Hi experts,
I found some strange programs running on my pc and started to investigate, this is what I found:
Small program for remote controlling the PC from
http://www.dameware.com (72kb) dntus26.exe
Small program for ftp-server tasksrv.exe (22kb)
Question: How the heck did he get them there?
I am not running any servers on my pc. And no I have not surfed to the Nimda infected pages.
How did he start the telnet service remotely?
Below is from the eventlog.
Thanks in advance.
2002-05-11 05:39:00 Norton AntiVirus Error (1) 4097 NT AUTHORITY\SYSTEM HOMEPC1 The description for Event ID ( 4097 ) in Source ( Norton AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: The file
C:\Documents and Settings\Administrator\Loc
al Settings\Temporary Internet Files\Content.IE5\EXXPQOHR
\wbk24A.tm
p
is infected with the W32.Nimda.A@mm (dr) virus.; Access to the file was denied..
2002-05-11 05:39:00 Norton AntiVirus Error (1) 4097 NT AUTHORITY\SYSTEM HOMEPC1 The description for Event ID ( 4097 ) in Source ( Norton AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: The file
C:\Documents and Settings\Administrator\Loc
al Settings\Temporary Internet Files\Content.IE5\EXXPQOHR
\wbk24A.tm
p
is infected with the W32.Nimda.A@mm (dr) virus.; Unable to repair this file..
2002-05-11 05:39:00 Norton AntiVirus Error (1) 4097 NT AUTHORITY\SYSTEM HOMEPC1 The description for Event ID ( 4097 ) in Source ( Norton AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: The file
C:\Documents and Settings\Administrator\Loc
al Settings\Temporary Internet Files\Content.IE5\YJGFKXU3
\readme[1]
.eml
is infected with the W32.Nimda.enc virus.; Access to the file was denied..
2002-05-11 05:39:00 Norton AntiVirus Error (1) 4097 NT AUTHORITY\SYSTEM HOMEPC1 The description for Event ID ( 4097 ) in Source ( Norton AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: The file
C:\Documents and Settings\Administrator\Loc
al Settings\Temporary Internet Files\Content.IE5\YJGFKXU3
\readme[1]
.eml
is infected with the W32.Nimda.enc virus.; Unable to repair this file..
2002-05-11 04:20:53 TlntSvr Information None 1001 N/A HOMEPC1 The MS Telnet Service has shut down successfully.
2002-05-11 04:20:07 TlntSvr Information None 1000 N/A HOMEPC1 The MS Telnet Service has started successfully.
2002-05-11 04:14:03 TlntSvr Error None 4000 N/A HOMEPC1 An error occurred while attempting to create shell process.
2002-05-11 04:14:02 TlntSvr Error None 4000 N/A HOMEPC1 An error occurred while attempting to create shell process.
2002-05-11 04:14:02 TlntSvr Error None 4000 N/A HOMEPC1 An error occurred while attempting to create shell process.
2002-05-11 04:14:02 TlntSvr Error None 4000 N/A HOMEPC1 An error occurred while attempting to create shell process.
2002-05-11 04:14:01 TlntSvr Error None 4000 N/A HOMEPC1 An error occurred while attempting to create shell process.
2002-05-11 04:14:01 TlntSvr Error None 4000 N/A HOMEPC1 An error occurred while attempting to create shell process.
2002-05-11 04:14:00 TlntSvr Error None 4000 N/A HOMEPC1 An error occurred while attempting to create shell process.
2002-05-11 04:13:59 TlntSvr Error None 4000 N/A HOMEPC1 An error occurred while attempting to create shell process.
2002-05-11 04:13:56 TlntSvr Error None 4000 N/A HOMEPC1 An error occurred while attempting to create shell process.
2002-05-11 03:31:22 FrontPage 4.0 Warning None 1000 N/A HOMEPC1 Microsoft FrontPage Server Extensions:
error #50001 message: there is no environment variabel of type SERVER_PORT.
2002-05-11 03:27:55 Norton AntiVirus Error (1) 4097 NT AUTHORITY\SYSTEM HOMEPC1 The description for Event ID ( 4097 ) in Source ( Norton AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: The file
C:\DOCUME~1\ADMINI~1\LOCAL
S~1\Temp\F
rontPageTe
mpDir\_vti
_inf.html
was infected with the W32.Nimda.A@mm(html) virus.; The file was repaired..
2002-05-11 03:22:58 Norton AntiVirus Error (1) 4097 NT AUTHORITY\SYSTEM HOMEPC1 The description for Event ID ( 4097 ) in Source ( Norton AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: The file
C:\DOCUME~1\ADMINI~1\LOCAL
S~1\Temp\F
rontPageTe
mpDir\_vti
_inf.html
was infected with the W32.Nimda.A@mm(html) virus.; The file was repaired..
2002-05-11 01:37:54 Norton AntiVirus Error (1) 4097 NT AUTHORITY\SYSTEM HOMEPC1 The description for Event ID ( 4097 ) in Source ( Norton AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: The file
C:\Documents and Settings\Administrator\Loc
al Settings\Temporary Internet Files\Content.IE5\CMH0YNG2
\wbk19D.tm
p
is infected with the W32.Nimda.A@mm (dr) virus.; Access to the file was denied..
2002-05-11 01:37:54 Norton AntiVirus Error (1) 4097 NT AUTHORITY\SYSTEM HOMEPC1 The description for Event ID ( 4097 ) in Source ( Norton AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: The file
C:\Documents and Settings\Administrator\Loc
al Settings\Temporary Internet Files\Content.IE5\CMH0YNG2
\wbk19D.tm
p
is infected with the W32.Nimda.A@mm (dr) virus.; Unable to repair this file..
2002-05-11 01:37:53 Norton AntiVirus Error (1) 4097 NT AUTHORITY\SYSTEM HOMEPC1 The description for Event ID ( 4097 ) in Source ( Norton AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: The file
C:\Documents and Settings\Administrator\Loc
al Settings\Temporary Internet Files\Content.IE5\EXXPQOHR
\readme[1]
.eml
is infected with the W32.Nimda.enc virus.; Access to the file was denied..
2002-05-11 01:37:53 Norton AntiVirus Error (1) 4097 NT AUTHORITY\SYSTEM HOMEPC1 The description for Event ID ( 4097 ) in Source ( Norton AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: The file
C:\Documents and Settings\Administrator\Loc
al Settings\Temporary Internet Files\Content.IE5\EXXPQOHR
\readme[1]
.eml
is infected with the W32.Nimda.enc virus.; Unable to repair this file..
2002-05-11 01:37:52 Norton AntiVirus Error (1) 4097 NT AUTHORITY\SYSTEM HOMEPC1 The description for Event ID ( 4097 ) in Source ( Norton AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: The file
C:\Documents and Settings\Administrator\Loc
al Settings\Temporary Internet Files\Content.IE5\EXXPQOHR
\readme[1]
.eml
is infected with the W32.Nimda.enc virus.; Access to the file was denied..
2002-05-11 01:37:52 Norton AntiVirus Error (1) 4097 NT AUTHORITY\SYSTEM HOMEPC1 The description for Event ID ( 4097 ) in Source ( Norton AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: The file
C:\Documents and Settings\Administrator\Loc
al Settings\Temporary Internet Files\Content.IE5\EXXPQOHR
\readme[1]
.eml
is infected with the W32.Nimda.enc virus.; Unable to repair this file..
2002-05-11 01:37:52 Norton AntiVirus Error (1) 4097 NT AUTHORITY\SYSTEM HOMEPC1 The description for Event ID ( 4097 ) in Source ( Norton AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: The file
C:\Documents and Settings\Administrator\Loc
al Settings\Temporary Internet Files\Content.IE5\EXXPQOHR
\readme[1]
.eml
is infected with the W32.Nimda.enc virus.; Access to the file was denied..
2002-05-11 01:37:52 Norton AntiVirus Error (1) 4097 NT AUTHORITY\SYSTEM HOMEPC1 The description for Event ID ( 4097 ) in Source ( Norton AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: The file
C:\Documents and Settings\Administrator\Loc
al Settings\Temporary Internet Files\Content.IE5\EXXPQOHR
\readme[1]
.eml
is infected with the W32.Nimda.enc virus.; Unable to repair this file..
2002-05-11 01:37:45 Norton AntiVirus Error (1) 4097 NT AUTHORITY\SYSTEM HOMEPC1 The description for Event ID ( 4097 ) in Source ( Norton AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: The file
C:\Documents and Settings\Administrator\Loc
al Settings\Temporary Internet Files\Content.IE5\YJGFKXU3
\170.143.1
72[1].htm
was infected with the W32.Nimda.A@mm(html) virus.; The file was repaired..