943,832 Members | Top Members by Rank

Ad:
Oct 30th, 2008
0

zvsarc.exe

Expand Post »
Hello.

This is my first post so appologies in advance.

Does anyone know what the process zvsarc.exe is I have tried to google it and get no useful results. I noticed one of my XP machines has been contantly downloading and uploading to the internet and have tracked it back to the "zvsarc.exe" process.

I have dissabled the process and resumed normal network traffic however would like to know what the process is and what it does. Any help will be appreaciated.

Thanks
Reputation Points: 10
Solved Threads: 4
Light Poster
magic_mikey is offline Offline
28 posts
since Mar 2008
Oct 30th, 2008
0

Re: zvsarc.exe

download and run process explorer
Reputation Points: 10
Solved Threads: 11
Junior Poster in Training
nsindian is offline Offline
56 posts
since Jul 2008
Oct 30th, 2008
0

Re: zvsarc.exe

Click to Expand / Collapse  Quote originally posted by nsindian ...
download and run process explorer
Thank you nsindian. I have downloded and run process explorer. I need to look into it a bit further to understand the results however it has sown me that I am connecting to ruthless.snoke.nl. sounds like a nasty that I don't need.
Reputation Points: 10
Solved Threads: 4
Light Poster
magic_mikey is offline Offline
28 posts
since Mar 2008
Oct 30th, 2008
0

Re: zvsarc.exe

you may also want to use autoruns, which can be downloaded from sysinternals site
Reputation Points: 10
Solved Threads: 11
Junior Poster in Training
nsindian is offline Offline
56 posts
since Jul 2008
Oct 30th, 2008
0

Re: zvsarc.exe

Download Malwarebytes' Anti-Malware (http://www.majorgeeks.com/Malwarebyt...are_d5756.html) to your desktop.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure to checkmark the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
post the log back here
Team Colleague
Reputation Points: 1056
Solved Threads: 792
I hate 20 Questions
caperjack is offline Offline
12,723 posts
since Aug 2003
Oct 30th, 2008
0

Re: zvsarc.exe

OK so here is the log from Malwarebytes (this is before the removal actions were taken as I did not save the file again after removal and restart). I has found a couple of things that my SuperAntiSpyware Pro hasn't found however it has also disabled msconfig and two of the below "malware" removals have had to be restored to fix msconfig.

The process zvsarc.exe is still there. I have manually removed it with regedit from the Run and Run services folder.

This is what I know about the process so far. It connects me to an IRC server in the Netherlands (ruthless.snoke.nl/217.67.230.216). It has an active connection which constantly downloads and uploads. It resides in c\windows\system32 and runs as a service calling it self "Microsoft Update Machine" from an unknown vendor.

I have disabled the service and deleted from the system32 folder, I have blocked the IRC port and the domain. Now to see if it has gone completly or if it will come back. I will keep the quarantine items incase I find any other tools have been identified as a backdoor.bot.

I am still curious as to what the process is? and how it has attached itself to the pc.

Malwarebytes' Anti-Malware 1.30
Database version: 1340
Windows 5.1.2600 Service Pack 3

30/10/2008 22:35:15
mbam-log-2008-10-30 (22-35-09).txt

Scan type: Full Scan (C:\|F:\|)
Objects scanned: 104675
Time elapsed: 21 minute(s), 33 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 1
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 7

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3cab59b4-55a3-4737-9fd5-b93c6430bf75} (Trojan.Vundo) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\affri (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IProxyProvider (Trojan.Vundo) -> No action taken.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\msconfig (Backdoor.Bot) -> No action taken.

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowHelp (Hijack.StartMenu) -> Bad: (0) Good: (1) -> No action taken.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\All Users\Documents\Drivers\Computer Hardware info\Windows Server 2003 R2 Enterprise Edition With SP2 (Trojan.Vundo) -> No action taken.
C:\Documents and Settings\All Users\Documents\Drivers\Computer Hardware info\Windows Server 2003 R2 Enterprise Edition With SP2 (Malware.Tool) -> No action taken.
C:\WINDOWS\pchealth\helpctr\binaries\msconfig.exe (Backdoor.Bot) -> No action taken.
C:\WINDOWS\BMbfd20034.xml (Trojan.Vundo) -> No action taken.
C:\WINDOWS\BMbfd20034.txt (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> No action taken.
C:\Program Files\Setup.exe (Rogue.Installer) -> No action taken.
Last edited by magic_mikey; Oct 30th, 2008 at 8:28 pm. Reason: log before removal
Reputation Points: 10
Solved Threads: 4
Light Poster
magic_mikey is offline Offline
28 posts
since Mar 2008
Oct 30th, 2008
0

Re: zvsarc.exe

are u sure msconfig wasn't already disabled before you ran malwarebytes
Team Colleague
Reputation Points: 1056
Solved Threads: 792
I hate 20 Questions
caperjack is offline Offline
12,723 posts
since Aug 2003
Oct 30th, 2008
0

Re: zvsarc.exe

Hi caperjack. thanks for your support, I am sure msconfig was enabled I have used it a couple of times today to enable and disable the "microsoft update machine" service.
Reputation Points: 10
Solved Threads: 4
Light Poster
magic_mikey is offline Offline
28 posts
since Mar 2008
Oct 31st, 2008
0

Re: zvsarc.exe

zvsarc.exe, when i google this file ,this thread is the only results found .i would suggest you re-post in our virus and other nastiest forum here, and maybe get and run hijackthis and post a hijackthis log there
Team Colleague
Reputation Points: 1056
Solved Threads: 792
I hate 20 Questions
caperjack is offline Offline
12,723 posts
since Aug 2003
Oct 31st, 2008
0

Re: zvsarc.exe

Thanks caperjack. I will try hijackthis and see if it shows anything. I am fairly sure that I have removed the process now though. If it shows anything I will post in the virus section. Thankyou to all who helped.
Reputation Points: 10
Solved Threads: 4
Light Poster
magic_mikey is offline Offline
28 posts
since Mar 2008

This thread is solved

Either the thread starter or a moderator has marked this thread as solved. You can most likely trust the responses and answers given. There is most likely no reason for any further responses to be posted here. If you have a related question, please start a new thread in this forum instead.

This thread is more than three months old

No one has posted to this discussion for at least three months. Please let old threads die and do not reply to them unless you feel you have something new and valuable to contribute that absolutely must be added to make the discussion complete. Otherwise, please start a new thread in this forum instead.
Message:
Previous Thread in Windows NT / 2000 / XP Forum Timeline: start up
Next Thread in Windows NT / 2000 / XP Forum Timeline: Help with Blue Screen





About Us | Contact Us | Advertise | Acceptable Use Policy
Forum Index | Build Custom RSS Feed


Follow us on Twitter


© 2011 DaniWeb® LLC