This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack log - Thanks for the help

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Server has been generating outbound port 1433 SQLServer probes

Logfile of HijackThis v1.99.1
Scan saved at 9:28:40 AM, on 10/4/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\netdde.exe
D:\Program Files\Symantec\pcAnywhere\awhost32.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINNT\System32\svchost.exe
d:\imail\IMonitor.exe
d:\imail\iwebmsg.exe
C:\WINNT\System32\llssrv.exe
C:\WINNT\system32\mssqll.exe
C:\PROGRA~1\MICROS~4\MSSQL\binn\sqlservr.exe
C:\Program Files\NavNT\rtvscan.exe
C:\Program Files\Seagate Software\WCS\pageserver.exe
d:\imail\POP3D32.exe
d:\imail\queuemgr.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\regedit.exe
d:\imail\smtpd32.exe
D:\Program Files\EasyMail SMTP Express\smtpexp.exe
d:\imail\SYSLOGD.exe
C:\tcpstat.exe
C:\Program Files\Seagate Software\WCS\WebCompServer.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\netsrv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\Program Files\Microsoft SQL Server\MSSQL\binn\sqlagent.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Atomic Clock Sync\Atomic.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\WINNT\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
D:\HiJackThis\HijackThis.exe

O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [Sr.exe] C:\WINNT\Sr.exe
O4 - HKLM\..\Run: [Atomic.exe] C:\Program Files\Atomic Clock Sync\Atomic.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O12 - Plugin for .NPSSView: C:\Program Files\Seagate Software\Viewers\ActiveXViewer\\NPssView.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1124239364921
O17 - HKLM\System\CCS\Services\Tcpip\..\{395513A2-68AF-4E57-AA77-7F2A88E67B5B}: NameServer = 69.28.135.130
O17 - HKLM\System\CCS\Services\Tcpip\..\{5CBDE026-CA0D-4958-8EAC-F190EE88D6E0}: NameServer = 69.28.135.130
O17 - HKLM\System\CCS\Services\Tcpip\..\{71DE6705-F5FD-45EA-80D4-1A46FE5C5A01}: NameServer = 69.28.135.130
O17 - HKLM\System\CCS\Services\Tcpip\..\{D96B7E39-7A04-4993-A8D6-22ABBE59D716}: NameServer = 69.28.135.130
O20 - Winlogon Notify: NavLogon - C:\WINNT\System32\NavLogon.dll
O20 - Winlogon Notify: PCANotify - C:\WINNT\SYSTEM32\PCANotify.dll
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - D:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Persits Software Email Agent (EmailAgent) - Persits Software, Inc. - D:\PROGRA~1\PERSIT~1\AspEmail\EMAILA~1\BIN\EMAILA~1.EXE
O23 - Service: IMail FINGER Server (FINGRD32) - Ipswitch, Inc. - d:\imail\FINGRD32.exe
O23 - Service: IMail IMAP4 Server (IMAP4D32) - Ipswitch, Inc. - d:\imail\IMAP4D32.exe
O23 - Service: IMail Monitor Service (IMonitor) - Ipswitch, Inc. - d:\imail\IMonitor.exe
O23 - Service: IMail Web Calendar Service (IWebCal) - Ipswitch, Inc. - d:\imail\IWebCal.exe
O23 - Service: IMail Web Service (IWEBMSG) - Ipswitch, Inc. - d:\imail\iwebmsg.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: IMail LDAP Service (OpenLDAP-slapd) - Unknown owner - d:\imail\OpenLDAP\bin\slapd.exe
O23 - Service: Seagate Page Server (pageserver) - Unknown owner - C:\Program Files\Seagate Software\WCS\pageserver.exe" -service -cache -deleteCache (file missing)
O23 - Service: IMail POP3 Server (POP3D32) - Ipswitch, Inc. - d:\imail\POP3D32.exe
O23 - Service: IMail PWD Server (PSERVE) - Ipswitch, Inc. - d:\imail\PSERVE.exe
O23 - Service: IMail Queue Manager Service (QUEUEMGR) - Ipswitch, Inc. - d:\imail\queuemgr.exe
O23 - Service: Serv-U FTP Server (Serv-U) - Unknown owner - C:\WINNT\system32\regedit.exe
O23 - Service: IMail SMTP Server (SMTPD32) - Ipswitch, Inc. - d:\imail\smtpd32.exe
O23 - Service: EasyMail SMTP Express (smtpexp) - Quiksoft Corporation - D:\Program Files\EasyMail SMTP Express\smtpexp.exe
O23 - Service: IMail Sys Logger Service (SYSLOGD) - Ipswitch, Inc. - d:\imail\SYSLOGD.exe
O23 - Service: System (system) - Unknown owner - Monitor (file missing)
O23 - Service: IP / TCP Services (TCP-IP) - Unknown owner - C:\tcpstat.exe
O23 - Service: Seagate Web Component Server (WebCompServer) - Unknown owner - C:\Program Files\Seagate Software\WCS\WebCompServer.exe" -service (file missing)
O23 - Service: IMail WHOIS Server (WHOISD32) - Ipswitch, Inc. - d:\imail\WHOISD32.exe
O23 - Service: Windows Scheduler (WinShr) - Unknown owner - C:\WINNT\system32\netsrv.exe
hi sorry for the late reply, but as you can see we have more that our fair share of logs.. there looks to be a possibly unauthorised ( or hidden) ftp server installed but first i need you to post a fresh hiajckthis log so we can start cleaning it
Current hijack file as requested - thanks


Logfile of HijackThis v1.99.1
Scan saved at 10:40:08 AM, on 10/13/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\termsrv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\netdde.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINNT\System32\svchost.exe
d:\imail\IMAP4D32.exe
d:\imail\IMonitor.exe
d:\imail\iwebmsg.exe
C:\WINNT\system32\qttask.exe
C:\WINNT\System32\llssrv.exe
C:\WINNT\system32\mssqll.exe
C:\PROGRA~1\MICROS~4\MSSQL\binn\sqlservr.exe
C:\Program Files\NavNT\rtvscan.exe
C:\Program Files\Seagate Software\WCS\pageserver.exe
d:\imail\queuemgr.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\regedit.exe
d:\imail\smtpd32.exe
D:\Program Files\EasyMail SMTP Express\smtpexp.exe
d:\imail\SYSLOGD.exe
C:\tcpstat.exe
C:\Program Files\Seagate Software\WCS\WebCompServer.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\netsrv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\Program Files\Microsoft SQL Server\MSSQL\binn\sqlagent.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\rdpclip.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\WINNT\system32\mmc.exe
d:\imail\POP3D32.exe
D:\HiJackThis\HijackThis.exe

O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [Sr.exe] C:\WINNT\Sr.exe
O4 - HKLM\..\Run: [Error Nuker] C:\Program Files\Error Nuker\bin\ErrorNuker.exe autostart
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O12 - Plugin for .NPSSView: C:\Program Files\Seagate Software\Viewers\ActiveXViewer\\NPssView.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1124239364921
O17 - HKLM\System\CCS\Services\Tcpip\..\{395513A2-68AF-4E57-AA77-7F2A88E67B5B}: NameServer = 69.28.135.130
O17 - HKLM\System\CCS\Services\Tcpip\..\{5CBDE026-CA0D-4958-8EAC-F190EE88D6E0}: NameServer = 69.28.135.130
O17 - HKLM\System\CCS\Services\Tcpip\..\{71DE6705-F5FD-45EA-80D4-1A46FE5C5A01}: NameServer = 69.28.135.130
O17 - HKLM\System\CCS\Services\Tcpip\..\{D96B7E39-7A04-4993-A8D6-22ABBE59D716}: NameServer = 69.28.135.130
O20 - Winlogon Notify: NavLogon - C:\WINNT\System32\NavLogon.dll
O20 - Winlogon Notify: PCANotify - C:\WINNT\SYSTEM32\PCANotify.dll
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - D:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Persits Software Email Agent (EmailAgent) - Persits Software, Inc. - D:\PROGRA~1\PERSIT~1\AspEmail\EMAILA~1\BIN\EMAILA~1.EXE
O23 - Service: IMail FINGER Server (FINGRD32) - Ipswitch, Inc. - d:\imail\FINGRD32.exe
O23 - Service: IMail IMAP4 Server (IMAP4D32) - Ipswitch, Inc. - d:\imail\IMAP4D32.exe
O23 - Service: IMail Monitor Service (IMonitor) - Ipswitch, Inc. - d:\imail\IMonitor.exe
O23 - Service: IMail Web Calendar Service (IWebCal) - Ipswitch, Inc. - d:\imail\IWebCal.exe
O23 - Service: IMail Web Service (IWEBMSG) - Ipswitch, Inc. - d:\imail\iwebmsg.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: IMail LDAP Service (OpenLDAP-slapd) - Unknown owner - d:\imail\OpenLDAP\bin\slapd.exe
O23 - Service: Seagate Page Server (pageserver) - Unknown owner - C:\Program Files\Seagate Software\WCS\pageserver.exe" -service -cache -deleteCache (file missing)
O23 - Service: IMail POP3 Server (POP3D32) - Ipswitch, Inc. - d:\imail\POP3D32.exe
O23 - Service: IMail PWD Server (PSERVE) - Ipswitch, Inc. - d:\imail\PSERVE.exe
O23 - Service: IMail Queue Manager Service (QUEUEMGR) - Ipswitch, Inc. - d:\imail\queuemgr.exe
O23 - Service: Serv-U FTP Server (Serv-U) - Unknown owner - C:\WINNT\system32\regedit.exe
O23 - Service: IMail SMTP Server (SMTPD32) - Ipswitch, Inc. - d:\imail\smtpd32.exe
O23 - Service: EasyMail SMTP Express (smtpexp) - Quiksoft Corporation - D:\Program Files\EasyMail SMTP Express\smtpexp.exe
O23 - Service: IMail Sys Logger Service (SYSLOGD) - Ipswitch, Inc. - d:\imail\SYSLOGD.exe
O23 - Service: IP / TCP Services (TCP-IP) - Unknown owner - C:\tcpstat.exe
O23 - Service: Seagate Web Component Server (WebCompServer) - Unknown owner - C:\Program Files\Seagate Software\WCS\WebCompServer.exe" -service (file missing)
O23 - Service: IMail WHOIS Server (WHOISD32) - Ipswitch, Inc. - d:\imail\WHOISD32.exe
O23 - Service: Windows Scheduler (WinShr) - Unknown owner - C:\WINNT\system32\netsrv.exe
hi

there are indeed a couple of suspicious entries..

Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
also post a new hijackthis log
The original scan was a mess. I cleaned up about 95% of it and this is the result so far:

kaspersky:

——————————————————————————-
KASPERSKY ON-LINE SCANNER REPORT
Friday, October 14, 2005 02:11:55
Operating System: Microsoft Windows 2000 Advanced Server, Service Pack 4 (Build 2195)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 14/10/2005
Kaspersky Anti-Virus database records: 153896
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
Z:\

Scan Statistics:
Total number of scanned objects: 110865
Number of viruses found: 12
Number of infected objects: 23
Number of suspicious objects: 5
Duration of the scan process: 4194 sec

Infected Object Name - Virus Name
C:\System Volume Information\hidden32.exe Infected: not-a-virus:RiskTool.Win32.HideWindows
C:\WINNT\system32\config\AdmDll.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20
C:\WINNT\system32\config\raddrv.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20
C:\WINNT\system32\config\update.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21
C:\WINNT\system32\drivers\etc\service.exe/netsrv.exe Infected: not-a-virus:Server-FTP.Win32.Serv-U.4002
C:\WINNT\system32\drivers\etc\service.exe/Config/AdmDll.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20
C:\WINNT\system32\drivers\etc\service.exe/Config/ra.reg Infected: Backdoor.Win32.RA-based.z
C:\WINNT\system32\drivers\etc\service.exe/Config/raddrv.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20
C:\WINNT\system32\drivers\etc\service.exe/Config/update.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21
C:\WINNT\system32\drivers\etc\service.exe/Restore/hidden32.exe Infected: not-a-virus:RiskTool.Win32.HideWindows
C:\WINNT\system32\drivers\etc\service.exe Infected: not-a-virus:RiskTool.Win32.HideWindows
C:\WINNT\system32\qttask.exe Infected: not-a-virus:Server-FTP.Win32.Serv-U.gen
C:\WINNT\system32\regedit.exe Infected: not-a-virus:Server-FTP.Win32.Serv-U.5000
C:\WINNT\system32\vvv.exe Infected: Backdoor.Win32.Codbot.ba
C:\WINNT\system32\www.exe Infected: Backdoor.Win32.Codbot.ba
D:\IMail\virtuals\sportscareers_com\users\resumes\main.mbx/[From alexandria_dragonheart_reiven <[removed]>][Date Sat, 13 Aug 2005 03:32:53 -0400 (EDT)]/html Suspicious: Exploit.HTML.Iframe.FileDownload
D:\IMail\virtuals\sportscareers_com\users\resumes\main.mbx/[From Mail Delivery System <[removed]>][Date 13 Aug 2005 03:33:04 -0400]/UNNAMED/[From questions <[removed]>][Date Tue, 30 Aug 2005 02:00:35 -0400 (EDT)]/html Suspicious: Exploit.HTML.Iframe.FileDownload
D:\IMail\virtuals\sportscareers_com\users\resumes\main.mbx/[From Mail Delivery System <[removed]>][Date 13 Aug 2005 03:33:04 -0400]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload
D:\IMail\virtuals\sportscareers_com\users\resumes\main.mbx Suspicious: Exploit.HTML.Iframe.FileDownload
D:\Payflo_Pro\ASP\verisign\payflowpro\win32\perl\lib\+03+ ®®®\1.;%%;;\uuu\ÿÿ . ÿ\ÿÿÿ . ÿ\dfind.exe Infected: not-a-virus:NetTool.Win32.DFind
D:\Payflo_Pro\ASP\verisign\payflowpro\win32\perl\lib\+03+ ®®®\1.;%%;;\uuu\ÿÿ . ÿ\ÿÿÿ . ÿ\pskill.exe Infected: not-a-virus:RiskTool.Win32.PsKill.1101

Scan process completed.


New hijack:


Logfile of HijackThis v1.99.1
Scan saved at 2:14:22 AM, on 10/14/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\termsrv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\netdde.exe
D:\Program Files\Kaspersky Lab\Kaspersky Administration Kit\klserver.exe
C:\WINNT\System32\svchost.exe
d:\imail\IMAP4D32.exe
d:\imail\IMonitor.exe
d:\imail\iwebmsg.exe
d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for File Servers 5\kavmm.exe
D:\Program Files\Kaspersky Lab\Kaspersky Administration Kit\Nagent\klnagent.exe
C:\WINNT\system32\qttask.exe
C:\WINNT\System32\llssrv.exe
C:\PROGRA~1\MICROS~4\MSSQL\binn\sqlservr.exe
d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for File Servers 5\kavmm.exe
C:\Program Files\Seagate Software\WCS\pageserver.exe
d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for File Servers 5\kavmm.exe
d:\imail\POP3D32.exe
d:\imail\queuemgr.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\regedit.exe
d:\imail\smtpd32.exe
D:\Program Files\EasyMail SMTP Express\smtpexp.exe
d:\imail\SYSLOGD.exe
C:\Program Files\Seagate Software\WCS\WebCompServer.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\Program Files\Microsoft SQL Server\MSSQL\binn\sqlagent.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\rdpclip.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\WINNT\system32\logon.scr
D:\HiJackThis\HijackThis.exe

O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [Sr.exe] C:\WINNT\Sr.exe
O4 - HKLM\..\Run: [Error Nuker] C:\Program Files\Error Nuker\bin\ErrorNuker.exe autostart
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O12 - Plugin for .NPSSView: C:\Program Files\Seagate Software\Viewers\ActiveXViewer\\NPssView.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kav…can_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1124239364921
O17 - HKLM\System\CCS\Services\Tcpip\..\{395513A2-68AF-4E57-AA77-7F2A88E67B5B}: NameServer = 69.28.135.130
O17 - HKLM\System\CCS\Services\Tcpip\..\{5CBDE026-CA0D-4958-8EAC-F190EE88D6E0}: NameServer = 69.28.135.130
O17 - HKLM\System\CCS\Services\Tcpip\..\{71DE6705-F5FD-45EA-80D4-1A46FE5C5A01}: NameServer = 69.28.135.130
O17 - HKLM\System\CCS\Services\Tcpip\..\{D96B7E39-7A04-4993-A8D6-22ABBE59D716}: NameServer = 69.28.135.130
O20 - Winlogon Notify: NavLogon - C:\WINNT\System32\NavLogon.dll
O20 - Winlogon Notify: PCANotify - C:\WINNT\SYSTEM32\PCANotify.dll
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - D:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Kaspersky Administration Server (CSAdminServer) - Kaspersky Lab - D:\Program Files\Kaspersky Lab\Kaspersky Administration Kit\klserver.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Persits Software Email Agent (EmailAgent) - Persits Software, Inc. - D:\PROGRA~1\PERSIT~1\AspEmail\EMAILA~1\BIN\EMAILA~1.EXE
O23 - Service: IMail FINGER Server (FINGRD32) - Ipswitch, Inc. - d:\imail\FINGRD32.exe
O23 - Service: IMail IMAP4 Server (IMAP4D32) - Ipswitch, Inc. - d:\imail\IMAP4D32.exe
O23 - Service: IMail Monitor Service (IMonitor) - Ipswitch, Inc. - d:\imail\IMonitor.exe
O23 - Service: IMail Web Calendar Service (IWebCal) - Ipswitch, Inc. - d:\imail\IWebCal.exe
O23 - Service: IMail Web Service (IWEBMSG) - Ipswitch, Inc. - d:\imail\iwebmsg.exe
O23 - Service: Kaspersky Anti-Virus Service (klfsblogic) - Unknown owner - d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for File Servers 5\kavmm.exe" -run bl -n Fileserver -v 5.0.0.0 (file missing)
O23 - Service: Kaspersky Network Agent (KLNagent) - Kaspersky Lab - D:\Program Files\Kaspersky Lab\Kaspersky Administration Kit\Nagent\klnagent.exe
O23 - Service: mssqll SQL Server (mssqll) - Unknown owner - C:\WINNT\system32\mssqll.exe (file missing)
O23 - Service: IMail LDAP Service (OpenLDAP-slapd) - Unknown owner - d:\imail\OpenLDAP\bin\slapd.exe
O23 - Service: Seagate Page Server (pageserver) - Unknown owner - C:\Program Files\Seagate Software\WCS\pageserver.exe" -service -cache -deleteCache (file missing)
O23 - Service: IMail POP3 Server (POP3D32) - Ipswitch, Inc. - d:\imail\POP3D32.exe
O23 - Service: IMail PWD Server (PSERVE) - Ipswitch, Inc. - d:\imail\PSERVE.exe
O23 - Service: IMail Queue Manager Service (QUEUEMGR) - Ipswitch, Inc. - d:\imail\queuemgr.exe
O23 - Service: Serv-U FTP Server (Serv-U) - Unknown owner - C:\WINNT\system32\regedit.exe
O23 - Service: IMail SMTP Server (SMTPD32) - Ipswitch, Inc. - d:\imail\smtpd32.exe
O23 - Service: EasyMail SMTP Express (smtpexp) - Quiksoft Corporation - D:\Program Files\EasyMail SMTP Express\smtpexp.exe
O23 - Service: IMail Sys Logger Service (SYSLOGD) - Ipswitch, Inc. - d:\imail\SYSLOGD.exe
O23 - Service: IP / TCP Services (TCP-IP) - Unknown owner - C:\tcpstat.exe (file missing)
O23 - Service: Seagate Web Component Server (WebCompServer) - Unknown owner - C:\Program Files\Seagate Software\WCS\WebCompServer.exe" -service (file missing)
O23 - Service: IMail WHOIS Server (WHOISD32) - Ipswitch, Inc. - d:\imail\WHOISD32.exe
O23 - Service: Windows Scheduler (WinShr) - Unknown owner - C:\WINNT\system32\netsrv.exe (file missing)
hi
i see tha you have installed kaspersky antivirus software, so the following may not be required. still just in case:


first, copy this text here into notepad, save inot a convenient place. later we will go to safe mode and this page will not be available

1) Please download the Killbox.
Unzip it to the desktop but do NOT run it yet.

2) Then please reboot into Safe Mode by restarting your computer and pressing F8 as your computer is booting up. Then select the Safe Mode option.

3) Once in Safe Mode, please run Killbox.

4) Select "Delete on Reboot".

5) Open the text file with these instructions in it, and copy the file names below to the clipboard by highlighting them and pressing Control-C:


C:\System Volume Information\hidden32.exe
C:\WINNT\system32\config\AdmDll.dll
C:\WINNT\system32\config\raddrv.dll
C:\WINNT\system32\config\update.exe
C:\WINNT\system32\drivers\etc\service.exe
C:\WINNT\system32\qttask.exe
C:\WINNT\system32\regedit.exe
C:\WINNT\system32\vvv.exe
C:\WINNT\system32\www.exe


6) Return to Killbox, go to the File menu, and choose "Paste from Clipboard".

7) Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, click here to download and run missingfilesetup.exe. Then try TheKillbox again..

Let the system reboot.
open hijacthis click do a system scan only
tick the boxes next to these lines

O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O4 - HKLM\..\Run: [Sr.exe] C:\WINNT\Sr.exe
O4 - HKLM\..\Run: [Error Nuker] C:\Program Files\Error Nuker\bin\ErrorNuker.exe autostart
O23 - Service: Serv-U FTP Server (Serv-U) - Unknown owner - C:\WINNT\system32\regedit.exe
O23 - Service: Windows Scheduler (WinShr) - Unknown owner - C:\WINNT\system32\netsrv.exe (file missing)


then close all browser and explorer windows and hit fix checked

reboot
rescan with kaspersky( dont worry if it shows infections in c:\killbox)
post the report
also do a fresh scan with hijackthis
and post its log
I've tried twice to get rid of C:\System Volume Information\hidden32.exe but Killbox seems to be ignoring it.

Latest Kaspersky:

Infected Object Name - Virus Name
C:\System Volume Information\hidden32.exe Infected: not-a-virus:RiskTool.Win32.HideWindows
D:\IMail\virtuals\sportscareers_com\users\resumes\main.mbx/[From alexandria_dragonheart_reiven <[removed]>][Date Sat, 13 Aug 2005 03:32:53 -0400 (EDT)]/html Suspicious: Exploit.HTML.Iframe.FileDownload
D:\IMail\virtuals\sportscareers_com\users\resumes\main.mbx/[From Mail Delivery System <[removed]>][Date 13 Aug 2005 03:33:04 -0400]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload
D:\Payflo_Pro\ASP\verisign\payflowpro\win32\perl\lib\+03+ ®®®\1.;%%;;\uuu\ÿÿ . ÿ\ÿÿÿ . ÿ\dfind.exe Infected: not-a-virus:NetTool.Win32.DFind
D:\Payflo_Pro\ASP\verisign\payflowpro\win32\perl\lib\+03+ ®®®\1.;%%;;\uuu\ÿÿ . ÿ\ÿÿÿ . ÿ\pskill.exe Infected: not-a-virus:RiskTool.Win32.PsKill.1101

Scan process completed.

Latest Hijack:


Logfile of HijackThis v1.99.1
Scan saved at 1:15:57 PM, on 10/15/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\termsrv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\netdde.exe
D:\Program Files\Kaspersky Lab\Kaspersky Administration Kit\klserver.exe
C:\WINNT\System32\svchost.exe
d:\imail\IMonitor.exe
d:\imail\iwebmsg.exe
d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for File Servers 5\kavmm.exe
D:\Program Files\Kaspersky Lab\Kaspersky Administration Kit\Nagent\klnagent.exe
C:\WINNT\System32\llssrv.exe
C:\PROGRA~1\MICROS~4\MSSQL\binn\sqlservr.exe
C:\Program Files\Seagate Software\WCS\pageserver.exe
d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for File Servers 5\kavmm.exe
d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for File Servers 5\kavmm.exe
d:\imail\POP3D32.exe
d:\imail\queuemgr.exe
C:\WINNT\system32\MSTask.exe
d:\imail\smtpd32.exe
D:\Program Files\EasyMail SMTP Express\smtpexp.exe
d:\imail\SYSLOGD.exe
C:\Program Files\Seagate Software\WCS\WebCompServer.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\Program Files\Microsoft SQL Server\MSSQL\binn\sqlagent.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\rdpclip.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\HiJackThis\HijackThis.exe

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O12 - Plugin for .NPSSView: C:\Program Files\Seagate Software\Viewers\ActiveXViewer\\NPssView.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kav…can_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1124239364921
O17 - HKLM\System\CCS\Services\Tcpip\..\{395513A2-68AF-4E57-AA77-7F2A88E67B5B}: NameServer = 69.28.135.130
O17 - HKLM\System\CCS\Services\Tcpip\..\{5CBDE026-CA0D-4958-8EAC-F190EE88D6E0}: NameServer = 69.28.135.130
O17 - HKLM\System\CCS\Services\Tcpip\..\{71DE6705-F5FD-45EA-80D4-1A46FE5C5A01}: NameServer = 69.28.135.130
O17 - HKLM\System\CCS\Services\Tcpip\..\{D96B7E39-7A04-4993-A8D6-22ABBE59D716}: NameServer = 69.28.135.130
O20 - Winlogon Notify: NavLogon - C:\WINNT\System32\NavLogon.dll
O20 - Winlogon Notify: PCANotify - C:\WINNT\SYSTEM32\PCANotify.dll
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - D:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Kaspersky Administration Server (CSAdminServer) - Kaspersky Lab - D:\Program Files\Kaspersky Lab\Kaspersky Administration Kit\klserver.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Persits Software Email Agent (EmailAgent) - Persits Software, Inc. - D:\PROGRA~1\PERSIT~1\AspEmail\EMAILA~1\BIN\EMAILA~1.EXE
O23 - Service: IMail FINGER Server (FINGRD32) - Ipswitch, Inc. - d:\imail\FINGRD32.exe
O23 - Service: IMail IMAP4 Server (IMAP4D32) - Ipswitch, Inc. - d:\imail\IMAP4D32.exe
O23 - Service: IMail Monitor Service (IMonitor) - Ipswitch, Inc. - d:\imail\IMonitor.exe
O23 - Service: IMail Web Calendar Service (IWebCal) - Ipswitch, Inc. - d:\imail\IWebCal.exe
O23 - Service: IMail Web Service (IWEBMSG) - Ipswitch, Inc. - d:\imail\iwebmsg.exe
O23 - Service: Kaspersky Anti-Virus Service (klfsblogic) - Unknown owner - d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for File Servers 5\kavmm.exe" -run bl -n Fileserver -v 5.0.0.0 (file missing)
O23 - Service: Kaspersky Network Agent (KLNagent) - Kaspersky Lab - D:\Program Files\Kaspersky Lab\Kaspersky Administration Kit\Nagent\klnagent.exe
O23 - Service: Logical Disk Service (LdmSvc) - Unknown owner - C:\WINNT\system32\qttask.exe (file missing)
O23 - Service: mssqll SQL Server (mssqll) - Unknown owner - C:\WINNT\system32\mssqll.exe (file missing)
O23 - Service: IMail LDAP Service (OpenLDAP-slapd) - Unknown owner - d:\imail\OpenLDAP\bin\slapd.exe
O23 - Service: Seagate Page Server (pageserver) - Unknown owner - C:\Program Files\Seagate Software\WCS\pageserver.exe" -service -cache -deleteCache (file missing)
O23 - Service: IMail POP3 Server (POP3D32) - Ipswitch, Inc. - d:\imail\POP3D32.exe
O23 - Service: IMail PWD Server (PSERVE) - Ipswitch, Inc. - d:\imail\PSERVE.exe
O23 - Service: IMail Queue Manager Service (QUEUEMGR) - Ipswitch, Inc. - d:\imail\queuemgr.exe
O23 - Service: Serv-U FTP Server (Serv-U) - Unknown owner - C:\WINNT\system32\regedit.exe (file missing)
O23 - Service: IMail SMTP Server (SMTPD32) - Ipswitch, Inc. - d:\imail\smtpd32.exe
O23 - Service: EasyMail SMTP Express (smtpexp) - Quiksoft Corporation - D:\Program Files\EasyMail SMTP Express\smtpexp.exe
O23 - Service: IMail Sys Logger Service (SYSLOGD) - Ipswitch, Inc. - d:\imail\SYSLOGD.exe
O23 - Service: IP / TCP Services (TCP-IP) - Unknown owner - C:\tcpstat.exe (file missing)
O23 - Service: Seagate Web Component Server (WebCompServer) - Unknown owner - C:\Program Files\Seagate Software\WCS\WebCompServer.exe" -service (file missing)
O23 - Service: IMail WHOIS Server (WHOISD32) - Ipswitch, Inc. - d:\imail\WHOISD32.exe
O23 - Service: Windows Scheduler (WinShr) - Unknown owner - C:\WINNT\system32\netsrv.exe (file missing)



Should I remoe the lines with 'file missing'?


Thanks again
hi

dont just go remove those: hijackthis has a bug in it, a bug that makes it sometimes show file missing even when the file is ther up and running..

these need to go:

O23 - Service: Serv-U FTP Server (Serv-U) - Unknown owner - C:\WINNT\system32\regedit.exe (file missing)

O23 - Service: Windows Scheduler (WinShr) - Unknown owner - C:\WINNT\system32\netsrv.exe (file missing)

click start>run> type services.msc
loacte the services listed above, once found doubleclick, stop the service if running, then set its startup type to disabled
do this for those i listed above

to get rid of their reg entries lets use one of hjt's features:
open hjt, click go to misc tools section
there find delete an Nt service, click it
into the input box copy paste this: Serv-U
then click OK

repeat, this time copy paste WinShr

reboot

post a final log
Completed - see latest hijack log below.

Is there any concern about the C:\System Volume Information\hidden32.exe file that won't delete?

Thanks


Logfile of HijackThis v1.99.1
Scan saved at 3:04:18 PM, on 10/15/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\termsrv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\netdde.exe
D:\Program Files\Kaspersky Lab\Kaspersky Administration Kit\klserver.exe
C:\WINNT\System32\svchost.exe
d:\imail\IMAP4D32.exe
d:\imail\IMonitor.exe
d:\imail\iwebmsg.exe
d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for File Servers 5\kavmm.exe
D:\Program Files\Kaspersky Lab\Kaspersky Administration Kit\Nagent\klnagent.exe
C:\WINNT\System32\llssrv.exe
C:\PROGRA~1\MICROS~4\MSSQL\binn\sqlservr.exe
C:\Program Files\Seagate Software\WCS\pageserver.exe
d:\imail\POP3D32.exe
d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for File Servers 5\kavmm.exe
d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for File Servers 5\kavmm.exe
d:\imail\queuemgr.exe
C:\WINNT\system32\MSTask.exe
d:\imail\smtpd32.exe
D:\Program Files\EasyMail SMTP Express\smtpexp.exe
d:\imail\SYSLOGD.exe
C:\Program Files\Seagate Software\WCS\WebCompServer.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\Program Files\Microsoft SQL Server\MSSQL\binn\sqlagent.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\rdpclip.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\HiJackThis\HijackThis.exe

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O12 - Plugin for .NPSSView: C:\Program Files\Seagate Software\Viewers\ActiveXViewer\\NPssView.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kav…can_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1124239364921
O17 - HKLM\System\CCS\Services\Tcpip\..\{395513A2-68AF-4E57-AA77-7F2A88E67B5B}: NameServer = 69.28.135.130
O17 - HKLM\System\CCS\Services\Tcpip\..\{5CBDE026-CA0D-4958-8EAC-F190EE88D6E0}: NameServer = 69.28.135.130
O17 - HKLM\System\CCS\Services\Tcpip\..\{71DE6705-F5FD-45EA-80D4-1A46FE5C5A01}: NameServer = 69.28.135.130
O17 - HKLM\System\CCS\Services\Tcpip\..\{D96B7E39-7A04-4993-A8D6-22ABBE59D716}: NameServer = 69.28.135.130
O20 - Winlogon Notify: NavLogon - C:\WINNT\System32\NavLogon.dll
O20 - Winlogon Notify: PCANotify - C:\WINNT\SYSTEM32\PCANotify.dll
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - D:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Kaspersky Administration Server (CSAdminServer) - Kaspersky Lab - D:\Program Files\Kaspersky Lab\Kaspersky Administration Kit\klserver.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Persits Software Email Agent (EmailAgent) - Persits Software, Inc. - D:\PROGRA~1\PERSIT~1\AspEmail\EMAILA~1\BIN\EMAILA~1.EXE
O23 - Service: IMail FINGER Server (FINGRD32) - Ipswitch, Inc. - d:\imail\FINGRD32.exe
O23 - Service: IMail IMAP4 Server (IMAP4D32) - Ipswitch, Inc. - d:\imail\IMAP4D32.exe
O23 - Service: IMail Monitor Service (IMonitor) - Ipswitch, Inc. - d:\imail\IMonitor.exe
O23 - Service: IMail Web Calendar Service (IWebCal) - Ipswitch, Inc. - d:\imail\IWebCal.exe
O23 - Service: IMail Web Service (IWEBMSG) - Ipswitch, Inc. - d:\imail\iwebmsg.exe
O23 - Service: Kaspersky Anti-Virus Service (klfsblogic) - Unknown owner - d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for File Servers 5\kavmm.exe" -run bl -n Fileserver -v 5.0.0.0 (file missing)
O23 - Service: Kaspersky Network Agent (KLNagent) - Kaspersky Lab - D:\Program Files\Kaspersky Lab\Kaspersky Administration Kit\Nagent\klnagent.exe
O23 - Service: Logical Disk Service (LdmSvc) - Unknown owner - C:\WINNT\system32\qttask.exe (file missing)
O23 - Service: mssqll SQL Server (mssqll) - Unknown owner - C:\WINNT\system32\mssqll.exe (file missing)
O23 - Service: IMail LDAP Service (OpenLDAP-slapd) - Unknown owner - d:\imail\OpenLDAP\bin\slapd.exe
O23 - Service: Seagate Page Server (pageserver) - Unknown owner - C:\Program Files\Seagate Software\WCS\pageserver.exe" -service -cache -deleteCache (file missing)
O23 - Service: IMail POP3 Server (POP3D32) - Ipswitch, Inc. - d:\imail\POP3D32.exe
O23 - Service: IMail PWD Server (PSERVE) - Ipswitch, Inc. - d:\imail\PSERVE.exe
O23 - Service: IMail Queue Manager Service (QUEUEMGR) - Ipswitch, Inc. - d:\imail\queuemgr.exe
O23 - Service: IMail SMTP Server (SMTPD32) - Ipswitch, Inc. - d:\imail\smtpd32.exe
O23 - Service: EasyMail SMTP Express (smtpexp) - Quiksoft Corporation - D:\Program Files\EasyMail SMTP Express\smtpexp.exe
O23 - Service: IMail Sys Logger Service (SYSLOGD) - Ipswitch, Inc. - d:\imail\SYSLOGD.exe
O23 - Service: IP / TCP Services (TCP-IP) - Unknown owner - C:\tcpstat.exe (file missing)
O23 - Service: Seagate Web Component Server (WebCompServer) - Unknown owner - C:\Program Files\Seagate Software\WCS\WebCompServer.exe" -service (file missing)
O23 - Service: IMail WHOIS Server (WHOISD32) - Ipswitch, Inc. - d:\imail\WHOISD32.exe
hi i assume that you cant open that folder and delete it manually? also tell me which of the remote administration programs is the one that you installed/ use?
I changed the permissions on the folder long enough to delete the hidden32 program. The server has previously had VNC and pcanywhere in use but they are both disabled now. CUrrently just using Remote Desktop for remote admin.
so you can fix these lines:

O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper

O20 - Winlogon Notify: PCANotify - C:\WINNT\SYSTEM32\PCANotify.dll
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - D:\Program Files\Symantec\pcAnywhere\awhost32.exe

if you decide to use them its easy to re-enable them using hjt's backups

its starting to look good, but lets do one more check:



Please download ewido security suite it is a free version of the program.
  • Install ewido security suite
  • When installing, under "Additional Options" uncheck..
    • Install background guard
    • Install scan via context menu
  • Launch ewido, there should be an icon on your desktop, double-click it.
  • The program will now open to the main screen.
  • When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.
  • You will need to update ewido to the latest definition files.
    • On the left hand side of the main screen click update.
    • Then click on Start Update.
  • The update will start and a progress bar will show the updates being installed.
    (the status bar at the bottom will display ("Update successful")
If you are having problems with the updater, you can use this link to manually update ewido.
ewido manual updates

Once the updates are installed do the following:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • You will be prompted to clean the first infection.
  • Select "Perform action on all infections", then proceed.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop or a location where you can find it easily.
Close ewido security suite.

post its report here thank you
Here is the scan report: ——————————————————— ewido security suite - Scan report ——————————————————— + Created on: 9:26:20 PM, 10/18/2005 + Report-Checksum: F57AD85B + Scan result: C:\!KillBox\regedit.exe -> Backdoor.ServU-based : Cleaned with backup C:\Documents and Settings\Administrator\Cookies\system@hypertracker[1].txt -> Spyware.Cookie.Hypertracker : Cleaned with backup C:\Documents and Settings\fcitech\Cookies\fcitech@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup C:\Documents and Settings\IUSR\Cookies\iusr@atdmt[1].txt -> Spyware.Cookie.Atdmt : Cleaned with backup C:\Documents and Settings\IUSR\Cookies\iusr@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup ::Report End Thanks for all the help
hi looks good :D post a final hijackthis log and we can mark this topic as solved. as for the cookies, after we can see you're clean i'll post some advice how to prevent them
Thanks for the serious help - here is the hijack log



Logfile of HijackThis v1.99.1
Scan saved at 7:13:04 PM, on 10/19/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\termsrv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\netdde.exe
D:\Program Files\Kaspersky Lab\Kaspersky Administration Kit\klserver.exe
C:\WINNT\System32\svchost.exe
d:\imail\IMAP4D32.exe
d:\imail\IMonitor.exe
d:\imail\iwebmsg.exe
d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for File Servers 5\kavmm.exe
D:\Program Files\Kaspersky Lab\Kaspersky Administration Kit\Nagent\klnagent.exe
C:\WINNT\System32\llssrv.exe
C:\PROGRA~1\MICROS~4\MSSQL\binn\sqlservr.exe
C:\Program Files\Seagate Software\WCS\pageserver.exe
d:\imail\POP3D32.exe
d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for File Servers 5\kavmm.exe
d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for File Servers 5\kavmm.exe
d:\imail\queuemgr.exe
C:\WINNT\system32\MSTask.exe
d:\imail\smtpd32.exe
D:\Program Files\EasyMail SMTP Express\smtpexp.exe
d:\imail\SYSLOGD.exe
C:\Program Files\Seagate Software\WCS\WebCompServer.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\Program Files\Microsoft SQL Server\MSSQL\binn\sqlagent.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\logon.scr
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\rdpclip.exe
C:\WINNT\Explorer.EXE
D:\HiJackThis\HijackThis.exe

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O12 - Plugin for .NPSSView: C:\Program Files\Seagate Software\Viewers\ActiveXViewer\\NPssView.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kav…can_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1124239364921
O17 - HKLM\System\CCS\Services\Tcpip\..\{395513A2-68AF-4E57-AA77-7F2A88E67B5B}: NameServer = 69.28.135.130
O17 - HKLM\System\CCS\Services\Tcpip\..\{5CBDE026-CA0D-4958-8EAC-F190EE88D6E0}: NameServer = 69.28.135.130
O17 - HKLM\System\CCS\Services\Tcpip\..\{71DE6705-F5FD-45EA-80D4-1A46FE5C5A01}: NameServer = 69.28.135.130
O17 - HKLM\System\CCS\Services\Tcpip\..\{D96B7E39-7A04-4993-A8D6-22ABBE59D716}: NameServer = 69.28.135.130
O20 - Winlogon Notify: NavLogon - C:\WINNT\System32\NavLogon.dll
O20 - Winlogon Notify: PCANotify - C:\WINNT\SYSTEM32\PCANotify.dll
O23 - Service: Kaspersky Administration Server (CSAdminServer) - Kaspersky Lab - D:\Program Files\Kaspersky Lab\Kaspersky Administration Kit\klserver.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Persits Software Email Agent (EmailAgent) - Persits Software, Inc. - D:\PROGRA~1\PERSIT~1\AspEmail\EMAILA~1\BIN\EMAILA~1.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: IMail FINGER Server (FINGRD32) - Ipswitch, Inc. - d:\imail\FINGRD32.exe
O23 - Service: IMail IMAP4 Server (IMAP4D32) - Ipswitch, Inc. - d:\imail\IMAP4D32.exe
O23 - Service: IMail Monitor Service (IMonitor) - Ipswitch, Inc. - d:\imail\IMonitor.exe
O23 - Service: IMail Web Calendar Service (IWebCal) - Ipswitch, Inc. - d:\imail\IWebCal.exe
O23 - Service: IMail Web Service (IWEBMSG) - Ipswitch, Inc. - d:\imail\iwebmsg.exe
O23 - Service: Kaspersky Anti-Virus Service (klfsblogic) - Unknown owner - d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for File Servers 5\kavmm.exe" -run bl -n Fileserver -v 5.0.0.0 (file missing)
O23 - Service: Kaspersky Network Agent (KLNagent) - Kaspersky Lab - D:\Program Files\Kaspersky Lab\Kaspersky Administration Kit\Nagent\klnagent.exe
O23 - Service: Logical Disk Service (LdmSvc) - Unknown owner - C:\WINNT\system32\qttask.exe (file missing)
O23 - Service: mssqll SQL Server (mssqll) - Unknown owner - C:\WINNT\system32\mssqll.exe (file missing)
O23 - Service: IMail LDAP Service (OpenLDAP-slapd) - Unknown owner - d:\imail\OpenLDAP\bin\slapd.exe
O23 - Service: Seagate Page Server (pageserver) - Unknown owner - C:\Program Files\Seagate Software\WCS\pageserver.exe" -service -cache -deleteCache (file missing)
O23 - Service: IMail POP3 Server (POP3D32) - Ipswitch, Inc. - d:\imail\POP3D32.exe
O23 - Service: IMail PWD Server (PSERVE) - Ipswitch, Inc. - d:\imail\PSERVE.exe
O23 - Service: IMail Queue Manager Service (QUEUEMGR) - Ipswitch, Inc. - d:\imail\queuemgr.exe
O23 - Service: IMail SMTP Server (SMTPD32) - Ipswitch, Inc. - d:\imail\smtpd32.exe
O23 - Service: EasyMail SMTP Express (smtpexp) - Quiksoft Corporation - D:\Program Files\EasyMail SMTP Express\smtpexp.exe
O23 - Service: IMail Sys Logger Service (SYSLOGD) - Ipswitch, Inc. - d:\imail\SYSLOGD.exe
O23 - Service: IP / TCP Services (TCP-IP) - Unknown owner - C:\tcpstat.exe (file missing)
O23 - Service: Seagate Web Component Server (WebCompServer) - Unknown owner - C:\Program Files\Seagate Software\WCS\WebCompServer.exe" -service (file missing)
O23 - Service: IMail WHOIS Server (WHOISD32) - Ipswitch, Inc. - d:\imail\WHOISD32.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI