Slooow surfing Virus??

General software, Operating Systems, and Programming discussion.
Everything from software questions, OSes, simple HTML to scripting languages, Perl, PHP, Python, MySQL, VB, C++ etc.
Post Reply
macmuffy

Slooow surfing Virus??

Post by macmuffy »

Happy as a clam with speed. Two nights ago, logged on and could not link off my home page, some favorites would not work, and if it did work, just like home page, could not link off that page.
I keep java and activeX disabled.
Mail and all other programs worked OK.

Noticed that send light was blinking when I was in the think mode trying to figure this out. By using ZoneAlarm was able to ID what was causing the traffic. MSGSRV322.exe was the cause. did a ctrl/alt/delete to see if it was running and it was not.
(Msgsrv32.exe seems to be a kosher file)

Did a registery search and removed it, did a directory search and only found one instance of the file in the \win\system directory and removed it. Power down and repowered and surfing was still slow/unusable. Repaired IE5, same results. did another search for the offending file and could not find it. ZA did not report this file running after deletion.

Had to reformat and reload an older backup to get things back to normal. (Major pain in the rear)

Question is what is this program and would anybody like to take a stab as to how I got it?
If it is a virus how would I remove it?
subzero

Post by subzero »

I've heard of this virus. It is supposed to bring down entire cable networks since its all shared. But this virus doesn't work. It does slow you down by collapsing the tcp/ip stack and some parts of your registry. Apperantly this virus didn't work too good.
User avatar
blebs
Posts: 12819
Joined: Sat Dec 02, 2000 12:00 am
Location: North Canton, Ohio

Post by blebs »

URL=http://support.microsoft.com/support/kb ... CH&SPR=W98]Msgrsrv32[/URL]


MSGSRV32 -Microsofts description^^^^^^^^^^^^^^^




If the slowness happens again, open netstat from the dos prompt and type in netstat -a -n enter, this will show you all open ports and what type of connection is established or listening on the port.

While I'm typing, this is what I have running

C:\WINDOWS>netstat -a -n

Active Connections

Proto Local Address Foreign Address State
TCP 0.0.0.0:2746 0.0.0.0:0 LISTENING
TCP xx.xxx.xxx.xxx:2746 64.4.13.51:1863 ESTABLISHED
TCP 127.0.0.1:110 0.0.0.0:0 LISTENING
TCP 127.0.0.1:2725 0.0.0.0:0 LISTENING
TCP 127.0.0.1:2747 0.0.0.0:0 LISTENING
UDP 127.0.0.1:2725 *:*
UDP 127.0.0.1:2747 *:*
The 64.4.13.51 on port 1863 in MSN Messenger Service!
You might find this tool helpful in the future. ;)
I get the feeling that your not using any Anti-Virus Program on your system. If this is the case, go to the following link
Inoculate It Personal Edition and download a copy and install it (It is Free for personal use) then immediately go back to the site and get the updated virus definitions and install, then run a complete system check. If it's a virus on there, it's about 98.9% sure to be caught! :)
Then just follow the programs recommendations for getting rid of the offender.[
subzero

Post by subzero »

He's right. sorry but i got the name mixed up with MGRSS222M.exe. This was a virus released about 2 years ago but it was not that common.
User avatar
ColdFusion
Posts: 3542
Joined: Mon Oct 30, 2000 12:00 am
Location: Vancouver, BC

Post by ColdFusion »

Well,
If you want to find out what the virus is, I suggest you goto http://www.mcafee.com and do a search for MSGSRV322.exe

Hope This Helps
Mat
donald_k
Regular Member
Posts: 406
Joined: Tue Oct 17, 2000 12:00 am
Location: Thunder Bay, Ontario, Canada

Post by donald_k »

:eek: :eek: :eek: MSGSRV32 is a system component of WIN9X/ME. It is not an MSN Messenger component. When the windows GUI first loads up the very first thing after mstask.tsk MSGSVR32 loads, if you are fast enough when the machine first loads up and press cntrl+alt+del and see it then go ahead and kill it. But more than likely the machine will need a reboot as the startup process will be hung. Now if you are at the desktop and see MSGSVR32 in the CTRL+ALT+DEL box then something is wrong or a virus is present as normally it runs as a system level process and will not show up in the box when windows is fully loaded up. To be on the safe side get a virus scanner to scan your hardrive. If you are running NT/2K then take immediate action as MSGSVR32 is NOT present in Windows NT/2000 as the kernel itself in those operating systems handles the process calls directly, also is why NT is so much better than 9x for stability :sleep: .
User avatar
blebs
Posts: 12819
Joined: Sat Dec 02, 2000 12:00 am
Location: North Canton, Ohio

Post by blebs »

Originally posted by donald_k
:eek: :eek: :eek: MSGSRV32 is a system component of WIN9X/ME. It is not an MSN Messenger component. :.
I'm glad you said something! I always thought it was for MSN Messenger because I never caught a glimpse of it until I started using that program.

I stand corrected. I'll go back into my hole in the wall now and continue to feel small for a while longer. ;)
User avatar
SVO-1
Advanced Member
Posts: 534
Joined: Sat Jun 02, 2001 11:39 am

Post by SVO-1 »

Dude - you have a hell of a puter there:
- - -
1000mhz tbird
1Gig RAM
2 80gig HD
3com NIC
Asus MB
18mbs download cap
256kb/s upload cap
Sound Blaster Live card
NVidia Geforce 2 64MB ddr
Viewsonic flat panal moniter
Monsoon speakers
WindowsME
- - -
Good luck with your problem man
Thanks -
C Ya
User avatar
SVO-1
Advanced Member
Posts: 534
Joined: Sat Jun 02, 2001 11:39 am

Post by SVO-1 »

OH - you're not the one with the problem subzero - sorry.
Hell of a puter anyway. And good luck to you macmuffy.
Thanks -
C Ya
User avatar
Brent
SG VIP
Posts: 42153
Joined: Fri Oct 01, 1999 12:00 pm

Post by Brent »

Format and Re-Install, heh

that's the surefire way to clear everything up, and next time run a virus checker program :)

Also moving to Software forum
"Would you mind not standing on my chest, my hats on fire." - The Doctor
Post Reply