Just had attempted shellcode attack through msnmgr.exe
I am using Comodo Firewall with Defense+ and antivirus, and just had a message come up on screen, from Comodo Defense+, unfortunately i wasnt able to make a complete note of the message before it disappeared.however the gist of it is belowCOMODO DEFENSE+ ALERTTo help you protect your PC, Comodo Defense+ temporarily blocked this application. It has tried to Execute Shellcode as a result of a possible buffer overflow attack.Application MSNMSGR.exeThis is typical of a Buffer Overflow Attack.Comodo Defense+ has already isolated msnmsgr.exe from the rest of the system+will keep it isolated unless you skip this alert. However it is still strongly recommended to close this application and contact the vendor for a fix.Checking back through logs it looks as if this is the second time this has been attempted the last being on the 28/02/09. Current version of msn live is Version 2009 (Build 14.0.8064.206) this was an update done recently after MSN messenger informed me of an update required. Is there a way i can verify this is actually the latest official MS build and not an unofficial trojan for want of a better description.Edit i have been able to get the full message, as when i opened up Messenger again earlier on i had the same message appear again, which now makes it 3 possible attempts since the latest update to messenger.
March 4th, 2009 12:17am

Hi,Are you running Windows 7? Where is msnmsgr.exe located (what path?). More than likely Comodo is misinterpreting MSN's calls. Victor Constantinescu - MVP Security, MCTS
Free Windows Admin Tool Kit Click here and download it now
March 5th, 2009 12:52am

Yes Im running Windows 7 build 7000 64 bit.path is "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe"
March 5th, 2009 2:41am

I have 14.0.8064.206 as well. I'm with YounGun, I've seen Comodo have false positives.
Free Windows Admin Tool Kit Click here and download it now
March 8th, 2009 10:55am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics