Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Please Look at my logs


  • Please log in to reply

#1
Computeralli

Computeralli

    New Member

  • Member
  • Pip
  • 1 posts
I've had a lot of problems with this server hogging all my bandwidth can some one let me know what's going on..Thanks


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:59:10 AM, on 4/5/2008
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\termsrv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
D:\CFusionMX\runtime\bin\jrunsvc.exe
D:\CFusionMX\db\slserver52\bin\swagent.exe
D:\CFusionMX\db\slserver52\bin\swstrtr.exe
D:\CFusionMX\db\slserver52\bin\swsoc.exe
D:\PROGRA~1\sav\DefWatch.exe
D:\CFusionMX\runtime\bin\jrun.exe
D:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\WINNT\System32\svchost.exe
d:\Imail\IMonitor.exe
C:\WINNT\System32\cba\pds.exe
d:\Imail\iwebmsg.exe
C:\WINNT\System32\llssrv.exe
D:\MICROS~1\MSSQL\binn\sqlservr.exe
D:\PROGRA~1\sav\Rtvscan.exe
D:\PROGRA~1\Symantec\SYMANT~1\NSCTOP.EXE
d:\Imail\POP3D32.exe
C:\WINNT\system32\regsvc.exe
c:\program files\saraja software\system monitor\system monitor.exe
C:\WINNT\system32\MSTask.exe
C:\PROGRA~1\Serv-U\SERVUD~1.EXE
d:\Imail\smtpd32.exe
D:\MICROS~1\MSSQL\binn\sqlagent.exe
C:\winnt\driver~1\i386\csrss.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\system32\inetsrv\inetinfo.exe
C:\WINNT\System32\msdtc.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\WINNT\system32\MsgSys.EXE
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\rdpclip.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Java\jre1.5.0_10\bin\jucheck.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINNT\system32\logon.scr
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R3 - Default URLSearchHook is missing
O1 - Hosts: 209.195.4.71 vinz
O1 - Hosts: 209.195.4.69 keymaster
O1 - Hosts: 64.25.2.125 monitor.computeralli.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [vptray] D:\PROGRA~1\sav\vptray.exe
O4 - HKLM\..\Run: [DiskeeperSystray] "D:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop...p/PCPitStop.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6CBDDF17-DF69-4FA9-9BF7-C388FED02686}: NameServer = 10.0.1.195,64.25.2.118
O17 - HKLM\System\CCS\Services\Tcpip\..\{CB065F56-4289-48F8-9ABC-18AABFF4C554}: NameServer = 64.25.4.118,66.180.96.11,64.238.96.9,205.152.0.5,205.152.0.20,4.2.2.2
O17 - HKLM\System\CS1\Services\Tcpip\..\{6CBDDF17-DF69-4FA9-9BF7-C388FED02686}: NameServer = 10.0.1.195,64.25.2.118
O17 - HKLM\System\CS2\Services\Tcpip\..\{6CBDDF17-DF69-4FA9-9BF7-C388FED02686}: NameServer = 10.0.1.195,64.25.2.118
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: ColdFusion MX Application Server - Macromedia Inc. - D:\CFusionMX\runtime\bin\jrunsvc.exe
O23 - Service: ColdFusion MX ODBC Agent - Unknown owner - D:\CFusionMX\db\slserver52\bin\swagent.exe
O23 - Service: ColdFusion MX ODBC Server - Unknown owner - D:\CFusionMX\db\slserver52\bin\swstrtr.exe
O23 - Service: DefWatch - Symantec Corporation - D:\PROGRA~1\sav\DefWatch.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - D:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: IMail FINGER Server (FINGRD32) - Ipswitch, Inc. - d:\Imail\FINGRD32.exe
O23 - Service: Handy Backup Pro Agent - Novosoft - D:\PROGRA~1\Novosoft\HANDYB~2\hbagent.exe
O23 - Service: IMail LDAP Server (ILDAP) - Ipswitch, Inc. - d:\Imail\ILDAP.exe
O23 - Service: IMail IMAP4 Server (IMAP4D32) - Ipswitch, Inc. - d:\Imail\IMAP4D32.exe
O23 - Service: IMail Monitor Service (IMonitor) - Ipswitch, Inc. - d:\Imail\IMonitor.exe
O23 - Service: Intel PDS - Intel® Corporation - C:\WINNT\System32\cba\pds.exe
O23 - Service: IMail Web Calendar Service (IWebCal) - Ipswitch, Inc. - d:\Imail\IWebCal.exe
O23 - Service: IMail Web Service (IWEBMSG) - Ipswitch, Inc. - d:\Imail\iwebmsg.exe
O23 - Service: Symantec AntiVirus Server (Norton AntiVirus Server) - Symantec Corporation - D:\PROGRA~1\sav\Rtvscan.exe
O23 - Service: Symantec System Center Discovery Service (NSCTOP) - Symantec Corporation - D:\PROGRA~1\Symantec\SYMANT~1\NSCTOP.EXE
O23 - Service: IMail POP3 Server (POP3D32) - Ipswitch, Inc. - d:\Imail\POP3D32.exe
O23 - Service: IMail PWD Server (PSERVE) - Ipswitch, Inc. - d:\Imail\PSERVE.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Saraja Software System Monitor (SarSoftSysMon) - - c:\program files\saraja software\system monitor\system monitor.exe
O23 - Service: Serv-U FTP Server (Serv-U) - Cat Soft - C:\PROGRA~1\Serv-U\SERVUD~1.EXE
O23 - Service: IMail SMTP Server (SMTPD32) - Ipswitch, Inc. - d:\Imail\smtpd32.exe
O23 - Service: IMail Sys Logger Service (SYSLOGD) - Ipswitch, Inc. - d:\Imail\SYSLOGD.exe
O23 - Service: IMail WHOIS Server (WHOISD32) - Ipswitch, Inc. - d:\Imail\WHOISD32.exe
O23 - Service: WinDLL DLL Loader (WinDLL) - Unknown owner - C:\winnt\driver~1\i386\csrss.exe

--
End of file - 7319 bytes
  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP