Windows Vista Forums
Vista Forums Home Join Vista Forums Donate Vista Tutorials Tags

Welcome to Vista Forums we are your forum to discuss Windows Vista x64 and x86 systems. Whether you need help or just want to post an idea you have on Vista, this is the forum for you.
Register at Vista forums...the world biggest Windows Vista resource Join Vista Forums Now

Go Back   Vista Forums > Vista Newsgroups > Vista security

msxml2r32.exe? what is this?

Closed Thread
 
Thread Tools Display Modes
Old 09-07-2007   #1 (permalink)
...
Guest


 

msxml2r32.exe? what is this?

Every time I restart Vista Ult with latest updates, I notice my router's
lights blinking and I recently noticed this setting that keeps coming back
on my Persistent Port Forwarding options:
msxml2r32 Inbound Port 1757 on TCP

I delete this setting and restart the PC, and it's back.

I can't find this find anywhere on my PC. I've searched the net and only
found couple of Korean or Chinese sites that I don't understand, but they
mention Norton Antivirus, and a folder path to
C:\windows\system\msxml2r32.exe
I've looked on HKLM Run and HKCU Run settings in regedit, I've searched the
whole PC (indexed and non-indexed folders) and I am unable to find this
file.
Has anyone else come accross this?
Thanks
Gino

Old 09-08-2007   #2 (permalink)
Jesper
Guest


 

RE: msxml2r32.exe? what is this?

It is highly likely to be malware of some sort. Malware can configure your
router if it is configurable via UPNP, or if you have typed your password for
the router on the infected system.

I found one site that stated the file name has been found on a virus written
in either Japanese or Korean that randomly chose names. Symantec calls it
antinny. Here's the page:
http://www.symantec.com/security_res...045-99&tabid=3

Have you scanned this system with a virus scanner from neutral media?

---
Your question may already be answered in Windows Vista Security:
http://www.amazon.com/gp/product/047...otectyourwi-20


"..." wrote:
Quote:

> Every time I restart Vista Ult with latest updates, I notice my router's
> lights blinking and I recently noticed this setting that keeps coming back
> on my Persistent Port Forwarding options:
> msxml2r32 Inbound Port 1757 on TCP
>
> I delete this setting and restart the PC, and it's back.
>
> I can't find this find anywhere on my PC. I've searched the net and only
> found couple of Korean or Chinese sites that I don't understand, but they
> mention Norton Antivirus, and a folder path to
> C:\windows\system\msxml2r32.exe
> I've looked on HKLM Run and HKCU Run settings in regedit, I've searched the
> whole PC (indexed and non-indexed folders) and I am unable to find this
> file.
> Has anyone else come accross this?
> Thanks
> Gino
>
>
Closed Thread

Thread Tools
Display Modes


Similar Threads
Thread Thread Starter Forum Replies Last Post
msxml2r32.exe? what is this? ... Vista General 1 09-08-2007 07:32 PM
msxml2r32.exe? what is this? ... Vista networking & sharing 1 09-08-2007 07:32 PM








Vistax64.com is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media 2005-2008

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50