Please help!

At one of our locations we have discovered that a spam virus has infected the mail server. Our issue is that we have been listed in the PBL blacklist and our outgoing email is getting denied from some recipients. I do not want to request the removal until I can be certain that our system is clean.

This has been the issue since Thursday and I wanted to get NeatSuite back to working order as my first line of defense. I am waiting for renewal activation codes but cant wait alot longer as our email usage is needed on our 4 day offline. Currently, I need some guidance on which direction to turn to begin cleanup on our server.

Attached is what HouseCall found TWICE now. Yesterday I ran it at noon and clean and removed and again today at 10:30am cleaned and removed.
Below is a HJT log of the 2003 server. PLEASE HELP!!!

Best Regards,
Tom


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:32:22 AM, on 8/26/2008
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
F:\Program Files\Trend\SPROTECT\SpntSvc.exe
F:\Program Files\Trend\SPROTECT\StWatchDog.exe
F:\Program Files\Trend\SPROTECT\StOPP.exe
C:\WINDOWS\system32\certsrv.exe
C:\Program Files\HP\Cissesrv\cissesrv.exe
C:\WINDOWS\system32\cpqrcmc.exe
C:\WINDOWS\system32\Dfssvc.exe
C:\WINDOWS\System32\dns.exe
F:\Program Files\Trend\SPROTECT\EarthAgent.exe
C:\Program Files\EFI\EAP\jboss\bin\wrapper.exe
C:\WINDOWS\System32\svchost.exe
F:\Program Files\Trend Micro\Smex\EUQ\EUQMonitor.exe
C:\Program Files\EFI\EAP\jdk\bin\java.exe
C:\Program Files\Hewlett-Packard\PNM\server\mysql\bin\mysqld-max-nt.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$BKUPEXEC\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL$SBSMONITORING\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL$SHAREPOINT\Binn\sqlservr.exe
f:\PROGRA~1\MICROS~1\MSSQL\binn\sqlservr.exe
C:\WINDOWS\system32\ntfrs.exe
C:\Program Files\Trend Micro\OfficeScan\PCCSRV\web\service\ofcservice.exe
C:\Program Files\Trend Micro\OfficeScan\PCCSRV\Web\Service\DbServer.exe
C:\Program Files\EFI\PF_Connector and Utilities\PF_IOService.exe
C:\Program Files\Iomega\REV System Software\RevUDF.exe
F:\Program Files\Trend Micro\Smex\svcGenericHost.exe
F:\Program Files\Trend Micro\Smex\svcGenericHost.exe
F:\Program Files\Trend Micro\Smex\SMEX_SystemWatcher.exe
C:\Program Files\Microsoft SQL Server\MSSQL$SBSMONITORING\Binn\sqlagent.EXE
F:\Program Files\Trend Micro\Smex\SMEX_Master.exe
f:\PROGRA~1\MICROS~1\MSSQL\binn\sqlagent.exe
C:\WINDOWS\system32\sysdown.exe
C:\hp\hpsmh\bin\smhstart.exe
C:\WINDOWS\system32\lserver.exe
C:\WINDOWS\System32\wins.exe
C:\hp\hpsmh\bin\hpsmhd.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\EFI\EAP\pgsql\windows\pgsql\bin\postmaster.exe
C:\Program Files\Hewlett-Packard\PNM\server\Wrapper.exe
E:\Program Files\Exchsrvr\bin\exmgmt.exe
C:\hp\hpsmh\bin\rotatelogs.exe
C:\hp\hpsmh\bin\rotatelogs.exe
C:\Program Files\Hewlett-Packard\PNM\jre\bin\javaw.exe
C:\hp\hpsmh\bin\hpsmhd.exe
C:\hp\hpsmh\bin\rotatelogs.exe
C:\hp\hpsmh\bin\rotatelogs.exe
C:\Program Files\EFI\EAP\pgsql\windows\pgsql\bin\postgres.exe
C:\Program Files\EFI\EAP\pgsql\windows\pgsql\bin\postgres.exe
C:\Program Files\EFI\EAP\pgsql\windows\pgsql\bin\postgres.exe
E:\Program Files\Exchsrvr\bin\mad.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hewlett-Packard\PNM\server\bin\TLS.exe
E:\Program Files\Exchsrvr\bin\store.exe
E:\Program Files\Exchsrvr\bin\emsmta.exe
C:\Program Files\Hewlett-Packard\PNM\server\bin\Trafficd.exe
C:\Program Files\EFI\EAP\pgsql\windows\pgsql\bin\postgres.exe
C:\Program Files\EFI\EAP\pgsql\windows\pgsql\bin\postgres.exe
C:\Program Files\EFI\EAP\pgsql\windows\pgsql\bin\postgres.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\dmadmin.exe
C:\WINDOWS\System32\svchost.exe
c:\windows\system32\inetsrv\w3wp.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\rdpclip.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cpqteam.exe
F:\Program Files\VERITAS\VxUpdate\VxTaskbarMgr.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
c:\windows\system32\inetsrv\w3wp.exe
C:\Program Files\EFI\EAP\pgsql\windows\pgsql\bin\postgres.exe
C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/hardAdmin.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://shdoclc.dll/hardAdmin.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = res://shdoclc.dll/hardAdmin.htm
O1 - Hosts: 172.16.0.19 admat-as01
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [CPQTEAM] cpqteam.exe
O4 - HKLM\..\Run: [DWPersistentQueuedReporting] C:\PROGRA~1\COMMON~1\MICROS~1\DW\DWTRIG20.EXE -a
O4 - HKLM\..\Run: [VxTaskbarMgr] F:\Program Files\VERITAS\VxUpdate\VxTaskbarMgr.exe
O4 - HKLM\..\Run: [AtomTime] "C:\Program Files\AtomTime Pro\AtomTime.EXE"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [TMRUBottedTray] "C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe"
O4 - HKCU\..\Run: [Iomega Automatic Backup Pro] "C:\Program Files\Iomega\Automatic Backup Pro\LiveSystem.exe" -s
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-3362752990-540122329-3931283075-1223\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SMEX Administrator')
O4 - HKUS\S-1-5-21-3362752990-540122329-3931283075-1269\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'besa')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Startup: Server Management.lnk = Program Files\Microsoft Windows Small Business Server\Administration\LaunchConsole.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O14 - IERESET.INF: START_PAGE_URL=http://companyweb
O15 - ESC Trusted Zone: http://h18023.www1.hp.com
O15 - ESC Trusted Zone: http://h20180.www2.hp.com
O15 - ESC Trusted Zone: http://welcome.hp.com
O15 - ESC Trusted Zone: http://www.hp.com
O15 - ESC Trusted Zone: http://runonce.msn.com
O15 - ESC Trusted Zone: http://*.windowsupdate.com
O15 - ESC Trusted Zone: http://*.windowsupdate.com (HKLM)
O16 - DPF: {264AED84-12F1-4CA1-8AA7-EB939AE58D8D} (STCWeb Control) - https://secure.bcti.com/CACHE/stc/2/binaries/stcweb.cab
O16 - DPF: {35C3D91E-401A-4E45-88A5-F3B32CD72DF4} (Encrypt Class) - https://admat-r59xkaxf4.admatintcoasters.lo…html/AtxEnc.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1170442068656
O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - http://localhost/tsweb/msrdp.cab
O16 - DPF: {8990AFAD-D352-42AC-A72F-A660BBF6E209} (OfficeScan Management Console) - https://admat-r59xkaxf4.admatintcoasters.lo…/AtxConsole.cab
O16 - DPF: {A050E865-64E3-431B-8079-F0DFCEA90A2D} (PieChart Class) - https://admat-r59xkaxf4.admatintcoasters.lo…html/AtxPie.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = AdmatIntCoasters.local
O17 - HKLM\Software\..\Telephony: DomainName = AdmatIntCoasters.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{55637A5C-3642-4765-AA96-A6513A60DAB5}: NameServer = 172.16.0.113
O17 - HKLM\System\CCS\Services\Tcpip\..\{E907DD4B-94F1-436D-A1CC-4EE8E0D89DDE}: Domain = admatintcoasters.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{E907DD4B-94F1-436D-A1CC-4EE8E0D89DDE}: NameServer = 172.16.0.113
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = AdmatIntCoasters.local
O17 - HKLM\System\CS1\Services\Tcpip\..\{55637A5C-3642-4765-AA96-A6513A60DAB5}: NameServer = 172.16.0.113
O18 - Protocol: hpapp - {24F45006-5BD9-41B7-9BD9-5F8921C8EBD1} - C:\Program Files\Compaq\Cpqacuxe\Bin\hpapp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Backup Exec Remote Agent for Windows Servers (BackupExecAgentAccelerator) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\beremote.exe
O23 - Service: Backup Exec Agent Browser (BackupExecAgentBrowser) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\benetns.exe
O23 - Service: Backup Exec Device & Media Service (BackupExecDeviceMediaService) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\pvlsvr.exe
O23 - Service: Backup Exec Job Engine (BackupExecJobEngine) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\bengine.exe
O23 - Service: Backup Exec Naming Service (BackupExecNamingService) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\benser.exe
O23 - Service: Backup Exec Server (BackupExecRPCService) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\beserver.exe
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates International Inc. - C:\Program Files\CA\SharedComponents\CA_LIC\\lic98rmt.exe
O23 - Service: HP Smart Array SAS/SATA Event Notification Service (Cissesrv) - Hewlett-Packard Company - C:\Program Files\HP\Cissesrv\cissesrv.exe
O23 - Service: HP ProLiant Remote Monitor Service (CpqRcmc) - Hewlett-Packard Company - C:\WINDOWS\system32\cpqrcmc.exe
O23 - Service: Trend ServerProtect Agent (EarthAgent) - Trend Micro Inc. - F:\Program Files\Trend\SPROTECT\EarthAgent.exe
O23 - Service: ExecView Communication Module (ECM) (ECM Service) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\ECM\ECM.exe
O23 - Service: EFI EIS Server - Unknown owner - C:\Program Files\EFI\EAP\jboss\bin\wrapper.exe
O23 - Service: EUQ_Monitor - Trend Micro Inc. - F:\Program Files\Trend Micro\Smex\EUQ\EUQMonitor.exe
O23 - Service: EUQ_Setup - Trend Micro Inc. - F:\Program Files\Trend Micro\Smex\EUQ\setupInstExchangeRule.exe
O23 - Service: HP ProCurve Datastore - Unknown owner - C:\Program Files\Hewlett-Packard\PNM\server\mysql\bin\mysqld-max-nt.exe
O23 - Service: HP ProCurve Network Manager Server - Unknown owner - C:\Program Files\Hewlett-Packard\PNM\server\Wrapper.exe
O23 - Service: HP ProCurve Traffic Launch Service (HPTLS) - Hewlett-Packard - C:\Program Files\Hewlett-Packard\PNM\server\bin\TLS.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: OAConnector - Printcafe, Inc. - C:\Program Files\Hagen OA\OA Connector\OAConnector.exe
O23 - Service: OfficeScan Master Service (ofcservice) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan\PCCSRV\web\service\ofcservice.exe
O23 - Service: PFConnector - PrintCafe - C:\Program Files\EFI\PF_Connector and Utilities\PrintFlowXmlService.exe
O23 - Service: PF_IOService - Unknown owner - C:\Program Files\EFI\PF_Connector and Utilities\PF_IOService.exe
O23 - Service: RevUDFService - Iomega Corp - C:\Program Files\Iomega\REV System Software\RevUDF.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Trend Micro RUBotted Service (RUBotted) - Trend Micro Inc. - C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
O23 - Service: ScanMail for Microsoft Exchange Master Service (ScanMail_Master) - Trend Micro Inc. - F:\Program Files\Trend Micro\Smex\svcGenericHost.exe
O23 - Service: ScanMail for Microsoft Exchange Remote Configuration Server (ScanMail_RemoteConfig) - Trend Micro Inc. - F:\Program Files\Trend Micro\Smex\svcGenericHost.exe
O23 - Service: ScanMail for Microsoft Exchange System Watcher (ScanMail_SystemWatcher) - Trend Micro Inc. - F:\Program Files\Trend Micro\Smex\svcGenericHost.exe
O23 - Service: Trend ServerProtect (SpntSvc) - Trend Micro Inc. - F:\Program Files\Trend\SPROTECT\SpntSvc.exe
O23 - Service: HP ProLiant System Shutdown Service (sysdown) - Hewlett-Packard Company - C:\WINDOWS\system32\sysdown.exe
O23 - Service: HP System Management Homepage (SysMgmtHp) - Hewlett-Packard Company - C:\hp\hpsmh\bin\smhstart.exe
O23 - Service: WIN-PAK Communications Server (WPCommunicationsService) - Unknown owner - C:\Program Files\WINPAK2\WP Communications Server.exe

–
End of file - 13725 bytes

Attachments: