home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Security and Privacy Issues
Join TechIMO for Free!
Register Blogs FAQ Members List Calendar Search Today's Posts Mark Forums Read
Reply Get bargains at  »  Dealighted.com
 
Thread Tools
Currently Active Users: 1819
Discussions: 188,470, Posts: 2,244,169, Members: 232,723
Old February 27th, 2007, 11:10 AM   Digg it!   #1 (permalink)
Pump you sucker! Pump!
 
Chuckiechan's Avatar
 
Join Date: Oct 2001
Location: Sacto, Colliefornia
Posts: 7,340
Malware mvsr32.exe - What is it?

It keeps asking Zone Alarm for permission to contact the internet, so I "killed" it. I've done a variety of Trojan and Virus scans and nothing comes up.

More Info: the IP it is trying to reach is 66.60.130.2DNS Anyone know where this is? Note: there is a : between the 2 and the D - If I put it in I get a Smiley Face...


I've done a system search and nothing comes up.

I did a Google search and the results are not in English and the translator isn't doing a very good job.

I can't find an English description to tell me how to remove it.

Any ideas?
__________________
America has spoken; Now it is time for our enemies to speak.


Last edited by Chuckiechan : February 27th, 2007 at 12:03 PM.
Chuckiechan is offline   Reply With Quote
Old February 28th, 2007, 04:31 AM     #2 (permalink)
Ultimate Member
 
BluesMan1's Avatar
 
Join Date: Jun 2003
Location: Not on this planet..
Posts: 1,102
CW Shredder worth a try: http://www.intermute.com/spysubtract..._download.html

Ad Aware SE Personnal: http://www.lavasoftusa.com/

Spybot: http://www.safer-networking.org/en/download/index.html

Hijack This, create a log: http://www.spywareinfo.com/~merijn/programs.php

Copy the log here and analyze it: http://hijackthis.de/index.php

You can also use some online tools: http://housecall.trendmicro.com/

I'm sure that you'll get more tools from the people here also.......

Good Luck

BluesMan1 is offline   Reply With Quote
Old February 28th, 2007, 04:36 AM     #3 (permalink)
Senior Member
 
Micro Bean's Avatar
 
Join Date: Feb 2003
Location: Worcester, MA
Posts: 670
surely seem like a spyware program that got installed cant be so positive though I have seen that somewhere....I think the reason its trying to connect You know how when you get tons of ad popups those are the programs that cause it mainly the spyware progs So I believe its that I will look into it and try to remember what it was.
__________________
\\Opty 165 stock// \\ECS KN1 Extreme Lite//\\2gig Gskill DDR500//\\7800GTX 256mb Stock//\\Viper XG//

Micro Bean is offline   Reply With Quote
Old February 28th, 2007, 07:30 AM     #4 (permalink)
Ultimate Member
 
nomaxim's Avatar
 
Join Date: May 2002
Location: Stow, Ohio, Sol III
Posts: 1,190
The IP comes back through a WhoIs look-up as;
Quote:
IP Information 66.60.130.2
OrgName: Surewest Internet
OrgID: SURW
Address: P.O. Box 969
City: Roseville
StateProv: CA
PostalCode: 95678
Country: US
NetRange: 66.60.128.0 - 66.60.191.255
CIDR: 66.60.128.0/18
NetName: SUREWEST-INTERNET
NetHandle: NET-66-60-128-0-1
Parent: NET-66-0-0-0-0
NetType: Direct Allocation
NameServer: NS1.SUREWEST.NET
NameServer: NS2.SUREWEST.NET
Comment: ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE
RegDate: 2001-01-03
Updated: 2002-10-24

RTechHandle: ZR32-ARIN
RTechName: DNS Admin
RTechPhone: +1-916-772-5000
RTechEmail: dnsadmin @ surewest.net

OrgAbuseHandle: ABUSE57-ARIN
OrgAbuseName: Abuse Department
OrgAbusePhone: +1-916-772-5000
OrgAbuseEmail: abuse @ surewest.net

OrgNOCHandle: ZR32-ARIN
OrgNOCName: DNS Admin
OrgNOCPhone: +1-916-772-5000
OrgNOCEmail: dnsadmin @ surewest.net

OrgTechHandle: ZR32-ARIN
OrgTechName: DNS Admin
OrgTechPhone: +1-916-772-5000
OrgTechEmail: dnsadmin @ surewest.net
E-mails addy edited, remove spaces.

Wouldn't by chance be your ISP would it?
__________________
Well, if crime fighters fight crime and fire fighters fight fire, what do freedom fighters fight? They never mention that part to us, do they?
nomaxim is offline   Reply With Quote
Old February 28th, 2007, 12:29 PM     #5 (permalink)
Pump you sucker! Pump!
 
Chuckiechan's Avatar
 
Join Date: Oct 2001
Location: Sacto, Colliefornia
Posts: 7,340
That's me...

What does "Abuse" mean?

The message I get a boot up when I take ZA off "kill" is:

mvsr32.exe is trying to modify a driver or service: WSCSVC

Oddly, it doesn't appear to reside on my system under the file name of mvsr32.exe. I wonder if it belongs to my ISP?

I'll be back in town Friday...
Chuckiechan is offline   Reply With Quote
Old March 3rd, 2007, 02:54 PM     #6 (permalink)
Pump you sucker! Pump!
 
Chuckiechan's Avatar
 
Join Date: Oct 2001
Location: Sacto, Colliefornia
Posts: 7,340
Well, after much research I went into the registry and killed it. It's dead and presumably gone.... asleep until the next Torrent download....Zzzzz

Chuckiechan is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may post new threads
You may post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
2Wire malware? Bradte20 Networking and Internet 6 February 21st, 2006 06:10 PM
Virus/malware HELP wera General Tech Discussion 12 February 2nd, 2006 03:13 PM
malware cusmano_04 General Tech Discussion 1 November 15th, 2004 01:00 PM
Malware Attack! minduka Networking and Internet 8 October 7th, 2004 03:04 AM
What to do about New Malware Athlonanime Security and Privacy Issues 1 April 10th, 2004 04:33 AM

Most Active Discussions
Is It Just Me? (2996)
Intel Pentium 4 531 (7)
"mastermind" of London at.. (65)
Please don't divorce us (40)
AMD Phenom II X4 940 Black Edition (11)
Replacing integrated video card (5)
nVidia GTX 295 now available (21)
Folderchat Weekday thread (458)
building a gaming computer, input p.. (14)
Recent Discussions
nVidia GTX 295 now available (21)
Folderchat Weekday thread (458)
Could I run this set-up (15)
Bought the Visiontek Radeon 387.. (1)
CPU Overheating ?? (18)
Computer will not boot(powers o.. (2)
*TechIMO's Top 30 PCs* (44)
New psu question (1)
Finishing off my first built co.. (4)
Blackberry Storm, Gears of War .. (2)
Core 2 Quad Q9550 system (3)
COWBOOM Ripoff! Used Laptop w/$.. (4)


All times are GMT -4. The time now is 05:41 AM.
TechIMO Copyright 2008 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28