Wikiposts
Search
Computer/Internet Issues & Troubleshooting Anyone with questions about the terribly complex world of computers or the internet should try here. NOT FOR REPORTING ISSUES WITH PPRuNe FORUMS! Please use the subforum "PPRuNe Problems or Queries."

Virus or Malware?

Thread Tools
 
Search this Thread
 
Old 27th Oct 2009, 19:49
  #1 (permalink)  
Thread Starter
 
Join Date: Dec 2002
Location: Dorset,UK
Posts: 474
Received 16 Likes on 5 Posts
Virus or Malware?

On the last two occasions that I have started my computer Zonealarm firewall has reported that Proytecto1 is trying to access the internet. It seems the application involved is winpvr.exe and the destination IP is 192.168.2.1.53

A GOOGLE search seems to show that it is a worm of some sort but AVG shows nothing. Can anybody shed any light on this please.

CC
Compass Call is offline  
Old 27th Oct 2009, 20:27
  #2 (permalink)  
More bang for your buck
 
Join Date: Nov 2005
Location: land of the clanger
Age: 82
Posts: 3,512
Likes: 0
Received 0 Likes on 0 Posts
Try downloading SuperAntiSpyware (free edition) and running that: SUPERAntiSpyware.com - Downloads
green granite is offline  
Old 27th Oct 2009, 22:14
  #3 (permalink)  
 
Join Date: Nov 2000
Location: Cambridge, England, EU
Posts: 3,443
Likes: 0
Received 1 Like on 1 Post
the destination IP is 192.168.2.1.53
Unlikely, both because IP addresses aren't written like that - they can have one or two or three dots in them but not four - and because 192.168.something is a non-routable address anyway (although there's no saying that the malware isn't crap software that uselessly tries to access a non-routable address, I've seen similar daft and useless behaviour).
Gertrude the Wombat is offline  
Old 27th Oct 2009, 22:34
  #4 (permalink)  
Location, Location, Location
 
Join Date: Oct 2003
Location: If it moves, watch it like a hawk: If it doesn't, hit it with a hammer until it does...
Age: 60
Posts: 142
Likes: 0
Received 0 Likes on 0 Posts
maybe the OP meant:

the destination IP is 192.168.2.1:53

port 53/tcp Domain Name Server
port 53/udp Domain Name Server

That might make sense if the software is trying to resolve a hostname for communication with the outside world and your PC is on a network where the local DNS server has the IP address 192.168.2.1

As others said, malware and/or viruses (as well as legitimate programs) are not immune to programming errors so maybe it was coded to look for a specific IP address to find a DNS server rather than querying the properties of the network connection to ascertain who it should talk to for hostname-IP resolution.

Although, IIRC all Belkin routers and cable/ISDN modems default to 192.168.2.1 on the private/internal network interface if not re-configured by the enduser.

Last edited by mocoman; 27th Oct 2009 at 22:45.
mocoman is offline  
Old 27th Oct 2009, 22:47
  #5 (permalink)  
 
Join Date: Dec 2005
Location: Wellington,NZ
Age: 66
Posts: 1,679
Received 10 Likes on 4 Posts
Is the process "Proytecto 1", or "Proyecto 1" ?
Superantispyware has a good reputation.
So has MBAM.
I'd definitely try a scan with either (or both.)
MBAM is the smaller download.
Tarq57 is online now  
Old 27th Oct 2009, 23:44
  #6 (permalink)  
 
Join Date: Nov 2000
Location: Cambridge, England, EU
Posts: 3,443
Likes: 0
Received 1 Like on 1 Post
Good suggestion about the : instead of the ..

Although, IIRC all Belkin routers and cable/ISDN modems default to 192.168.2.1 on the private/internal network interface if not re-configured by the enduser.
My Linksys router talks to a cable modem and the default gateway address is 192.168.1.1, so they aren't all .2.1. Neither the Linksys router nor the cable modem has a DNS server in it so a DNS query appears (I've just checked with Wireshark) as an access to the correct external address of the ISP's DNS server.

If the OP is indeed running their own private DNS server on 192.168.2.1 one might expect them to know about it, no? - it doesn't sound like the sort of thing you set up by accident?
Gertrude the Wombat is offline  
Old 28th Oct 2009, 07:32
  #7 (permalink)  
More bang for your buck
 
Join Date: Nov 2005
Location: land of the clanger
Age: 82
Posts: 3,512
Likes: 0
Received 0 Likes on 0 Posts
The IP address 192.168.2.1 is the default for certain models of home broadband routers principally SMC and Belkin brands. This address is set by the manufacturer at the factory, but you can change it at any time using the network router's administrative console.
green granite is offline  

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service

Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.