Hello,
Our windows 2003 server has been hacked. I have done 2 virus scans and cleaned what it could find (used AVG and Microsoft Malicious Software removal.
However, we are still being flagged as "Spammers" so something is still not right.
Here is our HijackThis Log File...
Logfile of HijackThis v1.99.1
Scan saved at 10:53:02 AM, on 7/21/2007
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\3ware\3DM\3dmd.exe
C:\Program Files\AMCC\3DM2\3dm2.exe
C:\Program Files\Common Files\Acronis\Schedule2\sc
hedul2.exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\CommVault Systems\Galaxy\Base\cvd.ex
e
C:\WINDOWS\system32\inetsr
v\inetinfo
.exe
C:\PROGRA~1\MICROS~1\MSSQL
\binn\sqls
ervr.exe
C:\Program Files\SWsoft\Plesk\Databas
es\MySQL\b
in\mysqld-
nt.exe
C:\Program Files\SWsoft\Plesk\dns\bin
\named.exe
C:\Program Files\SWsoft\Plesk\MySQL\b
in\mysqld-
nt.exe
C:\WINDOWS\system32\logon.
exe
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\SWsoft\Plesk\Additio
nal\Tomcat
\bin\tomca
t5.exe
C:\Program Files\CommVault Systems\Galaxy\Base\evmgrc
.exe
C:\Program Files\Common Files\System\MSSearch\Bin\
mssearch.e
xe
C:\Program Files\SWsoft\Plesk\admin\b
in\plesksr
v.exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\SWsoft\Plesk\admin\b
in\psa-ser
v.exe
C:\Program Files\Microsoft SQL Server\MSSQL\binn\sqlagent
.exe
C:\Program Files\SWsoft\Plesk\admin\b
in\Apache.
exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\SWsoft\Plesk\kav\kav
svc.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\rdpcli
p.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Acronis\Schedule2\sc
hedhlp.exe
C:\Program Files\SWsoft\Plesk\Acronis
\TrueImage
Enterprise
\TrueImage
Monitor.ex
e
C:\WINDOWS\system32\ctfmon
.exe
C:\Program Files\3ware\3DM\3dm.exe
C:\Program Files\SWsoft\Plesk\admin\b
in\traymon
itor.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlma
ngr.exe
C:\Program Files\AMCC\3DM2\WinAVAlarm
.exe
C:\PROGRA~1\Grisoft\AVG7\a
vgrssvc.ex
e
C:\PROGRA~1\Grisoft\AVG7\a
vgrssvc.ex
e
C:\PROGRA~1\Grisoft\AVG7\a
vgemc.exe
C:\PROGRA~1\Grisoft\AVG7\a
vgamsvr.ex
e
C:\PROGRA~1\Grisoft\AVG7\a
vgupsvc.ex
e
C:\Program Files\Grisoft\AVG7\avgcc.e
xe
c:\windows\system32\inetsr
v\w3wp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cisvc.
exe
C:\WINDOWS\system32\cidaem
on.exe
C:\WINDOWS\system32\cidaem
on.exe
c:\windows\system32\inetsr
v\w3wp.exe
C:\Program Files\SWsoft\Plesk\admin\b
in\PopPass
D.exe
C:\Program Files\SWsoft\Plesk\admin\b
in\SpamAss
assinServi
ce.exe
C:\PROGRA~1\SWsoft\Plesk\A
DDITI~1\Pe
rl\bin\per
l.exe
C:\PROGRA~1\SWsoft\Plesk\A
DDITI~1\Pe
rl\bin\per
l.exe
C:\Program Files\SWsoft\Plesk\admin\b
in\stunnel
.exe
C:\Program Files\SWsoft\Plesk\Mail Servers\Mail Enable\Bin\MESMTPC.EXE
C:\Program Files\SWsoft\Plesk\Mail Servers\Mail Enable\Bin\MEPOC.EXE
C:\Program Files\SWsoft\Plesk\Mail Servers\Mail Enable\Bin\MEPOPS.EXE
C:\Program Files\SWsoft\Plesk\Mail Servers\Mail Enable\Bin\MEMTA.EXE
C:\Program Files\SWsoft\Plesk\Mail Servers\Mail Enable\Bin\MELSC.EXE
C:\downloaded files\Hijack This\HijackThis.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL = res://shdoclc.dll/hardAdmi
n.htm
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.electricink.ca/R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\sc
hedhlp.exe
"
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\SWsoft\Plesk\Acronis
\TrueImage
Enterprise
\TrueImage
Monitor.ex
e
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\a
vgcc.exe /STARTUP
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dump
rep 0 -u
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKCU\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSC
lientMsiTr
ans\tscuin
st.vbs"
O4 - Global Startup: 3DM.lnk = ?
O4 - Global Startup: Plesk Services Monitor.lnk = C:\Program Files\SWsoft\Plesk\admin\b
in\traymon
itor.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlma
ngr.exe
O4 - Global Startup: WinAVAlarm Startup Item.lnk = C:\Program Files\AMCC\3DM2\WinAVAlarm
.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {215B8138-A3CF-44C5-803F-8
226143CFC0
A} (Trend Micro ActiveX Scan Agent 6.6) -
http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cabO16 - DPF: {5ED80217-570B-4DA9-BF44-B
E107C0EC16
6} (Windows Live Safety Center Base Module) -
http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cabO16 - DPF: {6414512B-B978-451D-A0D8-F
CFDF33E833
C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1147544667130O16 - DPF: {6E32070A-766D-4EE6-879C-D
C1FA91D2FC
3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1158013453546O16 - DPF: {EF791A6B-FC12-4C68-99EF-F
B9E207A39E
6} (McFreeScan Class) -
http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,4948/mcfscan.cabO17 - HKLM\System\CCS\Services\T
cpip\..\{D
729357B-F1
4A-4E47-8F
33-0315B25
3E217}: NameServer = 64.34.24.23,64.34.24.24
O20 - Winlogon Notify: avgwlntf - C:\WINDOWS\SYSTEM32\avgwln
tf.dll
O20 - Winlogon Notify: dimsntfy - C:\WINDOWS\SYSTEM32\dimsnt
fy.dll
O23 - Service: 3DM - Unknown owner - C:\Program Files\3ware\3DM\3dmd.exe
O23 - Service: AMCC 3DM2 (3DM2) - Unknown owner - C:\Program Files\AMCC\3DM2/3dm2.exe
O23 - Service: Acronis Remote Agent (AcronisAgent) - Acronis - C:\Program Files\Common Files\Acronis\Agent\agent.
exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\sc
hedul2.exe
O23 - Service: Alerter - Unknown owner - C:\WINDOWS\system32\driver
s\alerter.
exe (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\a
vgamsvr.ex
e
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\a
vgupsvc.ex
e
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\a
vgrssvc.ex
e
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\a
vgemc.exe
O23 - Service: ClipBook (ClipSrv) - Unknown owner - C:\WINDOWS\System32\clipsv
r.exe (file missing)
O23 - Service: Galaxy Communications Service (ControlSet001) (GxCVD(ControlSet001)) - Unknown owner - C:\Program Files\CommVault Systems\Galaxy\Base\cvd.ex
e" -vm ControlSet001 (file missing)
O23 - Service: Galaxy Client Event Manager (ControlSet001) (GxEvMgrC(ControlSet001)) - Unknown owner - C:\Program Files\CommVault Systems\Galaxy\Base\evmgrc
.exe" -vm ControlSet001 (file missing)
O23 - Service: IIS Administrator (iisadm) - Unknown owner - C:\WINDOWS\system32\inetin
fo.exe (file missing)
O23 - Service: KasperskyTM Anti-Virus (kavsvc) - Unknown owner - C:\Program Files\SWsoft\Plesk\kav\kav
svc.exe
O23 - Service: MailEnable List Connector (MELCS) - MailEnable Pty Ltd - C:\Program Files\SWsoft\Plesk\Mail Servers\Mail Enable\Bin\MELSC.EXE
O23 - Service: MailEnable Mail Transfer Agent (MEMTAS) - MailEnable Pty Ltd - C:\Program Files\SWsoft\Plesk\Mail Servers\Mail Enable\Bin\MEMTA.EXE
O23 - Service: MailEnable Postoffice Connector (MEPOCS) - MailEnable Pty Ltd - C:\Program Files\SWsoft\Plesk\Mail Servers\Mail Enable\Bin\MEPOC.EXE
O23 - Service: MailEnable POP Service (MEPOPS) - MailEnable Pty Ltd - C:\Program Files\SWsoft\Plesk\Mail Servers\Mail Enable\Bin\MEPOPS.EXE
O23 - Service: MailEnable SMTP Connector (MESMTPCS) - MailEnable Pty Ltd - C:\Program Files\SWsoft\Plesk\Mail Servers\Mail Enable\Bin\MESMTPC.EXE
O23 - Service: MySQL Server (MySQL) - Unknown owner - C:\Program Files\SWsoft\Plesk\Databas
es\MySQL\b
in\mysqld-
nt.exe" --defaults-file="C:\Progra
m Files\SWsoft\Plesk\Databas
es\MySQL\D
ata\my.ini
" MySQL (file missing)
O23 - Service: Plesk Name Server (named) - Unknown owner - C:\Program Files\SWsoft\Plesk\dns\bin
\named.exe
" -n1 (file missing)
O23 - Service: PleskControlPanel - Unknown owner - C:\Program Files\SWsoft\Plesk\admin\b
in\Apache.
exe" -k runservice (file missing)
O23 - Service: Plesk Miscellaneous Service (pleskmiscsrv) - Unknown owner - C:\Program Files\SWsoft\Plesk\admin\b
in\psa-ser
v.exe
O23 - Service: Plesk SQL Server (PleskSQLServer) - Unknown owner - C:\Program Files\SWsoft\Plesk\MySQL\b
in\mysqld-
nt.exe" --defaults-file="C:\Progra
m Files\SWsoft\Plesk\MySQL\D
ata\my.ini
" PleskSQLServer (file missing)
O23 - Service: Plesk Management Service (plesksrv) - Unknown owner - C:\Program Files\SWsoft\Plesk\admin\b
in\plesksr
v.exe" -run (file missing)
O23 - Service: Plesk PopPass Service (PopPassD) - Unknown owner - C:\Program Files\SWsoft\Plesk\admin\b
in\PopPass
D.exe" -run (file missing)
O23 - Service: Primary Logon (prilogon) - Unknown owner - C:\WINDOWS\system32\logon.
exe
O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINDOWS\system32\driver
s\isplog.e
xe" /service (file missing)
O23 - Service: SWsoft SiteBuilder (SiteBuilder) - Unknown owner - C:\Program Files\SWsoft\Plesk\WinSite
Builder\do
croot\site
builder.ex
e" -x (file missing)
O23 - Service: Plesk SpamAssassin Service (SpamAssassinService) - - C:\Program Files\SWsoft\Plesk\admin\b
in\SpamAss
assinServi
ce.exe
O23 - Service: Plesk SSL Wrapper Service (stunnel) - Unknown owner - C:\Program Files\SWsoft\Plesk\admin\b
in\stunnel
.exe" -service (file missing)
O23 - Service: Apache Tomcat (Tomcat5) - Unknown owner - C:\Program Files\SWsoft\Plesk\Additio
nal\Tomcat
\bin\tomca
t5.exe" //RS//Tomcat5 (file missing)
Thank you
Kirk
Start Free Trial