Does anyone know what the process zvsarc.exe is I have tried to google it and get no useful results. I noticed one of my XP machines has been contantly downloading and uploading to the internet and have tracked it back to the "zvsarc.exe" process.
I have dissabled the process and resumed normal network traffic however would like to know what the process is and what it does. Any help will be appreaciated.
Thank you nsindian. I have downloded and run process explorer. I need to look into it a bit further to understand the results however it has sown me that I am connecting to ruthless.snoke.nl. sounds like a nasty that I don't need.
* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure to checkmark the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
post the log back here
OK so here is the log from Malwarebytes (this is before the removal actions were taken as I did not save the file again after removal and restart). I has found a couple of things that my SuperAntiSpyware Pro hasn't found however it has also disabled msconfig and two of the below "malware" removals have had to be restored to fix msconfig.
The process zvsarc.exe is still there. I have manually removed it with regedit from the Run and Run services folder.
This is what I know about the process so far. It connects me to an IRC server in the Netherlands (ruthless.snoke.nl/217.67.230.216). It has an active connection which constantly downloads and uploads. It resides in c\windows\system32 and runs as a service calling it self "Microsoft Update Machine" from an unknown vendor.
I have disabled the service and deleted from the system32 folder, I have blocked the IRC port and the domain. Now to see if it has gone completly or if it will come back. I will keep the quarantine items incase I find any other tools have been identified as a backdoor.bot.
I am still curious as to what the process is? and how it has attached itself to the pc.
Malwarebytes' Anti-Malware 1.30
Database version: 1340
Windows 5.1.2600 Service Pack 3
Hi caperjack. thanks for your support, I am sure msconfig was enabled I have used it a couple of times today to enable and disable the "microsoft update machine" service.
zvsarc.exe, when i google this file ,this thread is the only results found .i would suggest you re-post in our virus and other nastiest forum here, and maybe get and run hijackthis and post a hijackthis log there
Thanks caperjack. I will try hijackthis and see if it shows anything. I am fairly sure that I have removed the process now though. If it shows anything I will post in the virus section. Thankyou to all who helped.
Either the thread starter or a moderator has marked this thread as solved. You can most likely trust the responses and answers given. There is most likely no reason for any further responses to be posted here. If you have a related question, please start a new thread in this forum instead.
This thread is more than three months old
No one has posted to this discussion for at least three months. Please let old threads die and do not reply to them unless you feel you have something new and valuable to contribute that absolutely must be added to make the discussion complete. Otherwise, please start a new thread in this forum instead.
Previous Thread in Windows NT / 2000 / XP Forum Timeline:start up