Welcome Guest to What the Tech! ( Log In | Register ) We specialize in the removal of malicious software (malware), but here you'll find free help and support for all your tech questions. We invite you to ask questions, share experiences, and learn. Explore our message boards, or register now to post messages of your own. Please Start Here. Register today (registration removes advertising)
![]() ![]() |
Apr 9 2007, 01:14 AM
Post
#1
|
|
|
New Member ![]() Group: New Member Posts: 1 Joined: 9-April 07 Member No.: 69,363 Operating System: Win2k |
Thanks Logfile of HijackThis v1.99.1 Scan saved at 3:06:21 AM, on 4/9/2007 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\System32\termsrv.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\WINNT\System32\cisvc.exe C:\Program Files\NavNT\defwatch.exe C:\WINNT\System32\svchost.exe z:\IMail\IMonitor.exe z:\IMail\IWebCal.exe z:\IMail\iwebmsg.exe C:\Program Files\LogMeIn\RaMaint.exe C:\Program Files\LogMeIn\LogMeIn.exe C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe C:\PROGRA~1\MICROS~3\MSSQL\binn\sqlservr.exe C:\Program Files\NavNT\rtvscan.exe z:\IMail\POP3D32.exe z:\IMail\queuemgr.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\MSTask.exe z:\IMail\smtpd32.exe C:\WINNT\System32\svchost.exe C:\PROGRA~1\TEXASI~1\WFTPDP~1\WFTPD.EXE C:\WINNT\System32\WBEM\WinMgmt.exe C:\PROGRA~1\WEBTRE~1\wtrs_ui.exe C:\PROGRA~1\WEBTRE~1\wtrs.exe C:\WINNT\system32\svchost.exe C:\WINNT\System32\svchost.exe C:\WINNT\system32\Dfssvc.exe C:\WINNT\System32\dns.exe C:\WINNT\System32\msdtc.exe C:\WINNT\system32\MsgSys.EXE C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe C:\WINNT\System32\cidaemon.exe C:\WINNT\system32\logon.scr C:\WINNT\System32\inetsrv\inetinfo.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\rdpclip.exe C:\WINNT\explorer.exe C:\Program Files\Analog Devices\SoundMAX\Smtray.exe C:\Program Files\LogMeIn\LogMeInSystray.exe C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe C:\Documents and Settings\Administrator\Desktop\ProcessExplorer\procexp.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Hijackthis\HijackThis.exe O1 - Hosts: 65.16.121.85 glider.com O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\LogMeInSystray.exe" O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1104723632281 O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1125237569640 O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab O16 - DPF: {B91AEDBE-93DF-4017-8BB3-F1C300C0EC51} (InstallShield Setup Player 2K2) - http://ipswitch.com/Support/IMail/IMWMML/L...ackV1/setup.exe O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = glider.com O17 - HKLM\System\CCS\Services\Tcpip\..\{468DB75C-9183-4236-9058-B7A1D515793E}: NameServer = 4.2.2.1,65.16.121.83,65.16.121.85 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = glider.com O17 - HKLM\System\CS1\Services\Tcpip\..\{468DB75C-9183-4236-9058-B7A1D515793E}: NameServer = 65.16.121.85 O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = glider.com O17 - HKLM\System\CS2\Services\Tcpip\..\{468DB75C-9183-4236-9058-B7A1D515793E}: NameServer = 4.2.2.1,65.16.121.83,65.16.121.85 O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = glider.com O17 - HKLM\System\CS3\Services\Tcpip\..\{468DB75C-9183-4236-9058-B7A1D515793E}: NameServer = 4.2.2.1,65.16.121.83,65.16.121.85 O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\NavLogon.dll O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe O23 - Service: CA License Server (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe O23 - Service: Persits Software Email Agent (EmailAgent) - Persits Software, Inc. - C:\PROGRA~1\PERSIT~1\AspEmail\EMAILA~1\BIN\EMAILA~1.EXE O23 - Service: IMail FINGER Server (FINGRD32) - Ipswitch, Inc. - z:\IMail\FINGRD32.exe O23 - Service: IMail IMAP4 Server (IMAP4D32) - Ipswitch, Inc. - z:\IMail\IMAP4D32.exe O23 - Service: IMail Monitor Service (IMonitor) - Ipswitch, Inc. - z:\IMail\IMonitor.exe O23 - Service: IMail Web Calendar Service (IWebCal) - Ipswitch, Inc. - z:\IMail\IWebCal.exe O23 - Service: IMail Web Service (IWEBMSG) - Ipswitch, Inc. - z:\IMail\iwebmsg.exe O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\RaMaint.exe O23 - Service: LogMeIn Service (LogMeIn) - LogMeIn, Inc. - C:\Program Files\LogMeIn\LogMeIn.exe O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe O23 - Service: Network DDE Drivers (NetworkDDEDrivers) - Unknown owner - C:\WINNT\I386\Drivers\core\ndis.exe" -k runservice (file missing) O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe O23 - Service: OESH (Office Source Engine Help) - Unknown owner - C:\Program.exe (file missing) O23 - Service: IMail LDAP Service (OpenLDAP-slapd) - Unknown owner - z:\IMail\OpenLDAP\bin\slapd.exe O23 - Service: IMail POP3 Server (POP3D32) - Ipswitch, Inc. - z:\IMail\POP3D32.exe O23 - Service: IMail PWD Server (PSERVE) - Ipswitch, Inc. - z:\IMail\PSERVE.exe O23 - Service: IMail Queue Manager Service (QueueMgr) - Ipswitch, Inc. - z:\IMail\queuemgr.exe O23 - Service: IMail SMTP Server (SMTPD32) - Ipswitch, Inc. - z:\IMail\smtpd32.exe O23 - Service: IMail Sys Logger Service (SYSLOGD) - Ipswitch, Inc. - z:\IMail\SYSLOGD.exe O23 - Service: WFTPD Pro - Texas Imperial Software - C:\PROGRA~1\TEXASI~1\WFTPDP~1\WFTPD.EXE O23 - Service: IMail WHOIS Server (WHOISD32) - Ipswitch, Inc. - z:\IMail\WHOISD32.exe O23 - Service: WebTrends Reporting UI (wtinterface) - Unknown owner - C:\PROGRA~1\WEBTRE~1\wtrs_ui.exe O23 - Service: WebTrends Reporting Center (wtrs) - WebTrends Corp. - C:\PROGRA~1\WEBTRE~1\wtrs.exe |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
0 | unc | 0 | 22 minutes ago Last post by: unc |
|||
![]() |
0 | BoomerUS | 14 | Today, 03:10 PM Last post by: BoomerUS |
|||
![]() |
0 | marrus | 7 | Today, 01:58 PM Last post by: marrus |
|||
![]() |
0 | Ted Guinness | 17 | Today, 11:41 AM Last post by: Ted Guinness |
|||
|
Time is now: 8th January 2009 - 10:57 PM |