Please Help! I can't sole my problems... (wmiprvse, msmsgs, MediaPlex, Avenue Inc.)
Hi to everyone.
I think have a serious problem here.
My machine is based on WinXP Pro @ SP2 w/ Firewall ON and I use antivirus Symantec Norton 2005 w/ Internet Worm Protection OFF and use toscan for spywares with SpyBot S&D 1.31XT.
I get strange lookups of some apps like IExplorer or eDonkey2000 after using them a while.
I don't know if that's correct or not, but I have wmiprvse.exe (located in C:\WINDOWS\system32\wbem\.. ) and msmsgs.exe (located in C:\Program Files\Messenger\.. ) that might have something wrong.
I say this because msmsgs.exe always starts up with Windows even if its NOT in my msconfig at startup and have MSN Messenger to NOT load up when Windows starts, and wmiprvse.exe is always located under the same svchost.exe, that if terminated it let come up the automatic countdown for WIndows shutdown (like old sasser problem).
Now... I think that the svchost.exe in case is some kind of MS patch for excluding the old sasser problem, but I just don't understand why the two files wmiprvse.exe and msmsgs.exe are related to that particular svchost.exe.
Now here are two screenshots about Process Explorer taken at startup (first pic) and after a while when I have several IExplorer pages open, Outlook opened and composing an email with Outlook composer (based on WINWORD).
http://img104.exs.cx/img104/7797/pe14ws.th.jpg
(save to disk for better resolution)
http://img104.exs.cx/img104/4805/pe21sc.th.jpg
(save to disk for better resolution)
I have made some SpyBot S&D scans since I first had these lookups and I foud several spywares that now are completely gone.
The only two that I just can't remove definitely are the MediaPlex and the Avenue A, Inc. spywares that use to appear again in the Spybot S&D scan list after a while.
Here is a shot of the scan:
http://img196.exs.cx/img196/9148/sb12jr.th.jpg
(save to disk for better resolution)
I thought maybe this could be related to some open prots I have in my Windows or in my router, so I downloaded Windows Worms Doors Cleaner and took a look at it, and I found the following ports opened. Is this part of the cause of my problems?
http://img200.exs.cx/img200/738/wwdc10at.th.jpg
(save to disk for better resolution)
(end of first part of message)