I believe I may have a server with infected with Mallware, I recently ran Hijackthis on my Win 2003 exchange server. Can anyone point out known entries processes that I should clean?
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:58:35 PM, on 8/21/2007
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\Dfssvc
.exe
C:\WINDOWS\System32\dns.ex
e
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\csifcsvc.exe
C:\WINDOWS\system32\inetsr
v\inetinfo
.exe
C:\Program Files\Microsoft SQL Server\MSSQL$SBSMONITORING
\Binn\sqls
ervr.exe
C:\Program Files\Microsoft SQL Server\MSSQL$SHAREPOINT\Bi
nn\sqlserv
r.exe
c:\Program Files\Microsoft SQL Server\MSSQL$WSUS\Binn\sql
servr.exe
C:\WINDOWS\system32\ntfrs.
exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Symantec\SMSMSE\5.0\
Server\SAV
FMSESrv.ex
e
C:\Program Files\Microsoft SQL Server\MSSQL$SBSMONITORING
\Binn\sqla
gent.EXE
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Symantec\SMSMSE\5.0\
Server\SAV
FMSECtrl.E
XE
C:\Program Files\Symantec\SMSMSE\5.0\
Server\SAV
FMSEUI.EXE
C:\Program Files\Symantec\SMSMSE\5.0\
Server\SAV
FMSESp.exe
C:\Program Files\Symantec\SMSMSE\5.0\
Server\SAV
FMSESp.exe
C:\Program Files\Symantec\SMSMSE\5.0\
Server\SAV
FMSESp.exe
C:\Program Files\Symantec\SMSMSE\5.0\
Server\SAV
FMSESp.exe
C:\Program Files\Symantec\SMSMSE\5.0\
Server\SAV
FMSESp.exe
C:\Program Files\Symantec\SMSMSE\5.0\
Server\SAV
FMSESp.exe
C:\Program Files\Symantec\SMSMSE\5.0\
Server\SAV
FMSESp.exe
C:\Program Files\Symantec\SMSMSE\5.0\
Server\SAV
FMSESp.exe
C:\Program Files\Symantec\SMSMSE\5.0\
Server\SAV
FMSESp.exe
C:\WINDOWS\System32\wins.e
xe
C:\Program Files\Symantec\SMSMSE\5.0\
Server\SAV
FMSELog.EX
E
C:\Program Files\Symantec\SMSMSE\5.0\
Server\SAV
FMSESJM.EX
E
C:\Program Files\Symantec\SMSMSE\5.0\
Server\SAV
FMSETask.e
xe
C:\Program Files\Symantec\SMSMSE\5.0\
Server\Con
soleAppMgr
.exe
C:\Program Files\Symantec\SMSMSE\5.0\
Server\con
duit.exe
C:\WINDOWS\system32\tcpsvc
s.exe
C:\Program Files\LiveVault Corporation\BackupEngine\L
V_Super.ex
e
C:\Program Files\Exchsrvr\bin\exmgmt.
exe
C:\Program Files\LiveVault Corporation\BackupEngine\L
V_Engine.e
xe
C:\Program Files\Exchsrvr\bin\mad.exe
C:\Program Files\Dell SAS RAID Storage
Manager\Framework\VivaldiF
ramework.e
xe
C:\Program Files\Common Files\System\MSSearch\Bin\
mssearch.e
xe
C:\WINDOWS\system32\cmd.ex
e
C:\Program Files\Dell SAS RAID Storage Manager\JRE\bin\javaw.exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Dell SAS RAID Storage Manager\MegaMonitor\mrmoni
tor.exe
C:\Program Files\Exchsrvr\bin\store.e
xe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Symantec\SMSMSE\5.0\
Server\SAV
FMSESpamSt
atsManager
.exe
c:\windows\system32\inetsr
v\w3wp.exe
C:\PROGRA~1\SYMANT~1\DWHWI
ZRD.EXE
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\rdpcli
p.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Broadcom\BACS\BacsTr
ay.exe
C:\Program Files\Dell SAS RAID Storage Manager\MegaPopup\Popup.ex
e
C:\WINDOWS\startup.exe
C:\WINDOWS\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon
.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QB
ServerUtil
ityMgr.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlma
ngr.exe
c:\windows\system32\inetsr
v\w3wp.exe
C:\WINDOWS\System32\svchos
t.exe
c:\windows\system32\inetsr
v\w3wp.exe
C:\WINDOWS\system32\mmc.ex
e
D:\shared\HiJackThis.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
res://shdoclc.dll/hardAdmi
n.htm
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
res://shdoclc.dll/hardAdmi
n.htm
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} -
C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEH
elper.dll
O4 - HKLM\..\Run: [DWPersistentQueuedReporti
ng]
C:\PROGRA~1\COMMON~1\MICRO
S~1\DW\DWT
RIG20.EXE -a
O4 - HKLM\..\Run: [bacstray] C:\Program Files\Broadcom\BACS\BacsTr
ay.exe
O4 - HKLM\..\Run: [Popup] "C:\Program Files\Dell SAS RAID Storage
Manager\MegaPopup\Popup.ex
e"
O4 - HKLM\..\Run: [Kav_key] C:\WINDOWS\startup.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IM
JPMIG.EXE"
/Spoil
/RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IME
KRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PI
NTLGNT\ImS
cInst.exe
/SYNC
O4 - HKLM\..\Run: [PHIME2002ASync]
C:\WINDOWS\system32\IME\TI
NTLGNT\TIN
TSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TI
NTLGNT\TIN
TSETP.EXE
/IMEName
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec
Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTra
y.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall]
%systemroot%\system32\tscu
pgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall]
%systemroot%\system32\tscu
pgrd.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-492134541-69
0652631-89
0307051-11
47\..\RunO
nce:
[tscuninstall] %systemroot%\system32\tscu
pgrd.exe (User
'QBDataServiceUser17')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall]
%systemroot%\system32\tscu
pgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall]
%systemroot%\system32\tscu
pgrd.exe (User 'Default user')
O4 - Startup: Server Management.lnk = ?
O4 - Global Startup: QuickBooks Database Server Manager.lnk = C:\Program
Files\Common Files\Intuit\QuickBooks\QB
ServerUtil
ityMgr.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL
Server\80\Tools\Binn\sqlma
ngr.exe
O14 - IERESET.INF: START_PAGE_URL=
http://companywebO15 - ESC Trusted Zone:
http://rmd.atdmt.comO15 - ESC Trusted Zone:
http://view.atdmt.comO15 - ESC Trusted Zone:
http://help.live.comO15 - ESC Trusted Zone:
http://js.shared.live.comO15 - ESC Trusted Zone:
http://onecare.live.comO15 - ESC Trusted Zone:
http://shared.live.comO15 - ESC Trusted Zone:
http://toolbar.live.comO15 - ESC Trusted Zone:
http://ads1.msn.comO15 - ESC Trusted Zone:
http://rad.msn.comO15 - ESC Trusted Zone:
http://runonce.msn.comO15 - ESC Trusted Zone:
http://*.whois.comO15 - ESC Trusted Zone:
http://*.windowsupdate.comO15 - ESC Trusted Zone:
http://runonce.msn.com (HKLM)
O15 - ESC Trusted Zone:
http://*.windowsupdate.com (HKLM)
O15 - ESC Trusted IP range:
http://192.168.0.1O16 - DPF: {6E32070A-766D-4EE6-879C-D
C1FA91D2FC
3} (MUWebControl Class) -
http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1187231103527O17 - HKLM\System\CCS\Services\T
cpip\Param
eters: Domain = mjscpapc.local
O17 - HKLM\Software\..\Telephony
: DomainName = mjscpapc.local
O17 -
HKLM\System\CCS\Services\T
cpip\..\{E
27A8856-48
90-41B8-B2
96-4390155
D7606}:
NameServer = 192.168.0.2
O17 - HKLM\System\CS1\Services\T
cpip\Param
eters: Domain = mjscpapc.local
O17 - HKLM\System\CS2\Services\T
cpip\Param
eters: Domain = mjscpapc.local
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program
Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation -
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec
Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation -
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec
Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: FileCabinet Solution Print Service (FCPrintService) -
Creative Solutions - C:\WINDOWS\csifcsvc.exe
O23 - Service: Vorkstation (ianmanworkstawio) - Unknown owner -
C:\WINDOWS\system32\explor
er.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision
Corporation - C:\Program Files\Common Files\InstallShield\Driver
\1050\Inte
l
32\IDriverT.exe
O23 - Service: LiveVault Backup Service (LVBackupService) - Iron Mountain
Digital - C:\Program Files\LiveVault Corporation\BackupEngine\L
V_Super.ex
e
O23 - Service: MRMonitor (MegaMonitorSrv) - Unknown owner - C:\Program
Files\Dell SAS RAID Storage Manager\MegaMonitor\mrmoni
tor.exe
O23 - Service: SSMFramework (MSMFramework) - Unknown owner - C:\Program
Files\Dell SAS RAID Storage Manager\Framework\VivaldiF
ramework.e
xe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. -
C:\Program Files\Common
Files\Intuit\QuickBooks\FC
S\Intuit.Q
uickBooks.
FCS.exe
O23 - Service: QuickBooksDB17 - iAnywhere Solutions, Inc. -
D:\srvapps\QUICKB~1\QBDBMg
rN.exe
O23 - Service: Symantec Mail Security Spam Statistics
(SAVFMSESpamStatsManager) - Symantec Corporation - C:\Program
Files\Symantec\SMSMSE\5.0\
Server\SAV
FMSESpamSt
atsManager
.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec
AntiVirus\SavRoam.exe
O23 - Service: Symantec Mail Security for Microsoft Exchange (SMSMSE) -
Symantec Corporation - C:\Program
Files\Symantec\SMSMSE\5.0\
Server\SAV
FMSESrv.ex
e
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec
Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation -
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program
Files\Symantec AntiVirus\Rtvscan.exe
--
End of file - 10265 bytes
Start Free Trial