February 27th, 2007, 11:10 AM
|
#1 (permalink)
| | Pump you sucker! Pump!
Join Date: Oct 2001 Location: Sacto, Colliefornia
Posts: 7,340
| Malware mvsr32.exe - What is it?
It keeps asking Zone Alarm for permission to contact the internet, so I "killed" it. I've done a variety of Trojan and Virus scans and nothing comes up. More Info: the IP it is trying to reach is 66.60.130.2DNS Anyone know where this is? Note: there is a : between the 2 and the D - If I put it in I get a Smiley Face...
I've done a system search and nothing comes up.
I did a Google search and the results are not in English and the translator isn't doing a very good job.
I can't find an English description to tell me how to remove it.
Any ideas?
__________________
America has spoken; Now it is time for our enemies to speak.
Last edited by Chuckiechan : February 27th, 2007 at 12:03 PM.
|
| |
February 28th, 2007, 04:31 AM
|
#2 (permalink)
| | Ultimate Member
Join Date: Jun 2003 Location: Not on this planet..
Posts: 1,102
| |
| |
February 28th, 2007, 04:36 AM
|
#3 (permalink)
| | Senior Member
Join Date: Feb 2003 Location: Worcester, MA
Posts: 670
|
surely seem like a spyware program that got installed cant be so positive though I have seen that somewhere....I think the reason its trying to connect You know how when you get tons of ad popups those are the programs that cause it mainly the spyware progs So I believe its that I will look into it and try to remember what it was.
__________________
\\Opty 165 stock// \\ECS KN1 Extreme Lite//\\2gig Gskill DDR500//\\7800GTX 256mb Stock//\\Viper XG//
|
| |
February 28th, 2007, 07:30 AM
|
#4 (permalink)
| | Ultimate Member
Join Date: May 2002 Location: Stow, Ohio, Sol III
Posts: 1,190
|
The IP comes back through a WhoIs look-up as; Quote:
IP Information 66.60.130.2
OrgName: Surewest Internet
OrgID: SURW
Address: P.O. Box 969
City: Roseville
StateProv: CA
PostalCode: 95678
Country: US
NetRange: 66.60.128.0 - 66.60.191.255
CIDR: 66.60.128.0/18
NetName: SUREWEST-INTERNET
NetHandle: NET-66-60-128-0-1
Parent: NET-66-0-0-0-0
NetType: Direct Allocation
NameServer: NS1.SUREWEST.NET
NameServer: NS2.SUREWEST.NET
Comment: ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE
RegDate: 2001-01-03
Updated: 2002-10-24
RTechHandle: ZR32-ARIN
RTechName: DNS Admin
RTechPhone: +1-916-772-5000
RTechEmail: dnsadmin @ surewest.net
OrgAbuseHandle: ABUSE57-ARIN
OrgAbuseName: Abuse Department
OrgAbusePhone: +1-916-772-5000
OrgAbuseEmail: abuse @ surewest.net
OrgNOCHandle: ZR32-ARIN
OrgNOCName: DNS Admin
OrgNOCPhone: +1-916-772-5000
OrgNOCEmail: dnsadmin @ surewest.net
OrgTechHandle: ZR32-ARIN
OrgTechName: DNS Admin
OrgTechPhone: +1-916-772-5000
OrgTechEmail: dnsadmin @ surewest.net
| E-mails addy edited, remove spaces.
Wouldn't by chance be your ISP would it?
__________________
Well, if crime fighters fight crime and fire fighters fight fire, what do freedom fighters fight? They never mention that part to us, do they?
|
| |
February 28th, 2007, 12:29 PM
|
#5 (permalink)
| | Pump you sucker! Pump!
Join Date: Oct 2001 Location: Sacto, Colliefornia
Posts: 7,340
|
That's me...
What does "Abuse" mean?
The message I get a boot up when I take ZA off "kill" is:
mvsr32.exe is trying to modify a driver or service: WSCSVC
Oddly, it doesn't appear to reside on my system under the file name of mvsr32.exe. I wonder if it belongs to my ISP?
I'll be back in town Friday... |
| |
March 3rd, 2007, 02:54 PM
|
#6 (permalink)
| | Pump you sucker! Pump!
Join Date: Oct 2001 Location: Sacto, Colliefornia
Posts: 7,340
|
Well, after much research I went into the registry and killed it. It's dead and presumably gone.... asleep until the next Torrent download....Zzzzz  |
| | |
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | | |
Posting Rules
| You may post new threads You may post replies You may not post attachments You may not edit your posts HTML code is Off | | |
Similar Threads | | Thread | Thread Starter | Forum | Replies | Last Post | | 2Wire malware? | Bradte20 | Networking and Internet | 6 | February 21st, 2006 06:10 PM | | Virus/malware HELP | wera | General Tech Discussion | 12 | February 2nd, 2006 03:13 PM | | malware | cusmano_04 | General Tech Discussion | 1 | November 15th, 2004 01:00 PM | | Malware Attack! | minduka | Networking and Internet | 8 | October 7th, 2004 03:04 AM | | What to do about New Malware | Athlonanime | Security and Privacy Issues | 1 | April 10th, 2004 04:33 AM | | Most Active Discussions | | | | | Recent Discussions  | | | | | |