A Windows Vista forum. Vista Banter

Welcome to Vista Banter.

You are currently viewing our boards as a guest which gives you limited access to view most discussions, articles and access our other FREE features. By joining our free community you will have access to ask questions and reply to others posts, upload your own photos and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact support.

Go Back   Home » Vista Banter forum » Microsoft Windows Vista » Networking with Windows Vista
Site Map Home Register Authors List Search Today's Posts Mark Forums Read Web Partners

Networking with Windows Vista Networking issues and questions with Windows Vista. (microsoft.public.windows.vista.networking_sharing)

msxml2r32.exe? what is this?



 
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old September 8th 07, 01:37 AM posted to microsoft.public.windows.vista.security,microsoft.public.windows.vista.general,microsoft.public.windows.vista.networking_sharing
...
external usenet poster
 
Posts: 18
Default msxml2r32.exe? what is this?

Every time I restart Vista Ult with latest updates, I notice my router's
lights blinking and I recently noticed this setting that keeps coming back
on my Persistent Port Forwarding options:
msxml2r32 Inbound Port 1757 on TCP

I delete this setting and restart the PC, and it's back.

I can't find this find anywhere on my PC. I've searched the net and only
found couple of Korean or Chinese sites that I don't understand, but they
mention Norton Antivirus, and a folder path to
C:\windows\system\msxml2r32.exe
I've looked on HKLM Run and HKCU Run settings in regedit, I've searched the
whole PC (indexed and non-indexed folders) and I am unable to find this
file.
Has anyone else come accross this?
Thanks
Gino

  #2 (permalink)  
Old September 9th 07, 12:32 AM posted to microsoft.public.windows.vista.networking_sharing,microsoft.public.windows.vista.security,microsoft.public.windows.vista.general
Jesper
external usenet poster
 
Posts: 839
Default msxml2r32.exe? what is this?

It is highly likely to be malware of some sort. Malware can configure your
router if it is configurable via UPNP, or if you have typed your password for
the router on the infected system.

I found one site that stated the file name has been found on a virus written
in either Japanese or Korean that randomly chose names. Symantec calls it
antinny. Here's the page:
http://www.symantec.com/security_res...045-99&tabid=3

Have you scanned this system with a virus scanner from neutral media?

---
Your question may already be answered in Windows Vista Security:
http://www.amazon.com/gp/product/047...otectyourwi-20


"..." wrote:

Every time I restart Vista Ult with latest updates, I notice my router's
lights blinking and I recently noticed this setting that keeps coming back
on my Persistent Port Forwarding options:
msxml2r32 Inbound Port 1757 on TCP

I delete this setting and restart the PC, and it's back.

I can't find this find anywhere on my PC. I've searched the net and only
found couple of Korean or Chinese sites that I don't understand, but they
mention Norton Antivirus, and a folder path to
C:\windows\system\msxml2r32.exe
I've looked on HKLM Run and HKCU Run settings in regedit, I've searched the
whole PC (indexed and non-indexed folders) and I am unable to find this
file.
Has anyone else come accross this?
Thanks
Gino


 




Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 06:38 PM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.Search Engine Optimization by vBSEO 3.0.0 RC6
Copyright ©2004-2024 Vista Banter.
The comments are property of their posters.