what is this file?

  • jlknauff
  • Expert
  • Expert
  • User avatar
  • Joined: May 18, 2004
  • Posts: 502
  • Loc: Florida
  • Status: Offline

Post June 11th, 2004, 1:42 pm

Has anyone ever heard of a file called mstime.exe? Whenever I search with Google my firewall tells me it is trying to access the internet. Considering that MS is waaaaaay behind Google I'm wondering if they are trying to somehow get more infomation on what's going on with Google users. Any ideas?
  • Anonymous
  • Bot
  • No Avatar
  • Joined: 25 Feb 2008
  • Posts: ?
  • Loc: Ozzuland
  • Status: Online

Post June 11th, 2004, 1:42 pm

  • SecureITGroup
  • Proficient
  • Proficient
  • User avatar
  • Joined: May 16, 2004
  • Posts: 293
  • Status: Offline

Post June 11th, 2004, 1:49 pm

Have you tried to run a virus scan on that file?
  • SecureITGroup
  • Proficient
  • Proficient
  • User avatar
  • Joined: May 16, 2004
  • Posts: 293
  • Status: Offline

Post June 11th, 2004, 1:50 pm

Oh and run a spyware program. I recomend SpyBot Search & Distroy;)
  • Freakyp
  • Graduate
  • Graduate
  • User avatar
  • Joined: Apr 12, 2004
  • Posts: 210
  • Loc: M'boro. TN, USA
  • Status: Offline

Post June 11th, 2004, 4:39 pm

yah... I dont think there is a file in windows called 'mstime.exe' so yah as 'SecureITGroup' said its probly not a good thing.... good luck :wink:
  • jlknauff
  • Expert
  • Expert
  • User avatar
  • Joined: May 18, 2004
  • Posts: 502
  • Loc: Florida
  • Status: Offline

Post June 14th, 2004, 1:08 pm

I ran Spybot and came up with 11 entries. I had them fixed but everytime I rebot they are back. Any ideas?
  • Freakyp
  • Graduate
  • Graduate
  • User avatar
  • Joined: Apr 12, 2004
  • Posts: 210
  • Loc: M'boro. TN, USA
  • Status: Offline

Post June 14th, 2004, 1:36 pm

what are they?.. if you can get the names, try to find a patch for them on the microsft site, or your anti-virus zite...
  • ATNO/TW
  • Super Moderator
  • Super Moderator
  • User avatar
  • Joined: May 28, 2003
  • Posts: 23404
  • Loc: Woodbridge VA
  • Status: Offline

Post June 14th, 2004, 1:43 pm

Are you sure it was mstime.exe and not mstime.dll?
"There's no place like 127.0.0.1 except for ::1."
Alexandria Networks. Leader in IT consulting for associations/non-profits, and small to medium sized businesses around the northern Virginia and Washington D.C. metro area.
  • jlknauff
  • Expert
  • Expert
  • User avatar
  • Joined: May 18, 2004
  • Posts: 502
  • Loc: Florida
  • Status: Offline

Post June 14th, 2004, 3:47 pm

yep. This is the message I get

C:\WINNT\system32\mstime.exe is trying to connect to search.requestlookup.net (206.58.237.248) using remote port 80 (HTTP - World Wide Web). Do you want to allow this program to access the network?

:roll:

Not good...
  • conorific
  • Proficient
  • Proficient
  • User avatar
  • Joined: Jan 12, 2004
  • Posts: 350
  • Loc: NY
  • Status: Offline

Post June 17th, 2004, 2:11 pm

That sounds like ZoneAlarm; is that what firewall you're using? I googled mstime.exe and found nothing but this post. How weird.
  • ShEDeViL
  • Graduate
  • Graduate
  • User avatar
  • Joined: Mar 29, 2004
  • Posts: 216
  • Status: Offline

Post June 17th, 2004, 2:13 pm

My guess is whatever it is, it's not a good thing. If I was you, I would put a .remove at the end of the file name so it will look something like "mstime.exe.remove" and see what happens. This way you're not deleting it if you find out that you really do need it for something, but if you don't, it should stop it from doing whatever it's doing.
  • conorific
  • Proficient
  • Proficient
  • User avatar
  • Joined: Jan 12, 2004
  • Posts: 350
  • Loc: NY
  • Status: Offline

Post June 17th, 2004, 2:15 pm

I didn't think of that. It might work, Windows is tricked into all sorts of things. SheDevil, are you following me? :D
  • ShEDeViL
  • Graduate
  • Graduate
  • User avatar
  • Joined: Mar 29, 2004
  • Posts: 216
  • Status: Offline

Post June 17th, 2004, 2:17 pm

Shhhhh, you weren't supposed to know ;)
  • jlknauff
  • Expert
  • Expert
  • User avatar
  • Joined: May 18, 2004
  • Posts: 502
  • Loc: Florida
  • Status: Offline

Post June 17th, 2004, 2:22 pm

Here is what I have come up with so far-

It is somehow related to a searchengine called requestlookup.net. I'm thinking it is trying to send querries to their SE rather than the one I tried to use. I have renamed the file a few minutes ago and everthing seems to be working fine-without anything trying to acccess the net. So, it looks like your idea worked shedevil :wink: I'm going to let it sit the way it is for a few days and make sure everything run fine, then delete it.
From what I see this is a shady way for a SE to get traffic so we should all let everyone know what they are doing. Thanks for your help everyone!
  • ShEDeViL
  • Graduate
  • Graduate
  • User avatar
  • Joined: Mar 29, 2004
  • Posts: 216
  • Status: Offline

Post June 17th, 2004, 2:28 pm

Yay glad its working! :)
  • Vladdrac
  • Mastermind
  • Mastermind
  • User avatar
  • Joined: Feb 04, 2004
  • Posts: 2136
  • Loc: Louisville, Ky
  • Status: Offline

Post June 17th, 2004, 10:17 pm

glad your problem is resolved, is the spyware still not getting erased?
  • Anonymous
  • Bot
  • No Avatar
  • Joined: 25 Feb 2008
  • Posts: ?
  • Loc: Ozzuland
  • Status: Online

Post June 17th, 2004, 10:17 pm

Post Information

  • Total Posts in this topic: 29 posts
  • Users browsing this forum: No registered users and 104 guests
  • You cannot post new topics in this forum
  • You cannot reply to topics in this forum
  • You cannot edit your posts in this forum
  • You cannot delete your posts in this forum
  • You cannot post attachments in this forum
 
cron
 

© 2011 Unmelted, LLC. Ozzu® is a registered trademark of Unmelted, LLC.