home    About    Download    Register    News    Help

Print Thread
Joined: Jul 2004
Posts: 2
S
Sanz72 Offline OP
Bowl of petunias
OP Offline
Bowl of petunias
S
Joined: Jul 2004
Posts: 2
I've recently discovered msthost.exe running in my processes on Win xp home upgrade. upgraded from win 98 se.
After alot of googling, and mostly, alot of help from a certain tech forum I won't mention the name of cuz it seems to cause problems with forum admins hehe..
msthost.exe attempts to access the internet from my computer an average of 50 times an hour. I know this because I have installed a firewall that catalogues the IP adress it was attemting to connect to. Googling the ip adress brought up IRC related pages. Which is why i'm here. I was hoping one of you could possibly identify this running process for me. Tell me what its doing and why. maybe tell me if i need it or not. If the admins wanna take a closer look at whats going on, I have a hijackthis logfile and the ip msthost.exe is trying to connect to. Just let me know if you would like to see the information I have available.

Joined: Jun 2003
Posts: 5,024
M
Hoopy frood
Offline
Hoopy frood
M
Joined: Jun 2003
Posts: 5,024
It's actually more useful to post links if you've been obtaining help elsewhere to establish past activity. The IP you posted at computertechs.com points to an EFnet server. EFnet is a very big IRC network - it points to one of their servers, efnet.xs4all.nl. Why it would do this I have no idea - it could well be that you're infected.

Many anti-virus/trojan resources can be found in this thread. I would highly recommend using two or so virus scanners and two or so trojan scanners as they scan in slightly different ways. From my own Google search of this process there was a mention of a trojan.

As a note on a comment I saw from you on that forum, IRC means Internet Relay Chat - It's a chat protocol. mIRC is a popular program which allows people to connect to IRC. No, it is not a file sharing program wink - Unfortunately, many trojans make use of mIRC to connect their 'drones' to IRC networks where they can then be controlled by someone to attack servers, users or websites. Those drones are connected by infected users - you may be one of those.

I have no experience with hijackthis logs, however, for the benefit of other people who may wish to help, this persons logs may be found in this thread.

Have you downloaded anything or gone to any unusual websites since you noticed this appearing? Anything in the past few weeks/days?

Regards,


Mentality/Chris
Joined: Jul 2004
Posts: 2
S
Sanz72 Offline OP
Bowl of petunias
OP Offline
Bowl of petunias
S
Joined: Jul 2004
Posts: 2
Waladave helped me out alot. msthost.exe has been turned off in task manager and then renamed. If it is a trojan, I don't think that could've been accomplished so easily. I'm not discounting that drone theory.. maybe thats all it was. either way. It's gone now, I think. I'm rebooting nowto see if my changes worked. If so, i'm deleting the renamed file. Thanks for your help.


Link Copied to Clipboard