Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

HJT:Computer shuts down randomly, constant pop-ups


  • Please log in to reply

#1
diggerisgone

diggerisgone

    New Member

  • Member
  • Pip
  • 1 posts
Before I get yelled at for allowing web surfing on my server, let me say that I just came into this mess and am working to straighten out the whole place.

My computer reboots at random - no warning, no shutdown, just black screen. Started yesterday evening, along with loads of pop-ups all the time and terrible performance. I've run Adaware and Spyware Doctor. First run found about 1200 problems. Subsequent runs have found about 600 more. I've just let them fix all. I manually fought off MediaPass.exe. It appears to be gone now (there were about 150 instances of it running.

Please help! I have advertising pop-ups on my screen at seemingly random times, even when I'm not touching the thing.

The bigger problem is that this machine is a server - users at remote offices connect to it by terminal services. That means that I have lots of users with the ability to access web sites on the server. I am working to change the configuration so that this doesn't happen anymore, but I still have to get the server back in working order!


Please help!!!

Here is my log file:

Logfile of HijackThis v1.99.1
Scan saved at 11:43:29 AM, on 3/23/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\Documents and Settings\flatfoot\WINDOWS\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\termsrv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\msdtc.exe
C:\PROGRA~1\APC\POWERC~1\agent\pbeagent.exe
C:\PROGRA~1\APC\POWERC~1\server\PBESER~1.EXE
E:\Program Files\VERITAS\Backup Exec\NT\beremote.exe
C:\WINNT\system32\crypserv.exe
E:\PROGRA~1\sav\DefWatch.exe
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\System32\tcpsvcs.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\WINNT\system32\cba\pds.exe
C:\WINNT\System32\ismserv.exe
C:\WINNT\System32\llssrv.exe
C:\Program Files\Microsoft SQL Server\MSSQL$BKUPEXEC\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL$EMMSDE\Binn\sqlservr.exe
E:\PROGRA~1\sav\Rtvscan.exe
C:\WINNT\system32\ntfrs.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\System32\locator.exe
e:\Program Files\Symantec\SAVFMSE\SMSESrv.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\lserver.exe
e:\Program Files\Symantec\SAVFMSE\SMSECtrl.EXE
e:\Program Files\Symantec\SAVFMSE\SMSESp.exe
e:\Program Files\Symantec\SAVFMSE\SMSESp.exe
e:\Program Files\Symantec\SAVFMSE\SMSESp.exe
e:\Program Files\Symantec\SAVFMSE\SMSEUI.EXE
C:\WINNT\System32\WBEM\WinMgmt.exe
e:\Program Files\Symantec\SAVFMSE\SMSELog.EXE
C:\WINNT\System32\wins.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
e:\Program Files\Symantec\SAVFMSE\SMSESJM.EXE
E:\SUS\wusync\WUSyncSvc.exe
e:\Program Files\Symantec\SAVFMSE\SMSETask.exe
C:\Program Files\IMR\Alchemy Server\AuServer.exe
C:\WINNT\System32\dns.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\WINNT\system32\ams_ii\hndlrsvc.exe
C:\WINNT\system32\MsgSys.EXE
C:\WINNT\system32\ams_ii\iao.exe
C:\WINNT\system32\cba\xfr.exe
E:\Program Files\Exchsrvr\bin\exmgmt.exe
E:\Program Files\Exchsrvr\bin\mad.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
E:\Program Files\VERITAS\Backup Exec\NT\beserver.exe
E:\Program Files\Exchsrvr\bin\store.exe
E:\Program Files\Exchsrvr\bin\emsmta.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\winlogon.exe
E:\PROGRA~1\sav\vptray.exe
E:\Program Files\VERITAS\VxUpdate\VxTaskbarMgr.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
C:\Program Files\rv1ryi98\rv1ryi98.exe
C:\Documents and Settings\All Users.WINNT\Application Data\msw\BMan1.exe
C:\WINNT\system32\mim2gt.exe
C:\winnt\system32\spoipaja.exe
C:\WINNT\system32\rdpclip.exe
C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\msw\BMan.exe
C:\WINNT\system32\vanpin.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
E:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\eFax Messenger Plus 3.3\J2GDllCmd.exe
C:\Program Files\eFax Messenger Plus 3.3\J2GTray.exe
C:\winnt\system32\packager.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
E:\Program Files\Adobe\Acrobat 5.0\Distillr\acrodist.exe
C:\Program Files\rv1ryi98\44770935.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
C:\Program Files\rv1ryi98\rv1ryi98.exe
C:\Documents and Settings\All Users.WINNT\Application Data\msw\BMan1.exe
C:\WINNT\system32\mim2gt.exe
C:\winnt\system32\spoipaja.exe
C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\msw\BMan.exe
C:\WINNT\system32\vanpin.exe
C:\WINNT\system32\HPJETDSC.EXE
E:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\eFax Messenger Plus 3.3\J2GDllCmd.exe
C:\winnt\system32\calc.exe
C:\Program Files\eFax Messenger Plus 3.3\J2GTray.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\System32\tsadmin.exe
C:\WINNT\system32\taskmgr.exe
C:\WINNT\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
\prime01\public\TRANSFER\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Documents and Settings\flatfoot\WINDOWS\about.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\WINNT\system32\userinit.exe,
O2 - BHO: PynixObj Class - {00000000-DD60-0064-6EC2-6E0100000000} - C:\WINNT\Pynix.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~2\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O4 - HKLM\..\Run: [vptray] E:\PROGRA~1\sav\vptray.exe
O4 - HKLM\..\Run: [VxTaskbarMgr] E:\Program Files\VERITAS\VxUpdate\VxTaskbarMgr.exe
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [rv1ryi98] C:\Program Files\rv1ryi98\rv1ryi98.exe
O4 - HKLM\..\Run: [BMan] C:\Documents and Settings\All Users.WINNT\Application Data\msw\BMan1.exe
O4 - HKLM\..\Run: [etbrun] C:\winnt\system32\elitenub32.exe
O4 - HKLM\..\Run: [u36V3ni] mim2gt.exe
O4 - HKLM\..\Run: [spoipaja] c:\winnt\system32\spoipaja.exe
O4 - HKLM\..\Run: [farmmext] C:\WINNT\farmmext.exe
O4 - HKLM\..\Run: [xmfclih] C:\WINNT\xmfclih.exe
O4 - HKLM\..\Run: [KavSvc] C:\WINNT\system32\vanpin.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Startup: Acrobat Distiller 5.0.lnk = E:\Program Files\Adobe\Acrobat 5.0\Distillr\acrodist.exe
O4 - Global Startup: Acrobat Assistant.lnk = E:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: eFax Live Menu 3.3.lnk = C:\Program Files\eFax Messenger Plus 3.3\J2GDllCmd.exe
O4 - Global Startup: eFax Tray Menu 3.3.lnk = C:\Program Files\eFax Messenger Plus 3.3\J2GTray.exe
O4 - Global Startup: nutk.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Add to White List - C:\PROGRAM FILES\ADVANCED SEARCHBAR\addtolist.js
O8 - Extra context menu item: Delete from White List - C:\PROGRAM FILES\ADVANCED SEARCHBAR\delfromlist.js
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O10 - Broken Internet access because of LSP provider 'c:\documents and settings\flatfoot\windows\system32\rnr20.dll' missing
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.aspiryon.com
O15 - Trusted Zone: *.bankofamerica.com
O15 - Trusted Zone: *.bofa.com
O15 - Trusted Zone: *.citibank.com
O15 - Trusted Zone: *.citimortgage.com
O15 - Trusted Zone: *.digeratisolutions.net
O15 - Trusted Zone: *.factualdata.com
O15 - Trusted Zone: *.fanniemae.com
O15 - Trusted Zone: ww2.gemstoneohio.com
O15 - Trusted Zone: *.gemstoneohio.com
O15 - Trusted Zone: *.hfwholesale.com
O15 - Trusted Zone: *.lendingtree.com
O15 - Trusted Zone: *.meyersinternet.com
O15 - Trusted Zone: *.myownmortgage.com
O15 - Trusted Zone: *.originatornetwork.com
O15 - Trusted Zone: *.prime-loans.com
O15 - Trusted Zone: *.rfc.com
O15 - Trusted Zone: *.tandberg.com
O15 - Trusted Zone: *.veritas.com
O15 - Trusted Zone: elliemae.webex.com
O15 - Trusted Zone: *.webex.com
O15 - Trusted Zone: *.wellsfargo.com
O15 - Trusted Zone: *.aspiryon.com (HKLM)
O15 - Trusted Zone: *.bankofamerica.com (HKLM)
O15 - Trusted Zone: *.bofa.com (HKLM)
O15 - Trusted Zone: *.citibank.com (HKLM)
O15 - Trusted Zone: *.citimortgage.com (HKLM)
O15 - Trusted Zone: *.digeratisolutions.net (HKLM)
O15 - Trusted Zone: *.factualdata.com (HKLM)
O15 - Trusted Zone: *.fanniemae.com (HKLM)
O15 - Trusted Zone: ww2.gemstoneohio.com (HKLM)
O15 - Trusted Zone: *.gemstoneohio.com (HKLM)
O15 - Trusted Zone: *.hfwholesale.com (HKLM)
O15 - Trusted Zone: *.lendingtree.com (HKLM)
O15 - Trusted Zone: *.meyersinternet.com (HKLM)
O15 - Trusted Zone: www.myownmortgage.com (HKLM)
O15 - Trusted Zone: *.myownmortgage.com (HKLM)
O15 - Trusted Zone: *.originatornetwork.com (HKLM)
O15 - Trusted Zone: *.prime-loans.com (HKLM)
O15 - Trusted Zone: *.rfc.com (HKLM)
O15 - Trusted Zone: *.tandberg.com (HKLM)
O15 - Trusted Zone: *.veritas.com (HKLM)
O15 - Trusted Zone: *.webex.com (HKLM)
O15 - Trusted Zone: *.wellsfargo.com (HKLM)
O15 - Trusted IP range: http://192.168.4.21
O16 - DPF: {284DAE3C-A691-11D3-AD58-00E0B8107A24} (SISCtrl Class) - http://sef.mlxchange...ontrol/SISC.cab
O16 - DPF: {4989312D-58CF-11D5-A7D7-00E02911103E} (Interealty MultiSelect) - http://sef.mlxchange...ectComboBox.cab
O16 - DPF: {56BCB794-783A-48F1-A4C2-110F32371830} (ContClickLoan Control) - https://www.clickloa...ntClickLoan.cab
O16 - DPF: {6FD482A3-7B57-438B-B040-52CAA30147EE} (MLXchange Client Utils) - http://sef.mlxchange...ClientUtils.cab
O16 - DPF: {83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E} (GeacRevw Control) - http://sef.mlxchange...ol/IRCSharc.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://elliemae.web...ort/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = prime.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{5F4F2540-79E9-4F45-B3F4-52AA4353D5CB}: NameServer = 192.168.2.251,192.168.2.250
O17 - HKLM\System\CCS\Services\Tcpip\..\{FA16FF1B-F848-42A7-92CC-F9B35524DC74}: NameServer = 192.168.2.251,192.168.2.250
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = prime.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = prime.com
O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\\NavLogon.dll
O23 - Service: Alchemy Server (AlchemyServer) - Information Management Research, Inc. - C:\Program Files\IMR\Alchemy Server\AuServer.exe
O23 - Service: Alerter - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\services.exe (file missing)
O23 - Service: APC PBE Agent (APCPBEAgent) - APC - C:\PROGRA~1\APC\POWERC~1\agent\pbeagent.exe
O23 - Service: APC PBE Server (APCPBEServer) - APC - C:\PROGRA~1\APC\POWERC~1\server\PBESER~1.EXE
O23 - Service: Application Management (AppMgmt) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\system32\services.exe (file missing)
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (file missing)
O23 - Service: Backup Exec Remote Agent for Windows Servers (BackupExecAgentAccelerator) - VERITAS Software Corporation - E:\Program Files\VERITAS\Backup Exec\NT\beremote.exe
O23 - Service: Backup Exec Agent Browser (BackupExecAgentBrowser) - VERITAS Software Corporation - E:\Program Files\VERITAS\Backup Exec\NT\benetns.exe
O23 - Service: Backup Exec Device & Media Service (BackupExecDeviceMediaService) - VERITAS Software Corporation - E:\Program Files\VERITAS\Backup Exec\NT\pvlsvr.exe
O23 - Service: Backup Exec Job Engine (BackupExecJobEngine) - VERITAS Software Corporation - E:\Program Files\VERITAS\Backup Exec\NT\bengine.exe
O23 - Service: Backup Exec Naming Service (BackupExecNamingService) - VERITAS Software Corporation - E:\Program Files\VERITAS\Backup Exec\NT\benser.exe
O23 - Service: Backup Exec Server (BackupExecRPCService) - VERITAS Software Corporation - E:\Program Files\VERITAS\Backup Exec\NT\beserver.exe
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Computer Browser (Browser) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\services.exe (file missing)
O23 - Service: ClipBook (ClipSrv) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\system32\clipsrv.exe (file missing)
O23 - Service: Crypkey License - Unknown owner - crypserv.exe (file missing)
O23 - Service: DefWatch - Symantec Corporation - E:\PROGRA~1\sav\DefWatch.exe
O23 - Service: Distributed File System (Dfs) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\system32\Dfssvc.exe (file missing)
O23 - Service: DHCP Client (Dhcp) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\services.exe (file missing)
O23 - Service: DHCP Server (DHCPServer) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\tcpsvcs.exe (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\dmadmin.exe (file missing)
O23 - Service: Logical Disk Manager (dmserver) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\services.exe (file missing)
O23 - Service: DNS Server (DNS) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\dns.exe (file missing)
O23 - Service: DNS Client (Dnscache) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\services.exe (file missing)
O23 - Service: ExecView Communication Module (ECM) (ECM Service) - VERITAS Software Corporation - E:\Program Files\VERITAS\Backup Exec\NT\ECM\ECM.exe
O23 - Service: Event Log (Eventlog) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\system32\services.exe (file missing)
O23 - Service: Fax Service (Fax) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\system32\faxsvc.exe (file missing)
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: Intel Alert Handler - Intel® Corporation - C:\WINNT\system32\ams_ii\hndlrsvc.exe
O23 - Service: Intel Alert Originator - Intel® Corporation - C:\WINNT\system32\ams_ii\iao.exe
O23 - Service: Intel File Transfer - Intel® Corporation - C:\WINNT\system32\cba\xfr.exe
O23 - Service: Intel PDS - Intel® Corporation - C:\WINNT\system32\cba\pds.exe
O23 - Service: Intersite Messaging (IsmServ) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\ismserv.exe (file missing)
O23 - Service: Kerberos Key Distribution Center (kdc) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: Server (lanmanserver) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\services.exe (file missing)
O23 - Service: Workstation (lanmanworkstation) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\services.exe (file missing)
O23 - Service: License Logging Service (LicenseService) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\llssrv.exe (file missing)
O23 - Service: TCP/IP NetBIOS Helper Service (LmHosts) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\services.exe (file missing)
O23 - Service: Messenger - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\services.exe (file missing)
O23 - Service: Network DDE (NetDDE) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\system32\netdde.exe (file missing)
O23 - Service: Network DDE DSDM (NetDDEdsdm) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\system32\netdde.exe (file missing)
O23 - Service: Net Logon (Netlogon) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: Network Connections (Netman) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Symantec AntiVirus Server (Norton AntiVirus Server) - Symantec Corporation - E:\PROGRA~1\sav\Rtvscan.exe
O23 - Service: File Replication Service (NtFrs) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\system32\ntfrs.exe (file missing)
O23 - Service: NT LM Security Support Provider (NtLmSsp) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: Removable Storage (NtmsSvc) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Plug and Play (PlugPlay) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\system32\services.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\spool\DRIVERS\W32X86\3\HPZipm12.exe
O23 - Service: IPSEC Policy Agent (PolicyAgent) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: Protected Storage (ProtectedStorage) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\system32\services.exe (file missing)
O23 - Service: Remote Access Auto Connection Manager (RasAuto) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Remote Access Connection Manager (RasMan) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Remote Registry Service (RemoteRegistry) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\system32\regsvc.exe (file missing)
O23 - Service: Remote Procedure Call (RPC) Locator (RpcLocator) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\locator.exe (file missing)
O23 - Service: Remote Procedure Call (RPC) (RpcSs) - Unknown owner - C:\Documents.exe (file missing)
O23 - Service: QoS RSVP (RSVP) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\rsvp.exe (file missing)
O23 - Service: Security Accounts Manager (SamSs) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Symantec AntiVirus/Filtering for Microsoft Exchange 2000 (SAVFMSE) - Symantec Corporation - e:\Program Files\Symantec\SAVFMSE\SMSESrv.exe
O23 - Service: Smart Card Helper (SCardDrv) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\SCardSvr.exe (file missing)
O23 - Service: Smart Card (SCardSvr) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\SCardSvr.exe (file missing)
O23 - Service: Task Scheduler (Schedule) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\system32\MSTask.exe (file missing)
O23 - Service: RunAs Service (seclogon) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\system32\services.exe (file missing)
O23 - Service: System Event Notification (SENS) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Print Spooler (Spooler) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\system32\spoolsv.exe (file missing)
O23 - Service: Performance Logs and Alerts (SysmonLog) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\system32\smlogsvc.exe (file missing)
O23 - Service: Telephony (TapiSrv) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Terminal Services (TermService) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\termsrv.exe (file missing)
O23 - Service: Terminal Services Licensing (TermServLicensing) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\lserver.exe (file missing)
O23 - Service: Telnet (TlntSvr) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\system32\tlntsvr.exe (file missing)
O23 - Service: Distributed Link Tracking Server (TrkSvr) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\system32\services.exe (file missing)
O23 - Service: Distributed Link Tracking Client (TrkWks) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\system32\services.exe (file missing)
O23 - Service: Utility Manager (UtilMan) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\UtilMan.exe (file missing)
O23 - Service: Windows Time (W32Time) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\services.exe (file missing)
O23 - Service: Windows Management Instrumentation (WinMgmt) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\WBEM\WinMgmt.exe (file missing)
O23 - Service: Windows Internet Name Service (WINS) (WINS) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\wins.exe (file missing)
O23 - Service: Portable Media Serial Number Service (WmdmPmSN) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Windows Management Instrumentation Driver Extensions (Wmi) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\system32\Services.exe (file missing)
O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\Documents and Settings\flatfoot\WINDOWS\system32\svchost.exe (file missing)
  • 0

Advertisements


#2
njustice

njustice

    Member

  • Member
  • PipPipPip
  • 521 posts
Hello and welcome to GTG!
We are sorry for the late reply,
If you’re still looking to resolve this issue, please run through the steps outlined in this Topic.

Post back a fresh HijackThis log when done.

If you have resolved this issue please let us know,
Thank you and again sorry for the late reply.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP