This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Cleaning A Hacked Computer...

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey everyone, the worst happened to me yesterday. I came to work with a crashed web/mail/sql remote Windows 2003 server, hoping it was just low on resources and needed a restart. As I was on the phone to have the folks at my hosting company restart it, the FBI called and at that point, I new that I had been HACKED… I have no clue how this guy got into my machine. I utilize insane passwords with symbols, letters, and numbers, usually 16 characters long, and have NEVER given them out or used them in a public environment. Somehow, he was able to login as Administrator, download three files from the internet via RDP through the systems browser, and basically turned my computer into a slave.

Unfortunately after much searching through the computer, there is very little that I can actually find on it. He downloaded a setup.exe file which the FBI has yet to tell me what it is…. He also downloaded a file calc.exe and starter.exe which appears to be the configuration file for calc.exe. I accidentally ran calc.exe and thank God its a command line program which requires parameters to run. It turned out to be a blessing in disguise, because then I was able to see what it was… "Bouncer 1.0rc6" which a few websites report as the following:

"Bouncer is a network tool which allows you to bypass proxy restrictions and obtain outside connections from an internal LAN. It uses SSL tunneling, which allows you to obtain a constant streaming connection out of a proxy. If you are restricted behind a proxy and can access secure online ordering sites, then you can get out to whatever host on whatever port you want. It also supports a lot of other features including socks 5, basic authentication, access control lists, and Web-based administration, and will run on Windows, Linux, and FreeBSD."

He then placed a Scheduled Task in Windows Scheduler to run starter.exe every 5 minutes. I deleted the two files as well as the WINRAR program he downloaded to extract the two files from the archive. I have yet to findout what "setup".exe was, but I do know it wasn't the WINRAR setup that he downloaded separately. ANYWAYS, sorry for the long intro, but Symantec Antivirus appears to be corrupted on the system, my PLESK doesn't work, and Microsoft Update just sits there forever.

Here are the HiJackThis logs, and two Netstat reports I ran… Any help that ANYONE can offer would be greatly appreciated. Basically, I'm trying to clean this machine, get rid of dangerous port openers and security vulnerabilities, and perhaps even find out how he got in as administrator in the first place…

HiJackThis log:
Logfile of HijackThis v1.99.1
Scan saved at 9:27:55 AM, on 8/9/2007
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\system32\serverappliance\appmgr.exe
C:\Program Files\SWsoft\Plesk\DrWeb\drwebcom.exe
C:\WINDOWS\system32\serverappliance\elementmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\PROGRA~1\MICROS~1\MSSQL$~1\binn\sqlservr.exe
C:\Program Files\SWsoft\Plesk\MSDE\MSSQL\Binn\sqlservr.exe
C:\Program Files\SWsoft\Plesk\Databases\MySQL\bin\mysqld-nt.exe
C:\Program Files\SWsoft\Plesk\dns\bin\named.exe
C:\Program Files\SWsoft\Plesk\MySQL\bin\mysqld-nt.exe
C:\Program Files\SWsoft\Plesk\admin\bin\plesksrv.exe
C:\WINDOWS\system32\serverappliance\srvcsurg.exe
C:\Program Files\SWsoft\Plesk\Additional\Tomcat\bin\tomcat5.exe
C:\Program Files\Troxo\LiveUpdateTroxo\TroxoLiveUpdate.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\Program Files\SWsoft\Plesk\admin\bin\psa-serv.exe
C:\Program Files\SWsoft\Plesk\admin\bin\Apache.exe
C:\Program Files\SWsoft\Plesk\admin\bin\PopPassD.exe
C:\Program Files\SWsoft\Plesk\MSDE\MSSQL\Binn\sqlagent.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SWsoft\Plesk\kav\kavsvc.exe
c:\windows\system32\inetsrv\w3wp.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\rdpclip.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Acronis\TrueImageServer\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageServer\TimounterMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\SWsoft\Plesk\admin\bin\packagemng.exe
c:\windows\system32\inetsrv\w3wp.exe
C:\Program Files\Java\jre1.5.0_06\bin\jucheck.exe
C:\Program Files\SWsoft\Plesk\admin\bin\SpamAssassinService.exe
C:\PROGRA~1\SWsoft\Plesk\ADDITI~1\Perl\bin\perl.exe
C:\Program Files\SWsoft\Plesk\admin\bin\stunnel.exe
C:\Program Files\SWsoft\Plesk\admin\bin\traymonitor.exe
C:\WINDOWS\system32\MsiExec.exe
C:\Program Files\SWsoft\Plesk\Mail Enable\BIN\MEPOPS.EXE
C:\Program Files\SWsoft\Plesk\Mail Enable\BIN\MEMTA.EXE
C:\Program Files\SWsoft\Plesk\Mail Enable\BIN\MESMTPC.EXE
C:\Program Files\SWsoft\Plesk\Mail Enable\BIN\MELSC.EXE
C:\Program Files\SWsoft\Plesk\Mail Enable\BIN\MEPOC.EXE
C:\WINDOWS\system32\cmd.exe
C:\Program Files\SWsoft\Plesk\admin\bin\runtask.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\SWsoft\Plesk\admin\bin\runtask.exe
c:\windows\system32\inetsrv\w3wp.exe
c:\windows\system32\inetsrv\w3wp.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\netstat.exe
C:\WINDOWS\system32\more.com
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/softAdmin.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://shdoclc.dll/softAdmin.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageServer\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageServer\TimounterMonitor.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Plesk Services Monitor.lnk = C:\Program Files\SWsoft\Plesk\admin\bin\traymonitor.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase8300.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1186608424971
O17 - HKLM\System\CCS\Services\Tcpip\..\{E1A9F5E2-85A3-421D-905D-71B61639AC82}: NameServer = 216.55.128.7,216.55.144.5
O20 - AppInit_DLLs: wiadefulb.dll
O20 - Winlogon Notify: dimsntfy - C:\WINDOWS\SYSTEM32\dimsntfy.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: DrWebCom - Doctor Web Ltd. - C:\Program Files\SWsoft\Plesk\DrWeb\drwebcom.exe
O23 - Service: KasperskyTM Anti-Virus (kavsvc) - Unknown owner - C:\Program Files\SWsoft\Plesk\kav\kavsvc.exe
O23 - Service: MailEnable List Connector (MELCS) - MailEnable Pty Ltd - C:\Program Files\SWsoft\Plesk\Mail Enable\BIN\MELSC.EXE
O23 - Service: MailEnable Mail Transfer Agent (MEMTAS) - MailEnable Pty Ltd - C:\Program Files\SWsoft\Plesk\Mail Enable\BIN\MEMTA.EXE
O23 - Service: MailEnable Postoffice Connector (MEPOCS) - MailEnable Pty Ltd - C:\Program Files\SWsoft\Plesk\Mail Enable\BIN\MEPOC.EXE
O23 - Service: MailEnable POP Service (MEPOPS) - MailEnable Pty Ltd - C:\Program Files\SWsoft\Plesk\Mail Enable\BIN\MEPOPS.EXE
O23 - Service: MailEnable SMTP Connector (MESMTPCS) - MailEnable Pty Ltd - C:\Program Files\SWsoft\Plesk\Mail Enable\BIN\MESMTPC.EXE
O23 - Service: MySQL Server (MySQL) - Unknown owner - C:\Program Files\SWsoft\Plesk\Databases\MySQL\bin\mysqld-nt.exe" –defaults-file="C:\Program Files\SWsoft\Plesk\Databases\MySQL\Data\my.ini" MySQL (file missing)
O23 - Service: Plesk Name Server (named) - Unknown owner - C:\Program Files\SWsoft\Plesk\dns\bin\named.exe" -n1 (file missing)
O23 - Service: PleskControlPanel - Unknown owner - C:\Program Files\SWsoft\Plesk\admin\bin\Apache.exe" -k runservice (file missing)
O23 - Service: Plesk Miscellaneous Service (pleskmiscsrv) - Unknown owner - C:\Program Files\SWsoft\Plesk\admin\bin\psa-serv.exe
O23 - Service: Plesk SQL Server (PleskSQLServer) - Unknown owner - C:\Program Files\SWsoft\Plesk\MySQL\bin\mysqld-nt.exe" –defaults-file="C:\Program Files\SWsoft\Plesk\MySQL\Data\my.ini" PleskSQLServer (file missing)
O23 - Service: Plesk Management Service (plesksrv) - Unknown owner - C:\Program Files\SWsoft\Plesk\admin\bin\plesksrv.exe" -run (file missing)
O23 - Service: Plesk PopPass Service (PopPassD) - Unknown owner - C:\Program Files\SWsoft\Plesk\admin\bin\PopPassD.exe" -run (file missing)
O23 - Service: SWsoft SiteBuilder (SiteBuilder) - Unknown owner - C:\Program Files\SWsoft\Plesk\WinSiteBuilder\docroot\sitebuilder.exe" -x (file missing)
O23 - Service: Plesk SpamAssassin Service (SpamAssassinService) - - C:\Program Files\SWsoft\Plesk\admin\bin\SpamAssassinService.exe
O23 - Service: Plesk SSL Wrapper Service (stunnel) - Unknown owner - C:\Program Files\SWsoft\Plesk\admin\bin\stunnel.exe" -service (file missing)
O23 - Service: Apache Tomcat (Tomcat5) - Unknown owner - C:\Program Files\SWsoft\Plesk\Additional\Tomcat\bin\tomcat5.exe" //RS//Tomcat5 (file missing)
O23 - Service: TroxoLiveUpdate - TROXO - C:\Program Files\Troxo\LiveUpdateTroxo\TroxoLiveUpdate.exe

Netstat Report:

Active Connections

Proto Local Address Foreign Address State
TCP 216-55-164-46:1034 216-55-164-46:8443 CLOSE_WAIT
TCP 216-55-164-46:1102 216-55-164-46:8306 ESTABLISHED
TCP 216-55-164-46:8306 216-55-164-46:1102 ESTABLISHED
TCP 216-55-164-46:http adsl-67-123-159-70.dsl.sktn01.pacbell.net:4029 ESTABLISHED
TCP 216-55-164-46:pop3 [removed]:1245 TIME_WAIT
TCP 216-55-164-46:pop3 [removed]:1247 TIME_WAIT
TCP 216-55-164-46:1035 58-65-239-58.myrdns.com:http CLOSE_WAIT
TCP 216-55-164-46:1039 58-65-239-58.myrdns.com:http CLOSE_WAIT
TCP 216-55-164-46:1041 58-65-239-58.myrdns.com:http CLOSE_WAIT
TCP 216-55-164-46:1045 58-65-239-58.myrdns.com:http CLOSE_WAIT
TCP 216-55-164-46:1063 58-65-239-58.myrdns.com:http CLOSE_WAIT
TCP 216-55-164-46:1064 58-65-239-58.myrdns.com:http CLOSE_WAIT
TCP 216-55-164-46:1205 [removed]:http CLOSE_WAIT
TCP 216-55-164-46:1206 [removed]:http CLOSE_WAIT
TCP 216-55-164-46:ms-sql-s [removed]:4069 ESTABLISHED
TCP 216-55-164-46:3389 adsl-67-123-159-70.dsl.sktn01.pacbell.net:1141 ESTABLISHED
TCP 216-55-164-46:4890 [removed]:https ESTABLISHED

Netstat -ABO Report:

Active Connections

Proto Local Address Foreign Address State PID
TCP 216-55-164-46:ftp 216-55-164-46:0 LISTENING 1720
[inetinfo.exe]

TCP 216-55-164-46:http 216-55-164-46:0 LISTENING 4
[System]

TCP 216-55-164-46:pop3 216-55-164-46:0 LISTENING 5748
[MEPOPS.EXE]

TCP 216-55-164-46:epmap 216-55-164-46:0 LISTENING 788
RpcSs
[svchost.exe]

TCP 216-55-164-46:https 216-55-164-46:0 LISTENING 4
[System]

TCP 216-55-164-46:microsoft-ds 216-55-164-46:0 LISTENING 4
[System]

TCP 216-55-164-46:465 216-55-164-46:0 LISTENING 5428
[stunnel.exe]

TCP 216-55-164-46:995 216-55-164-46:0 LISTENING 5428
[stunnel.exe]

TCP 216-55-164-46:1025 216-55-164-46:0 LISTENING 512
[lsass.exe]

TCP 216-55-164-46:1027 216-55-164-46:0 LISTENING 1720
[inetinfo.exe]

TCP 216-55-164-46:1029 216-55-164-46:0 LISTENING 1720
[inetinfo.exe]

TCP 216-55-164-46:1030 216-55-164-46:0 LISTENING 1720
[inetinfo.exe]

TCP 216-55-164-46:ms-sql-s 216-55-164-46:0 LISTENING 1916
[sqlservr.exe]

TCP 216-55-164-46:2805 216-55-164-46:0 LISTENING 1884
[sqlservr.exe]

TCP 216-55-164-46:3306 216-55-164-46:0 LISTENING 1940
[mysqld-nt.exe]

TCP 216-55-164-46:3389 216-55-164-46:0 LISTENING 572
TermService
[svchost.exe]

TCP 216-55-164-46:3559 216-55-164-46:0 LISTENING 4
[System]

TCP 216-55-164-46:5053 216-55-164-46:0 LISTENING 2464
[sitebuilder.exe]

TCP 216-55-164-46:8009 216-55-164-46:0 LISTENING 2588
[tomcat5.exe]

TCP 216-55-164-46:8025 216-55-164-46:0 LISTENING 1720
[inetinfo.exe]

TCP 216-55-164-46:8080 216-55-164-46:0 LISTENING 2588
[tomcat5.exe]

TCP 216-55-164-46:8098 216-55-164-46:0 LISTENING 4
[System]

TCP 216-55-164-46:8099 216-55-164-46:0 LISTENING 4
[System]

TCP 216-55-164-46:8306 216-55-164-46:0 LISTENING 2180
[mysqld-nt.exe]

TCP 216-55-164-46:8401 216-55-164-46:0 LISTENING 4
[System]

TCP 216-55-164-46:8402 216-55-164-46:0 LISTENING 4
[System]

TCP 216-55-164-46:8425 216-55-164-46:0 LISTENING 4
[System]

TCP 216-55-164-46:8443 216-55-164-46:0 LISTENING 2100
[Apache.exe]

TCP 216-55-164-46:9008 216-55-164-46:0 LISTENING 2588
[tomcat5.exe]

TCP 216-55-164-46:9080 216-55-164-46:0 LISTENING 2588
[tomcat5.exe]

TCP 216-55-164-46:30000 216-55-164-46:0 LISTENING 5428
[stunnel.exe]

TCP 216-55-164-46:smtp 216-55-164-46:0 LISTENING 2264
[MESMTPC.EXE]

TCP 216-55-164-46:domain 216-55-164-46:0 LISTENING 1980
[named.exe]

TCP 216-55-164-46:106 216-55-164-46:0 LISTENING 2928
[PopPassD.exe]

TCP 216-55-164-46:783 216-55-164-46:0 LISTENING 5388
[perl.exe]

TCP 216-55-164-46:953 216-55-164-46:0 LISTENING 1980
[named.exe]

TCP 216-55-164-46:1040 216-55-164-46:0 LISTENING 232
[alg.exe]

TCP 216-55-164-46:8005 216-55-164-46:0 LISTENING 2588
[tomcat5.exe]

TCP 216-55-164-46:8090 216-55-164-46:0 LISTENING 5356
[SpamAssassinService.exe]

TCP 216-55-164-46:smtp 216-55-164-46:0 LISTENING 2264
[MESMTPC.EXE]

TCP 216-55-164-46:smtp 216-55-164-46:0 LISTENING 2264
[MESMTPC.EXE]

TCP 216-55-164-46:smtp 216-55-164-46:0 LISTENING 2264
[MESMTPC.EXE]

TCP 216-55-164-46:smtp 216-55-164-46:0 LISTENING 2264
[MESMTPC.EXE]

TCP 216-55-164-46:smtp 216-55-164-46:0 LISTENING 2264
[MESMTPC.EXE]

TCP 216-55-164-46:smtp 216-55-164-46:0 LISTENING 2264
[MESMTPC.EXE]

TCP 216-55-164-46:smtp 216-55-164-46:0 LISTENING 2264
[MESMTPC.EXE]

TCP 216-55-164-46:smtp 216-55-164-46:0 LISTENING 2264
[MESMTPC.EXE]

TCP 216-55-164-46:smtp 216-55-164-46:0 LISTENING 2264
[MESMTPC.EXE]

TCP 216-55-164-46:smtp 216-55-164-46:0 LISTENING 2264
[MESMTPC.EXE]

TCP 216-55-164-46:smtp 216-55-164-46:0 LISTENING 2264
[MESMTPC.EXE]

TCP 216-55-164-46:domain 216-55-164-46:0 LISTENING 1980
[named.exe]

TCP 216-55-164-46:domain 216-55-164-46:0 LISTENING 1980
[named.exe]

TCP 216-55-164-46:domain 216-55-164-46:0 LISTENING 1980
[named.exe]

TCP 216-55-164-46:domain 216-55-164-46:0 LISTENING 1980
[named.exe]

TCP 216-55-164-46:domain 216-55-164-46:0 LISTENING 1980
[named.exe]

TCP 216-55-164-46:domain 216-55-164-46:0 LISTENING 1980
[named.exe]

TCP 216-55-164-46:domain 216-55-164-46:0 LISTENING 1980
[named.exe]

TCP 216-55-164-46:domain 216-55-164-46:0 LISTENING 1980
[named.exe]

TCP 216-55-164-46:domain 216-55-164-46:0 LISTENING 1980
[named.exe]

TCP 216-55-164-46:domain 216-55-164-46:0 LISTENING 1980
[named.exe]

TCP 216-55-164-46:domain 216-55-164-46:0 LISTENING 1980
[named.exe]

TCP 216-55-164-46:1102 216-55-164-46:8306 ESTABLISHED 2248
[plesksrv.exe]

TCP 216-55-164-46:8306 216-55-164-46:1102 ESTABLISHED 2180
[mysqld-nt.exe]

TCP 216-55-164-46:http [removed]:61580 ESTABLISHED 4
[System]

TCP 216-55-164-46:http adsl-67-123-159-70.dsl.sktn01.pacbell.net:61581 ESTABLISHED 4
[System]

TCP 216-55-164-46:3389 adsl-67-123-159-70.dsl.sktn01.pacbell.net:1141 ESTABLISHED 572
TermService
[svchost.exe]

TCP 216-55-164-46:1034 216-55-164-46:8443 CLOSE_WAIT 1588
[drwebcom.exe]

TCP 216-55-164-46:1035 58-65-239-58.myrdns.com:http CLOSE_WAIT 912
wuauserv
[svchost.exe]

TCP 216-55-164-46:1039 58-65-239-58.myrdns.com:http CLOSE_WAIT 912
wuauserv
[svchost.exe]

TCP 216-55-164-46:1041 58-65-239-58.myrdns.com:http CLOSE_WAIT 2780
[psa-serv.exe]

TCP 216-55-164-46:1045 58-65-239-58.myrdns.com:http CLOSE_WAIT 2780
[psa-serv.exe]

TCP 216-55-164-46:1063 58-65-239-58.myrdns.com:http CLOSE_WAIT 4544
[winlogon.exe]

TCP 216-55-164-46:1064 58-65-239-58.myrdns.com:http CLOSE_WAIT 4544
[winlogon.exe]

TCP 216-55-164-46:1205 [removed]:http CLOSE_WAIT 704
[jucheck.exe]

TCP 216-55-164-46:1206 [removed]:http CLOSE_WAIT 704
[jucheck.exe]

TCP 216-55-164-46:pop3 [removed]:1247 TIME_WAIT 0
TCP 216-55-164-46:pop3 [removed]:1245 TIME_WAIT 0
UDP 216-55-164-46:4892 *:* 4980
[sqlmangr.exe]

UDP 216-55-164-46:1028 *:* 852
Dnscache
[svchost.exe]

UDP 216-55-164-46:3456 *:* 1720
[inetinfo.exe]

UDP 216-55-164-46:4500 *:* 512
[lsass.exe]

UDP 216-55-164-46:1026 *:* 1980
[named.exe]

UDP 216-55-164-46:ms-sql-m *:* 1916
[sqlservr.exe]

UDP 216-55-164-46:microsoft-ds *:* 4
[System]

UDP 216-55-164-46:isakmp *:* 512
[lsass.exe]

UDP 216-55-164-46:ntp *:* 872
W32Time
[svchost.exe]

UDP 216-55-164-46:3456 *:* 1720
[inetinfo.exe]

UDP 216-55-164-46:domain *:* 1980
[named.exe]

UDP 216-55-164-46:ntp *:* 872
W32Time
[svchost.exe]

UDP 216-55-164-46:ntp *:* 872
W32Time
[svchost.exe]

UDP 216-55-164-46:ntp *:* 872
W32Time
[svchost.exe]

UDP 216-55-164-46:ntp *:* 872
W32Time
[svchost.exe]

UDP 216-55-164-46:ntp *:* 872
W32Time
[svchost.exe]

UDP 216-55-164-46:ntp *:* 872
W32Time
[svchost.exe]

UDP 216-55-164-46:domain *:* 1980
[named.exe]

UDP 216-55-164-46:domain *:* 1980
[named.exe]

UDP 216-55-164-46:ntp *:* 872
W32Time
[svchost.exe]

UDP 216-55-164-46:domain *:* 1980
[named.exe]

UDP 216-55-164-46:domain *:* 1980
[named.exe]

UDP 216-55-164-46:domain *:* 1980
[named.exe]

UDP 216-55-164-46:domain *:* 1980
[named.exe]

UDP 216-55-164-46:domain *:* 1980
[named.exe]

UDP 216-55-164-46:domain *:* 1980
[named.exe]

UDP 216-55-164-46:domain *:* 1980
[named.exe]

UDP 216-55-164-46:domain *:* 1980
[named.exe]

UDP 216-55-164-46:ntp *:* 872
W32Time
[svchost.exe]

UDP 216-55-164-46:ntp *:* 872
W32Time
[svchost.exe]

UDP 216-55-164-46:ntp *:* 872
W32Time
[svchost.exe]

UDP 216-55-164-46:ntp *:* 872
W32Time
[svchost.exe]

UDP 216-55-164-46:domain *:* 1980
[named.exe]

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI